Out of band management interface on Catalyst 9200L running in Cloud Operating Mode

Yostie
Conversationalist

Out of band management interface on Catalyst 9200L running in Cloud Operating Mode

We are currently testing Catalyst 9200L with IOS-XE 17.15.3 in Meraki Cloud Operating mode.  Converting the switch to Meraki mode was easy.  I do have a question about dashboard connectivity options.  When we converted, it created a VLAN1 SVI and connected to the Dashboard right away.  I am trying to set up an automated testing environment and my preference would be to have any switch we are working with(9200 now, 9300 in the future, both L2 and L3 use cases) use the out of band management interface to connect to the Meraki Dashboard to keep the dashboard management traffic completely separate from data plane traffic so changes can be made and not have to worry about losing dashboard connectivity.

 

Is this possible or am I limited to using an SVI to talk to the Dashboard?  Is creating a VRF, putting the management SVI into that VRF, and talking to the Dashboard that way possible?

4 Replies 4
Mloraditch
Kind of a big deal
Kind of a big deal

Using the OOB port is not possible.

 

As to VRFs it feels like that may work but the feature only became available earlier this week and the documentation doesn’t address it. 

 

https://documentation.meraki.com/MS/Layer_3_Switching/VRF

 

If you have a lab switch perhaps put the 17.18.1 beta on and see if it works!

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
CKnetworking
Comes here often

Hi,

 

out of curiosity, I gave it a try in my lab with a Catalyst 9300 and IOS XE 17.18.1 beta: It doesn't work. As soon as you select a VRF other than the default one in the interface editor, the "Uplink" option gets greyed out (and automatically deselected if you've selected it before setting a custom VRF).

 

Best regards,

Chris

GIdenJoe
Kind of a big deal
Kind of a big deal

The OOB port is actually being used for the local status page in addition to the front pages on the separate IP.  In the current implementation you can't have the management on another VRF.

DarrenOC
Kind of a big deal
Kind of a big deal

I obviously don’t know your environment but could you keep this simple and use a single interface on your switch purely for management and have that connected directly into your firewall/upstream device?  This way you can control changes to all other ports just as long as you don’t push anything to that uplink?

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Get notified when there are additional replies to this discussion.