Information about configuring an external IP address manager.
You can configure Catalyst Center to integrate with external IP address managers (IPAMs) such as Infoblox, BlueCat, or any third-party IPAM that uses Cisco's generic IPAM interface. After integration, your external IPAM is automatically synchronized with any IP pools or addresses you create, reserve, or delete in Catalyst Center.
Before you begin
Requirements for external IPAM integration:
-
Create a role that has write permission to the IPAM function and assign it to the user account used for integration with Catalyst Center.
If you are integrating a BlueCat external IPAM, ensure that your user has been granted API access in the BlueCat Address Manager. Refer to BlueCat documentation to configure API access for your user.
-
To enable IP pool creation by LAN automation for point-to-point addressing and for SDA to make use of multiple address spaces, the role must include:
-
For Infoblox: Write permission for Network Views.
-
For BlueCat: Full access permission for Configurations.
-
-
If you choose Infoblox as your provider, to integrate Catalyst Center with Common Criteria, your Infoblox environment must be running a version later than 9.0.7. For information on supported Infoblox ciphers, refer to https://docs.infoblox.com/space/nios90/414059185/set+ssl_tls_ciphers.
-
To integrate Catalyst Center with BlueCat in Federal Information Processing Standards (FIPS) mode, use BlueCat 9.3.0 or later.
-
You can update the server URL for an existing external IPAM integration only if the new endpoint represents the same third-party IPAM state as the current one (for example, during a server migration, a hostname change, or a transition to a failover target).
-
Catalyst Center does not trigger a resynchronization or validate IP pool ownership and conflicts when the server URL is updated.
-
If you are migrating to a completely different third-party IPAM instance that requires synchronization, you must delete the existing integration and create a new one.
-
Deleting an integration does not remove existing IP pool or IP address data from Catalyst Center or from your third-party IPAM server.
-
Procedure
What to do next
Go to to verify that the certificate has been added successfully.
In trusted certificates, the certificate is referenced as a third-party trusted certificate.
Go to and verify the external IP address manager connection.