cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1487
Views
2
Helpful
14
Replies

Cisco ISE Patch

ja.aljaloud
Level 1
Level 1

Hallo everyone,

i am planning to patch cisco ise and i have this version 2.1.0.474. I searched to find Upgrade path but i did not find it.

Anyone can help me?!

 

 

Screenshot 2023-03-17 135506.png

14 Replies 14

balaji.bandi
Hall of Fame
Hall of Fame

2.1 EOL Long long back - i am sure TAC also not support any more.

Only TAC assists you here.

best is Move to Latest version 3.0  and Migrate your Servces.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

but i can move dirctly to version 3.0?

You can not move Directly to ISE 3.0

to reach ISE 3.0 you need to lot of Upgrade and and time consume ?

https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/upgrade_guide/HTML/b_upgrade_method_3_0.html

i would always suggest to directly install ISE 3.0 (depends on what hardware or VM you have).

Note : make sure you take the backup of ISE before you make any action.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

@ja.aljaloud Are using physical hardware, this will unlikely support ISE 3.x. You'd have to purchase new hardware or VM.

If using a Virtual Machine, as ISE 2.1 is so old you'd have to upgrade to an interim (2.6 patch 10 or above or 2.7 patch 4 and above) version before upgrading to 3.x

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217509-upgrade-ise-with-full-upgrade-method.html

 

i have one is running on physical Hardware and the other one is running on VM.

In this case you can build new VM with 3.0 and Migrate Services to VM Once that is working.

and do the re-image appliance is best option i can see.

Until you like to go Long sleepless nights to upgrade from 2.1 to 3.0

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

what do you mean with : and do the re-image appliance is best option i can see.

should we buy a new appliance?!

@ja.aljaloud you don't say what hardware you are running. As you are using ISE 2.1 I assume it's very old hardware. ISE 3.0 requires the 3500 or 3600 series, so if you are running the older hardware then you will need to purchase new hardware or use a VM.

https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/release_notes/b_ise_30_rn.html

 

i have this applince: SNS3415-K9

@ja.aljaloud Your 3415 will NOT run ISE 3.x, replace the hardware or use a VM with the correct specs.

ISE 3.0 requires 3500 or 3600 series hardware, as per the link previously provided.

RobIngram_0-1679062353507.png

ISE 3.2 requires the 3600 series hardware.

RobIngram_1-1679062494709.png

 

Re-image means fresh installation - as i look your appliance also EOL :

https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/eos-eol-notice-c51-737032.html

The only Option you have to build new VM or buy a new appliance which support latest verson of ISE 3.0 or more.

below guide explains hardware and VM requirement :

https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/install_guide/b_ise_InstallationGuide30/b_ise_InstallationGuide30_chapter_1.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

There is a Doku. how can i migrate Services from old VM to new VM?!

From what I can see, you can go from 2.1->2.6->3.1

As stated by others, your hardware will not be able to run it. Options are new hardware, or switch to VMs.

Now, what I would try to verify is this:

1) Backup current system.

2) Bring up a test ISE VM on version 2.6 and patch to last patch. (Bring up as small server, not eval)

3) restore backup, do not restore ad-os as it will take over name and IP.

4) Make new backup of 2.6 version.

5) Bring up test ISE VM of version 3.1 and patch. (Bring up as small server, not eval)

6) Load in the 2.6 backup and you should be able to verify if everything is correct.

VM has a 90 day trial license, so good to use for testing.

**3.x uses new licensing, so you would have to have any current licenses converted before you change.