03-01-2022 05:50 AM
Hi experts,
Has anyone tried out this new feature in the DNAC? So we have an SDA environment and I wanted to onboard APs using PnP and dot1x, any guides or reference that can help me guide through the process?
Thanks.
03-01-2022 07:00 AM
There are a lot of guides under the DNAc section. Here is a link to some:
Cisco DNA Center User Guide, Release 2.2.2 - Provision Your Network [Cisco DNA Center] - Cisco
You can also search., "cisco DNAc access point PnP"
05-31-2023 02:30 AM - edited 05-31-2023 02:34 AM
Hi,
I'm just chiming in here because there seems to be an issue when deploying the access points through PnP with authentication through the TLS certificate.
Please take into account that currently behaviour seems to be misaligned between the WLC and AP onboarded through PnP for TLS, the AP will present the TLS certificate which is LSC and the WLC will put the AP in LSC fallback state which does not allow the AP to download the WLAN info through the CAPWAP. There might be a very easy manual workaround for that, but it could defeat the whole purpose of PnP (zero touch) automation.
I have not experienced any issues using the PEAP option with credentials though and this can also be leveraged efficiently in ISE Policy.
Engineering is looking into the issue with the TLS LSC certificate as we speak and I'm convinced we will see a fix on the DNAC side eventually, but for now PEAP seems the way to go if you want some added security enabling some form of AP authentication.
Bear in mind that I'm not a security expert and I advise you to go over this with your security team or a Cisco security expert before rolling this out in production.
05-29-2024 03:05 AM
For anyone looking for the guide, here is one that has been put together by sandjose
Secure AP onboarding- An Introduction to Enhanced Network Security
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide