Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
HPE Aruba Networking Central On-Premises Deployment
HPE Aruba Networking Central On-Premises deployment can be done in two different ways:
-
Appliance—In this mode, customers deploy HPE Aruba Networking Central On-Premises on Aruba Central Appliance (R1Q05B) or Aruba Central Ready AirWave 8 Appliance (R1Q04B). For Gen 11 appliance mode deployment, it supports s4P01A appliance.
-
HPE Aruba Networking Central On-Premises on Bare Metal (non-appliance)—In this mode, customers deploy HPE Aruba Networking Central On-Premises on HPE servers as mentioned in the following tables:
Attention
While using HPE Aruba Networking Central On-Premises on bare metal mode, you should only use HPE OEM ProLiant DL360 Gen10 and Gen11 8SFF CTO Server platform along with the configurations mentioned in the tables below.
While using HPE DL360 servers, you can use a mix of Gen 10 and Gen 11 servers.
Important Notes
If you install HPE Aruba Networking Central On-Premises in non-appliance mode using HPE DL360 server, then you must set the following configuration on the server before proceeding with the installation:
-
Disable TPM Trusted Platform Module. TPM is an international standard for a secure cryptoprocessor, which is a dedicated microcontroller designed to secure hardware by integrating cryptographic keys into devices. in the ILO configuration
-
Set TPM visibility to false in the BIOS Basic Input/Output System (BIOS) program is used by a computer's microprocessor to start the system when powered on. It also manages the data flow between the operating system and other attached devices, for example, keyboard, hard disk, mouse, video adapter, etc. setting
-
To onboard an IAP websocket connection, you must upload any trusted CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. certificate to the HPE Aruba Networking Central On-Premises cluster.
-
To onboard a controller websocket connection for troubleshooting any issues, you must download root CA certificate from the HPE Aruba Networking Central On-Premises cluster and use the same certificate in the controller.
The following accessories are required to support HPE Aruba Networking Central On-Premises on both Bare Metal and Appliance mode for Gen 11:
-
Aruba 10Gb SFP The Small Form-factor Pluggable. SFP is a compact, hot-pluggable transceiver that is used for both telecommunication and data communications applications. + to SFP+ 1m Direct Attach Cable J9281D
-
Aruba 10Gb SFP+ to SFP+ 3m Direct Attach Cable J9283D
-
Aruba 10Gb SFP+ to SFP+ 7m Direct Attach Cable J9285D
Along with the DAC cables mentioned above, J9150D (Aruba 10G SFP+ LC SR 300m OM3 MMF Transceiver) is the supported SFP Transceiver.
The following table lists the only supported server specification that can be purchased from HPE to support HPE Aruba Networking Central On-Premises on Bare Metal mode for Gen 11:
| Quantity |
Product Part Number |
Description |
|---|---|---|
|
1 |
P52499-B21 |
HPE DL360 Gen11 8SFF CTO Server |
|
1 |
P52499-B21 |
HPE DL360 Gen11 8SFF CTO Server |
|
2 |
P49599-B21 |
INT Xeon-G 6442Y CPU Central Processing Unit. A CPU is an electronic circuitry in a computer for processing instructions. for HPE |
|
2 |
P49599-B21 |
Factory Integrated |
|
16 |
P43328-B21 |
HPE 32GB 2Rx8 PC5-4800B-R Smart Kit |
|
16 |
P43328-B21 |
Factory Integrated |
|
1 |
P48895-B21 |
HPE DL360 G11 8SFF x1 U.3 TM BP Kit |
|
1 |
P48895-B21 |
Factory integrated |
|
5 |
P49049-B21 |
HPE 1.6TB SAS MU SFF BC MV SSD |
|
5 |
P49049-B21 |
Factory Integrated |
|
1 |
P48926-B21 |
HPE DL3X0 G11 1U DP/USB Universal Serial Bus. USB is a connection standard that offers a common interface for communication between the external devices and a computer. USB is the most common port used in the client devices. /ODD Blank Kit |
|
1 |
P48926-B21 |
Factory Integrated |
|
1 |
726536-B21 |
HPE 9.5mm SATA DVD-ROM Optical Drive |
|
1 |
726536-B21 |
Factory Integrated |
|
1 |
P51178-B21 |
BCM 5719 1Gb 4p BASE-T Adptr |
|
1 |
P51178-B21 |
Factory Integrated |
|
1 |
P01366-B21 |
HPE 96W Smart Stg Li-ion Batt 145mm Kit |
|
1 |
P01366-B21 |
Factory Integrated |
|
1 |
P48918-B21 |
HPE DL360 Gen11 Stg Cntrl Enable Cbl Kit |
|
1 |
P48918-B21 |
Factory Integrated |
|
1 |
P47781-B21 |
HPE MR416i-o Gen11 SPDM Storage Cntlr |
|
1 |
P47781-B21 |
Factory Integrated |
|
1 |
P10106-B21 |
INT E810 10/25GbE 2p SFP28 OCP3 Adptr |
|
1 |
P10106-B21 |
Factory Integrated |
|
1 |
P48908-B21 |
HPE DL3X0 Gen11 1U High Perf Fan Kit |
|
1 |
P48908-B21 |
Factory Integrated |
|
1 |
P38997-B21 |
HPE 1600W FS Plat Ht Plg LH Pwr Sply Kit |
|
1 |
P38997-B21 |
Factory Integrated |
|
1 |
BD505A |
HPE iLO Integrated Lights-Out (iLO) by Hewlett-Packard Enterprise is a proprietary embedded server management technology providing out-of-band management facilities. Adv 1-svr Lic 3yr Support |
|
1 |
BD505A |
Factory Integrated |
|
1 |
P48830-B21 |
HPE DL3XX Gen11 CPU2/OCP2 x8 Enable Kit |
|
1 |
P48830-B21 |
Factory Integrated |
|
1 |
P52416-B21 |
HPE DL360 Gen11 OROC TM Cbl Kit |
|
1 |
P52416-B21 |
Factory Integrated |
|
6 |
845970-B21 |
HPE QSFP28 to SFP28 Adapter |
|
6 |
845970-B21 |
Factory Integrated |
|
1 |
P26489-B21 |
HPE DL300 Gen10+ 1U CMA for Rail Kit |
|
1 |
P26489-B21 |
Factory Integrated |
|
1 |
P35876-B21 |
HPE CE Mark Removal FIO Enable Kit |
|
2 |
P48905-B21 |
HPE DL360 Gen11 High Perf Heat Sink Kit |
|
2 |
P48905-B21 |
Factory Integrated |
|
1 |
P52341-B21 |
HPE DL3XX Gen11 Easy Install Rail 3 Kit |
|
1 |
P52341-B21 |
Factory integrated |
The following table lists the only supported server specification that can be purchased from HPE to support HPE Aruba Networking Central On-Premises on Bare Metal mode for Gen 10:
| Quantity |
Product Part Number |
Description |
|---|---|---|
|
1 |
869121-B21 |
HPE OEM ProLiant DL360 Gen10 8SFF Configure-to-order Server |
|
1 |
869121-B22 |
HPE OEM DL360 Gen10 8-SFF CTO Server |
|
1 |
869121-B23 |
OEM LL DL360 Gen10 6138 Xeon-G FIO Kit |
|
1 |
869121-B24 |
OEM LL DL360 Gen10 6138 Xeon-G Kit |
|
1 |
869121-B25 |
Factory Integrated |
|
16 |
869121-B26 |
HPE 32GB (1x32GB) Dual Rank x4 DDR4-2666 CAS-19-19-19 Registered Smart Memory Kit |
|
16 |
869121-B27 |
Factory Integrated |
|
1 |
869121-B28 |
HPE DL360 Gen10 8SFF Display Port/USB/Optical Drive Blank Kit |
|
1 |
869121-B29 |
Factory Integrated |
|
4 |
869121-B30 |
HPE 960GB SATA 6G Mixed Use SFF SC Multi Vendor SSD |
|
4 |
869121-B31 |
Factory Integrated |
|
1 |
726536-B21 |
HPE 9.5mm SATA DVD-ROM Optical Drive |
|
1 |
726536-B21 0D1 |
Factory Integrated |
|
1 |
727055-B21 |
HPE Ethernet Ethernet is a network protocol for data transmission over LAN. 10Gb 2-port SFP+ X710-DA2 Adapter |
|
1 |
727055-B21 0D1 |
Factory Integrated |
|
1 |
P01366-B21 |
HPE 96W Smart Storage Lithium-ion Battery with 145mm Cable Kit |
|
1 |
P01366-B21 0D1 |
Factory Integrated |
|
1 |
804331-B21 |
HPE Smart Array P408i-a SR Gen10 (8 Internal Lanes/2GB Cache) 12G SAS Modular Controller |
|
1 |
804331-B21 0D1 |
Factory Integrated |
|
1 |
865408-B21 |
HPE 500W Flex Slot Platinum Hot Plug Low Halogen Power Supply Kit |
|
1 |
865408-B21 0D1 |
Factory Integrated |
|
1 |
512485-B21 |
HPE iLO Advanced 1-server License with 1yr Support on iLO Licensed Features |
|
1 |
512485-B21 0D1 |
Factory Integrated |
|
1 |
734811-B21 |
HPE 1U Cable Management Arm for Rail Kit |
|
1 |
734811-B21 0D1 |
Factory Integrated |
|
1 |
864279-B21 |
HPE Trusted Platform Module 2.0 Gen10 Option |
|
1 |
864279-B21 0D1 |
Factory Integrated |
|
|
872211-B21 |
HPE OEM 1U Non-Brand Gen10 Bezel FIO Kit |
|
1 |
873770-B21 |
HPE DL3XX Gen10 Rear Serial Cable and Enablement Kit |
|
1 |
873770-B21 0D1 |
Factory Integrated |
|
1 |
874543-B21 |
HPE 1U Gen10 SFF Easy Install Rail Kit |
|
1 |
874543-B21 0D1 |
Factory Integrated |
|
Total = 68 |
||
If a customer is using COP on Bare Metal mode, a pop-up is displayed when you login to the HPE Aruba Networking Central On-Premises setup, from where you can download the root certificate authority (CA) to connect to your network devices. When you click the link, a root_certificate.pem file is downloaded on your local system. This certificate should be uploaded to your respective devices for authentication.
If you click Cancel the pop-up is not displayed again in the same session, but if the customer logins again to HPE Aruba Networking Central On-Premises the pop-up will be displayed.
IMPORTANT CONSIDERATIONS
Ensure the below details are ready before setting up HPE Aruba Networking Central On-Premises. Ensure that the following are correct and reachable.
Any mistype or incorrect details in the Network Settings cannot be modified after the cluster setup. The only option is to perform Factory Reset and re-run HPE Aruba Networking Central On-Premises.
- FQDN Fully Qualified Location Name. FQLN is a device location identifier in the format: APname.Floor.Building.Campus. , IP Address, Subnet Mask, Gateway, DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. IP for each node in cluster
- VIP Virtual IP (VIP) is an IP address that as the name suggests, does not communicate with any physical network interface. (Virtual IP for cluster), Subnet Mask, Gateway, and multiple FQDNs (FQDNs for VIP) for cluster.
- The HPE Aruba Networking Central On-Premises appliance opens multiple ports for communication, so it is recommended that you host the HPE Aruba Networking Central On-Premises appliance behind a firewall.
- In HPE Aruba Networking Central On-Premises deployment, the port 8888 is a dedicated inbound port which is used for HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. based firmware image download on CX and PVOS devices.
Multiple FQDNs
As a part of the HPE GreenLake updates, HPE Aruba Networking Central On-Premises now requires multiple FQDNs to be configured for HPE Aruba Networking Central On-Premises cluster.
-
The multiple FQDNs created must resolve to the same Cluster Virtual IP Address (VIP).
-
These multiple FQDNs should be resolvable by both primary and secondary DNS servers configured on HPE Aruba Networking Central On-Premises.
The new FQDNs should be in the format mentioned below:
- cluster_fqdn
- central-<cluster_fqdn>
- apigw-<cluster_fqdn>
- ccs-user-api-<cluster_fqdn>
- sso-<cluster_fqdn>
The following table provides details of the multiple FQDNs and their consumer names that are configured for HPE Aruba Networking Central On-Premises cluster.
| FQDN | Consumer |
|---|---|
|
cop-deployment.companyx.com |
Central-UI User Interface. home page access from the browser |
|
central-cop-deployment.companyx.com |
Central-UI NMS Network Management System. NMS is a set of hardware and/or software tools that allow an IT professional to supervise the individual components of a network within a larger network management framework. page access from the browser |
|
apigw-cop-deployment.companyx.com |
Central NBAPI access from the customer application |
|
ccs-user-api-cop-deployment.companyx.com |
Central-UI API Application Programming Interface. Refers to a set of functions, procedures, protocols, and tools that enable users to build application software. access |
|
sso-cop-deployment.companyx.com |
Central-UI authentication page access |
Additionally, the DNS servers must also resolve the public and private DNS namespaces required by the organization.
Server Hardware Details
HPE Aruba Networking Central On-Premises can be installed on an Aruba Central ready AirWave appliance and Aruba Central appliance. The server is an HPE ProLiant DL360 Gen10 server with 40 physical cores, 512 GB RAM Random Access Memory. , 4 TB disk space, and 10 Gbps Gigabits per second. minimum network interface speed.
Supported Ports
Configure the appropriate ports. The following table lists the supported ports:
| Protocol and port | Domain Names and Purpose |
|---|---|
|
Inbound Ports Traffic |
|
|
To access and manage HPE Aruba Networking Central On-Premises. |
|
|
For HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection. and web-socket between HPE Aruba Networking Central On-Premises and devices. |
|
|
To receive AMON Advanced Monitoring. AMON is used in Aruba WLAN deployments for improved network management, monitoring, and diagnostic capabilities. messages and view data for controllers in the HPE Aruba Networking Central On-Premises monitoring dashboard. |
|
|
TCP 22
|
For management access through SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. and cluster setup. |
|
For CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. between HPE Aruba Networking Central On-Premises and devices. |
|
|
To access and manage HPE Aruba Networking Central On-Premises. |
|
|
TCP 80 |
For browser redirect from HTTP to HTTPS. |
|
TCP 2379, 2380, 4433, 6433, and 10250 |
For communication between HPE Aruba Networking Central On-Premises nodes in a cluster. |
|
TCP 4343 |
To access the setup-wizard installation. The HPE Aruba Networking Central On-Premises setup-wizard is shut down and the port 4343 is closed after 2 hours when the COP setup is completed successfully. The time span of 2 hours is provided to the user to inspect the status of the HPE Aruba Networking Central On-Premises cluster setup. |
|
TCP 22020 |
To allow remote console (RCS) access of device from HPE Aruba Networking Central On-Premises. |
|
TCP 30633 |
To allow the devices to set up a connection with the OpenFlow OpenFlow is an open communications interface between control plane and the forwarding layers of a network. controller. |
|
TCP 8888 |
For HTTP-based firmware image download for CX and PVOS switches. |
|
To receive AMON on secure port. |
|
|
Outbound Ports Traffic |
|
|
TCP 25, 465, or 587 |
Dependent on the SMTP configuration for alerts, reports, and HPE Aruba Networking Central On-Premises account registration. |
|
UDP 123 |
To access ntp.ubuntu.com. This is default destination. Users can reconfigure this port. |
|
UDP 161, 162 |
|
|
UDP 514 |
For Syslog. |
|
TCP 4343 |
For device bootstrap to controllers. |
|
TCP 22 |
To access nexus2.airwave.com to support connection. |
|
TCP 443 |
To access and allow HPE Aruba Networking Central On-Premises to check firmware versions for automatic upgrades.
|
|
To access images from the quay.io registry. HPE Aruba Networking Central On-Premises downloads packages from private allow listed repositories and uses signed packages for images. Quay.io traffic can originate from multiple IP ranges, refer to the article to allow traffic from Quay nodes. |
|
|
To access maps.googleapis.com to translate address. |
|
|
To access api.mapbox.com to view maps from user's browser. |
|
|
To access d1c50u1zbkqmph.cloudfront.net for CDN A Content Delivery Network (CDN) is a group of servers that are distributed geographically and speed up web content delivery by bringing it closer to the user's location. from user's browser. |
|
|
To access https://enterpriselicense.hpe.com for licensing. |
|
|
To access help.arubanetworks.com for documentation from user's browser. |
|
The outbound traffic can be initiated from any node of HPE Aruba Networking Central On-Premises cluster. Hence, the outbound traffic from all nodes of HPE Aruba Networking Central On-Premises cluster should be allow-listed in the firewall.
The default protocol for sending Syslog messages is UDP with a default port of 514. However, the user can choose any port for communication.