Manage Roles and Policies

Roles and policies work together to control user access and enforce various security policies across your network. By carefully defining roles and applying relevant policies, you can ensure secure, role-based access while protecting network resources and maintaining compliance.

Following is the typical flow to implement access control effectively:

  1. Create roles to define access level and privileges for different user types (such as employees or guests).

  2. Create and apply policies to these roles to enforce network usage guidelines and security measures.

This approach ensures that users are assigned the correct permissions and their activity is governed by appropriate policies.

Roles allow you to assign specific access and permissions to different individuals or groups within your organization. By defining roles, you can control the actions and settings that each user or group can perform within the network. For example, you can assign an Employee role to certain users, granting them full access and control over the network. You can also assign a Guest role to visitors, restricting their access to limited resources within your network.

Once a client device is associated with a user role, HPE Aruba Networking Central uses this association to determine:

  • The device's access privileges

  • Bandwidth contract assignments

  • Frequency of client authentication

Policies, on the other hand, define rules and restrictions applied to traffic generated by users assigned to a particular role. Policies allow you to set rules and guidelines for consistent and secure network usage across your organization. Policies can protect against unauthorized access, minimize vulnerabilities, and mitigate potential risks or threats to your network. For example, a policy can do the following:

  • Restrict user access to certain applications or websites

  • Enforce specific encryption standards or authentication methods that require strong and unique passwords

  • Block risky services or ports

These security policies are applied to the network traffic that passes through the HPE Aruba Networking Central devices. You can apply one or more policies to each role, giving you granular control over both access permissions and network behavior.

If a user's role assignment, including the restricted resource restriction policy (RRP) mapping, has already been configured for HPE Aruba Networking Central application, then when a new region is provisioned under the existing account, the user must update the RRP list to include the groups associated with the newly provisioned region. This ensures uninterrupted access to Classic Central for the newly added region.

Note: When a user-role is configured with a scope limited to a specific device type, it is not automatically enforced across the network. The role is applied to the intended device type only after a corresponding firewall policy is created and the user-role is associated with that policy. Once created, the firewall policy must be scoped to the target device type to ensure the user-role is enforced on the appropriate devices. This is expected Day-1 behavior across all device categories.

Prerequisites

Before configuring roles and policies, complete the following tasks:

  • Map devices to a site first and then move the devices to a HPE Aruba Networking Central group.

  • Onboard the devices to a cluster. Do not use the devices which are already present on a cluster. If a device is present on a cluster, un-assign it, and re-provision it back.

  • Do not create policy-based routing for a HPE Aruba Networking Central group from Classic Central with a policy name starting with sys_policy prefix.

  • Ensure that AOS-CX and AOS-S switches do not have any pre-configured security roles or policies before moving it to a New Central group.

  • Ensure that AOS-CX switches run AOS-CX 10.13.0005 or later version.

  • Ensure that AOS-S switches run AOS-S 16.11.0028 or later versions.

  • Ensure that gateways run the latest ArubaOS 10.x version.

Limitations

The following limitations apply when configuring roles and policies:

  • A configuration can be created and assigned only to the global scope.

  • Configuration is not supported in specific sites, device groups, or site collections.

  • Configuration fails when another request is in progress.

  • The login role is pushed as an initial role instead of the default role after SSID creation on a HPE Aruba Networking Central group.

  • When roles, alias, or services are created during creation of policy rule, respective configuration options are not listed.

  • For overlay SSID, HPE Aruba Networking Central roles are not shown in the Classic Central group WLAN work flow.

  • Policy-based routing cannot be applied to a role created in HPE Aruba Networking Central.

  • Policy-based routing cannot be added when creating an SSID.

AP Limitations

The following limitations apply to APs:

  • AP device configuration supports AOS-10 and ArubaOS 8.x.

  • An AP discards a rule destination as role.

  • AP configuration does not support service ports with comma.

  • AP does not support alias IPv6 configuration.

  • The device password and country code for APs must be configured in Classic Central.

AOS-CX Limitations

The following limitations apply to AOS-CX switches:

AOS-CX switches do not support spaces in role or rule names.

• A role or role-related configuration is pushed to all devices when an Access Based Policy (ABP) or a Group Based Policy (GBP) is added to AOS-CX switches. There is no impact on traffic from the role or role-related configuration.

• Default GBP roles are added on AOS-CX switches 6200, 6300, 6400, 8100, and 8360. These roles are not displayed in the UI, and creating a role name similar to the default GBP roles causes the switch to go out of synchronization.

• It is not recommended to onboard VSX synchronized devices to HPE Aruba Networking Central.

• The configuration added through HPE Aruba Networking Central cannot be edited in the MultiEdit mode through Classic Central.

AOS-CX switches support only role as the option in the source field.

• Internal traffic is not allowed from a default role to a destination role. As a workaround, the specific rule can be configured using reverse console.

Gateway Limitations

The following limitations apply to gateways:

  • Gateways do not support spaces in role names.

  • Only role-based policy rules are pushed to gateways.

  • When an alias is referenced in a policy, modification of the alias attribute, host or network, is not restricted.

  • When an SSID is deleted, the roles that are created during the WLAN SSID workflow creation are not deleted.

  • Gateways and policies do not support alias IPv6 configuration.