Port Profile for Switches

The Port Profile allows you to define a set of attributes that can be applied to multiple interfaces on a switch.

In the Port Profiles page, you can create a profile, modify profile configurations, and delete local profiles from the scope view.

A Port Profile template can be applied to a maximum of 10 interfaces at a time.

Note:

Configuration fails if port profiles with same names are created on multiple devices. For example, if a user defines port profiles with the same name on two devices, any higher-level configuration changes will not apply successfully to those devices.

Creating a Port Profile for Switches

To create a Port profile, complete the following steps:

  1. In the Classic Central app, turn on the New Central toggle switch.

    The HPE Aruba Networking Central landing page is displayed.

  2. Click the configuration icon.

    The Profiles tab is displayed.

  3. In the left navigation menu, select one of the following options:

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    • To create profiles at the Global level, select the device type as Switch from the Device Function drop-down list before step 4.

    • To create profiles at the Sites, Devices, and Device Group level, complete the following steps before step 4:

      • Select a Site Collection, Site, Device, or Device Group in the left navigation menu.

      • Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.

      • Select the device type as Switch from the Device Function drop-down list.

  4. On the Interfaces card, click Port Profile.

    Alternatively, you can complete the following steps:

    a. On the Interfaces card, click Manage.

    b. On the Port Profile card, click Manage.
    The Port Profile list view is displayed.

  5. Click Create profile.
    The Create Port Profile page is displayed.

  6. Configure the General parameters as described in the following table.

    Note:
    • Changing the routing or VLAN mode settings will automatically clean up any mutually exclusive configuration items. Conflicting entries are removed to ensure the system or device remains consistent.

    • When applying configurations to AOS-S ports over NBAPI, ensure that the value of poe-max-power is between 1 and 30. Entering a value greater than 30 triggers the error message Unsatisfied range - value '31' is out of the allowed range, due to stricter validation enforcement in HPE Aruba Networking Central.


    Table 1: General Parameters

    Parameter

    Description

    Name

    Enter the name of the port profile.

    Description

    Enter the description for the port profile.

    Device

    Select Switch from the list.

    Admin State

    Select this check box to indicate if the port is Up or Down.

    Speed/Duplex

    Select an option from the drop-down list.

    MTU

    Enter the supported range of MTU (Maximum Transmission Unit) for the interface.

    PoE

    Select this check box to enable Power over Ethernet option, and configure the following parameters:

    • Priority—Select the priority from the drop-down list.

    • PoE Allocation By—Select the PoE allocation mode from the drop-down list.

    • Pre-Standard Detect—Select this checkbox to enable pre-standard detection.

    UDLD

    In the UDLD section, configure the following parameters:

    • Enable UDLD—select this checkbox to enable Unidirectional Link Detection (UDLD).

    • Mode—Select the mode compatibility, and then the mode type from the drop-down list.

    LLDP and CDP

    In the LLDP and CDP section, configure the following parameters:

    • LLDP Mode—Select the Link Layer Discovery Protocol (LLDP) mode from the drop-down list.

    • Enable CDP—Select this checkbox to enable Cisco Discovery Protocol (CDP).

    LAG

    Enable Lag—Select this checkbox to enable LAG. If selected, configure the follow parameters as applicable:

    • LAG ID—Enter a LAG ID only if you are not selecting the Auto-generate LAG ID option.

    • LAG Admin State—Select this checkbox to set the LAG to an administrator state.

    • LAG Type—Set the LAG type to LAG or MCLAG. If the LAG type is set to LAG, the LACP Mode field is displayed.

    • LACP—Select this checkbox to enable LACP. If enabled, the Rate and LACP Fallback Static (or LACP Fallback, if the LAG type is set to MCLAG) fields are displayed.

    • LACP Mode—Select Active or Passive from the drop-down list.

    • Rate—Select Slow (default) or Fast from the drop-down list.

    • LACP Fallback Static (or LACP Fallback, if the LAG type is set to MCLAG)—Select this checkbox to enable LACP fallback.

    Note: The Enable Lag checkbox will be disabled (greyed-out) for existing Port profiles that are not LAG-enabled. Converting Port profiles to LAG-enabled Port profiles and vice-versa is not supported.
  7. Configure the Network Parameters as described in the following table.

    Table 2: Network Parameters

  8. Parameter

    Description

    Use Switchport Alias

    Select this checkbox to use switchport alias.

    Alias

    Select an alias from the drop-down list.

    VLAN Mode

    Select the port mode from one of the following options:

    • Access—Allows the port to carry a single VLAN specified as the native VLAN.

    • Trunk—Allows the port to carry packets for multiple VLANs specified as allowed VLANs.

    Access VLAN

    Select the VLAN ID to be assigned to the access interface from the drop-down list. Only one VLAN ID can be assigned to each access interface. To create a New VLAN, click New VLAN.

    Trunk VLAN

    Enter the following details:

    • Native VLAN—Select the native VLAN from the drop-down list.

    • Allowed VLANs—Enter the allowed VLANs.

    DHCPv4 Snooping Trust

    Select this checkbox to enable DHCP snooping for an IPv4 address.

    • If disabled, enter the max binding value in the Max Binding field.

    DHCPv6 Snooping Trust

    Select this checkbox to enable DHCP snooping for an IPv6 address.

    • If disabled, enter the max binding value in the Max Binding field.

    ARP Inspection Trust

    Select this checkbox to enable ARP inspection.

    IPv4 Source Lockdown

    Select the checkbox to enable IPv4 source lockdown. A tooltip appears displaying the following message: Ensure IP bindings are populated on switch by configuring DHCP snooping and static IP bindings before enabling IP source lockdown to avoid possible traffic loss.

    IPv6 Source Lockdown

    Select the checkbox to enable IPv6 source lockdown. A tooltip appears displaying the following message: Ensure IP bindings are populated on switch by configuring DHCP snooping and static IP bindings before enabling IP source lockdown to avoid possible traffic loss.

  9. Configure the Loop Prevention parameters as described in the following table.

    Table 3: Loop Prevention Parameters

    Parameter

    Description

    Loop Protection

    Select this checkbox to enable loop protection, by transmitting loop protocol packets out of ports.

    VLANs

    Enter the VLANs to be covered under loop protection.

    Action

    Select the action to be performed.

    STP Priority

    Move the slider to set the Spanning Tree Protocol (STP) priority.

    STP Cost

    Enter the STP cost.

    STP Options

    Select the STP options as required

  10. Configure the Port Security parameters as described in the following table.

    Table 4: Port Security Parameters

    Parameter

    Description

    Enable Port Security

    Select this checkbox to enable the port security feature. Port security allows you to configure each switch port with a list of authorized MAC addresses, ensuring only specified devices can access the network through that port.

    Note:

    Port Security and Port Authentication are mutually exclusive features and cannot be enabled at the same time on the same port.

    Port Security is not applicable for the LAG interface.

    Client Limit

    Specify the maximum number of clients allowed on a port.

    Security Violation

    Action

    Select one of the following actions to define how the system should respond if the client limit is exceeded:

    • None—No action will be taken.

    • Notify—An alert is generated when the client limit is exceeded.

    • Shutdown—The affected port is immediately disabled to prevent further unauthorized access. If this option is selected, you need to configure the following parameters:

      • Enable Auto Recovery—Select the checkbox to re-enable a port that was shut down due to a security violation.

      • Recovery Interval—Specify the time period (in seconds) after which the system attempts to automatically recover the port.

  11. Configure the Fault Monitoring parameters as described in the following table.

    Table 5: Fault Monitoring Parameters

    Parameter

    Description

    Enable Fault Monitoring

    Select this checkbox to enable fauClt monitoring.


    QoS

    Select the QoS Trust type from the drop-down list. If None is selected, configure the following parameters in the QoS Remark section:

    • Enter the CoS value in the Specify CoS Value field.

    • Enter the DSCP value in the Specify DSCP Value field.

    Advanced

    Click the drop-down arrow to configure the following advanced parameters:

    • Shape Outbound Traffic—Select this checkbox to enable the shape outbound traffic option.

    • Unit—Select the type of unit from the drop-down list.

    • 1-100—Enter a value between one and hundred.

    Rate Limit

    Select the rate limits as applicable, along with the unit types.

    Telemetry

    Configure the following parameters:

    • IP Client Tracker—Select the IP client tracker type from the drop-down list.

    • IP Tracking Client Limit—Enter the IP tracking client limit. The IP Tracking Client Limit field is disabled when the IP Client Tracker parameter is set to Disable.

    • Enable Application Recognition—Select this checkbox to enable Application Recognition and Control (ARC), to enforce traffic policies based on application types.

    • Enable Flow Telemetry for Central—Select this checkbox to enable flow telemetry on AOS-CX switches. This field is enabled by default. When enabled, the switch activates flow telemetry on the interface, configures the necessary global flow telemetry configuration, and starts sending flow telemetry information to HPE Aruba Networking Central.

      The following platforms require additional SVI/ROP/Loopback configurations to enable sending flow telemetry information HPE Aruba Networking Central: 8325, 8325H, 8325P, 9300, 9300S, 10000.

      The following is the sample global flow telemetry configuration pushed to the switch:

      Configuration elements are subject to platform capabilities.

      Sample Configuration:Closed
      flow record sys_cx_record_v4_default description Default IPv4 Flow Record used in telemetry config match ip destination address match ip protocol match ip source address match ip version match transport destination port match transport source port collect application dns response-code collect application https url collect application name collect counter bytes collect counter packets collect datalink mac destination address in collect datalink mac source address in collect egress interface collect egress queue collect egress vlan collect forwarding-status collect ingress interface collect timestamp absolute first collect timestamp absolute last flow record sys_cx_record_v6_default description Default IPv6 Flow Record used in telemetry config match ipv6 destination address match ipv6 protocol match ipv6 source address match ipv6 version match transport destination port match transport source port collect application dns response-code collect application https url collect application name collect counter bytes collect counter packets collect datalink mac destination address in collect datalink mac source address in collect egress interface collect egress queue collect egress vlan collect forwarding-status collect ingress interface collect timestamp absolute first collect timestamp absolute last flow exporter sys_cx_exporter_local_default description Default Flow Exporter with internal destination used in telemetry confi destination traffic-insight sys_cx_ti_instance_default destination type traffic-insight export-protocol ipfix template data timeout 60 flow monitor sys_cx_monitor_v4_default description Default IPv4 Flow Monitor used in telemetry config record sys_cx_record_v4_default exporter sys_cx_exporter_local_default cache timeout active 1800 cache timeout inactive 30 flow monitor sys_cx_monitor_v6_default description Default IPv6 Flow Monitor used in telemetry config record sys_cx_record_v6_default exporter sys_cx_exporter_local_default cache timeout active 1800 cache timeout inactive 30 traffic-insight sys_cx_ti_instance_default enable source ipfix monitor sys_cx_application_monitor_default type application-flows monitor sys_cx_raw_monitor_default type raw-flows monitor sys_cx_dns_average_latency_default type dns-average-latency monitor sys_cx_dns_onboard_latency_default type dns-onboarding-latency Interface 1/1/X ip flow monitor sys_cx_monitor_v4_default in ipv6 flow monitor sys_cx_monitor_v6_default in

  12. Click Create.

    The newly created port profile is displayed in the Port Profile list.
    Once a port profile is created, you can apply the Port Profile to the ports at the device level from Interfaces > Switch Interface Configuration.

  13. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view. The Edit Profile page is displayed.

    2. Edit the required parameters.

    3. Click Update.

  14. To delete a port profile, hover on the profile name, and click the delete icon.

  15. To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

Note:

You cannot assign scope to a configuration created at the device level.