WLAN Profile

You can configure WLAN profiles to provide different network access or services to users on the same physical network. For example, you can configure a WLAN to provide access to guest users and another WLAN to provide access to employee users through the same APs. You can also configure a WLAN that offers open authentication and Captive Portal access with data rates of 1 and 2 Mbps, and another WLAN that requires WPA authentication with data rates of up to 11 Mbps. You can apply both virtual AP configurations to the same AP or an AP group.

Note:

The WLAN profile can be configured through the API. However, the same WLAN profile cannot be updated in the WebUI under Library > Wireless > WLAN.

Creating an Access Type WLAN Profile

To create an access type WLAN profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a WLAN Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Groups level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Sites, Devices, and Device Group level, complete the following steps before step 4:
      1. Select Site Collection, Site, Device, or Device Group in the left navigation menu.
      2. Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
      3. Select the device type from the Device Function drop-down list.

  3. On the Wireless card, click WLAN. Alternatively, you can complete the following steps:

    1. On the Wireless card, click Manage.

    2. On the WLAN card, click Manage.

    The WLAN list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the following parameters as described in the following table.

    Table 1: WLAN Profile Parameters

    Parameter

    Description

    General

    Create as a local profile

    Select this option if you want to configure this profile as local.

    Note:

    The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the WLAN profile.

    Description

    Enter a brief description for the WLAN profile.

    Type

    Select the Access type.

    Use Alias

    Select the check box to allow network alias.

    ESSID Name

    The ESSID name is automatically populated with the same name as the WLAN profile. You can enter a different ESSID name if required.

    If you select the Use Alias check box, then select an alias from the ESSID drop-down list.

    To create a new ESSID alias, click New ESSID Alias.

    Configure the ESSID alias parameters as described below, and click Finish.

    • Name—Enter a name that uniquely identifies a wireless network. The network name, or ESSID can be up to 32 ASCII characters, if it contains unicode, depending on the language, the maximum characters vary. For example, ESSID could be up to 10 Chinese characters. If the ESSID includes spaces, you must enclose it in quotation marks.

    • Description—Enter description for the new ESSID.

    • Type—The type is auto-populated as EssId.

    • ESSID Name—Enter a name that uniquely identifies a wireless network.

    2.4 GHz

    Select the check box to allow this band for the WLAN profile. This band is selected by default.

    5 GHz

    Select the check box to allow this band for the WLAN profile. This band is selected by default.

    6 GHz

    Select the check box to allow this band for the WLAN profile.

    Disable Network

    Enable the check box to disable the network for the WLAN profile.

    Network Configuration

    Select one of the following options based on the requirement:

    • Most Compatible

    • Balanced

    • High Density

    • Custom

    ESSID Name Prefix

     

    Advanced

    Broadcast/Multicast

    If you select this option, then the following options are displayed:

    • Broadcast Filtering—Select one of the following broadcast filtering option:

      • All—The AP drops all broadcast and multicast frames except DHCP and ARP, IGMP group queries, and IPv6 neighbor discovery protocols.

      • ARP—The AP drops broadcast and multicast frames except DHCP and ARP, IGMP group queries, and IPv6 neighbor discovery protocols. Additionally, it converts ARP requests to unicast and sends frames directly to the associated clients. By default, the AP is configured to ARP mode.

      • Unicast ARP only—This option enables AP to convert ARP requests to unicast frames thereby sending them to the associated clients.

      • Disabled—The AP forwards all the broadcast and multicast traffic is forwarded to the wireless interfaces.

    • IPv6 RA and ND Optimization—IPv6 RA and ND optimization allows local IPv6 hosts to automatically configure their own IP address based on information advertised by switches or routers operating on the network. Select one of the following options: None—Disables the IPv6 RA, NS, or NA packets optimization on the WLAN SSID. Convert to Unicast—Converts multicast IPv6 RA, NS, or NA packets to unicast.

    Data Rates

    If you select this option, then select the basic and transmit rates for 2.4 GHz and 5 GHz bands drop-down lists under Data Rates.

    Bandwidth Control

    If you select this option, then the following Wi-Fi Protocols list is displayed under Bandwidth Control:

    • Wi-Fi 4

    • Wi-Fi 5

    • Wi-Fi 6

    • Wi-Fi 7

    All the Wi-Fi protocols are selected by default.

    WiFi Multimedia

    If you select this option, then the following options are displayed:

    • Background—Allocates bandwidth for background traffic such as file downloads or print jobs. Specify the appropriate DSCP mapping values within a range of 0–63 for the background traffic in the corresponding DSCP mapping text-box. Enter up to 8 values with no white space and no duplicate single DSCP mapping value.

    • Best Effort—Allocates bandwidth or best effort traffic such as traffic from legacy devices or traffic from applications or devices that do not support QoS. Specify the appropriate DSCP mapping values within a range of 0–63 for the best effort traffic.

    • Video—Allocates bandwidth for video traffic generated from video streaming. Specify the appropriate DSCP mapping values within a range of 0–63 for the video traffic.

    • Audio—Allocates bandwidth for voice traffic generated from the incoming and outgoing voice communication. Specify the appropriate DSCP mapping values within a range of 0–63 for the voice traffic.

    Miscellaneous

    Select this option to configure the miscellaneous settings for the WLAN profile.

    • Disable on 6 GHz Mesh—Select this check box to stop the SSID from broadcasting on 6 GHz radio when mesh is enabled on the 6 GHz radio. The 6 GHz Mesh is only supported for devices with 6 GHz capability.

    • Multi-Link Operation—Select this option to allow concurrent connections on multiple channels across a single or multiple radio frequency bands. This optimizes the bandwidth for an enhanced performance.

    • Hide SSID—Select this option if you do not want the SSID to be visible to users.

      Note:

      Removing the SSID from the corresponding Information Element (IE) intentionally makes the network more difficult to discover and will predictably result in client connectivity and roaming issues. As such, configuring a hidden SSID is not recommended and is not considered a best practice. Concealing the SSID hinders standard client discovery mechanisms, increases association complexity, and can negatively impact overall network reliability and user experience.

    • Deauthenticate Inactive Clients—Select this option to allow the AP to send a de-authentication frame to the inactive client and the clear client entry.

    • FTM (802.11mc) Responder Mode—Select this option to enable the fine timing measurement (802.11mc) responder mode.

    • Advertise Access Point Name—Select this option to enable the advertising of AP name.

    • Advertise Date and Time—Select this option to enable the advertising of date and time.

    • Probe Request SNR Threshold (dB)—Specify a threshold value to limit the number of incoming probe requests, measured in decibels.

    • Authentication Request SNR Threshold (dB)—Specify a threshold value to limit the number of incoming authentication requests, measured in decibels.

    • Disable SSID When—Disable the SSID based on the following states of the AP:
      • Internet Down

      • None

      • Tunnel Down

      • Uplink down

      The network turns out of service when the selected event occurs and the SSID is disabled according to the configuration settings applied.

      For example, if you select the Uplink Down option from the drop-down list, the SSID is disabled when the uplink is down and is enabled when the uplink is restored.

    VLAN

    Traffic Forwarding Mode

    Select Tunnel from the following options:

    • Bridge—This mode is used to bridge the user traffic locally. All the wireless traffic is terminated locally at the AP and bridged onto the local Ethernet segment.

    • Tunnel—This mode forwards client traffic to a HPE Aruba Networking Central gateway within the assigned gateway cluster. The traffic is processed by the gateway mapped to the SSID in the configuration before being forwarded based on network policies.

    • Mixed—This mode uses both bridge and tunnel forwarding modes to enable APs to tunnel client traffic to a gateway node in the tunnel mode network.

    Selecting Tunnel mode displays the Primary Gateway Cluster  parameter.

    Primary Gateway Cluster

    Select a gateway cluster that you created before from the drop-down list. For more information, see Gateway Clustering Profile.

    Selecting Primary Gateway Cluster displays the Secondary Gateway Cluster  parameter.

    Secondary Gateway Cluster

    (Optional) Select a secondary gateway cluster profile from the drop-down list.

    Use Named VLAN

    Select the check box to allow the usage of named VLAN for the WLAN profile.

    Note:

    Configure either Default VLAN with shared object created before or Use Named VLAN.

    Default VLAN

    Enter the default VLAN value of the WLAN profile. If you select the Use Named Vlan check box, then select the default VLAN from the drop-down list.

    To create a named VLAN, click New Named VLAN.

    Create Named VLAN

    Configure the named VLAN parameters as described below, and click Finish:

    • Name—Enter a name for the VLAN.

    • Description—Enter description for the named VLAN.

    • VLAN Profiles—Select VLAN profiles from the drop-down list. To display only the selected options, click View Selection.

      To create a new VLAN profile, click New VLAN.

    Create VLAN Profile

    Configure the VLAN profile parameters as described below, and click Finish:

    • VLAN ID—Enter a ID for the VLAN profile.

    • Description—Enter description for the VLAN profile.

    • Switch Specific Parameters—Select the check box to configure switch parameters.

    • Policy —Select a policy from the following options:

      • None

      • Inbound Outbound

      • Inbound

      • Outbound

    • Inbound Network Access List—Select the network access list for the inbound traffic from the drop-down list.

    • Outbound Network Access List—Select the network access list for the outbound traffic from the drop-down list.

    • Voice—Select the check box to enable voice VLANs support for the VLAN interface.

    When you edit the VLAN ID for the overlay WLAN, the old VLAN is removed, and the new VLAN is added to the gateway's scope. Consequently, the gateway will no longer retain the old VLAN.

    To retain the VLAN configuration on the gateway, you can configure the VLAN in one of the following ways:

    • Create the VLAN as a local object under the gateway persona with the appropriate scope.

    • Create the VLAN at the global scope under the gateway persona.

    • Configure the VLAN under the Named VLAN.

    Advanced

    VLAN Assignment Rules

    (Optional) Click the Add button to add VLAN assignment rules.

    APs support a maximum of eight VLAN rules.

    Add VLAN Assignment

    (Optional) Configure the VLAN assignment rule parameters as described below and click Finish.

    • Attribute—Select an attribute option from the drop down list.

    • Operation—Select an operation option from the drop down list.

    • String—Enter a string value from the drop-down list.

    • Use Named VLAN—Select the check box to allow the usage for named VLAN.

    • VLAN—Enter the VLAN value of the WLAN profile. If you select the Use Named Vlan check box, then select the default VLAN from the drop-down list.

    Security

    Security Level

    Select the security level from the following options:

    • Enterprise

    • Personal

    • Open

    Enterprise—Select this option to set the security level of the WLAN SSID as enterprise.

    Key Management

    Select any of the following options from the drop-down list:

    • WPA2-Enterprise—Select this option to use WPA2 security. The WPA2 Enterprise requires user authentication and requires the use of a RADIUS server for authentication.

    • WPA-Enterprise—Select this option to use both WPA Enterprise.

    • Both (WPA2 & WPA)—Select this option to use both WPA2 and WPA security.

    • Dynamic WEP with 802.1X—If you do not want to use a session key from the RADIUS Server to derive pairwise unicast keys, set Session Key for LEAP to Enabled. This is required for old printers that use dynamic WEP through LEAP authentication. The Session Key for LEAP feature is Disabled by default

    • WPA3-Enterprise(CNSA)—Select this option to use WPA3 security employing CNSA encryption operation mode.

    • WPA3-Enterprise(CCM 128)—Select this option to use WPA3 security employing CCM encryption operation mode limited to encrypting 128 bits of plain text.

    • WPA3-Enterprise(GCM 256)—Select this option to use WPA3 security employing GCM encryption operation mode limited to encrypting 256 bits of plain text.

    When either WPA2-Enterprise or Both (WPA2-WPA) encryption type is selected and if 802.1X authentication method is configured, ensure that you select the Opportunistic Key Caching (OKC) check box under Advanced settings to enable OKC. When OKC is enabled, a cached Pairwise Master Key (PMK) is used when the client roams to a new AP. This allows faster roaming of clients without the need for a complete 802.1X authentication. OKC roaming can be configured only for the Enterprise security level.

    Authentication

    Server Group

    Select the server group from the drop-down list. To create a new server group, see Authentication Server Group Profile.

    The default is Primary And Backup Only.

    Primary Server

    Select a primary server for client authentication from the drop-down list. To create a new authentication server, see Authentication Server Profile.

    Secondary Server

    Select a secondary server for client authentication from the drop-down list. To create a new authentication server, see Authentication Server Group Profile.

    Re authentication Interval

    Define a value for Reauth Interval. When set to a value greater than zero, APs periodically re-authenticate all associated and authenticated clients. The following events occur when the re-authentication interval is configured on WLAN SSIDs:

    • On an SSID performing L2 authentication (MAC or 802.1X authentication)—When re-authentication fails, the clients are disconnected. If the SSID is performing only MAC authentication and has a pre-authentication role assigned to the client, the client will get a post-authentication role only after a successful re-authentication. If re-authentication fails, the client retains the pre-authentication role.

    • On an SSID performing L2 authentication (MAC with captive portal authentication)—When re-authentication succeeds, the client retains the role that is already assigned. If re-authentication fails, a pre-authentication role is assigned to the client.

    Perform MAC Authentication Before 802.1X

    Select the check box to use 802.1X authentication after the client completes the MAC authentication successfully.

    MAC Authentication Fail-Through

    Select the check box to enable 802.1X authentication when the MAC authentication of an AP client fails.

    Accounting

    Accounting

    Select one of the options from the drop-down list to enable or disable RADIUS accounting:

    • Use Authentication Servers—To select authentication servers.

    • Use Separate Servers—To select separate servers.

    • Accounting Server Group—To select accounting server group.

    • Disable—To disable accounting option.

    Advanced<Enterprise>

    Denylisting

    Select this option to enable deny listing of the clients with a specific number of authentication failures. The users who fail to authenticate the number of times specified in the Max Authentication Failures field are dynamically deny listed. By default, the Denylisting option is disabled.

    Client Isolation

    Select this option to isolate clients from one another and disable all peer-to-peer communication within the network. This feature enhances the security of the network and protects it from vulnerabilities.

    Enforce DHCP

    Select this option to enforce DHCP and block traffic for AP clients that do not obtain IP address from DHCP.

    When DHCP is enforced:

    • A layer-2 user entry is created when a client associates with an AP.

    • The client DHCP state and IP address are tracked.

    • When the client obtains an IP address from DHCP, the DHCP state changes to complete.

    • If the DHCP state is complete, a layer-3 user entry is created.

    • When a client roams between the APs, the DHCP state and the client IP address are synchronized with the new AP.

    WPA3 Transition

    Select this option to allow transition from WPA3 to WPA2 and vice versa. This option is available only when you select Enhanced Open option in the Key Management drop-down list.

    Delete PMK Cache For Inactive Clients

    Select this option to delete PMK cache for inactive clients.

    Beacon Protection

    Select this option to enable beacon protection. This option is only displayed when you select WPA3-Enterprise(CNSA), WPA3-Enterprise(CCM 128), or WPA3-Enterprise(GCM 256) option from the Key Management drop-down list.

    DPP

    Select this option to enable device provisioning protocol that allows onboarding IoT devices easily, securely, and on a large scale. This option is available only when you select WPA2-Enterprise or WPA3-Enterprise (CCM 128) or WPA3-Enterprise (GCM 256) option in the Key Management drop-down list.

    Max Authentication Failures

    Sets a value for the maximum allowed authentication failures. Enter a number between 1-10.

    Passpoint Service Profile

    Select a Passpoint service profile from the drop-down list.

    Use IP for Calling Station ID

    Select this option to configure the client IP address as calling station ID.

    Called Station ID Type

    The Called Station ID Type detail can be configured even if the Use IP for Calling Station ID is set to disabled. Select any of the following options for configuring a called station ID:

    • Access Point Group—Uses the AP's IP address as the called station ID.

    • Access Point Name—Uses the host name of the AP as the called station ID.

    • IP Address—Uses the IP address of the AP as the called station ID.

    • MAC Address—Uses the MAC address of the AP as the called station ID.

    • VLAN ID—Uses the VLAN ID of as the called station ID.

    Called Station ID Include SSID

    Appends the SSID name to the called station ID.

    Called Station ID Delimiter

    Sets a delimiter at the end of the called station ID.

    MAC Authentication Parameters

    MAC Address Delimiter

    Select a character as a delimiter for the MAC address string. When configured, the AP uses the delimiter in the MAC authentication request.

    For example, if you select the colon as a delimiter, MAC addresses in the xx:xx:xx:xx:xx:xx format are used. If the delimiter is not specified, the MAC address in the xxxxxxxxxxxx format is used. The supported characters are :(colon), ,(comma), - (dash), None, % (percent), and / (slash).

    MAC Address Case

    This option is enabled when you select Perform MAC Authentication Before 802.1X option.

    Select the case to allow the AP to use lower or upper case letters in the MAC address string for MAC authentication.

    Fast Roaming

    Opportunistic Key Caching (OKC)

    Select this option to reduce the time needed for authentication. When OKC is enabled, multiple APs can share Pairwise Master Keys (PMKs) and use these keys when clients roam to a neighboring AP.

    802.11r

    Select this option to enable 802.11r roaming. Selecting this option enables fast BSS transition. The fast BSS transition mechanism minimizes the delay when a client transitions from one BSS to another within the same cluster.

    802.11k

    Select this option to enable 802.11k roaming. The 802.11k protocol enables APs and clients to dynamically discover the available radio resources. When 802.11k is enabled, APs and clients send neighbor reports, beacon reports, and link measurement reports to each other.

    RRM Quiet IE

    Select this option to disable Quiet IE and disable transmission of the 802.11k Quiet IE information elements. When you enable RRM Quiet IE, the AP will advertise in beacon and probe responses the Quiet IE, that is used to silence the channel for measurement purposes. When an AP uses Quiet IE to schedule a quiet interval, stations will not transmit on that channel during the quiet interval.

    MDID

    A mobility domain identifier (MDID). Enter a value between 1-65535. This option is available only when 802.11r is enabled.

    Personal—Select this option to set the security level of the WLAN SSID as personal.

    Key Management

    Select one of the following options from the drop-down list:

    • WPA2-Personal—Includes WPA2-PSK-AES.

    • WPA Personal—Includes WPA-PSK-TKIP and WPA-PSK-AES.

    • DPP—Includes DPP.

    • Both (WPA2 and WPA)—Includes WPA-PSK-TKIP, WPA-PSK-AES, WPA2-PSK-AES, and WPA2-PSK-TKIP.

    • Static WEP—For static WEP, configure the following parameters:

      • WEP Key Size—Select an appropriate value for WEP key size from the drop-down list. You can define 64-bit or 128-bit.

      • TX Key—Select an appropriate value for Tx key from the drop-down list.
      • WEP Key and Retype WEP Key—Enter an appropriate WEP key and reconfirm.

    • WPA3 Personal

    • MPSK AES

    • MPSK Local—If you select MPSK local in the Key Management drop-down list, select an MPSK profile from the MPSK Local drop-down list.

      To create a new MPSK profile, click New MPSK Local. For more information, see the parameter configuration in MPSK Profile.

    Passphrase Format

    Select a passphrase format. The options available are 8-63 alphanumeric characters and 64 hexadecimal characters.

    This parameter is available only when you select WPA2-Personal, WPA Personal, Both (WPA2 and WPA), or WPA3 Personal option from the Key Management drop-down list.

    Passphrase

    Enter the passphrase of length between 8 and 63 characters.

    This parameter is available only when you select WPA2-Personal, WPA Personal, Both (WPA2 and WPA), or WPA3 Personal option from the Key Management drop-down list.

    Retype Passphrase

    Retype the password.

    This parameter is available only when you select WPA2-Personal, WPA Personal, Both (WPA2 and WPA), or WPA3 Personal option from the Key Management drop-down list.

    SAE Sub Mode

    Select one of the following Simultaneous Authentication of Equals (SAE) sub-modes from the drop-down list to control the operational modes for WPA3 security configurations:

    • Gcm 256 Only Mode—Select this option to exclusively use Galois/Counter Mode (GCM) with 256-bit encryption, which is required for Wi-Fi 7 and Multi-Link Operation (MLO).

    • Legacy Mode—Select this option to prevent AKM Suite Selector of 24 and GCM-256 from being advertised, which are required for Wi-Fi 7 and MLO.

    • Mix Mode—Select this option to enable the advertisement and support for both Legacy Mode and Gcm 256 Only Mode simultaneously.

      This parameter is available only when you select WPA3 Personal option from the Key Management drop-down list.

    Captive Portal

    Select one of the following captive portal options from the drop-down list:

    • None—By default this option is selected.

    • External Captive Portal—The guest users are required to enter the proxy server details such as IP address and captive portal proxy server port details.

    Captive Portal Profile

    Select the captive portal profile from the drop-down list.

    To create a new captive portal profile, click New Captive Portal. For more information see, Captive Portal Authentication Profile.

    Authentication

    MAC Authentication

    Select this option to enable MAC address based authentication of clients. When MAC authentication is enabled, you can configure Reauth Interval.

    This parameter is not available when you select MPSK AES option from the Key Management drop-down list.

    Server Group

    Select a server group from the drop-down list.

    To create a new server group, click New Server Group. For more information, see Authentication Server Group Profile.

    Primary Server

    Add a primary server.

    To create a new server, click New Authentication Server. For more information, see Authentication Server Profile.

    Secondary Server

    Add a secondary server.

    To create a new server, click New Authentication Server. For more information, see Authentication Server Profile.

    Reauthentication Interval

    Enter a value in the text box.

    When set to a value greater than zero, APs periodically re-authenticate all associated and authenticated clients. The following events occur when the re-authentication interval is configured on WLAS SSIDs:

    • On an SSID performing L2 authentication (MAC or 802.1X authentication), if re-authentication fails, the clients are disconnected. If the SSID is performing only MAC authentication and has a pre-authentication role assigned to the client, the client will get a post-authentication role only after a successful re-authentication. If re-authentication fails, the client retains the pre-authentication role.

    • On an SSID performing L2 authentication (MAC with captive portal authentication): When re-authentication succeeds, the client retains the role that is already assigned. If re-authentication fails, a pre-authentication role is assigned to the client.

    The Reauth Interval parameter is available only when you enable MAC Authentication parameter.

    Accounting

    Select one of the options from the drop-down list to enable or disable RADIUS accounting:

    • Disabled—To disable accounting option.

    • Use Separate Servers—To select specific accounting.

    • Use Authentication Servers—To select authentication servers.

    Accounting Server1

    Select a server from the drop-down list.

    To create a new server, click New Authentication Server. For more information, see Authentication Server Profile.

    Accounting Interval

    Enter a number to set the minutes used for interim accounting. You can specify a value within the range of 1-60 minutes.

    Setting the value to 0 disables interim accounting.

    Advanced<Personal>

    Fast Roaming

    Configure the following fast roaming parameters for personal security level:

    • 802.11k

    • RRM Quiet IE

    DPP Select this option to enable device provisioning protocol that allows onboarding IoT devices easily, securely, and on a large scale. This option is available only when you select WPA2-Personal or WPA3-Personal option in the Key Management drop-down list and when you select 2.4 GHz or 5 GHz or 6 GHz option under General parameters.

    Open—Select this option to set the security level of the WLAN SSID as open.

    Key Management

    Select one of the following options from the drop-down list:

    • Open

    • Enhanced Open

    Captive Portal

    Select one of the following captive portal options from the drop-down list:

    • None—By default this option is selected.

    • External Captive Portal—The guest users are required to enter the proxy server details such as IP address and captive portal proxy server port details.

    Authentication

    MAC Authentication

    Select this check-box to enable MAC address based authentication of clients. When MAC authentication is enabled, you can configure Reauth Interval.

    Server Group

    Select a server group from the drop-down list.

    To create a new server group, click New Server Group. For more information, see Authentication Server Group Profile.

    Primary Server

    Add a primary server.

    To create a new server, click New Authentication Server. For more information, see Authentication Server Profile.

    Secondary Server

    Add a secondary server.

    To create a new server, click New Authentication Server. For more information, see Authentication Server Profile.

    Reauthentication Interval

    Enter a value in the text box.

    When set to a value greater than zero, APs periodically re-authenticate all associated and authenticated clients. The following events occur when the re-authentication interval is configured on WLAS SSIDs:

    • On an SSID performing L2 authentication (MAC or 802.1X authentication), if re-authentication fails, the clients are disconnected. If the SSID is performing only MAC authentication and has a pre-authentication role assigned to the client, the client will get a post-authentication role only after a successful re-authentication. If re-authentication fails, the client retains the pre-authentication role.

    • On an SSID performing L2 authentication (MAC with captive portal authentication): When re-authentication succeeds, the client retains the role that is already assigned. If re-authentication fails, a pre-authentication role is assigned to the client.

    The Reauth Interval parameter is available only when you enable MAC Authentication parameter.

    Advanced<Open>

    Denylisting

    Select this option to enable deny listing of the clients with a specific number of authentication failures. The users who fail to authenticate the number of times specified in the Max Authentication Failures field are dynamically deny listed. By default, the Denylisting option is disabled.

    Client Isolation

    Select this option to isolate clients from one another and disable all peer-to-peer communication within the network. This feature enhances the security of the network and protects it from vulnerabilities.

    Enforce DHCP

    Select this option to enforce DHCP and block traffic for AP clients that do not obtain IP address from DHCP.

    When DHCP is enforced:

    • A layer-2 user entry is created when a client associates with an AP.

    • The client DHCP state and IP address are tracked.

    • When the client obtains an IP address from DHCP, the DHCP state changes to complete.

    • If the DHCP state is complete, a layer-3 user entry is created.

    • When a client roams between the APs, the DHCP state and the client IP address are synchronized with the new AP.

    WPA3 Transition

    Select this option to allow transition from WPA3 to WPA2 and vice versa. This option is available only when you select Enhanced Open option in the Key Management drop-down list.

    Max Authentication Failures

    Sets a value for the maximum allowed authentication failures. Enter a number between 1-10.

    Use IP for Calling Station ID

    Select this option to configure the client IP address as calling station ID.

    Called Station ID Type

    The Called Station ID Type detail can be configured even if the Use IP for Calling Station ID is set to disabled. Select any of the following options for configuring a called station ID:

    • Access Point Group—Uses the AP's IP address as the called station ID.

    • Access Point Name—Uses the host name of the AP as the called station ID.

    • IP Address—Uses the IP address of the AP as the called station ID.

    • MAC Address—Uses the MAC address of the AP as the called station ID.

    • VLAN ID—Uses the VLAN ID of as the called station ID.

    Called Station ID Include SSID

    Appends the SSID name to the called station ID.

    Called Station ID Delimiter

    Sets a delimiter at the end of the called station ID.

    Fast Roaming

    Configure the following fast roaming parameters for open security level:

    • 802.11k

    • RRM Quiet IE

    Access

    Override default role

    Select the check box to override the default role.

    Note: The option to override the default role is supported only in APs running AOS 10.7.0.0 and later versions.

    Default Role

    Select the default role from the drop-down list. You can edit the default policies for the default role under Roles & Policies > Role-based Policies. For more information, see Editing a Policy.

    For more information on default roles and policies, seeSystem Default Gateway Policy and Auto-Created Role Behavior

    Advanced

    Enforce Machine Authentication

    1. Toggle the Enforce Machine Authentication switch to enable.

    2. Configure access rules for these roles by selecting the roles in the Machine auth only and User auth only drop-down lists.

    Role Assignment Rules

    Select a role assignment rule from the Role Assignment Rules list. APs support a maximum of sixteen Role rules.

    To add a role assignment rule, complete the following steps:

    1. Click the Add button.

      The Add Role Assignment Rule page is displayed.

    2. In the Add Role Assignment Rule, configure the following:

    • Attribute—Select an attribute from the drop-down list.

    • Operation—Select a operator from the drop-down list.

    • String—Enter a string.

    • Role—Select the role from the drop-down list.

    1. Click Finish.
  6. Click Finish.

Note:

In HPE Aruba Networking Central, roles could only be mapped at Global, Site Collections, Sites, and Devices level. When you configured a WLAN, associated user roles were required to be mapped at the Global level only, even if the WLAN was scope mapped at a Device Groups level. This update now allows roles to be scoped at the Device Groups level that enhances scalability and optimizes resource efficiency. It is important to note that roles mapped to Device Groups derive policies from the Global level only.

Creating a Recovery Type WLAN Profile

To create a recovery type WLAN profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a WLAN Profile.

    • Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.

    • Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.

    • Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.

    • Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.

    • Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.

    Note:

    • To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
    • To create profiles at the Sites, Devices, and Device Group level, complete the following steps before step 4:
      1. Select Site Collection, Site, Device, or Device Group in the left navigation menu.
      2. Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
      3. Select the device type from the Device Function drop-down list.

  3. On the Wireless card, click WLAN. Alternatively, you can complete the following steps:

    1. On the Wireless card, click Manage.

    2. On the WLAN card, click Manage.

    The WLAN list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the following parameters as described in the following table.

    Table 2: WLAN Profile Parameters

    Parameter

    Description

    Create as a local profile

    Select this option if you want to configure this profile as local.

    Note:

    The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    Name

    Enter the name of the WLAN profile.

    Description

    Enter a brief description for the WLAN profile.

    Type

    Select the Recovery type.

    ESSID Name Prefix

    Enter an ESSID name. The SSID prefix can be up to 22 characters long, and the Access Point (AP) automatically appends the last 9 characters of the AP MAC address as a suffix to the entered SSID prefix.

    2.4 GHz

    Select the check box to allow this band for the WLAN profile. This band is selected by default.

    5 GHz

    Select the check box to allow this band for the WLAN profile. This band is selected by default.

    Key Management

    Select one of the following:

    • WPA2-Personal

    • WPA3-Personal

    Passphrase Format

    Select a passphrase format. The options available are 8-63 characters and 64 hexadecimal characters.

    Passphrase

    Enter the passphrase of length between 8 and 63 characters.

    Retype Passphrase

    Retype the passphrase.

  6. Click Finish.

Assigning Scope to a WLAN Profile

For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.

To assign scope to a profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.

    The Profiles tab is displayed.

  2. Ensure that the default option Library is selected in the left navigation menu.

  3. On the Wireless card, click the second radio button, and then click WLAN.

    Alternatively, you can complete the following steps:

    1. On the Security card, click Manage.

    2. On the WLAN card, click Manage.

    The WLAN list view is displayed.

  4. Hover on the profile to which you want to assign a scope and click the ellipsis icon.

  5. Select Assign.

    The Assign Profile side panel is displayed.

    Note:

    When assigning a scope map using the API call [POST/PATCH] /network-config/v1alpha1/scope-maps/{scope-name}/{persona}/{resource} for Overlay WLAN and WLAN SSIDs, both the Overlay WLAN and the WLAN SSIDs must be scope-mapped. If only the WLAN SSID is scope-mapped, attempting to unassign the scope map from the UI display the error message Delete for unexpected req_xpath.

  6. Select the device types from Device Function list.

  7. To add a scope, click the Addicon on the Scopes table.

  8. Select a scope from the following Scope Level options in the drop-down list.

    • Global—Selecting this option assigns the scope at the Global level.

    • Site Collections—Select the site collections from the Assign to Scope drop-down list.

    • Sites—Select the sites from the Assign to Scope drop-down list.

    • Devices—Select the devices from the Assign to Scope drop-down list.

    • Device Groups—Select the device groups from the Assign to Scope drop-down list.

  9. Click Add.

    The Scopes table displays the newly added scopes.

  10. Click Assign.

    The WLAN list displays the device functions and number of scopes assigned to the profile.

  11. To unassign a scope from a profile, complete the following steps:

    1. Hover on the profile name and click the ellipsis icon.

    2. Select Unassign.

    3. Select the required scope and click Unassign.

  12. To customize the WLAN profile list, click the Customize Columns icon. For more information, see Customizing List.

WLAN List View Actions

  • To edit a profile, complete the following steps:

    1. Click anywhere on the row of the profile in the list view.

      The profile edit view is displayed in the side panel.

    2. Edit the required parameters.

    3. Click Update.

  • To delete a profile, complete the following steps:

    1. Hover on the profile name.

    2. Click the delete icon.

  • To search for a profile, type the profile name in the search bar.

    The search bar displays dynamic results as soon as you start typing.

  • To enable or disable a profile, complete the following steps:

    1. Hover on the profile name and click the ellipsis icon.

    2. Select Enable or Disable from the pop-up options.

System Default Gateway Policy and Auto-Created Role Behavior

As part of the Overlay WLAN workflow, the administrator can either assign a custom role or choose not to specify any role during WLAN creation. In the absence of a user-defined role, the custom modifier automatically generates a role with the same name as the SSID, if it is not already present. This generated role is mapped to the same scope as the SSID and is automatically associated with the relevant AP or gateway persona since it is referenced within the SSID profile.

Along with this behavior, an allow-all policy named System Default GW Policy (sys_allow_all_gw) is created as part of the default configuration. This policy is applicable to new tenants, while for existing tenants it is created under the WLAN (overlay mode) custom modifier. A new default policy (sys_allow_all_gw) is also added to the appropriate Policy Group through the HPE Aruba Networking Central or API as required, and any necessary restrictions are enforced through this policy.

The WLAN role, whether auto-generated or custom, is referenced as an allow-all rule within the System Default GW Policy, and the rule is inserted at the next available position in the custom modifier. This eliminates the need to create and configure a default role manually in the WLAN profile.

From a scope perspective, when an overlay WLAN scope is mapped, the role follows the SSID scope (for example, cluster or site level), while the System Default GW Policy remains mapped to the global scope. If the overlay WLAN scope is removed, the role is deleted from the GW cluster scope (service connection), whereas the default policy is retained in the global scope and is never removed.

For authentication workflows, the auto-created role is set as the default role in the WLAN profile and automatically acts as the initial or default role in the AAA profile for Captive Portal, MAC Authentication (mac-default-role), and DOT1X (dot1x-default-role), ensuring consistent policy enforcement without additional manual configuration.

Note:

When an overlay WLAN with auto role is configured with a manual cluster profile created at device group, users are unable to assign scope to the overlay WLAN profile using the API. As a workaround, users can configure the profile from the WebUI. However, the auto role will be mapped to the Global scope.