01-22-2024
06:41 AM
- last edited on
01-22-2024
08:39 AM
by
shaiksh
Dear Community,
Current we are using AnyConnect agent version 4.x with Compliance Module 4.3.17XX
We plan to upgrade to new Compliance Module 4.3.33XX though SCCM server.
Please kindly provide good practice to achieve this goal with no impact.
Appreciated for your advise and commend.
Thanks,
01-22-2024 09:56 AM
Deploy from ISE via Client Provisioning Portal/Policy, not SCCM.
01-22-2024 06:40 PM
Are the any impact or ISE high load performance or not if we perform via ISE Client Provisioning Policy?
We have around 6K endpoints.
thanks,
01-23-2024 04:51 AM
None that I can think of. What size deployment?
01-23-2024 05:53 PM
Dear @ahollifield ,
There are three deployment nodes ( PAN, Secondary, and pxGRID ).
01-24-2024 04:21 AM
01-28-2024 06:16 PM
Dear @ahollifield
It is medium deployment.
01-29-2024 02:12 AM - edited 01-29-2024 02:13 AM
In medium-sized deployment the recommendation as of ISE 3.0+ would be having 2x nodes for the Admin, MnT, and pxGrid and separate the PSNs. You can have up to 6x PSNs in the medium deployment. More details in the link shared by @ahollifield.
01-23-2024 01:46 AM
I think you can upgrade the endpoints via SCCM, however, upgrading through ISE wouldn't cause any issue. If you upgrade via SCCM you would still need to upload the interested posture agent version to ISE because the endpoints would always do a check on the agent version installed locally on the endpoints and the one on ISE.
01-23-2024 05:55 PM
Dear @Aref Alsouqi ,
Could you share the document support and how to achieve it? thanks,
01-24-2024 01:09 AM
I found this link that might help:
Cisco Identity Services Engine:Provisioning AnyConnect for ISE Posture (lookingpoint.com)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide