Port Profile for Switches
The Port Profile allows you to define a set of attributes that can be applied to multiple interfaces on a switch.
In the Port Profiles page, you can create a profile, modify profile configurations, and delete local profiles from the scope view.
A Port Profile template can be applied to a maximum of 10 interfaces at a time.
Configuration fails if port profiles with same names are created on multiple devices. For example, if a user defines port profiles with the same name on two devices, any higher-level configuration changes will not apply successfully to those devices.
Creating a Port Profile for Switches
To create a Port profile, complete the following steps:
-
In the Classic Central app, turn on the New Central toggle switch.
The HPE Aruba Networking Central landing page is displayed.
-
Click the configuration
icon.The Profiles tab is displayed.
-
In the left navigation menu, select one of the following options:
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
-
To create profiles at the Global level, select the device type as Switch from the Device Function drop-down list before step 4.
-
To create profiles at the Sites, Devices, and Device Group level, complete the following steps before step 4:
-
Select a Site Collection, Site, Device, or Device Group in the left navigation menu.
-
Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
-
Select the device type as Switch from the Device Function drop-down list.
-
-
-
On the Interfaces card, click Port Profile.
Alternatively, you can complete the following steps:
a. On the Interfaces card, click Manage.
b. On the Port Profile card, click Manage.
The Port Profile list view is displayed. -
Click Create profile.
The Create Port Profile page is displayed. -
Configure the General parameters as described in the following table.
Note:-
Changing the routing or VLAN mode settings will automatically clean up any mutually exclusive configuration items. Conflicting entries are removed to ensure the system or device remains consistent.
-
When applying configurations to AOS-S ports over NBAPI, ensure that the value of poe-max-power is between 1 and 30. Entering a value greater than 30 triggers the error message Unsatisfied range - value '31' is out of the allowed range, due to stricter validation enforcement in HPE Aruba Networking Central.
Table 1: General Parameters
Parameter
Description
Name
Enter the name of the port profile.
Description
Enter the description for the port profile.
Device
Select Switch from the list.
Admin State
Select this check box to indicate if the port is Up or Down.
Speed/Duplex
Select an option from the drop-down list.
MTU
Enter the supported range of MTU (Maximum Transmission Unit) for the interface.
PoE
Select this check box to enable Power over Ethernet option, and configure the following parameters:
-
Priority—Select the priority from the drop-down list.
-
PoE Allocation By—Select the PoE allocation mode from the drop-down list.
-
Pre-Standard Detect—Select this checkbox to enable pre-standard detection.
UDLD
In the UDLD section, configure the following parameters:
-
Enable UDLD—select this checkbox to enable Unidirectional Link Detection (UDLD).
-
Mode—Select the mode compatibility, and then the mode type from the drop-down list.
LLDP and CDP
In the LLDP and CDP section, configure the following parameters:
-
LLDP Mode—Select the Link Layer Discovery Protocol (LLDP) mode from the drop-down list.
-
Enable CDP—Select this checkbox to enable Cisco Discovery Protocol (CDP).
LAG
Enable Lag—Select this checkbox to enable LAG. If selected, configure the follow parameters as applicable:
-
LAG ID—Enter a LAG ID only if you are not selecting the Auto-generate LAG ID option.
-
LAG Admin State—Select this checkbox to set the LAG to an administrator state.
-
LAG Type—Set the LAG type to LAG or MCLAG. If the LAG type is set to LAG, the LACP Mode field is displayed.
-
LACP—Select this checkbox to enable LACP. If enabled, the Rate and LACP Fallback Static (or LACP Fallback, if the LAG type is set to MCLAG) fields are displayed.
-
LACP Mode—Select Active or Passive from the drop-down list.
-
Rate—Select Slow (default) or Fast from the drop-down list.
-
LACP Fallback Static (or LACP Fallback, if the LAG type is set to MCLAG)—Select this checkbox to enable LACP fallback.
Note: The Enable Lag checkbox will be disabled (greyed-out) for existing Port profiles that are not LAG-enabled. Converting Port profiles to LAG-enabled Port profiles and vice-versa is not supported. -
-
Configure the Network Parameters as described in the following table.
Table 2: Network Parameters
-
Access—Allows the port to carry a single VLAN specified as the native VLAN.
-
Trunk—Allows the port to carry packets for multiple VLANs specified as allowed VLANs.
-
Native VLAN—Select the native VLAN from the drop-down list.
-
Allowed VLANs—Enter the allowed VLANs.
-
If disabled, enter the max binding value in the Max Binding field.
-
If disabled, enter the max binding value in the Max Binding field.
-
Configure the Loop Prevention parameters as described in the following table.
Table 3: Loop Prevention Parameters
Parameter
Description
Loop Protection
Select this checkbox to enable loop protection, by transmitting loop protocol packets out of ports.
VLANs
Enter the VLANs to be covered under loop protection.
Action
Select the action to be performed.
STP Priority
Move the slider to set the Spanning Tree Protocol (STP) priority.
STP Cost
Enter the STP cost.
STP Options
Select the STP options as required
-
Configure the Port Security parameters as described in the following table.
Table 4: Port Security Parameters
Parameter
Description
Enable Port Security
Select this checkbox to enable the port security feature. Port security allows you to configure each switch port with a list of authorized MAC addresses, ensuring only specified devices can access the network through that port.
Note:Port Security and Port Authentication are mutually exclusive features and cannot be enabled at the same time on the same port.
Port Security is not applicable for the LAG interface.
Client Limit
Specify the maximum number of clients allowed on a port.
Security Violation
Action Select one of the following actions to define how the system should respond if the client limit is exceeded:
-
None—No action will be taken.
-
Notify—An alert is generated when the client limit is exceeded.
-
Shutdown—The affected port is immediately disabled to prevent further unauthorized access. If this option is selected, you need to configure the following parameters:
-
Enable Auto Recovery—Select the checkbox to re-enable a port that was shut down due to a security violation.
-
Recovery Interval—Specify the time period (in seconds) after which the system attempts to automatically recover the port.
-
-
-
Configure the Fault Monitoring parameters as described in the following table.
Table 5: Fault Monitoring Parameters
Parameter
Description
Enable Fault Monitoring
Select this checkbox to enable fauClt monitoring.
QoS
Select the QoS Trust type from the drop-down list. If None is selected, configure the following parameters in the QoS Remark section:
-
Enter the CoS value in the Specify CoS Value field.
-
Enter the DSCP value in the Specify DSCP Value field.
Advanced
Click the drop-down arrow to configure the following advanced parameters:
-
Shape Outbound Traffic—Select this checkbox to enable the shape outbound traffic option.
-
Unit—Select the type of unit from the drop-down list.
-
1-100—Enter a value between one and hundred.
Rate Limit
Select the rate limits as applicable, along with the unit types.
Telemetry
Configure the following parameters:
-
IP Client Tracker—Select the IP client tracker type from the drop-down list.
-
IP Tracking Client Limit—Enter the IP tracking client limit. The IP Tracking Client Limit field is disabled when the IP Client Tracker parameter is set to Disable.
-
Enable Application Recognition—Select this checkbox to enable Application Recognition and Control (ARC), to enforce traffic policies based on application types.
-
Enable Flow Telemetry for Central—Select this checkbox to enable flow telemetry on AOS-CX switches. This field is enabled by default. When enabled, the switch activates flow telemetry on the interface, configures the necessary global flow telemetry configuration, and starts sending flow telemetry information to HPE Aruba Networking Central.
The following platforms require additional SVI/ROP/Loopback configurations to enable sending flow telemetry information HPE Aruba Networking Central: 8325, 8325H, 8325P, 9300, 9300S, 10000.
The following is the sample global flow telemetry configuration pushed to the switch:
Configuration elements are subject to platform capabilities.
-
-
Click Create.
The newly created port profile is displayed in the Port Profile list.
Once a port profile is created, you can apply the Port Profile to the ports at the device level from Interfaces > Switch Interface Configuration. -
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view. The Edit Profile page is displayed.
-
Edit the required parameters.
-
Click Update.
-
To delete a port profile, hover on the profile name, and click the delete
icon. -
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
|
Parameter |
Description |
|---|---|
|
Use Switchport Alias |
Select this checkbox to use switchport alias. |
|
Alias |
Select an alias from the drop-down list. |
|
VLAN Mode |
Select the port mode from one of the following options: |
|
Access VLAN |
Select the VLAN ID to be assigned to the access interface from the drop-down list. Only one VLAN ID can be assigned to each access interface. To create a New VLAN, click New VLAN. |
|
Trunk VLAN |
Enter the following details: |
|
DHCPv4 Snooping Trust |
Select this checkbox to enable DHCP snooping for an IPv4 address. |
|
DHCPv6 Snooping Trust |
Select this checkbox to enable DHCP snooping for an IPv6 address. |
|
ARP Inspection Trust |
Select this checkbox to enable ARP inspection. |
|
IPv4 Source Lockdown |
Select the checkbox to enable IPv4 source lockdown. A tooltip appears displaying the following message: Ensure IP bindings are populated on switch by configuring DHCP snooping and static IP bindings before enabling IP source lockdown to avoid possible traffic loss. |
|
IPv6 Source Lockdown |
Select the checkbox to enable IPv6 source lockdown. A tooltip appears displaying the following message: Ensure IP bindings are populated on switch by configuring DHCP snooping and static IP bindings before enabling IP source lockdown to avoid possible traffic loss. |
You cannot assign scope to a configuration created at the device level.