Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I completely agree with you, especially if it's WAN exposed to internet. I would not recommend to use netconf.
Cisco wake-up and provide a better solution.
Yes, the ACL is working but with connection reset and no ACL matching.
If you try you get:
From denied host:D:\cmd>ssh xxxx@1.1.1.1 -p 830kex_exchange_identification: read: Connection resetConnection reset by 1.1.1.1 port 830From the permitted host: ...
System certificate for DNA center have to be full chain.After CSR and CA authority signed, it has to be put in a file together with the complete chain of the certificate and imported into DNA Center.-----BEGIN CERTIFICATE-----System Cert-----END CERT...