Explore Aruba Tech with Lionel Medina

Post 5: Access Point Provisioning – From Box to Online in Minutes (Week 5)

Mar 3, 2026 | Aruba Wireless | 0 comments

By Lionel Medina

Purpose

Guide readers through physical AP installation and the "magic" of Zero-Touch Provisioning, where APs auto-configure and join Central.

Content Outline

What is Zero-Touch Provisioning (ZTP)?

  • ZTP allows APs to auto-configure when plugged in—no console, no manual setup
  • APs boot, get DHCP, resolve DNS, contact Aruba Activate, redirect to Central
  • Central pushes configuration based on group assignment
  • Result: "Plug it in, walk away"​

How ZTP Works (Behind the Scenes)

  1. AP powers on and requests DHCP address
  2. AP uses DNS to resolve activate.arubanetworks.com
  3. AP contacts Aruba Activate server in the cloud
  4. Activate checks device serial number against your account
  5. Activate tells AP which Central instance to join
  6. AP connects to your Central instance
  7. Central identifies AP by serial number and assigns to group
  8. Central pushes configuration to AP based on group settings
  9. AP applies config and goes live

Network Prerequisites for ZTP

  • DHCP server: AP must get IP address, gateway, DNS server
  • DNS resolution: AP must resolve activate.arubanetworks.com and your Central instance
  • Internet access: Outbound HTTPS (TCP 443) to Aruba Activate and Central
  • Firewall rules: Allow AP subnet to reach Activate and Central FQDNs
  • No NAT issues: If behind firewall, ensure proper routing

Step 1: Physical AP Installation

  • Power options:
    • PoE (Power over Ethernet): Simplest—use PoE+ (802.3at, 25W) or PoE++ (802.3bt, 60W+)
    • Local power adapter: If PoE not available
  • Mounting:
    • Indoor APs: Ceiling or wall mount (consult Aruba installation guides)
    • Outdoor APs: Weatherproof enclosures, grounding required
  • Network connection:
    • Plug Ethernet cable into AP and access layer switch
    • Ensure switch port is configured: Access or trunk mode, correct VLAN

Step 2: Verify DHCP Assignment

  • From your DHCP server, check for new leases
  • Note the IP address assigned to the AP (by MAC address)
  • If AP doesn't get DHCP:
    • Check switch port status (is it up?)
    • Verify DHCP scope has available IPs
    • Check VLAN configuration on switch port

Step 3: Watch the AP Join Central

  • In Aruba Central, go to "Manage" > "Devices" > "Access Points"
  • Set context filter to "All Devices" or your group
  • Wait 5-10 minutes (first boot takes longer)
  • AP should appear in the device list with status "Up"
  • If AP doesn't appear after 15 minutes, proceed to troubleshooting

Step 4: Verify AP Status and Configuration

  • Click on the AP name to open the device details page
  • Check key fields:
    • Status: Should be "Up" (green)
    • Group: Should match your intended group
    • Site: Should match your site (if already assigned)
    • IP Address: Matches DHCP lease
    • Firmware: Displays current AOS version
    • Uptime: Shows how long AP has been running

Step 5: Verify Configuration Sync

  • In the AP context, click "Audit Trail" from the left menu
  • Look for "Access Point Configuration sync successful"
  • This confirms AP received and applied group configuration
  • If sync failed, check error message in Audit Trail

Using Install Manager (For Multi-Site Deployments)

  • Install Manager simplifies deployments with on-site technicians
  • Setup:
    • In Central, go to "Organization" > "Install Manager"​
    • Click "Installers" tab
    • Click "+ Add" to add installer accounts
    • Enter technician details: Name, email, phone​
    • Assign installer to specific sites
  • Installer Mobile App:
    • Installer receives text with app download link (iOS/Android)​
    • App guides installer through: Scan AP barcode → Confirm location → Hang AP → Test signal​
    • AP auto-provisions and inherits group configuration​
  • Why use Install Manager: Non-technical staff can deploy APs without IT on-site​​

Manual Provisioning (Alternative to ZTP)

  • If ZTP isn't feasible (no internet, isolated network), use manual setup
  • Console access:
    • Connect via console cable (USB or serial)
    • Default credentials: Username varies, check docs
    • Run setup wizard or manual CLI commands
    • Configure static IP, Central IP/FQDN, AP-Central communication
  • When to use manual: Air-gapped networks, testing, troubleshooting

Troubleshooting AP Provisioning

IssuePossible CauseSolution
AP doesn't power onNo PoE, bad cable, insufficient powerCheck PoE switch capability; try local power adapter
AP gets IP but doesn't join CentralDNS resolution failureVerify DNS server in DHCP; test DNS from another device
AP joins Central but stays "Down"Firewall blocking CentralAllow HTTPS (TCP 443) to Central FQDN
"Configuration sync failed"Group misconfiguration, firmware mismatchCheck Audit Trail for error details; verify firmware version
AP appears in wrong groupMoved to default during provisioningManually move to correct group; check provisioning rules

Verifying Internet Connectivity from AP

  • From Central, select the AP
  • Go to "Analyze" > "Tools" > "Network Check"
  • Run Ping test to 8.8.8.8 or activate.arubanetworks.com
  • Run DNS test to verify resolution
  • This confirms AP has internet access and can reach Central

🧠 Lionel's Tip: ZTP in the Real World
🧠 I've deployed hundreds of APs via ZTP, and the #1 failure point is DNS. APs get DHCP but can't resolve activate.arubanetworks.com. Always test DNS from a laptop on the AP VLAN before shipping APs to remote sites. Also, firewall rules: Many customers forget to allow AP management VLAN outbound to Central. Document those FQDNs in your firewall change request upfront.

What We Accomplished
✅ Physically installed access points
✅ APs obtained DHCP addresses
✅ APs auto-joined Central via Zero-Touch Provisioning
✅ Verified AP status is "Up" and configuration synced
✅ (Optional) Set up Install Manager for future deployments
✅ Troubleshot common provisioning issues

Next Week: We'll configure radio profiles to optimize RF performance—channel selection, transmit power, band steering, and Adaptive Radio Management (ARM). Time to fine-tune the airwaves!

Explore More on Wireless Innovations

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *