03-01-2025 09:10 PM
Hi everyone,
I used the following command to install ISE version 3.3.0 and it failed with the following error:
application install ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz ise < "repo name"
2025-03-02T04:00:39.057764+00:00 CARSSetup[4345]: ADEAUDIT 2021, type= APP INSTALL, name=APP INSTALL START, username=system, cause=Application install has been inititated, adminipaddress=127.0.0.1, interface=CLI, detail=Application Install initiated with bundle - ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz, repo - ise
2025-03-02T04:00:39.055728+00:00 ADE-SERVICE[1304]: [4345]:[info] user: cars_install.c[5514] [system]: Illegal characters or double dots not found in name ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz
2025-03-02T04:00:39.057641+00:00 ADE-SERVICE[1304]: [4345]:[info] application:install cars_install.c[2405] [system]: Install initiated with bundle - ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz, repo - ise
2025-03-02T04:00:39.074941+00:00 ADE-SERVICE[1304]: [4345]:[info] transfer: cars_xfer.c[170] [system]: local copy in of ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz requested
2025-03-02T04:02:03.173125+00:00 ADE-SERVICE[1304]: [4345]:[info] application:install cars_install.c[2637] [system]: Got bundle at - /storeddata/Installing/.1740888039/ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz
2025-03-02T04:02:03.214944+00:00 ADE-SERVICE[1304]: [4345]:[info] application:install cars_install.c[2710] [system]: Unbundling package ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz
2025-03-02T04:03:12.345000+00:00 ADE-SERVICE[1304]: [4345]:[info] application:install cars_install.c[2812] [system]: Verifying signature for package ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz
2025-03-02T04:03:54.406287+00:00 ADE-SERVICE[1304]: [4345]:[info] application:install cars_install.c[2836] [system]: Signed bundle /storeddata/Installing/.1740888039/ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz confirmed with release key
2025-03-02T04:04:48.148827+00:00 ADE-SERVICE[1304]: [4345]:[error] application:install cars_install.c[5897] [system]: Error while Installing - Application bundle: ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz Repository: ise ErrorCode: -640
Any idea? Per this line, "2025-03-02T04:03:54.406287+00:00 ADE-SERVICE[1304]: [4345]:[info] application:install cars_install.c[2836] [system]: Signed bundle /storeddata/Installing/.1740888039/ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz confirmed with release key" file integrity looks good.
Solved! Go to Solution.
03-04-2025 08:26 AM
Thanks. I opened a case with TAC and here it is their solution:
"
Currently, the AWS Marketplace only publishes certain ISE versions (for example, 3.4, 3.3, 3.2, 3.1 p1). ISE does not support a traditional “downgrade” from 3.4 to 3.3. This means the best way to get ISE 3.3 on AWS is to build a fresh instance running ISE 3.3.
In practice, this can be achieved in the following way:
Go to View Purchase options in AMI, click on continue to configure and select version 3.3. Because you have already deployed 3.4 in AWS and removed the ISE application, you would still need to redeploy a fresh ISE 3.3 instance."
03-02-2025 12:11 AM
- Check if this is relevant for you : https://community.cisco.com/t5/network-access-control/ise-urt-installation-error/m-p/4906301/highlight/true#M583464
M.
03-02-2025 07:05 PM
Thank you for your response. That was not related to my case, mine is a standalone/new installation.
03-02-2025 11:03 PM
- Verify the md5sum of ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz anyway,
(despite ...>/ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz confirmed with release key" file integrity looks good.)
M.
03-03-2025 12:42 AM
I tried, but there is no "verify" command available! These are all available commands!
Possible completions:
application Application Install and Administration
backup Backup system
backup-logs Backup system and application logs
clear Reset functions
clock Set the System Clock
configure cfg
copy Enter URL (use disk:/path/file for local) (Max Size - 2048)
crypto Crypto operations
debug Debugging functions (see also 'undebug')
delete Delete a file
dir List files on local filesystem
exit Exit the management session
forceout Force Logout all the sessions of a specific system user
generate-password Username for which password has to be generated
halt Shutdown the system
idle-timeout Idle timeout for all the sessions of a specific system user
mkdir Create new directory
nslookup DNS lookup for an IP address or hostname
password Update Password
patch Install System or Application Patch
permit List cli for Secure Tunnel
ping Ping a remote ip address
ping6 Ping a remote ipv6 address
reload Reload the system
reset-config Reset network and time settings
restore Restore system
rmdir Remove existing directory
screen-length Configure screen length
screen-width Configure screen width
show Show information about the system
ssh SSH to a remote ip address
tech TAC commands
terminal Set terminal line parameters
traceroute Trace the route to a remote ip address
undebug Disable debugging functions (see also 'debug')
who Display currently logged on users
I have already removed the ISE version 3.4, and I Am trying to downgrade to version 3.3. By the way, it is an AMI on AWS.
03-03-2025 01:16 AM
- You can also verify the file on your 'download platform' first (where you downloaded it) ; before the install attempt was made on ISE ,
M.
03-03-2025 02:19 AM
(Added) - Ref : https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/upgrade_guide/Upgrade_Journey/PDF/b_ise_upgrade_guide_3_3_pdf.pdf
>...Upgrade a Standalone Node
You can use the application upgrade <upgrade bundle name> <repository name> command directly, or
the application upgrade prepare <upgrade bundle name> <repository name> and application upgrade
proceed commands in the specified sequence to upgrade a standalone node.
- Could you try the methodology highlighted in green and check if that can help ?
M.
03-03-2025 09:01 AM
Instalation was failed here what I have got, I tried both the iso and tar.gz file format:
application upgrade prepare ise-upgradebundle-3.0.x-3.2.x-to-3.3.0.430b.SPA.x86_64.tar.gz ise
Be sure that all your software is working stable, check your system on UI page (Administration > System > Health Checks)
Type yes once confirmed that health of the system is good to proceed: (yes/no) [yes] ? yes
Be sure that all your software is working stable, check your system on UI page (Administration > System > Health Checks)
Getting bundle to local machine...
Unbundling Application Package...
Verifying Application Signature..
% Application not installed, please use install option
Application upgrade preparation Failed
====================================================================================
application upgrade prepare Cisco-ISE-3.3.0.430.SPA.x86_64.iso ise
Be sure that all your software is working stable, check your system on UI page (Administration > System > Health Checks)
Type yes once confirmed that health of the system is good to proceed: (yes/no) [yes] ? yes
Be sure that all your software is working stable, check your system on UI page (Administration > System > Health Checks)
Getting bundle to local machine...
Unbundling Application Package...
% Unable to unbundle the package. It should be in tar.gz file format
Application upgrade preparation Failed
03-03-2025 09:55 AM
- @Masoud ha : Check output from show logging system ade/ADE.log after it failed
It won't work with the ISO ;
If nothing useful can be found from examining ADE.log ; then I advice to contact TAC
M.
03-03-2025 10:48 AM
Thanks, the same message on the logs. I'll open a case with TAC.
03-03-2025 11:21 AM
- Ok , one last thing to verify too: check if all partitions on the ise node have sufficient free disk space ,
M.
03-03-2025 11:30 AM
Looks good:
show disks
disks
Internal filesystems:
Filesystem Size Used Avail Use% Mounted on
devtmpfs 16G 0 16G 0% /dev
tmpfs 16G 0 16G 0% /dev/shm
tmpfs 16G 512K 16G 1% /run
tmpfs 16G 0 16G 0% /sys/fs/cgroup
/dev/nvme0n1p2 30G 11G 18G 39% /
tmpfs 1.0G 5.6M 1019M 1% /var/lib/sss/db
/dev/nvme0n1p6 1.9G 84K 1.8G 1% /tmp
/dev/nvme0n1p3 92M 44K 85M 1% /storedconfig
/dev/nvme0n1p7 550G 64G 461G 13% /opt
/dev/nvme0n1p1 966M 115M 786M 13% /boot
tmpfs 3.1G 0 3.1G 0% /run/user/0
tmpfs 3.1G 0 3.1G 0% /run/user/440
all internal filesystems have sufficient free space
03-04-2025 02:55 AM
- Another thing you could download and or look into from : https://software.cisco.com/download/home/283801620/type/283802505/release/3.3.0
is the : Upgrade Readiness Tool (URT)
Maybe it can provide insights,
M.
03-04-2025 08:26 AM
Thanks. I opened a case with TAC and here it is their solution:
"
Currently, the AWS Marketplace only publishes certain ISE versions (for example, 3.4, 3.3, 3.2, 3.1 p1). ISE does not support a traditional “downgrade” from 3.4 to 3.3. This means the best way to get ISE 3.3 on AWS is to build a fresh instance running ISE 3.3.
In practice, this can be achieved in the following way:
Go to View Purchase options in AMI, click on continue to configure and select version 3.3. Because you have already deployed 3.4 in AWS and removed the ISE application, you would still need to redeploy a fresh ISE 3.3 instance."
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide