cancelar
Mostrando los resultados de 
Buscar en lugar de 
Quiere decir: 
cancel
255
Visitas
0
ÚTIL
0
Respuestas

NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho

Scott12
Level 1
Level 1

Hi there,

I am trying to add our WLC 9800 in DNA Center, but for some reason we're the NETCONF isn't working. NETCONF is already configured on the WLC with the SNMP community is fine until here. When I go to the DNA Center and try to validate the credencials I can see this:

CLI (check mark OK)
SNMP (check mark OK)
NETCONF (X in red color)

As I mentioned before, the NETCONF is configured and to be able to access the WLC we use TACACs throughout Cisco ISE, all of our accounts have the 15 priviledge.

I was able to catch this log on the wlc 9800

%5-authentication failed: chassis 1 R0/0: dmiauthd: Authentication failure for netconf over ssh

And below you can find my configuration about AAA authentication.


aaa new-model
aaa group server tacacs+ SRV_Tacacs
server name Serv_Tacacs_172.16.21.11
server name Serv_Tacacs_172.21.11.11
aaa authentication login default local
aaa authentication login Tacacs-authentication group SRV_Tacacs local
aaa authorization exec Tacacs-authorization group SRV_Tacacs if-authenticated
aaa authorization network default local
aaa accounting exec Tacacs_Authorization_Accounting start-stop group SRV_Tacacs
!
!
aaa session-id common
ip http authentication aaa login-authentication Tacacs-authentication
ip http authentication aaa exec-authorization Tacacs-authorization
commands configure include aaa attribute list
commands configure include aaa attribute
commands configure include aaa
commands exec include show aaa local
commands exec include show aaa
wireless aaa policy default-aaa-policy
aaa-override

I am not sure if I have to add or modify something else on ISE side or on the WLC.

Any thought?

Thanks in advance

 

0 RESPUESTAS 0