<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNA SD-Access Interface Configurations in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526081#M4643</link>
    <description>&lt;P&gt;Gerry,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is a fantastic workaround and I will definitely give it a shot. Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you come up with some code using the DNA-SDK please share your Github link! It would be a great resource for everyone.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jan 2022 19:46:04 GMT</pubDate>
    <dc:creator>jamessciortino0060</dc:creator>
    <dc:date>2022-01-03T19:46:04Z</dc:date>
    <item>
      <title>DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4468044#M4041</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading DNA Center to 2.1.2.7, there is a discrepancy between the access interface configuration for my switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After provisioning a LAN Automated switch and making it fabric enabled, I would expect the following configuration on my access interfaces:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch1# shwo run interface GigabitEthernet5/0/48&lt;/P&gt;&lt;P&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy IPDT_MAX_10&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;source template DefaultWiredDot1xClosedAuth&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But lately, a lot of the switches being onboarded are missing the command &lt;STRONG&gt;spanning-tree bpduguard enable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch2# show run int GigabitEthernet1/0/48&lt;/P&gt;&lt;P&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy IPDT_MAX_10&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;source template DefaultWiredDot1xClosedAuth&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I have found that when I onboard stacked switches, the stack members are completely missing their access interface configurations. This has been an ongoing problem since DNA Center 1.3.3.5. Anyone know a workaround to this without having to manually configure the interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;StackedSwitch1# show run int GigabitEthernet1/0/48&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;device-tracking attach-policy IPDT_MAX_10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running the following versions:&lt;/P&gt;&lt;P&gt;DNA 2.1.2.7&lt;/P&gt;&lt;P&gt;ISE 2.6 Patch 7&lt;/P&gt;&lt;P&gt;IOS-XE 16.12.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I primarily deploy C9300L's in a stack, and C9410R's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 22:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4468044#M4041</guid>
      <dc:creator>jamessciortino0060</dc:creator>
      <dc:date>2021-09-16T22:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4468662#M4043</link>
      <description>&lt;P&gt;I think you have some very valid concerns here, but I'm not seeing any internal documentation that explains either issue. &amp;nbsp;It would be great if you could work with TAC to get to the bottom of this and let us know what the final resolution is.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 18:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4468662#M4043</guid>
      <dc:creator>Preston Chilcote</dc:creator>
      <dc:date>2021-09-17T18:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4524637#M4637</link>
      <description>&lt;P&gt;Hi, I have similar issue on 2.2.2.6&lt;/P&gt;&lt;P&gt;TAC is suspecting a potential bug for our case ( new stack members doesn't have any port configuration). We have seen the same behavior for all versions from 1.3.X.X. The workaround suggested in the bug details will still miss the IPDT command or sometime bpduguard command&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa44791" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa44791&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 05:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4524637#M4637</guid>
      <dc:creator>Rajesh Kongath</dc:creator>
      <dc:date>2021-12-29T05:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526047#M4642</link>
      <description>&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;I opened the Case which resulted in the mentioned Bug&amp;nbsp;CSCwa44791 , however the TAC Engineer did not document my workaround &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The "easiest" way to have DNAC configure all interfaces of the added Stack-Member is:&lt;/P&gt;&lt;P&gt;1. goto Fabric -&amp;gt; Host-Onboarding&lt;/P&gt;&lt;P&gt;2. select all access-ports from the new switch, (hold-down shift-key if you have more than one added switch.)&lt;/P&gt;&lt;P&gt;3. assign any existing IP-Pool (does not matter which) and deploy it.&lt;/P&gt;&lt;P&gt;4. than select the ports again and choose "clear" and deploy it again.&lt;/P&gt;&lt;P&gt;Now DNAC configures all the Ports as default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Cisco does not provide a fix soon, I will check out if this procedure can be done using a script with DNAC-SDK &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Gerry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 17:25:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526047#M4642</guid>
      <dc:creator>gerry.schmucker</dc:creator>
      <dc:date>2022-01-03T17:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526081#M4643</link>
      <description>&lt;P&gt;Gerry,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is a fantastic workaround and I will definitely give it a shot. Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you come up with some code using the DNA-SDK please share your Github link! It would be a great resource for everyone.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 19:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526081#M4643</guid>
      <dc:creator>jamessciortino0060</dc:creator>
      <dc:date>2022-01-03T19:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526239#M4644</link>
      <description>&lt;P&gt;Hi Gerry&lt;/P&gt;&lt;P&gt;We had tried this option, but it was never injecting IPDT policy command, did you face the same issue?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 08:35:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526239#M4644</guid>
      <dc:creator>Rajesh Kongath</dc:creator>
      <dc:date>2022-01-04T08:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526370#M4645</link>
      <description>Hi Rajesh,&lt;BR /&gt;&lt;BR /&gt;the command “device-tracking attach-policy IPDT_POLICY” got pushed during discovery phase in older DNAC, however they push it now during “add to Fabric”.&lt;BR /&gt;the funny thing is , if you discover via API and not via GUI you get this command on all the interfaces after discovery-phase as before (without any additional commands) !&lt;BR /&gt;I do not remember if this command was there when I added Stackmembers, however I have a couple of Stack Extentions in the next couple of weeks to find out &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;I think this policy was used to limit the number of Client per port to 10 in earlier Versions of DNAC. However they lifted this limit now.&lt;BR /&gt;So far as I saw device-tracking works also without this policy, maybe this policy will disappear in next releaases….&lt;BR /&gt;&lt;BR /&gt;We can still push it with templates as a last resort….. however in my opinion all this are workaround for a bug which hopefully get’s fixed soon.&lt;BR /&gt;&lt;BR /&gt;Cheers ,&lt;BR /&gt;&lt;BR /&gt;Gerry&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Jan 2022 13:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4526370#M4645</guid>
      <dc:creator>gerry.schmucker</dc:creator>
      <dc:date>2022-01-04T13:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4527977#M4668</link>
      <description>&lt;P&gt;Gerry,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We just on boarded 6x C9300L switch stacks (each with 3 members) and a C9410R with four line cards. Using 16.12.4 IOS-XE btw.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IPDT_Policy is missing from every single access interface. However, everything else on the config looks good, including spanning-tree bpdu guard commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I thought the IPDT_POLICY was needed to probe devices and maintain the device-tracking database?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 15:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4527977#M4668</guid>
      <dc:creator>jamessciortino0060</dc:creator>
      <dc:date>2022-01-07T15:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4528046#M4669</link>
      <description>Hi James,&lt;BR /&gt;&lt;BR /&gt;That’s true however if you have not configured the policy IPDT_POLICY on the interface it fallsback to LISP-DT-GUARD-VLAN , i you can check with “show device-tracking data detail” after removing the IPDT_POLICY.&lt;BR /&gt;The differences between the policies are in the amount of mac address and lifetime.&lt;BR /&gt;checkout with :&lt;BR /&gt;&lt;BR /&gt;show device-tracking policy IPDT_POLICY&lt;BR /&gt;show device-tracking policy LISP-DT-GUARD-VLAN&lt;BR /&gt;&lt;BR /&gt;That’s why it works without the IPDT_POLICY, however we stay on the save side and configure the IPDT_POLICY via template when we re-provison the switch/stack after extending for the moment.&lt;BR /&gt;Hopefully, there is soon an “official” solution from Cisco &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Gerry&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Jan 2022 17:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4528046#M4669</guid>
      <dc:creator>gerry.schmucker</dc:creator>
      <dc:date>2022-01-07T17:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNA SD-Access Interface Configurations</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4797485#M6631</link>
      <description>&lt;P&gt;I found a workaround for this issue,&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;DNAC &amp;gt; Design &amp;gt; Network Settings &amp;gt; Go to the affected site/floor &amp;gt; Disable wired end point data collection&lt;/LI&gt;&lt;LI&gt;DNAC&amp;nbsp; &amp;gt; Provision &amp;gt; Inventory &amp;gt; Go to affected site &amp;gt; select affected device &amp;gt; Action&amp;nbsp; &amp;gt; Telemetry &amp;gt; Update telemetry settings &amp;gt; Force.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Now re-enable wired data end point collection and re-apply telemetry settings with forced ticked. This will add the missing&amp;nbsp;&lt;SPAN&gt;“device-tracking attach-policy IPDT_POLICY”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hope it helps, Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 06:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/dna-sd-access-interface-configurations/m-p/4797485#M6631</guid>
      <dc:creator>Rajesh Kongath</dc:creator>
      <dc:date>2023-03-20T06:56:25Z</dc:date>
    </item>
  </channel>
</rss>

