<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco DNA Sensor in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942025#M7729</link>
    <description>&lt;P&gt;I have a DNA sensor to add to DNAC. Its the first one to be added. I can see it in PnP but it doesn't join correctly. onboarding stops at 10%&lt;/P&gt;&lt;P&gt;logs from sensor ssh:&lt;/P&gt;&lt;P&gt;CertificateError: hostname 'pnpserver.domain' doesn't match either of 'localhost', 'kong', 'kong.maglev-system', 'kong.maglev-system.svc', 'kong.maglev-system.svc.cluster', 'kong.maglev-system.svc.cluster.local',&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNA device status:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NCOB02066: Device disconnected probably due to incorrect certificate or TLS version.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anyone come across this and found a fix?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 12:32:02 GMT</pubDate>
    <dc:creator>michael18</dc:creator>
    <dc:date>2023-10-17T12:32:02Z</dc:date>
    <item>
      <title>Cisco DNA Sensor</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942025#M7729</link>
      <description>&lt;P&gt;I have a DNA sensor to add to DNAC. Its the first one to be added. I can see it in PnP but it doesn't join correctly. onboarding stops at 10%&lt;/P&gt;&lt;P&gt;logs from sensor ssh:&lt;/P&gt;&lt;P&gt;CertificateError: hostname 'pnpserver.domain' doesn't match either of 'localhost', 'kong', 'kong.maglev-system', 'kong.maglev-system.svc', 'kong.maglev-system.svc.cluster', 'kong.maglev-system.svc.cluster.local',&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNA device status:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NCOB02066: Device disconnected probably due to incorrect certificate or TLS version.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anyone come across this and found a fix?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 12:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942025#M7729</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2023-10-17T12:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco DNA Sensor</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942168#M7730</link>
      <description>&lt;P&gt;DNA sensor - what DNAC Sensor ? you mean Sensor AP ?&lt;/P&gt;
&lt;P&gt;if&amp;nbsp; Wifi sensor AP&amp;nbsp; - then what is the version of DNAC ? it required 2.3.X version to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942168#M7730</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-10-17T13:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco DNA Sensor</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942306#M7731</link>
      <description>&lt;P&gt;yeh, AP1801. a sensor used with DNAC. current version 2.3.4&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942306#M7731</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2023-10-17T14:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco DNA Sensor</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942353#M7735</link>
      <description>&lt;P&gt;It sounds like you replaced the self-signed certificate, but didn't include pnpserver.domain in the Certificat Signing Request (CSR). &amp;nbsp;Be sure to follow this doc to generate a new CSR and certificate that includes that url:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 15:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/4942353#M7735</guid>
      <dc:creator>Preston Chilcote</dc:creator>
      <dc:date>2023-10-17T15:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco DNA Sensor</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/5022626#M8545</link>
      <description>&lt;P&gt;In our lab I have recently replaced the certificate on DNAC with one signed by the internal CA.&amp;nbsp; I used the GUI to generate the CSR, hit the issue with the CN only being accepted if it was the IPv4 address, but I put the various SAN entries in so it all seems to work.&amp;nbsp; This then had some knock-on effects that has taken me some time to resolve - ISE integration broke and I had to "&lt;SPAN&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;sudo maglev-config refresh_certs" on DNAC to get it to accept the certificate from ISE - not sure why this worked, but it did.&amp;nbsp; We also have a AP1800S-WiFi-Sensor and this hasn't worked since I replaced the DNAC cert.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;On the sensor I am getting the error "ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] unknown error: unable to get local issuer certificate (_ssl.c:1123)"&amp;nbsp; and I am struggling to solve it.&amp;nbsp; The SAN on the DNAC cert contains all the IPv4 addresses as well as the DNA names, plus a 'pnpserver.&amp;lt;local DNS suffix&amp;gt;'.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;I'm not sure what else to try.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;EDIT:&amp;nbsp; I replaced the DNAC system certificate again.&amp;nbsp; I used the GUI to create the CSR, added the various SAN DNS names including 'pnpserver.&amp;lt;domain suffix&amp;gt;', got it signed by the internal CA.&amp;nbsp; I then combined the resulting PEM file with the CA root PEM file into a single file and fed it back to DNAC.&amp;nbsp; DNAC kicked me out due to the new cert.&amp;nbsp; I logged back in, rebooted the sensor (PoE off/on) and its now gone through the PNP stuff and onboarded.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Its a proper house of cards.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/5022626#M8545</guid>
      <dc:creator>andrew.butterworth</dc:creator>
      <dc:date>2024-02-22T14:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco DNA Sensor</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/5023466#M8559</link>
      <description>&lt;P&gt;Michael18,&lt;/P&gt;
&lt;P&gt;Just to let you know, we do not support the Access Points (AP1801 or other APs) as a sensor device in Catalyst Center Appliances in most recent releases. We only support the &lt;BR /&gt;Cisco Aironet 1800s Active Sensor and each sensor runs sensor specific software which matches the Catalyst Center Release Train that it wants to join.&lt;/P&gt;
&lt;P&gt;Cisco Aironet 1800s Active Sensor&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/access_point/1800/quick/guide/ap1800sgetstart.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/access_point/1800/quick/guide/ap1800sgetstart.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cisco Aironet Active Sensor Deployment Guide&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/deploy-guide/Cisco_1800S_Sensor_Deployment_Guide_133.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/deploy-guide/Cisco_1800S_Sensor_Deployment_Guide_133.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Aironet 1800s Network Sensor&lt;BR /&gt;&lt;A href="https://software.cisco.com/download/home/286318948/type/286288051/release/2.3.7.0" target="_blank"&gt;https://software.cisco.com/download/home/286318948/type/286288051/release/2.3.7.0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 14:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-dna-sensor/m-p/5023466#M8559</guid>
      <dc:creator>Tomas de Leon</dc:creator>
      <dc:date>2024-02-23T14:32:07Z</dc:date>
    </item>
  </channel>
</rss>

