Adding a Rule

To create a policy rule, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, select a site from the Sites menu.

    Alternatively, you can click the expand icon on the Sites menu to search for a site from the list.

    The site dashboard is displayed with the network and connectivity information for the site.

  2. Click the configuration icon.

  3. Click Library.

  4. Click Roles & Policies.

  5. Under Security Policies card, click Manage.

  6. Under Role-based Policies card, click Manage.

  7. In the Role-based Policies table, click the ellipsis icon for a policy.

  8. Click Add Rule.

    The Create Rule panel is displayed on the right.

  9. Configure the following parameters:

    • Description—Enter a description of the rule.

    • Source—Configure the source parameters.

      • Source—Select a source from the drop-down list. The following options are available:

        • Any

        • Access Role

        • Network

        • Host

        • Network Destination

        Note:

        When you select Network or Host from the Service/Application drop-down list, the Use Alias check box is displayed. When you select the check box, the corresponding Alias parameter is displayed. Click the New Alias option to create a new alias under the rule. For more information, see Creating a Service.

      • Access Role—Select an access role from the drop-down list. You can also create a new access role by clicking the New Role option under Access Role. For more information, see Creating a Role.

      • Source Role Options—Select role options from the drop-down list. The following options are available:

        • Role

        • Network Destination

        • Host

        • Network

        • Local IP

        • User

        • Any

        Note:

        AOS-S does not support setting Source Role Options in a role-based policy rule.

        AOS-CX does not support setting Network Destination as a Source Role Options in a role-based policy rule.

      • Roles Options—Select role options from the drop-down list.

        Note:

        AOS-S does not support setting Destination Roles Options in a role-based policy rule.

      • Destination—Configure the destination parameters.

        • Destination—Select a source from the drop-down list. The following options are available:4

          • Any

          • Access Role

          • Network

          • Host

          • Network Destination

          Note:

          AOS-CX does not support setting Network Destination as a Destination in a role-based policy rule..

        • Choose an address family for this rile.*—Select one of the following:

          • IPv4 Address—Select this option to apply the rule for IPv4 address-family.

          • IPv6 Address—Select this option to apply the rule for IPv6 address-family.

          Note:

          A rule supports a single address-family at a time.

        • Service/Application/Application Category/Web Category/ Reputation—Select one from the drop-down list.

        • Service/Application—Select a service or an application from the drop-down list. The following options are available:

          • Any

          • Service

          • Application

          • Application Category

          • Web Category/ Reputation

          • Protocol and Port

          Note:

          Depending on the option that you select from the Service/ Application drop-down list, the corresponding parameter is displayed.

          When you select Service from the Service/ Application drop-down list, the corresponding Service parameter is displayed. You can also create a new service by clicking the New Service option under Service. For more information, see Creating a Service.

        • Service/Application/Application Category/Web Category/ Reputation—Select one from the drop-down list.

          Note:
          • AOS-S does not support setting Application/Application Category/Web Category/ Reputation in a role-based policy rule.

          • AOS-CX does not support setting Service/Web Category/Reputation in a role-based policy rule.

        • Action—Select an action from the drop-down list.

        • Time Profile—Allows you to apply the rule only during certain times (e.g., business hours).

        • Log—Enable logging for traffic that matches this rule.

        • QoS—Select Quality of Service options for both dropdowns: DSCP and 802.1P.

          • DSCP—Differentiated Services Code Point for prioritizing traffic.

          • 802.1P —Layer 2 priority marking for traffic classification.

    • Create Another—Select this check box to create another rule.

  10. Click Create.

    The new rule is added to the specified role-based policy.

Note:

Gateways and policies do not support alias IPv6 configuration. Hence, the Network and Host options under Source and Destination drop-down list are not applicable to IPv6 configuration of gateways.

The following image displays the parameters to configure a rule.

Figure 1: Add Rule