09-08-2020 06:37 AM
Hi team,
I need to understand when we need adding Root CA to vBOND controller in Cisco PNP. Suppose, I use on-premise controllers and enterprise CA for controller authorization. In addition, I want vedge authorization to be done automatically (vmanage signed). Do I need add Root CA for vbond controller in Cisco PNP ,in this case? Or it is needed if I use enterprise CA for vedges which is different case.
Thank in advance,
09-21-2020 02:37 AM
enterprise certificate in vBond profile on PNP portal needed for ZTP. If you're not using ZTP, you may ignore this. vManage sign certificates for cloud devices only (if you selected this option for WAN edge cloud devices), and cloud devices does not use ZTP as such, for cloud device you have to supply bootstrap file with OTP token and enterprise certificate via bootstrap file.
09-21-2020 02:47 AM
Hi,
thank you very much! But if we are using ZTP and controller certificate is enterprise CA, then we definitely need to add local CA root cert to vbond profile, right? Could you describe in which phase of ZTP process this certificate is needed/used?
I think, when vEDGE or cEDGE connects to ZTP, ZTP server provides enterprise CA root certificate, so that routers can authenticate vbond, true?
Regards,
09-21-2020 03:45 AM
Yes you got it right.
03-06-2024 01:51 PM
Hi,
is the onboarding working with this setup? I‘m looking for the same. How will the root CA installed on the cEdge? Will it be doenloaded from PNP during first contact? Do you have some special settings in vManage?
best regsrds, Stefan
09-21-2020 04:04 AM
Thank you! Just one more question:
I know that vedge-cloud does not support ZTP. But what about CSR1000v? Does it support ZTP (actually, PNP as it is cEDGE)? I haven't found any yes or no answer in docs, honestly. That's why I'm asking.
Regards,
09-21-2020 09:53 AM
No, CSR1kv is software based device (no SUDI chip here) hence you need same approach as for vEdge-Cloud with OTP token, and hence ZTP won't work. You should use ciscosdwan_cloud_init.cfg bootstrap file instead.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide