Since f35b59e a CLI poll reports trunk members as `3` with
trunk_group `Trk3`, but `show interfaces brief` has no line for Trk3
itself, so the trunk was missing from the interface list. The REST path
built that row on its own.
Both paths now use napalm_device_types.add_lag_interfaces, and the REST
path's copy is gone. One visible change there: `lag_members` is now in
port order (7, 10) instead of API order; the description already was.
The CLI path does not know the mode yet, so its trunks carry no
lag_mode. That needs `show trunks`, whose output is not at hand.
Needs napalm-device-types f3fa75b.
Closes#5
A 2800-series switch on J.15.09 polled over CLI came back with no
interfaces and an empty OS version, while VLANs and ARP parsed fine.
`show interfaces brief` on that firmware has an Intrusion Alert column
between the `|` and Enabled, and puts Mode before MDI rather than after:
Port Type | Alert Enabled Status Mode Mode ...
3-Trk3 100/1000T | No Yes Down 1000FDx MDI ...
The regex read Alert as Enabled, then failed on Yes where it wanted
Up|Down, so no line matched. It now skips the Alert column where there is
one and takes the speed from either position. Trunk members are listed as
`<port>-Trk<n>`; the port is `<port>` and the suffix becomes its
trunk_group, so the per-port `show interfaces 3` is a command the switch
knows.
The empty OS version was the alternatives list in _send_command. It moved
to the next command on "% Invalid" or "Error", but ProCurve rejects an
unknown command with "Invalid input: system-information" -- so that line
was parsed as system information. "Invalid input" now counts as failure.
Getting there took longer than it should have, because the first symptom
was "Authentication failed: Login failed". That was Telnet's error, the
last transport tried; the REST probe and both SSH attempts had failed
before it and said nothing above debug level. In fact the switch had run
out of CLI sessions and closed SSH straight after the password. open()
now records why each transport failed, and both the auth error and the
final "Cannot connect" carry that list.
Fixtures are that switch's output, with hostname, serial and MAC
replaced.
Closes#2Closes#3Closes#4
set_interface() always POSTed to vlans-ports, treating every membership as
new. Moving a port that already carries the VLAN from untagged to tagged is
not a create, though, and the switch says so:
POST vlans-ports {"vlan_id":10,"port_id":"10","port_mode":"POM_TAGGED_STATIC"}
-> 400 {"message":"Association exists"}
Only 409 was handled as "already there"; v7 firmware answers 400. The
membership is its own resource named {vlan_id}-{port_id} and takes a PUT:
PUT vlans-ports/10-10 -> 200
So the exact case anyone hits first failed outright — a port holding VLAN 10
untagged alongside 30/40/50 tagged, with VLAN 10 to become tagged too.
The response body is now carried into both error messages. The ports PUT just
above already did this; here it was dropped, so "Association exists" — which
names the cause outright — never reached the caller. The message read
"vlans-ports POST HTTP 400" and nothing more.
Verified against a 2530-24G-PoEP on REST v7: set_interface("10", trunk
vlan 30), where that membership already exists, now completes and leaves the
port exactly as it was.
HP ProCurve needs invoke_shell (not exec_channel) — exec_command via
paramiko returns 'SSH command execution is not supported'. Netmiko's
hp_procurve device type handles this correctly. Port 22 explicit.
In API transport mode, self.port = 443 (HTTPS). All SSH attempts were
connecting to port 443 which speaks TLS, not SSH — hence 'banner exchange
timed out'. Fix: hardcode port 22 for the SSH config fallback.
paramiko 4.x is incompatible with Mocana SSH 6.3 on HP 2530/YA firmware.
OpenSSH subprocess with +diffie-hellman-group1-sha1 kex works correctly
and connects in < 5s instead of hitting the 15s banner timeout.
HP ProCurve switches allow only 1 session per user. The REST API session
blocks SSH — closing it before the SSH attempt allows the connection.
_collect_config() is called last so all poll data is already collected.
The SSH console link works on this switch using plain paramiko
SSHClient.connect() with no disabled_algorithms and no Transport hacks.
Our previous approaches (Transport._preferred_kex, socket-level timeout)
were breaking the negotiation. Revert to the simple approach that works.
paramiko banner_timeout/auth_timeout do not cover kex negotiation.
Using raw socket with settimeout(8) ensures the entire SSH handshake
is bounded, preventing the poll from hanging and timing out.
- Replace netmiko with direct paramiko connection for SSH config fallback
- Explicitly set preferred_kex to include diffie-hellman-group1-sha1
(required by old Mocana SSH 6.3 on HP 2530 / YA firmware)
- Hard timeout caps: banner_timeout=auth_timeout=8s, no keys/agent
Each SSH attempt was using driver timeout (30s). With 2 attempts that
consumed the entire poll budget → device marked OFFLINE. Now capped at
8s per attempt (max 16s total), well within the 30s poll limit.
HP 2530 switches with YA firmware do not expose /rest/v7/running-config.
_get_config_via_ssh() opens a temporary netmiko session to run
'show running-config' as fallback when the API endpoint returns 404.
AOS-Switch returns the config body as text/plain, not JSON.
The previous get_config() called self.get() which calls resp.json(),
silently caught the JSONDecodeError, and returned ''. Now uses _get_text()
which reads resp.text directly.
Firmware J.15.x (2520G-8-PoE) only supports 'show system', not
'show system-information'. Adding it as the third fallback so serial
number and OS version can still be parsed via parse_system_info().
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Old ProCurve show version starts with "Image stamp:" — the HP product
banner (e.g. "HP J9298A Switch 2520G-8-PoE") appears on a later line.
Scan all lines and use the first HP/HPE/Aruba banner found.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Guard against show version outputs that start with "Image stamp:" or
other non-banner lines — return ("", "") when the first line doesn't
begin with HP/HPE/Aruba.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
api_client.get_facts() now applies the same J-code extraction as the
CLI path: product_model "HP2530-8G Switch(J9777A)" → model="HP2530-8G
Switch", part_number="J9777A".
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
parse_system_info() now extracts HPE/HP J-codes (e.g. J9298A, J9777A)
from the System Model field and returns them as part_number separately.
The model name is cleaned of the J-code and surrounding punctuation:
"HP J9298A Switch 2520G-8-PoE" → model="HP 2520G-8-PoE Switch", pn="J9298A"
"HP2530-8G Switch(J9777A)" → model="HP2530-8G Switch", pn="J9777A"
get_facts() includes part_number in the returned dict so NetOrk can
store it on Device.part_number and pass it to NetBox device types.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Raw MAC addresses from the ArubaOS-Switch API use a non-standard
format; normalize via napalm.base.helpers.mac() for consistency.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
get_interfaces() now fills in ports missing from the /ports collection
(e.g. the 4th SFP uplink on a 2530-48G) using system/status/switch, and
synthesizes a logical interface for each configured LAG/trunk group with
lag_members/lag_mode. New set_lag_members() adds/removes trunk members via
the REST /cli passthrough (PUT ports/{id} silently ignores trunk_group).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds get_poe_status()/set_poe() to expose per-port PoE configuration
(enable state, priority, allocation method, allocated power) and allow
toggling it via the AOS-Switch REST API.
connect() never sent back the sessionId returned in the login response
body, so all writes (POST/PUT/DELETE) were silently rejected with
"Access is unauthorized" while reads worked fine. Also fix
_api_set_vlan to PUT the full VLAN object (AOS-Switch v3 rejects
partial PUT bodies with HTTP 400).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Extracted _netmiko_kwargs() helper that strips port/timeout/disabled_algorithms
from netmiko_optional_args before spreading, so explicit values always win.
Used in both _try_ssh and _action_fix_snmp SSH fallback loop.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The REST API has no writable config endpoint for SNMP communities.
When _action_fix_snmp() is called on a REST-connected driver, it now
opens a temporary Netmiko SSH session (standard KEX, then legacy KEX
fallback), runs the config-mode CLI commands, and restores the REST
transport state on exit. SSH errors are surfaced verbatim instead of
being silently swallowed.
Also:
- _save_config: guard against REST transport (was calling self._device
directly → NoneType AttributeError when transport == "api")
- _action_fix_snmp: extracted CLI logic into _action_fix_snmp_cli()
so it is reused for both the SSH-fallback and native SSH/Telnet paths
- api_client: add get_snmp_communities() + configure_snmp_community()
for future use; improve GET error logging (warn vs debug on non-404)
- _try_api: probe timeout capped at 15 s; SSL retry loop for
self-signed certificates; improved log levels
- _api_set_interface / _cli_set_interface: handle enabled/description
fields that were previously ignored
- probe(): broaden accepted status codes (301/302/303/403)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Implements SNMP health collection for ProCurve/Aruba switches using
HP-proprietary CPU/memory/uptime OIDs with IF-MIB interface counters.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Mirrors the robust fallback pattern from napalm-opnsense so the driver
works regardless of which key name the caller passes in optional_args.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
get_snmp_config() uses single 'show snmp-server' command with read_timeout=10
to avoid blocking the poll. fix_snmp configures 'snmp-server community public
manager restricted'. get_device_warnings() added (was missing, caused AttributeError).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>