cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9816
Views
0
Helpful
19
Replies

3850 cannot connect in Cisco Network Assistant

SuperDragon
Level 1
Level 1

With my brand new Cisco 3850 Switch, I got it configured with a LAN IP.  Then, on my PC I opened up Cisco Network Assistant (version 5.8.5.1 which supports the 3850).  I went to add the 3850 to the community by discovering the device, and was prompted with the user/pass box.  The password I set was not allowing me to connect, and I realized it's because a username was required and I had not set up a username on the switch.  So, I then configured an admin user with level 15 privileges on the switch.  However, now when in CNA I try to add the 3850 to the community, it doesn't even prompt me for user/pass, it just says "unable to connect".

What do I need to do to add this 3850 to my community?

19 Replies 19

Reza Sharifi
Hall of Fame
Hall of Fame

Login via console and add these commands.  Then test again.

ip http server

ip http secure-server

HTH

Ok, it already had ip http secure-server.  I added ip http server, and now it says:

"Unable to connect.  Authentication failed."  I wasn't even given a chance to type in credentials.

Do you have this command?

ip http authen loca

I actually had that in the config when I started this thread, and removed it.  I added it back in after you mentioned it, and I tested both ways, says authentication failed on both.

by a mix of disabling/enabling CDP on the 3850 and closing and restarting the CNA, I got it to recognize the 3850, and allow me to update the stored credentials.  Now, it's just now showing the 3850 in the list on the Topology View (shows in the Map though).

Are you running .1 code on the 3850? .0 has already been deferred, just a thought. Also did you set an enable secret? I've seen the cna be very picky and want admin/enable secret to work.

Sent from Cisco Technical Support iPad App

Oddly, I put the 3850 into production yesterday (2 stacked 3850's)...and once again I'm getting "authentication failed" from the CNA on my PC.  I tried cycling CDP off and on again, no success. 

These all exist in the config file:

ip http server

ip http secure-server

ip http authentication local

I can telnet in with the setup username and secret, and can enable with the secret..but if I try using CNA or even through Internet Explorer, I get auth failed. 

Not sure what's going on?

have you set your enable secret? Set that and then use admin/xxxxx  (xxx = enable secret)

Yes, as I stated I can enable with the secret through telnet (yes, the enable secret is set).

In the CNA I've tried admin/xxx, I've tried no username and just the xxx, all kick back.

Not sure what to tell you.  I did a recreate the other day for CNA and the 3850 and litterally just added an enable secret and turned on the server, had no problems.  If you have console access into the switch, you might be able to check the log after an unsuccessful attempt via the CNA and see if it writes an relevant logs.  YOu may also try an upgrade to CNA version 5.8.6.

I upgraded to 5.8.6 yesterday.

Should I try removing the local login?  I do have console access, but I don't know the exact log to tail for the login issue.

I would strip it back down and keep it simple, make sure you always have a local log/pass so you dont get locked out.  If you run a 'show log' after an unsuccessful login attempt, if its printed, you will see it, it will be obvious. 

I tested that "show log" and it didn't show an unsuccessful logon attempt.  Do I have to turn that on in debug?

I turned on "login on-failure log", and it spit out the attempts in the console as they were happening.  I did notice that when in the CNA just trying to "discover" the 3850 by it's IP address, it immediately logged authentication failures in the console several times before prompting me for user/pass in the CNA, as if it was trying cached credentials.  I have already unchecked "encrypt and store device credentials" in the CNA, and moved the "Password-store" files to try to get it to not used cached, but I think it is anyways.

Review Cisco Networking products for a $25 gift card