The SSH console link works on this switch using plain paramiko
SSHClient.connect() with no disabled_algorithms and no Transport hacks.
Our previous approaches (Transport._preferred_kex, socket-level timeout)
were breaking the negotiation. Revert to the simple approach that works.
paramiko banner_timeout/auth_timeout do not cover kex negotiation.
Using raw socket with settimeout(8) ensures the entire SSH handshake
is bounded, preventing the poll from hanging and timing out.
- Replace netmiko with direct paramiko connection for SSH config fallback
- Explicitly set preferred_kex to include diffie-hellman-group1-sha1
(required by old Mocana SSH 6.3 on HP 2530 / YA firmware)
- Hard timeout caps: banner_timeout=auth_timeout=8s, no keys/agent
Each SSH attempt was using driver timeout (30s). With 2 attempts that
consumed the entire poll budget → device marked OFFLINE. Now capped at
8s per attempt (max 16s total), well within the 30s poll limit.
HP 2530 switches with YA firmware do not expose /rest/v7/running-config.
_get_config_via_ssh() opens a temporary netmiko session to run
'show running-config' as fallback when the API endpoint returns 404.
Firmware J.15.x (2520G-8-PoE) only supports 'show system', not
'show system-information'. Adding it as the third fallback so serial
number and OS version can still be parsed via parse_system_info().
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
parse_system_info() now extracts HPE/HP J-codes (e.g. J9298A, J9777A)
from the System Model field and returns them as part_number separately.
The model name is cleaned of the J-code and surrounding punctuation:
"HP J9298A Switch 2520G-8-PoE" → model="HP 2520G-8-PoE Switch", pn="J9298A"
"HP2530-8G Switch(J9777A)" → model="HP2530-8G Switch", pn="J9777A"
get_facts() includes part_number in the returned dict so NetOrk can
store it on Device.part_number and pass it to NetBox device types.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
get_interfaces() now fills in ports missing from the /ports collection
(e.g. the 4th SFP uplink on a 2530-48G) using system/status/switch, and
synthesizes a logical interface for each configured LAG/trunk group with
lag_members/lag_mode. New set_lag_members() adds/removes trunk members via
the REST /cli passthrough (PUT ports/{id} silently ignores trunk_group).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds get_poe_status()/set_poe() to expose per-port PoE configuration
(enable state, priority, allocation method, allocated power) and allow
toggling it via the AOS-Switch REST API.
connect() never sent back the sessionId returned in the login response
body, so all writes (POST/PUT/DELETE) were silently rejected with
"Access is unauthorized" while reads worked fine. Also fix
_api_set_vlan to PUT the full VLAN object (AOS-Switch v3 rejects
partial PUT bodies with HTTP 400).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Extracted _netmiko_kwargs() helper that strips port/timeout/disabled_algorithms
from netmiko_optional_args before spreading, so explicit values always win.
Used in both _try_ssh and _action_fix_snmp SSH fallback loop.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The REST API has no writable config endpoint for SNMP communities.
When _action_fix_snmp() is called on a REST-connected driver, it now
opens a temporary Netmiko SSH session (standard KEX, then legacy KEX
fallback), runs the config-mode CLI commands, and restores the REST
transport state on exit. SSH errors are surfaced verbatim instead of
being silently swallowed.
Also:
- _save_config: guard against REST transport (was calling self._device
directly → NoneType AttributeError when transport == "api")
- _action_fix_snmp: extracted CLI logic into _action_fix_snmp_cli()
so it is reused for both the SSH-fallback and native SSH/Telnet paths
- api_client: add get_snmp_communities() + configure_snmp_community()
for future use; improve GET error logging (warn vs debug on non-404)
- _try_api: probe timeout capped at 15 s; SSL retry loop for
self-signed certificates; improved log levels
- _api_set_interface / _cli_set_interface: handle enabled/description
fields that were previously ignored
- probe(): broaden accepted status codes (301/302/303/403)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Implements SNMP health collection for ProCurve/Aruba switches using
HP-proprietary CPU/memory/uptime OIDs with IF-MIB interface counters.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Mirrors the robust fallback pattern from napalm-opnsense so the driver
works regardless of which key name the caller passes in optional_args.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
get_snmp_config() uses single 'show snmp-server' command with read_timeout=10
to avoid blocking the poll. fix_snmp configures 'snmp-server community public
manager restricted'. get_device_warnings() added (was missing, caused AttributeError).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>