Configure the Cisco DNA Center Appliance

Similar documents
Configure the Cisco DNA Center Appliance

Configure the Cisco DNA Center Appliance

Release Notes for Cisco Application Policy Infrastructure Controller Enterprise Module, Release x

Cisco Digital Network Architecture Center Appliance Installation Guide, Release 1.0

Troubleshooting Cisco APIC-EM Single and Multi-Host

Troubleshooting Cisco APIC-EM Multi-Host

Configuring Cisco Mobility Express controller

SUSE Cloud Admin Appliance Walk Through. You may download the SUSE Cloud Admin Appliance the following ways.

Installing Cisco APIC-EM on a Virtual Machine

Chapter 10 Configure AnyConnect Remote Access SSL VPN Using ASDM

Cisco Prime Collaboration Deployment

Lab - Connect to a Router for the First Time

Deploying Cisco UCS Central

Installation of Cisco Business Edition 6000H/M

Installing the Cisco Virtual Network Management Center

Lab - Configure Wireless Router in Windows

Installation and Upgrade

IBM Single Sign On for Bluemix Version December Identity Bridge Configuration topics

VMware vsphere 5.5: Install, Configure, Manage Lab Addendum. Lab 3: Configuring VMware ESXi

Installation. Power on and initial setup. Before You Begin. Procedure

Connectra Virtual Appliance Evaluation Guide

VMware Identity Manager Connector Installation and Configuration (Legacy Mode)

Configuring the SMA 500v Virtual Appliance

Create a pfsense router for your private lab network template

Installing CMX 10.5 on Cisco MSE 3375

Chapter 10 - Configure ASA Basic Settings and Firewall using ASDM

ACE Live on RSP: Installation Instructions

Installing and Configuring vcloud Connector

Settings. IP Settings. Set Up Ethernet Settings. Procedure

Installation of Cisco HCM-F

Installing or Upgrading ANM Virtual Appliance

EdgeConnect for Amazon Web Services (AWS)

Installing Cisco MSE in a VMware Virtual Machine

Pexip Infinity and Amazon Web Services Deployment Guide

Installing Cisco StadiumVision Director Software from a DVD

Overview of the Cisco NCS Command-Line Interface

Installing and Configuring vcloud Connector

Installation. Installation Overview. Installation and Configuration Taskflows CHAPTER

Upgrading the Cisco APIC-EM Deployment

System Setup. Accessing the Administration Interface CHAPTER

Deploy the ExtraHop Discover 3100, 6100, 8100, or 9100 Appliances

UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0)

Connect the Appliance to a Cisco Cloud Web Security Proxy

Network Configuration Sheet

The Balabit s Privileged Session Management 5 F5 Azure Reference Guide

dctrack Quick Setup Guide (Recommended) Obtain a dctrack Support Website Username and Password

UDP Director Virtual Edition

GSS Administration and Troubleshooting

ARCSERVE UDP CLOUD DIRECT DISASTER RECOVERY APPLIANCE VMWARE

ForeScout CounterACT. Single CounterACT Appliance. Quick Installation Guide. Version 8.0

Configuring the Cisco TelePresence System

6.1. Getting Started Guide

NSX-T Data Center Migration Coordinator Guide. 5 APR 2019 VMware NSX-T Data Center 2.4

Deploy the ExtraHop Discover Appliance 1100

CSPC OVA Getting Started Guide

Proofpoint Threat Response

Cisco CSPC 2.7.x. Quick Start Guide. Feb CSPC Quick Start Guide

Configuring the Fabric Interconnects

Deploying the Cisco ASA 1000V

dctrack Quick Setup Guide Virtual Machine Requirements Requirements Requirements Preparing to Install dctrack

Deployment of FireSIGHT Management Center on VMware ESXi

Chapter 10 Configure Clientless Remote Access SSL VPNs Using ASDM

Managing the Cisco APIC-EM and Applications

Installing Your System Using Manual Deployment

Redhat OpenStack 5.0 and PLUMgrid OpenStack Networking Suite 2.0 Installation Hands-on lab guide

Cisco Mini ACI Fabric and Virtual APICs

Threat Response Auto Pull (TRAP) - Installation Guide

CHAPTER 7 ADVANCED ADMINISTRATION PC

LevelOne FBR User s Manual. 1W, 4L 10/100 Mbps ADSL Router. Ver

Security Gateway for OpenStack

The following topics explain how to get started configuring Firepower Threat Defense. Table 1: Firepower Device Manager Supported Models

ECDS MDE 100XVB Installation Guide on ISR G2 UCS-E and VMWare vsphere Hypervisor (ESXi)

Cisco VDS Service Broker Software Installation Guide for UCS Platforms

Chapter 10 Configure Clientless Remote Access SSL VPNs Using ASDM

Configuring High Availability (HA)

QUICK SETUP GUIDE VIRTUAL APPLIANCE - VMWARE, XEN, HYPERV CommandCenter Secure Gateway

CounterACT 7.0. Quick Installation Guide for a Single Virtual CounterACT Appliance

Microsoft Hyper-V. Installation Guide

VSEC FOR OPENSTACK R80.10

Upgrading the Cisco APIC-EM Deployment

Controller Installation

Installing Cisco WebEx Social

Infoblox Trinzic V-x25 Series Appliances for AWS

Cisco Unified Operating System Administration Web Interface

Cisco Unified Operating System Administration Web Interface for Cisco Emergency Responder

Pexip Infinity and Google Cloud Platform Deployment Guide

Using SSL to Secure Client/Server Connections

Migrate Data from Cisco Secure ACS to Cisco ISE

Initial Configuration for the Switch

Installing the Cisco Nexus 1000V Software Using ISO or OVA Files

Configuring the Switch with the CLI Setup Program

Configure HyperFlex Hardware Acceleration Cards

Cisco Emergency Responder Installation

Configuring the Cisco APIC-EM Settings

MediaSense Installation

American Dynamics RAID Storage System iscsi Software User s Manual

Virtual Appliance User s Guide

VPN Solutions for Zerto Virtual Replication to Azure. IPSec Configuration Guide

SOA Software API Gateway Appliance 6.3 Administration Guide

Deploy the ExtraHop Trace 6150 Appliance

Transcription:

Review Cisco DNA Center Configuration Wizard Parameters, page 1 Configure Cisco DNA Center Using the Wizard, page 5 Review Cisco DNA Center Configuration Wizard Parameters When Cisco DNA Center configuration begins, an interactive configuration wizard prompts you to enter configuration information. The following table displays the information for which the wizard will prompt you, and which you will need to supply in order to complete the configuration. Ensure that the DNS and NTP servers are reachable before you run the configuration wizard and whenever you reboot the DNA Center appliance. Table 1: Cisco DNA Center Configuration Wizard Parameters Configuration Wizard Prompt Description Example Host IP address Enter a host IP address for the NIC that 10.0.0.12 connects the appliance to the network. This host IP address must be a valid IPv4 address. Virtual IP Leave blank. The Virtual IP is used only Does not apply in deployments involving multiple DNA Center hosts, which is not supported in this release. Netmask Enter a netmask for the IP address. 255.255.255.0 This must be a valid IPv4 netmask. Default Gateway IP address Enter a default gateway IP address. 10.12.13.1 This must be a valid IPv4 address for the default gateway. 1

Review Cisco DNA Center Configuration Wizard Parameters Configuration Wizard Prompt DNS Servers Description Enter a DNS server address. This must be a valid IPv4 address for the primary DNS server. Enter either a single IP address for a single primary server, or multiple IP addresses separated by spaces for multiple DNS servers. Example 10.15.20.25 Static Routes Enter the IP address and subnet mask for a manually specified route for this interface. We recommend that you always specify at least one static route for the interface connecting to the fabric underlay. 204.2.0.0/255.255.0.0 Enter either a single IP address and subnet mask for a single static route, or a space-separated list of multiple IP addresses/masks for multiple static routes. CCO Username CCO Password Company Name Enter a Cisco Connection Online (CCO) username for cloud connectivity. This should be a CCO username your organization uses to access restricted locations on the CCO web site as either a Cisco customer or partner. Enter the password for the CCO Username you entered. Enter the name of your organization. MyCCOUserName MyPass201$ Acme Desert Supplies 2

Review Cisco DNA Center Configuration Wizard Parameters Configuration Wizard Prompt Linux Password Description Enter a Linux password. Identifies the Linux Grapevine password that is used for CLI access to the Grapevine roots and clients. This is the password for the "grapevine" users. You must create this password because there is no default. The password must meet the following requirements: Eight character minimum length. Does NOT contain a tab or a line break. Does contain characters from at least three of the following categories: Uppercase alphabet Lowercase alphabet Numeral Special characters (for example,! or #) Example MyGVPass01 (Optional) Password Generation Seed (Optional) Auto Generated Password Instead of creating and entering your own Linux and Administrator passwords, you can enter a seed phrase and press Generate Password to have the configuration wizard generate a random and secure password using that seed phrase. If you choose to enter a seed phrase, the generated password will be displayed in the Auto Generated Password field, where you can further edit it. If you choose to enter a seed phrase, the generated password (including your seed phrase) will be displayed in this field. If desired, you can either use this password "as is", or you can further edit this auto generated password. You must select Use Generated Password to save the password and have it used automatically. WhenAprilLastInDooryard 3

Review Cisco DNA Center Configuration Wizard Parameters Configuration Wizard Prompt Administrator Username Description Enter the administrator user name. Identifies the administrative username used for GUI access to Cisco DNA Center. We recommend that the username be three to eight characters in length and be composed of valid alphanumeric characters (A Z, a z, or 0 9). Example admin2780 Administrator Password Enter the admin password. Identifies the password used for GUI access to DNA center. You must create this password because there is no default. The password must meet the following requirements: Eight character minimum length. Does NOT contain a tab or a line break. Does contain characters from at least three of the following categories: Uppercase alphabet Lowercase alphabet Numeral Special characters (for example,! or #) MyIseYPass2 NTP Servers Enable IPSec Encryption Enter a primary NTP server address. This must be a valid IPv4 address or hostname of a Network Time Protocol (NTP) server. Before you deploy DNA Center, make sure that the time on the DNA Center appliance system clock is current and that you are using a Network Time Protocol (NTP) server that is keeping the correct time. Enter No. Encryption is used only in a multihost cluster deployment, which is not supported in this release. 10.12.13.10 Enter either a single IP address for a single NTP primary server, or multiple IP addresses separated by spaces for several NTP servers. We recommend that you configure three NTP servers for your deployment. No 4

Configure Cisco DNA Center Using the Wizard Configuration Wizard Prompt Description Example Harvest All Virtual Disks Delete All Users Enter No. This feature is used only when cleaning up a previous installation. Since this is a new install, there is no need to employ it. Enter No. This feature is used only when cleaning up a previous installation. Since this is a new install, there is no need to employ it. No No Configure Cisco DNA Center Using the Wizard Perform the steps below to configure the DNA Center appliance as a single host. The entire process takes over an hour, with the installation of component packages (after your final review of all the wizard settings) taking approximately 45 minutes. Before You Begin Be sure that you have: Configured CIMC for use with the appliance. See Configure CIMC. Used CIMC to configure the appliance hardware. See Use CIMC to Configure the Appliance. Reviewed and gathered appropriate information about the parameters for which the configuration wizard will prompt you. See Review Cisco DNA Center Configuration Wizard Parameters, on page 1. Step 1 Step 2 Step 3 Step 4 Boot up the host. Review the DNA License Agreement screen that appears and choose either <view license agreement> to review the license agreement or accept>> to accept the license agreement and proceed. You will not be able to proceed without accepting the license agreement. After accepting the license agreement, you are then prompted to select a configuration option. Review the Welcome to the DNA Center Configuration Wizard! screen and choose the Create a new DNA Center cluster option to begin. Enter configuration values for the NETWORK ADAPTER #1 on the host. The configuration wizard discovers and prompts you to confirm values for the network adapter or adapters on your host. Host IP address Enter the host IP address for the NIC that connects the appliance to the network. The configuration wizard validates the value entered and issues an error message if incorrect. If you receive an error message for the host IP address, check that eth0 is connected to the correct network adapter. 5

Configure Cisco DNA Center Using the Wizard Virtual IP Netmask Default Gateway IP address DNS Servers Static Routes Leave blank. This is used only in multihost cluster deployments. Enter the netmask for the network adapter's IP address. Enter a default gateway IP address to use for the network adapter. If no other routes match the traffic, traffic will be routed through this IP address. Enter the DNS server or servers IP addresses (separated by spaces) for the network adapter. If required for your network, enter a space separated list of static routes in this format: <network>/<netmask>/<gateway> Static routes, which define explicit paths between two routers, cannot be automatically updated; you must manually reconfigure static routes when network changes occur. You should use static routes in environments where network traffic is predictable and where the network design is simple. You should not use static routes in large, constantly changing networks because static routes cannot react to network changes. Once satisfied with the network adapter settings, enter next>> to proceed. After entering next>>, the configuration wizard proceeds to validate the values you entered. After validation, you are prompted to enter values for NETWORK ADAPTER #2 (eth1). If you are using two NICs to connect the appliance to your network, configure the second NIC as you did for Network Adapter #1 (eth0), then enter next>> to proceed Step 5 Enter configuration values for CLOUD CONNECTIVITY. CCO Username Enter a Cisco Connection Online (CCO) username for cloud connectivity. For example, enter the username that you use to log into the Cisco website to access restricted locations as either a Cisco customer or partner. If you do not have a CCO username and password, then enter your company name in the username and company name fields and leave the password field empty for this step. This will permit you to proceed through the config-wizard process. Values entered for this step are used for telemetry collection. For information about telemetry collection, see the Cisco DNA Center User Guide. 6

Configure Cisco DNA Center Using the Wizard CCO Password Enter a Cisco Connection Online (CCO) password for the CCO username. For example, enter the password that you use to log into the Cisco website to access restricted locations as either a Cisco customer or partner. Once satisfied with the cloud connectivity settings, enter next>> to proceed. After entering next>>, the configuration wizard proceeds to validate the values entered. After validation, you are then prompted to enter values for the LINUX USER SETTINGS. Step 6 Enter configuration values for the LINUX USER SETTINGS. Linux Password Enter a Linux password. The Linux password is used to ensure security for both the Grapevine root and clients located on the host. Access to the Grapevine root and clients requires this password. The default username is grapevine and cannot be changed The Linux password is encrypted and hashed in the controller database. Re-enter Linux Password Seed Phrase Password Generation Auto Generated Password Confirm the Linux password by entering it a second time. (Optional) Instead of creating and entering your own password in the above Linux Password fields, you can enter a seed phrase and have the configuration wizard generate a random and secure password using that seed phrase. Enter a seed phrase and then press <Generate Password> to generate the password. (Optional) The seed phrase appears as part of a random and secure password. If desired, you can either use this password "as is", or you can further edit this auto generated password. Press <Use Generated Password> to save the password. When finished with the password, be sure to save it to a secure location for future reference. After configuring the Linux password, enter next>> to proceed. After entering next>>, you are then prompted to enter values for the DNA CENTER ADMIN USER SETTINGS. Step 7 Enter configuration values for the DNA CENTER ADMIN USER SETTINGS. 7

Configure Cisco DNA Center Using the Wizard Administrator Username Administrator Password Re-enter Administrator Password Password Generation Seed Auto Generated Password Enter an administrator username. Your administrator username and password are used to ensure security for the appliance itself. Access to the appliance GUI requires that you enter this username and password. Enter an administrator password. The administrator password is encrypted and hashed in the controller database. Confirm the administrator password by entering it a second time. (Optional) Instead of creating and entering your own password in the above Administrator Password fields, you can enter a seed phrase and have the configuration wizard generate a random and secure password using that seed phrase. Enter a seed phrase and then press <Generate Password> to generate the password. (Optional) The seed phrase appears as part of a random and secure password. If desired, you can either use this password "as is", or you can further edit this auto generated password. When finished with the password, be sure to save it to a secure location for future reference. Press Use Generated Password to save the password. After configuring the administrator password, enter next>> to proceed. After entering next>>, you are then prompted to enter values for b NTP SERVER SETTINGS. Step 8 Enter configuration values for NTP SERVER SETTINGS. NTP servers Enter a single NTP server address or a list of NTP servers, each separated by a space. The Elastic Services Platform (Grapevine) manages a Network Time Protocol (NTP) server to provide time synchronization for the Grapevine clients. You must configure the NTP server for the clients. The NTP server is external to the cluster. We recommend that, for redundancy purposes, you configure at least three NTP servers for your deployment. Cisco routers and switches can also be configured as NTP servers. 8

Configure Cisco DNA Center Using the Wizard After configuring the NTP server(s), enter next>> to proceed. After entering next>>, you are then prompted to enter values for INTER-HOST COMMUNICATION. Step 9 Enter configuration values for INTER-HOST COMMUNICATION. Enable IPSec Encryption Enter No. This feature is used only between hosts in a multi-host cluster. Once satisfied with the inter-host communication setting, enter next>> to proceed. After entering next>>, the configuration wizard proceeds to validate the values you entered. Step 10 Enter configuration values for CONTROLLER CLEAN-UP. Harvest All Virtual Disks Entering yes will delete all Grapevine virtual disks that belong to the controller for this specific deployment. For an initial configuration, enter no. Delete All Clients Entering yes will delete all Grapevine clients that belong to the controller for this specific deployment. For an initial configuration, enter no. For an initial configuration, enter no for both options. After configuring the controller clean-up, enter next>> to proceed. After entering next>>, you are then prompted to enter values to finish the configuration and begin the configuration wizard installation. Step 11 A final message appears stating that the wizard is now ready to proceed with applying the configuration. The following options are available: [back] Review and verify your configuration settings. [cancel] Discard your configuration settings and exit the configuration wizard. [save & exit] Save your configuration settings and exit the configuration wizard. [proceed] Save your configuration settings and begin applying them. Enter proceed>> to complete the installation. After entering proceed>>, the configuration wizard applies the configuration values that you entered above. At the end of the configuration process, a CONFIGURATION SUCCEEDED! message appears, with IP addresses for the DNA Center host GUI and the Grapevine Web Console. Step 12 Step 13 Step 14 Open your compatible web browser and enter the DNA Center host IP address to access the DNA Center GUI. For compatible browsers, see Access Cisco DNA Center Using a Web Browser. After entering the IP address in the browser, a message stating that "Your connection is not private" appears. Ignore the message and click the Advanced link. After clicking the Advanced link, a message stating that the site s security certificate is not trusted appears. 9

Configure Cisco DNA Center Using the Wizard Ignore the message and click the link. This message appears because the controller uses a self-signed certificate. You will have the option to upload a trusted certificate using the controller GUI after installation completes. Step 15 In the Cisco DNA Center Login window, enter the administrator username and password that you configured earlier and click the Log In button. What to Do Next When these tasks are complete: 1 Integrate DNA Center with Cisco Identity Services Engine (ISE). This is a standard requirement for nearly all DNA Center deployments. See Integrate Cisco ISE With DNA Center. 2 Start to use DNA Center to manage and configure your network. For assistance with navigating the GUI and becoming familiar with its features, see the Cisco DNA Center User Guide. 10