10-28-2024 11:29 AM
HI
i have downloaded the the 3.3 upgrade bundle to our ISE Nodes, When I select the Sec PAN to be upgraded its stating 480 mins is this accerate, We are upgrading from 3. to 3.3
Also I have ran the purge from the gui fro data older than 30 days, Also is it possible to upgrade using cli now I have used the gui to download the bundle to the nodes? If so would upgrade using cli method be quicker ?
Thanks
10-28-2024 11:35 AM - edited 10-28-2024 11:40 AM
@benolyndav refer to the following Cisco guide - https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2024/pdf/BRKSEC-2889.pdf which provides a break down of the upgrade methods. CLI still takes a long time compared to the GUI upgrade, but is considered more complex and more work.
https://www.youtube.com/watch?v=D7poFnsd-8U&pp=ygULaXNlIHVwZ3JhZGU%3D
https://www.youtube.com/watch?v=q2JpC8oNssA&pp=ygULaXNlIHVwZ3JhZGU%3D
10-28-2024 11:44 AM
@Rob Ingram
Yes I have watced these and had forgot about the cli method being long, I am thinking the upgrade hasnt got a chance of being succesful due to the 4 hour upgrade process time limit, any thoughts please, is the 480 just an approx figure or is it accurate ?
Thanks
10-28-2024 11:52 AM
@benolyndav the last upgrade I performed (3.1 > 3.2) was quicker than the URT stated. How big is your database? What hardware are you using (physical or VM)?
What about using the Backup and Restore method?
Have you purged operational data, inactive endpoints and guest accounts?
10-28-2024 12:14 PM
VMs for hardware
M&T primary =47GB
M&T standby =39GB
We have 30000 inactive endpoints, I cant find how to purge these any idea please.?
Thanks
10-28-2024 12:27 PM
@benolyndav navigate to Administration > Identity Management > Settings > Endpoint Purge and create/modify the purge rule.
You can purge the operational data as below.
10-28-2024 12:37 PM
10-29-2024 02:42 AM
@Rob Ingram
In the maintenance tab what does( purge all data) do, I have purged data older than 20 days for now, Is it worth even attempting the upgrade if its stating estimate 480 mins for the PANS? could I expect the upgrades to be completed within the 4 hour threshold ??
10-29-2024 09:55 AM
Cisco ISE Monitoring Operational database contains information that is generated as Cisco ISE reports. Recent Cisco ISE (Cisco ISE Release 2.4 and above) releases have options to purge the monitoring operational data and reset the monitoring database when the application configure ise command is run.
This data can be purged as long as you don't not wish to run historical reports.
Can you re-run the URT after the data purge, what is the estimate now? The duration estimate is subject to environment specifics, 480 does seems excessive compared to the last upgrade I performed.
10-29-2024 10:14 AM
10-29-2024 10:16 AM
@benolyndav yes, ok to re-run the URT, just make sure no changes are being made nor backup taking place when the URT is run.
10-29-2024 11:10 AM
actually just noticed that urt says 2 hours less than gui, still seems to be lot of MnT?
Time estimate for upgrade
=========================
(Estimates are calculated based on size of config and mnt data only. Network latency between PAN and other nodes is not considered in calculating estimates)
Estimated time for each node (in mins):
MNT data is 58 GB, purging this data can reduce upgrade time
MAD-ISE-01(SECONDARY PAP,MNT):365
MNT data is 58 GB, purging this data can reduce upgrade time
CAM-ISE-01(PRIMARY PAP,MNT):360
MNT data is 58 GB, purging this data can reduce upgrade time
Each PSN(5 if in parallel):65
mnt.analytics.storage already exists in platform.properties
mnt.analytics.storage already exists in platform.properties-active
Final cleanup before exiting...
Application successfully installed
10-29-2024 11:42 AM
@benolyndav either purge more data to reduce upgrade time or use the backup/restore method.
10-30-2024 11:11 AM
@Rob Ingram
Do I need a different version of putty to ssh onto 3.3 i input credentials then the window opens and instantly shuts ??
10-30-2024 11:17 AM
@benolyndav I cannot say I've had a problem, I use the latest version of putty (0.81) without issue. Can you connect to the VM console of the node and confirm it is actually up?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide