Device Onboarding and Linux DHCP Options for cnMaestro On Premises

This document explains about the device on boarding to cnMeastro NOC server and configuring the DHCP server either Windows or Linux to send the DHCP options 15, 43 and 60 to the Cambium Devices.

Minimum Required Software Versions

This table shows the minimum required software version for devices in order to on-board to cnMaestro On-Premises.

Product Minimum Version
cnPilot E400/E500 2.5.2-r3
ePMP 1000 Hotspot 2.5.2-r3
ePMP 1000, 2000 and Force 180,200 3.0
cnPilot R200P/R201P 4.2.3-R4
PMP 450 or 450i 15.0.1
PMP 450m 15.0.2
cnPilot R190 4.3.1
cnPilot R195 4.5.2-R11 or 4.6-R5

Device software images can be downloaded from support.cambiumnetworks.com or from the cnMaestro NOC server itself by navigating to Operate → Software Update → Manage Images. Select your device type to display the available images, and then click the download icon .

Onboarding Methods

Devices can be on boarded to cnMaestro NOC server in the following way

  • Claim Through Static URL without Cambium ID and On-Boarding key (Recommended method)
  • Claim Through Static URL with Cambium ID and on boarding key
  • Zero touch on boarding using DHCP option 43
  • Zero touch on boarding using DHCP option 15
  • Claim Through MAC Address
  • Order of Device Discovery

Configuring Static URL for cnMaestro On Premises

Before claiming the devices user needs to Login to device GUI and navigate to Configure → System menu in ePMP 1000/ePMP 1000 HotSpot/cnPilot E400/E500 devices or Administration → cnMaestro in cnPilot R200P/R201P devices or Configuration → cnMaestro in PMP devices.

cnPilot R200P/R201P

1.Navigate to Administrator → cnMaestro tab

2.Enter NOC static URL in the cnMaestro URL field.

cnPilot E400/E500 and ePMP 1000 HotSpot

  1. Navigate to Configure → System

  2. Under Management section, enter NOC static URL in the cnMaestro URL field

ePMP 1000 AP/SM

  1. Navigate to Configuration → System

  2. Under cnMaestro section, enter NOC static URL in the cnMaestro URL field

PMP 450 or 450i AP/SM/BHM/BHS

  1. Navigate to Configuration → cnMaestro

  2. Under configurationsection, enter NOC static URL in the cnMaestro URL field

Claim Through Static URL without Cambium ID and on Boarding key

In order to claim the devices using the static url without cambium id and on boarding key please follow the below steps

  • Login to device GUI and navigate to Configure->System menu in ePMP 1000/ePMP 1000 HotSpot/cnPilot E400/E500 devices or Administration → cnMaestro in cnPilot R200P/R201P devices or Configuration → cnMaestro in PMP devices.
  • Provide the NOC static url https://NOCIPADDRESSORHOSTNAME and click save.
  • Reboot the device if necessary for devices like cnPilot R200P/R201P and PMP Devices
  • Device will come to the on boarding queue in the cnMaestro Home → On board Devices → On board page and the user can approve the device

Claim Through Static URL with Cambium ID and on Boarding key

In order to claim the devices using the static url with cambium id and on boarding key please follow the below steps

  • Login to NOC server using default username and password (admin/admin) or the Username and Password set by the Administrator at the time of installation
  • Navigate to Home → On board Devices → Claim from Device page
  • Select the checkbox for “Enable Cambium ID based authentication to onboard devices”
  • Click on Add new and select the username from the drop down box and specify the on boarding key and click save.

  • Login to device GUI and navigate to Configure → System menu in ePMP 1000/ePMP 1000 HotSpot/cnPilot E400/E500 devices or Administration → cnMaestro in cnPilot R200P/R201P devices or Configuration → cnMaestro in PMP devices.
  • Provide the NOC static url https://NOCIPADDRESSORHOSTNAME and Cambium ID(cnmaestro_on_premises) and on boarding key for that user and click save.
  • Reboot the device if necessary for devices like cnPilot R200P/R201P and PMP Devices

Device will come to the on boarding queue in the cnMaestro Home → On board Devices → On board page and the user can approve the device

Zero touch on boarding using DHCP option 43

In order to claim the devices using DHCP option 43 user needs to follow the below steps

  • Configure the Linux or windows DHCP server to send the options 43 and 60 to the Cambium Devices. A Cambium cnMatrix switch is also an option. Please follow the section for DHCP Configuration
  • For claiming devices through this method user need not specify the static url in the device as the device obtains this url from DHCP option 43
  • User need not specify anything else in the device as this is Zero touch on board
  • Device will come to the on boarding queue in the cnMaestro Home → On board Devices → On board page and the user can approve the device

Zero touch on boarding using DHCP option 15

In order to claim the devices using DHCP option 15 user needs to follow the following steps

  • Configure the Linux or windows DHCP server to send the options 15 to the Cambium Devices. A Cambium cnMatrix switch is also an option. Please follow the section for DHCP Configuration
  • For claiming devices through this method user need not specify the static url in the device as the device obtains this url from DHCP option 15 (cnmaestro.companyname.com)
  • User need not specify anything else in the device as this is Zero touch on board
  • Device will come to the on boarding queue in the cnMaestro Home → On board Devices → On board page and the user can approve the device

Note :- For DHCP options to work properly on the already deployed cnPilot R200P/R201P devices , please reset the devices. Before resetting take a backup of the configuration and restore it once the device is reset and comes back online.

For all other device types just make sure that no cnMaestro static url is configured in the device for the DHCP options to work fine.

Claim Through MAC Address

In order to claim through mac address , please follow the below steps

  1. Login to NOC server using default username and password (admin/admin) or the Username and Password set by the Administrator at the time of NOC server installation
  2. Navigate to Home → On board Devices → Claim from cnMaestro
  3. Select the Device type for which on boarding is to be done and provide the MAC Address in the combo box and click the Claim Devices button.

Multiple MAC Addresses of same device type can be claimed using "," separator between MAC Addresses or by entering them in the new line

Note :- Before claiming through MAC Address user needs to specify the static url in the device gui as mentioned in section 2.1 . Even if the device type is selected wrong during claim no need to worry . If the MAC Address is of the correct device , when the device contacts the server it will provide the server with the correct device type

Order of Device Discovery

The device discovery order is as follows in cnMaestro NOC Server and if any of the options is not configured the discovery method will fallback to the next option

DHCP Configuration

Linux DHCP Options (ISC-DHCP-Server)

A DHCP Server can be used to configure the IP Address, Gateway, and DNS servers for Cambium devices. If you administer the DHCP Server, you can also configure DHCP Options that will tell the devices how to access the cnMaestro (so the URL doesn’t need to be set on each device). Cambium devices support DHCP Options 43 and 15 for setting the cnMaestro On-Premises URL.

Using DHCP Option 43

DHCP Option 43 returns the cnMaestro On-Premises URL as a Vendor-Specific Option. DHCP Option 43 is returned in tandem with DHCP Option 60 (the Vendor Class Identifier, or VCI). The VCI for the individual Cambium products is listed below.

Product VCI (DHCP Option 60)
cnPilot R200 P Cambium-cnPilot R200P
cnPilot R201P Cambium-cnPilot R201P
cnPilot R200 Cambium-cnPilot R200
cnPilot R201 Cambium-cnPilot R201
cnPilot E Series Cambium-WiFi-AP
All ePMP Devices Cambium
ePMP 1000 Hotspot Cambium-WiFi-AP
PMP 450 AP Cambium PMP 450 AP
PMP 450 SM Cambium PMP 450 SM
PMP 450i AP Cambium PMP 450i AP
PMP 450i SM Cambium PMP 450i SM
PMP 430 SM Cambium PMP 430 SM
PTP 450 BHM Cambium PTP 450 BHM
PTP 450 BHS Cambium PTP 450 BHS
PTP 450i BHM Cambium PTP 450i BHM
PTP 450i BHS Cambium PTP 450i BHS
PMP 450m AP Cambium PMP 450m AP
450 MicroPoP Sector AP Cambium PMP 450 MicroPoP Sector AP
450 MicroPoP Omni AP Cambium PMP 450 MicroPoP Omni AP
450 MicroPoP AP Cambium PMP 450 MicroPoP AP
450 MicroPoP Connectorized AP Cambium PMP 450 MicroPoP Connectorized AP
PMP 450b Retro SM Cambium PMP 450b Retro SM
PMP 450b High Gain SM Cambium PMP 450b High Gain SM
PMP 450b Mid-Gain SM Cambium PMP 450b Mid-Gain SM
PMP 450b Connectorized SM Cambium PMP 450b Connectorized SM
PMP 450b6 SM Cambium PMP 450b6 High Gain SM
PMP 450v 4x4 AP Cambium PMP 450v 4x4 AP
PMP 450v 4x4 SM Cambium PMP 450v 4x4 SM
PMP 450v 2x2 SM Cambium PMP 450v 2x2 SM
PTP 450v 4x4 BHM Cambium PTP 450v 4x4 BHM
PTP 450v 4x4 BHS Cambium PTP 450v 4x4 BHS
cnPilot R190V Cambium-cnPilot R190V
cnPilot R190W Cambium-cnPilot R190W
cnPilot R195W Cambium-cnPilot R195W

Typically, Option 43 will be the preferred mechanism to configure the cnMaestro URL. Example configuration for the ISC DHCP Server is presented below (from the /etc/dhcp/dhcpd.conf file).

option option-43 code 43 = string;

# ePMP Devices
class "Cambium" {
    match if option vendor-class-identifier = "Cambium";
    # DHCP server MUST return the device’s Vendor Class back, in the offer.
    option vendor-class-identifier "Cambium";
    # cnMaestro On-Premises IP is 192.168.0.100
    option option-43 "https://192.168.0.100";
}

# WiFi Devices
class "Cambium-WiFi-AP" {
    match if option vendor-class-identifier = "Cambium-WiFi-AP";
    option vendor-class-identifier "Cambium-WiFi-AP";
    option option-43 "https://192.168.0.100";
}

# cnPilot R200P Devices
class "Cambium-cnPilot R200P" {
    match if option vendor-class-identifier = "Cambium-cnPilot R200P";
    option vendor-class-identifier "Cambium-cnPilot R200P";
    option option-43 "https://192.168.0.100";
}

# cnPilot R201P Devices
class "Cambium-cnPilot R201P" {
    match if option vendor-class-identifier = "Cambium-cnPilot R201P";
    option vendor-class-identifier "Cambium-cnPilot R201P";
    option option-43 "https://192.168.0.100";
}

# PMP Devices
class "Cambium PMP 450 AP" {
    match if option vendor-class-identifier = "Cambium PMP 450 AP";
    option vendor-class-identifier "Cambium PMP 450 AP";
    option option-43 "https://192.168.0.100";
}

Using DHCP Option 15

DHCP Option 15 allows the device to derive the cnMaestro URL from the domain name. For example, if the domain name in DHCP Option 15 is mycompany.com, then the device will try to access the cnMaestro server at cnmaestro.mycompany.com (essentially the string “cnmaestro” is prepended to the domain). The domain itself, and the IP address of cnMaestro, must be configured in the DNS server for this to work correctly.

Sample configuration for the ISC DHCP Server is presented below (from the /etc/dhcp/dhcpd.conf file).

option domain-name "mycompany.com";

Note :- User needs to map the cnmaestro.mycompany.com to the proper NOCSERVERIPADDRESS in the DNS server for on boarding to work properly

Can anybody provide a list of the VCI data for cnMatrix switches?

I have an EX1010P that is actually showing a VCI of “Cambium-cnMatrix-EX2K”, so I suspect that might be the Identifier used for all of the switches (regardless of 1k or 2k version), unless the TX series use something different (I have some of those to deal with as well but I believe they’re all on static IP at the moment so no easy way to check the VCI they announce).

Your instructions above imply that both Opt43 and Opt60 need to be sent back, but I’m trying to understand if that’s a “SHOULD/MAY” or a “MUST”. Do Cambium devices actually require the VCI to be sent back in the DHCP reply in order to also accept Option 43? Or can I just blindly send Option 43 back (without replying with a matching VCI for the specific device type)? On a Mikrotik router it’s relatively easy to match the VCI and then reply with option43; if I need to send back both 43 and the matched-VCI, this is more complicated.

Will sending Option 43 back override a device that has already been onboarded to cloud, or is the URL “hardcoded” to “cloud.cambiumnetworks.com” by the cloud cnM, so the DHCP option would only be helpful for a wiped/factory-clean device?

Per the info in the on-prem user guide (and is consistent for Enterprise APs at least :slight_smile: ), order of precedence is:

1) Statically assigned in config file (either via device ui, ssh, or config file by adding the appropriate line at the bottom of an existing cloud config's User-Defined Overrides)
2) DHCP Option 43/60 exchange
3) DHCP Option 15
4) Fallback to https://cloud.cambiumnetworks.com

Option 43 overrode an existing cloud-managed device in my testing on next boot. Though it’s unclear if that’s a behavior of my dhcp server I was testing with (Kea-DHCP4 via pfSense).

Understood re: the order of preference for choice of controller (I think that’s actually documented above too, or somewhere else on the discussion board).

I’m still wondering whether devices require the matching VCI (Option60) to be sent back in the reply, or if they will work without it. On a Mikrotik, it’s super easy to:

  1. Match a client-supplied option60 / VCI
  2. send back a generic reply (Option 43) for all clients that match point 1

If you need to also send back Option60 that matches what the client sent, this makes the config a bit more complicated. It’s still possible, just more involved.

So far I’ve been moving things by just using the “User-defined overrides” in either switch profile or AP Group, but was curious about the behavior with DHCP. One thing I have found is that after committing a config with the override to talk to your onprem server, you’ve got about 10-15 minutes to get it deleted from cloud and then approved on the onprem side. If you don’t do that in time, it will rollback to its last working config (the one without the override), which it accomplishes by rebooting itself (at least in the case of a cnMatrix switch, I assume APs are similar).

If you’ve already deleted the device from the cloud side, you’re then in somewhat of a conundrum, because you can’t use the cloud to re-point it back to onprem at that point… Luckily on the device where I had this happen, I still had local login access and was able to just give it the onprem URL that way, but I learned my lesson. :slight_smile:

So, I checked my notes… and apparently I took a packet capture.

Client (AP) Discover: Options 60, 61

Kea Offer: 43

Client Request: 60, 61

Kea ACK: 43