cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
24615
Views
95
Helpful
38
Replies

ISE 2.7.0.356

Hello, 

Could someone please advise which version of ISE is not affected by the log4j vulnerability?

What is the workaround if any ?

 

Cheers, 

Gan

 

38 Replies 38

It took me 15 min for installation to complete.

For those who are experiencing issues, I highly advice to make sure that file hash match the one on Cisco download page. I had issues where downloaded file had discrepancy. I ended up downloading from alternative computer and file MD5 hash finally matched.

On Windows you can use following cmd to check file MD5 hash: certutil -hashfile c:\temp\ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz MD5 (of course file path is as per where you stored the file)

Linux command: md5sum ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz MD5

 

Hello Guys,

I am having trouble to install the patch. 

I get an error incorrect file format. I have tried to unzip and upload the tar file, i get the same error. 

I have open a tac case meanwhile. 

Hi @ganeshwaree.ramburruth ,

 use the following command:

ise/admin# application install ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz LOCAL

Note: LOCAL is the name of my repository that points to disk:

repository LOCAL
url disk:/

I always prefer to put the patch on the disk:

ise/admin# dir
Directory of disk:/
...
4747 Dec 16 2021 05:56:27 ise-apply-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz
3413 Dec 16 2021 05:57:46 ise-rollback-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz
...

 

It took 10 to 15 min in a LAB environment.

 

Hope this helps !!!

Hi,

 

in second try, it started the installation, but now it´s stuck in "restarting application" for a long long time.

With a second terminal, i checked the services and not all of them are running.

 

What should i do now? It seems that the patch is installed, but the script doesn´t finish properly:

Cisco_Patch.png

With these issues, i´m afraid of patching our active nodes...

 

Regards,

Dennis

Hi @DennisTX ,

 on another CLI, try the show application status ise and check if the Application Server is running or initializing.

 

Hope this helps !!!

Hi ganeshwaree.ramburruth,

I'm having the same problem, did Cisco TAC solved the issue, if yes, could you please share what was the solution?

 

Thanks in advance!

Kilib52

Hi,
Cisco TAC advised to apply the hot fix via cli instead via GUI.

fedor.solovev
Spotlight
Spotlight

Guys,
How long should it take ?
The application restart..

it should take around 15mins.