User Group Profile
User Group profile provides a valuable opportunity to establish rules for a specific group of users. With this feature, you can effectively manage access by permitting or denying selected CLI commands for that group, enhancing both security and control.
Creating a User Group Profile
To create a User Group profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a User Group Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
- Select either Site Collection, Site, Deviceor Device Group from the left navigation menu depending on the scope of your configuration.
- Select either of the user created site collection, site, device, or device group from the list view depending on the scope.
- Select the device type from the Device Function drop-down list.
-
-
On the System card, click User Group.
Alternatively, you can complete the following steps:
-
On the System card, click Manage.
-
On the User Group card, click Manage.
The User Group list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.Figure 1: Create User Group Profile Side Panel
-
Enter the User Group profile parameters:
-
Create as a local profile— Select this option if you want to configure this profile as local.
Note:The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.
-
Name—Enter a name for the User Group profile.
-
Description—Enter the description for the User Group profile.
-
CX Specific Parameters—Click the
expand icon to view the CX specific parameters.-
Inherit User Group—Select a user group from the Inherit User Group drop-down menu that you wish to inherit from.
-
-
CLI Commands—The CLI Commands table displays the following information:
- Sequence No.—Displays the sequence number of the rule.
- Action—Displays the type of action for the rule. For example, Permit or Deny.
- CLI Commands—Displays the CLI command for which the rule is applied.
- Comments—Displays the comments for the rule.
To add a new rule, complete the following steps:
-
Click
Add.The Add Rule page is displayed.
-
Enter a sequence number for the rule in the Sequence No. text box.
-
Under Actions, select Permit or Deny action for the rule.
-
Enter the CLI command in the CLI Commands text box.
-
Enter a comment for the rule in the Comments text box.
-
Click Add.
-
-
Click Create Profile.
The Create Profile side panel is displayed.Figure 2: Creating a CLI Rule
Assigning Scope to a User Group Profile
You must assign a scope and device function to a User Group profile created in the Library.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the System card, click User Group.
Alternatively, you can complete the following steps:-
On the System card, click Manage.
-
On the User Group card, click Manage.
The User Group list view is displayed.
-
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The User Group list displays the device functions and number of scopes assigned to the profile.
-
To unassign a User Group Profile, hover over the User Group Profile name, and select the Ellipsis
icon, and click Unassign.
The Unassign pop-up window is displayed.-
Select the checkbox to unassign a scope.
-
Click Unassign.
-
-
To delete a User Group Profile, hover over the User Group Profile name, and click the delete
icon. -
To customize the User Group profile list, click the Customize Columns
icon.For more information, see Customizing List.