HPE Aruba Networking Central On-Premises Deployment

HPE Aruba Networking Central On-Premises deployment can be done in two different ways:

  • Appliance—In this mode, customers deploy HPE Aruba Networking Central On-Premises on Aruba Central Appliance (R1Q05B) or Aruba Central Ready AirWave 8 Appliance (R1Q04B). For Gen 11 appliance mode deployment, it supports s4P01A appliance.

  • HPE Aruba Networking Central On-Premises on Bare Metal (non-appliance)—In this mode, customers deploy HPE Aruba Networking Central On-Premises on HPE servers as mentioned in the following tables:

    Attention

    While using HPE Aruba Networking Central On-Premises on bare metal mode, you should only use HPE OEM ProLiant DL360 Gen10 and Gen11 8SFF CTO Server platform along with the configurations mentioned in the tables below.

While using HPE DL360 servers, you can use a mix of Gen 10 and Gen 11 servers.

Important Notes

If you install HPE Aruba Networking Central On-Premises in non-appliance mode using HPE DL360 server, then you must set the following configuration on the server before proceeding with the installation:

The following accessories are required to support HPE Aruba Networking Central On-Premises on both Bare Metal and Appliance mode for Gen 11:

Along with the DAC cables mentioned above, J9150D (Aruba 10G SFP+ LC SR 300m OM3 MMF Transceiver) is the supported SFP Transceiver.

The following table lists the only supported server specification that can be purchased from HPE to support HPE Aruba Networking Central On-Premises on Bare Metal mode for Gen 11:

Table 1: HPE OEM ProLiant DL360 Gen11 8SFF CTO Server Specifications

Quantity

 

Product Part Number

Description

1

P52499-B21

HPE DL360 Gen11 8SFF CTO Server

1

P52499-B21

HPE DL360 Gen11 8SFF CTO Server

2

P49599-B21

INT Xeon-G 6442Y CPU Central Processing Unit.  A CPU is an electronic circuitry in a computer for processing instructions. for HPE

2

P49599-B21

Factory Integrated

16

P43328-B21

HPE 32GB 2Rx8 PC5-4800B-R Smart Kit

16

P43328-B21

Factory Integrated

1

P48895-B21

HPE DL360 G11 8SFF x1 U.3 TM BP Kit

1

P48895-B21

Factory integrated

5

P49049-B21

HPE 1.6TB SAS MU SFF BC MV SSD

5

P49049-B21

Factory Integrated

1

P48926-B21

HPE DL3X0 G11 1U DP/USB Universal Serial Bus. USB is a connection standard that offers a common interface for communication between the  external devices and a computer. USB is the most common port used in the client devices. /ODD Blank Kit

1

P48926-B21

Factory Integrated

1

726536-B21

HPE 9.5mm SATA DVD-ROM Optical Drive

1

726536-B21

Factory Integrated

1

P51178-B21

BCM 5719 1Gb 4p BASE-T Adptr

1

P51178-B21

Factory Integrated

1

P01366-B21

HPE 96W Smart Stg Li-ion Batt 145mm Kit

1

P01366-B21

Factory Integrated

1

P48918-B21

HPE DL360 Gen11 Stg Cntrl Enable Cbl Kit

1

P48918-B21

Factory Integrated

1

P47781-B21

HPE MR416i-o Gen11 SPDM Storage Cntlr

1

P47781-B21

Factory Integrated

1

P10106-B21

INT E810 10/25GbE 2p SFP28 OCP3 Adptr

1

P10106-B21

Factory Integrated

1

P48908-B21

HPE DL3X0 Gen11 1U High Perf Fan Kit

1

P48908-B21

Factory Integrated

1

P38997-B21

HPE 1600W FS Plat Ht Plg LH Pwr Sply Kit

1

P38997-B21

Factory Integrated

1

BD505A

HPE iLO Integrated Lights-Out (iLO) by Hewlett-Packard Enterprise is a proprietary embedded server management technology providing out-of-band management facilities. Adv 1-svr Lic 3yr Support

1

BD505A

Factory Integrated

1

P48830-B21

HPE DL3XX Gen11 CPU2/OCP2 x8 Enable Kit

1

P48830-B21

Factory Integrated

1

P52416-B21

HPE DL360 Gen11 OROC TM Cbl Kit

1

P52416-B21

Factory Integrated

6

845970-B21

HPE QSFP28 to SFP28 Adapter

6

845970-B21

Factory Integrated

1

P26489-B21

HPE DL300 Gen10+ 1U CMA for Rail Kit

1

P26489-B21

Factory Integrated

1

P35876-B21

HPE CE Mark Removal FIO Enable Kit

2

P48905-B21

HPE DL360 Gen11 High Perf Heat Sink Kit

2

P48905-B21

Factory Integrated

1

P52341-B21

HPE DL3XX Gen11 Easy Install Rail 3 Kit

1

P52341-B21

Factory integrated

The following table lists the only supported server specification that can be purchased from HPE to support HPE Aruba Networking Central On-Premises on Bare Metal mode for Gen 10:

Table 2: HPE OEM ProLiant DL360 Gen10 8SFF CTO Server Specifications

Quantity

 

Product Part Number

Description

1

869121-B21

HPE OEM ProLiant DL360 Gen10 8SFF Configure-to-order Server

1

869121-B22

HPE OEM DL360 Gen10 8-SFF CTO Server

1

869121-B23

OEM LL DL360 Gen10 6138 Xeon-G FIO Kit

1

869121-B24

OEM LL DL360 Gen10 6138 Xeon-G Kit

1

869121-B25

Factory Integrated

16

869121-B26

HPE 32GB (1x32GB) Dual Rank x4 DDR4-2666 CAS-19-19-19 Registered Smart Memory Kit

16

869121-B27

Factory Integrated

1

869121-B28

HPE DL360 Gen10 8SFF Display Port/USB/Optical Drive Blank Kit

1

869121-B29

Factory Integrated

4

869121-B30

HPE 960GB SATA 6G Mixed Use SFF SC Multi Vendor SSD

4

869121-B31

Factory Integrated

1

726536-B21

HPE 9.5mm SATA DVD-ROM Optical Drive

1

726536-B21 0D1

Factory Integrated

1

727055-B21

HPE Ethernet Ethernet is a network protocol for data transmission over LAN. 10Gb 2-port SFP+ X710-DA2 Adapter

1

727055-B21 0D1

Factory Integrated

1

P01366-B21

HPE 96W Smart Storage Lithium-ion Battery with 145mm Cable Kit

1

P01366-B21 0D1

Factory Integrated

1

804331-B21

HPE Smart Array P408i-a SR Gen10 (8 Internal Lanes/2GB Cache) 12G SAS Modular Controller

1

804331-B21 0D1

Factory Integrated

1

865408-B21

HPE 500W Flex Slot Platinum Hot Plug Low Halogen Power Supply Kit

1

865408-B21 0D1

Factory Integrated

1

512485-B21

HPE iLO Advanced 1-server License with 1yr Support on iLO Licensed Features

1

512485-B21 0D1

Factory Integrated

1

734811-B21

HPE 1U Cable Management Arm for Rail Kit

1

734811-B21 0D1

Factory Integrated

1

864279-B21

HPE Trusted Platform Module 2.0 Gen10 Option

1

864279-B21 0D1

Factory Integrated

 

872211-B21

HPE OEM 1U Non-Brand Gen10 Bezel FIO Kit

1

873770-B21

HPE DL3XX Gen10 Rear Serial Cable and Enablement Kit

1

873770-B21 0D1

Factory Integrated

1

874543-B21

HPE 1U Gen10 SFF Easy Install Rail Kit

1

874543-B21 0D1

Factory Integrated

Total = 68

If a customer is using COP on Bare Metal mode, a pop-up is displayed when you login to the HPE Aruba Networking Central On-Premises setup, from where you can download the root certificate authority (CA) to connect to your network devices. When you click the link, a root_certificate.pem file is downloaded on your local system. This certificate should be uploaded to your respective devices for authentication.

If you click Cancel the pop-up is not displayed again in the same session, but if the customer logins again to HPE Aruba Networking Central On-Premises the pop-up will be displayed.

IMPORTANT CONSIDERATIONS

Ensure the below details are ready before setting up HPE Aruba Networking Central On-Premises. Ensure that the following are correct and reachable.

Any mistype or incorrect details in the Network Settings cannot be modified after the cluster setup. The only option is to perform Factory Reset and re-run HPE Aruba Networking Central On-Premises.

Multiple FQDNs

As a part of the HPE GreenLake updates, HPE Aruba Networking Central On-Premises now requires multiple FQDNs to be configured for HPE Aruba Networking Central On-Premises cluster.

  • The multiple FQDNs created must resolve to the same Cluster Virtual IP Address (VIP).

  • These multiple FQDNs should be resolvable by both primary and secondary DNS servers configured on HPE Aruba Networking Central On-Premises.

The new FQDNs should be in the format mentioned below:

  • cluster_fqdn
  • central-<cluster_fqdn>
  • apigw-<cluster_fqdn>
  • ccs-user-api-<cluster_fqdn>
  • sso-<cluster_fqdn>

The following table provides details of the multiple FQDNs and their consumer names that are configured for HPE Aruba Networking Central On-Premises cluster.

Table 3: Multiple FQDNs Example

FQDN Consumer

cop-deployment.companyx.com

Central-UI User Interface. home page access from the browser

central-cop-deployment.companyx.com

Central-UI NMS Network Management System. NMS is a set of hardware and/or software tools that allow an IT professional to supervise the individual components of a network within a larger network management framework. page access from the browser

apigw-cop-deployment.companyx.com

Central NBAPI access from the customer application

ccs-user-api-cop-deployment.companyx.com

Central-UI API Application Programming Interface. Refers to a set of functions, procedures, protocols, and tools that enable users to build application software. access

sso-cop-deployment.companyx.com

Central-UI authentication page access

Additionally, the DNS servers must also resolve the public and private DNS namespaces required by the organization.

Server Hardware Details

HPE Aruba Networking Central On-Premises can be installed on an Aruba Central ready AirWave appliance and Aruba Central appliance. The server is an HPE ProLiant DL360 Gen10 server with 40 physical cores, 512 GB RAM Random Access Memory. , 4 TB disk space, and 10 Gbps Gigabits per second. minimum network interface speed.

Supported Ports

Configure the appropriate ports. The following table lists the supported ports:

Table 4: Domain Names and Ports for HPE Aruba Networking Central

Protocol and port Domain Names and Purpose

Inbound Ports Traffic

TCP Transmission Control Protocol. TCP is a communication protocol that defines the standards for establishing and maintaining network connection for applications to exchange data. 443

To access and manage HPE Aruba Networking Central On-Premises.

For HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer  or transport layer security protocol connection. and web-socket between HPE Aruba Networking Central On-Premises and devices.

UDP User Datagram Protocol. UDP is a part of the TCP/IP family of protocols used for data transfer. UDP is typically used for streaming media. UDP is a stateless protocol, which means it does not acknowledge that the packets being sent have been received. 8211

To receive AMON Advanced Monitoring. AMON is used in Aruba WLAN deployments for improved network management, monitoring, and diagnostic capabilities. messages and view data for controllers in the HPE Aruba Networking Central On-Premises monitoring dashboard.

TCP 22

 

For management access through SSH Secure Shell. SSH is a network protocol that provides secure access to a remote device. and cluster setup.

For CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. between HPE Aruba Networking Central On-Premises and devices.

To access and manage HPE Aruba Networking Central On-Premises.

TCP 80

For browser redirect from HTTP to HTTPS.

TCP 2379, 2380, 4433, 6433, and 10250

For communication between HPE Aruba Networking Central On-Premises nodes in a cluster.

TCP 4343

To access the setup-wizard installation.

NOTE: The HPE Aruba Networking Central On-Premises setup-wizard is shut down and the port 4343 is closed after 2 hours when the COP setup is completed successfully. The time span of 2 hours is provided to the user to inspect the status of the HPE Aruba Networking Central On-Premises cluster setup.

TCP 22020

To allow remote console (RCS) access of device from HPE Aruba Networking Central On-Premises.

TCP 30633

To allow the devices to set up a connection with the OpenFlow OpenFlow is an open communications interface between control plane and the forwarding layers of a network. controller.

TCP 8888

For HTTP-based firmware image download for CX and PVOS switches.

DTLS Datagram Transport Layer Security is a communications protocol providing security to datagram-based applications by allowing them to communicate in a way designed to prevent tampering, message forgery or eavesdropping. 9009

To receive AMON on secure port.

Outbound Ports Traffic

TCP 25, 465, or 587

Dependent on the SMTP configuration for alerts, reports, and HPE Aruba Networking Central On-Premises account registration.

UDP 123

To access ntp.ubuntu.com.

NOTE: This is default destination. Users can reconfigure this port.

UDP 161, 162

For SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention.  and traps.

UDP 514

For Syslog.

TCP 4343

For device bootstrap to controllers.

TCP 22

To access nexus2.airwave.com to support connection.

TCP 443

To access and allow HPE Aruba Networking Central On-Premises to check firmware versions for automatic upgrades.

  • coreupdate.central.arubanetworks.com

  • coreupdate-prod.central.arubanetworks.com

  • geoip.maxmind.com

 

To access images from the quay.io registry.

NOTE: HPE Aruba Networking Central On-Premises downloads packages from private allow listed repositories and uses signed packages for images.

NOTE: Quay.io traffic can originate from multiple IP ranges, refer to the article to allow traffic from Quay nodes.

To access maps.googleapis.com to translate address.

To access api.mapbox.com to view maps from user's browser.

To access d1c50u1zbkqmph.cloudfront.net for CDN A Content Delivery Network (CDN) is a group of servers that are distributed geographically and speed up web content delivery by bringing it closer to the user's location. from user's browser.

To access https://enterpriselicense.hpe.com for licensing.

To access help.arubanetworks.com for documentation from user's browser.

The outbound traffic can be initiated from any node of HPE Aruba Networking Central On-Premises cluster. Hence, the outbound traffic from all nodes of HPE Aruba Networking Central On-Premises cluster should be allow-listed in the firewall.

The default protocol for sending Syslog messages is UDP with a default port of 514. However, the user can choose any port for communication.