Switch Interface Configuration Profile
The Switch Interface Configuration profile card allows you to view all the ports, configure Link Aggregation Groups (LAG), and modify port settings for AOS-CX
Link aggregation has the following benefits:
-
Increased bandwidth beyond the limits of single link. In an aggregate link, traffic is distributed across the member ports.
-
Improved link reliability. The member ports dynamically back up one another. When a member port fails, its traffic is automatically switched to other member ports.
You can add, modify, or delete LAGs and also modify port settings in HPE Aruba Networking Central.
Split Ports
Split ports provide the ability to divide a single high‑speed physical port into multiple lower‑speed logical ports, offering greater flexibility in network design.
This feature is commonly used to split interfaces such as 40G or 100G into smaller links. For example, a 40G port can be divided into four 10G links, while a 100G port can be divided into four 25G links.
It is particularly useful for optimizing port utilization in environments where breakout cables are used.
By splitting a port, users can configure and manage each child interface independently, enabling greater flexibility, and efficiency in network design.
The following are the key capabilities of split ports:
-
Enable or disable split‑port functionality on supported parent ports through the UI.
-
Update split‑port speed and count dynamically as needed.
-
Configure individual child‑port attributes directly through the UI after splitting.
Configuring Split Ports
To configure split ports, complete the following steps:
-
Select the port that you want to split.
-
Under Actions, click Split Interface.
The Split Port side panel is displayed.
-
Select the split count from Split Count. The available options are 2, 4, and 8.
-
Select the speed from the Speed drop‑down list. The available speeds are 10 Gbps, 25 Gbps, 50 Gbps, 100 Gbps, and 200 Gbps.
-
Click Split.
The parent port is split based on the selected split count.
Configuring LAG
To configure a LAG for ports, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.The Profiles tab is displayed.
-
In the left navigation menu, select Devices.
The Devices list view is displayed.
-
Select a switch from the list.
The Profiles Management view for the selected switch is displayed.
-
On the Interfaces card, click Switch Interface Configuration.
-
Alternatively, you can complete the following steps:
-
On the Interfaces card, click Manage.
-
On the Switch Interface Configuration card, click Manage.
The Switch Interface Configuration list view is displayed. Additionally, the Switch Interface Configuration page displays the faceplate representation of the selected switch.
-
-
Under the LAGs tab, click Create LAG.
The Create LAG form is displayed in the side panel. -
Configure the Switch Interface Configuration parameters as described in the following table.
Note:Changing the routing or VLAN mode settings will automatically clean up any mutually exclusive configuration items. Conflicting entries are removed to ensure the system or device remains consistent.
-
When mapping a LAG to a Port profile, ensure that the entered LAG ID matches the LAG ID added in the Port profile.
-
When selecting a LAG enabled Port profile, the LAG ID is populated automatically. If a LAG ID is entered manually, only the Port profiles matching that LAG ID are displayed in the drop-down list.
-
A LAG enabled Port profile cannot be applied if the corresponding LAG ID already exists.
-
Multiple LAG enabled Port profiles using the same LAG ID cannot be mapped.
For example - if a Port profile with LAG ID "10" is currently mapped to interfaces 1 and 2, then a second Port profile, also with LAG ID "10" cannot be mapped to interfaces 3 and 4 for the same device.
New LAG profiles using existing LAG IDs will overwrite the old profiles.
-
LAG enabled Port profiles cannot be applied to Ethernet interfaces that are already a part of a LAG created at the device scope.
-
Port Profile (LAG Enabled)—Select the LAG-enabled Port profile to be assigned, from the drop-down list. For more information on Port profiles, see Port Profile for Switches.
- LAG
- MCLAG
- LACP Active—When the LACP is operating in active mode on either end of a link, both ports can send Protocol Data Units (PDUs). The active LACP initiates an LACP connection by sending LACPDUs.
- LACP Passive—When the LACP is operating in passive mode on a local member port and its peer port, both ports cannot send PDUs. The passive LACP will wait for the remote end to initiate the link.
- Static—In the static LAG mode of operation, link failure is not detected as there is no keep alive PDU communication between the devices. A misconfiguration on one side can cause much trouble and be difficult to troubleshoot, because no signaling takes place between the two peers.
- Access—Port carries traffic only for the VLAN to which it is assigned.
- Trunk—Port can carry traffic for multiple VLANs.
- IPv4
- IPv6
- Helper address—Enter the helper IP address of the DHCP server in IPv4 format.
- Use Custom VRF—Select this checkbox to configure a VRF.
- VRF—Select the VRF from the drop-down list. To add a new VRF, click New VRF Profile from the drop-down list.
- Helper address—Enter the helper IP address of the DHCP server in IPv6 format.
- VLAN—Select the VLANs from the drop-down list. To add a new VLAN, click New VLAN from the drop-down list.
- Interface—Select the interfaces from the drop-down list.
- LAG—Select the LAGs from the drop-down list.
-
IGMP Version—Select the IGMP version.
-
Enable Strict Version Match—Select this checkbox to enable strict version matching.
-
Static Groups—Enter the IP address of a static group, and click the add
icon. -
Set ACL to Filter IGMP Packets—Select this checkbox to filter IGMP packets. If selected, select an access list from the Access List drop-down menu.
-
Enable Querier—Select this checkbox to enable the querier.
-
Querier Interval—Enter the querier interval.
-
Last Member Query Interval—Enter the last member querier interval.
-
Max Response Time—Enter the maximum response time.
-
MLD Version—Select the MLD version.
-
Enable Strict Version Match—Select this checkbox to enable strict version matching.
-
Static Groups—Enter the IP address of a static group, and click the add
icon. -
Set ACL to Filter MLD Packets—Select this checkbox to filter MLD packets. If selected, select an access list from the Access List drop-down menu.
-
Enable Querier—Select this checkbox to enable the querier.
-
Querier Interval—Enter the querier interval.
-
Last Member Query Interval—Enter the last member querier interval.
-
Max Response Time—Enter the maximum response time.
- Critical
- High
- Low
- Usage—Allocation is made based on the automatic allocation by the powered device.
- Class—Allocation is made based on class of the powered device.
- PIM Dense—Uses dense multicast routing.
- PIM Sparse—Uses sparse multicast routing.
- PIM BiDir—Uses bidirectional multicast routing. This mode is not applicable for PIM6.
- Disabled—Disables the PIM mode.
- Hello Interval—Specify the frequency at which the router transmits PIM hello messages on the interface.
- Override Interval—Specify the override interval that gets inserted into the Override Interval field of a LAN prune delay option.
- Propagation Delay—Specify the propagation delay that gets inserted into the LAN prune delay field of a LAN Prune Delay option.
- Enable LAN Prune Delay—Select the checkbox to enable LAN prune delay on the interface. With this enabled, the router informs downstream neighbors how long it will wait before pruning a flow after receiving a prune request.
- Do not disable—No ports are disabled. On every transmit interval, the loop will be detected and the detection will be reported via an SNMP trap and an event log message.
- Receive disable—The port that received the loop detection packet is disabled. This option is available only for AOS-S switches.
- Transmit disable—The port that transmitted the loop detection packet is disabled. When this setting is enabled, environments with N loops, must have loop protection configured on at least N-1 ports to have a loop free topology.
- Transmit and receive disable—The ports that transmitted and received the loop detection packet are disabled.
- BPDU Filter—Enables control of STP participation for each LAG. The feature can be used to exclude specific ports from becoming part of STP operations. A LAG with the BPDU filter enabled ignores incoming BPDU packets and stays locked in the STP forwarding state.
- BPDU Guard—Security feature used to protect the active STP topology by preventing manipulated BPDU packets from entering the STP domain.
- Admin Edge—Configures the interface in the forwarding state. If Admin edge is not configured on the switch, the default port type is admin-network.
- Root Guard—Configures the interface to prevent from being configured as a root port when it receives superior STP BPDUs.
-
Click Create.
The Switch Interface Configuration list displays the newly created LAG ID in the LAG column.
-
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
|
Parameter |
Description |
|---|---|
|
General |
To configure additional ports for LAG, click the Add |
|
LAG ID |
Enter the LAG ID for the interface. Range for AOS-CX: 1 to 480. The range for LAG ID varies for different AOS-CX platforms. Range for AOS-S: 1 to 144. Important points |
|
Description |
Enter the description for the LAG. This parameter is available only for AOS-CX switches. |
|
Use Port Profile |
Select this checkbox to assign the LAG to a LAG-enabled Port profile. If selected, configure the following parameter: Note: Selecting the Use Port Profile checkbox disables the remaining fields listed in this table.
This parameter is available only for AOS-CX switches. |
|
Enable |
Select this checkbox to enable the administrative state for the member interface. This is enabled by default. This parameter is available only for AOS-CX switches. |
| Type |
Select the type as one of the following: |
|
Mode |
Select operational mode of Link Aggregation Control Protocol (LACP) from one of the following options: |
|
Network Parameters |
|
|
VLAN Mode |
Select one of the following as the operation mode of the VLAN: |
| Routing |
Select this check box to enable routing. This parameter is available only for AOS-CX switches. Enabling routing mode automatically removes any interface configuration that is not compatible with it. On an unsupported device, it could cause unexpected changes to the interface profiles. |
| Select IP Versions |
Select one or both of the following IP versions: |
|
IPv4 Address |
Enter a valid network or device IPv4 address with subnet mask in the x.x.x.x/M format, where x is an integer from 0 to 255, and /M is the subnet mask. This parameter is displayed if you select IPv4 version. |
|
IPv6 Address |
Enter a valid network or device IPv6 address in the xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx/M format, where x is a hexadecimal number from 0 to F, and /M is the subnet mask. This parameter is displayed if you select IPv6 version. |
| VRF |
Select a VRF profile from the drop-down list. To create a new VRF profile, click New VRF Profile. For more information, see VRF Profile. |
|
IP MTU |
Enter the IP MTU (maximum transmission unit) for an interface. This defines the largest IP packet that can be sent or received by the interface. The default value is 1500. |
|
DHCPV4 Helper address |
Specify the DCHCPv4 helper addresses of a remote DHCP server or DHCP relay agent. You can add up to eight helper addresses. The DHCP relay agent forwards DHCP client requests to all configured servers. To add
DHCPv4 helper addresses , click the add |
|
IPV6 Unicast DHCP Helper |
Enter the DCHCPv6 unicast helper addresses of a remote DHCPv6 server or DHCPv6 relay agent. You can add up to eight helper addresses. The DHCPv6 relay agent forwards DHCP client requests to all configured servers. |
|
IPV6 Multicast DHCP Helper |
Enter the DCHCPv6 multicast helper addresses of a remote DHCPv6 server or DHCPv6 relay agent. You can add up to eight helper addresses. The DHCPv6 relay agent forwards DHCP client requests to all configured servers. To add
DHCPv6 multicast helper addresses , click the add |
|
Egress for all multicast DHCP server |
Select this checkbox to permit egress traffic for all multicast DHCP servers and configure the interfaces from the drop-down list. |
|
VRRP Router |
Select a VRRP Router profile to be assigned from the drop-down list. |
|
IGMP |
Select the Enable IGMP checkbox to enable Internet Group Management Protocol (IGMP). To configure advanced IGMP parameters, click the Advanced Parameters drop-down arrow, and configure the following: |
|
MLD |
Select the Enable MLD checkbox to enable Multicast Listener Discovery (MLD). To configure advanced MLD parameters, click the Advanced Parameters drop-down arrow, and configure the following: |
|
Access VLAN |
Select a VLAN from the drop-down list. This option is displayed if you select Access as the VLAN Mode. To create new VLAN, click New VLAN. For more information, see VLAN Profile. |
|
Native VLAN |
Select a native VLAN from the drop-down list. This option is displayed if you select Trunk as the VLAN Mode. |
|
Allowed VLANs |
Enter the VLANs or VLAN range. This option is displayed if you select Trunk as the VLAN Mode. Example: 1, 2-4. |
|
DHCPv4 Snooping Trust |
Select this check box to enable DHCPv4 snooping trust. |
|
DHCPv6 Snooping Trust |
Select this check box to enable DHCPv6 snooping trust. |
|
ARP Inspection Trust |
Select this check box to enable ARP Inspection trust. |
| Block Port Until Device Profile Active |
Select this check box to block the port until a profile match occurs for a device. This configuration is required when no security feature is enabled on the port. This parameter is available only when Routing is disabled for the port. |
|
Enable PoE |
Select this option to enable PoE, so that the switch sends power to the powered device. |
|
Priority |
Select the PoE priority level of the port from the following options: If there is not enough power available to provision all active PoE ports, then PoE ports at priority level as critical are powered first, then high, and low priority at the last. |
|
PoE Allocation By |
Select the PoE power allocation method used for the port from one of the following options: |
|
PIM or PIM6 |
|
|
PIM Mode |
Select the PIM mode from the drop-down list: |
|
Enable PIM or Enable PIM6 |
Select the checkbox to enable the PIM routing. |
|
Enable BFD |
Select this checkbox to enable Bidirectional Forwarding Detection (BFD). |
| Advanced Parameters |
Configure the following advanced parameters: |
|
Echo |
Enable or Disable support for BFD echo packets using the check box. Echo packet support is enabled by default. With Echo enabled, an operating device periodically sends BFD echo packets. The peer device returns the received BFD echo packets back without processing them. If the sending device does not receive BFD echo packet from the peer within the specified interval, the session is considered down. |
|
Action |
Select the action to be taken when a loop protection packet is received on a port: |
|
STP Options |
Select the check box to enable the following options: |
Editing a LAG
To edit a LAG mapped to a Port profile compete the following steps:
-
In the Switch Interface Configuration list view, click the LAGs tab.
-
Select a LAG in the list view that has an assigned Port profile.
The Edit LAG side panel is displayed.
-
Un-check the Use Port Profile checkbox.
The Port Profile configuration pop-up is displayed
-
Select any one of the following options:
-
Preserve—Un-maps the Port profile from the LAG and member ports, while retaining the LAG and Port Profile configurations.
-
Reset—Deletes the LAG and all LAG-Port Profile, and Port Profile configurations from the member ports.
-
Cancel—Cancels the operation without performing any changes.
-
-
Click Save.
Deleting a LAG
A LAG that has a Port profile assigned cannot be deleted.
To delete a LAG, complete the following steps:
-
In the Switch Interface Configuration list view, click the LAGs tab.
-
Hover over LAG in the list view, and click the
icon. -
Click Delete LAG.
The Delete LAG dialog is displayed. -
Click Delete.
Editing Port Settings
To edit port settings, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select Devices.
The Devices list view is displayed.
-
Select a switch from the list.
The Profiles Management view for the selected switch is displayed.
-
On the Interfaces card, click Switch Interface Configuration.
-
Alternatively, you can complete the following steps:
-
On the Interfaces card, click Manage.
-
On the Switch Interface Configuration card, click Manage.
The Switch Interface Configuration list view is displayed. Additionally, the Switch Interface Configuration page displays the faceplate representation of the selected switch.
-
-
Click the check box in the Port column or click anywhere on the row of the port you want to modify.
The Configure Interface side panel is displayed. -
Configure the port parameters as described in the following table.
Note:-
Changing the routing or VLAN mode settings will automatically clean up any mutually exclusive configuration items. Conflicting entries are removed to ensure the system or device remains consistent.
-
When the Port Profile is removed with Reset to defaults option, the system will not remove port security related parameters, such as sticky-mac-enable, macs, and sticky-macs.
Parameter
Description
Port
Displays the selected port number.
Description
Enter the description for the port.
Use Port Profile
Select this checkbox to assign a LAG-enabled Port profile. If selected, configure the following parameter:
-
Port Profile—Select the Port profile to be assigned from the drop-down list, or click New Port Profile to create a new port profile. For more information on Port profiles, see Port Profile for Switches.
Note: Selecting the Use Port Profile checkbox disables the remaining fields listed in this table.Unselect this checkbox to unassign a LAG-enabled Port profile. Once unselected, configure the following parameter:
-
Reset to Default—When the port profile is unselected for the port, it deletes the port profile configurations for the member port, resets it to default, and:
-
Retains the LAG if multiple ports are associated to the LAG port profile. (or)
-
Deletes the LAG and its related configurations if a single port is associated to the LAG port profile.
-
-
Cancel—Cancels the operation without performing any changes.
Note: From the Ports tab, only the Reset to Default operation is supported. The Preserve operation is not supported.This parameter is available only for AOS-CX switches.
Port Profile
Select a port profile from the drop-down list.
Enable Port
Select the check box to enable the port.
Speed Duplex
Select the speed and duplex configuration for the client traffic from the drop-down list.
Default: Auto for AOS-S switches.
MTU Enter the maximum transmission unit for the port interface. This defines the maximum size of a layer 2 (Ethernet) frame. To support jumbo frames (frames larger than 1522 bytes), increase the MTU as required by your network. A frame size of up to 9198 bytes is supported.
This parameter is available only for AOS-CX switches.Network Parameters
Routing Select this check box to enable routing.
This parameter is available only for AOS-CX switches.
Enabling routing mode automatically removes any interface configuration that is not compatible with it. On an unsupported device, it could cause unexpected changes to the interface profiles.
Select IP Versions Select one or both of the following IP versions:
- IPv4
- IPv6
IPv4 Address Enter a valid network or device IPv4 address with subnet mask in the x.x.x.x/M format, where x is an integer from 0 to 255, and /M is the subnet mask.
This parameter is displayed if you select IPv4 version.IPv6 Address Enter a valid network or device IPv6 address in the xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx/M format, where x is a hexadecimal number from 0 to F, and /M is the subnet mask.
This parameter is displayed if you select IPv6 version.VRF Select a VRF profile from the drop-down list.
To create a new VRF profile, click New VRF Profile. For more information, see VRF Profile.
IP MTU
Enter the IP MTU (maximum transmission unit) for an interface. This defines the largest IP packet that can be sent or received by the interface. The default value is 1500.
DHCPV4 Helper address
Specify the DCHCPv4 helper addresses of a remote DHCP server or DHCP relay agent. You can add up to eight helper addresses. The DHCP relay agent forwards DHCP client requests to all configured servers.
To add DHCPv4 helper addresses , click the add
icon and configure the following parameters:- Helper address—Enter the helper IP address of the DHCP server in IPv4 format.
- Use Custom VRF—Select this checkbox to configure a VRF.
- VRF—Select the VRF from the drop-down list. To add a new VRF, click New VRF Profile from the drop-down list.
IPV6 Unicast DHCP Helper
Specify the DCHCPv6 unicast helper addresses of a remote DHCPv6 server or DHCPv6 relay agent. You can add up to eight helper addresses. The DHCPv6 relay agent forwards DHCP client requests to all configured servers.
IPV6 Multicast DHCP Helper
Specify the DCHCPv6 multicast helper addresses of a remote DHCPv6 server or DHCPv6 relay agent. You can add up to eight helper addresses. The DHCPv6 relay agent forwards DHCP client requests to all configured servers.
To add DHCPv6 multicast helper addresses , click the add
icon and configure the following parameters:- Helper address—Enter the helper IP address of the DHCP server in IPv6 format.
- VLAN—Select one or more VLANs from the drop-down list. To add a new VLAN, click New VLAN from the drop-down list.
- Interface—Select the interfaces from the drop-down list.
- LAG—Select one more LAGs from the drop-down list.
VRRP Router
Select a VRRP Router profile to be assigned from the drop-down list.
IGMP
Select the Enable IGMP checkbox to enable Internet Group Management Protocol (IGMP).
To configure advanced IGMP parameters, click the Advanced Parameters drop-down arrow, and configure the following:
-
IGMP Version—Select the IGMP version.
-
Enable Strict Version Match—Select this checkbox to enable strict version matching.
-
Static Groups—Enter the IP address of a static group, and click the add
icon. -
Set ACL to Filter IGMP Packets—Select this checkbox to filter IGMP packets. If selected, select an access list from the Access List drop-down menu.
-
Enable Querier—Select this checkbox to enable the querier.
-
Querier Interval—Enter the querier interval.
-
Last Member Query Interval—Enter the last member querier interval.
-
Max Response Time—Enter the maximum response time.
MLD
Select the Enable MLD checkbox to enable Multicast Listener Discovery (MLD).
To configure advanced MLDparameters, click the Advanced Parameters drop-down arrow, and configure the following:
-
MLD Version—Select the MLD version.
-
Enable Strict Version Match—Select this checkbox to enable strict version matching.
-
Static Groups—Enter the IP address of a static group, and click the add
icon. -
Set ACL to Filter MLD Packets—Select this checkbox to filter MLD packets. If selected, select an access list from the Access List drop-down menu.
-
Enable Querier—Select this checkbox to enable the querier.
-
Querier Interval—Enter the querier interval.
-
Last Member Query Interval—Enter the last member querier interval.
-
Max Response Time—Enter the maximum response time.
Advanced Parameters
Select this check box to configure Bidirectional Forwarding Detection (BFD) parameters. BFD parameters are displayed only when Routing is enabled.
BFD
Detection Multiplier
Specify the BFD detection multiplier. Range: 1 to 5. Minimum Transmit Interval
Specify the minimum time interval between transmitted BFD control packets on an interface in milliseconds. Range: 500 to 20000 (For 6300, 6400, 8360, and 8400 switch series) and 50 to 20000 (For 8320 and 8325 switch series).
Minimum Receive Interval
Specify the minimum time interval between received BFD control packets on an interface in milliseconds. Range: 500 to 20000 (For 6300, 6400, 8360, and 8400 switch series) and 50 to 20000 (For 8320 and 8325 switch series).
Echo
Enable or Disable support for BFD echo packets using the check box. Echo packet support is enabled by default. In Echo mode, an operating device periodically sends BFD echo packets. The peer device returns the received BFD echo packets back without processing them. If the sending device does not receive BFD echo packet from the peer within the specified interval, the session is considered down.
PIM or PIM6
PIM Mode
Select the PIM mode from the drop-down list:
- PIM Dense—Uses dense multicast routing.
- PIM Sparse—Uses sparse multicast routing.
- PIM BiDir—Uses bidirectional multicast routing. This mode is not applicable for PIM6.
- Disabled—Disables the PIM mode.
Enable PIM or Enable PIM6
Select the checkbox to enable the PIM routing. Enable BFD
Select this checkbox to enable Bidirectional Forwarding Detection (BFD). Advanced Parameters Configure the following advanced parameters:
- Hello Interval—Specify the frequency at which the router transmits PIM hello messages on the interface.
- Override Interval—Specify the override interval that gets inserted into the Override Interval field of a LAN prune delay option.
- Propagation Delay—Specify the propagation delay that gets inserted into the LAN prune delay field of a LAN Prune Delay option.
- Enable LAN Prune Delay—Select the checkbox to enable LAN prune delay on the interface. With this enabled, the router informs downstream neighbors how long it will wait before pruning a flow after receiving a prune request.
Policies
Policy
Select a policy from one of the following options:
- Inbound—Controls the incoming traffic on the selected port.
- Outbound—Controls the outgoing traffic on the selected port.
- Inbound & Outbound—Controls the incoming and outgoing traffic on the selected port.
Inbound Network Policy
Select a policy from the drop-down list. This option is displayed if you select Inbound or Inbound & Outbound in the Policy drop-down list.
Outbound Network Policy
Select a policy from the drop-down list. This option is displayed if you select Outbound or Inbound & Outbound in the Policy drop-down list.
Access List
Select this checkbox to add an Access List (ACL). The Access List drop-down list is displayed. Select a policy from one of the following options:
- Inbound—Controls the incoming traffic on the selected port.
- Outbound—Controls the outgoing traffic on the selected port.
- Inbound & Outbound—Controls the incoming and outgoing traffic on the selected port.
Inbound Access List
Select a access list from the drop-down list. This option is displayed if you select Inbound or Inbound & Outbound in the Policy drop-down list.
To create a New Access List, select New Access List from the drop-down list.
Outbound Access List
Select a access list from the drop-down list. This option is displayed if you select Outbound or Inbound & Outbound in the Policy drop-down list.
To create a New Access List, select New Access List from the drop-down list.
Allowed VLANs
Enter the VLANs or VLAN range.
Example: 1, 2-4.
DHCPv4 Snooping Trust
Select this check box to enable DHCPv4 snooping trust.
DHCPv6 Snooping Trust
Select this check box to enable DHCPv6 snooping trust.
ARP Inspection Trust
Select this check box to enable ARP Inspection trust.
Block Port Until Device Profile Active Select this check box to block the port until a profile match occurs for a device. This configuration is required when no security feature is enabled on the port.
This parameter is available only when Routing is not enabled for the port.PoE
Enable PoE
Select this option to enable PoE, so that the switch sends power to the powered device.
Priority
Select the PoE priority level of the port from the following options:
- Critical
- High
- Low
If there is not enough power available to provision all active PoE ports, then PoE ports at priority level as critical are powered first, then high, and low priority at the last.
PoE Allocation By
Select the PoE power allocation method used for the port from one of the following options:
- Usage—Allocation is made based on the automatic allocation by the powered device.
- Class—Allocation is made based on class of the powered device.
Loop Prevention
Loop Protection
Select this check box to enable loop protection.
Action
Select the action to be taken when a loop protection packet is received on a port:
- Do not disable—No ports are disabled. On every transmit interval, the loop will be detected and the detection will be reported via an SNMP trap and an event log message.
- Receive disable—The port that received the loop detection packet is disabled. This option is available only for AOS-S switches.
- Transmit disable—The port that transmitted the loop detection packet is disabled. When this setting is enabled, environments with N loops, must have loop protection configured on at least N-1 ports to have a loop free topology.
- Transmit and receive disable—The ports that transmitted and received the loop detection packet are disabled.
STP Options
Select the check box to enable the following options:
- BPDU Filter—Enables control of STP participation for each LAG. The feature can be used to exclude specific ports from becoming part of STP operations. A LAG with the BPDU filter enabled ignores incoming BPDU packets and stays locked in the STP forwarding state.
- BPDU Guard—Security feature used to protect the active STP topology by preventing manipulated BPDU packets from entering the STP domain.
- Admin Edge—Configures the interface in the forwarding state. If Admin edge is not configured on the switch, the default port type is admin-network.
- Root Guard—Configures the interface to prevent from being configured as a root port when it receives superior STP BPDUs.
Authentication
Authentication Protocol
Select an authentication protocol from the following options:
- 802.1X
- MAC
- 802.1X then MAC
- MAC then 802.1X
- Concurrent
Client Limit
The maximum number of clients to allow on the port.
802.1X Parameters
Max Authentication Failure
Number of times a user can try to log in with wrong credentials after which the user is blacklisted as a security threat. Enter a non-zero integer to blacklist the user after the specified number of failures.
Range: 1-10 failures.
Reauthentication
Select this check box to enable reauthentication.
Reauthentication Interval
Interval, in seconds, between reauthentication attempts.
Cached Reauthentication
Select the check box to enable client authentication for the configured cached reauth period.
Cached Reauthentication Period
Enter the time (in seconds) when cached re-authentication is allowed on the port.
Discovery Period
Enter the period the port waits to retransmit the next EAPOL request identity frame on an 802.1X enabled port that has no authenticated clients.
EAPOL Timeout
Enter the time period (in seconds) to wait for a response from an authenticator before reattempting authentication.
Max EAPOL Requests
Enter the number of EAPOL requests to send to a supplicant that must time out before authentication fails and the authentication session ends.
Quiet Period
Enter the period during which the port does not try to acquire a supplicant. This period begins after the last authentication attempt, authorized by the maximum retries parameter, fails.
MAC Parameters
Max Authentication Failure
Number of times a user can try to log in with wrong credentials after which the user is blacklisted as a security threat. Enter a non-zero integer to blacklist the user after the specified number of failures.
Range: 1-10 failures.
Reauthentication
Select this check box to enable reauthentication.
Reauthentication Interval
Interval, in seconds, between reauthentication attempts.
Cached Reauthentication
Select the check box to enable client authentication for the configured cached reauth period.
Cached Reauthentication Period
Enter the time (in seconds) when cached re-authentication is allowed on the port.
Fault Monitoring
Enable Fault Monitoring
Select this check box to enable fault monitoring.
Fault Monitoring Profile
Select the fault monitoring profile from the drop-down list. To create a new fault monitoring profile, click New Fault Monitoring Profile. For more information, see Fault Monitoring Profile.
Port Security
Enable Port Security
Select this checkbox to enable port security.
Note: Configuring port security on an interface is mutually exclusive with AAA configuration. Port security is not applicable to LAG interfaces.Client Limit
Specify the maximum number of clients that are allowed on a port.
Sticky Mac enable
Select this checkbox to enable sticky MAC.
Sticky MAC is a port security feature that learns MAC addresses on an interface and retains them. When sticky learning is enabled on a port, all dynamically learned (non-static) MAC addresses are treated as sticky MACs.
Port Security MAC Addresses
Specify the MAC addresses of static clients.
Sticky MAC Addresses
Specify the MAC addresses of sticky static clients.
-
-
Click Save.
A Port Profile template can be applied to a maximum of 10 interfaces at a time.