Port Profile for APs

The Port profile allows you to define a set of attributes that can be applied to multiple interfaces of an AP.

To create a Port profile for an AP, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
      • Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
      • Select the device type from the Device Function drop-down list.

  3. On the Interfaces card, click Port.

    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Port card, click Manage.

    The Port list view is displayed.

  4. Click Create Profile.
    The Create Profile page is displayed.

  5. Configure the General parameters as described in the following table.

    Table 1: General Parameters

    Parameter

    Description

    Name

    Enter the name of the port profile.

    Description

    Enter the description for the port profile.

    Device

    Select Access Point from the list.

    Admin State

    Select this check box to indicate if the port is Up or Down.

    PoE

    Select this check box to enable Power over Ethernet option.

    Speed

    Select the speed mode of the port from the drop-down list:

    • Auto
    • 10Mbps
    • 1000Mbps
    • 1Gbps
    • 10Gbps

    Duplex

    Select one of the following options from the drop-down list:

    • Auto Duplex

    • Full Duplex

    • Half Duplex

    Advanced

    Click the drop-down arrow to configure the following settings:

    • Disable Wired Port When—Select one of the following options from the drop-down list:
      • None
      • Tunnel Down
    • Spanning Tree—Select this check box to enable STP on the wired port profile. STP ensures that there are no loops in any bridged Ethernet network and operates on all downlink ports, regardless of forwarding mode. STP does not operate on uplink ports and is supported only on APs with three or more ports. By default, STP is disabled on wired port profiles.
    • Loop Protection—Select this check box to enable loop protection on the port.
    • Loop Protection Interval—Enter the time, in seconds, to configure the time interval between successive loop protect packets sent on the port.
      Default: 2
    • Auto Recovery—Select this check box to enable auto-recovery of the port in the AP that is shut down because of loop protection. After the automatic recovery, if the loop re-occurs, then the port is shutdown again.
    • Auto Recovery Interval—Enter the time, in seconds, to automatically recover the port in the AP that is shut down because of loop protection.
      Range: 30-43200
      Default: 300
    • Storm Control Broadcast—Select this check box to enable the broadcast storm control. With this parameter enabled, if the AP detects a loop on one of its Ethernet port, it shuts down that Ethernet port. This prevents the AP from receiving or sending any frames.
    • Storm Control Interval—Enter broadcast packets per second on each Ethernet of an AP before the Ethernet port is shut down.
      Default: 2000
    • Inactivity Timeout—Select this check box to configure the time duration after which an inactive user needs to be disabled from the network. The user must undergo the authentication process to re-join the network.
    • Duration—Enter the inactivity timeout duration in minutes.
  6. Configure the VLAN parameters as described in the following table.

    Table 2: VLAN Parameters

  7. Parameter

    Description

    VLAN Mode

    Select the VLAN mode from one of the following options:

    • Access—Allows the port to carry a single VLAN specified as the native VLAN.
    • Trunk—Allows the port to carry packets for multiple VLANs specified as allowed VLANs.

    Traffic Forwarding Mode

    Select the traffic forwarding mode from one of the following options:

    • Bridge—APs bridge client traffic out their uplink interface on the desired VLAN.
    • Tunnel—APs tunnel client traffic to a primary cluster on the desired VLAN.
    • Mixed—APs bridge or tunnel client traffic based on VLAN assignment.
    Note:

    Selecting Tunnel mode displays the Primary Gateway Cluster  parameter.

    Primary Gateway Cluster  

    Select a gateway cluster that you created before from the drop-down list. For more information, see Gateway Clustering Profile.

    Selecting Primary Gateway Cluster displays the Secondary Gateway Cluster  parameter.

    Secondary Gateway Cluster

    (Optional) Select a secondary gateway cluster profile from the drop-down list.

    Access VLAN

    Enter the VLAN ID to be assigned to the access interface. Only one VLAN ID can be assigned to each access interface.

    Native VLAN

    Enter the native VLAN ID to be assigned to the trunk interface.

    Allowed VLAN

    Enter the allowed VLAN ID(s) to be assigned to the trunk interface.

    Advanced

    Click the drop-down arrow to configure the VLAN assignment rules.

    VLAN Assignment Rules

    Select the rules from the VLAN Assignment Rules table.

    To create new rules, click the Add icon and configure the following parameters:

    • Attribute—Select an attribute from the drop-down list, which matches the rule. The list of supported attributes includes RADIUS attributes, dhcp-option, dot1x-authentication-type, mac-address, and mac-address-and-dhcp-options.
    • Operator—Select one of the following operators from the drop-down list:
      • Contains—The rule is applied only if the attribute value contains the string specified in the Operand.
      • Ends With—The rule is applied only if the attribute value ends with string specified in the Operand.
      • Matches Regular Expression—The rule is applied only if the attribute value matches the regular expression specified in the Operand.
      • Match Equal—The rule is applied only if the attribute value is equal to the string specified in the Operand.
      • Not Equals—The rule is applied only if the attribute value is not equal to the string specified in the Operand.
      • Starts With—The rule is applied only if the attribute value starts with the string specified in the Operand.
      • Value Of—The rule is applied only if the attribute value is a value of the string specified in the Operand.
    • Operand—Enter the operand based on the selected operator.
    • VLAN—Enter the VLAN ID.
      Range: 1 to 4093
  8. Configure the Security parameters as described in the following table.

    Table 3: Security Parameters

    Parameter

    Description

    Client Authentication Select this check box to enable client authentication.

    Security Level

    Select one of the security levels from the following options:

    • 802.1X Authentication—Select this check box to enable 802.1X authentication.

    • MAC Authentication—Select this check box to enable MAC authentication.

    • Open—Select this check box to enable authentication using the Captive Portal.

    802.1X Authentication

    Server Group

    Select a server group from the drop-down list

    Primary Server

    Select a primary server from the drop-down list. This option is enabled only when you select Primary and Secondary Only as the Server Group.

    Secondary Server

    Select a secondary server from the drop-down list. This option is enabled only when you select Primary and Secondary Only as the Server Group.

    MAC Authentication

    Select this check box to enable MAC authentication.

    MAC Fail-through

    Select this check box to enable MAC authentication fail-through. When this option is enabled, 802.1X authentication is attempted when MAC authentication fails. This option is displayed only when both MAC authentication and 802.1X authentication are enabled.

    Accounting

    Select one of the following options from the drop-down list:

    • Disable—Disables accounting.

    • Use authentication server—Uses the configured authentication servers for accounting.

    Accounting Interval

    Enter an accounting interval within the range of 0–60 minutes for sending interim accounting information to the RADIUS server.

    Advanced

    Click the drop-down arrow to configure the following parameters:

    • Client Isolation—Disables inter-client communication by allowing only client to gateway traffic from clients to flow in the network. This feature enhances the security of the network and protects it from vulnerabilities.

    • Use IP for Calling Station ID—Allows to configure client IP address as calling station ID.

    Called Station ID Type

    Select one of the following station ID type options:

    • AP Group—Uses the VC ID as the called station ID.

    • AP MAC Address—Uses the MAC address of the AP as the called station ID.

    • AP Name—Uses the host name of the AP as the called station ID.

    • IP Address—Uses the IP address of the AP as the called station ID.

    • MAC Address—Uses the MAC address of the AP as the called station ID.

    • VLAN—Uses the VLAN ID of as the called station ID.

    The Called Station ID Type can be configured even if Use IP for Calling Station ID option is disabled.

    Reauthentication Interval Enter the time, in minutes, to set the reauthentication interval.

    MAC Authentication

    Type

    Select the captive portal authentication type from the following options:

    • None

    • External Captive Portal

    Captive Portal Profile

    Select the captive portal from the drop-down list. To create a new captive portal profile, click New Captive Portal. For more information, see Captive Portal Authentication Profile.

  9. Configure the Access Roles parameters as described in the following table.

    Table 4: Access Roles Parameters

    Parameter

    Description

    Default Role

    Select a role from the drop-down list.
    To create a New Role, click New Role. For more information, see Creating a Role.

    Role Assignment Rules

    To create new role assignment rules, click the Add icon and configure the following parameters:

    • Attribute—Select an attribute from the drop-down list.
    • Operator—Select an operator from the drop-down list.
    • Operand—Enter the operand in the input field.
    • Role—Select a role from the drop-down list.
    Click Add.
  10. Click Create.

    The newly created port profile is displayed in the Port Profile list.

  11. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view. The Edit Profile page is displayed.

    2. Edit the required parameters.

    3. Click Update.

  12. To delete a port profile, hover on the profile name, and click the delete icon.

  13. To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

Note:

You cannot assign scope to a configuration created at the device level.