Troubleshoot Zero Touch Deployment
Problem
Unable to find the process for Zero Touch Deployment (ZTD) related to tunnel provisioning in a network setup.
Solution
Here are the steps involved in ZTD for tunnel provisioning:
-
Register your device on Cisco IoT FND.
-
Ensure that the FAR is booted and connected to WAN.
-
Obtain the initial configuration settings.
-
Request a Local Device Identifier (LDevID) certificate from a Public Key Infrastructure (PKI) or Registration Authority (RA).
-
Communicate with the Tunnel Provisioning Service (TPS) to initiate tunnel setup.
-
Establish a FlexVPN tunnel to the HER.
-
The FAR contacts the Cisco IoT FND for device registration.
-
The configuration is sent from Cisco IoT FND to FAR.
-
The FAR is fully operational and registered in the Cisco IoT FND.
Here's an example tunnel provisioning log:
Received tunnel provisioning request from [IR1101-K9+FCW22520078]
Adding tunnel provisioning request to queue for FAR ID=
Provisioning tunnels on element [IR1101-K9+FCW22520078]
Retrieved current configuration of element [IR1101-K9+FCW22520078] before tunnel provisioning
Retrieved status of file [flash:/before-registration-config] on [IR1101-K9+FCW22520078]. File does not exist
Retrieved status of file [flash:/before-tunnel-config] on [IR1101-K9+FCW22520078]. File does not exist.
Copied running-config of [IR1101-K9+FCW22520078] to [flash:/before-tunnel-config]
Opened a NETCONF session with element [HTABT-TGOT-DC-RT1] at [163.88.181.2]
Sending [show interfaces | include Description: | Encapsulation | address is | line protocol | packets input, | packets output, | Tunnel protection | Tunnel protocol| Tunnel source] to element [HTABT-TGOT-DC-RT1]
Received response to [show interfaces | include Description: | Encapsulation | address is | line protocol | packets input, | packets output, | Tunnel protection | Tunnel protocol| Tunnel source] from element [HTABT-TGOT-DC-RT1]
Sending [show ip nhrp | include ^[0-9A-F]| Tunnel| NBMA] to element [HTABT-TGOT-DC-RT1]
Received response to [show ip nhrp | include ^[0-9A-F]| Tunnel| NBMA] from element [HTABT-TGOT-DC-RT1]
Sending [show ipv6 nhrp | include ^[0-9A-F]| Tunnel| NBMA] to element [HTABT-TGOT-DC-RT1]
Received response to [show ipv6 nhrp | include ^[0-9A-F]| Tunnel| NBMA] from element [HTABT-TGOT-DC-RT1]
Sending [show ipv6 interface | include address | protocol | subnet] to element [HTABT-TGOT-DC-RT1]
Received response to [show ipv6 interface | include address | protocol | subnet] from element [HTABT-TGOT-DC-RT1]
Closed NETCONF session with element [HTABT-TGOT-DC-RT1]
Obtained current configuration of element [HTABT-TGOT-DC-RT1] before tunnel provisioning
Configured tunnels on [IR1101-K9+FCW22520078]
Retrieved current configuration of element [IR1101-K9+FCW22520078] after tunnel provisioning.
Processed tunnel template for element [ASR1001+93UA2TVWZAR]. Time to process [5 ms].
Configured element [IR1101-K9+FCW223700AG] to register with IoT-FND at [https://10.48.43.229:9121/cgna/ios/registration]
Note |
|