Soru

Zorluk: Çok zorCisco DNA Center Enabled Device Management

An enterprise network engineer successfully performs discovery and inventory integration for a Cisco Catalyst 9300 switch within Cisco DNA Center using SNMPv3 and SSH credentials. In the Cisco DNA Center inventory, the switch shows a status of Reachable. However, when navigating to the Assurance dashboard, the overall health score for the switch continuously reads N/A, and no telemetry data or health metrics are displayed. Further inspection shows that ICMP, SSH (TCP port 22), and SNMPv3 (UDP port 161) traffic are completely permitted through firewalls between Cisco DNA Center and the switch. Which condition is the most likely root cause for the missing Assurance health metrics?

  1. NETCONF traffic over TCP port 830 is blocked by an intervening security policy, preventing Cisco DNA Center from deploying telemetry profiles and establishing model-driven telemetry subscriptions.Cevap
  2. B
    The network switch requires an HTTP POST API call to be manually dispatched from its local IOS XE CLI prompt to register its REST endpoint with Cisco DNA Center.
  3. C
    Cisco DNA Center requires an agent daemon to be installed inside a Linux container on the switch using an agent-based Ansible playbook before telemetry data streaming can start.
  4. D
    Global LLDP is disabled on the Catalyst switch, which prevents Cisco DNA Center from learning the switch's IP routing table and streaming health telemetry.

Cevap

The missing Assurance metrics are caused by NETCONF traffic over TCP port 830 being blocked by an intervening security policy, which prevents Cisco DNA Center from deploying telemetry profiles and establishing model-driven telemetry subscriptions.
Cisco DNA Center uses NETCONF (TCP port 830) to push network telemetry profiles and configure model-driven telemetry streaming on Catalyst switches. When SSH and SNMP are allowed, basic reachability and discovery succeed; however, if TCP port 830 is blocked by a firewall, Cisco DNA Center cannot apply the necessary telemetry subscriptions, causing the Assurance dashboard to report a health score of N/A.

Adım Adım Çözüm

1
Analyze the management channels used by Cisco DNA Center.
Inventory discovery and basic status check rely on SSH (TCP 22) and SNMP (UDP 161), both of which are functioning.
This explains why the switch appears as Reachable in the inventory despite lacking telemetry metrics.
2
Identify the protocol requirements for Cisco DNA Center Assurance telemetry deployment.
Cisco DNA Center configures and subscribes to telemetry metrics on IOS XE switches via NETCONF using TCP port 830.
Model-driven telemetry and telemetry profile provisioning fail if NETCONF communication over TCP port 830 is blocked between the controller and managed devices.
3
Evaluate why alternative causes are incorrect.
Cisco DNA Center is controller-based and agentless, so manual HTTP POST dispatches from switch CLI or Ansible agent containers are inaccurate.
Understanding controller-led agentless workflows isolates port-blocking as the true failure point.

Anahtar Kavram

Cisco DNA Center Assurance and Model-Driven Telemetry Provisioning
Tahmini Süre:2m 30s
Bu soruyu puanla