Christian Manivong e3bbac0656 fix(api): change an existing VLAN membership instead of re-creating it
set_interface() always POSTed to vlans-ports, treating every membership as
new. Moving a port that already carries the VLAN from untagged to tagged is
not a create, though, and the switch says so:

    POST vlans-ports {"vlan_id":10,"port_id":"10","port_mode":"POM_TAGGED_STATIC"}
      -> 400 {"message":"Association exists"}

Only 409 was handled as "already there"; v7 firmware answers 400. The
membership is its own resource named {vlan_id}-{port_id} and takes a PUT:

    PUT vlans-ports/10-10 -> 200

So the exact case anyone hits first failed outright — a port holding VLAN 10
untagged alongside 30/40/50 tagged, with VLAN 10 to become tagged too.

The response body is now carried into both error messages. The ports PUT just
above already did this; here it was dropped, so "Association exists" — which
names the cause outright — never reached the caller. The message read
"vlans-ports POST HTTP 400" and nothing more.

Verified against a 2530-24G-PoEP on REST v7: set_interface("10", trunk
vlan 30), where that membership already exists, now completes and leaves the
port exactly as it was.
2026-08-18 16:22:21 +07:00

napalm-hpe-aruba-procurve

NAPALM driver for HPE / Aruba ProCurve switches — from ancient 2520G-8-PoE to modern 2530/2540 series.

Transport auto-detection

The driver probes transports in order and uses the first one that succeeds:

Priority Transport Notes
1 REST API (HTTPS → HTTP, v7 → v6) Newer 2530/2540 with rest-interface enabled
2 SSH (standard) hp_procurve netmiko driver
3 SSH (legacy KEX) Forces older kex/cipher negotiation for 2520G-8-PoE etc.
4 Telnet Oldest devices without SSH or with broken SSH

Override the transport with optional_args={"transport": "ssh_legacy"} to skip auto-detection.

Switch prerequisites

REST API (newer switches, e.g. 2530, 2540)

web-management ssl
rest-interface
rest-interface session-idle-timeout 120

SSH (all ProCurve)

crypto key generate ssh rsa
ip ssh

Telnet is enabled by default on most ProCurve switches.

Installation

pip install napalm napalm-hpe-aruba-procurve

Or from source:

git clone https://github.com/chrismanivong/napalm-hpe-aruba-procurve
pip install -e napalm-hpe-aruba-procurve/

Quick start

from napalm import get_network_driver

Driver = get_network_driver("procurve")

with Driver(
    "10.0.0.1",
    "manager",
    "secret",
    optional_args={
        # "transport": "ssh",          # force transport (api/ssh/ssh_legacy/telnet)
        # "port": 22,
        # "ssl_verify": False,         # disable SSL cert check for API
        # "api_version": "v7",         # API version hint (v3/v6/v7)
        # "secret": "enablepassword",  # enable password for CLI
    },
) as dev:
    print(dev.get_facts())
    print(dev.get_interfaces())

Supported NAPALM methods

Method API SSH/Telnet
open() ✅ ✅
close() ✅ ✅
is_alive() ✅ ✅
get_facts() ✅ ✅
get_interfaces() ✅ ✅
get_interfaces_ip() ✅ ✅
get_arp_table() ✅ ✅
get_mac_address_table() ✅ ✅
get_lldp_neighbors() ✅ ✅
get_lldp_neighbors_detail() ✅ ✅
get_config() ✅ ✅
get_ntp_servers() ✅ ✅
get_environment() ❌ ✅
get_users() ❌ ✅
get_snmp_information() ❌ ✅
ping() ✅ ✅
cli() ✅ ✅
load_merge_candidate() ❌ ✅
load_replace_candidate() ❌ ✅
compare_config() ❌ ✅
commit_config() ❌ ✅
discard_config() ❌ ✅
rollback() ❌ ✅

Tested devices

  • HP ProCurve 2520G-8-PoE (J9565A) — SSH legacy / Telnet
  • HP ProCurve 2920-48G — SSH
  • Aruba 2530-8-PoE+ — SSH + REST API

License

Apache 2.0

S
Description
No description provided
Readme
516 KiB
Languages
Python 100%