Troubleshooting the Cisco Catalyst SD-WAN Portal

Update an expired IdP certificate

To update an expired identity provider (IdP) certificate, use the Need help signing in link in the Cisco Catalyst SD-WAN Portal Sign In window.

  1. Navigate to the Cisco Catalyst SD-WAN Portal URL.

  2. Click the Need help signing in link.

  3. Click the Need to reset IdP link.

    You are redirected to your Cisco account.

  4. Enter your Cisco login credentials.

  5. When prompted, set up or enter your MFA credentials.

Reset a Misconfigured IdP

If your identity provider (IdP) is misconfigured and you cannot log in, you can configure a new IdP.

  1. Go to the Cisco Catalyst SD-WAN Portal URL.

  2. Click Need help signing in.

  3. Click Need to reset IdP.

    You are redirected to your account.

  4. Enter your login credentials.

  5. When prompted, set up or enter your multifactor authentication (MFA) credentials.

Delete an IdP

  1. Go to the Cisco Catalyst SD-WAN Portal URL.

  2. Click Need help signing in.

  3. Click the Need to reset IdP.

  4. You are redirected to your account.

  5. Enter your login credentials.

  6. When prompted, set up or enter your MFA credentials.

  7. Select IdP details > Actions and delete the IDP.


Note


Only the IdP administrator is able to delete an IdP from Cisco Catalyst SD-WAN Portal. If you are not the IdP administrator or the administrator is no longer active, open a TAC case.


Troubleshoot Smart Account issues

Problem

A Smart Account is not visible in the Smart Account drop-down list after logging in to the Cisco Catalyst SD-WAN Portal. This can occur when there is no SD-WAN-capable attribute associated with the Smart Account.

Solution

Associate your DNA subscription with your Smart Account and Virtual Account.

For more information, see Workflow for Smart Account and Virtual Accounts for Provisioning the Controllers.

Contact Technical Support to have your Smart Account associated with your DNA cloud subscription.

Troubleshoot Virtual Account issues

Problem

The Cisco Catalyst SD-WAN Portal displays an error that the Virtual Account is not SD-WAN capable.

This error indicates that a DNA subscription is not associated with the Virtual Account.

Solution

If you have an enterprise agreement, you cannot automatically associate Virtual Accounts to an SD-WAN-capable attribute.

As an enterprise customer, complete these steps to associate a Virtual Account with your DNA subscription:

  1. Submit a cloud-controller provisioning request form through the Enterprise Agreement Workspace for the CloudOps team to provision the controllers.

  2. Contact Cisco Catalyst SD-WAN Technical Support to request that the desired Virtual Account become available on the Cisco Catalyst SD-WAN Portal.

  3. After the desired Virtual Account is available on the Cisco Catalyst SD-WAN Portal, provide the necessary enterprise agreement contract information to provision the controllers.

For more information, see Smart Account and Virtual Accounts.

For more information, see Workflow for Smart Account and Virtual Accounts for Provisioning the Controllers.

If you are unable to associate your Virtual Account with your DNA subscription, contact Technical Support to associate the Virtual Account with your DNA cloud subscription.

Troubleshoot browser security issues

Problem

You see this error:

CSRF Failed: CSRF token missing or incorrect

You see a cross-site request forgery (CSRF) token mismatch when the browser is unable to create a secure cookie or to access the cookie required for you to log in.

Solution

This error appears because of certain security settings in your web browser.

Clear the cache on your browser, or try another browser.