09-09-2025 05:10 AM
Solved! Go to Solution.
09-09-2025 07:36 AM
Hello @Dustin Anderson .. thank you for your advice.
I also wanted to propose a new IP address for the new VM, but I have heard of problems with IP change in the past, so wanted to avoid this. Now looking at it again, it seems for standalone, it might be alright.
I will readjust, basically:
Thanks again
Aaron
09-09-2025 10:45 AM
That should work, on a side note I don't believe 3.x loads the certs in anymore with the backup, so plan to export the certs for admin etc to load into the new VM to save yourself some headache.
09-09-2025 06:47 AM - edited 09-09-2025 06:49 AM
Take this as my opinion.
What you are suggesting seems to be adding time to maintenance, not reducing. I feel you are thinking upgrading is done at the same time, but is will update one node at a time unless you specify to do both in tandem. So with this you added creating a new VM and taking the appliance IP, so you loose redundancy. Once the VM is up but without config it will basically reject any auth sent to it until you restore the config.
Now, I know Cisco has got better on upgrades, they use to fail about 50% or so in 2.x so we mostly did reformat upgrades. So depending on how many upgrades the client has already done on these, I would look at this.
1 Deploy a VM on 3.4 and apply current patch. Do this on a 3rd IP to keep the redundancy in tact.
2 Restore backup to VM. I have not tried a 4 version update so this you would have to test if it imports correctly. If so this will give you the cleanest install. Otherwise you would need to deploy the lower version and upgrade.
3 assuming it all tests, replace the old VM with the new one and change the IP. As 3615 is small and EoL, I'm going to suggest that not be primary.
4 With the new VM functioning and tested, take the 3615 and reimage to 3.4, apply patch and rejoin the primary.
Just my 2 cents.
09-09-2025 07:36 AM
Hello @Dustin Anderson .. thank you for your advice.
I also wanted to propose a new IP address for the new VM, but I have heard of problems with IP change in the past, so wanted to avoid this. Now looking at it again, it seems for standalone, it might be alright.
I will readjust, basically:
Thanks again
Aaron
09-09-2025 10:45 AM
That should work, on a side note I don't believe 3.x loads the certs in anymore with the backup, so plan to export the certs for admin etc to load into the new VM to save yourself some headache.
09-09-2025 07:30 AM
the approach looks nice, but look at ISE 3.0 to 3.4 you need pass some path
Also add all the patches before you putting production.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide