cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1680
Views
2
Helpful
6
Replies

Problems installing patches on ISE2.3

Axel Boersma
Level 1
Level 1

Hello,

I am currently running ISE 2.3 with Patch 1. Reason is I am unable to install patch 2 or 3 without breaking my portals.

All is working fine with Patch 1, but as soon as I install Patch 2 or 3 things break badly.

Sponsor Portal:

Unable to authenticate, usually I just need to create an new ID sequence and get things working again. Not this time , logging in reporting doesn't help identifying the problem.

Guest Portal:

After logging in with correct credentials it works with Patch 1, but after applying Patch2 or 3 I get the following message

[400] Bad Request The request is invalid due to malformed syntax or invalid data.

Mydevices portal:

After logging in with Employee credentials it works with Patch 1, but after applying Patch2 or 3 I get the following message

[400] Bad Request The request is invalid due to malformed syntax or invalid data.

etc etc etc.

Rollback back to patch 1 fixes everything.

Bit reluctant to upgrade to 2.4 if I can't even get to Patch 2 or 3 without issues.

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Please open a tac case to investigate why this is happening

View solution in original post

6 Replies 6

Jason Kunst
Cisco Employee
Cisco Employee

Please open a tac case to investigate why this is happening

Was hoping there was a quick fix, but guess not. Will open TAC case.

Sorry things like this need to be troubleshot and tracked appropriately so engineering can get to the bottom of it.

Call created with our supplier. Always good to know for sure, that it isn't something simple to fix.

Update, rollback from Patch3 to 1, things are still broken . Hopefully TAC can fix this.

Hi Alex

I had the same issue after installing patch 2.  To be honest, I had no idea it was introduced since patch 2, because the problem is intermittent.
I have opened a TAC case a few weeks ago and no word on that yet.

My own investigations revealed that sometimes a guest account is created and it's unusable and ISE thinks the account state is "disabled" - so far we were able to trace it back to accounts that  were created via CSV import (the entire batch of accounts was affected).

See if you can tail the prrt-server.log on the PSN and search for the fetchUser function call - example below shows a guest cwg10@wifi.com who got the 400 Bad Request, versus a healthy guest (arne@email.com)

Guest Accounts causing HTTP400 Bad Request - log comparison.png

Axel Boersma
Level 1
Level 1

An update after talking to TAC via an WebEx session.

For some reason the workaround for now is to recreate the used (that means new not duplicate) identity sequence and Sponsor/Guest/mydevice portals. Then it looks like it all works again. Will continue with TAC to figure out why. First need to proof recreating everything within ISE gives the correct results. Hope they find this bug so an next upgrade doesn't corrupts the portals again. Need to add the specific config and special tweaks one at the time so we may find the config options that triggers this problem.

-Update-

Did some further testing, If I duplicate the guest portal en create an new identity sequence the portal works. When I then replace the old Identity Seq on the original portal it works again no more 400 error. So seems to be an issue with the Identity Sequence in Cisco ISE 2.3.

No such luck with the sponsor portal as of this moment, will update if I find more.

Axel.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: