11-14-2019 08:12 AM
Hello all,
We have a scenario where we have to upgrade from ISE 2.4 Patch 6 to Patch 9 in a distributed deployment
We have
one Primary admin node,
one secondary admin,
one primary monitoring node, one secondary monitoring node,
and 8 PSN's.
What would be the recommended sequence if we try to upgrade all the patch through CLI?
Thanks,
Nikhil
Solved! Go to Solution.
11-14-2019 09:12 AM
11-14-2019 11:12 AM
11-14-2019 08:27 AM
Hi @Nikhil Jadhav ,
Firstly, why patch 9? Why not patch 10? It would be even better and more stable.
There is no such "path" you have to take for patching ISE. I am curious to know why you aren't doing the patch from the GUI.
You can start from the PAN, SAN, MnT nodes and PSNs. However, if you wish to do testing at certain points, you should update PAN, 1-2 PSNs, then test the authentication and Admin node things like backup, configuration, etc. Once you feel confident, you can apply the patch to the rest of the nodes.
11-14-2019 08:58 AM
Hello Anurag,
Thank you for responding.
I appreciate your advice but this environment is also going to be used for SDA and ISE 2.4 Patch 10 is not yet validated by SDA BU that's why we are going with patch 9. Since I need to test authentication in between so I am thinking to proceed with the CLI approach. So just to confirm I will be upgrading Primary PAN first and then one of the PSN, test the authentication and if received expected result then upgrade the rest ISE nodes.
Waiting for your confirmation.
Nikhil
11-14-2019 11:12 AM
11-14-2019 09:12 AM
07-13-2023 06:35 AM
Hi All,
I have a similar deployment of 16 nodes( 2 Admin, 2 MNT and 12 PSNs). I am doing patch upgrade of ISE3.1p5 to p6 via CLI so that we can control the order. Just have a query if we need to de-register the node from deployment before proceeding with patch install.
If we dont de-register and directly perform patch install, will the node with patch6 be able to join back the remaining deployment still running on patch 5?
07-13-2023 07:05 AM
Resurrecting a 2-year old + thread that has an accepted solution limits the number of people that will take a look at it. The best thing to do is to start a new thread.
No, you don't need to De-Register nodes to install a patch.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide