06-05-2025 02:37 AM - edited 06-05-2025 02:38 AM
So we had an ISE which fell over after I've rebuilt our ISE with base software image (3.1.518), ready for deploying it back onto the network with the other appliance in a HA pair.
I've already raised this with Cisco TAC, but just wondering if someone experienced here can tell me where I have gone wrong?
We've got a pair of SNS-3615-K9's running ISE software version 3.1.0. One is in DC1, the other is in DC2.
Someone else in the team was tasked with upgrading the patch version of both units in the pair from 3.1.0.518-Patch7 to Patch 10.
It was previously decided to do this upgrade one unit at a time. I wasn't originally involved.
After upgrading the first unit (DC1), the GUI of that unit would no longer run, and looking at the Application Server status it was 'Not Running', and it would not come up even after waiting for some time (2 hours). Reloading failed to bring this back up. Luckily the other unit in the deployment was fine, and we were able to promote it to be the primary PAN.
He's now gone away and I am now tasked with fixing it.
I've rebuilt the failed ISE unit (DC1) with base software image (3.1.518) and then added Patch 7 as it was previously on, same as the other working DC2 unit, ready for re-deploying it back into the pair with the other DC2 unit.
To bring the rebuilt unit back into the deployment I followed these steps on the current active PAN (DC2):
So in summary, I've fixed the DC1 unit that was not working. This is working fine now. But the DC2 unit is now broken after failing over/promoting the newly build DC1 unit. I don't understand why.
I've already raised this with Cisco TAC, but just wondering if someone experienced here can tell me where I have gone wrong?
06-05-2025 09:31 AM
I have rebuilt a bunch of nodes and maybe its a good idea to rebuild your node in DC2 if its down. At least that will clear up any stale data. The issue could of been some corruption when the deployment was patched, but that would be an assumption. Since your ISE in DC1 is now up and functioning, it would be worth it for me to factory reset ISE in DC2 and add that back into the deployment. I'm also assuming that if you run a test to the ISE node in DC2, things are failing?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide