Installing the ClearPass 6.11 ISO Image

This section describes how to install the ClearPass 6.11.0 ISO image on a hardware appliance. A video recording of these re-installation procedures, ClearPass 6.11 Installation on Hardware Appliances, is also available on the Airheads Broadcasting channel.

This section includes:

* Converting the ISO to a Bootable USB Drive
* Setting the Boot Order Prior to Installation
* Installing the 6.11.1 Image on the Hardware Appliance
* Changing the BIOS TPM Configuration to TPM 2.0

Converting the ISO to a Bootable USB Drive

Many commercial or free/open source tools exist for converting an ISO to a Bootable USB drive. HPE Aruba Networking recommends the use of whatever tool you are most familiar with or that is supported within your organization to complete this task. The following steps illustrating the process use the Balena Etcher™ tool on macOS client systems as an example.

1. Download the executable for the operating system you want (for example, macOS, Windows, or Linux).
2. Install the executable. The Etcher interface displays the following:

3. Select Flash from file. An option is displayed to navigate to your computer and select the ISO that needs to be made bootable.

4. Select the USB target that should be plugged into the computer.

5. After the target is selected, select the Flash! button to make the ISO bootable2.

6. Set the root or admin privileges to start the writing process.

7. Flash the ISO to the USB drive to start and to view the progress bar.

8. After the write process is complete, the wizard validates the written USB disk.

9. After the validation process is complete, a Flash completion message is displayed and the disk is ready to use.

Setting the Boot Order Prior to Installation

This section describes how to set the boot order for the C3010, C2010, C3000, and C2000 ClearPass hardware appliances.

C3010 – HPE ProLiant DL360 Gen10, and C2010 – HPE Proliant DL20 Gen10

To change the Boot mode from Legacy BIOS to UEFI for a C3010 or C2010 appliance:

1. Connect the monitor, keyboard, and mouse to the server.
2. Power on the unit and press the F9 key to stop the server at System Utilities when prompted.
3. On the the System Utilities screen, select System Configuration.
4. On the the System Configuration screen, select BIOS/Platform Configuration (RBSU).
5. On the BIOS/Platform configuration (RBSU) screen, select Boot Options.
6. Set the Boot Mode to UEFI. A warning message is displayed. Click OK.

7. Change the Boot Mode from Legacy BIOS Mode to UEFI.

8. After the Boot mode is changed, an Information message prompts for a reboot. Press the F12 key to save and exit, and then reboot the server.

9. After the reboot, the Boot Mode is displayed as UEFI.

C3000 HPE ProLiant Gen9, and C2000 HPE ProLiant Gen9

To change the Boot mode from Legacy BIOS to UEFI for a C3000 or C2000 appliance:

1. Connect the monitor, keyboard, and mouse to the server.
2. Power on the unit and press the F9 key to stop the server at System Utilities when prompted.
3. On the System Utilities screen, select System Configuration.

4. On the System Configuration screen, select BIOS/Platform Configuration (RBSU).
5. On the BIOS/Platform configuration (RBSU) screen, select Boot Options.

6. Select Legacy BIOS Mode, and then click Enter.

7. A warning message is displayed stating that a system reboot is required for the changes to take effect.

8. Select UEFI Mode.

9. Press the F10 key and reboot the server.

Changing the Boot Mode on a C1000 Appliance

 

 

Of the three available boot modes (UEFI, LEGACY, and DUAL), only UEFI is supported with ClearPass 6.11.

To change the boot mode to UEFI for a C1000 appliance:

1. Reboot the server. While booting, press the Delete button.

 

 

The options only display for a few seconds.

2. Navigate to the Boot menu. On the Boot Mode Select window, select UEFI.

3. Press the F4 key to save and exit the configuration.

Installing the 6.11.1 Image on the Hardware Appliance

There are multiple ways to install the ClearPass 6.11.1 image on a hardware appliance:

* Install using a bootable ISO image (applicable to all models)
* Install using a DVD with 6.11.1 image (applicable to all models)
* Install using an ISO image mounted on an iLO card (not applicable on C1000, C2000, or C2010 models)

Before proceeding with the installation:

* Take a complete backup of the current ClearPass 6.9.X or 6.10.X image and save it for future restoration. For complete backup information, see Installation Process for 6.11 .
* For C1000 models, the monitor, keyboard, and mouse must be connected before starting the installation, as there is no iLO or remote console support on C1000 models.

 

 

Although the bootable ISO and DVD option installation options are available to all models, these instructions use the C1000 model as an example.

Installing via iLO  

 

 

Installation via iLO is not available for C1000, C2000, or C2010 appliances.

1. In this mode, the ClearPass ISO image can be placed in a shared network location and the "virtual media URL" option can be selected in the iLO.

2. Provide the URL to the ClearPass image file and then click Connect.

3. Reboot the server.
4. Press the F11 key to open the Boot Menu and enter the boot order.
5. Select iLO Virtual USB 2 : HPE iLO Virtual USB CD/DVD ROM, and then click Enter to boot the system.

6. After the reboot is complete, select the platform to install – for example, to install a C1000, select the model from the list.

Selecting the Boot Order to Boot from USB

To set the boot mode to boot from a defined USB device:

1. Plug in the bootable USB device with the 6.11.1 image. For more information, see Converting the ISO to a Bootable USB Drive.
2. Press the F11 key on the BIOS screen, and then if you are booting from a USB, select boot from USB. If you are booting from a DVD, select boot from DVD instead.

3. After the USB device is selected (manufacturer may vary), click Enter and attempt booting.

4. The wizard will prompt for the hardware model. Select the correct model and click Enter.

The installation begins. It should take approximately one hour to complete the installation of the 6.11.1 image on the selected hardware model.

5. After installation is complete, the software version, Management IP Address, and system model are displayed along with the login prompt. Review the image version for accuracy.

6. Log in with the username appadmin and a default password provided by HPE Aruba Networking's Technical Assistance Center (TAC).
7. Follow the wizard prompts to provide the IP address, gateway, hostname, and other requested information such as location and time zone.

Changing the BIOS TPM Configuration to TPM 2.0

If you are on a C2010 (HPE Proliant DL Gen10) or a C3010 (HPE Proliant DL 360 Gen10 ) server, then as part of the ClearPass 6.11 installation you must convert the TPM version to TPM 2.0. This only applies to the C2010 and C3010; it does not apply to other appliance types.

1. From the BIOS Settings (press the F9 key during boot to go to BIOS), go to the System utilities > System configuration > BIOS/Platform configuration (RBSU) > Server Security page.

2. Select Trusted Platform Module Options. The page for choosing the TPM options is displayed.

3. In the TPM Mode Switch Operation drop-down list select TPM 2.0.

4. Press the F10 key to save the configuration, and then press the F12 key to save and exit.