A network engineer is using a Python script to retrieve the operational status of all interfaces on a Cisco IOS XE device via RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state but receives an HTTP 401 Unauthorized response. The engineer can successfully ping the device and has verified that the RESTCONF feature is enabled with 'restconf' in global configuration. Which action will resolve the issue?
RESTCONF on Cisco IOS XE requires HTTP authentication. A 401 Unauthorized indicates missing or invalid credentials. Creating a local user with sufficient privilege and including the credentials in the Authorization header (Basic Auth) allows the request to be authenticated. This is the standard method for RESTCONF access when no AAA server is configured.
Why this answer
The 401 Unauthorized response indicates that the HTTP request lacks valid authentication credentials. RESTCONF on Cisco IOS XE uses HTTP Basic Authentication by default when no AAA is configured. The engineer must create a local user with appropriate privileges and include the credentials in the request.
Enabling HTTPS or adjusting ACLs does not address authentication.
Exam trap
The trap here is assuming that a 401 error is caused by a transport or feature configuration issue rather than missing or incorrect authentication credentials.