Cisco Catalyst Center Administrator Guide, Release 3.3.1

PDF

Cisco Catalyst Center Administrator Guide, Release 3.3.1

Configure an IP address manager

Want to summarize with AI?

Log in

Information about configuring an external IP address manager.


You can configure Catalyst Center to integrate with external IP address managers (IPAMs) such as Infoblox, BlueCat, or any third-party IPAM that uses Cisco's generic IPAM interface. After integration, your external IPAM is automatically synchronized with any IP pools or addresses you create, reserve, or delete in Catalyst Center.

Before you begin

Requirements for external IPAM integration:

  • Create a role that has write permission to the IPAM function and assign it to the user account used for integration with Catalyst Center.

    If you are integrating a BlueCat external IPAM, ensure that your user has been granted API access in the BlueCat Address Manager. Refer to BlueCat documentation to configure API access for your user.

  • To enable IP pool creation by LAN automation for point-to-point addressing and for SDA to make use of multiple address spaces, the role must include:

    • For Infoblox: Write permission for Network Views.

    • For BlueCat: Full access permission for Configurations.

  • If you choose Infoblox as your provider, to integrate Catalyst Center with Common Criteria, your Infoblox environment must be running a version later than 9.0.7. For information on supported Infoblox ciphers, refer to https://docs.infoblox.com/space/nios90/414059185/set+ssl_tls_ciphers.

  • To integrate Catalyst Center with BlueCat in Federal Information Processing Standards (FIPS) mode, use BlueCat 9.3.0 or later.

  • You can update the server URL for an existing external IPAM integration only if the new endpoint represents the same third-party IPAM state as the current one (for example, during a server migration, a hostname change, or a transition to a failover target).

    • Catalyst Center does not trigger a resynchronization or validate IP pool ownership and conflicts when the server URL is updated.

    • If you are migrating to a completely different third-party IPAM instance that requires synchronization, you must delete the existing integration and create a new one.

    • Deleting an integration does not remove existing IP pool or IP address data from Catalyst Center or from your third-party IPAM server.

Procedure

  1. From the main menu, choose System > Settings > External Services > IP Address Manager.

  2. Enter these values, then click Next:

    • Server name: Enter the name of the external IPAM server.

    • Server URL: Enter the URL of the IPAM server. Use the domain name or IP address of the IPAM server to match the Common Name (CN) value in the IPAM server's certificate.

    • Username and Password: Enter the IPAM server credentials.

    • Provider: Choose an external IPAM type.

  3. During certificate validation, a warning is displayed if the IPAM server's certificate is not trusted by Catalyst Center.

    1. Verify the issuer, serial number, and validity dates for the certificate.
    2. If the information is correct, check the check box to allow Catalyst Center to access the IP address and add the untrusted certificate to the trusted certificates.
    3. Check Accept the certificate.
    4. Click Next.
  4. From the View drop-down list, choose a default IPAM network view from the IPAM server for Catalyst Center to use.

  5. To export the IP pools and IP addresses on Catalyst Center to the IPAM server, check the Sync global pools from Catalyst Center to the IPAM Server's selected view check box. This is a one-time export or sync of the pools from Catalyst Center to the IPAM server. If you don't want to synchronize the IP pools, leave the check box unchecked.

    Note

    You should only skip the synchronization if you know that the view of the IPAM is already synchronized with the IP address pool on Catalyst Center. For example, this can occur when the IPAM server

    • has been upgraded through backup and restore to a new server instance, or

    • was accidentally removed from Catalyst Center and you want to re-add it.

    If you skip synchronization when adding or updating the IPAM and the view is out of sync with IP address pools on Catalyst Center, future pool operations might fail.

    After you check the Sync check box and click Next, the system runs a validation for the export. The next window displays the results of that validation. If you don't check the check box, the next window prompts you to confirm that the IPAM server details are correct before saving them.

    Note

    To prevent errors during the export process, do not modify IP pools in Catalyst Center or the external IPAM between this step (export validation) and the next step (export sync and integration). If any changes occur during this interval, you must repeat this step (export validation).

  6. For the "with sync" workflow, the window displays the result of the export validation. The window lists the global pools in Catalyst Center and separates them into Available IP pools (those that can be exported to the IPAM server) and Conflicting IP pools (those that can't immediately be exported to the IPAM server). Use the download link to download the information as a CSV file.

    Pools are marked as conflicting if their subnet

    • partially overlaps with the subnet of a pool in the IPAM server, or

    • exactly matches the subnet of a pool in the IPAM server and that pool in the IPAM server has either IP addresses assigned from it or has subpools.

    If there are no conflicting pools, you can proceed with the export (or terminate the integration workflow).

    If there are conflicting pools, choose one of these options and click Next:

    • Export only the non-conflicting pools: Any future changes made in Catalyst Center to the conflicting pools that aren't exported to the IPAM server will cause failures.

    • Sync all available IP pools and overwrite conflicting IP pools: This option removes the pool hierarchy of all conflicting pools from the IPAM server and then exports the equivalent hierarchy from Catalyst Center. This option could cause the loss of IP address configuration from the IPAM server, so we recommend that you back up the IPAM server before trying this option.

    • Terminate this workflow: You can take the CSV report for the validation and manually resolve the conflicts. You can then repeatedly restart the workflow and validation step until you are ready to continue with the integration.

  7. A summary of the selected integration is shown. If you select an export option, the export runs after you click Finish.

  8. Return to the IP Address Manager window or the View IP Address Pools window. You can monitor the progress of the export from the IP Address Manager window, where the server status changes to Connected when the integration completes.

What to do next

Go to System > Settings > Trust & Privacy > Trusted Certificates to verify that the certificate has been added successfully.

Note

In trusted certificates, the certificate is referenced as a third-party trusted certificate.

Go to System > System 360 and verify the external IP address manager connection.