Automatic Setup using ZTP
ZTPZero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. makes the deployment of managed device plug-n-play. The managed device now learns all the required information from the network and provisions itself automatically.
With ZTPZero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention., a managed device automatically gets its local and global configuration and license limits from a central managed device. A manage device with factory default settings gather the required information from the network and then provision itself automatically.
The main elements for ZTPZero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. are:
Auto discovery of Mobility Master.
Configuration download from the Mobility Master.
The following modes are supported:
In this mode, managed device provisions completely automatically. The managed device gets the local IP address and routing information from DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. and gets the Mobility Master information and regulatory domain from one of the supported servers. Then, it downloads the entire configuration from the Mobility Master.
In this mode, managed device gets its local IP address and routing information from DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server. However, user is required to provide Mobility Master information and regulatory domain. Then, it downloads the entire configuration from the Mobility Master.
In this mode, managed device gets all the basic provisioning information from user inputs. However, even in this mode, controller can download configuration from the Mobility Master if the managed device role is specified as a managed device.
An auto provisioning managed device acts as a DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. client to get its local IP address, routing information, and Mobility Master information and regulatory domain from a DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server or Activate server. A factory-default managed device boots in auto provisioning mode. To interrupt the auto provisioning process, enter the string mini-setup or full-setup at the initial setup dialog prompt shown below:
Auto-provisioning is in progress. Choose one of the following options to override or
debug...
'enable-debug' : Enable auto-provisioning debug logs
'disable-debug': Disable auto-provisioning debug logs
'mini-setup' : Stop auto-provisioning and start mini setup dialog for smart-branch role
'full-setup' : Stop auto-provisioning and start full setup dialog for any role
Enter Option (partial string is acceptable):_
If the managed device can not complete ZTPZero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. provisioning through Activate, then the initial setup process waits for the user to provide input
Activate
The managed device interacts with the activate server to get Mobility Master information. The managed device establishes HTTPSHypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection. connection with the activate server and posts provision requests to it. The activate server authenticates the managed device and provides the Mobility Master information and country code to the managed device.
Activate Interface— The managed device and the Mobility Master interact with the activate server to receive information about each other. Once all the information is available in the activate server, the relationship between a Mobility Master and all the managed device managed by it is provisioned automatically.
The managed device interacts with the activate server to learn about their role, Mobility Master information, and their regulatory domain. The Mobility Master sends its own information and not managed device information. Activate reuses existing AP-information field for managed device interactions. To achieve this, the following two steps are performed:
1. Mobility Master retrieving whitelist db from activate server. The following steps are involved to get the whitelist db:
a. Mobility Master sends initial post with ‘keep-alive’ connection type with the following information:
Type as provision update, mode as managed device, session id, Ap-information that includes <serial number>, <mac>, <model>.
b. Activate responds with the following information:
Type as provision update, activate assigned session id, status, and connection as keep alive.
c. Mobility Master then sends a second POSTPower On Self Test. An HTTP request method that requests data from a specified resource. with ‘close’ connection type with the following information:
Type as provision update, session id received from activate, Ap-information that includes <serial number>, <mac>, <model>, length of certificate, signed certificate, and device certificate.
d. Activate then responds with the following information:
Type as provision update, the same session id that activate assigned in the first response, status as success or failure, mode as master, and the list of managed devices with the whitelist db that contains <MACMedia Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address>,<Serial number>,<Model>,<Mode>,<Hostname>, and <Config group>.
2. Managed device contacting activate and retrieving the provisioning rule
The following steps are involved to retrieve the provision rule:
a. Navigate to the device list and select a device that you want to designate as Mobility Master.
b. Edit the selected device and set its mode to Master.
c. Go to setup and create a folder with the managed device_to_Master rule.
d. Populate the rule with the following information:
Select master device.
Specify IP address of the master.
Specify country code for managed device that will be in this folder.
Specify configuration group for managed device that will be in this folder.
|
|
A folder can contain only one type of managed device that have the same country code and map to the same configuration group. Different folders need to be created for each such group, if the country code or mapping to the configuration changes. |
e. Again, navigate to the device list and select a device that you intend to designate as managed device.
f. Edit the selected device and set its name to the desired hostname. If the name is not set, it will be autogenerated.
g. Move the selected managed device to the folder created in step c.
When a factory-default controller boots, it starts the auto-provisioning process. The following sections describe the provisioning workflow, and the process to prepare your network for ZTPZero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. using DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. for a managed device.
The managed device can get the information required for provisioning from a DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server instead of Activate. Using DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. helps the ZTPZero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. controllers get master information when the users are unable to use Activate. Option 43 of DHCPDynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. can be used for broadcasting the master information to the managed devices.
This feature supports the following topologies:
VMM with VPNC
HMM with VPNC
HMM without VPNC
|
|
VPNC must be a hardware controller and not a virtual machine. |
This feature also supports L2 and L3 Mobility Master redundancy scenarios, where the managed device can get primary Mobility Master and standby Mobility Master (L2 or L3 standby master) information.
In VPNC scenarios, the managed devices can get primary Mobility Master information, standby Mobility Master, Primary VPNC and standby VPNC information.
Option 43 contains the following information to help provision a managed device:
Master IP
VPNC IP
Primary Master MACMedia Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network.
Redundant Master MACMedia Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network.
Redundant VPNC MACMedia Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network.
Country Code
Option 43 contains the following information:
masterip, country-code, master-mac1 (No L2 redundant Master)
masterip, country-code, master-mac1, master-mac2 (L2 Redundant Master)
masterip, country-code, vpnc ip, vpnc-mac1 (No L2 Redundant VPNC)
masterip, country-code, vpnc ip, vpnc-mac1, vpnc-mac2 (L2 Redundant VPNC)
Perform the following steps to convert the 9004 device with an SDWAN image to a controller:
1. Ensure that the 9004 device is added in the correct Activate folder. For example, the folder should have the rule and the device serial number should be similar to CNHHKLB02B.
2. Reset the 9004 device to factory image and the 9004 device loads the 8.6.0.0 image.
|
|
In this example, ArubaOS 8.5.0.3 image is used. |
Aruba Networks
ArubaOS Version 8.5.0.0-1.0.7.1 (build 72342 / label #72342)
Built by p4build@pr-hpn-build05 on 2019-09-20 at 15:32:42 UTC (gcc version 4.9.4)
(c) Copyright 2019 Hewlett Packard Enterprise Development LP.
[02:47:16]:Starting device manager [ OK ]
<<<<< Welcome to Aruba Networks - Aruba A9004-US >>>>>
[02:47:18]:Probing for real-time clock [ OK ]
[02:47:18]:Uncompressing core image files [ OK ]
[02:47:36]:Extracting corefs [ OK ]
[02:47:36]:Waiting for storage device ... [ OK ]
Performing partition fast test... [ DONE ]
Checking for file system... [ OK ]
[02:47:37]:Mounting flash [ OK ]
[02:47:37]:Mounting disk1 [ OK ]
[02:47:37]:Mounting disk2 [ OK ]
[02:47:37]:Initializing 256MB as swap on zRam0 [ OK ]
[02:47:39]:Turning swap ON on zRAM0 [ OK ]
[02:47:39]:Installing ancillary FS [ OK ]
Performing integrity check on ancillary partition 0 [ OK ]
Running Startup script from /flashmv: unable to rename `/flash/config/fpapps': No such file or directory
mv: unable to rename `/flash/config/policymgr': No such file or directory
mv: unable to rename `/flash/config/hcm': No such file or directory
mv: unable to rename `/flash/config/sos.elf': No such file or directory
[ OK ]
[02:47:43]:QAT driver initialization [ OK ]
[02:47:59]:Reboot Cause: User reboot (Intent:cause: 86:50)
[02:47:59]:Starting syslog service [ OK ]
[02:47:59]:Deleting the Databases [ OK ]
[02:47:59]:Restoring the database [ OK ]
[02:47:59]:Starting random number generation service [ OK ]
[02:47:59]:Intel RDRAND is supported [ OK ]
[02:47:59]:Initiating hw random number generation service [ OK ]
[02:47:59]:Generating SSH keys [ OK ]
[02:47:59]:SPI NOR flash mounted successfully [ OK ]
[02:48:00]:Initializing TPM and certificates [ OK ]
[02:48:00]:Checking for configuration upgrade [ OK ]
[02:48:00]:Installing crash kernel [ OK ]
[02:48:01]:rcS Done(45 sec)
[02:48:01]:Starting OS services [ OK ]
n^?e
enable-debug
Starting ztp
Starting ztp auto provision
Starting auto provisioning
Registered for NTP Sync
Initiated DHCP, awaiting DHCP response
Received DHCP response, My IP = 192.168.82.1, Master = none, Mask = 255.255.255.0, GW = 192.168.82.254, DNS = 10.44.17.241, Country code = none, Physical Port = 3
Oct 28 02:49:28 LOG: Received DHCP response, My IP = 192.168.82.1, Master = none, Mask = 255.255.255.0, GW = 192.168.82.254, DNS = 10.44.17.241, Country code = none
DNS server name 10.44.17.241 assigned to info structure..
Oct 28 02:49:28 LOG: DNS server name 10.44.17.241 assigned to info structure..
Master info not received, trying activate
Oct 28 02:49:28 LOG: Master info not received, trying activate
Oct 28 02:49:28 LOG: Starting Activate communication
Oct 28 02:49:28 LOG: Activate server URL being used for auto-provisioning https://device.arubanetworks.com/provision
Oct 28 02:49:28 LOG: Sending provisioning parameters request to Activate
Oct 28 02:49:28 LOG: Posting message to Activate
Oct 28 02:49:28 LOG: Executing CURL Command /usr/sbin/curl https://device.arubanetworks.com/provision --cacert /tmp/act_cert_bundle.pem -X POST -H Expect: --trace-ascii /var/log/oslog/activate/trace1.txt -H "Connection: Keep-Alive" -H "X-Type: provision-update" -H "Content-Length: 0" -H "X-Mode: CONTROLLER" -H "X-Current-Version: 8.5.0.0-1.0.7.1_72342" -H "X-Ap-Info: CNHHKLB02B, 20:4c:03:40:0b:78, Aruba9004-US" -D /var/log/oslog/activate/act_resp
Oct 28 02:49:28 LOG: Provisioning parameters request sent to Activate
curl: (6) Could not resolve host: device.arubanetworks.com
Oct 28 02:49:28 LOG: Activate handler invoked for client 7230
Oct 28 02:49:28 ERR: Activate client failed with status 1536
Oct 28 02:49:28 ERR: Terminating Activate connection due to failure
Oct 28 02:49:28 LOG: Stopping Activate communication
Oct 28 02:49:28 LOG: Destroying Activate context
Oct 28 02:49:28 LOG: Calling response handler
Provisioning Parameters not received from Activate, will retry after 30 seconds
Oct 28 02:49:28 ERR: Activate failed, will retry after 30 seconds
Oct 28 02:49:28 LOG: Acitvate retry count is 1. Retries before DHCP reset: 9
Oct 28 02:49:58 LOG: Retrying Activate device.arubanetworks.com
Oct 28 02:49:58 LOG: Starting Activate communication
Oct 28 02:49:58 LOG: Activate server URL being used for auto-provisioning https://device.arubanetworks.com/provision
Oct 28 02:49:58 LOG: Sending provisioning parameters request to Activate
Oct 28 02:49:58 LOG: Posting message to Activate
Oct 28 02:49:58 LOG: Executing CURL Command /usr/sbin/curl https://device.arubanetworks.com/provision --cacert /tmp/act_cert_bundle.pem -X POST -H Expect: --trace-ascii /var/log/oslog/activate/trace1.txt -H "Connection: Keep-Alive" -H "X-Type: provision-update" -H "Content-Length: 0" -H "X-Mode: CONTROLLER" -H "X-Current-Version: 8.5.0.0-1.0.7.1_72342" -H "X-Ap-Info: CNHHKLB02B, 20:4c:03:40:0b:78, Aruba9004-US" -D /var/log/oslog/activate/act_resp
Oct 28 02:49:58 LOG: Provisioning parameters request sent to Activate
Oct 28 02:49:58 LOG: Activate handler invoked for client 7461
Oct 28 02:49:58 LOG: Parsing activate response
Oct 28 02:49:58 LOG: Received challenge, sending challenge response
Oct 28 02:49:58 LOG: Handling challenge and encoding it
Oct 28 02:49:58 LOG: Adding challenge hash
Oct 28 02:49:58 LOG: Adding message body
Oct 28 02:49:58 LOG: Posting message to Activate
Oct 28 02:49:58 LOG: Executing CURL Command /usr/sbin/curl https://device.arubanetworks.com/provision --cacert /tmp/act_cert_bundle.pem --trace-ascii /var/log/oslog/activate/trace2.txt -H "Connection: close" -H "X-Type: provision-update" -H "Content-Length: 2630" -H "X-Mode: CONTROLLER" -H "X-Current-Version: 8.5.0.0-1.0.7.1_72342" -H "X-Session-Id: 0f29ab6a-43d0-444d-8cdc-b26763a39945" -H "X-Challenge-Hash: SHA-1" -H "X-Oem-Tag: Aruba" -H "X-Ap-Info: CNHHKLB02B, 20:4c:03:40:0b:78, Aruba9004-US" --data-binary @/var/log/oslog/activate/act_body -D /var/log/oslog/activate/act_resp -o /var/log/oslog/activate/act_rbody
Oct 28 02:49:58 LOG: Challenge response sent to Activate
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 2720 100 90 100 2630 468 13697 --:--:-- --:--:-- --:--:-- 14240
Oct 28 02:49:58 LOG: Activate handler invoked for client 7467
Oct 28 02:49:58 LOG: Parsing activate response
Oct 28 02:49:58 LOG: Mandatory upgrade information available [8.5.0.3_72498], running version [8.5.0.0-1.0.7.1_72342]
Oct 28 02:49:58 LOG: Attempting mandatory upgrade firmware with http://activate-frm5-cf.arubathena.com/fwfiles/ArubaOS_90xx_8.5.0.3_72498...
............................................................Oct 28 02:50:18 LOG:
Checking if the file was downloaded successfully and try to update flash...
Image is signed;
Image is signed;
Image upgrade done sucessfully!
3. Ensure to have the required configurations in the Mobility Master, where the device terminates. After the 9004 devices comes up with required image, verify that the device is in UP and UPDATE SUCCESSFUL state.
(MASTER_CTRL_40_0B_78) #show roleinfo
switchrole:MD
masterip:10.8.248.150
Certificate Type: Factory Certificates
Master MAC: 20:4c:03:13:a0:e4
(MASTER_CTRL_40_0B_78) #show image version
----------------------------------
Partition : 0:0 (/mnt/disk1) **Default boot**
Software Version : ArubaOS 8.5.0.3 (Digitally Signed SHA1/SHA256 - Production Build)
Build number : 72498
Label : 72498
Built on : Tue Oct 1 08:00:09 UTC 2019
----------------------------------
Partition : 0:1 (/mnt/disk2)
Software Version : ArubaOS 8.5.0.3 (Digitally Signed SHA1/SHA256 - Production Build)
Build number : 72498
Label : 72498
Built on : Tue Oct 1 08:00:09 UTC 2019
(MASTER_CTRL_40_0B_78) #show switches
All Switches
------------
IP Address IPv6 Address Name Location Type Model Version Status Configuration State Config Sync Time (sec) Config ID
---------- ------------ ---- -------- ---- ----- ------- ------ ------------------- ---------------------- ---------
3.4.5.6 None MASTER_CTRL_40_0B_78 Building1.floor1 MD Aruba9004 8.5.0.3_72498 up UPDATE SUCCESSFUL 6 10
Total Switches:1
Was this information helpful?
Great! Thanks for the feedback
Sorry about that! How can we improve it? Send your comments and suggestions!