Adding a Rule
To create a policy rule, complete the following steps:
-
In the HPE Aruba Networking Central landing page, select a site from the Sites menu.
Alternatively, you can click the expand
icon on the Sites menu to search for a site from the list.The site dashboard is displayed with the network and connectivity information for the site.
-
Click the configuration
icon. -
Click Library.
-
Click Roles & Policies.
-
Under Security Policies card, click Manage.
-
Under Role-based Policies card, click Manage.
-
In the Role-based Policies table, click the ellipsis
icon for a policy. -
Click .
The Create Rule panel is displayed on the right.
-
Configure the following parameters:
-
Description—Enter a description of the rule.
-
Source—Configure the source parameters.
-
Source—Select a source from the drop-down list. The following options are available:
-
Any
-
Access Role
-
Network
-
Host
-
Network Destination
Note:When you select Network or Host from the Service/Application drop-down list, the Use Alias check box is displayed. When you select the check box, the corresponding Alias parameter is displayed. Click the New Alias option to create a new alias under the rule. For more information, see Creating a Service.
-
-
Access Role—Select an access role from the drop-down list. You can also create a new access role by clicking the New Role option under Access Role. For more information, see Creating a Role.
-
Source Role Options—Select role options from the drop-down list. The following options are available:
-
Role
-
Network Destination
-
Host
-
Network
-
Local IP
-
User
-
Any
Note:AOS-S does not support setting Source Role Options in a role-based policy rule.
AOS-CX does not support setting Network Destination as a Source Role Options in a role-based policy rule.
-
-
Roles Options—Select role options from the drop-down list.
Note:AOS-S does not support setting Destination Roles Options in a role-based policy rule.
-
-
Destination—Configure the destination parameters.
-
Destination—Select a source from the drop-down list. The following options are available:4
-
Any
-
Access Role
-
Network
-
Host
-
Network Destination
Note:AOS-CX does not support setting Network Destination as a Destination in a role-based policy rule..
-
-
Choose an address family for this rile.*—Select one of the following:
-
IPv4 Address—Select this option to apply the rule for IPv4 address-family.
-
IPv6 Address—Select this option to apply the rule for IPv6 address-family.
Note:A rule supports a single address-family at a time.
-
-
Service/Application/Application Category/Web Category/ Reputation—Select one from the drop-down list.
-
Service/Application—Select a service or an application from the drop-down list. The following options are available:
-
Any
-
Service
-
Application
-
Application Category
-
Web Category/ Reputation
-
Protocol and Port
Note:Depending on the option that you select from the Service/ Application drop-down list, the corresponding parameter is displayed.
When you select Service from the Service/ Application drop-down list, the corresponding Service parameter is displayed. You can also create a new service by clicking the New Service option under Service. For more information, see Creating a Service.
-
-
Service/Application/Application Category/Web Category/ Reputation—Select one from the drop-down list.
Note:-
AOS-S does not support setting Application/Application Category/Web Category/ Reputation in a role-based policy rule.
-
AOS-CX does not support setting Service/Web Category/Reputation in a role-based policy rule.
-
-
Action—Select an action from the drop-down list.
-
Time Profile—Allows you to apply the rule only during certain times (e.g., business hours).
-
Log—Enable logging for traffic that matches this rule.
-
QoS—Select Quality of Service options for both dropdowns: DSCP and 802.1P.
-
DSCP—Differentiated Services Code Point for prioritizing traffic.
-
802.1P —Layer 2 priority marking for traffic classification.
-
-
-
Create Another—Select this check box to create another rule.
-
-
Click Create.
The new rule is added to the specified role-based policy.
Gateways and policies do not support alias IPv6 configuration. Hence, the Network and Host options under Source and Destination drop-down list are not applicable to IPv6 configuration of gateways.
The following image displays the parameters to configure a rule.
Figure 1: Add Rule