cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1344
Views
5
Helpful
3
Replies

Does On-Prem ZTP Server Support cEdge yet?

bhenriques
Level 1
Level 1

I read this post that back in 2019 that said ZTP server probably doesn't support cEdges, only vEdges. 

https://community.cisco.com/t5/sd-wan-and-cloud-networking/demonstrate-on-prem-ztp-server/td-p/3912768

 

When I turn on my ASR, it reaches out to devicehelper.cisco.com or pnpserver.domain (which my DNS server resolves to my ZTP server's IP), I see traffic hit it, but then the router just says "PnP HTTP (or HTTPS) timed out on connection to PnP server.

 

I've got it set up according to this guide, including my enterprise cert:

https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/SDWAN/sdwan-wan-edge-onboarding-deploy-guide-2020nov.pdf

 

Any ideas?

3 Replies 3

ekhabaro
Cisco Employee
Cisco Employee

Starting from 17.3 software you can use onprem ZTP for cEdge as well, see release notes:

 

https://www.cisco.com/c/en/us/td/docs/routers/sdwan/release/notes/xe-17-3/sd-wan-rel-notes-xe-17-3.html

 

On Premises ZTP Server for Cisco SD-WAN

This feature extends the on-premise Plug and Play implementation support to Cisco IOS XE SD-WAN routers.

So I configured my DNS according to that guide and added "ztp.domainname" and it looks like it used that and got further in the process. However, on the ZTP server, I see

 

"vbond_peer_delete[1768]: %VDAEMON_DBG_ERROR-1: Connection attempt to ztp FAILED with peer chassis_num: , public_ip: X.X.X.X:12346, error ERR_RX_TEAR_DOWN" where "X.X.X.X" is my ASR's public IP address.

 

Under "show orchestrator connections-history" it shows "CRTVERFL" which means it failed to verify peer certificate.

 

It just repeats that over and over.

It is not clear if you are using enterprise root-ca or symantec-root-ca for the on-prem ZTP ?
If this is enterprise-root-ca - is this added to the ZTP server ?
Also, the ZTP entry for the device added on the ZTP server ?

If you are still having issues, you can open a TA Case to get the assistance needed.

Review Cisco Networking for a $25 gift card