HPE Aruba AOS-CX Initial Configuration Guide (6300/6400) - 夜莺博客

HPE Aruba AOS-CX Initial Configuration Guide (6300/6400)

Getting an HPE Aruba CX switch out of the box and onto your network is a task every network engineer will face eventually, and the AOS-CX operating system makes it predictable. This guide condenses the official HPE Aruba AOS-CX Fundamentals Guide for the 6300 and 6400 Switch Series into a practical walkthrough: connecting to the console port, configuring the out-of-band management interface with a static IP, setting the default gateway and DNS, synchronizing time with NTP, and restoring factory defaults when needed. Every command below comes straight from the vendor fundamentals documentation.

What You Need Before You Start

Twenty minutes of preparation removes almost every problem from a first boot. Have the following ready:

  • Console access. A USB-C console cable or an RJ-45 to USB serial adapter, plus a terminal emulator (PuTTY, SecureCRT, minicom, screen, or the terminal of your choice). AOS-CX console settings are 115200 baud, 8 data bits, no parity, 1 stop bit, no flow control — the older 9600 default does not work and produces garbage characters.
  • An IP plan. A management IP with its prefix length, the management gateway, DNS servers, and an NTP source. Decide the hostname convention before you log in; renaming a switch later means updating every monitoring and backup system that references it.
  • A decision about the management path. The dedicated mgmt port is out-of-band and should not be conflated with the data-plane VLANs. On the 6300/6400 the management port is a separate physical interface with its own default VRF entry, so the switch can be reachable even when the data plane is not yet configured.
  • Credentials policy. The factory default is admin with password admin and the switch forces a password change on first login. Have the real password ready in your password manager — do not leave the default in place on a device that will touch a production network.
  • Firmware baseline. Check what the switch shipped with (show version) and confirm it matches the release your standard configuration is validated against. There is nothing worse than discovering a missing feature after the device is racked.

Console Port or Management Port: Choosing the Path

Both paths work, and the choice depends on where you are:

  • Bench, staging area, or a switch with no DHCP — use the console port. It always works, needs no addressing, and never locks you out.
  • Rack with a working out-of-band network — connect the mgmt port first. The switch ships with ip dhcp enabled on that interface, so if a DHCP server exists on the OOB network the switch will pull an address and appear in the DHCP lease table. Find it there, then SSH in and convert it to a static address.
  • Zero-touch deployments — neither, in practice: the switch provisions itself from a DHCP/HTTP source or from Aruba Central. See the ZTP section below.

Regardless of the path you start with, always finish with the management interface statically addressed and the configuration written to flash.

AOS-CX Initial Configuration Options

The 6300/6400 series supports several bootstrap methods:

  • ZTP (Zero Touch Provisioning) - automatically discovers a DHCP server and downloads configuration.
  • Aruba CX Mobile App - Bluetooth-based provisioning from a smartphone.
  • CLI over console or SSH - the classic, scriptable approach covered here.

Connecting to the Switch for the First Time

Connect a console cable to the console port, or connect the management port to your management network. Log into the switch for the first time with the default admin credentials (password admin) and you will be prompted to change the password. The management interface on AOS-CX is mgmt.

Configuring the Management Interface

Enter configuration mode and assign a static IP to the management interface, then set the default gateway and DNS nameserver:

switch# configure terminal
switch(config)# interface mgmt
switch(config-if-mgmt)# ip static 10.10.10.2/24
switch(config-if-mgmt)# exit
switch(config)# default-gateway 10.10.10.1
switch(config)# ip dns server-address 8.8.8.8
switch(config)# end

Verify the settings with show interface mgmt and show running-config. Alternatively the DHCP client can be enabled with ip dhcp if you prefer dynamic addressing on the management port.

Setting Switch Time with the NTP Client

Accurate time is critical for logs and certificates. Enable NTP and point it at your time source:

switch(config)# ntp enable
switch(config)# ntp server 162.159.200.1
switch(config)# end
switch# show ntp associations
switch# show ntp status

Usernames, Passwords and SSH Access

The default account should be replaced immediately. Create a named administrator account, then confirm that SSH is serving the management VRF:

switch(config)# hostname RSVDC-ACC-SW01
switch(config)# user admin group administrators password plaintext ChangeMe-2026!
switch(config)# ssh server vrf mgmt
switch(config)# end
switch# show ssh server
switch# show user-list

Roles matter on AOS-CX: members of the administrators group can run every command, while other groups are limited to monitoring or to specific feature sets. If your organisation uses RADIUS or TACACS+ instead of local accounts, configure the AAA server group and login method now rather than later — local-only accounts on 200 switches are a maintenance problem. The same logic applies across vendors; our RADIUS versus TACACS+ guide explains which protocol to choose for command accounting, and the Dell OS10 management interface guide shows the equivalent management-path concepts on another platform.

DNS, Domain Name and Management Reachability

Name resolution is what makes SSH, NTP by hostname, syslog and firmware downloads convenient. Set a domain name and at least two resolvers:

switch(config)# ip dns domain-name corp.example.com
switch(config)# ip dns server-address 8.8.8.8
switch(config)# ip dns server-address 1.1.1.1
switch(config)# end
switch# show ip dns

On the management interface you can also set a resolver directly with nameserver, which is useful when the management VRF is deliberately isolated from the data plane. After configuration, prove reachability before you leave the site:

switch# ping corp.example.com
switch# ping 10.10.10.1
switch# show interface mgmt
switch# show ip route

If show interface mgmt shows the address as unassigned, the static address was rejected — usually a missing prefix length or a conflicting address on the segment. If pings by name fail but pings by address succeed, the problem is DNS, not routing.

Timezone and Log Timestamps

NTP gives you the correct time; the timezone determines how that time is displayed and logged. Set the zone with the IANA name so daylight saving transitions are handled automatically:

switch(config)# clock timezone Asia/Shanghai
switch(config)# end
switch# show clock

The no form returns the switch to UTC. Decide once whether your estate logs in UTC or local time and be consistent — correlating a switch log against a server log is much easier when both are in the same zone. If your environment needs sub-millisecond accuracy for telemetry or finance workloads, the trade-offs are covered in PTP versus NTP; for ordinary campus and branch switches NTP is sufficient, and the Cisco IOS NTP server and source-interface guide is a useful comparison for mixed estates.

Configuring Banners and Saving the Configuration

Add a legal or informational banner to every login session:

switch(config)# banner motd "Authorized access only"

Finally, persist the running configuration to the startup configuration with write memory (or copy running-config startup-config). If you ever need to start over, the factory default restore procedure is covered in the Fundamentals Guide's management section (erase startup-config followed by reload).

Checking Platform Health and Firmware After Boot

Before handing the switch over, confirm the hardware is healthy and the software is what you expect:

switch# show version
switch# show system
switch# show environment
switch# show module
switch# show boot-history

show environment reports temperatures, fan state and power supply status — the fastest way to catch a dead PSU or a fan tray that was not seated during installation. show version gives the AOS-CX release, the build date and the boot image in use. If the firmware needs to change, do it before you apply production configuration and document the image path so the same version can be loaded on the spare.

Then confirm that the neighbours agree with your documentation — an LLDP check takes seconds and catches mis-patched uplinks immediately:

switch# show lldp neighbor-info
switch# show lldp neighbor-info 1/1/49 detail

Our ArubaOS-CX LLDP guide covers transmit and receive settings plus the full verification set.

ZTP and Aruba Central Onboarding

Manual CLI work is fine for one switch and painful for two hundred. Two automated paths exist:

  • Zero Touch Provisioning. The switch boots, requests DHCP on the management interface, and uses the options returned by the DHCP server to locate a configuration file. Check whether the feature is active with show ztp information, and use ztp force provision to re-trigger provisioning after fixing the server-side configuration. The workflow is conceptually identical across vendors — see the Dell OS10 zero-touch deployment guide for a side-by-side.
  • Aruba Central / management platform. The switch is added to the management plane and configuration is pushed from there, which moves the initial CLI steps into a template. Our AOS-CX Central onboarding guide covers the join process and the token/mode considerations.

Either way, the manual steps in this article remain the reference: ZTP and Central both end up writing the same interface, gateway, DNS and NTP lines into the running configuration.

Restoring Factory Defaults and Re-Imaging

Lab switches and RMA replacements often arrive with someone else's configuration. Two levels of reset are available:

switch# erase startup-config
switch# erase all zeroize
switch# boot system

erase startup-config removes the saved configuration and reloads with defaults while leaving the software image, logs and other files alone. erase all zeroize is the complete wipe — use it before returning or disposing of hardware. After either command, confirm the result in the running configuration rather than assuming it worked, and remember that the management interface returns to ip dhcp, so the switch will reappear somewhere on the OOB network.

Complete Script: Initial Configuration

The whole sequence in one block, ready to paste into a console session on a new 6300 or 6400:

switch# configure terminal
switch(config)# hostname RSVDC-ACC-SW01
switch(config)# user admin group administrators password plaintext ChangeMe-2026!
switch(config)# interface mgmt
switch(config-if-mgmt)# ip static 10.10.10.2/24
switch(config-if-mgmt)# nameserver 8.8.8.8
switch(config-if-mgmt)# exit
switch(config)# default-gateway 10.10.10.1
switch(config)# ip dns domain-name corp.example.com
switch(config)# ip dns server-address 8.8.8.8
switch(config)# ntp enable
switch(config)# ntp server 162.159.200.1
switch(config)# clock timezone Asia/Shanghai
switch(config)# banner motd "Authorized access only - activity is logged"
switch(config)# ssh server vrf mgmt
switch(config)# end
switch# show interface mgmt
switch# show ntp status
switch# show clock
switch# write memory

Note the deliberate ordering: address and gateway first so the switch is reachable, then DNS and time so logs and names are correct, then the banner and SSH policy, and finally the save. Saving last means a mistake in the middle of the sequence costs nothing but a reload.

Troubleshooting First-Boot Problems

  • Console shows only garbage or nothing. Wrong baud rate. AOS-CX uses 115200; some terminal profiles keep a 9600 default. Also check that the cable is a console cable and not a straight-through Ethernet patch lead.
  • Cannot log in as admin. The switch forces a password change on first login and, if a previous administrator already completed it, the default no longer works. Recover with a console session and a factory reset if no credentials are known.
  • Management interface has no address. Verify the static address was accepted with show interface mgmt. If DHCP is still enabled on the interface, the static command may need the existing configuration removed first.
  • Can ping the switch on the local subnet but not from the NOC. The management default gateway is missing or wrong. Check show ip route for the default route and confirm the OOB gateway address.
  • show ntp status stays unsynchronised. The most common causes are no default gateway, an unreachable server, or a firewall that blocks UDP 123. Try a public source such as 162.159.200.1 to prove the path, then switch to your internal server.
  • Switch is not visible in the DHCP lease table during ZTP. The management port may not be patched to the provisioning network, or the DHCP server is not handing out the vendor options the switch needs. show ztp information tells you which stage failed.

FAQ

Is the management port mandatory? No. AOS-CX can be managed over a data-plane VLAN or loopback, but keeping management on the dedicated port (or a dedicated OOB VLAN) is best practice because it survives data-plane mistakes.

Which interface name does the management port use? mgmt. It is a distinct interface type with its own command set, not 1/1/x.

Do I need a licence for basic configuration? Basic L2/L3 forwarding, management, NTP and DNS do not need a licence; features such as EVPN-VXLAN and some advanced security capabilities do. Check the ordering guide for your platform before promising a feature.

Should I configure VSF or VSX before leaving the site? Yes if the switch is part of a pair or stack — it is far easier to verify redundancy at the rack than remotely months later. See ArubaOS-CX VSF stacking and ArubaOS-CX VSX configuration.

What about DHCP snooping on a new access switch? Configure it as part of the standard build rather than as an afterthought — our ArubaOS-CX DHCP snooping guide walks through the trusted-port design.

How do I prove the configuration survives a reboot? Run write memory, then compare show running-config with show startup-config. They should match; if they do not, the save did not complete.

Related Reading

原文链接:https://arubanetworking.hpe.com/techdocs/AOS-CX/10.13/PDF/fundamentals_6300-6400.pdf

相关阅读