cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3008
Views
25
Helpful
8
Replies

ISE 2.4 patch 6 feedback anyone?

Arne Bier
VIP
VIP

Hello

 

I have a customer on a freshly built 2.4 patch 5 setup, who is about to go live and I was wondering whether I can subject them to 2.4 patch 6 - too soon? 

 

Patch 6 has close to 300 bug fixes and that makes me a little bit nervous.  But if anyone out there has applied it to customer networks then please let me know whether it's stable (and any issues you have found).

 

Our feature set is pretty basic: Wired MAB, Wired 802.1X and Wireless 802.1X

 

regards

Arne

1 Accepted Solution

Accepted Solutions

Thomas Carmichael
Frequent Visitor
Frequent Visitor

Hi Arne, 

 

We implemented patch 6 earlier this week and have not run into any problems. It also fixed a number of issues for us. 

 

Tom

 

 

View solution in original post

8 Replies 8

Francesco Molino
VIP Alumni
VIP Alumni
Hi

I'm running it at 1 customer with an ISE cluster of 12 nodes and using all basic+ few advanced features.
Migrated few days ago and up to now, no issues or concerns on this patch.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi Arne,

 

I installed it since one week.

 

Till now it is running fine. but some of the bugs were they say are fixed in patch6 are not!

like endpoint identity groups getting assigned to empty group.

 

 

Damien Miller
VIP Alumni
VIP Alumni

I dont have any current deployments on p6 yet. 

All my deployments are being migrated to patch 6 as it fixes some major issues like CoA on reprofile.  No issues so far.

Thomas Carmichael
Frequent Visitor
Frequent Visitor

Hi Arne, 

 

We implemented patch 6 earlier this week and have not run into any problems. It also fixed a number of issues for us. 

 

Tom

 

 

Damien Miller
VIP Alumni
VIP Alumni

I just did a bug scrub for a client interested in going to patch 6 and found 18 open public facing bugs.  One of those is a concerning regression around profiling PC's behind phones when snmp polling profiler is enabled.  

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvk10674

 

A bunch are cosmetic or long standing nuisances, but a couple sev 2 and handful of sev 3's. Apic integration issues for aci/trustsec, and one talking about short portal url's breaking sponsor and my devices that is too vague to be any help.  

Hey @Damien Miller  what’s the moral of the story? There’s never a good time to patch. 

So far my customer is running ok on this patch. Just doing wired mab and 802.1x

 

i gave up on caring about release note years ago. It’s a game of Russian roulette. 

Got a large enough lab to emulate the load, use cases and complexity of your production? If so, let it run there for a few weeks and run your system tests. If not then why risk breaking it if it isn't broken? Have you seen the number of bugs documented due to upgrading from version X to version Y?

 

I figure that since the lifecycle from one patch to the next is roughly a couple of months, there is no need to be in a constant state of testing in the lab, applying to production, and a few weeks later doing it all over again. Especially if you have enough systems to juggle.

 

Scheduling a system upgrade twice a year should be enough to have it properly tested and not having to constantly deal with patching.