
PSN’s are only being used for TACACS/RADIUS authentication, not for any discovery or dot1x authentication.None of the PSN’s are behind load balancers.All Cisco ISE nodes are virtual machines running on VMWare ESXi.

This guide is built based on the following Cisco ISE environment: Understand that all implementations are different, so use this as another piece of information as you research how to perform this upgrade. Having gone through this upgrade path this past year, I thought that documenting the procedures that I followed may help others gain success in their own upgrades. This usually involves engaging Cisco TAC to help clarify points that aren’t necessarily obvious in their documentation. It is a complicated process if you have never been through it before, and often times you’re left with more questions than answers when researching how to proceed. If you have ever read through Cisco ISE 3.0 Upgrade Guide you know that it involves a lot of decision points and having to reference many other Cisco reference documents just to build a complete implementation plan for upgrading Cisco ISE from 2.x to 3.x.

Step 3 - Create Cisco ISE 3.0 Node Groups.Step 2 - Create Cisco ISE 3.0 Primary Monitor Node.Step 1 - Create Cisco ISE 3.0 Primary Admin Node.
