HPE Aruba Central, AP and CX Field Runbook
Aruba equipment can be physically healthy while appearing in the wrong Central group, inheriting unintended configuration or failing to provide usable client service. TechRunz aligns inventory, subscriptions, group architecture, switch and AP prerequisites, field installation and measured acceptance before the site is handed to operations.
Make each dispatch repeatable and recoverable
Define prerequisites, remote ownership, method of procedure, acceptance evidence and rollback before technicians arrive onsite.
Account, group and configuration readiness
Confirm device serials, customer account, subscriptions, Central group and site before shipping or installation. Identify whether the group uses UI configuration, templates or other approved orchestration, and determine which settings are inherited versus site-specific.
Review the AOS-CX and AP software plan, management addressing, DNS, NTP, certificates, VLANs, trunks, spanning tree, link aggregation, authentication and firewall dependencies. Record the approved startup or replacement path rather than allowing a factory-default device to join an uncertain group.
The remote team should supply the site identifier, approved design, equipment list, configuration status, contacts, access window and success criteria. The field technician verifies serials, labels, damage, accessories and prerequisites before changing production service.
- Authorized Central account
- Inventory, subscription and group
- Software and configuration baseline
- Network-service prerequisites
Switch and AP field installation
Rack and cable switches with clear member, uplink and power labels. For VSF or VSX designs, verify model support, member order, links and remote change sequence before joining production. Confirm transceivers, link speed, errors and PoE budget after the physical build.
Install APs at the scheduled coordinates using the approved mount and orientation. Reconcile each AP serial to room, cable and switch port. Confirm it receives the intended VLAN and power and appears in the correct Central site before moving to the next area.
Use a written method of procedure with hold points for configuration-sensitive actions. Photograph and label the before state, preserve known-good cabling or configuration, and keep a practical rollback path. Record deviations as they occur instead of reconstructing them after the visit.
- Switch member and uplink labels
- VSF or VSX verification
- AP serial, mount and cable mapping
- PoE and transceiver health
| Component | Field acceptance | Evidence |
|---|---|---|
| Central | Account, group, site and subscription | Inventory and health record |
| AOS-CX | Members, uplinks, VLANs, PoE and management | Port and topology checks |
| Access points | Location, cable, RF and client service | Annotated plan and tests |
| Operations | Alerts, software, recovery and ownership | Closeout package |
Client, RF and resilience validation
Test management reachability, gateway and routing behavior, DHCP, DNS, authentication and required application paths. Use representative wired and wireless clients and verify the intended SSID, role or policy rather than accepting association alone.
Review radio state, channel and power behavior after the network has stabilized. Test roaming on defined paths and approved switch, uplink or power recovery scenarios. Capture Central alerts and event timelines when results differ from the design so remote engineers can reproduce the condition.
Validation must cover physical status, management visibility, addressing, uplinks, power, policies and representative user traffic. When redundancy is expected, test the approved failure and restoration scenarios. Escalations should include timestamps, identifiers and reproducible evidence.
- Identity, DHCP and DNS
- Representative client workflows
- RF and roaming checks
- Approved failure and recovery tests
Central records and operational handoff
Reconcile Central inventory, group, site, labels and subscription status with installed serials and annotated plans. Record AOS-CX switch names, member positions, management addresses, uplinks, AP ports, software versions and outstanding alerts.
Deliver protected configuration and recovery records to the client-controlled repository. Name the team responsible for Central administration, software policy, certificate lifecycle, alert response and support entitlement. Temporary credentials and private configuration output should not appear in general field reports.
Closeout combines annotated photographs, serials, port and cable records, software versions, test output, exceptions and ownership. Credentials and private configurations belong in the client-controlled repository, while public pages should point only to official manufacturer support resources.
- Central inventory reconciliation
- Software and topology records
- Alerts, exceptions and ownership
- Protected recovery information
How we plan and deliver the work
The final design depends on site conditions, existing systems, client policies and the selected manufacturer or platform.
Prepare
Confirm access, equipment, remote readiness and rollback.
Execute
Install through the approved method and document deviations.
Test
Validate management, service, resilience and user workflows.
Close
Deliver evidence, inventory, exceptions and support ownership.
Information to gather before design
Good decisions are easier when the project team starts with complete operational and technical information. The following items help reduce assumptions, change orders and avoidable return visits.
- Site access and remote contacts
- Staging, inventory and prerequisites
- Method, maintenance window and rollback
- Acceptance tests and escalation
- Evidence and operational ownership
Frequently asked questions
These are common planning questions. A site-specific answer should be confirmed during discovery and design.
Why verify the Central group before an AP or switch connects?
Group assignment can control inherited configuration; an incorrect group can produce an avoidable outage or rework.
Is an AP healthy when Central shows it online?
Online status is necessary but not sufficient. Validate switch port, power, RF, authentication, addressing and representative applications.
Should VSF or VSX changes be improvised onsite?
No. Member order, supported topology and recovery should be reviewed in an approved method before production changes.
What should operations receive?
Central and device inventory, topology, ports, software, tests, alerts, exceptions, recovery records and named ownership.
Manufacturer software, firmware and technical files remain on the manufacturer’s official website. We do not mirror firmware files locally.
Build a repeatable field-deployment plan
Provide the site list, target schedule, equipment responsibility, change-window constraints and acceptance criteria. We will help turn them into a practical rollout and closeout workflow.