Hi
is there a knob in DNAC to change the direction in how DNA Center puts the Image onto the Router or Switch ?
If I interpret this error message correctly i would say : The router tries to establish a https or scp session to the DNAC to download the IOS Image. But that´s not a great Idea from a security perspective to establish sessions from OUTSIDE routers to a INSIDE DNAC. I would prefer that DNAC put´s the file to the Switch instead of the Switch tries to get the file from the DNAC. And if you have a firewall in between you already have a rule that allows ssh/scp from DNAC to the Switch
Error Message from DNAC while doing a Image Update Readiness Check
File Transfer Check
Unable to download file using HTTPs and SCP from source : 1.2.3.4 DNAC-CA certificate is present on the device. Please check the device connectivity.
Expected: Device need to have https/scp reachability to Controller
Action: Verify HTTPS/SCP configurations, Cisco DNA Center certificates on device and protocol reachability. Also, try with turning on Compatibility Mode from 'Image Distribution Servers' Settings page
regards Markus