Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring Downloadable Roles
HPE Aruba Networking Central allows you to download pre-existing user roles when you create network profiles.
The Aruba Instant 8.4.0.0 firmware version with a minimum of ClearPass ClearPass is an access management system for creating and enforcing policies across a network to all devices and applications. The ClearPass integrated platform includes applications such as Policy Manager, Guest, Onboard, OnGuard, Insight, Profile, QuickConnect, and so on. server version 6.7.8.
feature is available only for networks that include access points (APs) that run a minimum ofAruba Instant and ClearPass Policy Manager ClearPass Policy Manager is a baseline platform for policy management, AAA, profiling, network access control, and reporting. With ClearPass Policy Manager, the network administrators can configure and manage secure network access that accommodates requirements across multiple locations and multivendor networks, regardless of device ownership and connection method. include support for centralized policy definition and distribution.
When ClearPass Policy Manager successfully authenticates a user, the user is assigned a role by ClearPass Policy Manager. If the role is not defined on the IAP, the role attributes can also be downloaded automatically. In order to provide highly granular per-user level access, user roles can be created when a user has been successfully authenticated. During the configuration of a policy enforcement profile in ClearPass Policy Manager, the administrator can define a role that should be assigned to the user after successful authentication. In RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources. authentication, when ClearPass Policy Manager successfully authenticates a user, the user is assigned a role by ClearPass Policy Manager.
If the role is not defined on the IAP, the role attributes can also be downloaded automatically. This feature supports roles obtained by the following authentication methods:
- 802.1X 802.1X is an IEEE standard for port-based network access control designed to enhance 802.11 WLAN security. 802.1X provides an authentication framework that allows a user to be authenticated by a central authority. (WLAN Wireless Local Area Network. WLAN is a 802.11 standards-based LAN that the users access through a wireless connection. and wired users)
- MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. authentication
- Captive Portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.
This section describes the following topics:
- ClearPass Policy Manager Certificate Validation for Downloadable Role
- Enabling Downloadable Role Feature for Wireless Networks in HPE Aruba Networking Central
- Enabling Downloadable Role Feature for Wired Networks in HPE Aruba Networking Central
ClearPass Policy Manager Certificate Validation for Downloadable Role
When a ClearPass Policy Manager server is configured as the domain for RADIUS authentication for downloading user roles, in order to validate the ClearPass Policy Manager customized CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., IAPs are required to publish the root CA for the HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection. server to the well-known URL Uniform Resource Locator. URL is a global address used for locating web resources on the Internet. ( ). The IAP must ensure that an FQDN Fully Qualified Domain Name. FQDN is a complete domain name that identifies a computer or host on the Internet. is defined in the above URL for the RADIUS server and then attempt to fetch the trust anchor by using the RADIUS FQDN. Upon configuring the domain of the ClearPass Policy Manager server for RADIUS authentication along with a username and password, the IAP tries to retrieve the CA from the above well-known URL and store it in flash memory. However, if there is more than one ClearPass Policy Manager server configured for authentication, the CA must be uploaded manually.
Enabling Downloadable Role Feature for Wireless Networks in HPE Aruba Networking Central
To enable the
feature, complete the following steps:- In the WebUI, set the filter to a group containing at least one AP.
The dashboard context for the group is displayed.
- Under
A list of APs is displayed in the
view.
, click > . - Click the
The tabs to configure the APs are displayed.
icon. - Click the
The WLANs details page is displayed.
tab. - In the SSID Service Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network., select a wireless SSID from the table and then click the edit icon. tab, click . To modify an existing
- In the
At least one radius server must be configured to apply the Downloadable User Roles feature. For more information on configuring radius server, see Authentication Servers for IAPs
tab, select the server in field. - Click .
- The tab is displayed.
- Turn on the
- The Aruba Instant 8.4.0.0 firmware version with a minimum of ClearPass server version 6.7.8. feature is available only for networks that include APs that run a minimum of
- At least one radius server must be configured to apply the Authentication Servers for IAPs.
toggle switch to allow downloading of pre-existing user roles. The table with , , and columns related to the radius servers are displayed. - Click the action corresponding to the radius server listed in the
The
page displays the name of the radius server name. The field is non-editable.
table. The page is displayed. - Enter the following details:
- —Enter the ClearPass Policy Manager admin username.
- —Enter the password.
- —Retype the password.
- Click .
Enabling Downloadable Role Feature for Wired Networks in HPE Aruba Networking Central
To enable the
feature, perform the following steps:- In the WebUI, set the filter to a group containing at least one AP.
The dashboard context for the group is displayed.
- Under
A list of APs is displayed in the
view.
, click > . - Click the
The tabs to configure the APs are displayed.
icon. - Click .
- Click the
The Interfaces page is displayed.
tab. - Click the accordion.
- Under , click . To modify an existing profile, select the network that you want to edit in the pane, and then click the edit icon.
- In the
At least one radius server must be configured to apply the Authentication Servers for IAPs
feature. For more information on configuring radius server, see
tab, select the server in field. - Click .
- The tab is displayed.
- Enable the
- The Aruba Instant 8.4.0.0 firmware version with a minimum of ClearPass server version 6.7.8. feature is available only for networks that include APs that run a minimum of
- At least one radius server must be configured to apply the Authentication Servers for IAPs.
option to allow downloading of pre-existing user roles. The table with , , and columns related to the radius servers are displayed. - Click the action corresponding to the radius server listed in the
The
page displays the radius server name. The field is non-editable.
table. The page with the radius server name is displayed. - Enter the following details:
- —Enter the ClearPass Policy Manager admin username.
- —Enter the password.
- —Retype the password.
- Click .