Cloud Managed Networks

 View Only
  • 1.  HP 2530 - non-authenticated EST enrollment

    Posted Aug 04, 2020 10:19 AM

    Hello !

     

    I have a problem to connect my HPe/Aruba 2530-24G J9776A in Aruba Central, I don't know how to fix that...

     

    I added MAC+S/N in Aruba Central (and enable subscription) but nothing work...

     

    my error is: EST enrollment has failed with status code : non-authenticated

     

    if someone can help me, I wont refuse,

    Regards.

     

    ---

     

    My version :

     

    HP-2530-24G(config)# show version
    
    Image stamp:
     /ws/swbuildm/rel_ajanta_qaoff/code/build/lakes(swbuildm_rel_ajanta_qaoff_rel_aj
    anta)
                    Jun 26 2020 00:30:07
                    YA.16.10.0009
                    294
    Boot Image:     Primary
    
    Boot ROM Version:    YA.15.20

     

     

     

    My running-config :

     

    HP-2530-24G(config)# show run
    
    Running configuration:
    
    ; J9776A Configuration Editor; Created on release #YA.16.10.0009
    ; Ver #14:41.44.00.04.19.02.13.98.82.34.61.18.28.f3.84.9c.63.ff.37.27:05
    hostname "HP-2530-24G"
    password manager user-name "admin" sha1
     "d033e22ae348aeb5660fc2140aec35850c4da997"
    timesync ntp
    ntp unicast
    ntp server-name "0.pool.ntp.org" iburst
    ntp server-name "1.pool.ntp.org" iburst
    ntp server-name "2.pool.ntp.org" iburst
    ntp enable
    time daylight-time-rule western-europe
    time timezone 60
    web-management ssl
    ip dns server-address priority 1 1.1.1.1
    ip dns server-address priority 2 80.80.80.80
    snmp-server community "public"
    snmpv3 engineid "00:00:00:0b:00:00:80:c1:6e:cf:b5:e0"
    vlan 1
       name "DEFAULT_VLAN"
       untagged 1-28
       ip address dhcp-bootp
       exit
    spanning-tree

     

     

     

    I have network connexion and I ping aruba server :

     

    HP-2530-24G(config)# ping arubanetworks.com
    arubanetworks.com is alive, time = 87 ms

     

     

     

    but same if I force my provision, the status is always like this....

     

    HP-2530-24G(config)# show activate provision
    
     Configuration and Status - Activate Provision Service
    
      Activate Provision Service   : Enabled
      Activate Server Address      : devices-v2.arubanetworks.com
      Activation Key               : Not Available
      Time Sync Status             : Time sync from other source
      Activate DNS Lookup          : Success
      Proxy Server DNS Lookup      : NA
      Activate Connection Status   : Failure
      Error Reason                 : EST enrollment has failed with status code :
     non-authenticated

     


    #2530


  • 2.  RE: HP 2530 - non-authenticated EST enrollment

    Posted Sep 24, 2020 09:32 PM

    This is specific to the 2530, as this model does not have a TPM chip.

     

    You need to have the switch in Activate, but then TAC needs to manually whitelist the serial as well. Once that is complete, unsubscribe / re-subscribe your switch and it should show up. 



  • 3.  RE: HP 2530 - non-authenticated EST enrollment

    Posted Jan 20, 2022 10:30 AM
    Hello,

    I have the same issue with 2530 YA.16.11.0003 software revision.

    Can you please explain the procedure .

    what do you meen by "but then TAC needs to manually whitelist the serial as well" where can I white list my switch ?

    Regards


    ------------------------------
    Benoit DAVID
    ------------------------------



  • 4.  RE: HP 2530 - non-authenticated EST enrollment

    Posted Jan 20, 2022 05:43 PM
    Please reach out to Aruba support and describe this issue, they will have access to Activate service and will authorise the switch manually since this old switch does not have a TPM to automatically authenticate.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------