cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Announcement“Cisco Design Thinking Workshop”. Cisco Small Business is excited to invite its Silicon Valley customers to an exclusive interactive one-day session between customers and product Managers.  If you are interested in this exclusive workshop, please fill out the Registration Form. For more information, please check out our FAQ


Get the latest new and information the November issue of the Cisco Small Business Monthly Newsletter

1223
Views
0
Helpful
17
Replies
Highlighted
Beginner

Activated, Offline

My network agent is activated but shows offline on the portal what could be the issue?  Firewall?

Everyone's tags (1)
17 REPLIES 17
Cisco Employee

Activated, Offline

Here's the list of ports that need to be open (from the inside network hosting the ON100 connecting outwards towards the internet), from the OnPlus documentation:

  • Port 53 UDP (DNS)
  • Port 80 TCP (HTTP)
  • Port 123 UDP (NTP)
  • Port 443 TCP (HTTPS)
  • Port 11300 TCP (OnPlus heartbeat)

For enhanced OnPlus functionality, the following outbound ports will also need to be opened:

  • Port 14931 UDP (WAN Network Performance monitoring via the OnPlus Network Agent)
  • 11400 TCP (Remote device connections)

Working DNS and port 11300 TCP are the most critical to the device showing online at the portal.

-mike

Beginner

Activated, Offline

Michael

From Subsytem Status everythig is a go... would it give me an error if could not access those ports?

Account Status       OK
PKI Subsystem Status       OK
Settings Monitor       Running
Service Announcement       Running
Zeroconf Management       Running
Discovery       Running
Time Service       Running
Monitoring       Running

Account Status       OK
PKI Subsystem Status       OK
Settings Monitor       Running
Service Announcement       Running
Zeroconf Management       Running
Discovery       Running
Time Service       Running
Monitoring       Running

Beginner

Activated, Offline

Michael

Thanks for your reponse, port 11300 seems to be blocked.  Is the address 1-dfw.cisco-onplus.com where the agent is trying to get out to, ip address 216.227.195.156?

I beleive it would be a good thing sto see in the status if the agent is able to get out the required ports.

Thanks!
JP

Beginner

Activated, Offline

Hi JP,

The 'Status 2' led, once the device is activated, indicates the status of the heartbeat. In general, that's your first, best, check on the state of the connection. I can see that it might also be good to present that on the status page too, but as Mike noted, there's not too much there and it gets very little use in practice.

As for the IP address for 1-dfw.cisco-onplus.com, while that might be correct, our service has the ability to reconsitute with a different IP address during extreme service situations (never happened yet, but we're prepared). If you were thinking about doing an ACL to permit 11300 and 216.227.195.156, it might be better to target permitting the ON100 to use port 11300 without destination restriction, just for safety?

Robert

Cisco Employee

Re: Activated, Offline

That's one of several possible addresses that the agent might be trying to connect to. Unfortunately, there isn't a definitive list of IP addresses that need to be permitted traffic towards - the portal IP address to which the agent attempts to connect can change at any time. Instead, you'll need to make sure that the firewall permits connections on port 11300 TCP to the entire internet (0.0.0.0/0), at least for the IP address of the ON100 agent, which you can set to a static IP address if needed via the agent's 'Configuration' page (after logging into the device).

But testing against that address (1-dfw.cisco-onplus.com) should work to at least determine if the network is blocking outbound connections on that port to arbitrary internet hosts.

-mike

Cisco Employee

Re: Activated, Offline

Drats, Robert beat me to it. Now who will JP award the stars to?? 

-mike

Beginner

Activated, Offline

Wow!! You guys rock with your information, very detailed!  I'm attempting to open the port, I'll let you guys know my status upon finishing.

JP

Beginner

Activated, Offline

I'm having a simillar problem in the portal is shows Actiated/offline. But the device itself will not move past the activate screens. Despite going through the activate process a few times, it never brings me to a logon page.

I'm stuck at this point. (Firewall isn't blocking any traffic, ssl certs have been whitelisted)

Enthusiast

Activated, Offline

Hi William,

I have a few questions for you.

Have you registered at www.cisco-onplus.com? When you say it doesn't bring you to the 'logon' page, which page are you referring to?

Has the device been activated previously? If so, you'll need to do a factory reset. To do this, hold down the reset button on the back panel for more than 10 seconds.

What is the LED status?

When you click 'Activate', what happens? Are you on the LAN with the ON100?

Could you tell us the error message you are seeing? Or take a screenshot?

Thanks,

The OnPlus Team

Cisco Employee

Activated, Offline

Hi William,

Which SSL certs were whitelisted?

Depending on your geographic location, your device may try to talk to one of many servers in the cloud to activate itself. Another option rather than whitelisting specific certificates might be to assign the ON100 a static IP address prior to activation, and configure the firewall to permit *all* 80/443 traffic to and from this IP, in addition to the ports listed above.

-mike

Beginner

Activated, Offline

cisco.com and cisco-onplus.com are whitelisted (though I disabled ssl filtering already)

I can't have this device respond on 80/443 as I have RWW running on those ports. However our sonicwall doesn't block outgoing on those ports.

Cisco Employee

Activated, Offline

Ok, I see. Only outbound-initiated connections to 80/443 ports on the internet are needed. Aqib has some additional questions above that might shed light on the problem.

-mike

Beginner

Activated, Offline

Phone support helped me out. Firmware update got stuck.

Enthusiast

Activated, Offline

Glad to hear, thanks for the update!