Switch System Profile

The Switch System profile card allows you to create and manage switch system profiles.

Creating a Switch System Profile

Before creating a switch system profile, you must configure the Authentication and Authentication Server Group from the Security Card.

To create a Switch System profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Authentication Server Group Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:
    • To create profiles at the Global level, select the device type as switch from the Device Function drop-down list before step 4.

    • To create profiles at the Site Collections, Sites, Devices, or Device Group level, complete the following steps before step 4:

      1. Select Site Collection, Site, Device, or Device Group in the left navigation menu.

      2. Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.

      3. Select the device type as switch from the Device Function drop-down list.

  3. On the System card, click Switch System.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the Switch System card, click Manage.

    The Switch System list view is displayed.

  4. Click Create Profile.

  5. The Create Profile side panel is displayed.

  6. Configure the Switch System parameters as described in the following table.

  7. Parameter

    Description

    Create as a local profile

    Select this option if you want to configure this profile as local.

    The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the switch system profile.

    Description

    Enter a brief description for the switch system profile.

    Contact

    Specify administrator’s contact details to be used for SNMP.

    General

     

    Location

    Specify the location of the switch to be used for SNMP.

    Timezone

    Select a time zone from the drop-down list.

    Virtual MAC Address

    Specify the virtual MAC address if you are configuring at the device level.

    Enable Fast Boot

    Select the checkbox to enable or disable Fastboot for the system. When Fastboot is enabled, most of the tests under POST (Power-On Self-Test) will be skipped. POST (Power-On Self-Test) verifies the hardware functionality of various modules (subsystems, line modules, fabric modules, and interfaces) during boot-up. By default, fast boot is enabled.

    Disable USB-Port

    The USB port can be enabled or disabled based on your preferences. If you want to use the USB port, you can select the USB Port check box to enable the USB port. By default, the USB port is disabled.

    Enable Unsupported Transceiver

    Use the checkbox to enable or disable using the unsupported transceiver. By default, unsupported transceiver is enabled.

    Enable Unsupported Transceiver Logging

    Use the checkbox to enable or disable the unsupported transceiver logging. By default, the unsupported transceiver logging is disabled.

    Device-Specific Parameters

    Select the following checkboxes to configure device-specific parameters:

    • AOS-CX

    • AOS-S

    AOS-CX Specific Parameters

    Enable Port Security

    Select this checkbox to enable port security at the global level.

    Enable Port Security Violation Traps

    Use the checkbox to enable or disable the SNMP port-security violation traps on the system. Port-security violation traps are enabled by default.

    AAA

    Enable 802.1X

    Select this checkbox to enable the 802.1x method for authentication.

    Enable MAC Authentication

    Select this checkbox to enable the MAC method for authentication.

    EAP-TLS Fragment Size (in bytes)

    Specify the EAP-TLS fragment size sent to the RADIUS server. The allowable range is 576 to 3072 bytes.

    MAC Address Format

    Select the MAC address format from the drop‑down list.

    MAC Radius Auth Method 

    Select PAP (Password Authentication Protocol) as the MAC Radius Authentication method to communicate with RADIUS servers from the drop-down list.

    When configuring a MAC Authentication Server Group in Central NAC, select only the PAP authentication method.

    802.1X Authentication Server Group

    Select a server group for the 802.1X Authentication from the drop-down list. If you want to create a new server group, select New Server Group from the drop-down list. This selection is mandatory if you have enabled 802.1X Authentication.

    MAC Authentication Server Group

    Select a server group for the MAC Authentication from the drop-down list. If you want to create a new server group, select New Server Group from the drop-down list. This selection is mandatory if you have enabled MAC Authentication.

    MAC Authentication Password

    Enter the MAC authentication password.

    Retype MAC Authentication Password

    Re‑enter the MAC authentication password to confirm.

    Device-Specific Parameters

    Select the following checkboxes to configure device-specific parameters:

    • AOS-CX

    • AOS-S

    AOS-CX Specific Parameters

    AOS-CX Specific Parameters

    Enable 802.1X Supplicant

    Select the checkbox to enable the 802.1X supplicant on the system.

    Client Move

    Select the client move option from the drop‑down list. The following are the available options:

    • Enable—Allows port access clients to move to other port access‑enabled interfaces and re‑authenticated on the new interface.
    • Disable—Prevents port access clients from moving to other port access‑enabled interfaces.
    • Secure—Stops attackers from spoofing a client’s MAC on another port‑access enabled port.

    Accounting

    Accounting Mode

    Select the accounting mode from the drop-down list. The following are the available options are:

    • Start-Stop—Selects accounting information capture from the point at which the client is authenticated until the client disconnects.
    • Stop-Only—Selects accounting information capture only when a client disconnects.

    Local Accounting

    Select the checkbox to enable local accounting. This defines port access accounting as being local.

    Enable Group

    Select the checkbox to enable accounting as remote with the Account Server Group from the drop‑down list.

    Interim Update on Reauth Enable

    Select the checkbox to enable re‑authentication of clients during interim accounting updates.

    Interim Update Enable

    Select the checkbox to enable interim accounting updates (between start and stop) and specify the interval in the Interim Update Interval field. Default: 60 minutes. Range: 1 to 525,600 minutes

    Security

    Enable ICMP Unreachable Messages

    Select the checkbox to enable the sending of ICMPv4 and ICMPv6 destination unreachable messages from the switch to the source when a specific host is unreachable.

    Policy (Inbound/Ingress Traffic)

    Select the policy name from the drop-down list.

    Device-Specific Parameters

    Select the AOS-CX Specific Parameters checkbox configure the device-specific parameters.

    ICMP Throttle

    Specify the ICMPv4 and ICMPv6 packet interval in seconds. Default: 1.

    Enable MACSec Self Test

    Select the checkbox to run a self test for MACsec on all MACsec-capable interfaces. When enabled, the system will drop traffic on all MACsec capable interfaces until the MACsec selftest completes successfully on the interface.

    Disable Factory Reset

    Select the checkbox to prevent a manual hard reset to factory defaults by pressing and holding the reset button

    Loop Protect

    Re-Enable Timer

    Specify the time interval after which an interface disabled by loop protection is re-enabled. The loop-protection timer is disabled by default.

    Transmit Interval

    Specify the time interval between successive loop-protect packets sent on an interface using the slider. Default: 5 seconds.

    Trap on Loop Detection

    Select the checkbox to enable sending SNMP traps for loop-protect–related events when a loop is detected.

    Access List

    Log Enabled

    Select this checkbox to enable the log timer interval for all Access Control Entries (ACEs). This is enabled by default.

    Log Timer

    Specify the log timer interval in seconds. Range: 5 to 300. Default: 300

    Power

    Power Redundancy

    Select the desired power redundancy mode for the switch power supplies. The available options include:

    • None— Provides only the required operating capacity with no redundancy,

    • N+1—Adds a single redundant power supply to ensure continued operation in the event of one power supply failure.

    • N+N—Delivers full redundancy by splitting power into two independent groups, each capable of powering the switch.

    Stack Power Redundancy

    Select the desired power redundancy mode for each stack member by choosing the appropriate VSF member from the drop-down list, and click + to add additional VSF member entries.

    Consumption Average Period

    Specify the time interval, in seconds, used to calculate the average power consumption. Range: 60‐3600.

    System Internal VLAN Range

    Specify the VLAN range reserved for internal use by route-only ports and LAGs, ensuring it does not overlap with any VLANs currently in use. This field is applicable only for 6200 Switch Series.

    Telemetry

    Enable DFP

    Select this checkbox to enable the Device Fingerprinting telemetry. This is enabled by default.

    When using the HPE Aruba Networking Central UI, AOS-CX switch system profiles support only the default Device Fingerprinting Profile configuration. The default profile is applied to all AOS-CX switch ports.

    Enable IP Client Tracker

    Select this checkbox to enable the IP Client Tracker telemetry. This is enabled by default.

    Enable Client Insight

    Select the checkbox to enable Client Insight. When enabled, this feature provides enhanced visibility into client activities, including capturing onboarding details. This field is applicable for both AOS-CX and AOS-S Switches.

    Enable Event Log for Client Insight

    Select the checkbox to enable event logging for Client Insight. When enabled, the system logs client onboarding status events. This field is applicable only for AOS-CX Switches.

    ICMP

    Enable ICMP Redirect

    Select this checkbox to enable the sending of ICMPv4 and ICMPv6 redirect messages to the source host. This is enabled by default.

  8. Click Create.

The newly created Switch System profile is displayed in the Switch System list.

To edit a profile, complete the following steps:

  1. Click anywhere on the row of the profile in the list view.
    The profile edit view is displayed in the side panel.

  2. Edit the required parameters.

  3. Click Update.

To delete a switch system profile, hover on the profile name, and click the delete icon.

To search for a profile, type the profile name in the search bar.

The search bar displays dynamic results as soon as you start typing.

Assigning Scope to a Switch System Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the System card, click Switch System.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the Switch System card, click Manage.

    The Switch System list view is displayed.

  4. Hover on the profile to which you want to assign a scope and click the ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Add icon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The Switch System list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the ellipsis icon.

    2. Select Unassign.

    3. Select the required scope and click Unassign.

    Note:

    After unassigning the scope from a profile, the profile will still exist at the library if it was not created locally. Unassigning will only disconnect the scope and profile.

  12. To customize the Switch System profile list, click the Customize Columns icon . For more information, see Customizing List.