ArubaOS 8.10.0.0 User Guide
- June 13, 2024
- aruba
Table of Contents
ArubaOS 8.10.0.0
Product Information
The product is ArubaOS 8.10.0.0, and this is the Getting Started Guide for the product. It provides information on the initial setup of an Aruba user-centric network, which includes an Aruba managed device and Aruba Access Points (APs).
Copyright Information
© Copyright 2022 Hewlett Packard Enterprise Development LP.
Open Source Code
This product includes code licensed under the GNU General Public License, the
GNU Lesser General Public License, and/or certain other open source licenses.
A complete machine-readable copy of the source code corresponding to such code
is available upon request. This offer is valid to anyone in receipt of this
information and shall expire three years following the date of the final
distribution of this product version by Hewlett Packard Enterprise Company. To
obtain such source code, send a check or money order in the amount of US
$10.00 to:
Hewlett Packard Enterprise Company
6280 America Center Drive
San Jose, CA 95002
USA
Revision History
The following table lists the revisions of this document.
Table 1: Revision History
Revision | Change Description |
---|---|
Revision 01 | Initial release. |
This document describes the initial setup of an Aruba user-centric network that consists of an Aruba managed device and Aruba Access Points (APs).
Following are the topics covered in this guide:
- Installing Mobility Conductor and Managed Devices
- Initial Setup
- Manual Setup
- Automatic Setup
- Configuring the Managed Devices and APs
Related Documents
The following guides are part of the complete documentation for the Aruba user-centric network:
- ArubaOS 8.10.0.0 Getting Started Guide Release Notes
- ArubaOS User Guide
- ArubaOS CLI Reference Guide
- ArubaOS API Guide
- Aruba Mobility Conductor Licensing Guide
- Aruba Virtual Appliance Installation Guide
- Aruba Mobility Conductor Hardware Appliance InstallationGuide
- Aruba Wireless Access Point Installation Guide
Supported Browsers
The following browsers are officially supported for use with the ArubaOS WebUI:
- Microsoft Internet Explorer 11 on Windows 7 and Windows 8
- Microsoft Edge (Microsoft Edge 92.0.902.62 and MicrosoftEdgeHTML 18.19041) on Windows 10
- Firefox (91.0) on Windows 7, Windows 8, Windows 10, andmacOS
- Apple Safari 8.0 or later on macOS
- Google Chrome (92.0.4515.131) on Windows 7, Windows 8, Windows10, and macOS
Terminology Change
As part of advancing HPE’s commitment to racial justice, we are taking a much- needed step in overhauling HPE engineering terminology to reflect our belief system of diversity and inclusion. Some legacy products and publications may continue to include terminology that seemingly evokes bias against specific groups of people. Such content is not representative of our HPE culture and moving forward, Aruba will replace racially insensitive terms and instead use the following new language:
Contacting Support
**Table 2:** Contact Information
Main Site | arubanetworks.com |
---|---|
Support Site | https://asp.arubanetworks.com/ |
Airheads Social Forums and Knowledge Base |
community.arubanetworks.com
North American Telephone|
1-800-943-4526 (Toll Free)
International Telephone| arubanetworks.com/support-services/contact-
support/
Software Licensing Site|
lms.arubanetworks.com
End-of-life Information| arubanetworks.com/support-services/end-of-
life/
Security Incident Response Team| Site: arubanetworks.com/support-services
/security-bulletins/ Email: aruba-sirt@hpe.com
Overview
This section provides an overview on how to install the Mobility Conductor and managed devices. Perform the following steps to install the Mobility Conductor and managed devices:
- Launch the WebUI or Console Setup Wizard to configure the managed
- Connect the managed device to the wired
- Configure the managed device to the Mobility The Mobility Conductor – Managed Device topology or stand-alone controller topology is supported.
- If it is a stand-alone controller deployment, installing the Mobility Conductor is not
Install and connect your APs to the network
Installing Mobility Conductor and Managed Devices
To install the Aruba Mobility Conductor and Managed Devices, follow the instructions provided in the documentation.
The Aruba Mobility Conductor provides a 64-bit virtualized software-based managed platform on VM architecture.
The Mobility Conductor is the centralized management platform for the deployment in the virtualized network infrastructure. The Mobility Conductor operates on the VM platforms in the VMware environment and can reside with other virtualized appliances.
Installing the Managed Devices
The WebUI Startup Wizard allows you to configure access to the managed device. The Startup Wizard is available the first time you connect to and log into the managed device or whenever the managed device is reset to its factory default configuration. The serial console setup dialog allows you to configure basic managed device settings through a serial port connection to the managed device.
The Startup Wizard works only on 0/0/1 port on all controllers,
After you complete the Startup Wizard or serial console setup procedure, the managed device reboots using the new configuration information you entered.
Do not connect the managed device to your network when running the Setup Wizard or serial console setup dialog. The factory-default managed device boots up with a default IP address and both DHCP server and spanning tree functions enabled. Once you have completed setup and rebooted the managed device, the managed device should appear on the Mobility Conductor for the management of managed device from the Mobility Conductor.
In addition to the traditional method mentioned above, the 7000 Series controllers running ArubaOS 8.9.0.0 can be configured without user intervention with zero touch provisioning (ZTP). This option automatically configures the managed device using Activate. For more details, see Automatic Setup
Initial Setup
The initial setup process involves manual setup or automatic setup.
You can launch the setup wizard using any PC or workstation that can run a supported Web browser.
The PC or workstation must either be configured to obtain its IP address using DHCP, or configured to have a static IP address on the 172.16.0.254/24 sub- network. The default IP address of the managed device is 172.16.0.254/24. Connect a PC or workstation to 0/0/1 port on the managed device, then enter this IP address into a supported Web browser to launch the Setup Wizard.
To run the Setup Wizard:
- Connect your PC or workstation to 0/0/1 port on the managed
- Make sure that the managed device is not connected to any device on your
- Boot up the managed
- On your PC or workstation, open a Web browser and connect to https://172.16.0.254/24.
- The initial window of the Mobility Controller Setup Wizard asks you to select one of the following deployment Select Standalone or Managed then click Continue.
- Standalone Controller : This is the only controller on the
- Managed Controller : This managed device will be managed by a Mobility
Initial Setup on a Serial Port Connection
The serial port is located on the front panel (back panel in case of 7024 and 7008 controllers) of the managed device. You can start the Initial Setup dialog when you connect a terminal, PC or workstation running a terminal emulation program to the serial port on the managed device.
The serial port connection only allows you to configure the basic configuration required to connect the managed device to the network. The recommended browser-based configuration Wizard allows you to also install software licenses and configure internal and guest WLANs. If you use the Initial Setup dialog to configure the managed device, the browser-based Setup Wizard will not be available unless you reset the managed device to its factory default configuration.
To run the Initial full setup dialog from a serial connection:
-
Configure your terminal or terminal emulation program to use the following communication settings:
Table 3: _ _Terminal Communication Settings__ Baud Rate| Data Bits| Parity| Stop Bits| Flow Control
---|---|---|---|---
9600| 8| None| 1| None -
Connect your terminal or PC/workstation to the serial port on the managed devices using an RS-232 serial cable. RJ-45 cable and DB-9 to RJ-45 adapter is You may need a USB adapter to connect the serial cable to your PC.
-
Boot up the managed After the managed device has booted up, you should see a screen similar to the following setup dialog for managed devices:
Auto-provisioning is in progress. Choose one of the following options to override or debug… -
(Applicable to managed devices using ZTP) enter f to invoke full-setup.
-
The Serial Port Configuration Dialog displays the configuration The prompts may vary, depending upon the switch role you choose. Enter the required information at each prompt, then press Enter to continue to the next question.
Table 4: Serial Console Configuration Dialog -
At the end of the Initial Setup, you are asked to review and confirm your configuration Enter y to accept the changes. The managed device reboots.
If you want to complete optional configuration options (e.g. disabling spanning tree or installing software licenses) before connecting the managed device to the network, refer to the ArubaOS 8.9.0.0 User Guide for additional information on configuration.
Manual Setup
To manually set up the system, you need to add system information, Mobility Conductor information, uplink information, and AirWave information. Refer to the documentation for detailed instructions on each step.
Following lists the high-level configurations to be performed to setup either a managed device or a stand-alone controller manually:
- Add the system information
- Add the Mobility Conductor information
- Add the Uplink information
- Add the AirWave information
If you select Stand-alone Controller or Managed Controller in the initial window of the Mobility Controller Setup Wizard, you will be prompted to enter the information described in the following sections.
Add System Information
You can add the system information like Host name, country code, password, clock information.
Table 5: Controller Information
The default certificate installed in the managed device does not guarantee security in production networks. Aruba strongly recommends that you replace the default certificate with a custom certificate issued for your site or domain by a trusted Certificate Authority. See the ArubaOS 8.9.0.0 User Guide for more information about certificates.
Add Mobility Conductor Information
After entering the system information, you will be prompted to add the details of the Mobility Conductor so that the managed device can connect with the Mobility Conductor.
Table 6: Mobility Conductor Information
Add Uplink Information
After adding the Mobility Conductor information, click Next and specify the uplink setting for the managed device to reach the Mobility Conductor.
Table 7: Uplink Settings Information
A summary of the setup is displayed after you add the Uplink information
Add AirWave Information
The following step applies only to stand-alone controllers. After you have completed the basic configuration, you will be prompted to add the AirWave information as described in the below table:
Table 8: AirWave Stand-alone Controller Information
After entering the AirWave information, you will be prompted to add connectivity and licensing information.
Automatic Setup
You can also use Zero Touch Provisioning (ZTP) with DHCP to automatically provision a Managed Device. The documentation provides instructions on how to use ZTP for provisioning.
ZTP makes the deployment of managed device plug-n-play. The managed device now learns all the required information from the network and provisions itself automatically.
With ZTP, a managed device automatically gets its local and global configuration and license limits from a central managed device. A manage device with factory default settings gather the required information from the network and then provision itself automatically.
Zero Touch Provisioning
The main elements for ZTP are:
- Auto discovery of Mobility
- Configuration download from the Mobility
Provisioning Modes
The following modes are supported:
- auto: In this mode, managed device provisions completely The managed device gets the local IP address and routing information from DHCP and gets the Mobility Conductor information and regulatory domain from one of the supported servers. Then, it downloads the entire configuration from the Mobility Conductor.
- mini-setup: In this mode, managed device gets its local IP address and routing information from DHCP However, user is required to provide Mobility Conductor information and regulatory domain. Then, it downloads the entire configuration from the Mobility Conductor.
- full-setup: In this mode, managed device gets all the basic provisioning information from user However, even in this mode, controller can download configuration from the Mobility Conductor if the managed device role is specified as a managed device.
In the default state, controller starts in complete auto mode. While the controller is trying to provision automatically, user are also provided an option to override the auto-mode at any time and select the desired mode. If there is “NO” ZTP provisioning in activate, then quick setup will wait for the user to provide inputs.
For auto provisioning, last physical interface port of a 7000 Series controller should be connected as uplink which will be in VLAN 4094 and act as a DHCP client.
Automatically Provisioning a Managed Device
An auto provisioning managed device acts as a DHCP client to get its local IP address, routing information, and Mobility Conductor information and regulatory domain from a DHCP server or Activate server. A factory-default managed device boots in auto provisioning mode. To interrupt the auto provisioning process, enter the string mini- setup or full-setup at the initial setup dialog prompt shown below:
If the managed device can not complete ZTP provisioning through Activate, then the initial setup process waits for the user to provide input
Activate
The managed device interacts with the activate server to get Mobility Conductor information. The managed device establishes HTTPS connection with the activate server and posts provision requests to it. The activate server authenticates the managed device and provides the Mobility Conductor information and country code to the managed device.
Activate Interface— The managed device and the Mobility Conductor interact with the activate server to receive information about each other. Once all the information is available in the activate server, the relationship between a Mobility Conductor and all the managed device managed by it is provisioned automatically.
The managed device interacts with the activate server to learn about their role, Mobility Conductor information, and their regulatory domain. The Mobility Conductor sends its own information and not managed device information. Activate reuses existing AP-information field for managed device interactions. To achieve this, the following two steps are performed:
- Mobility Conductor retrieving allowlist db from activate The following steps are involved to get the allowlist db:
- Mobility Conductor sends initial post with ‘keep-alive’ connection type with the following information:
- Type as provision update, mode as managed device, session id, Ap-information that includes
, , . - Activate responds with the following information:
- Type as provision update, activate assigned session id, status, and connection as keep
- Mobility Conductor then sends a second POST with ‘close’ connection type with the following information:
- Type as provision update, session id received from activate, Ap-information that includes
, , , length of certificate, signed certificate, and device certificate.
- Activate then responds with the following information:
- Type as provision update, the same session id that activate assigned in the first response, status as success or failure, mode as conductor, and the list of managed devices with the allowlist db that contains
, , , , , and .
- Managed device contacting activate and retrieving the provisioning rule The following steps are involved to retrieve the provision rule:
- Navigate to the device list and select a device that you want to designate as Mobility
- Edit the selected device and set its mode to
- Go to setup and create a folder with the managed device_to_Conductor
- Populate the rule with the following information:
- Select conductor
- Specify IP address of the
- Specify country code for managed device that will be in this
- Specify configuration group for managed device that will be in this folder.
A folder can contain only one type of managed device that have the same country code and map to the same configuration group. Different folders need to be created for each such group, if the country code or mapping to the configuration changes
- Again, navigate to the device list and select a device that you intend to designate as managed
- Edit the selected device and set its name to the desired If the name is not set, it will be autogenerated.
- Move the selected managed device to the folder created in step
Using ZTP with DHCP to Provision a Managed Device
When a factory-default controller boots, it starts the auto-provisioning process. The following sections describe the provisioning workflow, and the process to prepare your network for ZTP using DHCP for a managed device.
The managed device can get the information required for provisioning from a DHCP server instead of Activate. Using DHCP helps the ZTP controllers get conductorinformation when the users are unable to use Activate. Option 43 of DHCP can be used for broadcasting the conductor information to the managed devices.
This feature supports the following topologies:
- VMM with VPNC
- HMM with VPNC
- HMM without VPNC
VPNC must be a hardware controller and not a virtual machine
This feature also supports L2 and L3 Mobility Conductor redundancy scenarios, where the managed device can get primary Mobility Conductor and standby Mobility Conductor (L2 or L3 standby conductor) information.
In VPNC scenarios, the managed devices can get primary Mobility Conductor information, standby Mobility Conductor, Primary VPNC and standby VPNC information.
Option 43 contains the following information to help provision a managed device:
- Conductor IP
- VPNC IP
- Primary Conductor MAC
- Redundant Conductor MAC
- Primary VPNC MAC
- Redundant VPNC MAC
- Country Code
Option 43 contains the following information:
- conductor, country-code, conductor-mac1 (No L2 redundant Conductor)
- conductorip, country-code, conductor-mac1, conductor-mac2 (L2 Redundant Conductor)
- conductorip, country-code, vpnc ip, vpnc-mac1 (No L2 Redundant VPNC)
- conductorip, country-code, vpnc ip, vpnc-mac1, vpnc-mac2 (L2 Redundant VPNC)
Configuring the Managed Devices and APs
After the initial setup, you need to configure the Managed Devices and APs. This involves configuring Peer MAC Address for PSK with MAC, identifying the MAC Address on a device, connecting the Managed Device to the wired network, configuring the Managed Device to support APs, and installing the Access Points. Please refer to the documentation for detailed instructions on each configuration step.
The following section describes how to configure a Peer MAC address, connect the managed devices, and install the APs.
Peer MAC Address Configuration for PSK with MAC
The Peer MAC address configuration on a device for PSK with MAC authentication is based on the platform type of the peer device.
The following table lists the type of MAC address to be configured as the peer MAC address for different platform combinations of a Mobility Conductor- Managed Device pair:
Table 9: Peer MAC Address Configuration
Identify the MAC Address on a Device
Execute the following command to view the Management MAC address (Applicable only for Mobility Conductor Virtual Appliance or Mobility Conductor Hardware Appliance) or the MAC address of the VLAN1 interface for any device:
Connect the Managed Device to the Wired Network
Once managed device setup is complete, connect a port on the managed device to the appropriately configured port on a Layer-2 switch or router. Make sure that you have the correct cables and that the port LEDs indicate proper connections and cable descriptions.
Configure the Managed Device to Support APs
Before you install APs in a network environment, you must ensure that the APs will be able to locate and connect to the managed device when powered on. Specifically, you need to ensure the following:
- When connected to the network, each AP is assigned a valid IP address
- APs are able to locate the managed devices
Each Aruba AP requires a unique IP address on a subnetwork that has connectivity to a managed device. Aruba recommends using the DHCP to provide IP addresses for APs; the DHCP server can be an existing network server or an Aruba managed device configured as a DHCP server.
If an AP is on the same subnetwork as the Mobility Conductor, you can configure the managed device as a DHCP server to assign an IP address to the AP. The managed device must be the only DHCP server for this subnetwork.
Enable DHCP Server Capability
Use the following procedure to use the WebUI to enable DHCP server capability:
- Enter the IP address of the managed device in the URL of a browser window to access the
- At the WebUI login page, enter the admin user name and the password you entered during the Initial
- Navigate to the Configuration > Services
- Open the DHCP Server
- Select Enable from either IPv4 or IPv6 DHCP server drop-down
- In the Pool Configuration table, click +.
- Enter information about the subnetwork for which IP addresses are to be
- Click Submit.
- If there are addresses that should not be assigned in the subnetwork:
- Click + in the Excluded Address Range
- Enter the address range in the Add Excluded Address
- Click Submit.
- Click Pending Changes.
- In the Pending Changes window, select the check box and click Deploy changes.
Managed Device Discovery
An Aruba AP can discover the IP address of the manage device in one of several ways. The ADP is enabled by default on all Aruba APs and managed devices. If all APs and managed devices are connected to the same Layer- 2 network, APs will use ADP to discover their managed devices. If the devices are on different networks, you must configure the AP to use a Layer-3 compatible discovery mechanism such as DNS, DHCP, or IGMP forwarding after installing the AP on the network. For details, refer to the ArubaOS 8.9.0.0 User Guide.
With ADP, APs send out periodic multicast and broadcast queries to locate the . If the APs are in the same broadcast domain as the managed device, the managed device automatically responds to the APs’ queries with its IP address. If the APs are not in the same broadcast domain as the managed device, you need to enable multicast on the network. If multicast is not an option, then the APs can be configured to use DNS or DHCP based provisioning to contact the managed device.
As APs do not terminate on the Mobility Conductor in ArubaOS 8.9.0.0, they are pointed to a managed device that has the configuration for the AP’s AP- group.
Install the Access Points
Refer to the AP placement map generated by RF Plan to identify the locations in which to physically install your APs. You can either connect the AP directly to a port on the managed device, or connect the AP to another switch or router that has Layer-2 or Layer-3 connectivity to the managed device. If the Ethernet port on the managed device is an 802.3af PoE port, the AP automatically uses it to power up. If a PoE port is not available, contact your Aruba vendor to obtain an AC adapter for the AP.
Once an AP is connected to the network and powered up, it will automatically attempt to locate the managed device. You can view a list of all APs connected to the managed device by accessing the Configuration > Access Points page in the WebUI of the Mobility Conductor. An AP installed on the network advertises its default SSID. Wireless users can connect to this SSID, but will not have access to the network until you configure authentication policies and user roles for your wireless users. For complete details on authentication policies and user roles, refer to the ArubaOS 8.9.0.0 User Guide.
Company Information
Hewlett Packard Enterprise Company
6280 America Center Drive
San Jose, CA 95002
USA
References
- Security Advisories | HPE Aruba Networking
- Home - Airheads Community
- Home - Airheads Community
- License Management System
- Intelligent data center networks | HPE Aruba Networking
- Contact Support | HPE Aruba Networking
- HPE Aruba Networking | Enterprise
- Security Advisories | HPE Aruba Networking
- HPE Aruba Networking | Enterprise
- License Management System
Read User Manual Online (PDF format)
Read User Manual Online (PDF format) >>