

When the patch is in progress you will see the following from the GUI but you will also get logged out while the Primary PAN is getting patched. Make sure that that the “Enable PAN Auto Failover” box is unticked as this is only needed when there are a total of 3 nodes.
CISCO ISE 2.4 UPGRADE INSTALL
When you install the patch in a 2 node deployment the Primary PAN will upgrade and if successful it will upgrade the secondary if the upgrade fails on the Primary node the secondary node does not attempt to install the patch. This is not a requirement but is advisable by Cisco. The first part of the upgrade process is to make sure that you install the latest patch in the 2.4 release, in my case this is patch 13.

The following article skips using the URT tool but if you really want to be on the safe side then you can run this from the CLI.

CISCO ISE 2.4 UPGRADE HOW TO
This guide will only contain information on how to upgrade from the GUI there are other articles out there explaining how to complete the upgrade from the CLI but in this case, I wanted to try the GUI for the upgrade process.
