Quick Start—Onboarding Standalone AOS-CX Switches

This topic describes how to onboard standalone or non-stacked switches to HPE Aruba Networking Central for centralized management and monitoring. HPE Aruba Networking Central provides a unified platform to configure, manage, and monitor switches effectively.

For the list of supported AOS-CX switches, see Supported AOS-CX Switch Platforms.

Important:

Automatic configuration migration from Classic Central group to HPE Aruba Networking Central group is currently not supported.

For a seamless onboarding process, see the following sections:

Note:

The CLI examples in this topic use AOS-CX switches. For AOS-S switches, refer to the switch CLI guide as there may be some minor differences.

Prerequisites

Before onboarding switches to Classic Central, ensure the following prerequisites are met:

  • HPE GreenLake Account and Classic Central Access—Ensure that you have an active HPE GreenLake workspace with the Classic Central service. Log in at https://common.cloud.hpe.com to access the workspace.

  • Licensing—Ensure you have an active Classic Central account with access to the appropriate subscriptions for switch management. Switches must be licensed with either Foundation or Advanced subscriptions in the proper tier as detailed in the Licensing Guide.

  • Network Connectivity—Ensure the switch has network connectivity to reach Classic Central. You can enable DNS and internet access either manually or through DHCP. Inline management or Out of Band Management are also supported.

  • Firmware Version—Update the switch to a firmware version that supports Classic Central onboarding. For more information, see Supported AOS-CX Switch Platforms.

Device Inventory

The Device Inventory tool in HPE Aruba Networking Central provides a centralized view of all managed devices. You can access it by selecting the Device Inventory card on the HPE Aruba Networking Central home page.

Figure 1: Device Inventory Card

The card displays a summary of devices, and clicking it opens a detailed inventory table as shown in the following image.

Figure 2: Device Inventory View

You can filter devices depending on your criteria. You can either use keywords (device name, model, or any other device information) in the search bar to find your devices, or filter devices as per type (for example, Switches), site assignment (Assigned and Unassigned), or any combination of the options. You can also select multiple devices using checkboxes and apply actions through the ellipsis option.

To configure a device in Central, the following must be assigned:

  • Subscription—Assigned in HPE GreenLake or configured for automatic assignment.

  • Site—Assigned in Classic Central.

  • Device Function—Assigned in the Device Inventory page. For a single device, click the ellipsis on the right of the device row and select Assign. For multiple devices, select the checkboxes for the desired devices, then use the ellipsis menu.

Note:

Third-party switches monitored through the OpsRamp extension appear in the inventory list but cannot be assigned a Device Function.

VSX Cluster and VSF Stacks

Two switch VSX clusters and 2-10 switch VSF stacks have unique requirements for onboarding. Refer to the corresponding links below:

  • VSX Clustering (AOS-CX 5420, AOS-CX 6300, AOS-CX 8000 Series, AOS-CX 9000 Series, AOS-CX 10000 Series switches)

  • VSF Stacking (AOS-CX 6200, AOS-CX 6300, AOS-CX 4100, and AOS-CX 6100 switches)

Note:

Before onboarding, you must review Quick Start—Onboarding AOS-CX Switch Stacks. For each switch model series, refer to the individual stacking guide.

Onboarding Workflow

To onboard switches to Classic Central, complete the following steps:

Step 1—Establishing Network Connectivity

Step 2—Adding the Switch to HPE GreenLake and Classic Central

Step 3—Configuring the Switch for Management

Step 4—Verifying Onboarding in HPE Aruba Networking Central

Note:

Onboarding is performed in Classic Central and is a one-time activity. All subsequent management and operations are handled in HPE Aruba Networking Central.

Step 1—Establishing Network Connectivity

To establish network connectivity, complete the following steps:

  1. Connect the Switch—Ensure the switch is physically connected to your network.

  2. Configure IP Address—Assign a static IP address and DNS or enable DHCP on the switch to ensure it has internet connectivity.

    Note:

    Starting 10.17, onward, DHCP configurations in vlan interface mode are supported on multiple interfaces. On HPE Aruba Networking Central DHCP, only 1 vlan interface is supported per device.

  3. Enable DNS Resolution if not done via DHCP—Verify that the switch can resolve device.arubanetworks.com or similar required domains.

  4. NTP Service—(Optional) It is strongly recommended to use NTP.

  5. Test Internet Access—Ping a public IP address (for example, 8.8.8.8) to confirm internet connectivity. Verify DNS resolution by pinging a known address such as www.hpe.com.

Step 2—Adding the Switch to HPE GreenLake and Classic Central

To onboard a switch, complete the following steps:

  1. Log in to HPE GreenLake:

    1. Open a web browser and navigate to the HPE GreenLake portal at https://common.cloud.hpe.com.

    2. Enter your credentials.

      Note:

      If you do not have an HPE GreenLake account, see Getting started with GreenLake platform for detailed information.

  2. Add the switch:

    1. In HPE GreenLake, navigate to DevicesDevice Inventory.

      The Inventory page is displayed containing all the devices in your inventory.

    2. Click Add Devices to open the wizard.

    3. Select one of the following options from Device Type:

      • Networking Devices

      • Storage Devices

      • Compute Devices

    4. Under Add Devices via, select one of the following radio buttons:

      • Serial Number & MAC Address—Enter the serial number and MAC address for the switch.

        Note:

        The serial number and MAC address details are usually available on the device label.

      • CSV File—To add multiple switches, upload the device serial number and MAC address from a CSV file.

      Figure 3: Serial Number & MAC Address Page

    5. (Optional) Assign a tag to the newly added devices. Select the name of an existing tag or create a tag to assign to your devices. Use the tags to categorize devices managed by HPE GreenLake. For more information on tags, see theHPE GreenLake documentation.

    6. (Optional) Add Location Name and Service Delivery Contact when prompted. This information automates support and services for the device. For information on creating a location and service delivery contact, see the HPE HPE GreenLake documentation.

  3. Assign the switch to the Central Service and desired region:

    1. Select one or more switches using the check box to the left of the device entry.

    2. From the Actions menu, select Assign to Service.

      Use the search and filter options in the list view as needed to find specific devices for the remaining steps.

    3. Select the Central service and the required region.

      Figure 4: Assign to Service

  4. Assign licensing to the switch:

    1. Select one or more switches using the check box to the left of the device entry.

    2. From the Actions menu, select Apply Subscription.

  5. (Optional) Add or Edit location and Service Delivery Contact:

    1. Select one or more switches using the check box to the left of the device entry.

    2. From the Actions menu, select Location and Service Delivery Contact to add or edit the details.

  6. Assign Group and Site:

    1. Select or create a group to organize the switch.

      Note:

      You must create the group in Classic Central and enable the Allow New Central to overwrite all configuration for this group toggle. For more information, see Creating a Group for Switches.

    2. Assign the switch to the previously created site within Classic Central. For more information, see Sites.

Step 3—Configuring the Switch for Management

Note:

If your environment uses DHCP for the management network, unless the switch is an AOS-CX 8000 or higher model, skip the following three steps.

To configure the switch for management, complete the following steps:

  1. Enable Classic Central Management:

    Note:

    If the factory default setting is not changed, skip the following steps.

    1. Access the switch through the CLI or the WebUI.

    2. Enable Classic Central management functionality using the following CLI command:

      switch(config)# hpe-anw-central

  2. Enable switch port used for Central Management:

    Note:

    This step is required for in-band management with AOS-CX 8000 and higher model switches if factory default is not changed.

    1. Access the switch through the CLI or the WebUI.

    2. Enable Classic Central management functionality using the following CLI command:

      switch(config)# interface 1/1/1

      switch(config-if)# enable
  3. Configure management port or VLAN for connectivity:

    Note:

    This step is required if you are not using DHCP or using custom VLAN ID for in-band management.

    1. For Out of Band management (change IP addresses and subnet mask as required):

      switch(config)# interface mgmt

      switch(config-if-mgmt)# ip address 192.168.25.10 255.255.255.0

       

       

      switch(config-if-mgmt)# default-gateway 192.168.25.1

       

       

      switch(config-if-mgmt)# nameserver 192.168.10.10

    2. For In-Band management (change IP addresses, subnet mask, port, and VLAN as required):

      switch(config)# vlan 20

       

      switch(config-vlan-20)# name management

       

      switch(config-if-mgmt)# interface vlan 20

       

      switch(config-if-vlan)# ip address 192.168.25.10 255.255.255.0

       

      switch(config-if-vlan)# exit

       

      switch(config)# ip route 0.0.0.0/0 192.168.25.1

       

      switch(config)# nameserver 192.168.10.10

       

      switch(config)# interface 1/1/1

       

      switch(config-if)# no shutdown

       

      switch(config-if)# no routing

       

      switch(config-if)# vlan access 20

      Figure 5: In-Band Management

  4. Verify Connectivity

    Check the connection status between the switch and Classic Central using the following command and verify that the Central Connection Status is Connected.

    switch(config)# show hpe-anw-central

    Note:

    It may take a few minutes for the switch to establish a connection with Classic Central

    Figure 6: Switch Connectivity

Step 4—Verifying Onboarding in HPE Aruba Networking Central

  1. Check Switch Status:

    1. In the HPE Aruba Networking Central portal, click the Device Inventory Card to access the Device Inventory menu.

    2. Confirm that the switch appears in the list of devices. Use the search and filter functions, if needed.

    3. Select the switch or switches, and select one of the following from Device Function depending on how they are used in the network:

      • Access Switch

      • Core Switch

      • Aggregation Switch

  2. Validate Functionality

    Before configuring the switches, ensure to add each switch to a Site and to a HPE Aruba Networking Central Configuration enabled group in Classic Central. Once added, the switch(es) should show up as online in the assigned Site in HPE Aruba Networking Central.

    Note:

    This is a one-time effort. Once the site is created, it is replicated in HPE Aruba Networking Central that is used to perform all actions after onboarding.

Troubleshooting

If the switch fails to onboard, check the following:

  • Network Issues—Ensure the switch has internet access and can resolve DNS.

  • Firmware—Verify that the switch firmware is updated to a compatible version.

  • Credentials—Confirm that the serial number and MAC address are entered correctly.

  • Debug Logs—Access the switch CLI and review logs for errors:

    Note:

    Alternatively, use CLI Viewer to check current configuration against the configuration being pushed to the device.

    switch# show logging | inc central

    The following image displays typical log entries for a successful onboarded switch.

    Figure 7: Log Entries for an Onboarded Switch

Note:

To resolve any errors or issues, consult HPE Aruba Networking support or your network administrator for assistance.

Auto-Import of Basic Connectivity Configurations

When you onboard an AOS-CX switch and move to the HPE Aruba Networking Central group, any pre-configured basic connectivity configurations will be imported automatically from switch to HPE Aruba Networking Central. Once the import is successful, Successfully Imported Connectivity Config from the Device message is displayed in the Audit Trail page.

The auto-imported configurations will be saved to the device scope profiles.

Note:
  • VSX-related connectivity configurations will not be auto-imported to HPE Aruba Networking Central.

  • Feature configurations are imported only if the device configuration differs from that in the HPE Aruba Networking Centralhierarchy. Device-level settings override configurations set at higher scopes during auto-import. To move a configuration to a higher scope, you must first create the object at that level and then delete the device-level instance.

  • Device onboarding fails when DHCP is enabled on multiple VLANs, as this configuration is not supported. In such cases, disable DHCP on any unused VLANs and re‑onboard the device to HPE Aruba Networking Central.
  • Any imported configuration with aliases is created at the device scope. For example, in VLAN configurations, the Description field has as an alias option. If a switch is onboarded with an existing VLAN description and the same VLAN is also configured in HPE Aruba Networking Central, it is recommended to configure the VLAN description as an alias in HPE Aruba Networking Central. This ensures that only the alias for that VLAN is created or overridden at the device scope.

Sample Connectivity Configurations

The following are the sample configurations that are automatically imported to HPE Aruba Networking Central during onboarding:

Feature

Sample Configurations

Static route

ip dns server-address 10.0.0.1 vrf default ip dns server-address 10.0.0.2 vrf mgmt ip route 10.2.3.0/24 1/1/5 distance 20 tag 2

Interfaces

interface 1/1/5 description ethernet interface no shutdown mtu 1300 routing ip mtu 1400 ip address 10.2.0.10/24 ip address 192.168.8.100/24 secondary ipv6 address link-local ipv6 address link-local fe80::a:a:a:a/64 ipv6 address autoconfig

interface 1/1/1 no shutdown no routing vlan trunk native 1 vlan tr

Management Interface

interface mgmt no shutdown ip static 2.2.2.2/24 default-gateway 2.2.2.3 nameserver 2.2.2.3 2.2.2.4

VLAN

vlan 5 - 10 description my vlan name vlan_2

VLAN Interface

interface vlan 10 description vlan interface ip mtu 1300 ip address 10.0.0.10/24 ip address 192.168.10.100/24 secondary ipv6 address link-local ipv6 address link-local fe80::a:a:a:a/64 ipv6 address 2000::1/64 ipv6 address 5000::/64 eui64 ipv6 address 5001::1/64 tag 10 ipv6 address 5002::/64 eui64 tag 10 ipv6 address autoconfig interface vlan 252 ip dhcp

Port Channel Interface

interface lag 1 no shutdown no routing vlan trunk native 1 vlan trunk allowed all interface lag 2 shutdown no routing vlan access 10 interface 1/1/52 no shutdown mtu 9198 lag 1 interface 2/1/52 no shutdown mtu 9198 lag 1 interface lag 1 description UPLINK no shutdown no routing vlan trunk native 150 vlan trunk allowed 1,101,107,109,121,125,127, 131-133,135-136,150,157-158,168-169,173,177, 202,208-210,1150 lacp mode active dhcpv4-snooping trust

Local Management (SSH and Web servers)

ssh server vrf default ssh server vrf mgmt ssh server allow-list ip 10.0.0.0/0 ip 10.0.0.0/24 ip 10.0.0.0/30 ip 10.0.0.0/31 ip 10.0.0.1 https-server session-timeout 69 https-server vrf default https-server vrf mgmt

HTTP Proxy

http-proxy test.com:2020 vrf default http-proxy test2.com:2020 vrf mgmt

DNS

ip dns server-address 10.0.0.1 vrf default ip dns server-address 10.0.0.2 vrf default

Remote Management

hpe-anw-central location-override device-aqua-d2.arubadev.cloud.hpe.com vrf mgmt

IP Source Interface

ip source-interface dns interface vlan850 ip source-interface central interface vlan850 ip source-interface ntp interface vlan850 ip source-interface http interface vlan850 ip source-interface ssh interface vlan850

VRF

interface vlan 1 no ip dhcp interface vlan 154 interface vlan 350 description NMS vrf attach vrf1 ip mtu 9100 · Static route with VRF should be present · Static ip needs to be preserved. ip address 10.1.50.3/24 ipv6 address 2a05:a880:50:350::a003/64 ip route 0.0.0.0/0 10.1.50.254 vrf vrf1 ip dns server-address 139.3.62.2 vrf vrf1 ip dns server-address 139.3.63.2 vrf vrf1 ntp server 158.98.224.20 version 3 ntp server 158.98.224.21 version 3 ntp vrf vrf1

VSF

vsf member 1 type jl660a link 1 1/1/26 link 2 1/1/25

vsf member 2 type jl660a link 1 2/1/25 link 2 2/1/26

NTP

ntp enable ntp server 16.93.50.254 iburst minpoll 4 maxpoll 5 ntp source Vlan99 ntp access-group peer 80 ntp server 10.226.26.11 ntp server 10.115.218.53 prefer ntp server 10.63.71.149

Speed-System Interface Group

system interface-group 1 speed 10g

Spanning Tree

spanning-tree mode rpvst spanning-tree spanning-tree instance 1 vlan 234

Hostname

hostname switch-S34KN009