Cloud Management with Device Configuration Support for C9500H Series - Feedback

bradly
Here to help

Cloud Management with Device Configuration Support for C9500H Series - Feedback

Hi, 

 

We have been testing onboarding our C9500-24Y4C Series switches running IOS XE 17.15.4 into Meraki Cloud Management with Device Configuration. 

 

It mostly works, the onboarding is successful and we can see our switch in the dashboard. We can view the configuration, event logs, device health, port status etc. However, usage and client data is unavailable. 

 

So, I had a look at the device's configuration, and it appears to be missing a lot of configurations that are 'required' for Meraki Cloud Management (according to Cloud Management with Device Configuration Required Modifications - Cisco Meraki Documentation) 

 

I compared our C9500's with our C9300 Series switches onboarded into Cloud Management with Device Configuration, running IOS XE 17.15.4 as well, along with the documentation linked above, and made a note of the following that appears to be missing: 

 

1. TRAFFIC ANALYTICS (NETFLOW) - COMPLETELY MISSING
------------------------------------------------

Missing Global Commands:
- flow record MERAKI_TA1_V4_IN
- flow record MERAKI_TA1_V4_OUT
- flow exporter MERAKI_TA1
- flow monitor MERAKI_TA1_V4_IN
- flow monitor MERAKI_TA1_V4_OUT

Missing on ALL Interfaces (49 total):
- ip flow monitor MERAKI_TA1_V4_IN input
- ip flow monitor MERAKI_TA1_V4_OUT output


2. DEVICE TRACKING POLICIES - COMPLETELY MISSING
---------------------------------------------

Missing Global Commands:
- device-tracking tracking auto-source
- device-tracking policy MERAKI_ACCESS_TRACK
- device-tracking policy MERAKI_NO_TRACK
- device-tracking policy MERAKI_TRUNK_TRACK

Missing on ALL Interfaces:
- device-tracking attach-policy [policy-name]


3. AAA YANG AUTHORIZATION - MISSING
--------------------------------

Edit: Ignore '3.' not part of required configuration. 

Missing Command:
- yang-interfaces aaa authorization method-list MERAKI


4. IPv6 MANAGEMENT ROUTE - MISSING
-------------------------------

Missing Command:
- ipv6 route FD0A:9B09:1F7:1::/64 Null0 2


5. SNMP SYSLOG TRAPS - PARTIALLY MISSING
-------------------------------------

Missing Commands:
- logging history informational
- logging snmp-trap emergencies
- logging snmp-trap alerts
- logging snmp-trap critical
- logging snmp-trap errors
- logging snmp-trap warnings
- snmp-server enable traps syslog


6. DEVICE CLASSIFIER - MISSING
---------------------------

Missing Command:
- device classifier

 

 

Just wanted to see if anyone else has been testing onboarding C9500H Series switches into Cloud Management with Device Configuration, running IOS XE 17.15.4 as well - are you seeing the same or similar results? 

 

Edit: Just to clarify, I have confirmed the following prerequisites have been met

 

Prerequisites

  • Uplink connectivity (from the switch to the cloud and not connectivity to the computer being used) must be via a front-panel port (not the management interface).
  • Only the default VRF is supported.
  • Ensure routes are in place to reach external addresses including a default route (use of ip default-gateway is not supported). 
  • IP routing (ip routing) must be enabled on the switch. 
  • AAA on the switch must be configured using aaa new-model. 
  • aaa authentication login default local and aaa authorization exec default local must be configured. 
  • The user account for onboarding must have privilege-15 level access on the switch. 
  • The Meraki Tunnel only supports the Global VRF. 
  • Domain Name Lookup is required for hostname resolution to the Dashboard Registration and Meraki Tunnel services 
    • ip name-server {Domain server IP address}
    • ip domain lookup
  • The switch clock must reflect the correct current time in order to establish a mutual TLS tunnel with the Registration and Meraki Tunnel services by enabling NTP services. 
    • ntp server {ntp server IP address}
  • Our C9300 and C9500 are both licenced with Advantage licencing. 

 

 

 

4 Replies 4
bradly
Here to help

Doing another test, I just noticed something. 

 

I finally saw some device-tracking configuration applied when onboarding. However, it only applied it to interfaces (trunk and access ports) not part of a port-channel. Also, it didn't apply all the required device-tracking configuration that should be applied (as per Cloud Management with Device Configuration Required Modifications). 

 

@Meraki Is that deliberate behaviour? 

GIdenJoe
Kind of a big deal
Kind of a big deal

Wasn't there a technical issue what the entire 9500H series with UADP chips to be doing client analytics on?  Usually the clients live on the 9400/9300/9200 and those platforms should fully support the clients traffic analytics.

Brash
Kind of a big deal
Kind of a big deal

I've got some C9500-48Y4C in Meraki, but they were onboarded back in the original Meraki monitor mode. I haven't yet switched them to the new onboarding method.

The main caveat I can recall was that client stats required DNA advantage licensing.

 

Looking at the new guide for Cloud Management with Device Configuration, there is a note that implies that device tracking configuration is not modified.

 

During onboarding of a C9500 to Device Configuration mode, device tracking will not be modified. Users can choose to modify it via CLI after onboarding. 

Enable Cloud Management for Catalyst Switches with Device Configuration - Cisco Meraki Documentation


I do vaguely recall having to attach device tracking policies to some interfaces but I don't remember which ones or why. I certainly didn't have to build it out from scratch.

bradly
Here to help

Just to clarify, I have confirmed the following prerequisites have been met

 

Prerequisites

  • Uplink connectivity (from the switch to the cloud and not connectivity to the computer being used) must be via a front-panel port (not the management interface).
  • Only the default VRF is supported.
  • Ensure routes are in place to reach external addresses including a default route (use of ip default-gateway is not supported). 
  • IP routing (ip routing) must be enabled on the switch. 
  • AAA on the switch must be configured using aaa new-model. 
  • aaa authentication login default local and aaa authorization exec default local must be configured. 
  • The user account for onboarding must have privilege-15 level access on the switch. 
  • The Meraki Tunnel only supports the Global VRF. 
  • Domain Name Lookup is required for hostname resolution to the Dashboard Registration and Meraki Tunnel services 
    • ip name-server {Domain server IP address}
    • ip domain lookup
  • The switch clock must reflect the correct current time in order to establish a mutual TLS tunnel with the Registration and Meraki Tunnel services by enabling NTP services. 
    • ntp server {ntp server IP address}
  • Our C9300 and C9500 are both licenced with Advantage licencing. 
Get notified when there are additional replies to this discussion.