Implementing AOS-CX v24.31 (ICX)
Welcome to Implementing Aruba AOS-CX
navigate to https://rubbernecks-arubanetworks.blogspot.com
Be sure you have downloaded the course learner guide as per the instructions you received in an email from HPE last week. Check your email history, spam folder, etc... for the keyword "OnSecure" if you cannot find the email. You only have 10 days to print this learner guide (PDF or paper), and one year of access to the online document.
- Click here for this week's lab access spreadsheet
- ask me for the link password
Lab Notes
- webgate: how to copy and paste while doing the labs
- ask me for the link password
Tips on how to google our site for documentation
- googling for AOS-Switch-related topics
- site:hpe.com -inurl:pdf -inurl:cx inurl:16\.11 "dhcp-snooping"
- googling for AOS-CX-related topics
- site:arubanetworks.com -inurl:pdf inurl:cx inurl:10\.16 "dhcp-snooping"
- search option notes:
- site:x only searched that domain
- -inurl:x don't report links with this text in the URL
- inurl:x only report on links with text
- (ideal for finding specific version documentation)
- googling for AOS-Switch-related topics
- site:hpe.com -inurl:pdf -inurl:cx inurl:16\.11 "dhcp-snooping"
- googling for AOS-CX-related topics
- site:arubanetworks.com -inurl:pdf inurl:cx inurl:10\.16 "dhcp-snooping"
- (ideal for finding specific version documentation)
Helpful Links
- about Aruba training and this course
- about Aruba training and this course
- where to find more information
- aruba: Aruba Technical Product Documentation Portal
- here you find:
- Technology Briefs
- Validated Reference Designs
- Aruba Validated Designs
- Compliancy Documentation related to GDPR
- airheads: community.arubanetworks.com
- abc: Airheads Broadcasting Channel
- afp: Partner Technical Webinars
- where to find online documentation
- where to find more information
- aruba: Aruba Technical Product Documentation Portal
- here you find:
- Technology Briefs
- Validated Reference Designs
- Aruba Validated Designs
- Compliancy Documentation related to GDPR
- airheads: community.arubanetworks.com
- abc: Airheads Broadcasting Channel
- afp: Partner Technical Webinars
- AOS-CX specific links
- AOS-CX specific links
- aruba: feature-navigator.arubanetworks.com
- aruba: CX switch software feature packs
- abc: AOS-CX Software Release Technical Update
- aruba: HPE ArubaNetworking 3D Catalog
- td: AOS-S and AOS-CX Transceiver Guide Edition
- td: VSX Config Best Practices V2 (2025)
- asp: CX Documentation Portal
- asp: CX_10.13 EVPN VXLAN Guide
- asp: CX_10.13 IP Services Guide
- asp: CX_10.13 Security Guide
- asp: CX_10.13 NAE
- asp: CX_10.13 Monitoring Guide
- asp: CX_10.13 ACLs and Classifier Policies Guide - 6[34]00,81xx,8360
- asp: CX_10.13 CoPP Guide
- asp: CX_10.13 IP Routing
- asp: CX_10.13 Fundamentals Guide
- hpe: DS_4100i Series
- hpe: DS_5420 Series
- hpe: DS_6000 Series
- hpe: DS_6100 Series
- hpe: DS_6200 Series
- hpe: DS_6300 Series
- hpe: DS_6400 Series
- hpe: DS_8100 Series
- hpe: DS_8320 Series
- hpe: DS_8325 Series
- hpe: DS_8360 Series V2
- hpe: DS_8400 Series
- hpe: DS_9300 Series
- hpe: DS_10000 Series
- aruba: feature-navigator.arubanetworks.com
- aruba: CX switch software feature packs
- abc: AOS-CX Software Release Technical Update
- aruba: HPE ArubaNetworking 3D Catalog
- td: AOS-S and AOS-CX Transceiver Guide Edition
- td: VSX Config Best Practices V2 (2025)
- asp: CX Documentation Portal
- asp: CX_10.13 EVPN VXLAN Guide
- asp: CX_10.13 IP Services Guide
- asp: CX_10.13 Security Guide
- asp: CX_10.13 NAE
- asp: CX_10.13 Monitoring Guide
- asp: CX_10.13 ACLs and Classifier Policies Guide - 6[34]00,81xx,8360
- asp: CX_10.13 CoPP Guide
- asp: CX_10.13 IP Routing
- asp: CX_10.13 Fundamentals Guide
- hpe: DS_4100i Series
- hpe: DS_5420 Series
- hpe: DS_6000 Series
- hpe: DS_6100 Series
- hpe: DS_6200 Series
- hpe: DS_6300 Series
- hpe: DS_6400 Series
- hpe: DS_8100 Series
- hpe: DS_8320 Series
- hpe: DS_8325 Series
- hpe: DS_8360 Series V2
- hpe: DS_8400 Series
- hpe: DS_9300 Series
- hpe: DS_10000 Series
- CX - Significant New Features
- 10.08: automatically create VLANs on switch when assigned to user by role
- port access auto-vlan
- 10.16: high availability
- VSF support for 4100i and 6100
- VSX support for 6300 (not the L version)
Day 1 - Lecture Modules & Labs
- M00: Course Introduction
- M01: Introduction to Aruba Switching
- Lab 1 - Base Configuration- Initial Lab Setup
- 1-1: Factory reset of devices (optional)
- 1-2: Configure the OOBM interface on Access-1
- 1-3: Configure the OOBM for Access-2, Core-1, and Core-2
- M02: VSX
- Lab 2 - VSX
- 2-1: Verify the lab starting configuration
- 2-2: Preparing for VSX
- 2-3: VSX basic setup
- 2-4: VSX configuration synchronization
- 2-5: VSX Layer 2—VSX link aggregation (VSX LAG)
- 2-6: VSX Layer 3 active gateway
- 2-7: VSX failover test (optional)
- 2-8: VSX split-brain handling
- 2-9: Finalize the configuration for the upcoming labs
- Lab 1 - Base Configuration- Initial Lab Setup
- 1-1: Factory reset of devices (optional)
- 1-2: Configure the OOBM interface on Access-1
- 1-3: Configure the OOBM for Access-2, Core-1, and Core-2
- Lab 2 - VSX
- 2-1: Verify the lab starting configuration
- 2-2: Preparing for VSX
- 2-3: VSX basic setup
- 2-4: VSX configuration synchronization
- 2-5: VSX Layer 2—VSX link aggregation (VSX LAG)
- 2-6: VSX Layer 3 active gateway
- 2-7: VSX failover test (optional)
- 2-8: VSX split-brain handling
- 2-9: Finalize the configuration for the upcoming labs
- M03: Layer 2 Optimization
- Lab 3 - Layer 2 Optimization and Protection features
- 3-1: Verify the lab starting configuration
- 3-2: Examine the LAG load sharing process
- 3-3: Using the LACP fallback feature
- 3-4: Configure an MSTP solution
- 3-5: Understanding edge ports and their operation with spanning
- 3-6: Implement BPDU guard
- 3-7: Implement root guard
- 3-8: Implement loop protection
- 3-9: Implement PVLANs (optional)
Day 2 - Lecture Modules & Labs
- M03: Layer 2 Optimization
- Lab 3 - Layer 2 Optimization and Protection features
- 3-1: Verify the lab starting configuration
- 3-2: Examine the LAG load sharing process
- 3-3: Using the LACP fallback feature
- 3-4: Configure an MSTP solution
- 3-5: Understanding edge ports and their operation with spanning
- 3-6: Implement BPDU guard
- 3-7: Implement root guard
- 3-8: Implement loop protection
- 3-9: Implement PVLANs (optional)
- M04:Advanced OSPF
- Lab 4.1 - OSPF single area
- 4.1.1: Verify Lab Start Configuration
- 4.1.2: Basic OSPF Setup on Core Area 0
- 4.1.3: OSPF Address Advertisements and Control
- 4.1.4: OSPF Peering Using VSX LAG
- Lab 4.2 - OSPF and multi-area
- 4.2.1: Assign Access1 to OSPF Area 1
- 4.2.2: Assign Access2 to OSPF Area 2
- 4.2.3: Route Summarization
- 4.2.4: Verify Route Propagation Impact with Summarization
- 4.2.5: ABR Route Filtering
- Lab 4.3 - Managing OSPF external routes
- 4.3.1: Setup Link to RouterA
- 4.3.2: Redistribute Static Routes into OSPF
- 4.3.3: Control Route Redistribution and Metric Types
- 4.3.4: Filter Routes with Stub and Totally Stub Areas
- 4.3.5: Filter Routes with a Not So Stubby Area (NSSA)
- 4.3.6: Save configuration checkpoints for the upcoming labs
- Lab 4.1 - OSPF single area
- 4.1.1: Verify Lab Start Configuration
- 4.1.2: Basic OSPF Setup on Core Area 0
- 4.1.3: OSPF Address Advertisements and Control
- 4.1.4: OSPF Peering Using VSX LAG
- Lab 4.2 - OSPF and multi-area
- 4.2.1: Assign Access1 to OSPF Area 1
- 4.2.2: Assign Access2 to OSPF Area 2
- 4.2.3: Route Summarization
- 4.2.4: Verify Route Propagation Impact with Summarization
- 4.2.5: ABR Route Filtering
- Lab 4.3 - Managing OSPF external routes
- 4.3.1: Setup Link to RouterA
- 4.3.2: Redistribute Static Routes into OSPF
- 4.3.3: Control Route Redistribution and Metric Types
- 4.3.4: Filter Routes with Stub and Totally Stub Areas
- 4.3.5: Filter Routes with a Not So Stubby Area (NSSA)
- 4.3.6: Save configuration checkpoints for the upcoming labs
- M05: BGP
- Lab 5 - Basic BGP peering
- 5.1: Prepare the lab setup
- 5.2: Core-1 eBGP peering to ISP1
- 5.3: Core-1 and Core2 iBGP peering
- 5.4: Core-2 eBGP Peering to ISP2
- 5.5: Announce Routes to eBGP Peers
- Lab 5 - Basic BGP peering
- 5.1: Prepare the lab setup
- 5.2: Core-1 eBGP peering to ISP1
- 5.3: Core-1 and Core2 iBGP peering
- 5.4: Core-2 eBGP Peering to ISP2
- 5.5: Announce Routes to eBGP Peers
- M06: Additional L3 Features
- Lab 6 - Additional Layer 3 Features
- 6.1: Prepare the lab start configuration
- 6-2: Add a new routing VRF
- 6-3: OSPF routing inside a VRF
- 6-4: Implementing DHCP snooping
- 6-5: Implementing Dynamic ARP Inspection
- Lab 6 - Additional Layer 3 Features
- 6.1: Prepare the lab start configuration
- 6-2: Add a new routing VRF
- 6-3: OSPF routing inside a VRF
- 6-4: Implementing DHCP snooping
- 6-5: Implementing Dynamic ARP Inspection
Day 3 - Lecture Modules & Labs
- M07: IGMP
- Lab 7 - IGMP
- 7-1: Prepare the lab starting configuration
- 7-2: Set up the multicast sender and receiver
- 7-3: Enable IGMP querier and snooping
- 7-4: Verify the IGMP snooping operation
- 7-5: Verify IGMP snooping fast leave (optional)
- Lab 7 - IGMP
- 7-1: Prepare the lab starting configuration
- 7-2: Set up the multicast sender and receiver
- 7-3: Enable IGMP querier and snooping
- 7-4: Verify the IGMP snooping operation
- 7-5: Verify IGMP snooping fast leave (optional)
- M08 Multicast Routing
- asp: AOS-CX 10.13 Multicast Guide
- asp: AOS-CX 10.13 Multicast Guide - (IGMP robustness)
- asp: AOS-CX 10.13 Multicast Guide - (active-active)
- wiki: Multicast address
- techdocs: IP multicast addresses
- iana: IPv4 Multicast Address Space Registry
- web: MAC address converter
- file: UDPMulticast Test (App from the lab)
- Lab 8 - PIM
- 8.1: Prepare and review the lab setup
- 8.2: Configure PIM sparse mode
- 8.3: Verify multicast forwarding
- M09: ACLs
- key point:
- The "implicit permit" behavior of policy matching differs from the "implicit deny" behavior of ACL matching.
- M08 Multicast Routing
- asp: AOS-CX 10.13 Multicast Guide
- asp: AOS-CX 10.13 Multicast Guide - (IGMP robustness)
- asp: AOS-CX 10.13 Multicast Guide - (active-active)
- wiki: Multicast address
- techdocs: IP multicast addresses
- iana: IPv4 Multicast Address Space Registry
- web: MAC address converter
- file: UDPMulticast Test (App from the lab)
- Lab 8 - PIM
- 8.1: Prepare and review the lab setup
- 8.2: Configure PIM sparse mode
- 8.3: Verify multicast forwarding
- M09: ACLs
- key point:
- The "implicit permit" behavior of policy matching differs from the "implicit deny" behavior of ACL matching.
- Lab 9 - ACLs
- 9.1: Verify the lab starting configuration
- 9.2: Port ACLs
- 9.3: Using object groups
- 9.4: Resource usage
- Lab 9 - ACLs
- 9.1: Verify the lab starting configuration
- 9.2: Port ACLs
- 9.3: Using object groups
- 9.4: Resource usage
Day 4 - Lecture Modules & Labs
- M10: 802.1X Authentication
- Lab 10 - Dot1X
- 10.1: Verify the lab starting configuration
- 10.2: RADIUS server setup
- 10.3: Basic 802.1X authentication with a single user
- 10.4: Change of authorization verification
- 10.5: Basic 802.1X authentication with a single user
- 10.6: Unknown role assignment
- Lab 10 - Dot1X
- 10.1: Verify the lab starting configuration
- 10.2: RADIUS server setup
- 10.3: Basic 802.1X authentication with a single user
- 10.4: Change of authorization verification
- 10.5: Basic 802.1X authentication with a single user
- 10.6: Unknown role assignment
- M11: MAC Authentication
- Lab 11 - Mac-Based Authentication
- 11.1: MAC authentication with a single device on a port
- 11.2: Verify access with two devices connected on same port
- 11.3: Aruba user role-based access
- 11.4: OPTIONAL—client-mode versus device-mode port authentication
- 11.5: Authentication priority order with combined MAC-auth and 802.1X
- 11.6: Verify 802.1X authentication precedence over MAC-auth
- 11.7: OPTIONAL—device profiles with LLDP
- 11.8: Save checkpoint configuration
- M12: Dynamic Segmentation
- m12 s35-36 errata
- most of the information on these 2 slides is inaccurate
- the controller IP is meant to point to a backup cluster, not a backup controller in the same cluster
- also, the primary-controller and backup-controller IP do not control the primary and backup GRE tunnel destinations, they only give the switch the initial contact point, bootstrapping the GRE is described in the links provided
- Lab 12.1 - CPPM DUR
- 12.1.1: CPPM REST API communication
- 12.1.2: CPPM user role definitions
- 12.1.3: Testing 802.1X DUR with employee and contractor
- 12.1.4: OPTIONAL—ClearPass DUR configuration and troubleshooting
- Lab 12.2 - CPPM UBT with MC
- 12.2.1: Prepare the lab devices
- 12.2.2: HPE Aruba Networking MC integration
- 12.2.3: User role configuration on the switch and the MC
- 12.2.4: Test MC integration
- 12.2.5: OPTIONAL—MAC authentication role example for IoT
- Lab 11 - Mac-Based Authentication
- 11.1: MAC authentication with a single device on a port
- 11.2: Verify access with two devices connected on same port
- 11.3: Aruba user role-based access
- 11.4: OPTIONAL—client-mode versus device-mode port authentication
- 11.5: Authentication priority order with combined MAC-auth and 802.1X
- 11.6: Verify 802.1X authentication precedence over MAC-auth
- 11.7: OPTIONAL—device profiles with LLDP
- 11.8: Save checkpoint configuration
- m12 s35-36 errata
- most of the information on these 2 slides is inaccurate
- the controller IP is meant to point to a backup cluster, not a backup controller in the same cluster
- also, the primary-controller and backup-controller IP do not control the primary and backup GRE tunnel destinations, they only give the switch the initial contact point, bootstrapping the GRE is described in the links provided
- Lab 12.1 - CPPM DUR
- 12.1.1: CPPM REST API communication
- 12.1.2: CPPM user role definitions
- 12.1.3: Testing 802.1X DUR with employee and contractor
- 12.1.4: OPTIONAL—ClearPass DUR configuration and troubleshooting
- Lab 12.2 - CPPM UBT with MC
- 12.2.1: Prepare the lab devices
- 12.2.2: HPE Aruba Networking MC integration
- 12.2.3: User role configuration on the switch and the MC
- 12.2.4: Test MC integration
- 12.2.5: OPTIONAL—MAC authentication role example for IoT
- M13: Quality of Service
- asp: AOS-CX 10.13 Quality of Service Guide - 83XX
- asp: AOS-CX 10.13 ACLs and Classifier Policies Guide - 83XX
- asp: AOS-CX 10.13 QoS Guide - 6[234]00 - queue action (WRED)
- How does green, yellow, red, AFCx1,x2,x3 affect drop probability?
- m13 errata
- many slides have the acronym DHCP
- in all cases, they mean to say DSCP
- m13 s33 errata
- for the code sample to be realistic the following code replaces what you saw on the slide, the bolded part has been modified
- qos trust none
- class ip VOICE
- 10 match udp any any range 5004 5065 count
- policy POLICY-VOICE
- 10 class ip VOICE action local-priority 5
- interface 1/1/1
- apply policy POLICY-VOICE in
- asp: AOS-CX 10.13 Quality of Service Guide - 83XX
- asp: AOS-CX 10.13 ACLs and Classifier Policies Guide - 83XX
- asp: AOS-CX 10.13 QoS Guide - 6[234]00 - queue action (WRED)
- How does green, yellow, red, AFCx1,x2,x3 affect drop probability?
- m13 errata
- many slides have the acronym DHCP
- in all cases, they mean to say DSCP
- m13 s33 errata
- for the code sample to be realistic the following code replaces what you saw on the slide, the bolded part has been modified
- qos trust none
- class ip VOICE
- 10 match udp any any range 5004 5065 count
- policy POLICY-VOICE
- 10 class ip VOICE action local-priority 5
- interface 1/1/1
- apply policy POLICY-VOICE in
- Lab 13 - Quality of Service
- 13.1: Prepare the lab start configuration
- 13.2: Port classification – trust configuration
- 13.3: LLDP device profile for QoS trust
- 13.4: QoS classification
- 13.5: Queue configuration
- 13.6: LLDP-MED and voice VLAN configuration
- Lab 13 - Quality of Service
- 13.1: Prepare the lab start configuration
- 13.2: Port classification – trust configuration
- 13.3: LLDP device profile for QoS trust
- 13.4: QoS classification
- 13.5: Queue configuration
- 13.6: LLDP-MED and voice VLAN configuration
Day 5 - Lecture Modules & Labs
- M14: Rest API
- Lab 14 - REST API
- 14.1: Enable access to REST API on the AOS-CX switch
- 14.2: REST reference interface
- M15: Network Analytics Engine
- Lab 14 - REST API
- 14.1: Enable access to REST API on the AOS-CX switch
- 14.2: REST reference interface
- Lab 15 - NAE Configuration
- 15.1: Test the environment
- 15.2: Review the built.in NAE script and agent
- 15.3: Add a new NAE script and agent
- 15.4: OPTIONAL – Connectivity check
- 15.5: Review the NAE agent in the switch configuration file
- Lab 15 - NAE Configuration
- 15.1: Test the environment
- 15.2: Review the built.in NAE script and agent
- 15.3: Add a new NAE script and agent
- 15.4: OPTIONAL – Connectivity check
- 15.5: Review the NAE agent in the switch configuration file
- M16: Troubleshooting
- Lab 16 - Troubleshooting
- 16.1: Prepare the lab start configuration
- 16.2: Support ticket troubleshoot
- Lab 16 - Troubleshooting
- 16.1: Prepare the lab start configuration
- 16.2: Support ticket troubleshoot
- M17: Conclusion
Appendix
- Acronyms or Key terms
- ASIC: application specific integrated circuit
- SVI: switched virtual interface (interface vlan <vlan-id>)
- TCAM: ternary content addressable memory (logic system: true, false, other)
- NetEDIT's types of Validation:
- Syntax: validated by command line parser in editor
- in-line typing, command and parameters validity
- Sematics: configuration consistency validated with "Validate" button
- eg: create vlan before creating SVI
- Conformance: applied by policies you create, in editor validation
- corporate polieis or minimum requirements conformancy
- Consistency: validated in editor
- eg: ensure interswitch trunk setting match
- Change: compare show output before and after deploy
- offers rollback or commit as followthrough in Plan deployment
- Lab Access Errata
- when experiencing any problems with remote lab access (WebGate):
- be sure your browser is in private (incognito) mode
- restart your browser and clear your cache and cookies
- do not try to login unless you are 100 percent sure the login page is fully loaded (the tab favicon will look similar to an orange triangle)
- during login to Central, did you select the SSO option?
- if you need to restart your windows host
- in cmd.com type "shutdown /r /t 0"
- if your 6300 is missing its firmware
- (this example was pod53, table10-access-1)
- boot to service OS
- ip addr 10.251.1.68 255.255.255.0 10.251.1.254
- tftp -b 65464 -g -r ArubaOS-CX_6400-6300_10_13_1000.swi 10.251.1.91
Comments
Post a Comment