SD-WAN Aruba Edgeconnect Collector Deployment and Configuration Guide

This document describes the steps to deploy and configure the SD-WAN Aruba EdgeConnect collector.

Important:

Please do not run sevone-cli command from a subdirectory under /opt/SevOne/upgrade and /var/log/pods. It can be run from any directory except for from subdirectories under /opt/SevOne/upgrade and /var/log/pods.

Important:

Please use support user for NMS version 7.0.0 and above.

However, for NMS versions prior to version 7.0.0, please use root user instead of support user.

Prerequisites

  • An administrator-level account in SevOne NMS.
  • SSH password for the tmp account.
  • IP address of the PAS.

Installation Steps

SevOne NMS

The following steps apply to perform an installation from scratch of the Aruba EdgeConnect on SevOne NMS.

  1. Using ssh, login to SevOne NMS appliance as support.
    ssh support@<SevOne NMS appliance IP address>
    
  2. To install the spk files, execute the following commands in the sequence as shown below.
    • For a list of containers and its ids, run the following command.
      podman ps
    • Go to SevOne NMS container.
      podman exec -it <nms_container_id_or_name>/bin/bash
    • Make a directory ArubaEdgeConnect under the /tmp folder and change the directory to /tmp/ArubaEdgeConnect.
      cd /tmp/
      mkdir ArubaEdgeConnect
      cd /tmp/ArubaEdgeConnect
  3. Download the following (latest) files from IBM Passport Advantage (https://www.ibm.com/software/passportadvantage/pao_download_software.html) via Passport Advantage Online. However, if you are on a legacy / flexible SevOne contract and do not have access to IBM Passport Advantage but have an active Support contract, please contact IBM SevOne Support for the latest files. You must place <tar/zip> files in the /tmp/ArubaEdgeConnect directory.
    1. sdwan-aruba-edgeconnect-installation-v7.2.0-build.<###>.tgz
    2. sdwan-aruba-edgeconnect-installation-v7.2.0-build.<###>.tgz.sha256.txt
    3. signature-tools-<latest-version>-build.<latest>.tgz
    4. signature-tools-<latest-version>-build.<latest>.tgz.sha256.txt
  4. Execute the following commands to verify the checksum of the code signing tool before extracting it.
    
    (cd /tmp/ArubaEdgeConnect && cat $(ls -Art signature-tools-*.tgz.sha256.txt | \
    tail -n 1) | sha256sum --check)
    
    sudo tar xvfz $(ls -Art /tmp/ArubaEdgeConnect/signature-tools-*.tgz | \
    tail -n 1) -C /tmp/ArubaEdgeConnect
  5. Verify the signature of Solutions .tgz files.
    sh usr/local/sbin/SevOne-validate-image \
    -i $(ls -Art /tmp/ArubaEdgeConnect/sdwan-*.tgz | tail -n 1) \
    -s $(ls -Art /tmp/ArubaEdgeConnect/sdwan-*.tgz.sha256.txt | tail -n 1)
  6. Make a directory. For example, sdwan-aruba-edgeconnect-installation.
    mkdir /tmp/ArubaEdgeConnect/sdwan-aruba-edgeconnect-installation
    
  7. Extract the latest build.
    tar xvfz $(ls -Art /tmp/ArubaEdgeConnect/sdwan-*.tgz | \
    tail -n 1) -C /tmp/ArubaEdgeConnect/sdwan-aruba-edgeconnect-installation 

    You will see the following files in the directory.

    • ArubaEdgeConnect.Certification.spk - it creates one device type SilverPeak and 58 object types.
    • ArubaEdgeConnect.TopNViews.spk - it imports 3 TopN Report views.
  8. Change directory to /tmp/ArubaEdgeConnect/sdwan-aruba-edgeconnect-installation.
    cd /tmp/ArubaEdgeConnect/sdwan-aruba-edgeconnect-installation
    
  9. Import the following . spk file.
    • Device Type and Object Type
      
      SevOne-import --allow-overwrite --file ArubaEdgeConnect.Certification.spk

Device Onboarding

To onboard Aruba EdgeConnect devices in SevOne NMS, execute the following steps.

  1. Using a web browser of your choice, enter the URL for the SevOne NMS appliance. Enter the credentials and click Login.

    arubaNMSLoginPage

    arubaHomePage

  2. From the navigation bar, click the Devices menu and select Device Manager.

    arubaDeviceManager

  3. Click Add Device to create a new device.

    arubaAddDevice

  4. On the New Device page, add the following details.

    arubaNewDevice

    1. In the Name field, enter the device name.
    2. In the Alternate Name field, enter an alternate device name. You can search for a device by its alternate name.
    3. In the Description field, enter the device description. You can use this to provide additional information about the function, location, or any other pertinent information about the device.
    4. In the IP Address field, enter the device IP address.
    5. Click the plugin drop-down. By default, it is set to SNMP. Select SDWAN.
      1. Select the Enable SDWAN API Integration check box. arubaSDWANPlugin
      2. Click the Vendor drop-down and select the Aruba EdgeConnect option.
      3. In the Orchestrator URL field, enter the URL for the SDWAN vendor, Aruba EdgeConnect.
      4. In the Username field, enter the username for the SDWAN vendor, Aruba EdgeConnect.
      5. In the Password field, enter the password for the SDWAN vendor, Aruba EdgeConnect.
      6. Enable field Auto-discover and monitor associated Edges - Use SNMP Plugin to automatically discover and monitor Aruba EdgeConnect devices.
    6. Once the SD-WAN plugin details are entered, select the SNMP plugin from the plugin drop-down menu.

      arubaSNMPPlugin

    7. Ensure that the field SNMP Capable check box is selected to enable the discovery of SNMP object types and to poll SNMP data on the device.
    8. In the Version field and select the version. For example, select 3 from the available options in the drop-down list.
    9. Enter credentials (Username & Password) for the Aruba EdgeConnect device. (Make sure to have same SNMP credentials for all Aruba EdgeConnect devices).
    10. Select other options and click Save As New to save the current changes as a New Device. This device is then queued for discovery.
    11. A new device has been added to the Device Manager screen.
    12. Again, click the Devices menu and select Discovery Manager. Now, you will see that the device is in the discovery queue.
    13. After the discovery process is completed, Aruba EdgeConnect devices will be visible on the Device Manager screen.arubaDevices
Note: TopN Report Views - Import on SevOne NMS

SevOne-import --allow-overwrite --file ArubaEdgeConnect.TopNViews.spk
The following is the list of TopN reports imported.
  • HPE Aruba EdgeConnect- Top TCP Established Connection
  • HPE Aruba EdgeConnect- Top TCP Segments Sent / Received
  • HPE Aruba EdgeConnect- Top UDP Datagrams

Aruba EdgeConnect OOTB Reports

  1. Log in to your SevOne Data Insight by navigating to the appropriate URL in your web browser. Enter your credentials on the login page and click Login.diLoginPage
  2. On the Report Manager screen, click Reports and then click on SevOne Folders. diReportManager
  3. Under SevOne Folders, select Aruba EdgeConnect folder from the SD-WAN drop-down list. arubaEdgeConnectReport
  4. Select the Aruba SDWAN Report displayed. You can either click on the Run button as shown below or click on the report link directly to view detailed OOTB reports. arubaHREReport
    Note: HPE Aruba SDWAN Report report is imported.

Aruba EdgeConnect Flows on SevOne NMS

To check the flows received on SevOne NMS, from the navigation bar, click the Administration menu, select Flow Configuration, and then select Flow Interface Manager.arubaFlowInterfaceManager

Support Long Flows on SevOne NMS

Warning:

Sometimes, the flows are dropped when Aruba EdgeConnect devices send flows with a longer duration than what is configured. To allow long flows, from the navigation bar, click the Administration menu and select Cluster Manager > Cluster Settings tab > FlowFalcon subtab > uncheck Drop Long Flows option. arubaDropLongFlows

Solution Verification & Customization

Perform the following steps to log onto your SevOne NMS appliance. For more details, please refer to SevOne NMS System Administration Guide or SevOne NMS User Guide > section Login.

  1. Enter the URL for the SevOne NMS appliance into your web browser to display the Login page.
  2. Enter the credentials and click Login. For example, Username: admin and Password: SevOne
  3. To check device groups imported, click the Devices menu and select Grouping, then Device Groups. For more details on Device Groups, SevOne NMS User Guide > section Device Groups. Device Groups
  4. To check object types, click on the Administration menu and select Monitoring Configuration, then Object Types.For more details on Object Groups, SevOne NMS System Administration Guide > section Object Types.

    Aruba Object Types