10-28-2016 04:20 AM - edited 03-01-2019 04:32 AM
Hi,
after upgrading (reinstalling) from EM 1.2 version to 1.3 we have tried to deploy IWAN with 2 remote Sites and 2 Service Provider (DCs)
and have no problems deploying HUB site but we have an issue with TRANIST-HUB-1 with these error:
Router debug:
*Oct 27 13:08:25.251 GMT: CRYPTO_PKI: status = 0x747(E_EOS : end of i/o stream): Imported PKCS12 file failure
*Oct 27 13:08:25.251 GMT: %PKI-6-PKCS12IMPORT_FAIL: PKCS #12 Import Failed.
APIC-EM Audit:
Underlay and Overlay configuration in site TRANSIT-HUB-1 failed. PKI configuration failed for device 10.X.X.1
Failed to download PKCS12
We have tested this topology before with version 1.2 and was working as expected.
Any idea about it?
Thanks in advanced.
Solved! Go to Solution.
10-28-2016 09:23 AM
10-28-2016 09:23 AM
sorry, is resolved it was a routing EM issue.
Regards.
10-28-2016 11:08 AM
So long as the correct configuration is pushed from apic-em-pki-broker service through apic-em-network-programmer on behalf of iWAN Manager (visibility-service), the actual download of PKCS12 certs would depend on routing and firewalling etc. between the actual device and APIC-EM controller.
08-17-2017 01:28 PM
Can you be more specific on the fix? I am running into the same issue.
Thanks,
Alex
08-18-2017 08:28 PM
make sure you have reachability from APIC-EM via both underlay and overlay IP address ranges on the device.
08-31-2017 07:02 AM
If the device is only accessible from a public IP, how can the underlay and overlay IP address ranges be reachable before the DMVPN tunnel is created?
07-16-2018 04:17 PM
Hello.. did you get an answer for this ?
i am also in same fix, please suggest
07-16-2018 04:20 PM
hello.. can you elaborate please, I am able to ping my remote site devices from APIC EM and vice versa.
I already provisioned 3 sites with same settings, no version change on APIC EM but started getting message like.
08-01-2018 01:05 PM
Hello!
Can you help me with this?, I have the same problem so I need to know how you resolved the problem, I will appreciate any help.
Thank you,
08-01-2018 01:35 PM
08-01-2018 01:40 PM
cchitnis Thanks for you reply,
The problem is, I have connectivity from APIC to the Branch my error is the next:
Underlay and overlay configuration in site xxx failed
PKI configuration failed for device Y.Y.Y.Y
Even the branch wan not configured with the lookback interface, the APIC was no able to push any kind of configuration into de branch.
Best Regards,
08-02-2018 06:54 AM
You are probably running into https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvk38328
...TAC can help you to fix this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide