Creating a Firmware Policy

HPE Aruba Networking Central allows you to create a new firmware policy in the Firmware Management application.

To create a firmware policy, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the icon to open the Menu page.

  2. On the Firmware Management card, click Manage.

    The Firmware Management page is displayed.

  3. In the left navigation, select one of the following scope levels:

    • Global—Displays a list of firmware policies created at the Global level.

      Note:

      Firmware policies set at the Global level apply to all devices unless a more specific policy is set at a lower scope (such as Sites or Devices).

    • Site Collections—Displays a list of site collections created at the Site Collections level. You can select multiple entries to create duplicate firmware policies with identical parameters across multiple site collections.

    • Sites—Displays a list of sites created at the Sites level. You can select multiple entries to create duplicate firmware policies with identical parameters across multiple sites.

    • Devices—Displays a list of devices created at the Devices level. You can select multiple entries to create duplicate firmware policies with identical parameters across multiple devices.

    • Device Groups—Displays a list of device groups created at the Device Groups level. You can select multiple entries to create duplicate firmware policies with identical parameters across multiple device groups.

      Note:

      Firmware policy creation is not supported for bridges at the Device Group level.

  4. Complete one of the following steps based on your requirement:

    • On the Global page, click Create Firmware Policy.

    • On the Site Collections, Sites, Devices, or Device Group page, select the check box for the desired entry in the list view. Click Create Firmware Policy.

      Alternatively, you can complete the following steps:

      1. On the Site Collections, Sites or Device Group page, click on a particular site collection, site, or device group name in the list view.

        The Firmware Policies page for the selected site collection, site, or device group is displayed.

      2. Click Create Firmware Policy.

    • To create the same firmware policy for multiple site collections, sites, devices, or device groups, complete the following steps:

      1. Navigate to Site Collections, Sites, Devices, or Device Group page.

      2. Click multiple rows of the site collection, site, device, or device group in the list view.

      3. Click Create Firmware Policy.

    The Create Firmware Policy side panel is displayed.

  5. Configure the Details parameters as described in the following table.

    Table 1: Firmware Policy Details

    Parameter

    Description

    Name

    Enter a name for the firmware policy. When creating a policy for a single device from the Devices page, the Name parameter is auto-populated with the device name, and is editable. This is a mandatory parameter.

    The policy name is case-insensitive and must be between 1 and 63 alphanumeric characters in length.

    Description

    (Optional) Enter a description of the firmware policy. The description can include a maximum of 255 characters including letters, numbers, and special characters.

  6. Click Next.

    The Parameters step is displayed.

  7. Configure the firmware upgrade parameters as described in the following table.

    Table 2: Firmware Upgrade Parameters

    Parameter

    Description

    Scope

    Displays the scope where the firmware policy is applied, based on your selection (such as Global, one or more Sites, Site Collections, Devices, or Device Groups). This parameter is non-editable and auto-populated.

    Device Function

    Select one of the following device types from the drop-down list:

    • Campus Access point

    • Microbranch Access Point

    • Branch Gateway

    • Mobility Gateway

    • Bridge

    • Access Switch

    • Aggregation Switch

    • Core Switch

    • AOS-S Access Switch

    • AOS-S Core Switch

    • AOS-S Aggregation Switch

    Firmware Version

    Select the firmware version available for the selected device function from the drop-down list.

    Custom Build Allows users to enter a custom firmware version.
    Note:
    • This parameter is displayed only when you select the Custom option from the Firmware Version drop-down list.

    • If a valid firmware version is entered, the system performs backend validation to verify that the corresponding firmware image exists in HPE Aruba Networking Central.

    • If an invalid firmware version is entered, the system displays an error message Invalid firmware build version entered, prompting the user to recheck and confirm the firmware version.

    Partition

    Select one of the following partition types from the drop-down list:

    • Primary

    • Secondary

    Note:

    This parameter is displayed only when you select Branch Gateway, Mobility Gateway, Access Switch, Aggregation Switch, Core Switch, AOS-S Access Switch, AOS-S Aggregation Switch, or AOS-S Core Switch from the Device Function drop-down list.

    Upgrade Type

    Select one of the following options from the drop-down list to specify how the firmware is applied to the selected devices:

    • Standard—Performs a standard upgrade on the selected devices. All services on the devices are temporarily disrupted during the upgrade. This upgrade is recommended for operations during maintenance windows.

    • Live—Performs a live upgrade without disrupting device connectivity. This upgrade is supported only for APs and Gateways, and for models that are part of a cluster. It is recommended for operations during working hours.

    Note:

    Live Upgrade is available only when you select Campus Access Point, Microbranch Access Point, Branch Gateway, or Mobility Gateway from the Device Function drop-down list.

    Advanced Options

    Model Firmware Exception

    Allows administrators to define firmware upgrade exceptions for specific device models within a firmware policy.

    Upgrade Cellular Modem

    Enable the toggle to upgrade the LTE cellular modem firmware for supported device functions.

    Note:

    This parameter is available only when you select Microbranch Access Point from the Device Function drop-down list.

    Upgrade Non-Failsafe Modules

    Enable the toggle to allow upgrades to non-failsafe components on the AOS-CX switch during firmware upgrade.

    Note:
    • Non-failsafe upgrades are not supported on AOS-CX devices running firmware version 10.14.

    • This parameter is available only when you select Access Switch, Aggregation Switch, or Core Switch from the Device Function drop-down list.

    Download Image from Server

    Enable the toggle to allow the device to download the firmware image from a local server instead of the default source.

    Base URL and Path

    Enter the full URL path of the firmware image hosted on the local server.

    Note:

    This parameter is available only when the Download Image from Server toggle is enabled.

  8. Click Next.

    The Schedule step is displayed.

  9. To determine when and how firmware upgrades are applied to the selected devices, configure the following parameters:

    1. Under Upgrades, select one of the following radio buttons:

      • Immediate—Applies the firmware upgrade to the selected devices as soon as the firmware policy is created. Any new devices added later to the selected scope are also upgraded immediately without requiring separate scheduling.

      • From Scheduled Date—Schedules the firmware upgrade to occur at a specific date and time.

        Configure the following sub-parameters:

        • Date—Select the date on which the upgrade will begin.

        • Time—Select the specific time for the scheduled upgrade to begin.

        • Time Zone—Select the appropriate time zone from the drop-down list to ensure that the devices are upgraded at the correct time.

          Note:
          • If a new device is added before the scheduled upgrade date, the device waits until the scheduled time to receive the upgrade.

          • If a new device is added after the scheduled date has passed, the device is upgraded immediately.

          • When scheduling is based on device local time, the upgrade time is determined by the site’s time zone. For example, devices in a Bangalore site follow IST (Chennai UTC +05:30 in the Time Zone drop-down list), while devices in a Santa Clara site follow PST (Pacific-Time UTC -07:00 in the Time Zone drop-down list).

        • Advanced Options—Configure the following parameters:

          • Pre-download Firmware Image—Enable this option to download the firmware image to the devices ahead of the scheduled upgrade time. By pre-staging the firmware, the actual upgrade window is reduced to only the reboot time. At the scheduled date and time, devices will automatically reboot and apply the pre-downloaded firmware upgrade.

          • Upgrade New Devices Immediately—Select this check box to immediately upgrade newly added devices in the selected scope, overriding the scheduled upgrade time defined in the policy. This ensures consistent firmware compliance without waiting for the scheduled firmware policy upgrade.

            Note:

            The Upgrade New Devices Immediately check box is not available for Devices scope.

    2. Click Next.

      The Review step is displayed containing a summary of the firmware policy configuration based on your selections in the previous steps.

  10. Verify the configuration details and click Create.

The firmware policy is created for the device function under the selected scope.

You can view the firmware upgrade status for all devices from the Overview or Devices page. For more information, see Managing Firmware Settings and Monitoring Upgrades .

When the firmware policy is created, the operation is logged on the Audit Trail page. For more information, see Viewing the Audit Trail Page.

Note:

In case of VSX, firmware upgrades are performed on each switch individually.

Important Points about Firmware Management

  • The During Maintenance Windows radio button is currently not supported. Future updates will provide support for this option.

  • You can configure only one firmware policy per-device function at a given scope. A new firmware policy at the same scope for the same device function replaces the previous one.

  • Selecting multiple entries (for example, Sites, Devices) creates duplicate firmware policies with identical parameters for each selected entry.

  • A firmware policy configured at a lower scope overrides any policy inherited from a higher scope for the same device function. The most specific scope always takes precedence.

  • The behavior for accessing firmware policies differs by scope as described below:

    • The Global page displays the firmware policy details in list view by default.

    • From the Site Collections, Sites, or Device Groups pages, clicking a scope name in list view opens the Firmware Policies page for that scope.

    • From the Devices or Overview pages, clicking a device name opens the Device details side panel instead of the Firmware Policies page.

    • To view a firmware policy created for a device, click Firmware Policies in the left navigation to access the parent Firmware Policies page. You can click the device name for the device-related firmware policy to access the Firmware Policy side panel.

The following animation displays how to create a firmware policy for Site Collections, Sites, Devices, and Device Groups scopes.