cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1071
Views
5
Helpful
2
Replies

Netconf Connection failure

JohnJudi
Beginner
Beginner

Hi Friends,

In my inventory list in DNAC, I have three switches with error Netconf connection failure in manageability column. I checked and did all the things that DNAC suggested. But I still have this error. In addition , I have below log in CLI:

 

66495: 066422: Mar 27 08:20:37.484: Switch 1 R0/0: ncsshd_bp: NETCONF/SSH: fatal: mm_answer_sign: Xkey_sign failed: error in libcrypto

 

DNA Software version is 2.2.3.4 and switch IOS-XE version is 17.3.3

I searched and found a bug related to this error.

Bug search.jpeg

 the screenshots of error.

netconf.PNG

netconf2.PNG

 

Do you have any idea to solve this problem?

 

thank you in advance for reply

 

 

1 Accepted Solution

Accepted Solutions

Dan Rowe
Cisco Employee
Cisco Employee

For the quickest resolution, I recommend opening up a TAC case to have them assist with performing the necessary debugs and troubleshooting to provide a root cause. This is a fairly common error that TAC is used to troubleshooting. This error is typically seen when the key to the trustpoint tied to the http/netconf process is incorrect or missing. 

 

When troubleshooting netconf issues, I like to take a tcpdump on the DNAC CLI along with capturing the following logs from the switch:

 

debug netconf-yang level debug
debug netconf all
show logging profile netconf internal level debug to-file flash:netconf.txt

 

I recommend collecting the debugs above & tcpdump from DNAC CLI in order to attach them to the TAC case you open.

View solution in original post

2 Replies 2

Dan Rowe
Cisco Employee
Cisco Employee

For the quickest resolution, I recommend opening up a TAC case to have them assist with performing the necessary debugs and troubleshooting to provide a root cause. This is a fairly common error that TAC is used to troubleshooting. This error is typically seen when the key to the trustpoint tied to the http/netconf process is incorrect or missing. 

 

When troubleshooting netconf issues, I like to take a tcpdump on the DNAC CLI along with capturing the following logs from the switch:

 

debug netconf-yang level debug
debug netconf all
show logging profile netconf internal level debug to-file flash:netconf.txt

 

I recommend collecting the debugs above & tcpdump from DNAC CLI in order to attach them to the TAC case you open.

cth
Beginner
Beginner

Hallo, i had this issue, too.

my solution was:

Inventory --> Actions --> Telemetry --> Update Telemetry Settings --> Check Box "Force Configuration Push" --> Next

wait five minutes and resync the Switch.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers