UBT Profile

User-based tunneling (UBT) uses GRE to tunnel ingress user traffic from a switch interface to a gateway for further processing. It enables the switch to enforce a centralized security policy by applying per-user authentication and access control, ensuring consistent access and permissions.

Creating a UBT Profile

To create a UBT profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a UBT Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
      1. Select Site Collection, Site, Device, or Device Group in the left navigation menu.
      2. Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
      3. Select the device type from the Device Function drop-down list.

  3. On the Security card, click UBT.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the UBT card, click Manage.

    The UBT list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the following parameters:

    • Create as a local profile—Select this checkbox if you want to configure this profile as local.

      Note:

      The Create as a local profile checkbox is available at the Global, Site Collections, Sites, Devices, and Device Groups levels. It is not available at the Library level.

    • Name—Enter the name of the UBT profile.

    • Description—Enter the description for the UBT profile.

    • Mode—Select the UBT mode. The available options are:

      • Local VLAN—Clients are assigned to a local switch VLAN, and their UBT role-based VLAN is applied only when their traffic reaches the gateway controller.

      • Extended—Clients are assigned to their UBT role-based VLAN directly in the hardware datapath.

    • Reserved VLAN ID—Select the reserved VLAN ID from the drop-down list. This field is mandatory when the mode is set to mode is set to Local VLAN.

  6. To add a zone for the selected UBT mode, click + in the Zone table and configure the following parameters:

    • Name—Enter the name of the UBT zone.

    • Description—Enter the description for the UBT zone.

    • Enable Zone—Select this checkbox to enable the UBT zone.

    • VRF—Select the VRF from the drop-down list. To add a new VRF profile, click New VRF Profile.

    • Primary Gateway IP—Specify the IP address of the primary gateway for the UBT zone.

    • Backup Gateway IP—Specify the IP address of the backup gateway for the UBT zone.

    • Set PAPI Security Key—Select this checkbox to enable PAPI Enhanced Security and configure a new security key.

      • PAPI Security Key—Enter the security key used to encrypt UBT PAPI messages exchanged between the switch and the gateway cluster for the zone.

      • Confirm PAPI Security Key—Re-enter the security key to confirm.

        Note:

        The same PAPI security key must be configured on the mobility controller for the UBT SAC bootstrap to be successful.

    • Wake on LAN VLANs—Specify one or more Wake-on-LAN VLANs for the UBT zone. This field is applicable only for UBT VLAN Extend mode.

    • Advanced—Select this checkbox to document the following advanced parameters:

      • User Anchor Keepalive Interval— Specify the User Anchor keepalive refresh time interval in seconds for the UBT zone.

      • Switch Anchor Heartbeat Interval —Specify the Switch Anchor heartbeat refresh time interval in seconds.

  7. Click Create.

    The newly created profile is displayed in the UBT list.

  8. To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.
      The Edit Profile view is displayed in the side panel.

    2. Edit the required parameters.

    3. Click Update.

  9. To delete a UBT profile, hover on the profile name, and click the delete icon.

  10. To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

Assigning Scope to a UBT Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the Security card, click UBT.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the UBT card, click Manage.

    The UBT list view is displayed.

  4. Hover on the profile to which you want to assign a scope and click the ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Add icon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The UBT list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the Ellipsis icon.

    2. Select Unassign.

      The Unassign pop-up window is displayed.

    3. Select the required scope and click Unassign.

  12. To customize the UBT Server profile list, click the Customize Columns icon . For more information, see Customizing List.