cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1868
Views
11
Helpful
2
Replies

Patch difference in deployment mode - Cisco ISE

JoseAlanis07669
Level 1
Level 1

Hello!
Does anyone know what Cisco's recommendations are about having different patches on my deployment.

My deployment has patch 3 of version 2.x but I am looking to upgrade only one node to patch 6 by CLI.

Will there be any compatibility issues between the rest of the nodes with patch 3 and the node with patch 6?

 

Thanks and have a nice day!

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

I've run in to some odd issues when I had a customer stop patching a deployment overnight. I would try to get all nodes on the same patch as quickly as possible starting with the primary admin node. 

The CLI won't prevent you from doing a single node, but no one will recommend leaving it in this state or applying it to any node but the PAN first. In a distributed deployment I will usually patch a PSN second after the PAN to test/validate/pause. Then once confirmed things are still working with that node we finish up the patching work. 

View solution in original post

2 Replies 2

@JoseAlanis07669 no, you should run the same patch version across all nodes in your ISE cluster. I doubt Cisco even supports running different patches on the ISE nodes.

Damien Miller
VIP Alumni
VIP Alumni

I've run in to some odd issues when I had a customer stop patching a deployment overnight. I would try to get all nodes on the same patch as quickly as possible starting with the primary admin node. 

The CLI won't prevent you from doing a single node, but no one will recommend leaving it in this state or applying it to any node but the PAN first. In a distributed deployment I will usually patch a PSN second after the PAN to test/validate/pause. Then once confirmed things are still working with that node we finish up the patching work.