03-18-2024 02:59 AM
Hello,
since november 2023, when our cisco prime 3.10.4 trying to get the config via ssh from our 4510+R Switch, the privilege level 15 changed to 1 and the ssh connection fails. Bevor the config was archived correctily. This problem only occours with the 4510+R switch running XE 03.11.09.E
Any idea, what the problem is?
Regards, Hubert
03-18-2024 06:43 AM
- Remove the particular device from Prime and re-enter it , but before final add ; press Verify Credentials first ,
M.
03-18-2024 07:04 AM
I did this last week but it didn't help. The same error.
03-18-2024 07:06 AM
Verify credentials said everything is ok. If I do a ssh session to prime and from there a ssh session to the 4510 it already works but not from prime config job.
03-18-2024 07:17 AM
- Check logs on the device when Prime tries to connect ,
M.
03-18-2024 10:12 AM
%SYS-5-PRIV_AUTH_PASS: Privilege level set to 1 by username on vty0 (IP Address)
002808: Mar 15 22:00:12: %SYS-6-LOGOUT: User username has exited tty session 1(IP Address)
03-18-2024 10:39 AM
- If the particular admin user is authenticated externally through radius or ldap for instance , then make sure it preserves sufficient privilege's after being authenticated , (sometimes you need extra attributes returned from radius to achieve that)
M.
03-18-2024 10:24 PM
Hi, no the admin user is not authenticated externally.
Hubert
03-18-2024 10:59 PM
the error is only visible whith prime config archive collection job.
03-20-2024 01:25 AM
I will try 3.11.10 on the 4510+E switch tomorrow. Maybe this solve the problem.........
03-20-2024 02:52 AM
- Ok , good plan ; otherwise you need to engage TAC ,
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide