cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
608
Views
1
Helpful
2
Replies

ISE upgrade to 3.1 version from 2.7

Gouthami Nair
Level 1
Level 1

Hi All,

We are upgrading our Cisco ISE deployment from 2.7 version to 3.1 version. Whether the nodes will rejoin if we are doing the upgrade without breaking the cluster and doing the upgrade through CLI?

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

If all goes well the nodes will still be joined when the upgrade is completed and done via the CLI, same as running the standard upgrade through the GUI. 

You will upgrade the secondary admin node first, it will deregister itself from the primary and become the new primary in the 3.1 deployment. You will then upgrade any other PSN/MNT/PXgrid nodes in the order you wish, these will automatically register with the new 3.1 admin node. The last node you upgrade will be the old primary admin node (still running 2.7), and it will also register and join the 3.1 primary admin node. 

When you're done upgrading you can swap back the primary admin role to the original primary node. 

Helpful tip, you might see queue link alarms in the dashboard during the upgrade in 3+ node deployments, you can disable the ISE messaging service before the upgrade, correct the root certificate chain + ISE messaging service certificates after the upgrade, then reenable the ISE messaging service. 

View solution in original post

2 Replies 2

Hi @Gouthami Nair 

 please take a look at: Cisco ISE 3.1 Upgrade Guide: Upgrade Method., search for Upgrade a Cisco ISE Deployment from the CLI and check your Deployment Type (Standalone, Two-Node or Distributed).

Hope this helps !!!

Damien Miller
VIP Alumni
VIP Alumni

If all goes well the nodes will still be joined when the upgrade is completed and done via the CLI, same as running the standard upgrade through the GUI. 

You will upgrade the secondary admin node first, it will deregister itself from the primary and become the new primary in the 3.1 deployment. You will then upgrade any other PSN/MNT/PXgrid nodes in the order you wish, these will automatically register with the new 3.1 admin node. The last node you upgrade will be the old primary admin node (still running 2.7), and it will also register and join the 3.1 primary admin node. 

When you're done upgrading you can swap back the primary admin role to the original primary node. 

Helpful tip, you might see queue link alarms in the dashboard during the upgrade in 3+ node deployments, you can disable the ISE messaging service before the upgrade, correct the root certificate chain + ISE messaging service certificates after the upgrade, then reenable the ISE messaging service.