Cloud Managed Networks

 View Only
last person joined: 3 days ago 

Forum to discuss all things related to HPE Aruba Networking Central and UXI Network Management, including deployment of managed networks, configuration, best practices, APIs, Cloud Guest, AIOps, Presence Analytics, and other included Applications
Expand all | Collapse all

HP 2530 - non-authenticated EST enrollment

This thread has been viewed 30 times
  • 1.  HP 2530 - non-authenticated EST enrollment

    Posted Aug 04, 2020 10:19 AM

    Hello !

     

    I have a problem to connect my HPe/Aruba 2530-24G J9776A in Aruba Central, I don't know how to fix that...

     

    I added MAC+S/N in Aruba Central (and enable subscription) but nothing work...

     

    my error is: EST enrollment has failed with status code : non-authenticated

     

    if someone can help me, I wont refuse,

    Regards.

     

    ---

     

    My version :

     

    HP-2530-24G(config)# show version
    
    Image stamp:
     /ws/swbuildm/rel_ajanta_qaoff/code/build/lakes(swbuildm_rel_ajanta_qaoff_rel_aj
    anta)
                    Jun 26 2020 00:30:07
                    YA.16.10.0009
                    294
    Boot Image:     Primary
    
    Boot ROM Version:    YA.15.20

     

     

     

    My running-config :

     

    HP-2530-24G(config)# show run
    
    Running configuration:
    
    ; J9776A Configuration Editor; Created on release #YA.16.10.0009
    ; Ver #14:41.44.00.04.19.02.13.98.82.34.61.18.28.f3.84.9c.63.ff.37.27:05
    hostname "HP-2530-24G"
    password manager user-name "admin" sha1
     "d033e22ae348aeb5660fc2140aec35850c4da997"
    timesync ntp
    ntp unicast
    ntp server-name "0.pool.ntp.org" iburst
    ntp server-name "1.pool.ntp.org" iburst
    ntp server-name "2.pool.ntp.org" iburst
    ntp enable
    time daylight-time-rule western-europe
    time timezone 60
    web-management ssl
    ip dns server-address priority 1 1.1.1.1
    ip dns server-address priority 2 80.80.80.80
    snmp-server community "public"
    snmpv3 engineid "00:00:00:0b:00:00:80:c1:6e:cf:b5:e0"
    vlan 1
       name "DEFAULT_VLAN"
       untagged 1-28
       ip address dhcp-bootp
       exit
    spanning-tree

     

     

     

    I have network connexion and I ping aruba server :

     

    HP-2530-24G(config)# ping arubanetworks.com
    arubanetworks.com is alive, time = 87 ms

     

     

     

    but same if I force my provision, the status is always like this....

     

    HP-2530-24G(config)# show activate provision
    
     Configuration and Status - Activate Provision Service
    
      Activate Provision Service   : Enabled
      Activate Server Address      : devices-v2.arubanetworks.com
      Activation Key               : Not Available
      Time Sync Status             : Time sync from other source
      Activate DNS Lookup          : Success
      Proxy Server DNS Lookup      : NA
      Activate Connection Status   : Failure
      Error Reason                 : EST enrollment has failed with status code :
     non-authenticated

     


    #2530


  • 2.  RE: HP 2530 - non-authenticated EST enrollment

    EMPLOYEE
    Posted Sep 24, 2020 09:32 PM

    This is specific to the 2530, as this model does not have a TPM chip.

     

    You need to have the switch in Activate, but then TAC needs to manually whitelist the serial as well. Once that is complete, unsubscribe / re-subscribe your switch and it should show up. 



  • 3.  RE: HP 2530 - non-authenticated EST enrollment

    Posted Jan 20, 2022 10:30 AM
    Hello,

    I have the same issue with 2530 YA.16.11.0003 software revision.

    Can you please explain the procedure .

    what do you meen by "but then TAC needs to manually whitelist the serial as well" where can I white list my switch ?

    Regards


    ------------------------------
    Benoit DAVID
    ------------------------------



  • 4.  RE: HP 2530 - non-authenticated EST enrollment

    EMPLOYEE
    Posted Jan 20, 2022 05:43 PM
    Please reach out to Aruba support and describe this issue, they will have access to Activate service and will authorise the switch manually since this old switch does not have a TPM to automatically authenticate.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------