cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
245
Views
0
Helpful
6
Replies

SDA and SXP Problem on Border - No IP-SGT Bindings

BertiniB
Level 1
Level 1

Hello guys,
I am trying to do SGT Role enforcement on the Fabric Border. It works by making an SXP connection on the Fabric Borders with the ISE PSNs. It works at first, all the IP-SGT Bindings are successfully downloaded. However, after some time all the IP-SGT Bindings are withdrawn from all the Borders. The SXP Connection shows as "ON" but I get "There are no IP-SGT Mappings". It works again, for some time, if I disable/enable the SXP service on the PSNs.
I followed this guide to achieve this: Policy Enforcement Within SDA Border - Cisco Community
Am I doing something wrong?

BertiniB_0-1749856430543.png

PL-SW-BCP-1#show run | sec cts
aaa authentication login dnac-cts-list group dnac-client-radius-group local
aaa authentication dot1x dnac-cts-DKC-CORP-8def09b1 group dnac-rGrp-DKC-CORP-8def09b1
aaa authentication dot1x dnac-cts-DKC-GUEST-788920b8 group dnac-rGrp-DKC-GUEST-788920b8
aaa authorization network dnac-cts-list group dnac-client-radius-group
aaa authorization network dnac-cts-DKC-CORP-8def09b1 group dnac-rGrp-DKC-CORP-8def09b1
aaa authorization network dnac-cts-DKC-GUEST-788920b8 group dnac-rGrp-DKC-GUEST-788920b8
cts authorization list dnac-cts-list
cts sxp enable
cts sxp default password 7 0131140548020A06200F1C594B54
cts sxp connection peer 10.0.128.25 source 10.0.14.3 password default mode local listener hold-time 0 0
cts sxp connection peer 10.0.2.75 source 10.0.14.3 password default mode local listener hold-time 0 0
 no ip redirects
 no cts role-based enforcement
 no ip redirects
 no cts role-based enforcement
 no ip redirects
 no ip redirects
 no ip redirects
 no ip redirects
 no ip redirects
cts role-based enforcement
cts role-based enforcement vlan-list 141-142,3001-3004
wireless cts-sxp profile default-sxp-profile
 security dot1x authentication-list dnac-cts-DKC-CORP-8def09b1
 filter tdl-uri /services;serviceName=ios_emul_oper/cts_env_data
 input table cts_rolebased_policy
  field dst_sgt
  field src_sgt
  field sgacl_name
  field monitor_mode
  field num_of_sgacl
  field policy_life_time
  field total_deny_count
  field last_updated_time
  field total_permit_count
  join-key cts_role_based_policy_key
  logical-op and
  type mandatory
  uri /services;serviceName=ios_emul_oper/cts_rolebased_policy
   field cts_rolebased_policy.src_sgt
   field cts_rolebased_policy.dst_sgt
   field cts_rolebased_policy.total_permit_count
   field cts_rolebased_policy.total_deny_count
   field cts_rolebased_policy.sgacl_name
   field cts_rolebased_policy.monitor_mode
   field cts_rolebased_policy.num_of_sgacl
   field cts_rolebased_policy.policy_life_time
   field cts_rolebased_policy.last_updated_time

BertiniB_1-1749856559526.png

BertiniB_2-1749856600586.png

Could it be this ISEInternalSxpDevice being OFF?

 

6 Replies 6

there could be number of reasons to this behaviour starting with not yet documented bug. consider TAC involvement.
from other hand u could get your BNs rectified from issue in quite quick manner by catching cts sxp event & running eem script to verify your sxp-generated sgt-map is in place & react correspondingly.
but if u decide resolve it with TAC please keep this tread updated
thank you

BertiniB
Level 1
Level 1

Thanks for the reply @Andrii Oliinyk. I don't know which TAC I should involve: ISE ou SD-Access. But I will try one, and keep updated.

you could sniff for SXP exchange between BNs&PxGridNodes with EPC
if you dont find there anything unusual just try workaround with catching empty sgt-map & resetting sxp connections
try to guess most useful form of one of the below

BertiniB
Level 1
Level 1

Changed the Global Password and changed the SXP Devices to use Default password. It restarted and the SGT Bindings are back on the switch. I will monitor if they are withdrawn again.
But does anyone know this ISEInternalSxpDevice? Is it garbage or legit from ISE?
It's status is OFF and the peer is 1.2.3.4

 

BertiniB
Level 1
Level 1

It didn`t work, something happened again and the IP SGT Bindings went gone...

    Buffer logging:  level debugging, 139038 messages logged, xml disabled,
                    filtering disabled
    Exception Logging: size (4096 bytes)
    Count and timestamp logging messages: disabled
    File logging: disabled
    Persistent logging: disabled

No active filter modules.

    Trap logging: level informational, 129367 message lines logged
        Logging to 10.0.128.35  (udp port 514, audit disabled,
              link up),
              129366 message lines logged,
              0 message lines rate-limited,
              0 message lines dropped-by-MD,
              xml disabled, sequence number disabled
              filtering disabled
        Logging Source-Interface:       VRF Name:
        Loopback0
    TLS Profiles:

Log Buffer (102400 bytes):
= 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 16:42:51.158: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:42:51.158: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:42:51.158: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:42:51.158: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:42:51.158: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:42:51.158: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:42:51.158: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:42:51.158: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:42:51.158: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 257, <10.0.2.75, 10.0.14.3>
Jun 14 16:43:09.274: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:43:09.274: CTS-SXP-CONN:ph_retry_open_timer
Jun 14 16:43:09.274: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped
Jun 14 16:43:09.274: CTS-SXP-CONN:retry conn setup; conn index = 1
Jun 14 16:43:09.274: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1
Jun 14 16:43:09.274: CTS-SXP-CONN:conn_cleanup <-1>
Jun 14 16:43:09.274: CTS-SXP-CONN:
sxp_calc_src_ip cfg src: 10.0.14.3, def src: 0.0.0.0 calc src: 10.0.14.3 vrf:, tableid:0x0
Jun 14 16:43:09.274: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.0.14.3
Jun 14 16:43:09.274: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.0.14.3
Jun 14 16:43:09.275: CTS-SXP-CONN:ph_send_open <1> fd: 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-CONN:get_conn_passwd_info <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 11, Resource temporarily unavailable, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-CONN:SXP SCM: socket_connect in progress, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-CONN: send sxp open, curr version 5,  <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-MSG:trp_send_msg <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-MSG:trp_socket_write fd<1>, cdbp->ph_sock_pending<1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:09.275: CTS-SXP-CONN:ph_retry_open_timer retry timer started
Jun 14 16:43:09.275: CTS-SXP-CONN:Received invalid DIRECT_EVENT
Jun 14 16:43:31.159: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:43:31.159: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:43:31.159: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:43:31.159: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:43:31.159: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:43:31.159: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:43:31.159: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:43:31.159: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:43:31.159: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 11, <10.0.2.75, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:43:39.275: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-CONN:SXP SCM: fd = 1, cdbp->listen_fd = -1, ci = 1,  <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-CONN:SXP SCM: fd = 1, cdbp->listen_fd = -1, ci = 1,  <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-MSG:trp_process_read_sock <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-MSG:trp_process_read_sock socket_recv result:-1 errno:257; <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-ERR:SXP TRP: socket_recv failed; fd = 1, errno = 257
Jun 14 16:43:39.275: CTS-SXP-CONN:scm_send_msg <TRP_TCP_CLOSE, 1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-CONN:ph_tcp_close <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-CONN:SXP SCM: sh_terminate_conn fd = 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.275: CTS-SXP-CONN:conn_cleanup <1>
Jun 14 16:43:39.275: %CTS-3-SXP_CONN_STATE_CHG_OFF: Connection <10.0.128.25, 10.0.14.3>-3 state changed from Pending_On to Off.
Jun 14 16:43:39.276: CTS-SXP-CONN:free_conn_buffers, <10.0.128.25, 10.0.14.3>
Jun 14 16:43:39.276: CTS-SXP-MSG:imu_sxp_conn_del <1>, <10.0.128.25, 10.0.14.3> ver 5 vrf
Jun 14 16:43:39.276: CTS-SXP-MDB:mdb_send_msg <IMU_DEL_DEVID>

Jun 14 16:43:39.276: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.0.128.25, ip2 10.0.128.25 conn mode1 2, conn_mode2 2

Jun 14 16:44:11.160: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:44:11.160: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:11.160: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:44:11.160: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:44:11.160: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:11.160: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:44:11.160: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:11.160: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:44:11.160: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 257, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:34.845: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 16:44:34.845: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 16:44:38.440: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 16:44:51.160: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:44:51.160: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:51.160: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:44:51.160: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:44:51.160: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:51.160: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:44:51.160: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:44:51.160: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:44:51.160: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 257, <10.0.2.75, 10.0.14.3>
Jun 14 16:45:09.276: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:45:09.276: CTS-SXP-CONN:ph_retry_open_timer
Jun 14 16:45:09.276: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped
Jun 14 16:45:09.276: CTS-SXP-CONN:retry conn setup; conn index = 1
Jun 14 16:45:09.276: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1
Jun 14 16:45:09.276: CTS-SXP-CONN:conn_cleanup <-1>
Jun 14 16:45:09.276: CTS-SXP-CONN:
sxp_calc_src_ip cfg src: 10.0.14.3, def src: 0.0.0.0 calc src: 10.0.14.3 vrf:, tableid:0x0
Jun 14 16:45:09.276: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.0.14.3
Jun 14 16:45:09.276: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.0.14.3
Jun 14 16:45:09.276: CTS-SXP-CONN:ph_send_open <1> fd: 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.276: CTS-SXP-CONN:get_conn_passwd_info <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.276: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.276: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 11, Resource temporarily unavailable, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.277: CTS-SXP-CONN:SXP SCM: socket_connect in progress, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.277: CTS-SXP-CONN: send sxp open, curr version 5,  <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.277: CTS-SXP-MSG:trp_send_msg <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.277: CTS-SXP-MSG:trp_socket_write fd<1>, cdbp->ph_sock_pending<1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:09.277: CTS-SXP-CONN:ph_retry_open_timer retry timer started
Jun 14 16:45:09.277: CTS-SXP-CONN:Received invalid DIRECT_EVENT
Jun 14 16:45:31.161: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:45:31.161: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:45:31.161: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:45:31.161: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:45:31.161: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:45:31.161: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:45:31.161: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:45:31.161: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:45:31.161: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 11, <10.0.2.75, 10.0.14.3>
Jun 14 16:45:36.616: Env-Data oper model: get env_data starts
Jun 14 16:45:36.616: Env-Data oper model: get env_data done
Jun 14 16:45:39.277: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:45:39.277: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-CONN:SXP SCM: fd = 1, cdbp->listen_fd = -1, ci = 1,  <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-CONN:SXP SCM: fd = 1, cdbp->listen_fd = -1, ci = 1,  <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-MSG:trp_process_read_sock <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-MSG:trp_process_read_sock socket_recv result:-1 errno:257; <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-ERR:SXP TRP: socket_recv failed; fd = 1, errno = 257
Jun 14 16:45:39.277: CTS-SXP-CONN:scm_send_msg <TRP_TCP_CLOSE, 1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-CONN:ph_tcp_close <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-CONN:SXP SCM: sh_terminate_conn fd = 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-CONN:conn_cleanup <1>
Jun 14 16:45:39.277: %CTS-3-SXP_CONN_STATE_CHG_OFF: Connection <10.0.128.25, 10.0.14.3>-3 state changed from Pending_On to Off.
Jun 14 16:45:39.277: CTS-SXP-CONN:free_conn_buffers, <10.0.128.25, 10.0.14.3>
Jun 14 16:45:39.277: CTS-SXP-MSG:imu_sxp_conn_del <1>, <10.0.128.25, 10.0.14.3> ver 5 vrf
Jun 14 16:45:39.277: CTS-SXP-MDB:mdb_send_msg <IMU_DEL_DEVID>

Jun 14 16:45:39.278: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.0.128.25, ip2 10.0.128.25 conn mode1 2, conn_mode2 2

Jun 14 16:46:11.162: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:46:11.162: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:11.162: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:46:11.162: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:46:11.162: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:11.162: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:46:11.162: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:11.162: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:46:11.162: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 257, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:51.162: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:46:51.162: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:51.162: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:46:51.162: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:46:51.162: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:51.162: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:46:51.162: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:46:51.162: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:46:51.162: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 257, <10.0.2.75, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:47:09.278: CTS-SXP-CONN:ph_retry_open_timer
Jun 14 16:47:09.278: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped
Jun 14 16:47:09.278: CTS-SXP-CONN:retry conn setup; conn index = 1
Jun 14 16:47:09.278: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1
Jun 14 16:47:09.278: CTS-SXP-CONN:conn_cleanup <-1>
Jun 14 16:47:09.278: CTS-SXP-CONN:
sxp_calc_src_ip cfg src: 10.0.14.3, def src: 0.0.0.0 calc src: 10.0.14.3 vrf:, tableid:0x0
Jun 14 16:47:09.278: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.0.14.3
Jun 14 16:47:09.278: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.0.14.3
Jun 14 16:47:09.278: CTS-SXP-CONN:ph_send_open <1> fd: 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-CONN:get_conn_passwd_info <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-CONN:sxp_socket_upd_md5_option <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 11, Resource temporarily unavailable, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-CONN:SXP SCM: socket_connect in progress, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-CONN: send sxp open, curr version 5,  <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.278: CTS-SXP-MSG:trp_send_msg <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.279: CTS-SXP-MSG:trp_socket_write fd<1>, cdbp->ph_sock_pending<1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:09.279: CTS-SXP-CONN:ph_retry_open_timer retry timer started
Jun 14 16:47:09.279: CTS-SXP-CONN:Received invalid DIRECT_EVENT
Jun 14 16:47:31.163: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:47:31.163: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:47:31.163: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:47:31.163: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:47:31.163: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:47:31.163: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:47:31.163: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:47:31.163: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:47:31.163: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 11, <10.0.2.75, 10.0.14.3>
Jun 14 16:47:39.278: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:47:39.279: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-CONN:SXP SCM: fd = 1, cdbp->listen_fd = -1, ci = 1,  <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-CONN:SXP SCM: fd = 1, cdbp->listen_fd = -1, ci = 1,  <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-MSG:trp_process_read_sock <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-MSG:trp_process_read_sock socket_recv result:-1 errno:257; <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-ERR:SXP TRP: socket_recv failed; fd = 1, errno = 257
Jun 14 16:47:39.279: CTS-SXP-CONN:scm_send_msg <TRP_TCP_CLOSE, 1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-CONN:ph_tcp_close <1>, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-CONN:SXP SCM: sh_terminate_conn fd = 1, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-CONN:conn_cleanup <1>
Jun 14 16:47:39.279: %CTS-3-SXP_CONN_STATE_CHG_OFF: Connection <10.0.128.25, 10.0.14.3>-3 state changed from Pending_On to Off.
Jun 14 16:47:39.279: CTS-SXP-CONN:free_conn_buffers, <10.0.128.25, 10.0.14.3>
Jun 14 16:47:39.279: CTS-SXP-MSG:imu_sxp_conn_del <1>, <10.0.128.25, 10.0.14.3> ver 5 vrf
Jun 14 16:47:39.279: CTS-SXP-MDB:mdb_send_msg <IMU_DEL_DEVID>

Jun 14 16:47:39.279: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.0.128.25, ip2 10.0.128.25 conn mode1 2, conn_mode2 2

Jun 14 16:47:52.377: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: admin] [Source: LOCAL] [localport: 0] at 16:47:52 UTC Sat Jun 14 2025
Jun 14 16:48:00.786: CTS-SXP-CONN:sxp_process_message_event = CTS_SXPMSG_REQUEST
Jun 14 16:48:00.786: CTS-SXP-CONN:sxp_process_request  CTS_SXPMSG_REQ_SHOWIPSGT
Jun 14 16:48:00.786: CTS-SXP-MSG:cts_sxp_show_ipsgtmap
Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT_ABORT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.786: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.787: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:00.788: CTS-SXP-MDB:mdb_send_msg <IMU_READ_IPSGT>

Jun 14 16:48:11.164: CTS-SXP-CONN:sxp_ha_role_active:TRUE
Jun 14 16:48:11.164: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 2, <10.0.2.75, 10.0.14.3>
Jun 14 16:48:11.164: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:48:11.164: CTS-SXP-CONN:SXP SCM: fd = 2, cdbp->listen_fd = -1, ci = 2,  <10.0.2.75, 10.0.14.3>
Jun 14 16:48:11.164: CTS-SXP-MSG:trp_process_read_sock <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:48:11.164: CTS-SXP-MSG:RCVD peer 10.0.2.75 readlen:8, datalen:0 remain:4096 bufp =
Jun 14 16:48:11.164: CTS-SXP-MSG:sxp_handle_rx_msg_v2 <2>, <10.0.2.75, 10.0.14.3>
Jun 14 16:48:11.164: CTS-SXP-CONN:hold timer of 10.0.2.75 is 120
Jun 14 16:48:11.164: CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 257, <10.0.2.75, 10.0.14.3>
Jun 14 16:48:36.007: CTS-SXP-CONN:sxp_process_message_event = CTS_SXPMSG_REQUEST
Jun 14 16:48:36.007: CTS-SXP-CONN:sxp_process_request  CTS_SXPMSG_REQ_CONN_NVGEN
Jun 14 16:48:36.007: CTS-SXP-CONN:cts_get_next_sxpconn_cli
Jun 14 16:48:36.007: CTS-SXP-CONN:cts_get_next_sxpconn_cli
Jun 14 16:48:36.008: CTS-SXP-CONN:cts_get_next_sxpconn_cli
Jun 14 16:49:39.279: %CTS-3-SXP_CONN_STATE_CHG_OFF: Connection <10.0.128.25, 10.0.14.3>-3 state changed from Pending_On to Off.
Jun 14 16:58:52.230: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 16:58:52.310: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 16:58:52 UTC Sat Jun 14 2025
Jun 14 16:58:52.310: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 16:58:57.503: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:21456  for netconf over ssh. External groups: PRIV15
Jun 14 17:00:35.347: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 17:02:59.894: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 17:02:59.895: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 17:11:39.562: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (hpotter1) joined with ssid (DKC-GUEST) for device with MAC: 00e0.2833.e2a3
 on channel (1)
Jun 14 17:12:36.122: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 17:12:36.202: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 17:12:36 UTC Sat Jun 14 2025
Jun 14 17:12:36.202: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 17:14:38.483: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 17:14:38.483: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 17:24:06.075: %SSH-3-NO_MATCH: No matching mac found: client hmac-md5,hmac-sha1,hmac-sha2-256,hmac-sha1-96,hmac-md5-96 server hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com
Jun 14 17:24:06.075: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.25 (tty = 0) using crypto cipher '', hmac '' Failed
Jun 14 17:24:06.075: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.25 (tty = 0) for user '' using crypto cipher '', hmac '' closed
Jun 14 17:25:58.429: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 17:33:24.978: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 14 17:33:24.985: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 14 17:33:25.953: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 14 17:33:25.967: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 14 17:40:27.879: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 17:40:27.954: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 17:40:27 UTC Sat Jun 14 2025
Jun 14 17:40:27.954: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 17:40:33.032: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:55867  for netconf over ssh. External groups: PRIV15
Jun 14 17:42:36.116: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 17:42:36.190: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 17:42:36 UTC Sat Jun 14 2025
Jun 14 17:42:36.190: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 17:44:38.522: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 17:44:38.522: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 17:46:15.446: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 17:46:15.446: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 17:46:31.639: %SSH-3-NO_MATCH: No matching mac found: client hmac-md5,hmac-sha1,hmac-sha2-256,hmac-sha1-96,hmac-md5-96 server hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com
Jun 14 17:46:31.639: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.25 (tty = 0) using crypto cipher '', hmac '' Failed
Jun 14 17:46:31.639: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.25 (tty = 0) for user '' using crypto cipher '', hmac '' closed
Jun 14 17:50:54.463: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 17:57:41.403: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:51333  for netconf over ssh. External groups: PRIV15
Jun 14 17:57:56.520: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Switch 1 R0/0: wncd: AP Event: AP Name: PL-AP-1 Mac: a400.4e27.d7c0 Session-IP: 172.16.2.11[5248] 10.0.14.3[5246] Disjoined Tag modified
Jun 14 17:58:23.328: %LOADBALANCE_TRACE_MESSAGE-5-LB_LOG_MSG: Switch 1 R0/0: wncmgrd: Loadbalancer Log : AP ( 172.16.2.10 ) : Loadbalancer algorithm assigned Instance (0) for site tag (DKC_Site_Tag)
Jun 14 17:58:40.983: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Switch 1 R0/0: wncd: AP Event: AP Name: PL-AP-2 Mac: a400.4e27.d9e0 Session-IP: 172.16.2.10[5248] 10.0.14.3[5246] Ethernet MAC: c4d6.66c1.9180 Joined
Jun 14 17:59:00.195: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Switch 1 R0/0: wncd: AP Event: AP Name: PL-AP-1 Mac: a400.4e27.d7c0 Session-IP: 172.16.2.11[5248] 10.0.14.3[5246] Ethernet MAC: c4d6.66c1.9070 Joined
Jun 14 18:00:23.624: %DOT1X-5-FAIL: Switch 1 R0/0: wncd: Authentication failed for client (00e0.2833.e2a3) with reason (Timeout) on Interface capwap_90000005 AuditSessionID 62A7000A0000002E6F982CE4 Username: host/WS-ENG-01.bsa.local
Jun 14 18:00:23.625: %SESSION_MGR-5-FAIL: Switch 1 R0/0: wncd: Authorization failed or unapplied for client (00e0.2833.e2a3) on Interface capwap_90000005 AuditSessionID 62A7000A0000002E6F982CE4. Failure reason: Authc fail. Authc failure reason: Timeout.
Jun 14 18:05:01.304: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:5191  for netconf over ssh. External groups: PRIV15
Jun 14 18:05:11.862: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Switch 1 R0/0: wncd: AP Event: AP Name: PL-AP-1 Mac: a400.4e27.d7c0 Session-IP: 172.16.2.11[5248] 10.0.14.3[5246] Disjoined Tag modified
Jun 14 18:05:35.431: %LOADBALANCE_TRACE_MESSAGE-5-LB_LOG_MSG: Switch 1 R0/0: wncmgrd: Loadbalancer Log : AP ( 172.16.2.11 ) : Loadbalancer algorithm assigned Instance (0) for site tag (DKC_Site_Tag)
Jun 14 18:05:53.251: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Switch 1 R0/0: wncd: AP Event: AP Name: PL-AP-1 Mac: a400.4e27.d7c0 Session-IP: 172.16.2.11[5248] 10.0.14.3[5246] Ethernet MAC: c4d6.66c1.9070 Joined
Jun 14 18:06:03.030: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Switch 1 R0/0: wncd: AP Event: AP Name: PL-AP-2 Mac: a400.4e27.d9e0 Session-IP: 172.16.2.10[5248] 10.0.14.3[5246] Ethernet MAC: c4d6.66c1.9180 Joined
Jun 14 18:07:35.909: %DOT1X-5-FAIL: Switch 1 R0/0: wncd: Authentication failed for client (00e0.2833.e2a3) with reason (Timeout) on Interface capwap_90000009 AuditSessionID 62A7000A000000306F9EC56E Username: host/WS-ENG-01.bsa.local
Jun 14 18:07:35.909: %SESSION_MGR-5-FAIL: Switch 1 R0/0: wncd: Authorization failed or unapplied for client (00e0.2833.e2a3) on Interface capwap_90000009 AuditSessionID 62A7000A000000306F9EC56E. Failure reason: Authc fail. Authc failure reason: Timeout.
Jun 14 18:09:26.287: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:35781  for netconf over ssh. External groups: PRIV15
Jun 14 18:10:37.118: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 18:12:36.118: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 18:12:36.224: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 18:12:36 UTC Sat Jun 14 2025
Jun 14 18:12:36.224: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 18:14:38.574: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 18:14:38.575: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 18:15:48.495: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 18:39:26.794: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:44217  for netconf over ssh. External groups: PRIV15
Jun 14 18:40:28.092: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 18:40:28.173: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 18:40:28 UTC Sat Jun 14 2025
Jun 14 18:40:28.173: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 18:40:33.274: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:34691  for netconf over ssh. External groups: PRIV15
Jun 14 18:40:45.461: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 18:42:36.121: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 18:42:36.203: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 18:42:36 UTC Sat Jun 14 2025
Jun 14 18:42:36.203: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 18:44:15.545: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 18:44:15.545: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 18:44:38.617: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 18:44:38.617: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 18:55:22.122: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:6088  for netconf over ssh. External groups: PRIV15
Jun 14 18:55:34.885: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 19:05:41.420: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 19:07:05.414: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:07:05.495: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:07:05 UTC Sat Jun 14 2025
Jun 14 19:07:05.495: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:07:23.491: %BGP-5-NBR_RESET: Neighbor 10.0.167.97 reset (Interface flap)
Jun 14 19:07:23.538: %BGP-5-ADJCHANGE: neighbor 10.0.167.97 Down Interface flap
Jun 14 19:07:23.538: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.97 IPv4 Unicast topology base removed from session  Interface flap
Jun 14 19:07:23.546: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Interface flap)
Jun 14 19:07:23.582: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Interface flap
Jun 14 19:07:23.582: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Interface flap
Jun 14 19:07:24.426: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan3003, changed state to down
Jun 14 19:07:24.544: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan3004, changed state to down
Jun 14 19:07:25.919: %DMI-5-SYNC_NEEDED: Switch 1 R0/0: dmiauthd: Configuration change requiring running configuration sync detected - '  interface range GigabitEthernet1/0/1 - 2'. The running configuration will be synchronized  to the NETCONF running data store.
Jun 14 19:07:26.694: %PARSER-5-HIDDEN: Warning!!! ' exit ' is a hidden command. Use of this command is not recommended/supported and will be removed in future.
Jun 14 19:07:26.723: %SYS-5-CONFIG_I: Configured from console by dnac on vty0 (10.0.128.35)
Jun 14 19:07:26.317: %DMI-5-SYNC_START: Switch 1 R0/0: dmiauthd: Synchronization of the running configuration to the NETCONF running data store has started.
Jun 14 19:07:57.022: %DMI-5-SYNC_COMPLETE: Switch 1 R0/0: dmiauthd: The running configuration has been synchronized to the NETCONF running data store.
Jun 14 19:07:57.288: %DMI-5-SYNC_NEEDED: Switch 1 R0/0: dmiauthd: Configuration change requiring running configuration sync detected - '  router lisp    instance-id-range 8196 ,
8197 , 8198 override     service ethernet '. The running configuration will be synchronized  to the NETCONF running data store.
Jun 14 19:07:57.688: %DMI-5-SYNC_START: Switch 1 R0/0: dmiauthd: Synchronization of the running configuration to the NETCONF running data store has started.
Jun 14 19:08:27.905: %DMI-5-SYNC_COMPLETE: Switch 1 R0/0: dmiauthd: The running configuration has been synchronized to the NETCONF running data store.
Jun 14 19:08:53.289: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:08:53.370: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:08:53 UTC Sat Jun 14 2025
Jun 14 19:08:53.370: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:08:58.487: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:7965  for netconf over ssh. External groups: PRIV15
Jun 14 19:09:27.364: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:46653  for netconf over ssh. External groups: PRIV15
Jun 14 19:09:30.916: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 19:09:30.916: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:10:03.397: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:10:03.479: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:10:03 UTC Sat Jun 14 2025
Jun 14 19:10:03.479: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:10:16.713: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan3004, changed state to down
Jun 14 19:10:17.162: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan3003, changed state to down
Jun 14 19:10:17.028: %DMI-5-SYNC_NEEDED: Switch 1 R0/0: dmiauthd: Configuration change requiring running configuration sync detected - 'switchport trunk allowed vlan all '. The running configuration will be synchronized  to the NETCONF running data store.
Jun 14 19:10:18.107: %DMI-5-SYNC_START: Switch 1 R0/0: dmiauthd: Synchronization of the running configuration to the NETCONF running data store has started.
Jun 14 19:10:19.550: %PARSER-5-HIDDEN: Warning!!! ' exit ' is a hidden command. Use of this command is not recommended/supported and will be removed in future.
Jun 14 19:10:19.578: %SYS-5-CONFIG_I: Configured from console by dnac on vty0 (10.0.128.35)
Jun 14 19:10:48.559: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan3003, changed state to up 
Jun 14 19:10:48.663: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan3004, changed state to up 
Jun 14 19:10:50.001: %BGP-5-NBR_RESET: Neighbor 10.0.167.97 active reset (BGP Notification sent)
Jun 14 19:10:50.008: %BGP-5-ADJCHANGE: neighbor 10.0.167.97 Up 
Jun 14 19:10:49.560: %DMI-5-SYNC_COMPLETE: Switch 1 R0/0: dmiauthd: The running configuration has been synchronized to the NETCONF running data store.
Jun 14 19:10:50.211: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up 
Jun 14 19:10:50.492: %DMI-5-SYNC_START: Switch 1 R0/0: dmiauthd: Synchronization of the running configuration to the NETCONF running data store has started.
Jun 14 19:10:51.343: %DMI-5-SYNC_NEEDED: Switch 1 R0/0: dmiauthd: Configuration change requiring running configuration sync detected - '  router lisp    instance-id-range 8196 ,
8197 , 8198 override     service ethernet '. The running configuration will be synchronized  to the NETCONF running data store.
Jun 14 19:11:22.917: %DMI-5-SYNC_COMPLETE: Switch 1 R0/0: dmiauthd: The running configuration has been synchronized to the NETCONF running data store.
Jun 14 19:11:45.592: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 19:11:45.592: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:12:13.461: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:12:13.539: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:12:13 UTC Sat Jun 14 2025
Jun 14 19:12:13.539: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:12:25.919: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 19:12:25.919: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:12:36.111: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:12:36.195: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:12:36 UTC Sat Jun 14 2025
Jun 14 19:12:36.195: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:14:38.672: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 19:14:38.673: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:15:05.597: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 19:15:05.597: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:17:33.806: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:17:33.884: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:17:33 UTC Sat Jun 14 2025
Jun 14 19:17:33.884: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:21:35.612: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 19:21:35.612: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:25:22.717: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:56143  for netconf over ssh. External groups: PRIV15
Jun 14 19:25:34.420: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 19:30:35.448: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 19:39:28.145: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:32653  for netconf over ssh. External groups: PRIV15
Jun 14 19:40:28.058: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:40:28.146: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:40:28 UTC Sat Jun 14 2025
Jun 14 19:40:28.146: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:40:33.343: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:23922  for netconf over ssh. External groups: PRIV15
Jun 14 19:42:36.120: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:42:36.201: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 19:42:36 UTC Sat Jun 14 2025
Jun 14 19:42:36.201: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 19:44:38.719: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 19:44:38.720: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:45:55.648: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 19:45:55.648: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 19:55:13.513: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:7100  for netconf over ssh. External groups: PRIV15
Jun 14 19:55:15.286: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (6)
Jun 14 19:55:58.483: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 20:09:23.753: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:47841  for netconf over ssh. External groups: PRIV15
Jun 14 20:12:36.109: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 20:12:36.189: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 20:12:36 UTC Sat Jun 14 2025
Jun 14 20:12:36.189: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 20:14:38.760: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 20:14:38.760: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 20:20:53.471: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 20:25:04.133: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:10054  for netconf over ssh. External groups: PRIV15
Jun 14 20:25:08.286: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 20:28:26.417: %APMGR_AWIPS_SYSLOG-6-APMGR_AWIPS_MESSAGE: Switch 1 R0/0: wncd: AWIPS alarm:(PL-AP-1) c4d6.66c1.9070 Radio MAC a400.4e27.d7c0 detected Airdrop Session (10021)
Jun 14 20:35:37.562: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 20:39:24.509: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:12212  for netconf over ssh. External groups: PRIV15
Jun 14 20:40:27.906: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 20:40:27.979: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 20:40:27 UTC Sat Jun 14 2025
Jun 14 20:40:27.979: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 20:40:33.071: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:27592  for netconf over ssh. External groups: PRIV15
Jun 14 20:42:36.154: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 20:42:36.239: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 20:42:36 UTC Sat Jun 14 2025
Jun 14 20:42:36.239: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 20:44:38.812: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 20:44:38.812: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 20:46:00.772: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 20:46:00.772: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 20:55:24.874: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:55191  for netconf over ssh. External groups: PRIV15
Jun 14 21:00:00.261: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:00:00.341: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 21:00:00 UTC Sat Jun 14 2025
Jun 14 21:00:00.342: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:00:32.812: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 21:02:15.811: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 21:02:15.811: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 21:07:00.623: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 21:09:25.229: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:14160  for netconf over ssh. External groups: PRIV15
Jun 14 21:12:36.095: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:12:36.169: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 21:12:36 UTC Sat Jun 14 2025
Jun 14 21:12:36.169: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:14:38.858: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 21:14:38.858: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 21:25:05.606: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:38892  for netconf over ssh. External groups: PRIV15
Jun 14 21:25:06.868: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (6)
Jun 14 21:25:30.433: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 21:39:25.942: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:46098  for netconf over ssh. External groups: PRIV15
Jun 14 21:40:27.974: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:40:28.049: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 21:40:28 UTC Sat Jun 14 2025
Jun 14 21:40:28.049: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:40:33.085: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:39610  for netconf over ssh. External groups: PRIV15
Jun 14 21:42:36.107: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:42:36.186: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 21:42:36 UTC Sat Jun 14 2025
Jun 14 21:42:36.186: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 21:44:38.899: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 21:44:38.899: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 21:46:15.901: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 21:46:15.901: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 21:50:26.477: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 22:09:26.535: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:38567  for netconf over ssh. External groups: PRIV15
Jun 14 22:12:36.104: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 22:12:36.185: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 22:12:36 UTC Sat Jun 14 2025
Jun 14 22:12:36.185: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 22:14:38.950: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 22:14:38.950: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 22:15:22.514: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 22:25:16.858: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:55242  for netconf over ssh. External groups: PRIV15
Jun 14 22:39:27.190: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:2821  for netconf over ssh. External groups: PRIV15
Jun 14 22:40:28.034: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 22:40:28.105: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 22:40:28 UTC Sat Jun 14 2025
Jun 14 22:40:28.105: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 22:40:33.234: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:8463  for netconf over ssh. External groups: PRIV15
Jun 14 22:40:46.654: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 22:42:36.117: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 22:42:36.203: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 22:42:36 UTC Sat Jun 14 2025
Jun 14 22:42:36.203: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 22:44:38.996: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 22:44:38.996: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 22:46:01.009: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 22:46:01.010: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 22:55:12.494: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:17720  for netconf over ssh. External groups: PRIV15
Jun 14 23:00:00.343: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:00:00.418: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 23:00:00 UTC Sat Jun 14 2025
Jun 14 23:00:00.418: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:02:09.020: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 23:02:09.020: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 23:05:41.413: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 23:09:27.726: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:59350  for netconf over ssh. External groups: PRIV15
Jun 14 23:12:36.097: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:12:36.170: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 23:12:36 UTC Sat Jun 14 2025
Jun 14 23:12:36.170: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:14:39.039: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 23:14:39.039: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 23:25:23.006: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:6423  for netconf over ssh. External groups: PRIV15
Jun 14 23:26:12.130: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 23:30:35.496: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 14 23:39:28.230: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:55398  for netconf over ssh. External groups: PRIV15
Jun 14 23:40:28.058: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:40:28.131: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 23:40:28 UTC Sat Jun 14 2025
Jun 14 23:40:28.132: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:40:33.255: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:13009  for netconf over ssh. External groups: PRIV15
Jun 14 23:42:36.100: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:42:36.174: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 23:42:36 UTC Sat Jun 14 2025
Jun 14 23:42:36.175: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 14 23:44:39.085: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 14 23:44:39.086: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 23:45:56.127: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 14 23:45:56.128: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 14 23:55:23.543: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:18997  for netconf over ssh. External groups: PRIV15
Jun 14 23:55:25.100: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 14 23:55:31.531: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 00:09:23.754: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:6464  for netconf over ssh. External groups: PRIV15
Jun 15 00:12:36.105: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 00:12:36.179: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 00:12:36 UTC Sun Jun 15 2025
Jun 15 00:12:36.180: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 00:14:40.129: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 00:14:40.129: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 00:20:29.447: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 00:25:14.077: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:36129  for netconf over ssh. External groups: PRIV15
Jun 15 00:25:21.626: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (6)
Jun 15 00:39:24.319: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:62329  for netconf over ssh. External groups: PRIV15
Jun 15 00:40:28.077: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 00:40:28.151: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 00:40:28 UTC Sun Jun 15 2025
Jun 15 00:40:28.151: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 00:40:33.212: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:43954  for netconf over ssh. External groups: PRIV15
Jun 15 00:42:36.099: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 00:42:36.173: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 00:42:36 UTC Sun Jun 15 2025
Jun 15 00:42:36.173: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 00:44:31.237: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 00:44:31.237: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 00:44:39.165: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 00:45:24.535: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 00:55:04.637: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:3227  for netconf over ssh. External groups: PRIV15
Jun 15 01:09:24.898: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:24807  for netconf over ssh. External groups: PRIV15
Jun 15 01:10:48.601: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 01:12:36.097: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 01:12:36.171: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 01:12:36 UTC Sun Jun 15 2025
Jun 15 01:12:36.171: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 01:14:39.211: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 01:14:39.212: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 01:25:20.174: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:34684  for netconf over ssh. External groups: PRIV15
Jun 15 01:25:28.518: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 15 01:35:43.605: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 01:39:25.420: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:54764  for netconf over ssh. External groups: PRIV15
Jun 15 01:40:28.117: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 01:40:28.191: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 01:40:28 UTC Sun Jun 15 2025
Jun 15 01:40:28.191: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 01:40:33.272: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:49911  for netconf over ssh. External groups: PRIV15
Jun 15 01:42:36.108: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 01:42:36.185: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 01:42:36 UTC Sun Jun 15 2025
Jun 15 01:42:36.186: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 01:44:39.268: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 15 01:44:39.268: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 01:44:41.361: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 01:55:10.744: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:26049  for netconf over ssh. External groups: PRIV15
Jun 15 02:00:39.521: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 02:09:25.977: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:1313  for netconf over ssh. External groups: PRIV15
Jun 15 02:12:36.103: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 02:12:36.189: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 02:12:36 UTC Sun Jun 15 2025
Jun 15 02:12:36.189: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 02:14:39.330: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 02:14:39.330: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 02:25:11.324: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:31296  for netconf over ssh. External groups: PRIV15
Jun 15 02:25:35.484: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 02:25:41.341: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (6)
Jun 15 02:39:26.647: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:16276  for netconf over ssh. External groups: PRIV15
Jun 15 02:40:28.144: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 02:40:28.215: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 02:40:28 UTC Sun Jun 15 2025
Jun 15 02:40:28.215: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 02:40:33.273: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:28070  for netconf over ssh. External groups: PRIV15
Jun 15 02:42:36.111: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 02:42:36.188: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 02:42:36 UTC Sun Jun 15 2025
Jun 15 02:42:36.188: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 02:44:39.375: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 15 02:44:39.375: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 02:46:01.479: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 02:46:01.479: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 02:50:30.468: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 02:55:16.990: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:56879  for netconf over ssh. External groups: PRIV15
Jun 15 03:09:27.249: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:27362  for netconf over ssh. External groups: PRIV15
Jun 15 03:12:36.104: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:12:36.182: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 03:12:36 UTC Sun Jun 15 2025
Jun 15 03:12:36.182: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:14:39.422: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 03:14:39.422: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 03:15:25.516: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 03:25:22.560: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:28761  for netconf over ssh. External groups: PRIV15
Jun 15 03:30:03.572: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:30:03.644: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 03:30:03 UTC Sun Jun 15 2025
Jun 15 03:30:03.644: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:32:04.443: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 03:32:04.443: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 03:39:27.803: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:35565  for netconf over ssh. External groups: PRIV15
Jun 15 03:40:28.316: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:40:28.395: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 03:40:28 UTC Sun Jun 15 2025
Jun 15 03:40:28.395: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:40:33.526: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:3212  for netconf over ssh. External groups: PRIV15
Jun 15 03:40:49.662: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 03:42:36.105: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:42:36.180: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 03:42:36 UTC Sun Jun 15 2025
Jun 15 03:42:36.180: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 03:44:39.465: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 15 03:44:39.466: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 03:45:56.590: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 03:45:56.591: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 03:53:57.425: %SYS-6-TTY_EXPIRE_TIMER: (exec timer expired, tty 0 (0.0.0.0)), user admin
Jun 15 03:53:57.425: %SYS-6-LOGOUT: User admin has exited tty session 0()
Jun 15 03:55:05.893: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: admin] [Source: LOCAL] [localport: 0] at 03:55:05 UTC Sun Jun 15 2025
Jun 15 03:55:18.123: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:37363  for netconf over ssh. External groups: PRIV15
Jun 15 04:05:44.550: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 04:09:28.376: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:35124  for netconf over ssh. External groups: PRIV15
Jun 15 04:12:36.097: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 04:12:36.172: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 04:12:36 UTC Sun Jun 15 2025
Jun 15 04:12:36.172: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 04:14:39.511: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 04:14:39.512: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 04:25:08.674: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:10620  for netconf over ssh. External groups: PRIV15
Jun 15 04:25:56.964: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 15 04:30:39.541: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 04:39:23.937: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:21597  for netconf over ssh. External groups: PRIV15
Jun 15 04:40:28.418: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 04:40:28.502: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 04:40:28 UTC Sun Jun 15 2025
Jun 15 04:40:28.502: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 04:40:33.715: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:18266  for netconf over ssh. External groups: PRIV15
Jun 15 04:42:36.116: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 04:42:36.195: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 04:42:36 UTC Sun Jun 15 2025
Jun 15 04:42:36.195: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 04:44:16.698: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 04:44:16.698: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 04:44:39.561: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 15 04:44:39.561: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 04:55:09.174: %SYS-6-TTY_EXPIRE_TIMER: (exec timer expired, tty 0 (0.0.0.0)), user admin
Jun 15 04:55:09.174: %SYS-6-LOGOUT: User admin has exited tty session 0()
Jun 15 04:55:19.218: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:46267  for netconf over ssh. External groups: PRIV15
Jun 15 04:55:20.639: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 15 04:55:34.592: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 05:01:29.835: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: admin] [Source: LOCAL] [localport: 0] at 05:01:29 UTC Sun Jun 15 2025
Jun 15 05:06:37.083: %BGP-5-NBR_RESET: Neighbor 10.0.167.69 reset (BGP Notification sent)
Jun 15 05:06:37.086: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.69 IPv4 Unicast topology base removed from session  BGP Notification sent
Jun 15 05:06:37.086: %BGP-3-NOTIFICATION: sent to neighbor 10.0.167.69 4/0 (hold time expired) 0 bytes
Jun 15 05:06:37.092: %BGP-5-ADJCHANGE: neighbor 10.0.167.69 Down BGP Notification sent
Jun 15 05:07:30.342: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (BGP Notification sent)
Jun 15 05:07:30.345: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  BGP Notification sent
Jun 15 05:07:30.345: %BGP-3-NOTIFICATION: sent to neighbor 10.0.167.65 4/0 (hold time expired) 0 bytes
Jun 15 05:07:30.352: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down BGP Notification sent
Jun 15 05:09:24.474: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:56493  for netconf over ssh. External groups: PRIV15
Jun 15 05:10:31.251: %BGP-5-NBR_RESET: Neighbor 10.0.167.69 active reset (BGP Notification sent)
Jun 15 05:10:31.254: %BGP-5-ADJCHANGE: neighbor 10.0.167.69 Up
Jun 15 05:10:41.122: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 05:11:10.149: %IM-5-IOX_INST_NOTICE: Switch 1 R0/0: ioxman: IOX SERVICE ThousandEyes_Enterprise_Agent LOG: Error calling checkIn: Curl error: Could not resolve host: c1.thousandeyes.com
Jun 15 05:12:30.220: %IM-5-IOX_INST_NOTICE: Switch 1 R0/0: ioxman: IOX SERVICE ThousandEyes_Enterprise_Agent LOG: last message repeated 2 times.
Jun 15 05:12:42.723: %BGP-3-NOTIFICATION: sent to neighbor 10.0.167.97 4/0 (hold time expired) 0 bytes
Jun 15 05:12:42.724: %BGP-5-NBR_RESET: Neighbor 10.0.167.97 reset (BGP Notification sent)
Jun 15 05:12:42.726: %BGP-5-ADJCHANGE: neighbor 10.0.167.97 Down BGP Notification sent
Jun 15 05:12:42.726: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.97 IPv4 Unicast topology base removed from session  BGP Notification sent
Jun 15 05:12:43.748: %BGP-3-NOTIFICATION: sent to neighbor 10.0.167.101 4/0 (hold time expired) 0 bytes
Jun 15 05:12:43.748: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (BGP Notification sent)
Jun 15 05:12:43.751: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down BGP Notification sent
Jun 15 05:12:43.751: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  BGP Notification sent
Jun 15 05:12:50.114: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 05:12:50.193: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 05:12:50 UTC Sun Jun 15 2025
Jun 15 05:12:50.193: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 05:12:50.700: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 05:13:13.866: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 05:14:33.673: %CTS-3-SXP_CONN_STATE_CHG_OFF: Connection <10.0.128.25, 10.0.14.3>-4 state changed from Delete_Hold_Down to Off.
Jun 15 05:14:33.677: %CTS-3-SXP_CONN_STATE_CHG_OFF: Connection <10.0.2.75, 10.0.14.3>-2 state changed from Delete_Hold_Down to Off.
Jun 15 05:14:54.600: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 05:14:54.600: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 05:17:50.227: %BGP-5-NBR_RESET: Neighbor 10.0.167.97 active reset (BGP Notification sent)
Jun 15 05:17:50.233: %BGP-5-ADJCHANGE: neighbor 10.0.167.97 Up
Jun 15 05:17:56.757: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 active reset (BGP Notification sent)
Jun 15 05:17:56.765: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
Jun 15 05:25:09.826: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:41462  for netconf over ssh. External groups: PRIV15
Jun 15 05:25:11.471: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 15 05:25:11.482: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 15 05:25:11.395: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (6)
Jun 15 05:32:39.932: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (Peer closed the session)
Jun 15 05:32:39.935: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down Peer closed the session
Jun 15 05:32:39.935: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 05:37:45.660: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 05:39:25.103: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:7952  for netconf over ssh. External groups: PRIV15
Jun 15 05:40:28.425: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 05:40:28.509: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 05:40:28 UTC Sun Jun 15 2025
Jun 15 05:40:28.509: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 05:40:33.649: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:10515  for netconf over ssh. External groups: PRIV15
Jun 15 05:40:52.622: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Peer closed the session)
Jun 15 05:40:52.629: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Peer closed the session
Jun 15 05:40:52.629: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 05:42:36.123: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 05:42:36.206: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 05:42:36 UTC Sun Jun 15 2025
Jun 15 05:42:36.206: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 05:44:16.809: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 05:44:16.810: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 05:44:39.668: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 15 05:44:39.669: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 05:53:23.212: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 05:55:10.425: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:19737  for netconf over ssh. External groups: PRIV15
Jun 15 05:56:21.034: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
Jun 15 06:01:55.280: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Peer closed the session)
Jun 15 06:01:55.283: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Peer closed the session
Jun 15 06:01:55.283: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 06:02:39.552: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 06:09:25.653: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:25412  for netconf over ssh. External groups: PRIV15
Jun 15 06:12:17.114: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (Peer closed the session)
Jun 15 06:12:17.117: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down Peer closed the session
Jun 15 06:12:17.117: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 06:12:36.103: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 06:12:36.176: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 06:12:36 UTC Sun Jun 15 2025
Jun 15 06:12:36.176: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 06:13:15.248: %BGP-3-NOTIFICATION: received from neighbor 10.0.167.65 active 6/7 (Connection Collision Resolution) 0 bytes
Jun 15 06:13:15.249: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 active reset (BGP Notification received)
Jun 15 06:13:15.252: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 active Down BGP Notification received
Jun 15 06:13:15.252: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  BGP Notification received
Jun 15 06:13:26.529: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 06:14:39.709: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 06:14:39.710: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 06:14:55.624: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
Jun 15 06:22:32.637: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Peer closed the session)
Jun 15 06:22:32.644: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Peer closed the session
Jun 15 06:22:32.644: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 06:25:15.961: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:57308  for netconf over ssh. External groups: PRIV15
Jun 15 06:28:03.928: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 06:31:02.563: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (Peer closed the session)
Jun 15 06:31:02.569: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down Peer closed the session
Jun 15 06:31:02.569: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 06:33:10.477: %BGP-3-NOTIFICATION: received from neighbor 10.0.167.65 active 6/7 (Connection Collision Resolution) 0 bytes
Jun 15 06:33:10.477: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 active reset (BGP Notification received)
Jun 15 06:33:10.480: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 active Down BGP Notification received
Jun 15 06:33:10.480: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  BGP Notification received
Jun 15 06:33:21.751: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 06:35:05.188: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
Jun 15 06:39:26.167: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:29862  for netconf over ssh. External groups: PRIV15
Jun 15 06:40:28.429: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 06:40:28.508: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 06:40:28 UTC Sun Jun 15 2025
Jun 15 06:40:28.508: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 06:40:33.522: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:8088  for netconf over ssh. External groups: PRIV15
Jun 15 06:41:01.854: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Peer closed the session)
Jun 15 06:41:01.861: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Peer closed the session
Jun 15 06:41:01.861: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 06:42:36.115: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 06:42:36.189: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 06:42:36 UTC Sun Jun 15 2025
Jun 15 06:42:36.189: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 1) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 06:44:39.749: %SYS-6-LOGOUT: User dnac has exited tty session 2(10.0.128.35)
Jun 15 06:44:39.749: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 1) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 06:45:57.188: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 06:45:57.188: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 06:51:14.412: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (Peer closed the session)
Jun 15 06:51:14.418: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down Peer closed the session
Jun 15 06:51:14.418: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 06:52:59.687: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 06:53:18.552: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
Jun 15 06:53:34.509: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 06:55:11.482: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:55432  for netconf over ssh. External groups: PRIV15
Jun 15 06:55:24.424: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 15 06:55:24.438: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 15 06:55:24.343: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (6)
Jun 15 06:59:16.783: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Peer closed the session)
Jun 15 06:59:16.789: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Peer closed the session
Jun 15 06:59:16.789: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 07:09:26.786: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:47101  for netconf over ssh. External groups: PRIV15
Jun 15 07:12:36.101: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 07:12:36.175: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 07:12:36 UTC Sun Jun 15 2025
Jun 15 07:12:36.175: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 07:13:09.476: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (Peer closed the session)
Jun 15 07:13:09.482: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down Peer closed the session
Jun 15 07:13:09.482: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 07:14:11.831: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
Jun 15 07:14:39.801: %SYS-6-LOGOUT: User dnac has exited tty session 1(10.0.128.35)
Jun 15 07:14:39.801: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.0.128.35 (tty = 0) for user 'dnac' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' closed
Jun 15 07:14:54.835: %BGP-3-NOTIFICATION: received from neighbor 10.0.167.65 active 6/7 (Connection Collision Resolution) 0 bytes
Jun 15 07:14:54.835: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 active reset (BGP Notification received)
Jun 15 07:14:54.839: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 active Down BGP Notification received
Jun 15 07:14:54.839: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  BGP Notification received
Jun 15 07:15:05.084: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 07:17:55.647: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint DNAC-CA failed
                      Reason : Enrollment URL not configured.
Jun 15 07:18:21.841: %BGP-5-NBR_RESET: Neighbor 10.0.167.101 reset (Peer closed the session)
Jun 15 07:18:21.847: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Down Peer closed the session
Jun 15 07:18:21.847: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.101 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 07:25:22.081: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:55725  for netconf over ssh. External groups: PRIV15
Jun 15 07:25:23.771: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 15 07:25:23.786: %SYS-5-CONFIG_P: Configured programmatically by process CTS CORE from console as admin on console
Jun 15 07:25:23.695: %CLIENT_ORCH_LOG-6-CLIENT_ADDED_TO_RUN_STATE: Switch 1 R0/0: wncd: Username entry (WS-ENG-01$@bsa.local) joined with ssid (DKC-CORP) for device with MAC: 00e0.2833.e2a3 on channel (11)
Jun 15 07:31:49.901: %BGP-5-NBR_RESET: Neighbor 10.0.167.65 reset (Peer closed the session)
Jun 15 07:31:49.904: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Down Peer closed the session
Jun 15 07:31:49.904: %BGP_SESSION-5-ADJCHANGE: neighbor 10.0.167.65 IPv4 Unicast topology base removed from session  Peer closed the session
Jun 15 07:36:02.734: %BGP-5-ADJCHANGE: neighbor 10.0.167.65 Up
Jun 15 07:36:44.795: %BGP-5-ADJCHANGE: neighbor 10.0.167.101 Up
PL-SW-BCP-1#$
Jun 15 07:39:27.326: %DMI-5-AUTH_PASSED: Switch 1 R0/0: dmiauthd: User 'dnac' authenticated successfully from 10.0.128.35:14662  for netconf over ssh. External groups: PRIV15
Jun 15 07:40:28.509: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded
Jun 15 07:40:28.591: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: dnac] [Source: 10.0.128.35] [localport: 22] at 07:40:28 UTC Sun Jun 15 2025
Jun 15 07:40:28.591: %SSH-5-SSH2_USERAUTH: User 'dnac' authentication for SSH2 Session from 10.0.128.35 (tty = 0) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded

The BGP Flapping was me shutting and no shutting some interfaces.

CTS-SXP-MSG:trp_process_read_sock socket_recv result:-1 errno:257;
CTS-SXP-MSG:SXP TRP: readlen = 8; errno = 11,
both indicates you have SXP-connections unhealthy. 
strange thing is after connections are restored switch doesnt pull sgt-maps from pxgrid nodes.
be advised to open case in TAC &| develop workaround with EEM.