02-16-2021 01:35 AM
Hi all,
Our customer has an SDA fabric and we use LAN automation to provision new switches.
In addition to the standard config that is applied during LAN automation (IPs, ISIS routing, AAA, etc), we have a requirement to apply custom configurations (SGT maps & SGACLs, multicast, etc) to all new switches so a day-0 template seems the logical solution.
Having done a bit of testing and reading, I don't think it's possible to apply a day-0 template during LAN automation. It looks to me that day-0 templates are only designed to be used for 'manual' PNP provisioning rather than DNAC LAN automation.
If it's not possible, our only option is to remember to provision a day-N template to push the required config each time a new switch is brought online which isn't perfect.
Can somebody please confirm or deny my thoughts?
Thanks,
Matt.
02-16-2021 02:00 AM
i do not see anything wrongdoing? if the process is tested and working as expected. ( i know this will minimize the number of changes also).
Since ISE is the basic requirement from day 0 and integrated with DNAC already with your scalable groups, and your security policies in place.
Agreed your views but Since this is a new approach, cisco may be doing a stage-wise approach to deploy, rather complicated. Lanautomation brings the device into the network - then apply the security policies required.
02-16-2021 05:39 AM
Thank you for the response BB,
It was more of a general question as to whether DNA supports LAN automation plus application of a day-0 template.
My testing suggests it does not support this but I wondered if maybe I was doing something wrong and if anyone else has been able to make this work.
Thanks!
02-18-2021 09:13 AM
As far as I'm aware, combining Day-0 and LAN automation is not an available feature.
That said, I'm not sure I understand your hesitance to implement Day-N templates. Day-N templates get applied when you provision a device from the Actions > Provision > Provision Device action, which is a required step before adding a device to a fabric. The main selling point of a Day-0 template is that they replace an entire configuration rather than SSH in and issue commands serially. If you are making changes that would disconnect your SSH sessions, you may be better served by manually building your underlay through PnP and Day-0 templates exclusively rather than LAN Automation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide