UBT Profile
User-based tunneling (UBT) uses GRE to tunnel ingress user traffic from a switch interface to a gateway for further processing. It enables the switch to enforce a centralized security policy by applying per-user authentication and access control, ensuring consistent access and permissions.
Creating a UBT Profile
To create a UBT profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a UBT Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
- Select Site Collection, Site, Device, or Device Group in the left navigation menu.
- Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Security card, click UBT.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the UBT card, click Manage.
The UBT list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.
-
Configure the following parameters:
-
Create as a local profile—Select this checkbox if you want to configure this profile as local.
Note:The Create as a local profile checkbox is available at the Global, Site Collections, Sites, Devices, and Device Groups levels. It is not available at the Library level.
-
Name—Enter the name of the UBT profile.
-
Description—Enter the description for the UBT profile.
-
Mode—Select the UBT mode. The available options are:
-
Local VLAN—Clients are assigned to a local switch VLAN, and their UBT role-based VLAN is applied only when their traffic reaches the gateway controller.
-
Extended—Clients are assigned to their UBT role-based VLAN directly in the hardware datapath.
-
-
Reserved VLAN ID—Select the reserved VLAN ID from the drop-down list. This field is mandatory when the mode is set to mode is set to Local VLAN.
-
-
To add a zone for the selected UBT mode, click + in the Zone table and configure the following parameters:
-
Name—Enter the name of the UBT zone.
-
Description—Enter the description for the UBT zone.
-
Enable Zone—Select this checkbox to enable the UBT zone.
-
VRF—Select the VRF from the drop-down list. To add a new VRF profile, click New VRF Profile.
-
Primary Gateway IP—Specify the IP address of the primary gateway for the UBT zone.
-
Backup Gateway IP—Specify the IP address of the backup gateway for the UBT zone.
-
Set PAPI Security Key—Select this checkbox to enable PAPI Enhanced Security and configure a new security key.
-
PAPI Security Key—Enter the security key used to encrypt UBT PAPI messages exchanged between the switch and the gateway cluster for the zone.
-
Confirm PAPI Security Key—Re-enter the security key to confirm.
Note:The same PAPI security key must be configured on the mobility controller for the UBT SAC bootstrap to be successful.
-
-
Wake on LAN VLANs—Specify one or more Wake-on-LAN VLANs for the UBT zone. This field is applicable only for UBT VLAN Extend mode.
-
Advanced—Select this checkbox to document the following advanced parameters:
-
User Anchor Keepalive Interval— Specify the User Anchor keepalive refresh time interval in seconds for the UBT zone.
-
Switch Anchor Heartbeat Interval —Specify the Switch Anchor heartbeat refresh time interval in seconds.
-
-
-
Click Create.
The newly created profile is displayed in the UBT list.
-
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The Edit Profile view is displayed in the side panel. -
Edit the required parameters.
-
Click Update.
-
-
To delete a UBT profile, hover on the profile name, and click the delete
icon. -
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
Assigning Scope to a UBT Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the Security card, click UBT.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the UBT card, click Manage.
The UBT list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The UBT list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the Ellipsis
icon. -
Select Unassign.
The Unassign pop-up window is displayed.
-
Select the required scope and click Unassign.
-
-
To customize the UBT Server profile list, click the Customize Columns icon
. For more information, see Customizing List.