cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
241
Views
0
Helpful
1
Replies

DNAC - Catalyst Center Tacacs authentication for device/switch onboard

Fredric-123
Level 1
Level 1

Hello,

we have new deployment catalyst center, with external IP tacacs server configured on global network setting assigned to the whole network site hierarky. We have also tacacs credentials (user/psw) configured on "CLI credentials"  in order to allow catalyst center to login/access on the devices.

i would like to ask:

1) if we have new factory default device, how catalyst center can access on it without any tacacs configurations on the device? or we need to define previuosly tacacs configuration on the device (or local credential)?

1) after discovery of the device, during assignment/provisioning of the device to a site, tacacs informations will be automacally pushed on the device referring to the global network setting?

thansk if someone can help.

 

1 Reply 1

@Fredric-123 

Thats exactly how you said. You need to provide some local authentication user not TACACS

The TACACS config will be pushed during assignment.

The process can be done using PnP and on this case you dont need to setup credential. First the device Will Join Cisco cloud with its serial number and after that Will be claimed by DNAC.

You can read about that here on this link

https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-5/user_guide/b_cisco_dna_center_ug_2_3_5/m_onboard-and-provision-devices-with-plug-and-play.html#id_90888