02-21-2024 01:15 PM
I have been struggling with getting my switches to properly register with my on prem SSM. I have followed every guide I can find, as well as looking at solutions on this board, all with no results. I have been able to use the SSM with my DNAC and ISE.
My test switch is a C9200CX (v17.13.1). I have tried CSLU, SmartTransport, and SmartCallHome and they all fail. The closest I got to making it work is using CSLU, however I get an error indicating it doesn't have the correct credentials (?)
I can't believe this is all that hard, so what am I missing? I know everyone will ask what my config is, so let me just say that I have tried the configs marked as SOLUTION from this board and others that don't work.
The last one I used is:
crypto pki trustpoint SLA-TrustPoint
enrollment terminal
revocation-check none
ip http client source-interface (either interface name or vrf)
license smart transport cslu
license smart url cslu (CSLU url from on-prem)
exit
license smart trust idtoken(token) local
license smart sync all
Solved! Go to Solution.
03-08-2024 07:01 AM
I did get this functioning (finally). TAC didn't get me there after a few weeks of back and forth, but I discovered the issue which was seriously basic. There was one line of config missing in my switches. What is needed is:
After this, you have to add the device policy in the SSM. It should make the connection as long as you have the profile in your device set for the destination address of the cslu url.
What was odd was that in some switches the aaa authorization exec default local was there by default, in others it was not. Since I hadn't used it before, I didn't know to look for it.
03-06-2024 09:51 PM
Hi,
Did you ever get this working? We have a lot of devices for our customer which work with the On-Prem, however I cannot seem to get the Nexus devices working. So frustrating! I have a TAC case open, but it's the typical scenario going around in circles. CSLU seems to get us the closest, where the device will show up on the product instance page, however it doesn't seem to use the trust token and take the appropriate licences. It can't be a firewall issue since the switch and the on-prem exist within the same subnet. Additionally, other devices also register without issue.
03-08-2024 07:01 AM
I did get this functioning (finally). TAC didn't get me there after a few weeks of back and forth, but I discovered the issue which was seriously basic. There was one line of config missing in my switches. What is needed is:
After this, you have to add the device policy in the SSM. It should make the connection as long as you have the profile in your device set for the destination address of the cslu url.
What was odd was that in some switches the aaa authorization exec default local was there by default, in others it was not. Since I hadn't used it before, I didn't know to look for it.
08-14-2024 12:40 PM
Hi akrapf_007 ,
I'm facing the same issue. Nexus, Catalyst, WLC, none of the devices seem to work registering with the On-Prem Manager. I'll follow the commands you have mentioned in your post. Can you pls elaborate on the device policy you have mentioned in your post.
rgds,
Ajit.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide