User Group Profile

User Group profile provides a valuable opportunity to establish rules for a specific group of users. With this feature, you can effectively manage access by permitting or denying selected CLI commands for that group, enhancing both security and control.

Creating a User Group Profile

To create a User Group profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a User Group Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
      1. Select either Site Collection, Site, Deviceor Device Group from the left navigation menu depending on the scope of your configuration.
      2. Select either of the user created site collection, site, device, or device group from the list view depending on the scope.
      3. Select the device type from the Device Function drop-down list.

  3. On the System card, click User Group.

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the User Group card, click Manage.

      The User Group list view is displayed.

  4. Click Create Profile.
    The Create Profile side panel is displayed.

    Figure 1: Create User Group Profile Side Panel

  5. Enter the User Group profile parameters:

    • Create as a local profile— Select this option if you want to configure this profile as local.

      Note:

      The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    • Name—Enter a name for the User Group profile.

    • Description—Enter the description for the User Group profile.

    • CX Specific Parameters—Click the expand icon to view the CX specific parameters.

      • Inherit User Group—Select a user group from the Inherit User Group drop-down menu that you wish to inherit from.

    • CLI Commands—The CLI Commands table displays the following information:

      • Sequence No.—Displays the sequence number of the rule.
      • Action—Displays the type of action for the rule. For example, Permit or Deny.
      • CLI Commands—Displays the CLI command for which the rule is applied.
      • Comments—Displays the comments for the rule.

      To add a new rule, complete the following steps:

      1. Click Add.

        The Add Rule page is displayed.

      2. Enter a sequence number for the rule in the Sequence No. text box.

      3. Under Actions, select Permit or Deny action for the rule.

      4. Enter the CLI command in the CLI Commands text box.

      5. Enter a comment for the rule in the Comments text box.

      6. Click Add.

  1. Click Create Profile.
    The Create Profile side panel is displayed.

    Figure 2: Creating a CLI Rule

     

Assigning Scope to a User Group Profile

You must assign a scope and device function to a User Group profile created in the Library.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the System card, click User Group.
    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the User Group card, click Manage.

    The User Group list view is displayed.

  4. Select the device types from Device Function list.

  5. To add a scope, click the Addicon on the Scopes table.

  6. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  7. Click Add.

    The Scopes table displays the newly added scopes.

  8. Click Assign.

    The User Group list displays the device functions and number of scopes assigned to the profile.

  9. To unassign a User Group Profile, hover over the User Group Profile name, and select the Ellipsis icon, and click Unassign.
    The Unassign pop-up window is displayed.

    1. Select the checkbox to unassign a scope.

    2. Click Unassign.

  10. To delete a User Group Profile, hover over the User Group Profile name, and click the delete icon.

  11. To customize the User Group profile list, click the Customize Columns icon.

    For more information, see Customizing List.