Authentication Server Profile
Based on the security requirements, you can configure internal or external RADIUS and TACACS servers to authenticate clients who need access to the wireless network. This section describes the types of authentication servers that can be configured for a network profile.
Creating an Authentication Server Profile
To create an Authentication Server profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to an Authentication Server Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
- Select Site Collection, Site, Device, or Device Group in the left navigation menu.
- Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Security card, click Authentication Server.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Authentication Server card, click Manage.
The Authentication Server list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.
-
Configure the authentication server profile parameters as described in the following table.
-
RADIUS
-
TACACS
-
Secure RADIUS
-
Auth Server Mode
-
Advanced
-
IP Address/FQDN
-
Shared Secret
-
Retype Shared Secret
-
Authentication Port
-
Accounting Port
-
ClearPass Credentials
-
RADIUS—Provides standard authentication and accounting using the RADIUS protocol.
-
RADIUS with CoA (Change of Authorization)—Extends standard RADIUS authentication with support for Change of Authorization, enabling dynamic updates to active session
-
CoA Only—Accepts only Change of Authorization requests.
-
Internal
-
Custom
-
EST Profile
-
NAS Identifier
-
NAS IP Address
-
Called Station ID
-
For AP-based cluster deployments, ensure that you enter the VC IP address as the NAS IP address.
-
For Cloud AP-based Campus WLAN deployments, ensure that you enter the AP IP address as the NAS IP address.
-
MACAddress—Uses the MAC address as the called station ID.
-
APGroup—Uses the host name of the Instant AP as the called station ID.
-
APMAC address—Uses the MAC address of the Instant AP as the called station ID.
-
APName—Uses the host name of the Instant AP as the called station ID.
-
IPAddress—Uses the IP address of the Instant AP as the called station ID.
-
VLAN—Uses the VLAN ID of as the called station ID.
-
Source Interface
-
Lowercase MAC Address
-
Use IP Address for Calling Station ID
-
MAC Address Delimiter
- Auth Type—Select the authentication type from the drop-down list. The available options are PAP and CHAP.
- Enable Tracking—Select this checkbox to enable RADIUS or TACACS server tracking.
- Tracking Mode—Select the tracking mode for the server that has tracking enabled with the server. The tracking mode is used to monitor the status of server reachability. The available options are: Any and Dead Only.
- Retries—Specify the number of server retries.
-
Username
-
Password
-
Retype Password
-
Retries
-
Dead Time
-
Click Create.
The newly created authentication server profile is displayed in the Authentication Server list.
-
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The profile edit view is displayed in the side panel. -
Edit the required parameters.
-
Click Update.
-
-
To delete an authentication server profile, hover on the profile name, and click the delete
icon. -
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
|
Parameter |
Description |
|---|---|
|
Create as a local profile |
Select this option if you want to configure this profile as local. The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level. |
|
Name |
Enter the name of the authentication server profile. |
|
Description |
Enter a brief description for the authentication server profile. |
|
Server Type |
Select the server type from the following options: Creating a Authentication Server profile using radius dyn-authorization (RFC3576) as the server type is not supported. |
|
RADIUS |
If you select RADIUS server, then the following configuration options are displayed: Note:
For AOS-CX switches, the Cipher text passwords are not supported when configuring RADIUS server through the WebUI or API. Only plain text passwords must be used for these configurations. |
|
Secure RADIUS |
Select this check box to secure communication between the RADIUS server and the gateway. If you select this option, then Certificate Type option is displayed. |
|
Auth Server Mode |
Select the authentication server mode from the following options: This is applicable only for AOS-CX switches. |
|
Server Address Alias |
Select the checkbox to enable the use of server address aliases. Once enabled, use the Server Address Alias drop-down to select the server address from existing aliases. This is applicable only for AOS-CX switches. |
|
Shared Secret Alias |
Select the checkbox to use aliases for shared secrets. Once enabled, use the Shared Secret drop-down list to select an existing alias. This is applicable only for AOS-CX switches. |
|
Certificate Type |
Select the certificate type from the following options: |
|
Advanced |
If you select Advanced, then the following configuration options are displayed: |
|
NAS Identifier |
Use this to configure strings for RADIUS attribute 32, NAS Identifier, to be sent with RADIUS requests to the RADIUS server. |
|
NAS IP Address |
Enter the IP address. |
|
Called Station ID Type |
Select any of the following options to configure called station ID: |
|
Called Station ID Delimiter |
Select a character delimiter for the string from the drop-down list. |
|
Include WLAN Name |
Select this check box to include the WLAN name. |
|
Device-Specific Parameters |
If you select Gateway in the device-specific parameters, then the following Gateway Parameters are displayed: If you select Switch in the device-specific parameters, you can configure the following AOS-CX Specific Parameters: |
|
IP Address/FQDN |
IP address or FQDN of the authentication server. The maximum supported FQDN length is 63 characters. Default: N/A |
|
Shared Secret |
Shared secret key between the gateway and the authentication server. The maximum length is 128 characters. |
|
Retype Shared Secret |
Retype the shared secret key. |
|
Authentication Port |
Authorization port number of the external RADIUS server. The default port number is 1812. |
|
Accounting Port |
The accounting port number used for sending accounting records to the RADIUS server. The default port number is 1813. |
|
ClearPass Credentials |
If you select this check box, following configuration options are displayed: |
|
Secure RADIUS Trusted CA |
The CA certificate that is uploaded as a Trusted CA when the Radsec server uses a certificate signed by a CA. This option is available when you select Custom Certificate or Certificate (EST Profile) as the Certificate Type. |
|
Radsec Client Certificate |
The client certificate sent to the Radsec server. |
|
Certificate Profile |
Select this option to use the EST certificate as the Radsec client certificate when establishing an SSL or TLS connection with the Radsec server. |
|
TACACS |
|
|
IP Address/FQDN |
IP address of the server. |
|
Shared Secret |
The secret key to authenticate communication between the TACACS client and server. |
|
Retype Shared Secret |
Retype the shared secret key. |
|
Session Authorization |
Select the check box to allow the authorization of sessions for TACACS server. |
|
Timeout |
A number between 1–30 seconds to indicate the timeout period for TACACS+ requests. The default value is 20 seconds. |
|
Authentication Port |
The TCP IP port used by the server. The default port number is 49. |
|
Device-Specific Parameters |
If you select Access Point, then the following configuration options are displayed: If you select Switch, then VRF option is displayed. |
|
Retries |
The maximum number of authentication requests that can be sent to the server group by the AP. You can specify a value within the range of 1–5. The default value is three requests. |
|
Dead Time |
Specify a dead time for authentication server in minutes. When two or more authentication servers are configured on the AP and a server is unavailable, the dead time configuration determines the duration for which the authentication server is available if the server is marked as unavailable. |
|
VRF |
Select the VRF name from the drop-down list. This name is used for communicating with the server. If no VRF name is provided, the default VRF name default is used. |
The following image displays the Create Profile side panel of an Authentication Server profile.
Figure 1: Authentication Server - Create Profile
Assigning Scope to an Authentication Server Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the Security card, click Authentication Server.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Authentication Server card, click Manage.
The Authentication Server list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Authentication Server list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the Ellipsis
icon. -
Select Unassign.
-
Select the required scope and click Unassign.
-
-
To customize the Authentication Server profile list, click the Customize Columns icon
.For more information, see Customizing List.