AAA Authentication Profile

Authentication, Authorization and Accounting (AAA) is a security framework for controlling and tracking user access within a network. AAA controls access to device resources, enforces policies, audits usage, and provides the information necessary to bill for services.

Configuring AAA Authentication Profile

The AAA Authentication profile configuration involves the following procedures:

  1. Creation of an Authentication Server profile. For more information, see Authentication Server Profile.

  2. Creation of an Authentication Server Group profile. For more information, see Authentication Server Group Profile.

    Note:

    Ensure that the profile created in the previous step is selected from the Authentication Server drop-down menu in the Authentication Server Group profile Create Profile side panel.

  3. Creation of a AAA Authentication profile. For more information, see Creating a AAA Authentication Profile.

  4. Creation of Port profile.

    Note:

    Ensure that the profile created in the previous step is selected from the AAA Profile drop-down menu under the Port Profile - Security parameters step in the Port profile Create Profile side panel.

  5. Configuration of a Port profile interface using a Switch Interface Configuration profile. For more information, see Configuring a Port Profile Interface.

For information on assigning scope to a AAA Authentication profile, see Assigning Scope to a AAA Authentication Profile.

Creating a AAA Authentication Profile

To create a AAA Authentication profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a AAA Authentication Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

  3. On the Security card, click AAA Authentication.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the AAA Authentication card, click Manage.

    The AAA Authentication list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the AAA Authentication profile parameters as described in the following table.

    Table 1: Authentication Server Profile Parameters

    Parameter

    Description

    Create as a local profile

    Select this option if you want to configure this profile as local.

    Note: The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the AAA Authentication profile.

    Description

    Enter a brief description for the AAA Authentication profile.

    Authentication Protocol

    Select one of the following authentication protocols from the drop-down menu:

    • None

    • 802.1X

    • MAC

    • 802.1X, then MAC

    • MAC, then 802.1X

    • Concurrent

    Client limit

    Enter the client limit for the AAA Authentication profile.

    802.1X Authentication Server Group

    Select the required 802.1X authentication server group profile.

    MAC Authentication Server Group

    Select the required MAC authentication server group profile.

    Note:

    You can configure the remaining profile parameters under the Accounting, 802.1X Parameters, and MAC Parameters sections as required.

  6. Click Create.

    The newly created authentication server profile is displayed in the AAA Authentication list.

  7. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.
      The profile edit view is displayed in the side panel.

    2. Edit the required parameters.

    3. Click Update.

  • To delete an authentication server profile, hover over the profile name, and click the delete icon.

  • To search for a profile, type the profile name in the search bar.
    The search bar displays dynamic results as soon as you start typing.

Note:

The RFC server does not automatically update in the AAA Authentication profile of the gateway when the existing authentication server is changed from Radius to Radius+COA. As a workaround, after editing the authentication server, you need to update the same server in the WLAN again. This will prompt the WLAN to fetch the updates and subsequently update the RFC server in the AAA Authentication profile.

Configuring a Port Profile Interface

To configure a Port profile interface using a Switch Interface Configuration profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a AAA Authentication Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

  3. Select a device from which you want to create a Port profile interface.

    The Profiles Management page is displayed.

  4. On the Interface card, click Switch Interface Configuration.

    Alternatively, you can complete the following steps:

    1. On the Interface card, click Manage.

    2. On the Switch Interface Configuration card, click Manage.

    The Switch Interface Configuration list view is displayed.

  5. Apply the AAA-associated Port profile to a single port or to multiple ports as follows:

    • To apply the AAA-associated Port profile to a single port, complete the following steps:

      1. Select the required port to be configured.

        The Configure Interface side panel is displayed.

      2. Select the Use Port Profile checkbox.

      3. Select the related AAA-associated Port profile from the Port Profile drop-down menu.

      4. Click Save.

    • To apply the AAA-associated Port profile to multiple ports, complete the following steps:

      1. Select the required ports to be configured.

        Note:

        Close the Configure Interface side panel, if it opens automatically when you select the first required port.

        The Apply Port Profile option is displayed when you select more than one port.

        Note:

        A maximum of ten ports can be selected.

      2. Click Apply Port Profile.

        The Apply Port Profile side panel is displayed, and the Use Port Profile checkbox is selected by default.

      3. Select the related AAA-associated Port profile from the Port Profile drop-down menu.

      4. Click Save.

Assigning Scope to a AAA Authentication Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the Security card, click AAA Authentication.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the AAA Authentication card, click Manage.

    The AAA Authentication list view is displayed.

  4. Hover on the profile to which you want to assign a scope and click the Ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Add icon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The AAA Authentication list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the ellipsis icon.

    2. Select Unassign.

    3. Select the required scope and click Unassign.

  12. To customize the system local administration profile list, click the Customize Columns icon. For more information, see Customizing List.