Authentication Server Global Profile
Authentication server profiles are a key component in the security profile ecosystem. The Authentication Server Global profile, used in conjunction with the Authentication Server Group profile, Authentication Server Profile, and AAA Authentication profile provides a comprehensive authentication framework for devices on the network.
Creating an Authentication Server Global Profile
To create an Authentication Server Global profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to an Authentication Server Global Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:-
To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
-
To create profiles at the Site Collections, Sites, Devices, or Device Group level, complete the following steps before step 4:
-
Select Site Collection, Site, Device, or Device Group in the left navigation menu.
-
Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
-
Select the device type from the Device Function drop-down list.
-
-
-
On the Security card, click Authentication Server Global.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Authentication Server Global card, click Manage.
The Authentication Server Global list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.
-
Configure the authentication server profile parameters as described in Table 1.
Table 1: Authentication Server Global Profile Parameters
Parameter Description Create as a local profile
Select this option if you want to configure this profile as local.
Note: The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.Name
Enter the name of the authentication server profile.
Description
Enter a brief description for the authentication server profile.
Server Type
Select the server type from the following options:
-
RADIUS
-
TACACS
Auth Type
Select the authentication type from the drop-down menu.
Timeout
Enter the timeout interval in seconds.
Enable Radsec
Select this checkbox to enable Radsec. If selected, configure the following parameter:
-
Dynamic Authorization—Select the checkbox to enable dynamic authorization. If selected, enter the required port number in the Dynamic Authorization Port field.
Retries
Enter the allowed number of retries.
Shared Secret
Enter the shared secret.
Retype Shared Secret
Retype the shared secret.
Auth Type
Select None, CHAP, or PAP from the drop-down list.
Timeout
Enter the time duration in seconds.
Tracking
Select this checkbox to enable tracking. If selected, configure the following parameters:
-
Mode—Select the tracking mode from the drop-down menu.
-
Username—Enter the username.
-
Password—Enter the password.
-
Retype Password—Retype the password.
-
Tracking Requests—Enter the number of tracking requests
-
Tracking Retries—Enter the allowed number tracking retries.
-
Tracking Interval—Enter the tracking interval in seconds.
-
-
Click Create.
The newly created profile is displayed in the Authentication Server Global list.
-
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The Edit Profile view is displayed in the side panel.
-
Edit the required parameters.
-
Click Update.
-
-
To delete an Authentication Server Global profile, hover on the profile name, and click the delete
icon. -
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
Assigning Scope to an Authentication Server Global Profile
You must assign a scope and device function to a Authentication Server Global profile created in the Library.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.The Profiles tab is displayed.
-
Ensure that the default option Library is selected in the left navigation menu.
-
On the Security card, click Authentication Server Global.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Authentication Server Global card, click Manage.
The Authentication Server Global list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the Ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Authentication Server Global list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the ellipsis
icon. -
Select Unassign.
-
Select the required scope and click Unassign.
-
-
To customize the Authentication Server Global profile list, click the Customize Columns
icon.