Ask the Experts: ISE Upgrade

Date: December 8, 2023

Disclaimer

This document is Cisco Confidential information provided for your internal business use in connection with the Cisco Services purchased by you or your authorized reseller on your behalf. This document contains guidance based on Cisco's recommended practices.

You remain responsible for determining whether to employ this guidance, whether it fits your network design, business needs, and whether the guidance complies with laws, including any regulatory, security, or privacy requirements applicable to your business.

免責: この文書は、お客様またはお客様の代理人である認定リセラーが購入したシスコサービスに関連して、お客様が社内業務において使用することを目的としてシスコが提供するシスコの機密情報です。この文書にはシスコが推奨するプラクティスに基づく手引きが記載されています。

お客様は、この手引きを使用するか否かやお客様のネットワーク設計および業務上のニーズにこの手引きが適合しているか否か、さらにはこの手引きが法律(お客様の業務に適用される規制上の要件、セキュリティ上の要件およびプライバシーに関する要件を含みます)に準拠しているか否かを判断する責任を引き続き負います。

Today's Topics

  1. Reasons to Upgrade
  2. Planning and Preparation
  3. Upgrade Execution
  4. Post-Upgrade Tasks

Reasons to Upgrade

This section details the benefits and motivations for upgrading Cisco ISE.

ISE 3.2 Release Highlights (Cisco Recommended - Golden Star Release)

The document also displays a dashboard with metrics such as Total Endpoints, Authentications, and Alarms, along with a breakdown of endpoint types and locations.

ISE Release Cycle (Before ISE 2.7)

Short-Term Releases (2-Year, Odd Versions)

This section illustrates the lifecycle of short-term ISE releases, indicating release dates, End-of-Life (EOL) notifications, and end-of-support timelines.

Long-Term Releases (4-Year, Even Versions)

This section illustrates the lifecycle of long-term ISE releases, indicating release dates, End-of-Life (EOL) notifications, and end-of-support timelines.

All EOL and EOS information can be found on cisco.com. You can also register for automatic notifications.

EOL/EOS Information [English]

ISE Release Cycle - New Model

Starting with ISE 2.7, short-term and long-term releases are discontinued. A new release cycle is applied.

For details on the ISE lifecycle, click the following link [English]:

[Link to ISE Lifecycle Details]

End-of-Life/EOS Announcements

This section provides announcements regarding End-of-Life (EOL) and End-of-Sale (EOS) for various ISE versions, including dates for software maintenance, software maintenance end, and support end.

Key milestones include Software Maintenance, Software Maintenance End, and Support End.

Find more information at: cs.co/ise-software

Planning and Preparation

  1. Compatibility Check and Upgrade Path
  2. Pre-Upgrade Activities
  3. Upgrade Preparation Tool
  4. Maintenance Window

ISE 3.x Supported Platforms

This table details the hardware platforms supported by ISE 3.x, including appliance models, session capacities, processors, memory, disk, RAID, and network interfaces.

Appliance Standalone Sessions PSN Sessions Processor Cores Memory Disk RAID Network Interface
SNS-3615 10,000 10,000 1 - Intel Xeon 2.10 GHz 4110 8 32 GB (16 GB x 2) 1 (600GB) No 2 x 10G base-T, 4 x 1G base-T
SNS-3655 25,000 50,000 1 - Intel Xeon 2.10 GHz 4116 12 96 GB (6 x 16 GB) 4 (600 GB) 10 2 x 10 G base-T, 4 x 1 G base-T
SNS-3695 50,000 100,000 1 - Intel Xeon 2.10 GHz 4116 12 256 GB (8 x 32 GB) 8 (600 GB) 10 2 x 10 GB base-T, 4x1 GB base-T
SNS-3515 7,500 7,500 1 - Intel Xeon 2.40GHz E5-2620 6 16 GB (8 GB x 2) 1 (600 GB) No 6 x 1 GBase-T
SNS-3595 20,000 40,000 1 - Intel Xeon 2.60 GHz E5-2640 8 64 GB (16 GB x 4) 4 (600 GB) 10 6 x 1 Gbase-T
SNS-3715 25,000 50,000 1 - Intel Xeon 2.10 GHz 4310 12 32 GB (2 x 16 GB) 1 (600 GB) 0 2 x 10 G base-T, 4x10 GE SFP
SNS-3755 50,000 100,000 1 - Intel Xeon 2.30 GHz 4316 20 96 GB (6 x 16 GB) 4 (600 GB) 10 2 x 10 G base-T, 4x10 GE SFP
SNS-3795 50,000 100,000 1 - Intel Xeon 2.30 GHz 4316 20 256 GB (8 x 32 GB) 8 (600 GB) 10 2 x 10 G base-T, 4x10 GE SFP

*SNS-3515 is no longer supported from ISE 3.1 onwards.

*VMware version 6.5 or later is required.

Native Deployment in Public Cloud

Default Username Change

From 3.2 onwards, the default username for all cloud deployments is: iseadmin

ZTP (Zero Touch Provisioning)

Password change is required upon the first login to the GUI.

Secure Console Connection

SSH key-based authentication is required for SSH console access to cloud platforms.

Compatibility Check

Supported Hardware

Supported Virtual Environments

Microsoft Active Directory Support

Cisco DNA Center Compatibility

**Verify that the virtual machine meets the ISE installation requirements.

Check the ISE Release Notes on cisco.com for the latest compatibility guidance.

ISE Licensing Model - Features

2.x Model

3.x Model

Base (Network Onboarding): AAA and 802.1X, Guest (Hotspot, Self-registration, Sponsor approval), TrustSec (Group-based policy), Easy Connect (Passive ID)

Migration from 2.x to 3.0 and Later

ISE Migration Guide

  1. PAK ➔ Smart Licensing
  2. Raise a Support Case
  3. Provide Conversion Specifics
  4. Allocate Licenses to Virtual Account
  5. Upgrade ISE Image
  6. Ready to use!

For details on ISE licensing, refer to the accelerator "ISE Smart Licensing".

Upgrade Path to ISE 3.2

Upgrade: Pre-Upgrade Checklist (To-Do List)

Best Practices

Backup

Notes

Clean Up

Important Points

Upgrade Readiness Tool (URT) - Download and Execute

This section describes the process of downloading and running the Upgrade Readiness Tool (URT).

Important: Do not perform the following simultaneously while running URT:

Estimated Time for URT in Demo Upgrade

The document notes that estimates are based on configuration and maintenance data only and do not account for network latency.

On-Demand ISE Health Check*

Verify Deployment Against Critical Errors

Verification Items:

Download the verification results before upgrading. If critical errors are found, they can be corrected. This is an optional step and not a replacement for URT, but rather an additional check.

*Available for 2.6 and 2.7 with the latest patch.

Demo: Upgrade Preparation Tool and Health Check

This section likely covers a demonstration of the tools mentioned previously.

Maintenance Window Scheduling

Adopting Maintenance Windows

For Updates and Upgrades.

Notification

Share scheduled downtime.

Minimizing Downtime

Scheduling

Factors Affecting Upgrade Time:

Estimation Method:

Deployment Type Node Persona Estimated Time
Standalone Admin, Policy Services, Monitoring 15 GB data per 240 min + 60 min
Distributed Secondary Admin Node 240 min
Policy Services Node 180 min
Monitoring 15 GB data per 240 min + 60 min

Upgrade Execution

This section details the process of executing the upgrade.

ISE Upgrade

  1. Deployment Type
  2. Upgrade Type and Process
  3. Upgrade Options

ISE Deployment Types

Diagrams illustrate different deployment scenarios:

Types of Upgrades

Split Upgrade and Full Upgrade

Split Upgrade:

Full Upgrade:

Upgrade Options - Split Upgrade

CLI, GUI, Backup/Restore

*Refer to the Upgrade Guide for details.

Upgrade Options GUI - Split Upgrade

  1. Step 1: Single Click Upgrade
  2. Step 2: Customize PSN Upgrade Order
  3. Step 3: Tandem or Group PSN Upgrade
  4. Step 4: Promote Original PAN and MNT after Completion
  5. Step 5: Install Latest Patch

Upgrade Options CLI - Split Upgrade

  1. Step 1: Manual Process
  2. Step 2: Individually Upgrade Each Node
  3. Step 3: Copy Upgrade Image to Each Node (9 GB)
  4. Step 4: Prepare and Execute Upgrade
  5. Step 5: Monitor Each Node Individually
  6. Step 6: Install Latest Patch

Note: Recommended for troubleshooting only.

Upgrade Options Backup, Re-image (New Deployment), Restore - Split Upgrade

  1. Step 1: Backup Configuration Database
  2. Step 2: Install ISE 3.2 (New Virtual Machine or Wear) or Re-image Existing Nodes
  3. Step 3: Restore Backup
  4. Step 4: Add New Deployment Nodes
  5. Step 5: Install Latest Patch

Hybrid Approach - Split Upgrade

  1. Step 1: Deregister Secondary PAN from GUI or CLI
  2. Step 2: Re-image all other nodes in the deployment
  3. Step 3: Manually add all nodes to PAN and synchronize
  4. Step 4: Promote the original primary PAN
  5. Step 5: Re-image the upgraded single node
  6. Step 6: Add the re-imaged node to the deployment
  7. Step 7: Install the latest patch

Choosing the Best Option

Feature Backup/Restore GUI CLI Hybrid
Complexity Medium Easy Complex (Involves many manual operations) Easy
Appliance and VM Access Required Minimal (Mainly for URT) Required Required
Parallel Functionality Yes PSN only Limited Yes
Rollback Impossible, requires re-imaging to previous version Limited Yes Limited
Previous Artifacts None, requires clean re-image of disk Maintenance (Due to previous issues with disk) Maintenance None, clean re-image
Time Medium Short Long Medium
Related Materials Staff numerous, additional VM resources Staff few Staff few Staff numerous, temporary VM resources
Errors Minor Minor if best practices are not followed Occurs if CLI operation skills are lacking Minor

Demo: GUI - Split Upgrade

This section likely covers a demonstration of the GUI-based split upgrade process.

Full Upgrade

Pre-checks:

Checklist:

  1. Repository Verification
  2. Bundle Download
  3. Memory Check
  4. PAN Failover Verification
  5. Scheduled Backup Check
  6. Configuration Backup Check
  7. Configuration Data Upgrade
  8. Platform Support Status Check
  9. Deployment Verification
  10. DNS Reachability
  11. Trust Store Certificate Validation
  12. System Certificate Validation
  13. Disk Space Check
  14. NTP Reachability and Time Source Verification
  15. Load Average Check
  16. License Validation
  17. Service or Process Failure

Demo: Full Upgrade

This section likely covers a demonstration of the full upgrade process.

Post-Upgrade Tasks

Best Practices

Today's Recap

Resources

Continue the conversation in our ISE community.

PDF preview unavailable. Download the PDF instead.

ISE Microsoft PowerPoint for Microsoft 365

Related Documents

Preview Cisco ISE アップグレードとバージョン3.3の新機能 | Ask the Experts
Cisco Identity Services Engine (ISE) のバージョン3.3へのアップグレードに関する専門家向けセッション。新機能、リリースサイクル、互換性、ライセンスモデル、アップグレードパスを解説。
Preview Cisco ISE 3.0 Upgrade Guide: Overview
Comprehensive guide to upgrading Cisco Identity Services Engine (ISE) to version 3.0, covering upgrade paths, licensing changes, smart licensing for air-gapped networks, and VM license categories. Includes procedures for configuring SSM On-Prem and understanding Permanent License Reservation.
Preview Cisco ISE Licensing Migration Guide
A comprehensive guide to migrating Cisco Identity Services Engine (ISE) licenses from older versions to the new Smart Licensing scheme, including VM Common licenses and Base, Plus, and Apex licenses to Essentials, Advantage, and Premier.
Preview Configure and Troubleshoot ISE with External LDAPS Identity Store
This document provides a comprehensive guide on configuring and troubleshooting Cisco Identity Services Engine (ISE) with an external LDAPS identity store. It covers prerequisites, network diagrams, step-by-step configuration for Active Directory, switches, and endpoints, as well as policy set configuration and verification steps.
Preview Cisco ISE Licenses: A Comprehensive Guide to Licensing Options
This document provides a detailed overview of Cisco Identity Services Engine (ISE) licensing, covering both Smart Licensing and Traditional Licensing models. It explains how to activate, register, manage, and troubleshoot license configurations, including different license packages like Base, Plus, Apex, and Device Administration. The guide also addresses licensing for air-gapped networks and license consumption logic.
Preview Cisco ISE-PIC Installation and Upgrade Guide, Release 3.3
Comprehensive guide for installing and upgrading Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) software, detailing prerequisites, installation steps, upgrade procedures, and troubleshooting for network administrators.
Preview Cisco Identity Services Engine CLI Reference Guide, Release 2.0
A comprehensive reference guide for the Cisco Identity Services Engine (ISE) Command Line Interface (CLI), covering management, configuration, and troubleshooting commands for Release 2.0.
Preview Cisco Identity Services Engine (ISE) v2.6: Common Criteria Operational User Guidance
This document provides comprehensive operational user guidance and preparative procedures for Cisco Identity Services Engine (ISE) version 2.6, focusing on its Common Criteria evaluated configuration, installation, and administration for network security professionals.