C9300 Onboard to Meraki - Can't use MGMT interface

Solved
JustinB
Comes here often

C9300 Onboard to Meraki - Can't use MGMT interface

I had the issue "Device is not eligible for onboarding. Reason: Unable to connect to TLS" with a Catalyst 9300 switch using the management interface for onboarding. On this platform, the management interface is dedicated to the Mgmt-vrf VRF.  Is this setup supported for onboarding?

 

Once I created a VLAN on the switch and connected the switch to the default VRF, then it was able to be onboarded.

 

Typically with Catalyst switches, we're often managing them from their MGMT port which is in the Mgmt-vrf.  If Meraki can't onboard a switch using this interface, it would be appreciated if the issue could be fixed and/or mention this in the release notes. Thank you!

 

-Justin

1 Accepted Solution
Jeff-L
Meraki Employee
Meraki Employee

Hi Justin, thanks for sharing this. We currently have this noted between #4 and #5 in the pre-onboarding checklist: "Connectivity must be via a front-panel port (not the management interface)."

 

Please let us know if you have any suggestions for improvement in the documentation or location of this note.

View solution in original post

2 Replies 2
Jeff-L
Meraki Employee
Meraki Employee

Hi Justin, thanks for sharing this. We currently have this noted between #4 and #5 in the pre-onboarding checklist: "Connectivity must be via a front-panel port (not the management interface)."

 

Please let us know if you have any suggestions for improvement in the documentation or location of this note.

JustinB
Comes here often

Thank you for clarifying.  I missed the "fine print".  It might not hurt in the doc to mention that the default VRF on the switch must also be used.  For example, if I had a front port in a different VRF than default, it probably wouldn't work -- the issue is the VRF on the switch in addition to port location.

 

I hope in future releases, the MGMT port will be supported since that is a very common way for Catalyst switches to be managed.

 

Thank you,

Justin

Get notified when there are additional replies to this discussion.