System Administration Profile

The System Administration profile card allows you to create and manage system administration profiles. These profiles allow you to configure Local, RADIUS, or TACACS authentication type for authenticating the users using SSH, Web, Telnet, and Console access.

Creating a System Administration Profile

To create a System Administration profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a System Local Administration Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:
    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.

    • To create profiles at the Site Collections, Sites, Devices, or Device Group level, complete the following steps before step 4:

      • Select Site Collection, Site, Device, or Device Group in the left navigation menu.

      • Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.

      • Select the device type from the Device Function drop-down list.

  3. On the System card, click through the radio buttons to locate and select System Administration.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the System Administration card, click Manage.

    The System Administration list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the system administration profile fields as described in the following table.

    Table 1: System Administration Profile Parameters

    Parameter

    Description

    Create as a local profile

    Select this option if you want to configure this profile as local.

    The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the system administration profile.

    Description

    Enter a brief description for the system administration profile.

    General

    Console Access

    Select this check box to enable access through console.

    Console Login Attempts

    Specify the number of failed console login attempts allowed before the user is locked out.

    Note:

    The range for console attempts is 1-10.

    Console Lockout Time

    Specify the duration for which a user is prevented from attempting to log in again after reaching the maximum number of failed console login attempts. Range: 1 to 65535 seconds.

    SSH Access

    Select this check box to enable access through SSH terminal.

    Encryption

    Select one of the encryption type from the drop-down list:

    • Both— (Default) Enables both AES-CBC AND AES-CTR authentication.

    • AES-CBC—Enables AES-CBC authentication for SSH.

    • AES-CTR—Enables AES-CTR authentication for SSH.

    Authentication

    Select one or both of the authentication type:

    • HMAC_SHA1—Enables HMAC-SHA1 authentication for SSH.

    • HMAC_SHA1_96—Enables HMAC-SHA1_96 authentication for SSH.

    • HMAC_SHA2_256—Enables HMAC-SHA2_256 authentication for SSH.

    Disable Weak DH Key Exchange Algorithms

    Select this check box to disable weak key exchange algorithm for SSH authentication.

    VRF

    Select one of the VRF options from the drop-down list:

    • All VRF Profiles— Enables all VRF profiles.

    • default— (Default)

    • mgmt— Enables management profile.

    Web Access

    Select this check box to enable access through web.

    Login Session Timeout

    Enter the time in minutes that a session remains active without any user activity.

    Note: By default, the login session timeout value is set to 5 minutes.

    Login Banner

    Enter a text banner to be displayed at the login prompt when a user accesses the device.

    Login Retries

    Number of acceptable login attempts.

    Retry Delay Seconds

    Specify the time interval between retries.

    Authentication

    Administration users

    Click + to add an administration user. In the Add Administration User side panel, select a user from the drop-down list, or click New Local Administration User to create a new user. For more information, see User Administration Profile.

    Authentication Groups

    Click + to create an authentication group.

    Session

    Select the session from the drop-down list. The following are the available options:

    Switch Specific: Console, SSH, Telnet

    AOS-CX Specific: HTTPS Server

    AOS-S Specific: REST, Web UI

    AOS-CX, Gateway, or AP Specific: Default.

    Access Groups

    Click + to create Access Group.

    Access Type

    Select the Access Type from the drop-down list.

    Primary Management Authentication Server

    Select the Primary Management Authentication Server from the drop-down list, or create a New Auth Server.

    Authentication Instances

    Add Authentication Instances.

    Authentication Method

    Select the Authentication Method from the drop-down list.

    Sequence ID

    Type in a Sequence ID.

    Accounting Groups

     

    Access Type

    Select the Access Type from the drop-down list.

    Record Type

    Select the Record Type from the drop-down list.

    Accounting Instances

    Add Accounting Instances.

    Accounting Method

    Select an Accounting Method from the drop-down list.

    Primary Management Authentication Server

    Select a Primary Management Authentication Server from the drop-down list.

    Backup Management Authentication Server

    Select a Backup Management Authentication Server from the drop-down list.

    Sequence ID

    Type in a Sequence ID.

  6. Click Create.

    The newly created system administration profile is displayed in the list view.

  7. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.

      The profile edit view is displayed in the side panel.

    2. Edit the required parameters.

    3. Click Update.

  8. To delete a system administration profile, hover on the profile name, and click the delete icon.

  9. To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

Assigning Scope to a System Local Administration Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the System card, click the fourth radio button, and then click System Local Administration.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the System Local Administration card, click Manage.

    The System Local Administration list view is displayed.

  4. Hover on the profile to which you want to assign a scope and click the ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Add icon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The System Local Administration list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover over the profile name and click the ellipsis icon.

    2. Select Unassign.

    3. Select the required scope and click Unassign.

  12. To customize the system administration profile list, click the Customize Columns icon . For more information, see Customizing List.