05-30-2022 03:43 AM - edited 05-30-2022 04:44 AM
Edit:Switch 3560CX version 15.2(7)E1a
DNAC version 2.2.2.8
I tried to configuration closed authentication on Host onboarding failed. In error show parameter is not support with Extended Switch. In DNAC version 1.3.3.7 we can configuration closed authentication on Host onboarding.
I'm not sure closed authentication can't config on 2.2.2.8 or this is bugs this version.
Solved! Go to Solution.
05-30-2022 01:09 PM
I did not find a doc stating that they change from 1.3 to 2.2.
For 1.3, this guide is clear on the port config:
But, for 2.2 I could not find simitar doc.
But, I have found this statement:
"Cisco Digital Building series switches, Cisco Catalyst 3560-CX switches, and Cisco Industrial Ethernet 4000,
4010, and 5000 series switches are not policy extended node devices. They do not support Cisco TrustSec
and Group selection during port assignment."
05-30-2022 04:37 AM
Hi
Consulting the DNAC Compatibility matrix, the 3560CX is support 15.2(7)E1a. But, I dont see 3560X.
https://www.cisco.com/c/dam/en/us/td/docs/Website/enterprise/dnac_compatibility_matrix/index.html
05-30-2022 04:46 AM
Thanks @Flavio Miranda. Sorry for mistake. my switch extended is 3560CX.
05-30-2022 04:58 AM
Can you share the exactly error message ?
05-30-2022 07:31 AM
Please see the error message.
05-30-2022 08:05 AM
As per the logs, this switch is seeing by DNAC as extended device and it is saying that "Extended node port assigment must use no auth authentication"
Are you expecting to use this device as Extended decice?
05-30-2022 08:56 AM
Thanks for your asking.
Are you expecting to use this device as Extended decice?
Sure.
I have another switch extended the same model was a setting configuration closed authentication on version 1.3.3.7 and using on version 2.2.2.8
I just wonder why this version (2.2.2.8) can't set closed authentication.
05-30-2022 01:09 PM
I did not find a doc stating that they change from 1.3 to 2.2.
For 1.3, this guide is clear on the port config:
But, for 2.2 I could not find simitar doc.
But, I have found this statement:
"Cisco Digital Building series switches, Cisco Catalyst 3560-CX switches, and Cisco Industrial Ethernet 4000,
4010, and 5000 series switches are not policy extended node devices. They do not support Cisco TrustSec
and Group selection during port assignment."
05-30-2022 05:56 PM
Closed Auth should be working on C3560-CX Extended Node. Please open a TAC case. Best regards, Jerome
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide