cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
112
Views
0
Helpful
5
Replies

Remote Management of Cisco C1000 Switches via Cisco Business Dashboard

ibenny10
Level 1
Level 1


Dear Cisco Support Team,

I am currently managing multiple Cisco C1000 switches across several schools.
Each school operates in a separate network with no communication between them,
and VPN connections are not permitted due to Ministry of Education restrictions.

I have installed Cisco Business Dashboard (CBD) on my laptop, which I carry between sites.
I would like to know if it’s possible to achieve remote management capabilities similar to what is available with the Meraki Dashboard.

I would like to confirm:

1. Is it possible to remotely monitor and manage Cisco C1000 switches from outside the local network without establishing VPN connections, similar to cloud-based management like Meraki?

2. Can CBD be configured to provide centralized management for all schools without direct network communication between them?

3. If not, are there alternative solutions for centralized remote management under these conditions that can offer a management experience similar to the Meraki Dashboard?
Thank you for your assistance.

Best regards,
Benny

5 Replies 5

@ibenny10 

1. Is it possible to remotely monitor and manage Cisco C1000 switches from outside the local network without establishing VPN connections, similar to cloud-based management like Meraki?

 Yes, but, we need to consider connectivity. Imagine the following situation. From the place you want to run the CBD, can you reach the switch on the school? If so, you can prepare the switch and then run the discovery from the CBD to that network you used to manage the switch.

 However, I dont believe you can do that because mostly probably your switch is using some internal private IP address which is not reachable from the internet.

VPN could indeed be a solution to overcome this but if you can not have VPN, I dont believe you can achieve this.

 

2. Can CBD be configured to provide centralized management for all schools without direct network communication between them?

It can as long as  you have connectivity which falls on the problem we discussed above.

 

3. If not, are there alternative solutions for centralized remote management under these conditions that can offer a management experience similar to the Meraki Dashboard?

For Cisco I dont believe so. However, if you dont overcome the connectivity problem, it does not matter. Any solution that you want to use to manage your device remotely, will drag you to the same point which is make your switch reachable from the internet.

 

Thank you for your response.

I understand that without a VPN or a public IP address for the switches,
remote management and monitoring through the CBD would be challenging.
Given the restrictions from the Ministry of Education on opening up
internet connections, it seems that setting up a VPN or exposing the
switches via public IP addresses would not be feasible.

I manage remote networks for dozens of schools using Cisco Meraki, and it
is crucial for me to find a solution that allows secure remote management,
especially given the scale of the networks I oversee.

Are there any alternative solutions or configurations Cisco offers that
would allow secure remote management under these conditions, without
requiring direct internet access to the switches? Specifically, is there a
way to manage the devices centrally and securely, possibly using internal
networks or other secure methods?

I would appreciate any further guidance or options Cisco can provide to
address this challenge.


Platform from Cisco to manage this switch only exist the CBD.  Now, to overcome this limitation there are many solutions but not necessarily easy. You can have a firewall in each school holding up one public IP address and you can allow the management traffic for those switch from the CBD.

You can use even a router with public IP address and control the traffic via Access-list.

Solutions like Meraki, Catalyst Center or SDWAN have feature that allows the client device to search the management tool from local network, as long as you have connectivity.

But CBD use a different approach which  is device discovery.

 

 

After further consideration, I understand that remote management of Cisco
C1000 switches through the CBD platform requires either a VPN connection or
an ACL configuration via the firewall.

However, since VPN is not an option for us due to limitations from the
Ministry of Education, and configuring ACL via the firewall requires a
fixed IP address (which we do not have, as we receive a public IP from the
Ministry of Education's address pool), this makes the solution complicated
and not feasible for us. Additionally, I cannot guarantee that the address
will be stable or always accessible from different locations.

Are there any alternative solutions we can use for remote management of the
switches without the need for a fixed IP address or VPN/ACL?


Sorry I think we are in circle here. Maybe someone else can say something different.