03-17-2019 07:56 PM - edited 02-21-2020 11:03 AM
Hello
I have a customer on a freshly built 2.4 patch 5 setup, who is about to go live and I was wondering whether I can subject them to 2.4 patch 6 - too soon?
Patch 6 has close to 300 bug fixes and that makes me a little bit nervous. But if anyone out there has applied it to customer networks then please let me know whether it's stable (and any issues you have found).
Our feature set is pretty basic: Wired MAB, Wired 802.1X and Wireless 802.1X
regards
Arne
Solved! Go to Solution.
03-21-2019 08:32 PM
Hi Arne,
We implemented patch 6 earlier this week and have not run into any problems. It also fixed a number of issues for us.
Tom
03-17-2019 10:24 PM
03-18-2019 06:53 AM
Hi Arne,
I installed it since one week.
Till now it is running fine. but some of the bugs were they say are fixed in patch6 are not!
like endpoint identity groups getting assigned to empty group.
03-18-2019 10:26 AM
I dont have any current deployments on p6 yet.
03-18-2019 01:13 PM
All my deployments are being migrated to patch 6 as it fixes some major issues like CoA on reprofile. No issues so far.
03-21-2019 08:32 PM
Hi Arne,
We implemented patch 6 earlier this week and have not run into any problems. It also fixed a number of issues for us.
Tom
03-22-2019 09:26 PM
I just did a bug scrub for a client interested in going to patch 6 and found 18 open public facing bugs. One of those is a concerning regression around profiling PC's behind phones when snmp polling profiler is enabled.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvk10674
A bunch are cosmetic or long standing nuisances, but a couple sev 2 and handful of sev 3's. Apic integration issues for aci/trustsec, and one talking about short portal url's breaking sponsor and my devices that is too vague to be any help.
03-23-2019 02:32 AM - edited 03-23-2019 02:34 AM
Hey @Damien Miller what’s the moral of the story? There’s never a good time to patch.
So far my customer is running ok on this patch. Just doing wired mab and 802.1x
i gave up on caring about release note years ago. It’s a game of Russian roulette.
03-23-2019 12:35 PM
Got a large enough lab to emulate the load, use cases and complexity of your production? If so, let it run there for a few weeks and run your system tests. If not then why risk breaking it if it isn't broken? Have you seen the number of bugs documented due to upgrading from version X to version Y?
I figure that since the lifecycle from one patch to the next is roughly a couple of months, there is no need to be in a constant state of testing in the lab, applying to production, and a few weeks later doing it all over again. Especially if you have enough systems to juggle.
Scheduling a system upgrade twice a year should be enough to have it properly tested and not having to constantly deal with patching.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide