Cisco ISE Patch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 05:57 AM
Hallo everyone,
i am planning to patch cisco ise and i have this version 2.1.0.474. I searched to find Upgrade path but i did not find it.
Anyone can help me?!
- Labels:
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:03 AM
2.1 EOL Long long back - i am sure TAC also not support any more.
Only TAC assists you here.
best is Move to Latest version 3.0 and Migrate your Servces.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:07 AM
but i can move dirctly to version 3.0?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:18 AM
You can not move Directly to ISE 3.0
to reach ISE 3.0 you need to lot of Upgrade and and time consume ?
https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/upgrade_guide/HTML/b_upgrade_method_3_0.html
i would always suggest to directly install ISE 3.0 (depends on what hardware or VM you have).
Note : make sure you take the backup of ISE before you make any action.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:14 AM
@ja.aljaloud Are using physical hardware, this will unlikely support ISE 3.x. You'd have to purchase new hardware or VM.
If using a Virtual Machine, as ISE 2.1 is so old you'd have to upgrade to an interim (2.6 patch 10 or above or 2.7 patch 4 and above) version before upgrading to 3.x
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:25 AM
i have one is running on physical Hardware and the other one is running on VM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:38 AM
In this case you can build new VM with 3.0 and Migrate Services to VM Once that is working.
and do the re-image appliance is best option i can see.
Until you like to go Long sleepless nights to upgrade from 2.1 to 3.0
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:40 AM
what do you mean with : and do the re-image appliance is best option i can see.
should we buy a new appliance?!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:44 AM - edited 03-17-2023 06:44 AM
@ja.aljaloud you don't say what hardware you are running. As you are using ISE 2.1 I assume it's very old hardware. ISE 3.0 requires the 3500 or 3600 series, so if you are running the older hardware then you will need to purchase new hardware or use a VM.
https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/release_notes/b_ise_30_rn.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 07:08 AM
i have this applince: SNS3415-K9
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 07:13 AM - edited 03-17-2023 07:16 AM
@ja.aljaloud Your 3415 will NOT run ISE 3.x, replace the hardware or use a VM with the correct specs.
ISE 3.0 requires 3500 or 3600 series hardware, as per the link previously provided.
ISE 3.2 requires the 3600 series hardware.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 11:16 AM
Re-image means fresh installation - as i look your appliance also EOL :
The only Option you have to build new VM or buy a new appliance which support latest verson of ISE 3.0 or more.
below guide explains hardware and VM requirement :
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 06:54 AM
There is a Doku. how can i migrate Services from old VM to new VM?!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 08:43 AM
From what I can see, you can go from 2.1->2.6->3.1
As stated by others, your hardware will not be able to run it. Options are new hardware, or switch to VMs.
Now, what I would try to verify is this:
1) Backup current system.
2) Bring up a test ISE VM on version 2.6 and patch to last patch. (Bring up as small server, not eval)
3) restore backup, do not restore ad-os as it will take over name and IP.
4) Make new backup of 2.6 version.
5) Bring up test ISE VM of version 3.1 and patch. (Bring up as small server, not eval)
6) Load in the 2.6 backup and you should be able to verify if everything is correct.
VM has a 90 day trial license, so good to use for testing.
**3.x uses new licensing, so you would have to have any current licenses converted before you change.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2023 10:31 AM
