10-21-2018 05:53 PM
Hello, I upgraded my ISE deployment to ISE 2.2 patch 11. I see that ISE 2.2 patch 11 has since been deferred.
What does Cisco recommend as the stable ISE 2.2 Patch release? Should we wait for Patch 12 or roll back to 9 or 10?
SEVT on Oct 7-13 recommended ISE 2.2 Patch 9. Just wondering if this is still the Cisco recommended patch release?
Thanks,
Solved! Go to Solution.
10-24-2018 10:18 AM
My TAC case on this issue reported it is planned to be fixed in the Patch 12 release.
10-22-2018 05:02 AM
In the very near future ISE 2.4 Patch 4 will be the recommended version of ISE.
I would expect this in the next couple weeks.
10-22-2018 05:12 AM
It's a fair question, and one that's becoming increasingly difficult to answer. I've shared some feedback with a few folks at Cisco regarding patches lately:
And now, patch 11 has been recalled. In my opinion, more rigor needs to be applied to patching. I'm very much a fan of Continuous Improvement, and rapid releases... but this methodology, when applied appropriately, should not introduce the number of flaws we've seen lately with these patches.
This often leaves us in a difficult position when TAC is advising us to patch ISE before further troubleshooting can occur, but the patch they would like us to move to will knowingly introduce additional issues.
10-22-2018 08:36 AM
10-22-2018 12:55 PM
We recently upgraded from patch 9 to 11. Everything was stable in 9. Under patch 11 we lost all authentication against AD. Under TAC advisement we rolled back to 10 on a few nodes which broke the application services, effectively killing our entire deployment. We have since rebuilt the broken nodes back to 11 but still do not have AD authentication working.
I would recommend holding on 9 until all of this gets sorted out...
10-22-2018 12:23 PM
If ISE 2.2 Patch 11 is working fine in your deployment, please keep it as it is for now. If you are planning to rollback, please engage Cisco TAC, due to CSCvm92278.
10-22-2018 01:44 PM
Thanks everyone for your comments. We are hitting bug CSCvm80261 on patch 11, not aware of anything else yet. Will remain on patch 11.
10-24-2018 09:37 AM
We're also running into CSCvm80261 on patch 10 on two of our regional deployments.
10-24-2018 10:18 AM
My TAC case on this issue reported it is planned to be fixed in the Patch 12 release.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide