11.2 Zero-Touch Provisioning (ZTP) and Aruba Activate
Key Takeaways
Zero-Touch Provisioning (ZTP) enables factory-default Aruba CX switches and APs to automatically acquire IP addressing, discover their management platform, download firmware, and receive production configurations without manual console staging.
Aruba Activate operates as the authoritative cloud redirector, maintaining a global registry of hardware serial numbers and MAC addresses linked to customer accounts, directing newly connected devices to their designated Aruba Central cluster.
Without the cloud, AOS-CX ZTP uses DHCP: option 43 sub-options 144 (configuration file), 145 (firmware image), 146 (on-premises Central server), and 148 (HTTP proxy), plus options 66 and 67 for TFTP.
The standard ZTP discovery workflow initiates with DHCP address acquisition, checks local DHCP vendor options, contacts Aruba Activate over outbound HTTPS (TCP port 443), and establishes a secure mutual TLS WebSocket (WSS) tunnel to Aruba Central.
Successful cloud ZTP requires three critical network prerequisites: outbound reachability to the Internet on TCP port 443, reliable DNS resolution for Activate and Central FQDNs, and accurate NTP time synchronization (UDP port 123) for TLS certificate validation.
Zero-Touch Provisioning (ZTP) and Aruba Activate
Quick Summary: Zero-Touch Provisioning (ZTP) automates the deployment of campus network infrastructure by eliminating manual console cabling, USB staging, and on-site engineering intervention. When a factory-default Aruba CX switch or AP powers on and connects to the network, it acquires an IP address via DHCP and contacts Aruba Activate, a cloud-based redirection service that maps the device's hardware identity to the customer's Aruba Central account. The device then establishes a secure WebSocket connection to Central, downloads its target firmware, and applies its group configuration automatically.
The Mechanics of Zero-Touch Provisioning (ZTP)
In traditional campus deployments, staging access switches and access points was labor-intensive. Network engineers had to unpack hardware in a staging lab, connect serial console cables, manually configure management IP addresses and hostnames, update firmware via TFTP or USB flash drives, and repackage the devices for shipping to remote sites. This model resulted in high operational costs, lengthy deployment schedules, and potential configuration drift.
Zero-Touch Provisioning (ZTP) fundamentally transforms this workflow:
- Hardware is shipped directly from the factory or distributor to the target campus or branch location.
- Non-technical field personnel physically mount the switch into the rack or install the AP on the ceiling and connect an Ethernet cable to an uplink port.
- Upon powering on, the device detects that it possesses a factory-default configuration and automatically initiates the ZTP onboarding state machine.
- Within minutes, the device connects to the cloud, updates its operating system, applies production security and VLAN configurations, and begins forwarding traffic—all without an engineer ever touching the local CLI.
The Factory-Default State
To participate in ZTP, an Aruba CX switch must be in its factory-default state:
- Management Interface (OOBM): The dedicated out-of-band management port is enabled by default as a DHCP client.
- Data Ports (VLAN 1): By default, all front-panel switch ports belong to VLAN 1 (the default VLAN) as untagged access ports, and an internal SVI for VLAN 1 is configured as a DHCP client.
- Default Credentials: The switch boots with the default
adminusername and no password. When Central provisions the switch, the configuration it pushes sets the administrator credentials. - Factory Device Identity: Aruba devices ship with a factory-installed device certificate (many models keep it in a Trusted Platform Module), giving each device a hardware-rooted identity that the cloud services can authenticate.
Aruba Activate: The Cloud Redirector Architecture
Aruba Activate is a globally distributed cloud redirector hosted by HPE Aruba Networking. It acts as an authoritative matchmaking service between newly powered-on hardware and customer management platforms.
Key functions of Aruba Activate include:
- Manufacturing Ledger: When an Aruba CX switch or AP is manufactured, its Serial Number, MAC Address, and public key certificate are permanently cataloged in the Activate global database.
- GreenLake Account Binding: When an organization purchases Aruba hardware, the ordering system automatically links the purchased serial numbers to the customer's HPE GreenLake and Aruba Central account workspace.
- Provisioning Rules: Within Aruba Activate, provisioning rules determine where a connecting device is redirected. The default rule directs the device to the customer's regional Aruba Central cluster (e.g.,
app1-eu.central.arubanetworks.comorapp-uswest4.central.arubanetworks.com). - Alternative Redirection Targets: For enterprise environments utilizing on-premises management, Activate rules can be configured to redirect devices to an on-premises Central cluster, an AirWave management server, or an on-premises mobility controller cluster.
The End-to-End ZTP Discovery and Connection Sequence
When a factory-default Aruba CX switch powers on and connects to an active network uplink, it executes a deterministic discovery sequence:
+-----------------------------------------------------------------------+
| 1. Physical Boot & DHCP Request (Option 60 VCI sent) |
| - Switch requests IP on OOBM and VLAN 1 |
+-----------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------+
| 2. Evaluate Local DHCP Options in DHCP ACK |
| - If DHCP Option 43 is present -> Connect directly to local server |
| - If DHCP Option 43 is ABSENT -> Proceed to Cloud Redirection |
+-----------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------+
| 3. Cloud Redirection via Aruba Activate (Port 443 HTTPS) |
| - Resolve activate.arubanetworks.com via DNS |
| - Authenticate using hardware TPM certificate |
| - Receive Central regional cluster FQDN and account credentials |
+-----------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------+
| 4. Mutual TLS & WebSocket Connection to Aruba Central (Port 443 WSS) |
| - Establish persistent WebSocket tunnel |
| - Central matches Serial/MAC to customer inventory |
+-----------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------+
| 5. Firmware Compliance & Configuration Synchronization |
| - Check Group firmware baseline -> Update OS and reboot if needed |
| - Push Group configuration + local variables -> Device "In Sync" |
+-----------------------------------------------------------------------+
Step-by-Step Sequence Details
- IP Addressing via DHCP: The switch broadcasts a DHCP Discover packet on both its out-of-band management port and front-panel VLAN 1 ports. In this request, the switch includes DHCP Option 60 (Vendor Class Identifier) containing
Arubafollowed by the model, which you can display withshow dhcp client vendor-class-identifier. - Local ZTP Options: The switch inspects the DHCP response. If it contains ZTP options (option 43 sub-options 144/145 or options 66/67), the switch downloads its configuration and firmware from the TFTP server; option 43 sub-option 146 points it to an on-premises Central server, and sub-option 148 supplies an HTTP proxy.
- Activate Resolution & Mutual TLS Handshake: If Option 43 is not provided, the switch uses its acquired DNS server to resolve
activate.arubanetworks.comand opens an outbound HTTPS connection over TCP port 443. The switch presents its factory TPM certificate. Activate validates the certificate, looks up the device serial number in its database, and returns the FQDN of the customer's Aruba Central regional cluster. - Aruba Central WebSocket Tunnel (WSS): The switch connects to the assigned Aruba Central cluster over outbound HTTPS/WSS (WebSocket Secure, TCP port 443). The switch validates Central's server certificate, and Central authenticates the switch's hardware identity. This persistent, bidirectional WebSocket tunnel remains open for all ongoing management, telemetry, and control traffic.
- Firmware and Configuration Deployment: Once connected, Central checks whether the device is licensed and assigned to a Group. If the Group specifies a target firmware baseline that differs from the switch's current operating system, Central pushes the new AOS-CX image. The switch writes the image to the secondary flash partition, reboots, reconnects to Central, and downloads its production configuration.
DHCP-Based Provisioning: Option 60 and Option 43
While cloud-based ZTP via Aruba Activate is the standard for modern enterprise deployments, organizations operating in air-gapped environments or private data centers rely on DHCP-based redirection.
DHCP Option 60 (Vendor Class Identifier - VCI)
Option 60 is transmitted by the client (the switch or AP) in its initial DHCP Discover packet. It informs the DHCP server of the device's vendor and platform type:
- AOS-CX switches send
Arubafollowed by the model information (shown byshow dhcp client vendor-class-identifier). - Aruba APs send
ArubaAP(controller-based campus APs) orArubaInstantAP(Instant APs). - By matching Option 60 strings, enterprise DHCP servers (such as Microsoft DHCP, Infoblox, or Linux ISC-DHCP) can conditionally supply tailored vendor options exclusively to Aruba hardware while delivering standard IP configurations to generic client PCs.
DHCP Option 43 (Vendor-Specific Information)
Option 43 is returned by the DHCP server in its DHCP Offer and ACK packets. When the switch receives Option 43, it parses the vendor-specific sub-options to determine its provisioning endpoint:
- AOS-CX switches (AOS-CX 10.14 Fundamentals Guide): sub-option 144 = configuration file name, 145 = firmware image file name, 146 = FQDN or IPv4 address of an on-premises Central server, 148 = FQDN or IPv4 address of an HTTP proxy. Option 66 supplies the TFTP server IPv4 address and option 67 the configuration file name (sub-option 144 takes precedence).
- Controller-based (AOS 8) campus APs: option 43 carries the Mobility Controller IP address.
- Instant APs (AOS 8): option 43 can carry AirWave details in the form organization, AirWave IP, shared key.
| DHCP Option | Direction | Purpose | Example Value |
|---|---|---|---|
| Option 60 (VCI) | Client to Server | Identifies hardware/OS family to the DHCP server | Aruba <model> (AOS-CX), ArubaAP, ArubaInstantAP |
| Option 43 | Server to Client | Supplies vendor parameters | AOS-CX sub-options 144/145/146/148; controller IP for campus APs |
| Options 66 / 67 | Server to Client | TFTP server IPv4 address and configuration file name for AOS-CX ZTP | 192.0.2.10, access-sw.cfg |
Network and Firewall Prerequisites for Cloud ZTP
For cloud-based ZTP to complete successfully through Aruba Activate and Aruba Central, the local network and perimeter firewalls must satisfy three essential requirements:
1. Outbound Port Access (No Inbound Ports Required!)
All communication between the switch, Activate, and Central is initiated outbound from the switch. Perimeter firewalls do not require any inbound port forwarding. The required outbound ports are:
- TCP Port 443 (HTTPS / WSS): Required for outbound web traffic to
activate.arubanetworks.comand*.central.arubanetworks.comfor registration, firmware download, and establishing the persistent WebSocket tunnel. - UDP Port 123 (NTP): Required for Network Time Protocol synchronization with public or internal time servers.
- UDP Port 53 (DNS): Required for Domain Name System queries to resolve public cloud hostnames.
2. Accurate Time Synchronization via NTP (Critical!)
The most frequent cause of ZTP onboarding failure in enterprise environments is blocked NTP (UDP port 123). Modern cloud security relies on mutual Transport Layer Security (mTLS). When the switch establishes an HTTPS session with Activate or Central, it must validate the digital certificate presented by the cloud server against its built-in trust store.
- Digital certificates contain strict Not Before and Not After validity timestamps.
- If the switch boots with a default factory hardware clock (e.g., set to January 1, 1970) because NTP traffic is blocked by an upstream firewall, the switch evaluates the cloud certificate as expired or not yet valid.
- As a result, the TLS handshake is aborted, and ZTP stalls indefinitely.
3. DNS Resolution
The switch must receive valid DNS server addresses via DHCP Option 6. It must be capable of resolving the fully qualified domain names for Activate and the regional Central clusters. If DNS queries fail, the switch cannot locate the cloud services.
Troubleshooting ZTP and Fallback Behavior
If a switch fails to connect to Central or Activate, it does not lock up; rather, it enters a periodic retry cycle:
- The switch periodically rebroadcasts DHCP requests and attempts Activate connections at expanding backoff intervals.
- The local serial console port remains functional. An administrator can plug in a console cable and run
show ztp information(the options offered by the DHCP server and the ZTP status) andshow aruba-central(the Central connection state).
Exam Trap Alert: AOS-CX ZTP starts automatically on a factory-default switch and stays active only until the running configuration is modified (AOS-CX 10.14 Fundamentals Guide). If a technician configures the switch locally before ZTP finishes, ZTP stops. To start over, return the switch to factory defaults (for example with
erase all zeroize).
What is the primary architectural function of Aruba Activate during the Zero-Touch Provisioning (ZTP) of an out-of-the-box Aruba CX switch?
It is a cloud redirector that recognizes the device's serial number and points it to its Central instance
It compiles CSV variable files into configuration templates and pushes them straight to local flash storage
It hands out dynamic IP address leases and default gateway information on the local management subnet
It acts as an inline cryptographic proxy that decrypts all user payload traffic leaving the campus
An enterprise network engineer is configuring an on-premises DHCP server to support automated provisioning of Aruba CX switches in a restricted, air-gapped network where outbound Internet access to Aruba Activate is completely prohibited. Which two DHCP options must be implemented on the DHCP server?
Option 3 (Router) and option 6 (DNS Servers) so that the switch can reach the Activate cloud
Option 51 (Lease Time) and option 12 (Host Name) to name each switch during its first boot
Option 60 (vendor class) to match Aruba switches, and option 43 (vendor-specific information)
Option 82 (Relay Agent Information) and option 15 (Domain Name) for the switch management VLAN
A network technician installs a brand new, factory-default Aruba CX 6200 switch in a remote branch office. The switch receives an IP address, default gateway, and DNS servers from the local DHCP server. However, the switch fails to establish communication with Aruba Activate or Aruba Central. Network logs show that outbound TCP port 443 is permitted through the firewall, but outbound UDP port 123 is blocked. Why does this firewall configuration cause ZTP onboarding to fail?
Aruba Activate requires UDP port 123 to deliver the customer's cloud activation key and group assignment parameters
DNS name resolution cannot function on AOS-CX switches unless UDP port 123 is active on the default VLAN
The switch operating system halts the network interface daemon if system time is not acquired within 120 seconds of boot
The switch cannot synchronize its system clock via NTP, causing mutual TLS certificate validation against Activate and Central to fail
Sections you finish are checked off in the contents.