Port Profile for Gateways

Physical ports on the gateways are trusted and are usually connected to internal networks by default. The untrusted ports connect to third-party APs, public areas, or other networks. When you define a physical port as untrusted, the traffic passing through that port needs to go through a predefined ACL policy.

Ports can also be classified as trusted or untrusted based on the VLAN interface associations. For example, traffic on the port is trusted only if the VLAN interface associated to that port is trusted. When a port and its associated VLANs are untrusted, any incoming and outgoing traffic must pass through a predefined ACL. For example, you can configure an Ethernet port as an untrusted access port; assign VLANs and classify them as untrusted; and designate a policy through which VLAN traffic on this port must pass. This configuration is useful if your business provides wired user guest access and you want the guest user traffic to pass through an ACL and connect to captive portal.

Creating a Port Profile for Gateways

To create a Port Profile profile for gateways, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a Port Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
      • Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
      • Select the device type from the Device Function drop-down list.

  3. On the Interfaces card, click Port Profile.
    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Port Profile card, click Manage.

    The Port Profile list view is displayed.

  4. Click Create Profile.
    The Create Profile page is displayed.

  5. Configure the Port Profile parameters as described in the following table.

    Table 1: Port Profile Parameters

    Parameter

    Description

    General

    Name

    Enter the name of the port profile.

    Description

    Enter the description for the port profile.

    Device

    Select Gateway from the Device list.

    Port Type

    Select the port type from the drop-down list.

    • Lan
    • Wan

    Admin State

    Select this check box to set the user state of the port interface as admin.

    Speed

    Select the speed mode of the port from the drop-down list:

    • Auto
    • 10Mbps
    • 1000Mbps
    • 1Gbps
    • 10Gbps

    Duplex

    Select one of the following values for duplex operation of the port:

    • Auto
    • Full
    • Half
    PoE Select this check box to set the port interface as a PoE source.
    Jumbo MTU Select this check box to enable Jumbo frame MTU configured on the interface. This setting is functional only if the Jumbo frame processing is enabled in the firewall policies.
    VLAN

    Use Switchport Alias

    Select this check box to use the Gateway Switchport alias. Select an alias from the Alias* drop-down list or click New Switchport Alias to create a new alias. For more information, see Creating an Alias.

    VLAN Mode

    Select the port mode from one of the following options:

    • Access—Select the VLAN ID assigned to the port or port channel. In ACCESS mode, VLAN Policy configuration is not applicable.
    • Trunk—Select this option to allow the LAN port to carry traffic for multiple VLANs. If you select the Trunk mode, configure a list of allowed VLANs. In TRUNK mode, Port Policy configuration is not applicable.
    Note:

    Port will be always Trusted in ACCESS and TRUNK mode.

    Access VLAN

    Select the VLAN ID to be assigned to the access interface from the drop-down list. Only one VLAN ID can be assigned to each access interface. To create a new VLAN, click New VLAN. Fore creating a new VLAN, see VLAN Profile.

    Native VLAN

    Select the untagged VLAN ID for the port or port channel from the drop-down list.

    Allowed VLANs

    Enter the range of VLAN IDs assigned to the port or port channel including the Native VLAN.

    Security

    Client Authentication

    When you select this check box, the VLANs are untrusted and you must assign an authentication policy to the selected VLANs to complete the client authentication configuration.

    Port Policy

    Select one of the security levels from the following options:

    • Inbound & Outbound—Select this check box to apply a firewall policy for the incoming and outgoing traffic.
      • Inbound Network Policy —Select a network policy for the incoming traffic from the drop-down list.

      • Outbound Network Policy—Select a network policy for the outgoing traffic from the drop-down list.

    • Per Session—Select this check box to apply a firewall policy for the session.
      • Network Policy—Select a network policy for the current session from the drop-down list.

    • None—Select this check box if you do not want to define any policy.
    Access Roles  

    Spanning Tree

    Select this check box to enable spanning tree protocol on the port.

    • Cost—Specify the spanning tree path cost of the port.
    • Priority—Specify the spanning tree priority of the port.
    • Point-to-point—Select this option to enable the port as a point-to-point link.
    • BPDU guard—Enable BPDU guard to protect the port from receiving STP BPDUs. However, the port can transmit STP BPDUs.
    • Port Fast—Select this option to enable forwarding of traffic from the port.

    LLDP Config

    Select this check box to configure the LLDP parameters:

    • LLDP Transmission—Select this check box to transmit LLDP packets.
    • Transmit Interval—Specify the interval between LLDP TLV transmission in seconds.
    • Transmit Hold—Enter a value from 1-100. This value is multiplied by the transmit interval to determine the number of seconds to cache the learned LLDP information before it is cleared. If the transmit-hold value is at the default value of 4, and the transmit interval is at its default value of 30 seconds, then the learned LLDP information is cached for 4 x 30 seconds, or 120 seconds.
    • Fast Transmit Interval—Set the LLDP fast transmission interval in seconds.
    • Fast Transmit Count—Enter a value from 1-100. This value is multiplied by the fast transmit interval to determine the number of seconds to cache the learned LLDP information before it is cleared. If the fast transmit-hold value is at the default value of 4, and the fast transmit interval is at its default value of 1 second, then the learned LLDP information is cached for 4 x 1 seconds, or 4 seconds.

    LLDP receive

    Select this check box to enable the port to receive LLDP packets.

    LLDP-MED

    Select this check box to enable LLDP-MED on the port.

  6. Click Create.

    The newly created port profile is displayed in the Port Profile list.

  7. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view. The Edit Profile page is displayed.

    2. Edit the required parameters.

    3. Click Update.

  8. To delete a port profile, hover on the profile name, and click the delete icon.

  9. To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

Assigning Scope to a Port Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.

    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the Interfaces card, click the second radio button, and then click Port Profile.

    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Port Profile card, click Manage.

    The Port Profile list view is displayed.

  4. On the Port Profile card, click Manage.

    The Port Profile list view is displayed.

  5. Hover on the profile to which you want to assign a scope and click the ellipsis icon.

  6. Select Assign.

    The Assign Profile side panel is displayed.

  7. Select the device types from Device Function list.

  8. To add a scope, click the Add icon on the Scopes table.

  9. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  10. Click Add.

    The Scopes table displays the newly added scopes.

  11. Click Assign.

    The Port Profile list displays the device functions and number of scopes assigned to the profile.

  12. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the ellipsis icon.

    2. Select Unassign.

      The Unassign pop-up window is displayed.

    3. Select the required scope and click Unassign.

  13. To customize the Port Profile list, click the Customize Columns icon . For more information, see Customizing List.