Overview
External Endpoint Discovery Management allows Elisity to discover endpoints on a Cisco switch whose IP Device Tracking configuration is owned by an external tool, such as Cisco Catalyst Center. When the setting is enabled on a Virtual Edge Node, endpoint discovery runs in report-only mode: Cloud Control Center continues to discover and classify endpoints, process syslog messages, and run scheduled device-tracking checks, but Elisity does not push its own IP Device Tracking policy to the switch interfaces.
This preserves the external tool's interface configuration while Cloud Control Center retains full endpoint visibility. The Endpoint Discovery tab becomes a read-only view that reports the status Elisity expects on each interface alongside the status actually applied on the switch.
For Virtual Edge Nodes where Elisity manages IP Device Tracking directly, see Managing Virtual Edges and Virtual Edge Nodes.
Prerequisites
- A Cisco switch onboarded as a Virtual Edge Node, or ready to be onboarded. The setting applies to Cisco switch Virtual Edge Nodes only — not to Cisco Wireless LAN Controllers or non-Cisco platforms.
- An external tool that manages the switch's IP Device Tracking configuration.
- Administrator access to Cloud Control Center.
Enabling External Endpoint Discovery Management
The setting is available in the Add Virtual Edge Node workflow and in the Edit workflow for an existing Cisco switch Virtual Edge Node.
Step 1. Open the Virtual Edge Node workflow
Navigate to Edge Management > Virtual Edge Nodes. For a node you are onboarding, select Add Virtual Edge Node and continue to the Virtual Edge Node Configuration step. For an existing node, select the Cisco switch Virtual Edge Node and click Edit.
Step 2. Enable the setting in Advanced Settings
On the Virtual Edge Node Configuration step, expand Advanced Settings and turn on Enable External Endpoint Discovery Management (Cisco Only).
When the setting is on, Enable Endpoint Discovery is turned on and greyed out. Endpoint discovery cannot be disabled while the switch is managed externally, because Elisity takes no configuration action on the interfaces.
Step 3. Save the configuration
Complete the remaining wizard steps and select Finish. Confirm the change by checking that the Endpoint Discovery column for the node reads External in the Virtual Edge Nodes table. The setting persists across Virtual Edge restarts, node re-registrations, and Cloud Control Center upgrades.
Viewing the Endpoint Discovery Tab in External Management Mode
Navigate to Edge Management > Virtual Edge Nodes and select the node to open Virtual Edge Node Details, then open the Endpoint Discovery tab, which appears alongside the Flow Telemetry tab.
An information banner confirms the management model: "This Virtual Edge Node's endpoint discovery is managed by an external configuration tool. You can view the expected and actual status below, but interface settings cannot be edited here." The Edit Configuration button and the Enable Endpoint Discovery toggle are not shown, and the Configuration Type column is omitted because interface settings are not applied by Elisity.
The tab reports the following values for each interface:
| Column | Description |
|---|---|
| Port Name | The switch interface, for example GigabitEthernet1/0/1. |
| Expected Status | The device-tracking state Elisity expects on the interface, either Enabled or Disabled. |
| Source | What determined the expected status — Default for the node-wide setting, or the interface condition that overrides it, such as the interface description or an administratively shut down port. |
| Actual Status | The device-tracking state currently applied on the switch, as reported by the Virtual Edge. This is the state the external tool has configured. |
Actual Status is sortable and filterable, can be hidden from the column selector, and is included in the exported interface list.
Monitoring Configuration Mismatches
Cloud Control Center compares Expected Status with Actual Status for every interface and flags any interface where the two differ.
When at least one interface differs, the banner above the table reports that discovery setting mismatches were detected, states how many interfaces are affected, and prompts you to review the highlighted interfaces below. On each affected row, the Actual Status value is highlighted and marked with an indicator icon, so mismatched interfaces stand out from the rows where the two values agree. Turn on Show Mismatches Only, at the right of the banner, to filter the table to the affected interfaces. An In Sync column is also available from the column selector.
For each flagged interface, verify the following:
- Expected Status and Source — confirm that the state Elisity expects is still correct, and that the condition named in Source is the one you intend to apply.
- Actual Status — confirm the state the external tool has applied on the switch, then decide which of the two states is correct for the interface.
The most common mismatch is an interface with an Expected Status of Disabled and an Actual Status of Enabled: device tracking remains applied on the switch for an interface that Elisity expects to be excluded from discovery. In the example above, GigabitEthernet1/0/4 is excluded because of its interface description and GigabitEthernet1/0/7 because the port is administratively shut down, while the interfaces with a Source of Default follow the node-wide setting and remain in sync.
Resolve a mismatch in the external tool that owns the switch configuration. Refresh the tab afterwards and confirm that Actual Status has updated and that the interface no longer appears when Show Mismatches Only is on.
Important: Endpoints connected to an interface where device tracking is not applied are not discovered through IP Device Tracking. Review mismatched interfaces promptly to avoid gaps in endpoint visibility.
Including the Setting in Bulk Virtual Edge Node Import
The downloadable import template and the bulk import view both provide a column for External Endpoint Discovery Management, so you can onboard multiple externally managed Cisco switches in a single operation. The import summary notes report-only mode for any node where the setting is enabled. For the full import workflow, see Bulk Onboarding Virtual Edges and Virtual Edge Nodes.
Disabling External Endpoint Discovery Management
To return management of IP Device Tracking to Elisity, navigate to Edge Management > Virtual Edge Nodes, select the node, click Edit, expand Advanced Settings, and turn off Enable External Endpoint Discovery Management (Cisco Only). Complete the wizard and select Finish. Elisity resumes pushing its IP Device Tracking policy to the switch interfaces, and the Endpoint Discovery tab returns to the standard editable view.
Important: In the Edit workflow, turning off External Endpoint Discovery Management leaves Enable Endpoint Discovery in the off state. Turn it back on in the same step if you want Elisity to manage device tracking and continue discovering endpoints on the node. In the Add Virtual Edge Node workflow, Enable Endpoint Discovery returns to the on state instead.
For guidance on bringing Cisco switches into Cloud Control Center, see Onboarding Cisco Switches as Virtual Edge Nodes.