Authentication Server Group Profile

You can create groups of servers for specific types of authentication. You can configure servers of different types in one group. For example, you can include the internal database as a backup to a RADIUS server. You can also configure the same server in more than one server group. However, you must configure the server before you can include it in a server group.

Creating an Authentication Server Group Profile

To create an Authentication Server Group profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to an Authentication Server Group Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:
    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.

    • To create profiles at the Site Collections, Sites, Devices, or Device Group level, complete the following steps before step 4:

      1. Select Site Collection, Site, Device, or Device Group in the left navigation menu.

      2. Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.

      3. Select the device type from the Device Function drop-down list.

  3. On the Security card, click Authentication Server Group.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the Authentication Server Group card, click Manage.

    The Authentication Server Group list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the authentication server profile parameters as described in Table 1.

    Table 1: Authentication Server Group Profile Parameters

    Parameter Description

    Create as a local profile

    Select this option if you want to configure this profile as local.

    Note: The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the authentication server profile.

    Description

    Enter a brief description for the authentication server profile.

    Server Type

    Select the server type from the following options:

    • RADIUS

    • TACACS

    Authentication Servers

    Select the authentication servers from the drop-down list.

    To create a server, click New Server. For more information see, Authentication Server Profile.

    To view the selected servers, click View Selection.

    Gateway Specific Parameters

    If you select this check box, then the High Availability options are displayed.

    High Availability

    Select one of the following configuration options:

    • Fail Through

    • Load Balance

    Advanced

    Select this check box to configure server rules.

    Server Rules

    Select the server rules in the server rules table.

    To create server rules, click the icon on the Server Rules table. For more information, see Server Rule Parameters.

  6. Click Create.

    The newly created profile is displayed in the Authentication Server Group list.

  7. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.

      The Edit Profile view is displayed in the side panel.

    2. Edit the required parameters.

    3. Click Update.

  8. To delete a captive portal authentication profile, hover on the profile name, and click the delete icon.

  9. To search for a profile, type the profile name in the search bar.
    The search bar displays dynamic results as soon as you start typing.

Figure 1: Authentication Server Group - Create Profile

Assigning Scope to an Authentication Server Group Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Authentication Server Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have Site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have Device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have Device Group scope assigned by default.

    Note:
    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.

    • To create profiles at the Sites, Devices, and Device Group level, complete the following steps before step 4.

      • Select a Site, Device, or Device Group from the list view.

      • Select the device type from the Device Function drop-down list.

     

  3. On the Security card, click Authentication Server Group.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the Authentication Server Group card, click Manage.

    The Authentication Server Group page is displayed.

  4. Hover on the profile to which you want to assign a scope and click the ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Add icon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list .

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The Authentication Server Group list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the Ellipsis icon.

    2. Select Unassign.

      The Unassign pop-up window is displayed.

    3. Select the required scope and click Unassign.

  12. To customize the Authentication Server Group profile list, click the Customize Columns icon . For more information, see Customizing List.