provision-ap
provision-ap
a-ant-bearing <bearing>
a-ant-gain <gain>
a-ant-pol <a-ant-pol>
a-ant-tilt-angle <angle>
a-antenna {1|2|both}
altitude <altitude>
ap-group <group>
ap-lldp-pse-detect {disabled|enabled}
ap-name <name>
ap-poe-power-optimization
ap2xx-prestandard-poe-detection
apdot1x-factory-cert
apdot1x-passwd <string>
apdot1x-timeout-bypass
apdot1x-timeout-retries
apdot1x-tls
apdot1x-tls-suffix
apdot1x-tls-suffix-domain <apdot1x-tls-suffix-domain>
apdot1x-username <name>
aruba-modem-apn <aruba-modem-apn>
aruba-modem-plmn <aruba-modem-plmn>
aruba-modem-user <aruba-modem-user>
aruba-modem-passwd <aruba-modem-passwd>
aruba-modem-auth <aruba-modem-auth>
cellular_nw_preference 3g-only|4g-only|advanced|auto
cert-DN
dns-server-ip <ipaddr>
dns-server-ip6 <ipv6 address>
domain-name <name>
dynamic-ant {0|1}
external-antenna
fqln <name>
g-ant-bearing <bearing>
g-ant-gain <gain>
g-ant-pol <g-ant-pol>
g-ant-tilt-angle <angle>
g-antenna {1|2|both}
gateway <ipaddr>
gateway6 <ipv6-address>
ikepsk <key>
ikepsk-hex-based
iot-ant-gain <gain>D
installation default|indoor|outdoor
ip6addr <ipv6-address>
ip6-addr-gen-mode <eui64|stable-privacy>
ip6prefix <ipv6-prefix>
ipaddr <ipaddr>
latitude <location>
link-priority-cellular <link-priority-cellular>
link-priority-ethernet <link-priority-ethernet>
link-priority-wifi <link-priority-wifi>
longitude <location>
master
master
mesh-role {mesh-auto|mesh-point|mesh-portal|none|remote-mesh-portal}
mesh-sae {sae-disable|sae-enable}
netmask <netmask>
no ...
ocsp_default
pap-passwd <string>
pap-user <name>
pkcs12-passphrase <string>
pppoe-chap-secret<key>
pppoe-passwd <string>
pppoe-service-name <name>
pppoe-user <name>
preferred_uplink
radio-0-5ghz-ant-gain <radio-0-5ghz-ant-gain>
radio-0-5ghz-ant-pol <radio-0-5ghz-ant-pol>
radio-1-5ghz-ant-gain <radio-1-5ghz-ant-gain>
radio-1-5ghz-ant-pol <radio-1-5ghz-ant-pol>
remote-ap
read-bootinfo {ap-name <name>|ip-addr <ipaddr>|wired-mac <macaddr>}
reprovision {all|ap-name <name>|ip-addr <ipaddr>|ip6-addr <ip6-addr>|serial-num <string>|wired-mac <macaddr>}
reset-bootinfo {ap-name <name>|ip-addr <ipaddr>|wired-mac <macaddr>}
sch-mode-radio-0
sch-mode-radio-1
sch-mode-radio-6ghz
server-ip <server-ip>
server-name <name>
set-ikepsk-by-addr <ip-addr>
set-trust-anchor
syslocation <string>
trustanchor
uplink-vlan <uplink-vlan>
usb-csr
usb-dev <usb-dev>
usb-dial <usb-dial>
usb-init <usb-init>
usb-passwd <usb-passwd>
usb-power-mode {auto|enable|disable}
usb-tty <usb-tty>
usb-tty-control <usb-tty-control>
usb-type <usb-type>
usb-user <usb-user>
wifi-uplink
Description
This command provisions or reprovisions an AP.
You do not need to provision APs before installing and using them. The exceptions are outdoor APs, which have antenna gains that you must provision before they can be used, and APs configured for mesh. You must provision the AP before you install it as a mesh node in a mesh deployment.
Users less familiar with this process may prefer to use the Provisioning page in the WebUI to provision an AP.
Provisioned or re-provisioned values do not take effect until the AP is rebooted. APs reboot automatically after they are successfully reprovisioned.
To enable cellular uplink for a Remote AP, the Remote AP must have the device driver for the USB data card and the correct configuration parameters. AOS includes device drivers for the most common hardware types, but you can use the usb commands in this profile to configure a Remote AP to recognize and use an unknown USB modem type.
Parameter |
Description |
---|---|
a-ant-bearing |
Determines the horizontal coverage distance of the 802.11a (5 GHz) antenna from True North. From a planning perspective, the horizontal coverage pattern does not consider the elevation or vertical antenna pattern. This parameter is supported on outdoor APs only. 0-360 Decimal Degrees |
a-ant-gain |
Antenna gain for 802.11a (5GHz) antenna. |
a-ant-pol |
Antenna polarization value for 5GHz radio. Use one of the following parameters: 0: CO-Polarized 1: Cross-Polarized |
a-ant-tilt-angle |
Directs the angle of the 802.11a (5GHz) antenna for optimum coverage. Use a - (negative) value for downtilt and a + (positive) value for uptilt. This parameter is supported on outdoor APs only. -90 to +90 Decimal Degrees |
a-antenna |
Antenna use for 5 GHz (802.11a) frequency band. Use one of the following parameters: 1: Use antenna 1 2: Use antenna 2 both: Use both antennas (default) 1, 2, both both |
altitude |
Altitude, in meters, of the AP. This parameter is supported on outdoor APs only. |
ap-group |
Name of the AP group to which the AP belongs. |
ap-lldp-pse-detect |
Enabling causes the AP to detect the POE type via LLDP POE TLV. Use one of the following parameters: : The AP uses PSE TYPE in the POE TLV to detect the PSE type. : The AP detects the POE using the HW classification. |
ap-name |
Name of the AP to be provisioned. |
ap-poe-power-optimization |
Enables optimization to minimize the POE draw of the AP. Enabling optimization may disable some parts of the AP. Disabling optimization ensures all features are enabled. |
ap2xx-prestandard-poe-detection |
Configures the pre-standard PoE detection on 200 Series APs. The POE+ pre-standard detection is only available on 200 Series APs. It consists of a basic voltage comparator. If the line voltage is equal to or greater than 51 V, the PSE is assumed to be 802.3at compatible. |
apdot1x-factory-cert |
Enables AP to use factory certificates when doing 802.1x EAP-TLS. |
apdot1x-passwd |
Password of the AP to authenticate to 802.1X using PEAP. |
apdot1x-timeout-bypass |
Enables AP to be provisioned when 802.1X authentication times out. |
apdot1x-timeout-retries |
Sets the apdot1x timeout threshold. If the auth timeouts over this threshold, the AP will bypass apdot1x auth. |
apdot1x-tls |
Enables AP to 802.1x using EAP-TLS. |
apdot1x-tls-suffix |
Enables AP to use EAP-TLS username suffix. |
apdot1x-tls-suffix-domain <apdot1x-tls-suffix-domain> |
Set the suffix domain for AP dot1x EAP-TLS username. If defined, use EAP-TLS username as suffix, else use .1- 63 string length |
apdot1x-username |
Username of the AP to authenticate to 802.1X using PEAP. |
aruba-modem-apn <aruba-modem-apn> |
Configures the APN of HPE Aruba Networking 4G LTE modem. |
aruba-modem-plmn <aruba-modem-plmn> |
Configures the PLMN of HPE Aruba Networking 4G LTE modem. |
aruba-modem-user <aruba-modem-user> |
Specifies the username of subscriber of the selected ISP. |
aruba-modem-passwd <aruba-modem-passwd> |
Specifies the password for the account associated with the subscriber of the selected ISP. |
aruba-modem-auth <aruba-modem-auth> |
Specifies the authentication type for USB.
pap |
cellular_nw_preference |
This setting allows you to select how the modem should operate. (default): In this mode, the modem firmware will control the cellular network service selection; so the cellular network service failover and fallback is not interrupted by the Remote AP. : Locks the modem to operate only in 3G. : Locks the modem to operate only in 4G. : The Remote AP controls the cellular network service selection based on the Received Signal Strength Indication (RSSI) threshold-based approach. Initially the modem is set to the default auto mode. This allows the modem firmware to select the available network. The Remote AP determines the RSSI value for the available network type (for example 4G), checks whether the RSSI is within required range, and if so, connects to that network. If the RSSI for the modem’s selected network is not within the required range, the Remote AP will then check the RSSI limit of an alternate network (for example, 3G), and reconnect to that alternate network. The Remote AP will repeat the above steps each time it tries to connect using a 4G multimode modem in this mode. |
cert-DN |
The Server Certificate CN for Identity |
dns-server-ip |
IP address of the DNS server for the AP. |
dns-server-ip6 |
IPv6 address of the DNS server for the AP. |
domain-name |
Domain name for the AP. |
dynamic-ant |
Specifies the antenna mode on 5 GHz and 6 GHz, in AP-679 and AP-679EX access points.
Use one of the following parameters:
NOTE: The wide antenna mode is set as default. |
external-anten |
Use an external antenna with the AP. |
fqln |
FQLN for the AP, in the format <APname.floor.building.campus>. |
g-ant-bearing |
Determines the horizontal coverage distance of the 802.11g (2.4GHz) antenna from True North. From a planning perspective, the horizontal coverage pattern does not consider the elevation or vertical antenna pattern. This parameter is supported on outdoor APs only. If you use this parameter to configure an indoor AP, an error message is displayed. 0-360 decimal degrees |
g-ant-gain |
Antenna gain for 802.11g (2.4GHz) antenna. |
g-ant-pol |
Antenna polarization value for 2.4GHz radio. Use one of the following parameters: 0: CO-Polarized 1: Cross-Polarized |
g-ant-tilt-angle |
Directs the angle of the 802.11g (2.4GHz) antenna for optimum coverage. Use a - (negative) value for downtilt and a + (positive) value for uptilt. This parameter is supported on outdoor APs only. If you use this parameter to configure an indoor AP, an error message is displayed. -90 to +90 Decimal Degrees |
g-antenna |
Antenna use for 2.4 GHz (802.11g) frequency band. Use one of the following parameters: 1: Use antenna 1 2: Use antenna 2 both: Use both antennas 1, 2, both both |
gateway |
IP address of the default gateway for the AP. |
gateway6 |
IPv6 address of the default gateway for the AP. |
ikepsk |
IKE preshared key for the AP. |
ikepsk-hex-based |
Specify if the ikepsk is hex-based or text-based. (set -> Hex, unset -> Text). |
iot-ant-gain <gain> |
Configures an antenna gain value for APs with external antennas. |
installation |
Specifies the type of installation (indoor or outdoor). The default parameter automatically selects an installation mode based upon the AP model type. indoor, outdoor |
ip6addr |
Static IPv6 address of the AP. |
ip6-addr-gen-mode <eui64|stable-privacy> |
This parameter specifies the method to generate IPv6 addresses. There are two supported methods for this process.
|
ip6prefix |
The prefix of static IPv6 address of the AP. |
ipaddr |
Static IP address for the AP. |
latitude |
Latitude coordinates of the AP. Use the format: Degrees, Minutes, Seconds (DMS). For example: 37 22 00 N |
link-priority-cellular <link-priority-cellular>
|
Sets the priority of the cellular uplink. By default, the cellular uplink is a lower priority than the wired uplink; making the wired link the primary link and the cellular link the secondary or backup link. Configuring the cellular link with a higher priority than your wired link priority will set your cellular link as the primary link. |
link-priority-ethernet <link-priority-ethernet>
|
Sets the priority of the wired uplink. Each uplink type has an associated priority; wired ports having the highest priority by default. |
link-priority-wifi <link-priority-wifi> |
Sets the priority of the Wi-Fi uplink. Both Wi-Fi and wired uplink types have equal priority, depending on their availablility. If one of the uplink types is not available, the other uplink type is set as the primary link by default. However if both the uplink types are available, one of them is chosen randomly as the primary link. |
longitude |
Longitude coordinates of the AP. Use the DMS format. For example: 122 02 00 W |
master |
Name or IP address of the Mobility Conductor. |
master |
Configures the preferred IP protocol (IPv4 or IPv6) for AP master |
mesh-role |
Configures the AP to operate as a mesh node. You assign one of four roles: mesh portal, mesh point or remote mesh point. If you select , the AP operates as a thin AP. , |
mesh-sae |
Enables or disables Simultaneous Authentication of Equals (SAE) on a mesh network. This option offers enhanced security over the default wpa2-psk-aes mesh security setting, and provides secure, attack-resistant authentication using a PSK. SAE supports simultaneous initiation of a key exchange, allowing either party to initiate an exchange or both parties to initiate a key exchange simultaneously To use the SAE feature, you must enable this parameter on all mesh nodes (points and portals) in the network, to prevent mesh link connectivity issues. This is a Beta feature only. This parameter should be kept “disabled” for this release. |
netmask |
Netmask for the IP address. |
ocsp_default |
If this parameter is set to 0 (default accept) and the certificate status is unknown, the server certificate is considered valid and the Remote AP comes up. If this parameter is set to 1 (default deny) and the certificate status is unknown, the server certificate is considered revoked and the Remote AP does not come up. By default, OCSP default is set to 0 (default accept). |
no |
Negates any configured parameter. |
pap-passwd |
PAP password for the AP. You can use special characters in the PAP password. Following are the restrictions: You cannot use double-byte characters You cannot use a tilde (~) You cannot use a tick (‘) If you use quotes (single or double), you must use the backslash (\) before and after the password |
pap-user |
PAP username for the AP. |
pkcs12-passphrase |
Passphrase in PKCS12 format. |
pppoe-chap-secret |
PPPoE CHAP secret key for the AP. |
pppoe-passwd |
PPPoE password for the AP. |
pppoe-service- |
PPPoE service name for the AP. |
pppoe-user |
PPPoE username for the AP. |
preferred_uplink |
Choose AP preferred uplink interface (eth0-eth1). This is only applicable to AP-318, AP-374, AP-375, and AP-377 access points. |
radio-0-5ghz-ant-gain <radio-0-5ghz-ant-gain> |
Antenna gain for Radio 0 (5 GHz) antenna. This parameter is only needed for APs that support dual 5 GHz mode. |
radio-0-5ghz-ant-pol <radio-0-5ghz-ant-pol> |
Antenna polarization value for Radio 0 (5 GHz) antenna. Use one of the following parameters: 0: CO-Polarized 1: Cross-Polarized This parameter is only needed for APs that support dual 5 GHz mode. |
radio-1-5ghz-ant-gain <radio-1-5ghz-ant-gain> |
Antenna gain for Radio 1 (5 GHz) antenna. This parameter is only needed for APs that support dual 5 GHz mode. |
radio-1-5ghz-ant-pol <radio-1-5ghz-ant-pol> |
Antenna polarization value for Radio 1 (5 GHz) antenna. Use one of the following parameters: 0: CO-Polarized 1: Cross-Polarized This parameter is only needed for APs that support dual 5 GHz mode. |
read-bootinfo |
Retrieves current provisioning parameters of the specified AP. This parameter can only be used on the Mobility Conductor. |
remote-ap |
This is a remote AP. |
Provisions one or more APs with the values in the provisioning-params workspace. To use reprovision, you must use read-bootinfo to retrieve the current values of the APs into the provisioning-ap-list. This parameter can only be used on the Mobility Conductor. After you complete configuration in the CLI, reprovision the AP for the configuration to take effect. |
|
reset-bootinfo |
Restores factory default provisioning parameters to the specified AP. This parameter can only be used on the Mobility Conductor. |
sch-mode-radio-0 |
If you are provisioning an 802.11n-capable AP, you can issue the sch-mode-radio-0 command to enable single-chain mode for the selected radio. AP radios in single-chain mode will transmit and receive data using only legacy rates and single-stream HT rates up to MCS 7. This setting is disabled by default. |
sch-mode-radio-1 |
If you are provisioning an 802.11n-capable AP, you can issue the sch-mode-radio-1 command to enable single-chain mode for the selected radio. AP radios in single-chain mode will transmit and receive data using only legacy rates and single-stream HT rates up to MCS 7. This setting is disabled by default. |
sch-mode-radio-6ghz |
If you are provisioning an 802.11n-capable AP, you can issue the sch-mode-radio-6Ghz command to enable single-chain mode for the selected radio. AP radios in single-chain mode will transmit and receive data using only legacy rates and single-stream HT rates up to MCS 7. This setting is disabled by default. |
server-ip |
IPv4 or IPv6 address of the managed device from which the AP boots. |
server-name |
DNS name of the managed device from which the AP boots. |
set-ikepsk-by-addr |
Sets a IKE preshared key to correspond to a specific IP address. |
set-trust-anchor |
Set trust anchor for the AP. |
syslocation |
User-defined description of the location of the AP. |
trustanchor |
Name of the trust anchor. |
uplink-vlan <uplink-vlan> |
If you configure an uplink VLAN on an AP connected to a port in trunk mode, the AP sends and receives frames tagged with this VLAN on its Ethernet uplink. By default, an AP has an uplink vlan of 0, which disables this feature. If an AP is provisioned with an uplink VLAN, it must be connected to a trunk mode port or the AP’s frames will be dropped. |
usb-csr |
The USB storage for CSR and private key file. |
usb-dev |
The USB device identifier, if the device is not already supported. |
usb-dial |
The dial string for the USB modem. This parameter only needs to be specified if the default string is not correct. |
usb-modeswitch "-v <default_vendor> -p <default_product> -V <target_vendor> -P <target_product> -M <message_content>" |
USB cellular devices on Remote APs typically register as modems, but may occasionally register as a mass-storage device. If a Remote AP cannot recognize its USB cellular modem, use the You must enclose the entire modeswitch parameter string in quotation marks. |
usb-init |
The initialization string for the USB modem. This string configures the AP Name setting of the USB modem. For the USB modem to understand this string, the value entered should adhere to one of the following formats: Use double-quotes and prefix them with a backslash character. See example below:
Use single-quote instead of double-quotes. AP translates single-quote into double-quotes. See example below:
Use the string begin-end pair without double quotes. See example below:
In some cases, the 4G/LTE modem requires the configuration of two AP Names during USB initialization. The first AP Name initiates the connection to obtain an IP address, and the second AP Name sends and receives data. Use the delimiter character to create two separate strings for the AP Names in the command. See example below:"AT+CGDCONT=1,\"IP\",\"APN1\";1,1,\"APN2\"" You must obtain the AP Name from your ISP and ensure that each AP Name entry follows the manufacturer's AT command reference. |
usb-passwd |
A PPP password, if provided by the cellular service provider |
usb-power-mode auto| enable|disable |
Sets the USB power mode to control the power to the USB port. |
usb-tty |
The TTY device path for the USB modem. This parameter only needs to be specified if the default path is not correct. |
usb-tty-control |
The TTY device control path for the USB modem. This parameter only needs to be specified if the default path is not correct. |
usb-type |
Specify the USB driver type. : Use ACM driver : Use Airprime driver : Use Beceem driver for 4G-WiMAX : Use CDC Ether driver for direct IP 4G device : Use HSO driver for newer Option : Disable 3G or 2G network on USB : Use Option driver : Same as "pantech-uml290" - to support upgrade : Use Pantech USB driver for UML290 device : Use Pantech USB driver for 4G device : Use a RNDIS driver for a 4G device : Use EVDO Sierra Wireless driver : Use GSM Sierra Wireless driver :Use SIERRA Direct IP driver for 4G device : Use USB flash as storage device for storing Remote AP certificates |
usb-user |
The PPP username provided by the cellular service provider. |
wifi-uplink |
Enables the AP to use Wi-Fi uplink. |
Provisioning a Single AP
To provision a single AP:
- Use the read-bootinfo option to read the current information from the deployed AP you wish to reprovision.
- Use the show provisioning-ap-list command to see the AP to be provisioned.
- Use the copy-provisioning-params option to copy the AP’s parameter values to the provisioning-params workspace.
- Use the provision-ap options to set new values. Use the show provisioning-params command to display parameters and values in the provisioning-params workspace. Use the clear provisioning-params command to reset the workspace to default values.
- Use the reprovision option to provision the AP with the values in provisioning-params workspace. The AP automatically reboots.
Provisioning Multiple APs at a Time
You can change parameter values for multiple APs at a time, however, note the following:
- You cannot provision the following AP-specific options on multiple APs:
- ap-name
- ipaddr
- pap-user
- pap-passwd
- ikepsk
- If any of these options are already provisioned on the AP, their values are retained when the AP is reprovisioned.
- The values of the server-name, a-ant-gain, or g-ant-gain options are retained if they are not reprovisioned.
- All other values in the provisioning-params workspace are copied to the APs.
To provision multiple APs at the same time:
- Use the read-bootinfo to read the current information from each deployed AP that you wish to provision.
The AP parameter values are written to the provisioning-ap-list. To reprovision multiple APs, the APs must be present in the provisioning-ap-list. Use the show provisioning-ap-list command to see the APs that will be provisioned. Use the clear provisioning-ap-list command to clear the provisioning-ap-list.
- Use the copy-provisioning-params option to copy an AP’s parameter values to the provisioning-params workspace.
- Use the provision-ap options to set new values. Use the show provisioning-params command to display parameters and values in the provisioning-params workspace. Use the clear provisioning-params command to reset the workspace to default values.
- Use the reprovisionall option to provision the APs in the provisioning-ap-list with the values in provisioning-params workspace. All APs in the provisioning-ap-list automatically reboot.
The following are useful commands when provisioning one or more APs:
show|clear provisioning-ap-list
displays or clears the APs that will be provisioned.show|clear provisioning-params
displays or resets values in the provisioning-params workspace.show ap provisioning
shows the provisioning parameters an AP is currently using.
Example
The following example changes the IP address of the Mobility Conductor on the AP:
(host) [mynode] (config) #provision-ap
(host) [mynode] (config-submode)read-bootinfo ap-name lab103
(host) [mynode] (config-submode)show provisioning-ap-list
(host) [mynode] (config-submode)copy-provisioning-params ap-name lab103
(host) [mynode] (config-submode)master
(host) [mynode] (config-submode)reprovision ap-name lab103
The following example configures the preferred IP protocol for AP master
(host) [mynode] (config) #provision-ap
(host) [mynode] (config-submode)master
The following example configures the APN and PLMN of HPE Aruba Networking MDM-USB-LTE 4G modem:
(host) [mynode] (config) #provision-ap
(host) [mynode] (config-submode) #aruba-modem-apn <aruba-modem-apn>
(host) [mynode] (config-submode) #aruba-modem-plmn <aruba-modem-plmn>
Command History
Release |
Modification |
AOS 8.12.0.0 |
The following parameters were added:
|
AOS 8.10.0.0 |
The following parameters were introduced:
iot-ant-gain <gain> |
|
The following parameters were introduced:
|
AOS 8.7.0.0 |
The |
AOS 8.5.0.0 |
The following parameters were added:
|
AOS 8.4.0.0 |
The following parameters were added:
|
AOS 8.3.0.0 |
The following parameters were added:
|
AOS 8.2.0.0 |
The following parameters were added:
|
AOS 8.1.0.0 |
The |
AOS 8.0.0.0 |
Command introduced. |
Command Information
Platforms |
License |
Command Mode |
All platforms, except for the parameters noted in the syntax table. |
Base operating system, except for the parameters noted in the syntax table. |
Config mode on Mobility Conductor. |