DHCPv6 Auto-provisioning

DHCPv6 auto-provisioning is used to automate the process of network image upgrades and configuration updates.

Overview

DHCPv6 auto-provisioning is essential for environments where minimizing manual configuration and ensuring devices are always running the latest software and configurations are critical. The process leverages DHCPv6 options to specify the boot file URL and other configuration details, enabling zero-touch provisioning (ZTP).

Requirements

DHCPv6 auto-provisioning is supported for all ICX devices.

Considerations

This feature has the following considerations pertaining to feature enablement or usage:

  • Auto-provisioning is enabled by default.
  • DHCPv6 auto-provisioning supports both HTTPS and TFTP protocols for downloading the boot file.
  • DHCPv6 client auto-provisioning is not supported in stateless mode.
  • The device must authenticate the server before downloading the image via HTTPS. This can be done using a user certificate downloaded in an insecure fashion using the obtained IPv6 address.
  • DHCPv6 client supports zero-touch provisioning (ZTP), which allows clients to boot-up with the latest image and configuration without manual intervention.
  • The DHCPv6 client upgrades its application or boot images with the help of a manifest file in a specific order if the Boot File URL option (Option 59) is received from the DHCPv6 server.
  • The DHCPv6 client downloads the respective image from the manifest file to a flash location from which the device has booted. The flash location cannot be configured and will always be to the flash partition of the running image.
  • After downloading the manifest file via TFTP, the device unzips the file and compares the file name of the requested flash image with the images stored in flash memory. In a stacking configuration, the device compares the file name with the image stored in the Active Controller only
  • The image upgrade option is triggered only if the boot file selected is of a different image version than the image version that resides. When the router is updated and reboots, the configuration files are downloaded from the HTTPS or TFTP server and applied.

Best Practices

This feature has the following recommendations for feature enablement or usage:

  • Verify that the device can reach the DHCPv6 server and that the server’s certificate is valid if using HTTPS.
  • Regularly update the boot file and configuration files on the server to ensure devices are always running the latest versions.

Prerequisites

This feature has the following prerequisites to feature enablement or usage:

  • The boot file URL option (Option 59) must be configured on the DHCPv6 server. Refer to Configuring the Bootfile URL (Option 59) for the DHCPv6 Server for more information.
  • The device must have IPv6 enabled on the interface. Refer to the ipv6 enable command in the RUCKUS FastIron Command Reference for more information.
  • Ensure that the DHCPv6 client and server are compatible and correctly configured to communicate.