Configure EdgeConnect SD-WAN Orchestrator

EdgeConnect gateways are onboarded in HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. You must enable Orchestrator communication with HPE Aruba Networking Central. Then you configure the gateways as hubs, so HPE Aruba Networking Central identifies them and they can be configured as VPNCs.

The following sections describe how to onboard the EdgeConnect gateways in Orchestrator.

This guide does not cover the full extent of zero touch provisioning. For more information on ZTP, see the USB-Based Zero Touch Provisioning section in the Orchestrator User Guide.

Enable Orchestrator to Communicate with HPE Aruba Networking Central

The following instructions describe how to enable Orchestrator to open HTTPS connections to HPE Aruba Networking Central.

  1. Log in to Orchestrator.

  2. Navigate to Orchestrator > HPE Integration Services > HPE Aruba Networking Central.

    The Enable HPE Aruba Networking Central dialog box opens.

  3. Click Enable HPE Aruba Networking Central.

  4. Complete the following elements:

    Field Description
    Segment Automatically set to “default” and cannot be changed.
    Unified fabric zone Select the zone for all OTO traffic. This allows you to map Unified Fabric traffic to your preferred network zones.
    Unified fabric fallback role Select the role for all OTO traffic. This ensures that Unified Fabric traffic has a consistent default role assigned to it.
  5. Click Save.

  6. Click OK.

Configure the EdgeConnect Gateways as Hubs

HPE Aruba Networking virtual private network concentrator (VPNC) is only supported on physical EdgeConnect gateways that are configured as Hubs in Orchestrator.

  1. In Orchestrator, navigate to Configuration > Overlays & Security > Hubs.

  2. Click Add hub.

  3. From the appliance tree, select the appliance that you want to configure as a hub.

  4. For Hub routing, leave the default selection of “Re-Advertise routes” and click Save.

    img

Repeat this process if there are other appliances to configure as hubs. Only one hub is required for the Unified Fabric solution.

Configure Loopback Interface with Loopback Orchestration

The EdgeConnect gateway hub must have a loopback interface with an IP address configured. HPE Aruba Networking recommends using the Loopback Orchestration feature to automatically assign a loopback address to each EdgeConnect managed by the Orchestrator from a group of address pools. You can create a pool of loopback addresses for Orchestrator to automatically create one or more loopback interfaces. You can also assign IP addresses from the pool of each gateway in the network.

NOTE: If you have a loopback interface configured on the EdgeConnect, you do not need to create a new one. Proceed to the next section.

The following steps describe how to set up loopback orchestration.

  1. In Orchestrator, navigate to Configuration > Overlays & Security > Interface Labels.

  2. Click Add, select LAN, and then enter a name (for example, LOOPBACK).

  3. Click Save.

  4. Navigate to Configuration > Networking > Loopback Orchestration.

  5. Select +Add Loopback Interface.

    The Loopback Interface dialog box opens.

  6. Select the Label that you configured from the drop-down list.

  7. Specify the firewall zone if you want to the loopback interface to be part of a specific firewall zone.

  8. Select the Management check box if you want management applications running on the appliance to use the loopback interface. This translates to “System-IP” for HPE Aruba Networking Central connectivity.

  9. Click OK.

    img

Create WAN Interface Label Names for the Unified Fabric

The WAN interface label names for the hubs in Orchestrator need to be appended with _inet or _mpls, so the names match or closely match the HPE Aruba Networking Central interface label names on the WAN interfaces for SD-Branch and Microbranch. The EdgeConnect gateways at branch locations can have traditional Orchestrator interface labels, such as INET or MPLs, and they do not need to be appended with _inet or _mpls, as they will have cross-connect configured to support the hub. For more information on interface label matching, see Overlay Tunnel Orchestrator (OTO).

The following steps describe how to create a WAN interface label for the Unified Fabric.

  1. In Orchestrator, navigate to Configuration > Overlays & Security > Interface Labels.

  2. Click Add and select WAN.

  3. Do one of the following:

    • If you are running 9.5.x or 9.6.x, enter a name for the label that is appended with _inet or _mpls. For example, if INETA is the internet label that will be used for the Unified Fabric, enter “INETA_inet” so it matches the HPE Aruba Networking Central label names.

    • If you are running 9.7.x or later, select the appropriate WAN type (inet or mpls). Orchestrator automatically appends the corresponding suffix based on the WAN type selection.

    NOTE: If you do not see the WAN type menu on the Interface Labels Configuration dialog box after you select WAN, you have not enabled HPE Aruba Networking Central.

  4. Click Save.

If you already have INETA and MPLS1 interface labels that will be used for the Unified Fabric, you can update the labels to add the suffixes, or you can create new labels. To update the label names, enter “INETA_inet” and “MPLS1_mpls”.

NOTE: If you update label names, do it during a maintenance window as it can be disruptive.

Next Steps

After you have configured Orchestrator, continue to Configure HPE Aruba Networking Central.