Table Of ContentConfiguration Guide for Cisco Network Plug and Play on Cisco
APIC-EM, Release 1.3.x
FirstPublished:2015-11-03
LastModified:2016-12-21
AmericasHeadquarters
CiscoSystems,Inc.
170WestTasmanDrive
SanJose,CA95134-1706
USA
http://www.cisco.com
Tel:408526-4000
800553-NETS(6387)
Fax:408527-0883
THESPECIFICATIONSANDINFORMATIONREGARDINGTHEPRODUCTSINTHISMANUALARESUBJECTTOCHANGEWITHOUTNOTICE.ALLSTATEMENTS,
INFORMATION,ANDRECOMMENDATIONSINTHISMANUALAREBELIEVEDTOBEACCURATEBUTAREPRESENTEDWITHOUTWARRANTYOFANYKIND,
EXPRESSORIMPLIED.USERSMUSTTAKEFULLRESPONSIBILITYFORTHEIRAPPLICATIONOFANYPRODUCTS.
THESOFTWARELICENSEANDLIMITEDWARRANTYFORTHEACCOMPANYINGPRODUCTARESETFORTHINTHEINFORMATIONPACKETTHATSHIPPEDWITH
THEPRODUCTANDAREINCORPORATEDHEREINBYTHISREFERENCE.IFYOUAREUNABLETOLOCATETHESOFTWARELICENSEORLIMITEDWARRANTY,
CONTACTYOURCISCOREPRESENTATIVEFORACOPY.
TheCiscoimplementationofTCPheadercompressionisanadaptationofaprogramdevelopedbytheUniversityofCalifornia,Berkeley(UCB)aspartofUCB'spublicdomainversionof
theUNIXoperatingsystem.Allrightsreserved.Copyright©1981,RegentsoftheUniversityofCalifornia.
NOTWITHSTANDINGANYOTHERWARRANTYHEREIN,ALLDOCUMENTFILESANDSOFTWAREOFTHESESUPPLIERSAREPROVIDED“ASIS"WITHALLFAULTS.
CISCOANDTHEABOVE-NAMEDSUPPLIERSDISCLAIMALLWARRANTIES,EXPRESSEDORIMPLIED,INCLUDING,WITHOUTLIMITATION,THOSEOF
MERCHANTABILITY,FITNESSFORAPARTICULARPURPOSEANDNONINFRINGEMENTORARISINGFROMACOURSEOFDEALING,USAGE,ORTRADEPRACTICE.
INNOEVENTSHALLCISCOORITSSUPPLIERSBELIABLEFORANYINDIRECT,SPECIAL,CONSEQUENTIAL,ORINCIDENTALDAMAGES,INCLUDING,WITHOUT
LIMITATION,LOSTPROFITSORLOSSORDAMAGETODATAARISINGOUTOFTHEUSEORINABILITYTOUSETHISMANUAL,EVENIFCISCOORITSSUPPLIERS
HAVEBEENADVISEDOFTHEPOSSIBILITYOFSUCHDAMAGES.
AnyInternetProtocol(IP)addressesandphonenumbersusedinthisdocumentarenotintendedtobeactualaddressesandphonenumbers.Anyexamples,commanddisplayoutput,network
topologydiagrams,andotherfiguresincludedinthedocumentareshownforillustrativepurposesonly.AnyuseofactualIPaddressesorphonenumbersinillustrativecontentisunintentional
andcoincidental.
CiscoandtheCiscologoaretrademarksorregisteredtrademarksofCiscoand/oritsaffiliatesintheU.S.andothercountries.ToviewalistofCiscotrademarks,gotothisURL:
http://www.cisco.com/go/trademarks.Third-partytrademarksmentionedarethepropertyoftheirrespectiveowners.Theuseofthewordpartnerdoesnotimplyapartnershiprelationship
betweenCiscoandanyothercompany.(1110R)
©2016CiscoSystems,Inc.Allrightsreserved.
CONTEN TS
PREFACE Preface v
Objectives v
ImportantInformationonFeatures v
RelatedDocumentation v
DocumentConventions vi
ObtainingDocumentationandSubmittingaServiceRequest viii
CHAPTER 1 NewandChangedInformation 1
CHAPTER 2 ConfiguringCiscoNetworkPlugandPlay 3
CiscoNetworkPlugandPlayOverview 3
CiscoNetworkPlugandPlayOrganization 4
CiscoNetworkPlugandPlayDashboard 5
ProjectPre-provisioningWorkflow 5
CreatingaProject 6
AddingaDevice 6
DeployingDevices 8
UsingConfigurationTemplate 8
CloningaProject 9
UnplannedDevicesWorkflow 10
ClaimingtheDevice 10
IgnoringUnclaimedDevices 11
UploadingtheCiscoDeviceImageFile 11
AssociatingtheDefaultImagetotheDevice 12
UploadingtheConfigurationFile 13
UploadingTemplates 13
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
iii
Contents
BulkImportProjectsandDevices 14
SecurityWorkflow 15
ViewingtheCiscoAPIC-EMCertificate 15
DeployingThird-PartyCA-SignedCertificateonCiscoAPIC-EM 15
UpdatingtheTrustpoolBundle 16
CreatinganInstallerRole 16
ConfiguringAAAontheDevice 17
TroubleshootingtheCiscoNetworkPlugandPlay 17
CollectingtheCiscoNetworkPlugandPlayLogs 17
ReviewingtheStatusofthePreprovisionedProjects 18
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
iv
Preface
Thissectionbrieflydescribestheobjectivesofthisdocumentandprovideslinkstoadditionalinformationon
relatedproductsandservices:
•Objectives,onpagev
•ImportantInformationonFeatures,onpagev
•RelatedDocumentation,onpagev
•DocumentConventions,onpagevi
•ObtainingDocumentationandSubmittingaServiceRequest,onpageviii
Objectives
ThisguideprovidesanoverviewoftheCiscoNetworkPlugandPlayandexplainstheprocesstopreprovision
sitesandmanagetheunplanneddevicesinthenetwork.
Important Information on Features
FormoreinformationaboutCiscoNetworkPlugandPlaysolution,seetheCiscoNetworkPlugandPlay
SolutionGuide.
TofindinformationabouttheCiscoNetworkPlugandPlaymobileapplication,seetheMobileApplication
UserGuideforCiscoNetworkPlugandPlay.
Related Documentation
•SolutionGuideforCiscoNetworkPlugandPlay—SolutionGuidefortheCiscoNetworkPlugandPlay
solution.
•CiscoOpenPlug-n-PlayAgentConfigurationGuide—DescribeshowtoconfiguretheCiscoOpen
Plug-n-PlayAgentsoftwareapplicationthatrunsonaCiscoIOSorIOS-XEdevice.
•ReleaseNotesforCiscoNetworkPlugandPlay—TheCiscoNetworkPlugandPlaysolutionprovides
asimple,secure,unified,andintegratedofferingforenterprisenetworkcustomerstoeasenewbranch
orcampusdevicedeploymentsorforprovisioningupdatestoanexistingnetwork.
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
v
Preface
DocumentConventions
•ReleaseNotesfortheCiscoApplicationPolicyInfrastructureControllerEnterpriseModule—Release
NotesfortheCiscoAPIC-EM—TheCiscoApplicationPolicyInfrastructureControllerEnterpriseModule
(CiscoAPIC-EM)isanetworkcontrollerthathelpsyoumanageandconfigureyournetwork.
•ReleaseNotesforCiscoIntelligentWideAreaNetworkApplication(CiscoIWANApp)—CiscoIWAN
App(ortheCiscoIWANonAPIC-EM)extendsSoftwareDefinedNetworkingtothebranchwithan
application-centricapproachbasedonbusinesspolicyandapplicationrules.ThisprovidesITcentralized
managementwithdistributedenforcementacrossthenetwork.
•MobileApplicationUserGuideforCiscoNetworkPlugandPlay—DescribeshowtousetheCisco
NetworkPlugandPlaymobileapplication.
•CiscoApplicationPolicyInfrastructureControllerEnterpriseModuleDeploymentGuide—Describes
howtodeployandtroubleshoottheCiscoAPIC-EM.
•CiscoApplicationPolicyInfrastructureControllerEnterpriseModuleConfigurationGuide—Describes
howtoconfiguresettingsfortheCiscoAPIC-EM.
Document Conventions
Thisdocumentationusesthefollowingconventions:
Convention Description
^orCtrl The^andCtrlsymbolsrepresenttheControlkey.
Forexample,thekeycombination^DorCtrl-D
meansholddowntheControlkeywhileyoupress
theDkey.Keysareindicatedincapitallettersbutare
notcasesensitive.
string Astringisanonquotedsetofcharactersshownin
italics.Forexample,whensettinganSNMP
communitystringtopublic,donotusequotation
marksaroundthestringorthestringwillincludethe
quotationmarks.
Commandsyntaxdescriptionsusethefollowingconventions:
Convention Description
bold Boldtextindicatescommandsandkeywordsthatyou
enterexactlyasshown.
italics Italictextindicatesargumentsforwhichyousupply
values.
[x] Squarebracketsencloseanoptionalelement(keyword
orargument).
| Averticallineindicatesachoicewithinanoptional
orrequiredsetofkeywordsorarguments.
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
vi
Preface
Preface
Convention Description
[x|y] Squarebracketsenclosingkeywordsorarguments
separatedbyaverticallineindicateanoptionalchoice.
{x|y} Bracesenclosingkeywordsorargumentsseparated
byaverticallineindicatearequiredchoice.
Nestedsetsofsquarebracketsorbracesindicateoptionalorrequiredchoiceswithinoptionalorrequired
elements.Forexample:
Convention Description
[x{y|z}] Bracesandaverticallinewithinsquarebrackets
indicatearequiredchoicewithinanoptionalelement.
Examplesusethefollowingconventions:
Convention Description
screen Examplesofinformationdisplayedonthescreenare
setinCourierfont.
bold screen ExamplesoftextthatyoumustenteraresetinCourier
boldfont.
<> Anglebracketsenclosetextthatisnotprintedtothe
screen,suchaspasswords.
! Anexclamationpointatthebeginningofaline
indicatesacommentline.(Exclamationpointsare
alsodisplayedbytheCiscoIOSXEsoftwarefor
certainprocesses.)
[] Squarebracketsenclosedefaultresponsestosystem
prompts.
Caution Meansreaderbecareful.Inthissituation,youmightdosomethingthatcouldresultinequipmentdamageor
lossofdata.
Note Meansreadertakenote.Notescontainhelpfulsuggestionsorreferencestomaterialsthatmaynotbecontained
inthismanual.
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
vii
Preface
ObtainingDocumentationandSubmittingaServiceRequest
Obtaining Documentation and Submitting a Service Request
Forinformationonobtainingdocumentation,submittingaservicerequest,andgatheringadditionalinformation,
seethemonthlyWhat'sNewinCiscoProductDocumentation,whichalsolistsallnewandrevisedCisco
technicaldocumentationat:http://www.cisco.com/c/en/us/td/docs/general/whatsnew/whatsnew.html.
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
viii
1
CH APTER
New and Changed Information
Thetablebelowsummarizesthenewandchangedfeaturesforthisdocumentandshowsthereleasesinwhich
eachfeatureissupported.Yoursoftwarereleasemightnotsupportallthefeaturesinthisdocument.For
informationaboutthefeaturesthataresupportedinyourrelease,seetheReleaseNotes.Forthelatestcaveats,
seetheBugSearchToolathttps://tools.cisco.com/bugsearch/.
Feature Description Changedin WhereDocumented
Release
Uploading Allowsyoutouploadtemplates. 1.3.2 Uploading
Templates Templates,onpage
13
Configuration Whenyouaddaprojectorclaimanunplanned 1.3.2 AddingaDevice,
/TemplateRadio device,youwillhavetheoptiontoselecteither onpage6
ButtonOption configurationfileortemplate.
Configuration AddedConfigurationTemplate,whichallows 1.3 Using
Template youtodesignthesetofdeviceconfigurations Configuration
thatyouneedtosetupthedevicesinabranch. Template,onpage
8
Configuring TheCiscoAPIC-EMsupportsexternal 1.3 ConfiguringAAA
AAA authenticationandauthorizationforusersfrom ontheDevice,on
aAAAserver.Theexternalauthenticationand page17
ontheDevice
authorizationisbaseduponusernames,
passwords,andattributesthatalreadyexistona
pre-configuredAAAserver.
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
1
NewandChangedInformation
ConfigurationGuideforCiscoNetworkPlugandPlayonCiscoAPIC-EM,Release1.3.x
2
Description:Network Plug and Play mobile application. • Cisco Application Policy Infrastructure Controller Enterprise Module Deployment Guide—Describes how to deploy and troubleshoot the Cisco APIC-EM. • Cisco Application Policy Infrastructure Controller Enterprise Module Configuration Guide—Describes.