<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Patching in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322543#M597882</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I tried an export from cli and got the below message, any idea why I've done this before successfully. ??&lt;BR /&gt;&lt;BR /&gt;Export Operation Failed. ISE CA keys are not in the trust store, check ISE node role or whether CA certificate is revoked/deleted&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 20 Aug 2025 15:25:13 GMT</pubDate>
    <dc:creator>benolyndav</dc:creator>
    <dc:date>2025-08-20T15:25:13Z</dc:date>
    <item>
      <title>ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322526#M597875</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Would an expired ISE&amp;nbsp; system certificate cause an ISE deployment patch to fail ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 14:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322526#M597875</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-20T14:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322528#M597876</link>
      <description>&lt;P&gt;gDay&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;and&amp;nbsp;no, an expired ISE system certificate won’t block a patch installation, but it can affect services like admin login, RADIUS/EAP, or HTTPS access, so it’s best to renew before patching........&lt;/P&gt;&lt;P&gt;-Enes&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322528#M597876</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-08-20T15:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322530#M597877</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;for patches no I don't believe so, but expired certificates are highlighted when you run a pre-upgrade&amp;nbsp;health check and you should ensure the health check is sucessful before starting the upgrade.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322530#M597877</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-20T15:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322531#M597878</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for that, would you suggest exporting certs before patching ? I do this before the upgrade but not sure whether&amp;nbsp; its required for patching.&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322531#M597878</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-20T15:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322534#M597880</link>
      <description>&lt;P&gt;u r absolutely welcome&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;.&amp;nbsp;About ur quesiton; exporting certs isn’t required for patching, but it’s a good practice to back them up (along with the config) just like u do before an upgrade, for recovery if anything goes wrong.... U know just so u can sleep good LOOOL...&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Enes&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322534#M597880</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-08-20T15:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322543#M597882</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I tried an export from cli and got the below message, any idea why I've done this before successfully. ??&lt;BR /&gt;&lt;BR /&gt;Export Operation Failed. ISE CA keys are not in the trust store, check ISE node role or whether CA certificate is revoked/deleted&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322543#M597882</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-20T15:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322544#M597883</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;That usually means the ISE node u’re exporting from isn’t the Primary Administration Node (PAN) or that the certificate authority keys were removed/revoked. Try the export from the PAN, and check under Administration - System - Certificates - Certificate Authority to confirm the CA keys are present and valid. Which means that if the keys are missing, u’ll need to re-import or regenerate them before export will work...&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322544#M597883</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-08-20T15:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322564#M597885</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I have just ran a tech-support and under deployment it states that the SEC PAN is actually ACTIVE and the PRI PAN STANDBY, you were right &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; any ideas why this would happen they are both online.??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 16:04:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322564#M597885</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-20T16:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322569#M597886</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;That can happen if the primary PAN lost communication with the rest of the deployment or a manual role swap occurred. Only one PAN can be active at a time, so if the secondary shows as active it has taken over. And my Cisco friend, i would suggest to check synchronization status, NTP alignment, and network connectivity between the PANs. So, if the primary is healthy, u can manually promote it back to active....&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 16:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322569#M597886</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-08-20T16:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322581#M597887</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strange thing is though under the Deployment in the GUI the Secondary promote button is still highlighted and ready to press, and also I am not sure how to promote the PRI PAN back to Active there is no button for that.??&lt;BR /&gt;What I mean is when I log into ISE I'm still logging into the PRI PAN GUI, but show tech-support says the SEC PAN is ACTIVE&lt;BR /&gt;and also the CERT export didn't work from the PRI PAN but did from the SEC PAN ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 16:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322581#M597887</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-20T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322602#M597889</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;alright I see. As I can remember from my last project, In ise only the secondary pan ever shows the Promote to Primary, button in the gui, which is whats expected. So the primary pan wont show a promote option cause its already designated as primary by role, even if its currently in standby... So let me use some bulletpoints to explain what is happening in ur case:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;Secondary PAN is currently Active&lt;/STRONG&gt; (running the admin services).&lt;/LI&gt;&lt;LI&gt;The &lt;STRONG&gt;Primary PAN is in Standby&lt;/STRONG&gt; (healthy, but not running admin services)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;and to the primary pan back to active, u need to :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Make sure both nodes are synced with the well known &lt;STRONG&gt;show application status ise&lt;/STRONG&gt; on both, and check Administration &amp;gt; System &amp;gt; Deployment &amp;gt; all services should show green).&lt;/LI&gt;&lt;LI&gt;From the GUI, click &lt;STRONG&gt;Promote to Primary&lt;/STRONG&gt; on the Secondary. This will flip the roles, the Secondary becomes Standby and the Primary becomes Active again.&lt;/LI&gt;&lt;LI&gt;If the GUI button fails, you can do it via CLI: application config ise&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;and also before promoting, please please confirm ntp and replication status, because if the primary is out of sync, forcing it Active can cause database issues. And check this link also:&amp;nbsp;&lt;A href="https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html" target="_blank" rel="noopener"&gt;Setting Up Cisco ISE in a Distributed Environment&amp;nbsp; [Cisco Identity Services Engine] - Cisco Systems&lt;/A&gt;&lt;/P&gt;&lt;P&gt;hope it wasnt a looong answer, and hope it helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Enes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 17:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5322602#M597889</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-08-20T17:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324299#M597951</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So I tried this but it promoted the Secondary to PRI PAN as when I browsed to the SEC PANs address it was now the PRI PAN very weird do you think its a bug ??&lt;/P&gt;&lt;P&gt;P.S apologies for the late response&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 08:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324299#M597951</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-26T08:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324411#M597952</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;We good man.&amp;nbsp;And actually, that’s actually expected, when you hit Promote to Primary on the Secondary, it flips roles, so the Secondary becomes the new Primary PAN. Not a bug. So u good!&lt;/P&gt;&lt;P&gt;hope it helped and stay EXPERT!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;-Enes&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 11:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324411#M597952</guid>
      <dc:creator>Enes Simnica</dc:creator>
      <dc:date>2025-08-26T11:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324426#M597953</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;in an &lt;STRONG&gt;ISE Cluster&lt;/STRONG&gt; you can have only &lt;STRONG&gt;2 PANs&lt;/STRONG&gt;, &lt;STRONG&gt;Primary&lt;/STRONG&gt; and &lt;STRONG&gt;Secondary&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Whenever you hit the &lt;STRONG&gt;Promote to Primary&lt;/STRONG&gt; button on the &lt;STRONG&gt;SPAN&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="SPAN Deployment.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250949iEF6689C22D61455D/image-size/large?v=v2&amp;amp;px=999" role="button" title="SPAN Deployment.png" alt="SPAN Deployment.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the &lt;STRONG&gt;SPAN&lt;/STRONG&gt; becomes the &lt;STRONG&gt;PPAN&lt;/STRONG&gt;, and you have to use the "&lt;STRONG&gt;Old SPAN&lt;/STRONG&gt;" &lt;STRONG&gt;IP Addr&lt;/STRONG&gt; to access the &lt;STRONG&gt;ISE GUI&lt;/STRONG&gt;&amp;nbsp;for administration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;About &lt;STRONG&gt;Certificate&lt;/STRONG&gt; ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;You can export via &lt;STRONG&gt;CLI&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE&gt;ise/admin# &lt;FONT color="#0000FF"&gt;application configure ise&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt; Selection configuration option&lt;BR /&gt; [1]Reset M&amp;amp;T Session Database&lt;BR /&gt; ...&lt;BR /&gt; &lt;FONT color="#0000FF"&gt;[7]Export Internal CA Store&lt;/FONT&gt;&lt;BR /&gt; [8]Import Internal CA Store&lt;BR /&gt; ...&lt;BR /&gt; [44]CA Diagnostic Tool&lt;BR /&gt; [0]Exit&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and via &lt;STRONG&gt;GUI&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Management &amp;gt; System Certificates&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="System Certificates - Export.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250950iEC6F736D9B900A94/image-size/large?v=v2&amp;amp;px=999" role="button" title="System Certificates - Export.png" alt="System Certificates - Export.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;at&amp;nbsp;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Management &amp;gt; Trusted Certificates&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Trusted Certificates - Export.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250951i472CD87111ECF7D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Trusted Certificates - Export.png" alt="Trusted Certificates - Export.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About your&amp;nbsp;&lt;STRONG&gt;SPAN&lt;/STRONG&gt; showing &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt;&amp;nbsp;...&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PPAN&lt;/STRONG&gt;&amp;nbsp;and &lt;STRONG&gt;SPAN&lt;/STRONG&gt; example:&lt;/P&gt;
&lt;PRE&gt;ise/admin# &lt;FONT color="#0000FF"&gt;show tech-support&lt;/FONT&gt;&lt;BR /&gt; ...&lt;BR /&gt; NAME             PERSONA   ROLE       ACTIVE  REPLICATION&lt;BR /&gt; ---------------  -------   ---------- ------  ---------------&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  PSN       SECONDARY  NONE    SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  PSN       SECONDARY  NONE    SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  PSN       SECONDARY  NONE    SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  &lt;FONT color="#0000FF"&gt;PAN       PRIMARY    NONE   &lt;/FONT&gt; Not Applicable&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  &lt;FONT color="#0000FF"&gt;MNT      &lt;/FONT&gt; SECONDARY  &lt;FONT color="#0000FF"&gt;ACTIVE&lt;/FONT&gt;  SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  PSN       SECONDARY  NONE    SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  PXG       SECONDARY  NONE    SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  &lt;FONT color="#0000FF"&gt;MNT&lt;/FONT&gt;       SECONDARY  &lt;FONT color="#0000FF"&gt;STANDBY&lt;/FONT&gt; SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  &lt;FONT color="#0000FF"&gt;PAN       SECONDARY  NONE   &lt;/FONT&gt; SYNC COMPLETED&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  PXG       SECONDARY  NONE    SYNC COMPLETED&lt;BR /&gt; ...&lt;/PRE&gt;
&lt;P&gt;please take a look if your&amp;nbsp;&lt;STRONG&gt;SPAN&lt;/STRONG&gt; is not also a &lt;STRONG&gt;PMnT&lt;/STRONG&gt;, the &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt; is for the &lt;STRONG&gt;PMnT&lt;/STRONG&gt; and not for the &lt;STRONG&gt;SPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 12:19:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324426#M597953</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-08-26T12:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324543#M597963</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1724308"&gt;@Enes Simnica&lt;/a&gt;&amp;nbsp;&amp;nbsp;but when I try to export the certs via cli I get this message (Export Operation Failed. ISE CA keys are not in the trust store, check ISE node role or whether CA certificate is revoked/deleted) any idea why at all&amp;nbsp; I ran a tech-support and it looks like the correct PAN is the PRI, I do see something I'm not too sure about its the (Not Applicable) any idea on that also&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;DC-STH-ISE-01 PAN,MNT SECONDARY ACTIVE SYNC COMPLETED&lt;BR /&gt;DC-NTH-ISE-01 PAN,MNT PRIMARY STANDBY &lt;STRONG&gt;Not Applicable&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 15:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324543#M597963</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-26T15:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324544#M597964</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the info , I see you have the Not Applicable is that how it is then for PRI PAN ??&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 15:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324544#M597964</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-08-26T15:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Patching</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324591#M597968</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;&amp;nbsp;PPAN&lt;/STRONG&gt; replication status is &lt;STRONG&gt;Not Applicable&lt;/STRONG&gt;, because the &lt;STRONG&gt;PPAN&lt;/STRONG&gt; is the &lt;STRONG&gt;Publisher&lt;/STRONG&gt; (responsible for the replication), the other &lt;STRONG&gt;Nodes&lt;/STRONG&gt; are the &lt;STRONG&gt;Subscribers&lt;/STRONG&gt;:&lt;/P&gt;
&lt;PRE&gt;ise/admin# &lt;FONT color="#0000FF"&gt;show tech-support&lt;/FONT&gt;&lt;BR /&gt; ...&lt;BR /&gt; NAME             PERSONA   ROLE       ACTIVE  REPLICATION&lt;BR /&gt; ---------------  -------   ---------- ------  ---------------&lt;BR /&gt; ...&lt;BR /&gt; &amp;lt;Node Hostname&amp;gt;  &lt;FONT color="#0000FF"&gt;&lt;FONT color="#000000"&gt;PAN       PRIMARY    NONE    &lt;/FONT&gt;&lt;U&gt;Not Applicable&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt; ...&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;You can also check that in the &lt;STRONG&gt;GUI&lt;/STRONG&gt; ... at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment &amp;gt;&lt;/STRONG&gt; mouse on the &lt;STRONG&gt;Node Status&lt;/STRONG&gt; bullseye:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;for &lt;STRONG&gt;PPAN&lt;/STRONG&gt;&amp;nbsp;(Publisher) ... &lt;STRONG&gt;Message Count&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="PPAN Deployment Status.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250989i610B0158B9B68ACC/image-size/large?v=v2&amp;amp;px=999" role="button" title="PPAN Deployment Status.png" alt="PPAN Deployment Status.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;for the &lt;STRONG&gt;Other Nodes&lt;/STRONG&gt;&amp;nbsp;(Subscribers) ... &lt;STRONG&gt;Sync Status&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="PMnT Deployment Status.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250990i324ADDB188DDDE31/image-size/large?v=v2&amp;amp;px=999" role="button" title="PMnT Deployment Status.png" alt="PMnT Deployment Status.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 17:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patching/m-p/5324591#M597968</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-08-26T17:50:12Z</dc:date>
    </item>
  </channel>
</rss>

