All perspectives
Cisco ISE·August 4, 2025·10 min read

ISE cluster upgrades without the 2 a.m. surprises

A pre-flight checklist, validation lab patterns, and the small details that make ISE upgrades feel boring — in a good way.

An ISE upgrade should feel like a non-event. When it doesn't, the cause is almost always something that could have been caught a week earlier: a stale certificate, a deprecated authorization condition, a PSN that was quietly out of sync with the primary admin node.

Pre-flight

  • Full backup of the primary admin node, restored into a lab cluster on the target version.
  • Certificate inventory with expiry dates, chain validation, and EAP-TLS trust paths verified end-to-end.
  • Policy export diffed against the previous quarter — unused conditions retired before, not during, the upgrade.
  • Sponsor and guest portals smoke-tested against the lab cluster with real client devices.
"If the lab cluster surprises you, the production cluster will surprise you louder."

The night of

Upgrades run node by node, with auth rates and live session counts on a visible dashboard. We do not advance to the next PSN until the previous one has cleared a 30-minute soak under real authentication traffic. The boring cadence is the point.