Basic Settings for Cisco vManage
The System template is used to configure system-level Cisco vManage workflows.
Use the Settings screen to view the current settings and configure the setting for Cisco vManage parameters, including the organization name, vBond orchestrator's DNS name or IP address, certificate settings, and statistics collection.
The current setting for each item is displayed in the bar for each item, immediately following the name.
Configure Organization Name
Before you can generate a Certificate Signing Request (CSR), you must configure the name of your organization. The organization name is included in the CSR.
In public key infrastructure (PKI) systems, a CSR is sent to a certificate authority to apply for a digital identity certificate.
To configure the organization name:
-
From the Cisco vManage menu, choose .
-
From Organization Name, click Edit .
-
In Organization Name, enter the name of your organization. The organization name must be identical to the name that is configured on the vBond orchestrator.
-
In Confirm Organization Name, re-enter and confirm your organization name.
-
Click Save.
Note |
After the control connections are up and running, the organization name bar is no longer editable. |
Configure Cisco vBond DNS Name or IP Address
-
From vBond, click Edit .
-
In vBond DNS/IP Address: Port, enter the DNS name that points to the vBond orchestrator or the IP address of the Cisco vBond orchestrator and the port number to use to connect to it.
-
Click Save.
Note
The DNS cache timeout should be proportional to the number of Cisco vBond Orchestrator IP addresses that DNS has to resolve, otherwise the control connection for Cisco vManage might not come up during a link failure. This is because, when there are more than six IP addresses (this is the recommended number since the default DNS cache timeout is currently two minutes) to check, the DNS cache timer expires even as the highest preferred interface tries all vBond IP addresses, before failing over to a different color. For instance, it takes about 20 seconds to attempt to connect to one IP address. So, if there are eight IP addresses to be resolved, the DNS cache timeout should be 20*8=160 seconds or three minutes.
Configure Controller Certificate Authorization Settings
Signed certificates are used to authenticate devices in the overlay network. Once authenticated, devices can establish secure sessions between each other. It is from the Cisco vManage that you generate these certificates and install them on the controller devices—Cisco vBond orchestrators,Cisco vManage, and Cisco vSmart controllers. You can use certificates signed by Symantec, or you can use enterprise root certificates.
The controller certification authorization settings establish how the certification generation for all controller devices will be done. They do not generate the certificates.
You need to select the certificate-generation method only once. The method you select is automatically used each time you add a device to the overlay network.
To have the Symantec signing server automatically generate, sign, and install certificates on each controller device:
-
From Controller Certificate Authorization, click Edit.
-
Click Symantec Automated (Recommended). This is the recommended method for handling controller signed certificates.
-
In the Confirm Certificate Authorization Change dialog box, click Proceed to confirm that you wish to have the Symantec signing server automatically generate, sign, and install certificates on each controller device.
-
Enter the first and last name of the requester of the certificate.
-
Enter the email address of the requester of the certificate. This address is required because the signed certificate and a confirmation email are sent to the requester via email; they are also made available though the customer portal.
-
Specify the validity period for the certificate. It can be 1, 2, or 3 years.
-
Enter a challenge phrase. The challenge phrase is your certificate password and is required when you renew or revoke a certificate.
-
Confirm your challenge phrase.
-
In Certificate Retrieve Interval, specify how often the Cisco vManage server checks if the Symantec signing server has sent the certificate.
-
Click Save.
To manually install certificates that the Symantec signing server has generated and signed:
-
From Controller Certificate Authorization, click Edit.
-
Click Symantec Manual.
-
In the Confirm Certificate Authorization Change dialog box, click Proceed to manually install certificates that the Symantec signing server has generated and signed.
-
Click Save.
To use enterprise root certificates:
-
From Controller Certificate Authorization, click Edit.
-
Click Enterprise Root Certificate.
-
In the Confirm Certificate Authorization Change dialog box, click Proceed to confirm that you wish to use enterprise root certificates.
-
In the Certificate box, either paste the certificate, or click Select a file and upload a file that contains the enterprise root certificate.
-
By default, the enterprise root certificate has the following properties: To view this information, issue the show certificate signing-request decoded command on a controller device, and check the output in the Subject line. For example:
-
Country: United States
-
State: California
-
City: San Jose
-
Organizational unit: ENB
-
Organization: CISCO
-
Domain Name: cisco.com
-
Email: cisco-cloudops-sdwan@cisco.com
vSmart# show certificate signing-request decoded ... Subject: C=US, ST=California, L=San Jose, OU=ENB, O=CISCO, CN=vsmart-uuid .cisco.com/emailAddress=cisco-cloudops-sdwan@cisco.com ...
-
Click Set CSR Properties.
-
Enter the domain name to include in the CSR. This domain name is appended to the certificate number (CN).
-
Enter the organizational unit (OU) to include in the CSR.
-
Enter the organization (O) to include in the CSR.
-
Enter the city (L), state (ST), and two-letter country code (C) to include in the CSR.
-
Enter the email address (emailAddress) of the certificate requester.
-
Specify the validity period for the certificate. It can be 1, 2, or 3 years.
-
-
Click Import & Save.
Enforce Software Version on Devices
If you are using the Cisco SD-WAN hosted service, you can enforce a version of the Cisco SD-WAN software to run on a router when it first joins the overlay network.
To ensure that templates are in sync after an upgrade that enforces a software version, make sure of the following before you perform the upgrade:
-
The bootflash and flash on the router must have enough free space to support the upgrade
-
The version of the SD-WAN image that is on the device before the upgrade must be a lower version than the enforced SD-WAN version you specify in the following procedure
To enforce a version of the Cisco SD-WAN software to run on a router when it first joins the overlay network, follow these steps:
-
Ensure that the software image for the desired device software version is present in the Cisco vManage software image repository:
-
From the Cisco vManage menu, choose .
The Software Repository screen opens and displays a table of software images. If the desired software image is present in the repository, continue with Step 2.
-
If you need to add a software image, click Add New Software.
-
Select the location from which to download the software images, either Cisco vManage, Remote Server, or Remote Server - vManage.
-
Select an x86-based or a MIPS-based software image.
-
To place the image in the repository, click Add.
-
-
From the Cisco vManage menu, choose .
-
From Enforce Software Version (ZTP), click Edit.
-
In Enforce Software Version, click Enabled.
-
From the Version drop-down list, select the version of the software to enforce on the device when they join the network.
-
Click Save.
Banner
Use the Banner template for Cisco vBond Orchestrators, Cisco vManages, Cisco vSmart Controllers, Cisco vEdge devices, and s.
You can configure two different banner text strings, one to be displayed before the CLI login prompt on a Cisco SD-WAN device and the other to be displayed after a successful login to the device.
-
To configure the banner text for login screens using Cisco vManage templates, create a Banner feature template to configure PIM parameters, as described in this topic.
-
To configure a login banner for the Cisco vManage system, from the Cisco vManage menu, choose .
Configure a Banner
-
From the Cisco vManage menu, choose .
-
Click Device Templates, and click Create Template.
Note
In Cisco vManage Release 20.7.x and earlier releases, Device Templates is called Device.
-
From the Create Template drop-down list, select From Feature Template.
-
From the Device Model drop-down list, select the type of device for which you are creating the template.
-
Click Additional Templates or scroll to the Additional Templates section.
-
From the Banner drop-down list, click Create Template. The Banner template form is displayed. This form contains fields for naming the template, and the fields for defining Banner parameters.
-
In Template Name, enter a name for the template. The name can be up to 128 characters and can contain only alphanumeric characters.
-
In Template Description, enter a description of the template. The description can be up to 2048 characters and can contain only alphanumeric characters.
When you first open a feature template, for each parameter that has a default value, the scope is set to Default (indicated by a check mark), and the default setting or value is shown. To change the default or to enter a value, click the Scope drop-down list.
-
To set a banner, configure the following parameters:
Table 1. Parameters to be configured while setting a banner: Parameter Name
Description
MOTD Banner
On a Cisco vEdge device enter message-of-the-day text to display after a successful login. The string can be up to 2048 characters long. To insert a line break, type \n.
Login Banner
Enter text to display before the login prompt. The string can be up to 2048 characters long. To insert a line break, type \n.
-
To save the feature template, click Save.
CLI equivalent:
banner{login text | motd text}
Release Information
Introduced in Cisco vManage NMS in Release 15.2.
Create a Custom Banner
To create a custom banner that is displayed after you log in to the Cisco vManage:
-
From Banner, click Edit.
-
In Enable Banner, click Enabled.
-
In Banner Info, enter the text string for the login banner or click Select a File to download a file that contains the text string.
-
Click Save.
Collect Device Statistics
Enable or disable the collection of statistics for devices in the overlay network. By default, the collection of statistics is enabled for all the devices in the overlay network.
-
From the Cisco vManage menu, choose .
-
To modify the settings for collecting device statistics, click Statistics Setting, and click Edit.
Tip
To view the configured settings, click View.
By default, for every group of statistics (such as Aggregated DPI and AppHosting), collection of statistics is enabled for all devices.
-
To enable the collection of a group of statistics for all devices, click Enable All for the particular group.
-
To disable the collection of a group of statistics for all devices, click Disable All for the particular group.
-
To enable the collection of a group of statistics for all devices only for consumption by Cisco vAnalytics, click vAnalytics only for the particular group.
-
To enable or disable the collection of a group of statistics for specific devices in the overlay network, click Custom for the particular group.
In the Select Devices dialog box, depending on whether statistics collection is enabled or disabled for a device, the device is listed among Enabled Devices or Disabled Devices respectively.
-
To enable statistics collection for one or more devices, choose the devices from Disabled Devices and move them to Enabled Devices.
Tip
To choose all Disabled Devices, click Select All.
-
To disable statistics collection for one or more devices, choose the devices from Enabled Devices and move them to Disabled Devices.
Tip
To choose all Enabled Devices, click Select All.
-
To save your selections, click Done.
To discard your selections, click Cancel.
-
-
To apply the modified settings, click Save.
To discard your changes, click Cancel.
To revert to the default settings, click Restore Factory Default.
Configure the Time Interval to Collect Device Statistics
-
From the Cisco vManage menu, choose .
-
To modify the time interval at which device statistics are collected, find Statistics Configuration and click Edit.
Tip
To view the configured time interval, click View.
-
Enter the desired Collection Interval in minutes.
-
Default value: 30 minutes
-
Minimum value: 5 minutes
-
Maximum value: 180 minutes
-
-
To apply the modified settings, click Save.
To discard your changes, click Cancel.
To revert to the default settings, click Restore Factory Default.
Configure or Cancel vManage Server Maintenance Window
You can set or cancel the start and end times and the duration of the maintenance window for the vManage server.
-
From the Cisco vManage menu, choose .
-
From Maintenance Window, click Edit.
To cancel the maintenance window, click Cancel.
-
Click the Start date and time drop-down list, and select the date and time when the Maintenance Window will start.
-
Click the End date and time drop-down list, and select the date and time when the Maintenance Window will end.
-
Click Save. The start and end times and the duration of the maintenance window are displayed in the Maintenance Window bar.
Two days before the start of the window, the Cisco vManage Dashboard displays a maintenance window alert notification.