Switch System Profile
The Switch System profile card allows you to create and manage switch system profiles.
Creating a Switch System Profile
Before creating a switch system profile, you must configure the Authentication and Authentication Server Group from the Security Card.
To create a Switch System profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Authentication Server Group Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:-
To create profiles at the Global level, select the device type as switch from the Device Function drop-down list before step 4.
-
To create profiles at the Site Collections, Sites, Devices, or Device Group level, complete the following steps before step 4:
-
Select Site Collection, Site, Device, or Device Group in the left navigation menu.
-
Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
-
Select the device type as switch from the Device Function drop-down list.
-
-
-
On the System card, click Switch System.
Alternatively, you can complete the following steps:
-
On the System card, click Manage.
-
On the Switch System card, click Manage.
The Switch System list view is displayed.
-
-
Click Create Profile.
-
The Create Profile side panel is displayed.
-
Configure the Switch System parameters as described in the following table.
-
AOS-CX
-
AOS-S
-
AOS-CX
-
AOS-S
- Enable—Allows port access clients to move to other port access‑enabled interfaces and re‑authenticated on the new interface.
- Disable—Prevents port access clients from moving to other port access‑enabled interfaces.
- Secure—Stops attackers from spoofing a client’s MAC on another port‑access enabled port.
- Start-Stop—Selects accounting information capture from the point at which the client is authenticated until the client disconnects.
- Stop-Only—Selects accounting information capture only when a client disconnects.
-
None— Provides only the required operating capacity with no redundancy,
-
N+1—Adds a single redundant power supply to ensure continued operation in the event of one power supply failure.
-
N+N—Delivers full redundancy by splitting power into two independent groups, each capable of powering the switch.
-
Click Create.
|
Parameter |
Description |
|---|---|
|
Create as a local profile |
Select this option if you want to configure this profile as local. The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level. |
|
Name |
Enter the name of the switch system profile. |
|
Description |
Enter a brief description for the switch system profile. |
|
Contact |
Specify administrator’s contact details to be used for SNMP. |
|
General |
|
|
Location |
Specify the location of the switch to be used for SNMP. |
|
Timezone |
Select a time zone from the drop-down list. |
|
Virtual MAC Address |
Specify the virtual MAC address if you are configuring at the device level. |
|
Enable Fast Boot |
Select the checkbox to enable or disable Fastboot for the system. When Fastboot is enabled, most of the tests under POST (Power-On Self-Test) will be skipped. POST (Power-On Self-Test) verifies the hardware functionality of various modules (subsystems, line modules, fabric modules, and interfaces) during boot-up. By default, fast boot is enabled. |
|
Disable USB-Port |
The USB port can be enabled or disabled based on your preferences. If you want to use the USB port, you can select the USB Port check box to enable the USB port. By default, the USB port is disabled. |
|
Enable Unsupported Transceiver |
Use the checkbox to enable or disable using the unsupported transceiver. By default, unsupported transceiver is enabled. |
|
Enable Unsupported Transceiver Logging |
Use the checkbox to enable or disable the unsupported transceiver logging. By default, the unsupported transceiver logging is disabled. |
|
Device-Specific Parameters |
Select the following checkboxes to configure device-specific parameters: |
|
AOS-CX Specific Parameters |
|
|
Enable Port Security |
Select this checkbox to enable port security at the global level. |
|
Enable Port Security Violation Traps |
Use the checkbox to enable or disable the SNMP port-security violation traps on the system. Port-security violation traps are enabled by default. |
|
AAA |
|
|
Enable 802.1X |
Select this checkbox to enable the 802.1x method for authentication. |
|
Enable MAC Authentication |
Select this checkbox to enable the MAC method for authentication. |
|
EAP-TLS Fragment Size (in bytes) |
Specify the EAP-TLS fragment size sent to the RADIUS server. The allowable range is 576 to 3072 bytes. |
|
MAC Address Format |
Select the MAC address format from the drop‑down list. |
|
MAC Radius Auth Method |
Select PAP (Password Authentication Protocol) as the MAC Radius Authentication method to communicate with RADIUS servers from the drop-down list. When configuring a MAC Authentication Server Group in Central NAC, select only the PAP authentication method. |
|
802.1X Authentication Server Group |
Select a server group for the 802.1X Authentication from the drop-down list. If you want to create a new server group, select New Server Group from the drop-down list. This selection is mandatory if you have enabled 802.1X Authentication. |
|
MAC Authentication Server Group |
Select a server group for the MAC Authentication from the drop-down list. If you want to create a new server group, select New Server Group from the drop-down list. This selection is mandatory if you have enabled MAC Authentication. |
|
MAC Authentication Password |
Enter the MAC authentication password. |
|
Retype MAC Authentication Password |
Re‑enter the MAC authentication password to confirm. |
|
Device-Specific Parameters |
Select the following checkboxes to configure device-specific parameters: |
|
AOS-CX Specific Parameters |
AOS-CX Specific Parameters |
|
Enable 802.1X Supplicant |
Select the checkbox to enable the 802.1X supplicant on the system. |
|
Client Move |
Select the client move option from the drop‑down list. The following are the available options: |
|
Accounting |
|
|
Accounting Mode |
Select the accounting mode from the drop-down list. The following are the available options are: |
|
Local Accounting |
Select the checkbox to enable local accounting. This defines port access accounting as being local. |
|
Enable Group |
Select the checkbox to enable accounting as remote with the Account Server Group from the drop‑down list. |
|
Interim Update on Reauth Enable |
Select the checkbox to enable re‑authentication of clients during interim accounting updates. |
|
Interim Update Enable |
Select the checkbox to enable interim accounting updates (between start and stop) and specify the interval in the Interim Update Interval field. Default: 60 minutes. Range: 1 to 525,600 minutes |
|
Security |
|
|
Enable ICMP Unreachable Messages |
Select the checkbox to enable the sending of ICMPv4 and ICMPv6 destination unreachable messages from the switch to the source when a specific host is unreachable. |
|
Policy (Inbound/Ingress Traffic) |
Select the policy name from the drop-down list. |
|
Device-Specific Parameters |
Select the AOS-CX Specific Parameters checkbox configure the device-specific parameters. |
|
ICMP Throttle |
Specify the ICMPv4 and ICMPv6 packet interval in seconds. Default: 1. |
|
Enable MACSec Self Test |
Select the checkbox to run a self test for MACsec on all MACsec-capable interfaces. When enabled, the system will drop traffic on all MACsec capable interfaces until the MACsec selftest completes successfully on the interface. |
|
Disable Factory Reset |
Select the checkbox to prevent a manual hard reset to factory defaults by pressing and holding the reset button |
|
Loop Protect |
|
|
Re-Enable Timer |
Specify the time interval after which an interface disabled by loop protection is re-enabled. The loop-protection timer is disabled by default. |
|
Transmit Interval |
Specify the time interval between successive loop-protect packets sent on an interface using the slider. Default: 5 seconds. |
|
Trap on Loop Detection |
Select the checkbox to enable sending SNMP traps for loop-protect–related events when a loop is detected. |
|
Access List |
|
|
Log Enabled |
Select this checkbox to enable the log timer interval for all Access Control Entries (ACEs). This is enabled by default. |
|
Log Timer |
Specify the log timer interval in seconds. Range: 5 to 300. Default: 300 |
| Power | |
|
Power Redundancy |
Select the desired power redundancy mode for the switch power supplies. The available options include: |
|
Stack Power Redundancy |
Select the desired power redundancy mode for each stack member by choosing the appropriate VSF member from the drop-down list, and click + to add additional VSF member entries. |
|
Consumption Average Period |
Specify the time interval, in seconds, used to calculate the average power consumption. Range: 60‐3600. |
|
System Internal VLAN Range |
Specify the VLAN range reserved for internal use by route-only ports and LAGs, ensuring it does not overlap with any VLANs currently in use. This field is applicable only for 6200 Switch Series. |
|
Telemetry |
|
|
Enable DFP |
Select this checkbox to enable the Device Fingerprinting telemetry. This is enabled by default. When using the HPE Aruba Networking Central UI, AOS-CX switch system profiles support only the default Device Fingerprinting Profile configuration. The default profile is applied to all AOS-CX switch ports. |
|
Enable IP Client Tracker |
Select this checkbox to enable the IP Client Tracker telemetry. This is enabled by default. |
|
Enable Client Insight |
Select the checkbox to enable Client Insight. When enabled, this feature provides enhanced visibility into client activities, including capturing onboarding details. This field is applicable for both AOS-CX and AOS-S Switches. |
|
Enable Event Log for Client Insight |
Select the checkbox to enable event logging for Client Insight. When enabled, the system logs client onboarding status events. This field is applicable only for AOS-CX Switches. |
|
ICMP |
|
|
Enable ICMP Redirect |
Select this checkbox to enable the sending of ICMPv4 and ICMPv6 redirect messages to the source host. This is enabled by default. |
The newly created Switch System profile is displayed in the Switch System list.
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The profile edit view is displayed in the side panel. -
Edit the required parameters.
-
Click Update.
To delete a switch system profile, hover on the profile name, and click the delete
icon.
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
Assigning Scope to a Switch System Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the System card, click Switch System.
Alternatively, you can complete the following steps:
-
On the System card, click Manage.
-
On the Switch System card, click Manage.
The Switch System list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Switch System list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the ellipsis
icon. -
Select Unassign.
-
Select the required scope and click Unassign.
Note:After unassigning the scope from a profile, the profile will still exist at the library if it was not created locally. Unassigning will only disconnect the scope and profile.
-
-
To customize the Switch System profile list, click the Customize Columns icon
. For more information, see Customizing List.