03-24-2023 07:37 AM
For those familiar with Cisco DNA I re-added at network setting an AAA server.
This was to progress a TAC case I had hoped to target one particular device. Unfortunately it not only target that device. It also initiated a configuration change on the ISE for 21 Cisco devices. Why!!!!!
What do I need to understand or check why these 21 devices suddenly had the attention of DNA and ISE on them.
What can be done to restore my confidence in DNA ?
03-25-2023 11:43 PM
>...What can be done to restore my confidence in DNA ?
- Perhaps you initiated a wrong command sequence on DNA , having impact on more devices then intended ?
M.
03-26-2023 12:54 AM
03-26-2023 06:49 AM
>...What identified these 13 for change
- Probably best is to take (detailed) diff(s) from previous (backed up) running config on these devices and check if changes made by DNA were legitimate or not.
M.
03-26-2023 10:12 AM
Just to add. If you wanted to just change once device while working with TAC, you should have made the change manual or automate by other means. This way you are only touching one device and working with TAC to figure out the final configuration or change.
you probably changed a global or site configuration that automatically pushes that change. That is what you should do after TAC and yourself identified what needs to happen to resolve the issue.
If you are not familiar with DNAc then do not make changes unless you know 100% what that change in DNAc does.
it’s not your fault, but DNAc is to help with device configuration and templates which is very different from like Prime Infrastructure where you can identify what device and validate before the push.
03-26-2023 11:02 AM
Hi
to provide more clear response, we need more information like where changes were done, whether those devices have any commonality, any config preview was done etc.
from your description, it looks like you have done aaa settings change in network design page. This indicates that changes were done at site or building or floor or global level for aaa settings. These changes will be pushed to all devices in that site/building/floor.
DnAC provides configuration preview before every provisioning task. It would be better to preview the config before it is pushed to devices.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide