Creating a Role

You must create roles and assign them to specific individuals or groups within your network.

Before You Begin

  • Create a site in Classic Central. For more information, see Classic Central Online Help.

  • Create a HPE Aruba Networking Central group. For more information, see Groups.

  • Map the devices to the site and move the devices from default group to the HPE Aruba Networking Central group. For more information, see Classic Central Online Help.

Creating a Role

To create a role, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, select a site from the Sites menu.

    Alternatively, you can click the expand icon on the Sites menu to search for a site from the list.

    The site dashboard is displayed with the network and connectivity information for the site.

  2. Click the configuration icon.

    The Network Overview page is displayed.

  3. Click Library in the left navigation pane.

  4. Click the Roles & Policies tab.

  5. Under Roles card, click Manage.

  6. Click Create Role.

    The Create Role panel is displayed on the right.

    Note:

    You can create roles at multiple scopes, including Library, Global, Sites, or Devices, and HPE Aruba Networking Central adds them to Library. However, HPE Aruba Networking Central does not allow role creation at the Site Collections and Device Groups scopes and displays an error message.

  7. Configure the following parameters:

    • Name—Enter a name of the role.

      The name must be between 1 and 50 characters in length, and can include numbers and lowercase letters.

    • Description—Enter a description of the role.

      The description can include a maximum of 256 characters including letters, numbers, and special characters.

    • VLAN ID—Enter a value between 1 and 4094 in numbers to specify the VLAN ID.

    • Captive Portal Profile—Select the captive portal from the drop-down list. To create a new captive portal profile, click New Captive Portal. For more information, see Captive Portal Authentication Profile.

    • GPID—The Global Policy Identifier (GPID) parameter is auto-populated by default. You can also enter a unique GPID value in the range of 100-8191.

    • Dynamic Application Prioritization—Select the check box if application traffic prioritization is required.

    • Under Device-Specific Parameters, select Switch, Gateway, or both, and configure the following parameters:

      • Switch Parameters:

        • Always Download Role—Select this checkbox to download the role, even if it does not have a policy or is not referenced in the configuration. This option is applicable only for the port access role.

        • Authentication Mode—Select one of the following:

          • Device—To authenticate the device itself.

          • Client—To authenticate end-user devices.

          • Multidomain—Allows both device and client authentication on the same port.

        • VLAN Type—Select one of the following:

          • Access—For single VLAN connectivity. If Access VLAN is selected, configure the following parameters:

            • VLAN Name—Enter the VLAN name used for single network access.

            • Access VLAN—Enter the VLAN ID used for single network access.

            • Wired Access VLAN Name—Enter the VLAN name for the wired access network.

          • Trunk—For multiple VLANs. select Trunk VLAN and configure the following parameters:

            • Native VLAN—Specify the VLAN ID to be used as the native VLAN.

            • Native VLAN Name—Enter the name of the native VLAN.

            • Allowed VLANs—Enter a comma-separated list of VLAN IDs permitted on the trunk.

            • Allowed VLAN Names—Select the VLAN names from the drop-down list.

        • PoE—Select the Power over Ethernet mode.

          Note: Certain ports on AOS-S switches do not support PoE. AOS-S switches reject configurations that enable PoE on nonsupporting ports with the following error message—Error setting value power-over-ethernet for port x.
        • PoE Allocation—Select whether the PoE power is allocated based on actual usage or device class.

        • MTU—Enter the Maximum Transmission Unit size in bytes.

        • Admin Edge Port—Select the check box if the port connects directly to an end device.

        • Trust Mode—Select the trust type for traffic prioritization. The available options are: CoS, DSCP, and None.

        • Client Inactivity Timeout—Time in seconds before inactive client are disconnected.

        • Reauthentication Period—Interval in seconds for reauthentication.

        • Cache Reauth Period—Time in seconds before cached authentication expires.

        • Session Timeout—maximum time a session can remain active.

        • User Based Tunnel—Select the check box if tunneling per-user traffic through gateway is required.

        • Gateway Zone—Enter the zone name configured on the gateway.

        • Gateway Role—Select the role associated with the gateway.

      • Gateway Parameters:

        • VLAN Assignment—Select one of the following:

          • VLAN ID—Once selected, the VLAN Profile field is displayed. Select a VLAN profile from the drop-down list. Click New VLAN to create a new VLAN profile. For more information, see Creating a VLAN Profile.

          • Named VLAN—Once selected, the Named VLAN Profile field is displayed. Select a named VLAN profile from the drop-down list. Click New Named VLAN to create a new named VLAN profile. For more information, see Creating a Named VLAN Profile.

        • Bandwidth Contract:

          • Uplink Limit—Specify the maximum upload speed for devices under this role.

            Note: You can set limits per user, per device, or per role depending on system configuration.
          • Downlink Limit—Specify the maximum download speed for devices under this role.

            Note: You can set limits per user, per device, or per role depending on system configuration.
  8. Click Create.

The new role is added to the Roles table.

The following image displays the Roles table.

Figure 1: Roles Table

In the Roles & Policies tab, you can find a table menu in the upper-right corner. This menu allows you to customize the columns or reset their sizes.

Figure 2: Table Menu

You can also use the search bar to filter by Role Name.

Figure 3: Search Bar in Roles & Policies tab