Creating an Alias

Aliases allow you to name your network ports, protocols, and services in a simple yet understandable way. When you configure multiple ACLs, you can use a common alias instead of providing details of the network ports, protocols, and services.

To create an alias, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, select a site from the Sites menu.

    Alternatively, you can click the expand icon on the Sites menu to search for a site from the list.

    The site dashboard is displayed with the network and connectivity information for the site.

  2. Click the configuration icon.

    The Configuration Overview page is displayed.

  3. Click Library.

  4. Click Named Objects.

  5. Under Aliases tile, click Manage Aliases.

    The Aliases table is displayed with a list of aliases.

  6. Click Create Alias.

    The Create an Alias side panel is displayed.

    Note:

    You can configure aliases at different hierarchy levels such as Global, Site Collections, Sites, and Devices. HPE Aruba Networking Central applies configurations based on scope hierarchy, with lower scopes (for example, Devices) overriding higher scopes.

    Some alias types support partial configuration at higher scopes and require completion at the device level. For example, VLAN IPv4 address aliases can be defined at Global, Site Collections, or Sites levels without an IP address. The IP address for such aliases must be configured at the device level to prevent duplicate IP address assignment across multiple devices.

  7. Configure the following parameters:

    • Name—Enter a name of the alias.

    • Description—Enter a description of the alias.

    • Attributes Type—Select one of the following from the drop-down list:

      Attribute

      Description

      Additional Fields

      Auth Server Address

      Select this attribute type to configure a RADIUS server IP alias. This alias type must be configured to be referenced in authentication server profiles for flexibility and simplifying updates.

      Server Address*— Enter an IP address or FQDN for the RADIUS server.

      Auth Server Shared Secret

      Select this attribute type to configure a RADIUS shared secret alias. This alias type must be configured to be referenced in authentication server profiles for flexibility and scalability.

      Shared Secret*— Enter key

      Retype Shared Secret*— Re-enter key

      DNS Servers List

      Select this attribute type to configure DNS server aliases. This alias type must be configured for referencing in the DNS Server profile.

      AOS-CX switches support a maximum number of three DNS servers per VRF. Gateways and AOS-S switches supports a maximum number of six and four DNS servers respectively.

      Click the icon to add a new DNS server.

      For more information on creating a DNS server, see DNS Server Profile.

      Echo Source IP Address

      Select this attribute type to specify the source IPv4 address for BFD echo packets.

      Echo Source IP Address

      ESSID

      Select this attribute type to specify the Extended Service Set Identifier (ESSID) name.

      ESSID

      Host

      Select this attribute type to configure host parameters.

      • IPv4 Address—Select the IPv4 Address check box under Options and enter the IPv4 address in the IPv4 Address field.

      • IPv6 Address—Select the IPv6 Address check box under Options and enter the IPv6 address in the IPv6 Address field.

      Gateway Switchport

      Select this attribute type to create a switchport alias for a gateway. This alias type must be configured to be referenced in a Port profile, which should then be applied to an Ethernet interface in the Gateway Interface Configuration profile.

      For more information, see the following:

      Interface Mode—Select anyone of the following:

      • Access—Select this option to configure the interface mode as Access. Then, select an access VLAN from theAccess VLAN* drop down list.

      • Trunk—Select this option to configure the interface mode as Trunk. Then, select a native VLAN from the Native VLAN* drop-down list and enter the allowed VLANs in the Allowed VLANs text box.

      IPv4 Address

      Select this attribute type to enter the IPv4 address, which will be set in the device's route information. This alias type must be configured for referencing in the Static Routing profile. For more information, see Static Routing Profile.

      IPv4 Address

      IPv4 System VLAN

      Select this attribute type to enter the IPv4 system VLAN alias. This alias type must be configured for referencing in the Gateway System profile. For more information, see Gateway System Profile

      IPv4 System VLAN

      IPv6 Address

      Select this attribute type to enter the IPv6 address, which will be set in the device's route information. This alias type must be configured for referencing in the Static Routing profile. For more information, see Static Routing Profile.

      IPv6 Address

      Network

      Select this attribute type to configure network parameters.

      • IPv4 Subnet—Select the IPv4 Subnet check box under Options and enter the IPv4 subnet address in the IPv4 Subnet field.

      • IPv6 Prefix—Select the IPv6 Prefix check box under Options and enter the IPv6 prefix address in the IPv6 Prefix field.

      Network Destination

      Select this attribute type to enter network destination addresses.

      Destination Type—Select anyone of the following:

      • IPv4—Select this option to configure IPv4 network destination addresses.

      • IPv6—Select this option to configure IPv6 network destination addresses.

      • Gateway Specific Configurations—Select this check box to configure gateway specific configurations.

        • Invert—Select this check box to if you want to apply the firewall rules to all the destinations except the one configured in the alias.

      • Entries—The Entries table shows the type and condition of the network destination.

      To add entries, complete the following steps:

      1. Click icon.

      2. On the Add Entry page, select a rule type from the drop-down list. The following rule types are available:

      • Host—Allows you to configure a rule for a specific host IP address.

      • Network—Allows you to configure a rule for a specific network IP address and subnet mask.

      • Range—Allows you to configure a rule for a range of IP addresses.

      • Network VLAN—Allows you to configure a rule for overriding a specific VLAN.

      • Host VLAN Offset—Allows you to configure a rule for overriding a specific host.

      • Domain Name—Allows you to configure a rule for a specific domain name.

      NTP Server List

      Select this attribute type and then select a NTP server from the NTP Server list. This alias type must be configured for referencing in the NTP Server profile. For more information, see NTP Server Profile.

      Click icon to add a new NTP server.

      Nexthop IPv4 Address

      Select this attribute type to enter the IPv4 nexthop address, which will be set in the device's route information. This alias type must be configured for referencing in the Static Routing profile. For more information, see Static Routing Profile.

      IPv4 Nexthop Address

      Nexthop IPv6 Address

      Select this attribute type to enter the IPv6 nexthop address, which will be set in the device's route information.

      IPv6 Nexthop Address

      VLAN

      Select this attribute to enter the VLAN ID ranges which will be set in the VLAN profile. For more information, see VLAN Profile.

      VLAN ID ranges—Enter the VLAN ranges for the profile.

      VLAN Active Gateway

      Select this attribute to enter the active gateway information which will be set in the VLAN profile. For more information, see VLAN Profile.

      Note: Create a dedicated VLAN Active Gateway alias for each VLAN (SVI).
      • Active Gateway L3 Source MAC—Enable the check box to configure the virtual gateway MAC address as the source MAC for routed packets.

      • Active Gateway IPv4 Address—Enter the IPv4 address used as the default gateway for clients, which must be part of the subnet but not the same as the SVI IP.

      • Active Gateway MAC Address v4—Enter the virtual MAC address used by the active gateway, allowing both peers to be active.

      • Active Gateway IPv6 Address—Enter the IPv6 address used as the default gateway for clients, which must be part of the subnet but not the same as the SVI IP.

      • Active Gateway MAC Address v6—Enter the virtual MAC address used by the active gateway, allowing both peers to be active.

      VLAN Description

      Select this attribute type to enter the VLAN description, which will be set in VLAN profile. For more information, see VLAN Profile.

      VLAN Description—Enter a description for the VLAN description.

      VLAN IPv4 Address

      Select this attribute type to configure either a static or DHCP IPv4 address. This can be assigned to a VLAN profile, enabling a single VLAN to have multiple IP addresses for different purposes. For more information, see VLAN Profile.

      IP Address Assignment
      • Static—Select this option to manually configure a static IPv4 address to the VLAN interface.

      • DHCP—Select this option to assign IPv4 address automatically from a DHCP server to the VLAN interface.

      VLAN IPv6 Address

      Select this attribute type to configure either a static or DHCP IPv6 address. This can be assigned to a VLAN profile, enabling a single VLAN to have multiple IP addresses for different purposes. For more information, see VLAN Profile.

      IP Address Assignment
      • Static—Select this option to manually configure a static IPv6 address to the VLAN interface.

      • DHCP—Select this option to assign IPv6 address automatically from a DHCP server to the VLAN interface.

      VLAN Voice Enable

      Select this attribute type to route tagged traffic from IP phones through this target VLAN.

      Enable the Voice check box to route tagged voice traffic.

      VRRP

      Select this attribute to set the VRRP priority. This value determines which router becomes the primary or active router in a redundant group with higher numbers taking precedence.

      VRRP Priority—Set this value to any integer between 1 and 255.

      WPA Passphrase

      Select this attribute to set the WPA passphrase used to generate a pre-shared key.

      • WPA Passphrase* — Enter the passphrase.

      • Retype WPA Passphrase* — Re-enter the passphrase.

  8. Click Create.

    The new alias is added to the Aliases table.

Assigning Scope to an Alias

You must assign a scope and device function to an alias created in the Library.

To assign scope to a alias, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Configuration Overview page is displayed.

  2. Click Library.

  3. Click Named Objects.

  4. Under Aliases tile, click Manage Aliases.

    The Aliases table is displayed with a list of aliases

  5. Hover on the alias to which you want to assign a scope and click the Ellipsis icon.

  6. Select Assign.

    The Assign Profile side panel is displayed.

  7. Select the device types from Device Function list.

  8. To add a scope, click the Add icon on the Scopes table.

  9. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

  10. Click Add.

    The Scopes table displays the newly added scopes.

  11. Review your changes to the Device Function and Scopes list and then click Assign.

    The Aliases list displays the device functions and number of scopes assigned to the alias.

  12. To unassign a scope from a alias, complete the following steps:

    1. Hover on the alias name and click the Ellipsis icon.

    2. Select Unassign.

    3. Select the required scope and click Unassign.

  13. To customize the Aliases list, click the Customize Columns icon .

Important Points to Note

  • AOS-CX devices do not support configuring a DHCP client on more than one VLAN.

  • You should not assign scope and device function to either static or DHCP VLAN IPv4 or IPv6 address aliases.

  • When you create a VLAN IPv4 Address or VLAN IPv6 Addressalias and select Static as the IP Address Assignment, you need to assign the IP address at the Devices scope.

  • When updating a VLAN IPv4 Address or VLAN IPv6 Address alias, consider the following scenarios:

    • You can modify an alias at the Devices scope. For example, you can update the IP address assignment for a VLAN from Static to DHCP or DHCP to Static.

    • If a Static VLAN IPv4 or IPv6 address alias is created at any scope other than Devices scope, you can update it to a corresponding DHCP VLAN address alias.

    • If a DHCP VLAN IPv4 or IPv6 address alias is created at any scope other than Devices scope, you cannot update it to Staticaddress alias.

  • When deleting a VLAN IPv4 Address or VLAN IPv6 Address alias, consider the following scenarios:

    • If the alias is not referenced by a VLAN profile and is not assigned to a scope, you can delete it directly from the Named Objects > Aliases page.

    • If the alias is referenced by a VLAN profile, you need to remove the reference from the VLAN profile and unassign any scopes from the alias before you can delete it from the Named Objects > Aliases page.

    • If the alias is locally overridden at the Devices scope, you need to delete the override, remove the reference from the VLAN profile, and unassign any scopes from the alias before you can delete it from the Named Objects > Aliases page.