08-14-2020 03:08 PM - edited 08-14-2020 07:24 PM
Hi Team,
I am trying to upgrade ISE from v2.4 to 2.7 currenlty and am stuck at an annoying part where I am unable to get upgrade bundle copied over from a Windows Server based SFTP repository to ISE local disk.
The port 22 communication is open and verified. The Host key add is successful when tried with the 'crypto host_key add host' command. But for some reason the repository doesn't get listed when I try 'show repository'. The error message that follows doesn't have much details to help with and I am not sure what is going wrong with it. Below is the error message I get:
% Error: Repository UpgradeJumpbox could not be accessed. In case Backup was Restored on different setup, Please reconfigure the repository passwords (expected behaviour).
When I then tried adding same repository via GUI, it gave me an error when I had C: in my path for C drive (/C:/FolderA/FolderB) which then made me question if it actually doesn't like Windows based SFTP server for any reason.
Any pointers by anyone on what can I do to get over the line with this and get started with my upgrade?
Solved! Go to Solution.
08-16-2020 06:06 PM
Thank you all for your inputs. I have moved it to a different server, and successfully transferred using FTP now.
08-14-2020 03:22 PM
Hope below thread help you :
make sure there no windows FW enabled, do you have any other blocker between SFTP and ISE ?
08-14-2020 03:56 PM
There are no firewalls between ISE and Windows SFTP server. Port 22 is open and tested from ISE.
If my upgrade bundle is under C:\temp\Cisco folder, what should my URL look like under the repository?
I have it as url sftp://IP address/C:/temp/Cisco
From that thread you shared, I am not sure if the bug listed in one of the replies is also impacting me by any chance:
https://quickview.cloudapps.cisco.com/quickview/bug/CSCum13116
My ISE nodes are currently on 2.4(0.357) which is shown as one of the Known affected releases under above bug advisory.
08-14-2020 04:07 PM - edited 08-14-2020 07:22 PM
Also, when I look at my SFTP server keys, it shows different value to what it does when I add the host key using 'crypto host_key add host' command under ISE CLI. I tried deleting this key and readd it but the same key shows up again as found added.
From ISE CLI:
host key fingerprint added
# Host 192.168.1.1 found: line 2
192.168.1.1 RSA SHA256:1Qci3ZCNyR75QhGDVXZeRGT+m/Kk1S5HC5tTd1hs5uU
Below is screenshot from SFTP server on Windows
08-14-2020 04:15 PM
08-14-2020 06:03 PM
08-14-2020 09:57 PM
08-15-2020 12:46 AM
what SFTP Server you are using, some of SFTP Server required permission to add IP address of ISE IP address to allow.
so please check that setting also to rule out.
08-16-2020 06:06 PM
Thank you all for your inputs. I have moved it to a different server, and successfully transferred using FTP now.
08-16-2020 11:57 PM
Glad all working at end, sometimes we need to look both the side issue.
so we mark as resolved.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide