Gateway System Profile

The Gateway System Profile card allows you to create and manage gateway system configurations, ensuring consistent behavior and policy enforcement across all associated gateways.

Creating a Gateway System Profile

To create a gateway system profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Profiles tab is displayed by default.

  2. In the left navigation menu, select Devices.

    The Devices table is displayed containing the list of devices.

    Note:

    If you create profiles at the Device level, then the profiles have device scope assigned by default.

  3. Select a gateway for which you want to create a gateway system profile.

    The Profiles Management page under Profiles tab is displayed.

  4. On the System card, click Gateway System.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the Gateway System card, click Manage.

    The Gateway System configuration page is displayed.

  5. Click Create Profile.

    The Create Profile side panel is displayed.

  6. Configure the Gateway System Profile parameters as described in the following table.

    Table 1: Gateway System Profile Parameters

    Parameter

    Description

    Create as a local profile

    Select the check box if you want to configure this profile as local.

    The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the gateway system profile.

    Description

    Enter a brief description for the gateway system profile.

    Location

    Enter the location of the device.

    Contact

    Enter the contact details.

    General

    Device Timezone

    Select a device time zone from the drop-down list.

    LCD Menu

    Select the check box to enable LCD functions for gateways with an LCD screen.

    LCD Maintenance

    Select the check box to enable the following LCD Maintenance Options for gateways with an LCD screen:

    • Upgrade Image—Select the check box to enable the upgrade image option in the LCD menu. The following options are displayed under Partition:

      • Partition 0—Select the check box to enable the image upgrade on partition 0.

      • Partition 1—Select the check box to enable the image upgrade on partition 1.

    • Upload Configuration—Select the check box to enable the upload configuration option in the LCD menu.

    • System Reboot—Select the check box to enable the system reboot option in the LCD menu.

    • Factory Default—Select the check box to enable the factory default option in the LCD menu.

    • Media Eject—Select the check box to enable the media eject option in the LCD menu. The following options are displayed under Slot:

      • Slot 0—Select the check box to enable the media eject on slot 0.

      • Slot 1—Select the check box to enable the media eject on slot 1.

    GPS

    Select the check box to enable the GPS option for gateways.

    Note:

    The GPS parameter is available only for HPE Aruba Networking 9004-LTE gateways.

    Use IPv4 System VLAN Alias

    Select the check box to use IPv4 System VLAN Alias in the profile

    IPv4 System VLAN Alias  *—Select an IPv4 system alias from the drop-down list.

    System IP

    Select the VLAN interface as system IP address for the gateway.

    Security

    FIPS Compliance

    Select the checkbox to enable FIPS compliance for the Gateway System profile. When enabled, the gateway will reboot.

    Note:

    FIPS compliance is applicable only for gateways running version AOS 10.8.2.0 or higher.

    Authentication Timers

    User Idle Timeout

    Enter the timeout value (in minutes) for inactive user sessions. The value must be less than or equal to 255 minutes.

    This parameter specifies the amount of time a user session can remain inactive before being automatically logged out due to inactivity.

    Authentication Server Dead Time

    Enter the duration (in minutes) that a gateway waits for an authentication server's response before marking it as unavailable and switching to another configured server. The value must be less than or equal to 60 minutes.

    Logon User Lifetime

    Enter the duration (in minutes) a user remains authenticated after their device's last activity with the gateway. The value must be less than or equal to 255 minutes.

    RADIUS Client

    NAS Interface Type

    Specify the network interface on the gateway used for communicating with a RADIUS server for user authentication. Select one of the following radio buttons, depending on the network configuration:

    • None

    • IP Address—Select this option to display a NAS IPv4 Address text box. Enter the NAS IPv4 address used for RADIUS authentication.

    • VLAN—Select this option to display a NAS VLAN drop-down list. Select the VLAN on the gateway that acts as the NAS interface for RADIUS authentication.

    Source Interface Type

    Specify the network interface that the gateway uses for communication. Select one of the following radio buttons, depending on the network configuration:

    • None

    • VLAN—Select this option to display a Source Interface VLAN drop-down list. Select the VLAN for outbound traffic from the drop-down list.

    Firewall

    Firewall Options

    The following firewall options are available:

    • Deny Inter User Bridging—Select this check box to block Layer 2 traffic between users.

    • Deny Inter User Traffic—Select this check box to prevent both Layer 2 and Layer 3 communication between users.

    • Trust Client Voice QOS—Select this check box for the gateway to trust existing Quality of Service (QoS) markings from client devices.

    • Jumbo Frames Processing—Select this check box to display a Jumbo Frames MTU text box that enables support for Ethernet frames larger than 1500 bytes. The value must be between 1789-9216 bytes.

    Logging

    Logging

    Displays the logging details configured for the device.

    To add logging levels for the device, complete the following steps:

    1. Click the + icon to open the Create Logging pane.

    2. Select a category from the Category drop-down list.

    3. Select a sub-category from the Subcategory drop-down list.

    4. Select a process from the Process drop-down list.

    5. Select a logging level from the Logging Level drop-down list.

    6. Enter the MAC address of the device in the MAC Address field.

    7. Click Add to save the logging levels for the device.

    Note:

    The MAC Address parameter is displayed only for the following categories: ARM_USER_DEBUG, PEER_DEBUG, and USER_DEBUG.

    The configuration of Category and Logging Level parameters is mandatory.

    When the AP-DEBUG category is selected, the Debug String parameter appears, prompting you to add a string.

    Duplicates of category, process, or subcategory are not permitted.

    To add more logging levels, repeat the above steps.

  7. Click Create.

    The newly created gateway system profile is displayed on the Gateway System Profile configuration page.

  8. To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

Note:

The LCD options are currently supported for the following gateway platforms:

  • 7010

  • 7024

  • 7030

  • 7205

  • 7210

  • 7220

  • 7240

  • 7240XM

  • 7280

  • 9240

Editing a Gateway System Profile

To edit a Gateway System Profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Profiles tab is displayed by default.

  2. In the left navigation menu, select Devices.

    The Devices table is displayed containing the list of devices.

  3. Select a gateway for which you want to edit the gateway system profile.

    The Profiles Management page under Profiles tab is displayed.

  4. On the System card, click Gateway System Profile.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the Gateway System Profile card, click Manage.

    The Gateway System Profile configuration page is displayed.

  5. Click a Gateway System Profile from the table.
    The Edit Profile side panel is displayed.

    Figure 1: Editing a Gateway System Profile

  6. Edit the relevant parameters described in Gateway System Profile Parameters.

  7. Click Update.

Deleting a Gateway System Profile

To delete a Gateway System Profile profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Profiles tab is displayed by default.

  2. In the left navigation menu, select Devices.

    The Devices table is displayed containing the list of devices.

  3. Select a gateway for which you want to edit the gateway system profile.

    The Profiles Management page under Profiles tab is displayed.

  4. On the System card, click Gateway System Profile.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the Gateway System Profile card, click Manage.

    The Gateway System Profile configuration page is displayed.

  5. Hover over the profile that you want to delete, and click the delete icon.
    The Delete Profile pop-up window is displayed.

    Figure 2: Deleting a Gateway System Profile

  6. Click Delete.

    The cluster profile is deleted from the Gateway System Profile configuration page.

Note:

To search for a profile, type the profile name in the search bar. The search bar displays dynamic results as soon as you start typing.