05-26-2026 10:52 AM
I am currently running Cisco ISE cluster 3.3 patch-7, and we mainly use it for 802.1x wired, wireless, and MAB. We also integrate Cisco ISE with Microsoft Active Directory (AD), and that's about it. We're currently running it on VM ESXi.
We're reducing the footprint by getting rid of the Data Center, and purchase two Cisco SNS-3815. I am thinking of using ISE 3.4 patch-5. My migration is this:
1- build two brand new SNS 3815 with 3.4,
2- patch them to patch-5,
3- restore the backup configuration of the 3.3 patch-7 to one of the 3.4 patch-5 nodes,
4- Add them into Active Directory,
5- Sync the two 3.4 patch-5 nodes,
6- Validation and testing,
Are there any issues or gotchas that I should be aware of in version 3.4 patch-5?
TIA
05-26-2026 03:46 PM
It's hard to say if a certain release is so fundamentally broken that it won't handle your use case. I don't think there are any major show stoppers in that release. I eventually moved off 3.4 and onto 3.5 because I had issues with incomplete Context Visibility - less than half of the Endpoint attributes were visible. After upgrade to 3.5, all good again. But it could also have been due to the history and upgrade path of that platform.
The only way to know for sure is to test. If you have no time to test, then you go with your gut feel and then keep a very close eye on the post upgraded system. Some little bugs I can live with. ISE 3.5 so far seems good.
05-26-2026 06:55 PM
steps looks fine but just make sure you back up the certificates as well
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide