Documentation>Cisco IoT Operations Dashboard
Cisco IoT Operations Dashboard
  • Overview
    • Welcome
    • Get Started
      • Onboarding an EDM-Managed device
      • Onboarding an Externally-Managed device
    • How to order
    • Set up the IoT Dashboard
    • Release notes
      • Edge Device release notes 2023
      • Edge Device release notes 2022
      • Edge Device release notes 2021
      • Edge Device release notes 2020
      • Application Manager
      • Cisco Cyber Vision release notes
      • Secure Equipment Access release notes 23
      • Secure Equipment Access release notes 22
      • Secure Equipment Access release notes 21
      • Edge Intelligence
        • 2023
        • 2022
        • 2021
        • 2020
      • Industrial Asset Vision
        • 2023
        • 2022
        • 2021
        • 2020
      • Industrial Wireless release notes
        • 2023
    • Log in
    • Upgrading Cisco IoT OD
    • Update network device firmware
    • Access control
      • Add and manage users
      • Create sub-organizations
      • Organization Hierarchy for IoT OD
      • Cisco SSO Login Experience
      • Enable Multi-Factor Authentication for an organization on IoT OD
    • Cisco Cross Platform Navigator
    • Audit user actions
    • Required accounts
    • Switch organizations or Services
    • View cloud service status
    • Feedback form
  • Edge Device Manager (EDM)
    • Requirements and release notes
      • Overview
      • Release notes
      • Firewall Rules: Device and network requirements
      • Supported devices and firmware
    • EDM Sandbox
    • Onboard network devices
      • Onboarding Quick Start Guide for IR devices
      • Prepare existing devices for onboarding
      • Troubleshoot IR device onboarding
      • Manually onboard network devices (alternative method)
    • Configure network devices
      • Overview
      • Create Configuration Group
      • Edit Configuration Group
      • Configuration Variables
      • Manage Configuration Group
      • Edit the configuration for a specific device
      • Create custom templates
      • Base Configuration
        • Hardware
        • WAN Uplink
        • LAN
        • Ethernet Settings
        • Interface
        • Device Settings
        • DHCP
        • Device Management
        • DNS/NTP
        • VPN
        • Network
        • Security
        • Wi-Fi
        • Serial
        • GPIO
    • Manage network devices
      • Add and manage network devices
      • Delete network devices
      • Deactivate network device
      • Mapping Modules for IR Devices
      • Connectivity from IR devices to Cellular Carriers
      • Convert AP to Autonomous Mode
      • Troubleshooting Issues
      • Add and monitor Meraki cameras
    • Monitor network devices
      • Monitor network device status
      • Track device location
      • View network device info on a map
      • View events and alerts
      • Manage notifications
    • EDM API
    • Application management
    • Application management troubleshooting tips
  • Application Manager
    • Overview
      • Release notes
    • Onboarding Externally-Managed IE3x00 Switches
      • Prerequisites
      • IoT OD Service Activation on an Externally-Managed IE3x00 Device
      • Firewall Rules: Devices and Network Requirements
      • Device Configuration and Initiating Connection to OD
    • Application Inventory and Application Instances
    • Device Inventory
    • Device Profiles
    • Role-Based Access Control
    • Technotes: Troubleshooting Tips
  • Cisco Cyber Vision
    • Overview
      • Introduction
      • Release notes
      • User roles and permissions
    • Dashboard
    • Inventory
      • Assets
      • Asset Selection
      • Asset Deletion
      • Asset Vulnerability Management
    • Security Posture
      • Vulnerabilities
      • Acknowledge Vulnerabilities
        • Acknowledge vulnerabilities
    • Data sources
      • PCAP
      • Sensor Application
        • Sensor application
        • Capture modes
    • Configuration
  • Secure Equipment Access
    • Overview
      • Secure Equipment Access overview
      • Release notes 23
      • Release notes 22
      • Release notes 21
    • Add network devices and connected clients
    • Manage and schedule access for existing SEA access groups
    • Monitor sessions
    • Duo user security posture checks
    • Record Inline Sessions
    • Access methods
      • SSH Access Method
      • RDP Access Method
      • VNC Access Method
      • Web App Access Method
      • Telnet Access Method
      • SEA Plus Access Method
  • Edge Intelligence
    • Overview
      • EI overview
      • Using EI
      • Dashboard
      • Release notes
        • 2023
        • 2022
        • 2021
        • 2020
      • Upgrade EI Agents
      • Requirements
      • Supported devices and firmware
    • Enable EI agents
    • Add assets
      • Asset Management
      • Asset Types
      • Add Asset Instances
      • Map Asset Instances
      • Edit Asset Inventory Details
      • View Data Policy Status of an Asset
    • Add data destinations
    • Deploy data rule policies
    • Deploy data logic policies
      • Introduction to Data Logic
      • Install and Update VS Code and EI extension
      • Create Data Logic scripts in VS Code
      • Deploy Data Logic in Cisco EI
      • Update Data Logic scripts
      • Clone Data Logic from Cloud UI
    • View EI events
    • Configure and view alert rules
    • Troubleshooting Issues
      • Recommended Log Rotation
      • Documentation for Metrics collection
    • Edge Intelligence API
  • Industrial Asset Vision
    • Overview
      • Introduction
      • Release notes
        • 2023
        • 2022
        • 2021
        • 2020
    • Prerequisites
    • Quick start guide
      • Getting started
        • Onboard Network Devices
        • Onboard Sensors
        • Onboard Bridges
      • Add asset type
      • Add asset
      • Add sensor
      • Assign sensors
      • Add bridge
      • Change Preferences (User Localization)
    • View status and troubleshoot
      • View asset details and locations
      • View sensors details and troubleshoot
      • View network devices details and troubleshoot
      • Arctic Integration
    • Create alerts and generate reports
      • Create and view alerts
      • Generate and view reports
    • RF Performance Tool
    • Add Templates
    • Stream sensor data
    • Add Geofences
    • Group sensors and assets
    • Northbound APIs
      • Using APIs
      • APIs
        • Overview
        • API
          • AssetTypes
            • Get Asset Types
            • Add Asset Type
            • Delete Asset Type
            • Get Asset Type By Id
            • Update Asset Type
          • Assets
            • Get Assets
            • Add Asset
            • Delete Asset
            • Get Asset By Id
            • Update Asset
            • Assign Sensors To Asset
            • Delete Image Of Asset
            • Get Image Of Asset
            • Upload Image Of Asset
            • Get Sensors By Asset Id
            • Get Thumbnail Image Of Asset
            • Unassign Sensors From Asset
          • Sensors
            • Get Sensors
            • Get Sensor By Dev Eui
            • Claim Sensor By Dev Eui
            • Delete Sensor
            • Get Sensor By Id
            • Update Sensor
            • Get Sensor Location Data
            • Onboard Sensor
            • Get Sensor Tabular Telemetry Data
            • Get Sensor Telemetry Data
        • Model
          • AdditionalAttributesMap
          • Asset
          • AssetListResponse
          • AssetRequest
          • AssetType
          • AssetTypeListResponse
          • AssetTypeRequest
          • AssignSensorsRequest
          • AssignSensorsResponse
          • CreateSensorRequest
          • CustomAttributeData
          • CustomAttributeMetadata
          • Error
          • LiveDataItem
          • Location
          • LocationData
          • LocationDataResponse
          • OnboardSensorRequest
          • OnboardSensorResponse
          • PageInfo
          • Sensor
          • SensorListResponse
          • TabularTelemetryDataResponse
          • TelemetryData
          • TelemetryDataResponse
          • TelemetryValue
          • UnassignSensorsRequest
          • UnassignSensorsResponse
          • UpdateSensorRequest
  • Industrial Wireless
    • Overview
      • Introduction
      • Release notes
        • 2023
    • Supported firmware
    • Add new IW devices
    • Manage IW devices
      • Upgrade IW devices
      • Create Groups
      • Assign IW devices to a Group
      • Configure IW devices in online / offline mode
      • Edit and Delete Groups
      • Remove IW devices from Group
      • Create Templates
      • Duplicate Templates
      • Edit and Delete Templates
    • View details
      • View Group details
      • View IW device details
  • Solution Design
    • Tech guidance
    • Gateway Networking
    • Enterprise Network Integration
    • Security
    • Edge Compute
    • Field Deployment
    • Glossary
  • Developer Resources
    • Sandbox
    • Learning Labs
  • Community and Support
    • Developer Support
    • Videos
    • Related Information
    • System Status

Onboarding Externally-Managed IE3x00 Switches

This section guides you through the process of onboarding an externally-managed device to the IoT OD Application Manager's Inventory and deploying Operational Technology (OT) services on the device. It also includes the device configuration process and initiating connection to the dashboard. For details, see Device Configuration and Initiating Connection to OD.

Note: Externally-managed devices refers to devices that are managed through CLI, Cisco Controllers, or other third-party systems. It excludes devices managed by the Edge Device Manager (EDM) service in IoT OD.

The IoT OD System Administrator can onboard externally-managed devices on the OD. For details on roles and permissions, refer Role-Based Access Control.

Prerequisites

Ensure the following for successful onboarding of the devices and deploying the Application Manager service:

  1. IoT OD (Customer Organization): Create your Organization (with active support for externally-managed devices) and onboard a target IE3x00 device as externally-managed. See Step 3 below.
  2. IE3x00 Device: Ensure IE3x00 has an SD card and runs a minimum IOS-XE version 17.12.1 or higher. Apply the required configuration commands via CLI, Local Manager, or DNAC template. See Step 4 below.
  3. Service Deployment: Configure a required service on IoT OD. For example, to configure SEA service, go to the SEA service in your Organization. See Step 5 below.

IoT OD Service Activation on an Externally-Managed IE3x00 Device

This section details the process and workflow required to have a Service supported by IoT OD up and running on an externally-managed IE3x00. The information is organized into the following steps:

  • Step 1: Device Readiness
  • Step 2: Customer Site Readiness
  • Step 3: Cloud Infrastructure and Operations Dashboard Readiness
  • Step 4: Device Configuration and Initiating Connection to OD
  • Step 5: IOx Application Deployment, Service Configuration, and Activation
  • Step 6: IoT OD Service Deactivation and Device removal on an Externally-Managed IE3x00

Step 1: Device Readiness

To ready your device:

  1. Ensure IoT OD supports your device. IoT OD supports externally-managed IE3x00 - IE3400 (all models) and IE3300 (4GB/RAM models).
  2. Make sure the IE3x00 device has an SD card installed and is configured. For more information, see Configure and Enable IOx section in Device Configuration and Initiating Connection to OD.
  3. Cable the device securely. Use the power cable and uplink connection cables.
  4. Ensure that the device is configured such that it has an IP address and internet access (to connect to IoT OD). Device configuration might include interfaces and networking.
  5. Record the serial number and base product ID of the device for later use.
  6. For externally-managed IE3x00 switches, apply configuration command shown below to establish websocket tunnel between the device and IoT OD.
Use the following command to show the product ID and serial# for your device:
Switch#show license udi
UDI: PID:IE-3300-8T2X,SN:FTX2000000N

In this example, the product ID (PID) is IE-3300-8T2X and serial number (SN) is FTX2000000N. 
This data will be used to add the device to IoT OD.

Step 2: Customer Site Readiness

For site security

  1. Refer to Firewall Rules: Device and network requirements and verify if you are using the available IP addresses and network ports for your region (EU or US).
  2. Please ensure the site is ready for communication with IoT OD by allowing dashboard's public IP addresses through ACLs, etc.

    Note: To simplify and start faster, open 9 IPs to communicate with the US or EU IoT OD clusters and port 443. At every given moment, only 3 IPs are used to communicate from each pool, but they can swap over time within the pool of 9.

    For a complete list of IP addresses for each cluster, see the following links:
  • US Cluster

  • EU Cluster

    For more specific use cases, please refer to the Firewall Rules: Device and network requirements.

Step 3: Cloud Infrastructure and Operations Dashboard Readiness

To begin onboarding an existing IE3x00 device into IoT OD:

  1. If the customer organization is not created on IoT OD, create the organization. Use the online instructions at [us.ciscoiot.com] or [eu.ciscoiot.com] based on the geographical location. In case of issues, use ask-sea-pm@cisco.com to contact support.
  2. Log in to the organization with a user who has appropriate permissions/roles to add devices or ask the Tenant Admin to create one.

Note: When a new user is created on IoT OD, the target user will receive a personal invitation to access the cloud platform. Only a Tenant Admin can pre-define or assign a custom role to the user.

  1. Create a new Device Profile or select an existing Device Profile for the device as applicable. For details on creating, editing or deleting a device profile, see Device Profiles.
  2. Add the device in IoT OD as an externally-managed device. For details, see Device Inventory.

Step 4: Device Configuration and Initiating Connection to OD

For details, see sections on Configuring devices managed by CLI/Local Manager and Configuring Devices managed by DNAC in Device Configuration and Initiating Connection to OD.

Step 5: IOx Application Deployment, Service Configuration, and Activation

See the following documentation for additional reference on Application Management in IoT OD:

  • Application Management

Note:

  • In most cases, you don't need Application Management to deploy SEA and CCV (future) Services on IoT OD. You can make all necessary service-specific configurations for those Services, including software installation onto IE3x00 devices, in the corresponding services on IoT OD.
  • To deploy EI, you will need Application Management for installing EI software onto the IE3x00 device. Afterward, you can use the EI service on IoT OD to configure it.

Secure Equipment Access (SEA)

For installing, configuring, and activating SEA on a device, see the following topics:

  • Secure Equipment Access–Overview
  • Add network devices and connected clients to a group

 

Edge Intelligence (EI)

For installing, configuring, and activating Edge Intelligence on a device, see the following topic:

  • Install EI agent on unmanaged devices using IoT OD

Step 6: IoT OD Service Deactivation and Device Removal on an Externally-Managed IE3x00

To deactivate IoT OD Services on an Externally-Managed IE3x00:

  1. Remove the OD-specific configuration from the device.

    // Remove the IoT OD connection profiles
    no cgna transport-profile wst
    no cgna profile cg-nms-register
    
    // Remove the user that was used by IoTOD (if this user is not used for any other purposes on the device)
    no username odserviceuser
    
    // Remove the trustpoint created for IoT OD connection (use the same name that was given while configuring the trust point)
    no crypto pki trustpoint iotod-cert
    
    // Remove WSMA & CGNA related configuration (if WSMA is not needed)
    no wsma agent exec
    no wsma agent config
    no wsma profile listener exec
    no wsma profile listener config
    no cgna gzip
    
    // Stop IOx and remove configuration of AppGigabitEthernet1/1 (if IOx is not needed)
    no iox
    interface AppGigabitEthernet1/1
    no switchport mode trunk
    
  2. Deactivate the device in IoT OD.

    1. From the Sevices select Application Manager.
    2. Click Devices > Registered.
    3. Use the checkbox to select the device(s) to be deactivated.
    4. Select the Deactivate Device action on the top of the table.
    5. Confirm the operation, when prompted.
  3. Remove the device from IoT OD.

    1. From the Sevices select Application Manager.
    2. Click Devices > Staged.
    3. Use the checkbox to select the device(s) to be removed.
    4. Select the Delete Device action on the top of the table.
    5. Confirm the operation when prompted.

For more details on possible errors and corresponding solutions see Troubleshooting Tips.

Next