08-13-2025 10:31 PM
Hi everyone!
Good day and greetings!
Does anyone here upgraded your ISE devices to 3.4 Patch 3? Did you guys encountered any issues and bugs?
Regards
08-14-2025 12:33 AM
The upgrade went smoothly for my lab deployment and I have not encountered any new bugs. If your production deployment already is on 3.4 I would probably upgrade, otherwise I would wait for it to become recommended.
08-14-2025 01:10 PM
I'm in the same situation as @Torbjørn - I patch my lab to see the outcome but I have not been testing a lot lately. Seems ok, apart from the lack of ansible support in ISE 3.4 - but that's an issue for people who use ansible to manage their ISE environments - I hope I am wrong, but it seems Cisco BU has abandoned the ansible ise collection, and it will be dropped from the next ansible release (v12). Really unfortunate, because I was just starting to make some inroads with this stuff.
08-14-2025 11:07 PM
It does seem that you're right. There hasn't been any updates to the git repo since January and I found the following PR under ansible community: https://github.com/ansible-community/ansible-build-data/pull/560. That's a real problem...
08-14-2025 11:54 PM
Hello Everyone, Ansible collection support is not a big issue. You can still use REST APIs of ISE in Ansible. This is the way we have been using it and it is not dependent on anyone to maintain ISE collection in Ansible. Rest someone from Cisco Devnet can comment if there is any plan to resume maintenance on collection.
08-15-2025 01:38 PM
@PSM - the value of a tool such as ansible, lies in creation and usage of modules - popularised in the Linux world and then found its way into other parts of IT. Cisco started out with the ise collection and the 445 modules they provide make life easier for someone wanting to automate their ISE deployment - that's the whole point of this, isn't it? . Anyone can run a curl, postman, python REST API call to ISE - I don't feel like using ansible to craft my own API calls to ISE.
I wasn't trying to say that we should not upgrade to ISE 3.4 because of this ansible saga - I just wished someone from the BU would respond and tell us what's going on.
08-16-2025 04:47 AM
@Arne Bier agree with you "the value of a tool such as ansible, lies in creation and usage of modules". Most of the automation which we use ansible is against NAD devices and then related tasks against ISE. For us it has been working quit ok. But off course modules are nicer and efficient.
10-06-2025 09:39 PM
Hi everyone!
Having issue with upgrading from 3.4 patch2 to 3.4 patch 3.
Two-node deployment
Upgrade via GUI – Upgrade & Rollback method.
Secondary node was not deregistered before upgrade.
Prerequisite checks passed, but upgrade failed.
CLI shows Patch 2 on both nodes, but
GUI says “Patch Install/Rollback in progress on nodes with new patch framework…”
No clear upgrade report available.
Any suggestion?
10-06-2025 10:14 PM
Applying a patch is not the same as upgrading. You're talking about applying patch 3 on your patch 2 deployment. There will be no node de-registrations.
I upgraded 3.3p7 to 3.4p3 recently and the upgrade was smooth - but after promoting the SPAN to PPAN, and both PANs were online again, all my nodes were shown as out of sync. I had to manually sync all of them - that's not what I had expected should happen after a promotion. And there is also a CRL download failure since the upgrade, and some object sync failures from time to time - the platform is working well - but I have a TAC case open to investigate the CRL and sync Alarms.
10-07-2025 12:07 PM
Hi @Arne Bier ,
about "CRL Download Failure" ... this interests me ... : )
you are talking about the "Alarm: CRL Retrieval Failed" with the description "Could not download Certificate Revocation List for certificate with ... " ?
If the answer is Yes:
Best regards !
10-07-2025 01:28 PM
Thanks for the comment - Yes I have been bypassing the CA's FQDN in the ISE Proxy Settings for a long time. The CA's FQDN is still in the ISE Proxy config.
The Event Description is "Failed performing HTTP GET with error: (28) Timeout was reached"
I tried to capture one of these in a tcpdump and I saw no traffic on port 80.
I think you're onto something - a bug that is causing the CRL download to go via the proxy (hence, why I can't see it in the tcpdump). I will toggle this and see if I can re-program the settings.
10-07-2025 02:25 PM
Hi @Arne Bier ,
yes, I'm having "a hard time" understanding what's causing some CRL Download issues.
Note: I have the same issue when capturing a tcpdump.
10-07-2025 11:51 AM - edited 10-07-2025 12:08 PM
Hi,
I'd like to give "my 2 cents" to the original question: "Did you guys encountered any issues and bugs ?"
The upgrade from ISE 3.3 P7 to ISE 3.4 P3 was smooth, but ISE 3.4 P3 failed to "understand" SNS 38xx, and not only in CLI but also in GUI it shows as SNS 37xx.
A TAC has been opened and ISE 3.4 P4 will probably solve this issue.
Hope this helps !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide