AOS-CX Switch Configuration

This section provides an overview of the AOS-CX switch configuration and operations journey. Configuring AOS-CX switches through HPE Aruba Networking Central provides centralized management, reduces manual errors, and accelerates deployments.

Note:

This section assumes that you have already onboarded standalone switches or AOS-CX 6200 or 6300 switch stacks based on your network design and requirements. For more information on the onboarding process, see the following sections:

The following image displays the high-level steps to deploy and configure AOS-CX switches.

Figure 1: AOS-CX Configuration and Operations

The following sections describe the steps displayed in AOS-CX Configuration and Operations:

Step 1—Configuring Firmware Policies

Step 2—Configuring System Profiles

Step 3—Configuring VLANs and Port Profiles

Step 4—Configuring Routing and Authentication Profiles

Step 5—Configuring Network Policies

Additional Resources

Use the following resources to assist with AOS-CX switch configuration:

Profiles Overview

The AOS-CX profiles in HPE Aruba Networking Central simplify switch configuration by grouping related settings into reusable templates. Instead of configuring parameters individually on each device, administrators can create and apply profiles to ensure consistency, reduce errors, and accelerate deployment. Profiles cover multiple functional areas, including system settings, VLAN and network configurations, interface behaviors, and security policies. By leveraging profiles, you can standardize configurations across devices, streamline management, and maintain compliance with organizational policies.

Following are the profile categories for AOS-CX switch configuration:

  • System Profiles—Define core system settings such as NTP, DNS, and switch administration parameters.

  • Switch Profiles—Configure system administration attributes for switches.

  • Switch Interface Configuration Profiles—Manage link aggregation (LAG) and related interface settings.

  • VLAN and Network Profiles—Create VLANs, configure Spanning Tree Protocol (STP), and manage network segmentation.

  • Security Profiles—Apply AAA authentication and access control policies.

  • Interface Profiles—Assign VLANs and configure port-specific behaviors.

This following image categorizes configuration profiles into VLANs & Networks, Interfaces, System, Security, Routing and Overlays, and Application Experience. These categories map directly to the configuration steps outlined in this topic, helping administrators understand where each profile fits in the overall process.

Figure 2: AOS-CX Profile Categories

Step 1—Configuring Firmware Policies

Firmware management in HPE Aruba Networking Central enables administrators to maintain consistent and tested firmware versions across all switches, including VSF/VSX clusters. This approach supports staged upgrades during maintenance windows, ensuring network stability, minimizing bugs, and simplifying support. By defining upgrade policies at various scopes such as Global, Sites, Device Groups, or individual devices, administrators can reduce vulnerabilities and streamline lifecycle management.

To configure a firmware policy, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the icon to open the Menu page.

  2. On the Firmware Management card, click Manage.

    Figure 3: Firmware Management Card

    The Firmware Management page is displayed containing the following options in the left navigation:

    • Overview

    • Firmware Policies

    • Global

    • Sites

    • Devices

    • Device Groups

  3. In the left navigation, select the Global scope.

  4. On the Global page, click Create Firmware Policy.

    Figure 4: Menu in HPE Aruba Networking Central

    The Create Firmware Policy side panel is displayed containing a four-step wizard.

  5. Configure the following parameters for each step in the wizard:

    • Step 1Details:

      1. Configure the following parameters:

        • Name—Enter "AccessSwitch_Upgrade" as the name of the firmware policy.

        • Description—Enter "Upgrade all Access Switches to firmware version 10.15.1050." as the description of the firmware policy.

      2. Click Next.

      Figure 5: Menu in HPE Aruba Networking Central

    • Step 2Parameters:

      1. Configure the following parameters:

        • Scope—This parameter is non-editable and auto-populated with Global.

        • Device Function—Select Access Switch from the drop-down list.

        • Firmware Version—Select 10.15.1050 from the drop-down list.

        • Partition—Select Primary from the drop-down list.

        • Advanced Options—Retain the default selections unless exceptions are needed.

      2. Click Next.

      Figure 6: Menu in HPE Aruba Networking Central

    • Step 3Schedule:

      1. Configure the following parameters:

        • Upgrades—Select From Scheduled Date radio button.

        • Date—Select the date on which the upgrade will begin.

        • Time—Select the specific time for the scheduled upgrade to begin.

        • Time Zone—Select the appropriate time zone from the drop-down list to ensure that the devices are upgraded at the correct time.

      2. Click Next.

      Figure 7: Menu in HPE Aruba Networking Central

    • Step 4Review:

      1. Verify the following configuration details:

        • Name—AccessSwitch_Upgrade

        • Scope—Global

        • Device Function—Access Switch

        • Firmware Version—10.15.1050

        • Upgrades—From Scheduled Date

      2. Click Create.

The firmware policy is created for the device function under the selected scope.

Best Practices

  • Always schedule upgrades during maintenance windows to minimize disruption.

  • Validate firmware compatibility before applying the policy.

  • Backup device configurations prior to upgrade.

  • Monitor upgrade status in the Devices tab after policy execution.

Step 2—Configuring System Profiles

To configure system profiles, see the following topics:

System > NTP Server Profile

Use this profile when accurate time synchronization is critical for AAA (Authentication, Authorization, and Accounting), logging, and certificate management. It is recommended in compliance-driven environments or when using non-default VRFs. Reliable time synchronization enhances security and simplifies troubleshooting.

An NTP (Network Time Protocol) server is a critical component in the infrastructure of modern networks, ensuring that all devices have synchronized time. This synchronization is vital for security, logging, and system management. A default NTP server profile already exists to ensure that devices remain in sync with Central. By default, it uses the public NTP server, pool.ntp.org.

To change this default or to add multiple NTP servers, you can create a new NTP server profile. To create a new NTP server profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, navigate to Library.

  3. On the System card, click NTP Server.

    Figure 8: NTP Server Card


    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the NTP Server card, click Manage.

    The NTP Server list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

    Figure 9: Create NTP Profile

  5. Enter the following NTP Server profile parameters:

    • Name—Enter the name of the NTP Server profile.

    • Description—Enter the description for the NTP Server profile.

    • NTP Alias—Select this check box to assign a NTP alias. 

      • Alias—Select an alias from the Alias drop-down list.

  6. Click the Add icon on the NTP Server table.

    The Add NTP Server pane is displayed.

  7. Enter NTP Server parameters:

    • Server Address—Select IPv4, IPv6, or FQDN.

      • IPv4—If you select IPv4, then enter the IPv4 address.

      • IPv6—If you select IPv6, then enter the IPv6 address.

      • FQDN—If you select FQDN, then enter domain name.

    • IBurst Mode—(Optional) Select the IBurst Mode if needed.

  8. Click Add.

    Figure 10: Add NTP Server

  9. Switch Parameters—Select this checkbox if you want the switches to use a different VRF other than default.

  10. VRF—This option is enabled when you select the Switch Parameters check box. Select the VRF profile from the drop-down list.

  11. Click Add.

  12. Click Create to create the NTP server profile.

    Figure 11: NTP Profile Switch Parameters

  13. Assign the profile to all relevant device functions and the appropriate scope.

    For additional information, see NTP Server Profile.

System > Switch System Profile

Use this profile to standardize SNMP, timezone, and security defaults across sites. It is useful for enabling IP tracking and loop protection, and helps reduce manual configuration. This ensures consistent behavior across the network.

Figure 12: Switch System Profile Card

Switch System profiles can be found in the System card and used to configure various switch-level defaults. There are three separate default profiles that cannot be edited:

  • default-system-profile-1: Applied to AOS-CX 8320 and 8325 switches.

  • default-system-profile-2: Applied to AOS-CX 10000 and 10040 switches.

  • default-system-profile-3: Applied to all other AOS-CX model switches.

The default profiles provide the necessary configuration for basic switch operation. However, to meet specific network requirements, it is recommended to create and assign custom profiles.

In addition to the profile name and description, the following settings can be configured for each Switch System profile:

  • Location and contact information to be used for SNMP

  • Time zone

  • Virtual MAC address

  • Enable/Disable USB port

  • Enable/Disable Unsupported transceivers

  • Enable/Disable Port Security

  • Default AAA settings

  • Auth Survivability settings

  • Loop Protection

  • Logging for ACL hits

  • VSF stack member power redundancy

  • CX Telemetry settings

    • Enable/Disable Device Fingerprinting

    • Enable/Disable IP Client Tracker

Since time zone and SNMP location data are included in these default settings, it is recommended to create a new profile for each site in your network. If more detailed site location information is required, for example, for sites with multiple closets, you can either apply Switch System profiles at the device level or use device-level overrides.

For additional information, see Switch System Profile.

System > System Administration Profile

System Administration profiles can be found in the System card and are used to set switch-level defaults related to administrative access.

Figure 13: System Administration Profile Card

Similar to Switch System profiles, there are three separate default profiles that cannot be edited:

  • access_no_mgmt_vrf: Applied to AOS-CX switches without dedicated IP management ports.

  • access_with_mgmt_vrf: Applied to AOS-CX switches with dedicated IP management ports.

  • core: Applied to AOS-CX core switches.

These profiles allow you to enable or disable console, SSH, and web access, configure session timeouts for switches, set login banners, and define the allowed login retries and delays between login attempts.

You can also enable additional authentication methods for administrative access, such as TACACS+, and allow or disallow fallback to local authentication.

In most cases, you can create a single profile and apply it at the global level. However, if you have different requirements for datacenter switches, for example, you should create additional profiles and apply them at the appropriate site or site collection level(s) as overrides.

For more information, see System Administration Profile.

System > DNS Profile

Use this profile when public DNS is blocked or internal DNS resolution is required. It facilitates device activation and HPE Aruba Networking Central connectivity, improves name resolution speed, and ensures compliance with security policies.

Figure 14: DNS Server Profile Card

HPE Aruba Networking Central comes with a pre-configured DNS profile for Google DNS that is applied at the global level, which may be sufficient for some users.

More commonly, ISP-provided or internal DNS servers will be required for operational or performance reasons. Depending on the size and structure of your network, it may be appropriate to apply these settings globally for smaller organizations, or at the site or site collection level for larger organizations.

Note:

You can create separate or combined profiles for multiple VRFs, and it is possible to use the same profile for both switches and gateways if required.

For more information, see DNS Server Profile.

Step 3—Configuring VLANs and Port Profiles

To configure VLANs and port profiles, see the following topics:

VLANs & Networks > VLAN Profile

Use this profile for consistent VLAN segmentation across multiple switches. It speeds up deployment and prevents manual errors, making it best suited for voice/data VLANs in campus or branch networks.

For SVIs, use this profile for shared Layer 3 gateway settings while keeping device-specific IPs local. It is ideal for VSX Anycast or Active-Gateway setups, as it simplifies configuration and minimizes per-device changes.

A VLAN profile is a configuration object that defines VLAN Layer 2 or Layer 3 properties for network devices. Properties can include VLAN name, ID, IPv4/IPv6 address, security parameters, type (data/voice), IGMP, MLD, MTU, and more.

Scope Levels

  • Global: Applies to all switches within the Device Function.

  • Site Collections/Sites: Applies to all switches within the Device Function at a specific site or site collection.

  • Devices: Applies to individual switches.

  • Device Groups: Applies to all switches within the Device Function of a specific device group.

Note:
  • A default VLAN profile with VLAN ID 1 is available at all scopes.

  • The default VLAN profile (VLAN ID 1) cannot be deleted or modified at the library.

  • At the Global level, only editing of the default VLAN profile (VLAN ID 1) is allowed.

  • Custom VLAN profiles can be created at all other hierarchy levels: Library, Site Collection, Site, Devices, and Device Groups.

Steps to Create a VLAN Profile – Layer 2 or Layer 3

To create a VLAN profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library

    • Global

    • Site Collections

    • Sites

    • Devices

    • Device Groups

  3. Select the device function such as Access Switch, Aggregation Switch, or Core Switch, from the Device Function drop-down list.

  4. On the VLANs & Networks card, click VLAN.

    Figure 15: VLAN Option

  5. Click Create Profile and configure the Layer 2 VLAN profile parameters as required.

  6. Select Enable L3 to configure Layer 3 parameters for the VLAN. For more information, see VLAN Profile.

The IP address for the SVI is configured at the Devices scope, as it is unique per device. Deployments using VSX Active-Gateway configuration can leverage the VLAN profile at a higher scope to configure the required parameters, while the device-specific IP address is configured at the Device scope. For more information about VLAN IPv4 Address and VLAN IPv6 Address, see Creating an Alias.

Recommendations

  • Configure VLAN profile at the Library and multi-select Device Functions (Access Switch and Aggregation Switch) and respective sites.

  • Navigate to the Site hierarchy and select the appropriate Device Function (Aggregation Switch) to modify the VLAN profile created at the Library.

  • At the local Site hierarchy, enable the option Save as local profile before editing the VLAN profile created at the Library level.

  • Configuration updates include adding Layer 3 constructs to the VLAN profile only for the aggregation switch devices at that Site hierarchy.

  • Anycast Gateway IP Address for the VSX configuration can be configured at a higher hierarchy.

  • Device-specific IP Address is always configured at the lowest hierarchy — Device — as it is unique per device.

  • Navigate to the Device hierarchy, enable the option Save as local profile before editing the VLAN profile, and click Update.

All configuration activities are recorded in the audit trail.

Monitoring

The VLAN configuration can be monitored by navigating to device monitoring in HPE Aruba Networking Central and expanding the VLAN card to view the VLANs configured on the device. For more information, see VLAN.

VLANs & Networks > STP Profile

Use this profile to prevent loops and set the STP root consistently. It is useful during migrations to MST for scalability and ensures a stable Layer 2 topology with predictable convergence.

Spanning Tree Protocols (STP) improve network stability by preventing Layer 2 loops. An STP profile enables consistent deployment by allowing the configuration of either MSTP or RPVST spanning-tree protocols.

  • A default STP profile named STP defaults is available at all scopes for convenience.

  • Default STP profiles cannot be deleted or modified at the Library level.

  • At the Global level, only editing of the STP profile is allowed.

  • Custom STP profiles can be created at all other hierarchy levels: Library, Site Collection, Site, Devices, and Device Groups.

Figure 16: STP Profile

Figure 17: Create STP Profile

Interfaces > Port Profile

Use this profile to apply repetitive port settings such as VLAN, PoE, and 802.1X. It speeds up provisioning for both access and uplink ports, reduces configuration errors, and enforces uniform policies across the network.

The Port Profile feature allows you to define a set of attributes that can be applied to multiple interfaces on a switch. From the Port Profiles page, you can create, modify, and delete profiles within the selected scope of view.

Use Case 1: Campus Access Switch (Voice/Data Downlinks)

Port Profile: User-Voice-Access

Purpose

Configure access ports for phones and PCs with PoE, LLDP, VLAN assignments, and security.

To create a port profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, navigate to Library.

  3. On the Interfaces card, click Port Profile.

    Figure 18: Port Profile


    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Port Profile card, click Manage.

    The Port Profile list view is displayed.

  4. Click Create Profile.

    The Create Profile side panel is displayed.

  5. Configure the following general parameters:

    • Name: User-Voice-Access

    • Description: Access ports for voice/data endpoints.

    • Device: Switch

    • Admin State: Up

    • Jumbo Frame MTU: Default

    • PoE: Enable

      • Priority: High

      • PoE Allocation By: Class

      • Pre-Standard Detect: Enable if legacy phones are present

    • UDLD: Disable (optional for access)

    • LLDP/CDP: Enable LLDP (Transmit and Receive) and Enable CDP

  6. Configure the following Network parameters:

    • VLAN Mode: Access

    • Access VLAN: 600

    • DHCPv4 Snooping Trust: Disabled (Untrusted)

    • DHCPv6 Snooping Trust: Disabled (Untrusted)

    • ARP Inspection Trust: Untrusted (Untrusted)

  7. Configure the following Loop Prevention parameters:

    • Loop Protection: Enabled

    • VLANs: 1-4094 (Enter a comma‑separated list, a range, or both (blank values are not allowed). Valid Range: 1–4094)

    • Action: Transmit and receive disable

    • STP Priority: Default

    • STP Cost: Default

    • STP Options: BPDU Guard enabled

  8. Configure the following Security parameters:

    • Enable Port Authentication: Yes

    • AAA Profile: Assign the created profile

  9. Configure the following Policy parameters:

    • Inbound Policy: Select as needed

    • Outbound Policy: Select as needed

    • Access List: Apply inbound ACL for isolation

  10. Configure the following Fault Monitoring parameter:

    • Enable Fault Monitoring: Yes

  11. Configure the following QoS parameters:

    • QoS Trust: None

    • QoS Remark: DSCP EF for voice traffic

  12. Configure the following Advanced parameters:

    • Shape Outbound Traffic: Optional

    • Rate Limits: Optional

  13. Configure the following Telemetry parameters:

    • IP Client Tracker: Enable

    • IP Tracking Client Limit: Set (For example: 10)

    • Enable Application Recognition: Enable

    • Enable Flow Telemetry for Central: Enable

  14. Click Create to save the profile.

    The newly created profile is added to the Port Profiles list.

    For more information, see Port Profile for Switches.

Interfaces > Interface Profile

Use this port profile to pre‑map port roles for quick switch turn‑up. It is ideal for large deployments that require consistent layouts, saves time during provisioning, and ensures predictable configurations across the network.

An Interface Profile in HPE Aruba Networking Central allows you to group ports and assign port profiles for uplinks and downlinks, ensuring consistent configuration across multiple switches.

To create an interface profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select one of the following options:

    • Library

    • Global

    • Site Collections

    • Sites

    • Devices

    • Device Groups

  3. On the Interfaces card, click Interface Profile (Beta).
    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Interface Profile (Beta) card, click Manage.

    The Interface Profile (Beta) list view is displayed.

  4. Click Create Profile.
    The Create Profile side panel is displayed.

  5. Enter the Interface profile parameters:

    • Name: Campus-Access-Layout

    • Description: Voice Access profiles

  6. In the Device Type section, configure the following parameters:

    • Device: The device type is set and locked to Switch by default.

    • Type: Standalone

      Note:

      Only AOS-CX switch models are currently supported.

    • Model: CX 6300M

    • Number of Ports: CX 48SFP 4SFP

  7. In the Uplink Port Profile and Downlink Port Profile sections, configure the following parameters:

    • Ports: 14-18

    • Assigned Port Profile: User-Voice-Access

    • Add Uplink Ports if needed:

      • Ports: 49-52

      • Assigned Port Profile: Uplink-Trunk

    Click the add icon.

  8. Click Create.

  9. If created at the Library scope, hover on the profile to which you want to assign a scope, as required.

For more information, see Interface Profile.

Interfaces > Switch Interface Configuration Profile - Link Aggregation Group (LAG)

Use this profile to increase bandwidth and redundancy on uplinks. It is ideal for dual-homed servers or aggregation links, improves resiliency, and eliminates STP blocking.

Ethernet Link Aggregation is a networking technique that combines multiple physical Ethernet connections into a single logical link, known as a Link Aggregation Group (LAG). This approach enhances bandwidth and reliability in network communications.

Benefits of Link Aggregation

  • Increased Bandwidth—By distributing traffic across multiple physical links, LAG allows for greater throughput than any single link could provide.

  • Enhanced Reliability—If one link fails, traffic is automatically rerouted through the remaining active links, ensuring continuous connectivity.

Example Scenario

Consider two devices, Device A and Device B, connected by three Ethernet cables that are grouped into a single LAG. The total bandwidth of the LAG is equal to the sum of the individual links. If one cable fails, the system dynamically redirects traffic to the remaining two cables, maintaining uninterrupted service.

Key Components

  • Aggregation Group—A set of physical interfaces combined for redundancy and load balancing.

  • Member Ports—The individual physical interfaces within the aggregation group.

  • Aggregate Interface—A logical interface used to configure and manage the aggregation group.

Link Aggregation Modes

LAG can operate in two primary modes:

  1. Static LAG

    • No protocol communication occurs between devices.

    • Link failures are not automatically detected.

    • Misconfigurations can be difficult to troubleshoot due to the lack of signaling.

  2. Dynamic LAG (LACP)

    • Uses the Link Aggregation Control Protocol (LACP) to manage member ports.

    • Devices exchange Protocol Data Units (PDUs) to monitor link status.

    • Automatically detects and responds to link failures.

    • Reduces configuration errors and simplifies network management.

Both Layer 2 and Layer 3 aggregation groups support static and dynamic modes.

The following figure illustrates how Ethernet Link Aggregation (LAG) combines multiple physical interfaces into a single logical connection.

Figure 19: Ethernet Link Aggregation

Steps to Configure LAG

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.

    The Profiles tab is displayed.

  2. In the left navigation menu, select Devices.

    The Devices list view is displayed.

  3. Select a switch from the list.

    The Profiles Management view for the selected switch is displayed.

  4. On the Interfaces card, click Switch Interface Configuration.

  5. Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Switch Interface Configuration card, click Manage.

    The Switch Interface Configuration list view is displayed. Additionally, the Switch Interface Configuration page displays the faceplate representation of the selected switch.

  6. Under the Ports tab, click the port name you want to configure.
    The Configure Interface side panel is displayed.

  7. Click Create LAG.
    Create LAG form is displayed in the side panel.

    Note:

    LAG interface configuration post-onboarding may cause discrepancies in maximum member support between the visual interface and the command-line interface.

  8. Configure the following parameters:

    • LAG ID & Description—Assign a unique identifier and add a description for the LAG.

    • Type—Choose between LAG (standard aggregation) or MCLAG (multi-chassis aggregation).

    • Mode—Select one of the following modes:

      • Static—No negotiation, manually configured.

      • LACP—Uses the Link Aggregation Control Protocol for dynamic negotiation.

    • LACP Mode (if LACP selected)—Select one of the following modes:

      • Active— Initiates LACP negotiation.

      • Passive— Responds to LACP negotiation.

    • VLAN Mode—Typically set to Trunk to carry multiple VLANs.

    • Native VLAN & Allowed VLANs—Select the native VLAN and specify which VLANs are allowed on the LAG.

  9. Apply and Save Configuration.

    • Review your settings.

    • Click Apply or Save to create the LAG.

    • Confirm that the LAG is successfully created and the participating ports are now part of the LAG.

Step 4—Configuring Routing and Authentication Profiles

To configure routing and authentication profiles, see the following topic:

Security > AAA Authentication Profile

Use this profile for centralized authentication with 802.1X and MAC authentication. It is ideal for mixed environments with fallback during outages and delivers consistent edge security and survivability.

This section outlines the configuration steps to enable and manage AAA (Authentication, Authorization, and Accounting) services for AOS-CX switches through HPE Aruba Networking Central. AAA provides centralized authentication, authorization, and accounting for administrative and network access using RADIUS or TACACS+ servers.

Prerequisites

  • Switches onboarded and connected to HPE Aruba Networking Central

  • Proper licensing (Foundation or Advanced)

  • RADIUS server credentials available

  • Administrator privileges in HPE Aruba Networking Central

Configuration Steps

  1. Define Authentication Servers

    1. At the Library scope, on the Security card, click Authentication Servers.

      Figure 20: Authentication Server


    2. Click Create Profile.

    3. Select Auth Server Mode as RADIUS (default).

    4. Enter Server Name and IP Address/FQDN.

    5. Enter Shared Secret password that matches on the RADIUS server.

    6. Enter the Authentication Port as 1812 and Accounting Port  as 1813. Both are defaults.

    7. Click Create.

    8. Assign a scope and a device function to the profile.

  2. Create a Server Group

    1. At the Library scope, on the Security card, click Authentication Server Group.

    2. Click Create Profile.

    3. Enter the name for the server group.

    4. Select the authentication server(s) from the list created in Step 1.

    5. Click Create.

    6. Assign a scope and a device function to the profile.

  3. Configure AAA Authentication Profile

    1. At the Library scope, on the Security card, click AAA Authentication.

    2. Click Create Profile.

    3. Enter the name for the AAA Authentication profile.

    4. Select Authentication Protocol from the drop-down list.

    5. Specify Client Limit This step is optional.

    6. Select the server group,

    7. Set the fallback method to AAA, then device local (recommended).

    8. Click Create.

    9. Assign a scope and a device function to the profile.

  4. Enable AAA on the Switch System profile.

    1. Create a new Switch System profile.

    2. Enter the name for the profile.

    3. Under AAA, select Enable 802.1X and Enable MAC Authentication checkboxes to enable 802.1X and MAC authentications.

    4. Select 802.1X Authentication Server Group  and MAC Authentication Server Group from the drop-down list.

  5. Click Create.

  6. Create a Port Profile

    1. Navigate to Interfaces > Port Profile.

    2. Enter the following details:

      • Profile Name

      • VLAN Mode: Access

      • Access VLAN

      • Under Security, select the Enable Port Authentication checkbox and select the previously created AAA profile from the AAA Profile drop-down list.

  7. Create an Interface Profile

    1. Navigate to Interfaces > Interface Profile.

    2. Enter the following details:

      • Profile Name

      • Under Port Profile Assignment, select the port profile.

    3. Apply to the desired interfaces or port groups.

    4. Save and push the configuration.

CLI Template Example - Running Configuration

To access the switch CLI through HPE Aruba Networking Central:

  1. Navigate to Troubleshooter from the Site UI.

  2. Select Remote Console.

  3. Choose the desired Device.

  4. Enter your login credentials.

  5. Click Start Session.

The following is a sample running configuration for AAA authentication:

show running-config ! radius-server host 10.82.64.184 key ciphertext radius-server host 10.82.64.185 key ciphertext aaa group server radius SG1 server 10.82.64.184 server 10.82.64.185 ! aaa group server radius SG2     server 10.82.64.184     server 10.82.64.185 ! #show running-config aaa authentication port-access ! aaa authentication port-access dot1x authenticator radius server-group SG1     enable aaa authentication port-access mac-auth     radius server-group SG1     enable interface 1/1/7     aaa authentication port-access dot1x authenticator         radius server-group SG1         enable interface 1/1/8     aaa authentication port-access dot1x authenticator         radius server-group SG1         enable

Best Practices

The following are the best practices for AAA authentication:

  • Use redundant servers for resilience.

  • Always keep local administrator credentials for fallback.

  • Regularly audit AAA logs in HPE Aruba Networking Central.

  • Synchronize time (NTP) between the switch and RADIUS/TACACS+ servers.

Step 5—Configuring Network Policies

Network policies in HPE Aruba Networking Central enable administrators to enforce security and access controls across switches. These policies help define roles, permissions, and traffic rules, ensuring consistent and secure network behavior.

To configure network policies, complete the following steps:

  1. Configuring Access Control Policies for Switches

  2. Managing Roles and Policies for Switches

Configuring Access Control Policies for Switches

Access control policies in HPE Aruba Networking Central provide granular traffic management beyond VLAN segmentation. These policies are useful for restricting management access, isolating IoT devices, and improving security through reusable configurations.

To implement access control by configuring Access Control Lists (ACLs), complete the following steps:

  1. Creating an ACL

  2. Adding Rules to the ACL

  3. Applying the ACL to Switch Ports or VLANs

Creating an ACL

To create an Access Control List (ACL), complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Configuration Overview dashboard is displayed with the network and connectivity information.

  2. Click Library, and then click the Roles & Policies tab on the right.

  3. Under Security Policies card, click Manage.

  4. Under Network Policies card, click Manage to view the existing ACLs or create a new one.

  5. Click Create Policy.

  6. In the Create Policy side panel, configure the following parameters:

    • Name—Enter a name of the ACL.

    • Description—(Optional) Enter a description of the ACL.

    • Switch Specific Parameters—Select the check box to view Switch Parameters.

      • Access List—Select the check box.

    • Create—Click to create an empty ACL.

    Figure 21: Create ACL

    The ACL is added to the Network Policies table.

Note:

A new ACL starts with an implicit deny rule. You must add rules to allow the desired traffic.

Adding Rules to the ACL

To add rules to the ACL created before, complete the following steps:

  1. In the Network Policies table, click the ellipsis icon against the ACL and select Add Rule.

    Figure 22: Add Rule Option for ACL

    The Create Rule panel is displayed on the right.

  2. Example—To restrict SSH and ICMP access to the in-band management interface of a switch to traffic on a Layer 3 (L3) enabled VLAN, complete the following steps:

    1. Create a new rule:

      1. Description—Enter "Allow SSH".

      2. Source and Destination—Select Any from the drop-down list.

      3. Service/Application—Select Service from the drop-down list.

      4. Service—Select svc-ssh from the drop-down list.

      5. Create Another—Select the check box, then click Create.

      Figure 23: Create Rule for ACL

    2. Create another rule:

      1. Description—Enter "Allow ICMP echo/ping".

      2. Source—Select Network from the drop-down list.

        • IPv4 Subnet—Enter "10.100.1.0/24".

      3. Destination—Select Any from the drop-down list.

      4. Service/Application—Select Service from the drop-down list.

      5. Service—ICMP is not listed by default, so you must click New Service to create a custom service:

        1. In the Create a Service side panel, configure the following parameters:

          • Name—Enter a name like "ICMP Echo Request"

          • Description—(Optional) Enter a description for the service.

          • Protocol—Select Protocol Number.

          • Protocol Number—Enter "1".

          • Restrict to following application (ALG)—Select ICMP from the drop-down list.

          • ICMP Type—Enter "8".

          • Click Create to save the custom service.

        2. Click Create in the Create Rule side panel.

        The new rule is created along with the custom service.

      Note:

      Expand the arrow next to the ACL to view the rules. The implicit deny rule is hidden. Use the ellipsis for options like add, delete, or reorder rules.

Applying the ACL to Switch Ports or VLANs

You can apply ACLs in one of the following three ways:

  • To L3 Enabled VLAN—Select Switch Specific Parameters followed by Access List, then application direction(s) and ACL to be applied.

  • Within Port Profiles—Select the Access List check box, then configure application direction(s) and ACL to be applied.

  • At Switch Level: Under Switch Interface Configuration, select any individual port(s), select the Access List checkbox, and configure application direction(s) and ACL to be applied.

Applying the ACL to VRF

You can apply ACLs to VRF using the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, navigate to Library.

  3. On the Routing & Overlays card, click VRF.

  4. Create a VRF (for example, red) if it is not the default or management VRF. The default VRF should already exist.

  5. Select the Advanced option checkbox. This enables you to apply or reference a policy in the control plane.

Managing Roles and Policies for Switches

Roles and policies in HPE Aruba Networking Central work together to control user access and enforce security across your network. By defining user roles such as employees, guests, and IoT devices, and applying security policies to these roles, organizations can achieve consistent, business-aligned segmentation and centralized security management.

Roles determine the level of network access for different user groups, while policies define the rules that govern connectivity and traffic behavior for those roles. This approach simplifies deployment, enhances security, and ensures uniform policy enforcement across sites and devices.

Roles and policies can be applied at multiple scope levels:

  • Global—Applies to all switches within selected device functions.

  • Sites/Site Collections—Applies to switches at a specific site or site collection.

  • Device Groups—Applies to all switches within a specific device group.

  • Devices—Applies to individual switches.

To manage roles and policies for switches, complete the following steps:

  1. Creating a Role

  2. Creating Role-Based Policies

Creating a Role

To create a user role, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon

    The Configuration Overview page is displayed.

  2. Click Library in the left navigation pane.

  3. Click the Roles & Policies tab.

  4. Under Roles card, click Manage.

    The Roles table displays the device default roles that are pre-created and assigned to respective device function(s) at Global scope.

  5. To create custom user role, click Create Role.

    The Create Role panel is displayed on the right.

    Note:

    A role can be created only at Global scope. If you create a role at any other scope, HPE Aruba Networking Central will display error with a failed message.

  6. Configure the following parameters:

    • Name—Enter a name of the user role.

    • Description—(Optional) Enter a description of the user role.

    • VLAN ID—Enter a value between 1 and 4094 in numbers to specify the VLAN ID.

    • Captive Portal Profile—(Optional) Select the captive portal from the drop-down list. To create a new captive portal profile, click New Captive Portal. For more information, see Captive Portal Authentication Profile.

    • GPID—The Global Policy Identifier (GPID) parameter is auto-populated by default. You can also enter a unique GPID value in the range of 100-8191.

      GPID values from 0 – 99 are reserved by the system for different device default roles.

    • Under Device-Specific Parameters, select Switch to configure additional device-specific parameters. For more information, see Creating a Role.

  7. Click Create to add the user role.

    Figure 24: Create Role

  8. In the Roles table, hover over the role that you created in the previous step, and click the ellipsis icon.

    Figure 25: Assign Device Function for User Role

  9. Select Assign.

    The Apply Role panel is displayed on the right.

  10. Under Device Function, select Access Switch.

  11. Under Scopes, click + to view the Add Scope panel.

  12. Select the hierarchy from the Scope Level drop-down list.

  13. Click Add.

  14. In the Apply Role panel, click Assign.

    The Roles table displays the updated information for the role under the Assigned Device Function column.

    Note:
    • Roles are not provisioned to the device until there is a security policy associated with the created role.

    • You can create user roles and policies at lower hierarchy. Navigate to the appropriate hierarchy (Site Collection, Site, Devices, or Device Group and select the Device Function (Access Switch) from the drop-down list to create roles and the relevant user role policies.

Creating Role-Based Policies

To create a role-based policy, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon

    The Configuration Overview page is displayed.

  2. Click Library in the left navigation pane.

  3. Click the Roles & Policies tab on the right.

  4. Under Security Policies card, click Manage.

  5. Under Role-based Policies card, click Manage.

  6. In the Role-based Policies table, click Create Policy to create security policies for the previously created user role.

  7. In the Create Policy side panel, configure the following parameters:

    • Name—Enter a name of the policy.

    • Description—(Optional) Enter a description of the policy.

  8. Click Create.

  9. In the Role-based Policies table, hover over the policy that you created in the previous step, and click the ellipsis icon.

    Figure 26: Assign Device Function for Role-Based Policy

  10. Select Assign.

    The Apply Profile panel is displayed on the right.

  11. Under Device Function, select Access Switch.

  12. Under Scopes, click + to view the Add Scope panel.

  13. Select the hierarchy from the Scope Level drop-down list.

  14. Click Add.

  15. In the Role-based Policies table, click the ellipsis icon for the policy.

  16. Click Add Rule.

    The Create Rule panel is displayed on the right.

  17. Configure the following parameters:

    • Description—(Optional) Enter a description of the rule.

    • Source—Select a source from the drop-down list. The following options are available:

      • Any

      • Access Role

      • Network

      • Host

      • Network Destination

      Note:

      When you select Network or Host from the Service/Application drop-down list, the Use Alias check box is displayed. When you select the check box, the corresponding Alias parameter is displayed. Click the New Alias option to create a new alias under the rule. For more information, see Creating a Service.

    • Source Role Options——Select role options from the drop-down list. The following options are available:

      • Role

      • Network Destination

      • Host

      • Network

      • Local IP

      • User

      • Any

    • Destination—Select a destination from the drop-down list.

    • Access Role—Select an access role from the drop-down list. You can also create a new access role by clicking the New Role option under Access Role. For more information, see Creating a Role.

    • Destination Roles Options—Select

    • Service/Application—Select a service or an application from the drop-down list. The following options are available:

      • Any

      • Service

      • Application

      • Application Category

      • Web Category/Reputation

      • Protocol and Port

      Note:

      Depending on the option that you select from the Service/Application drop-down list, the corresponding parameter is displayed.

      When you select Service from the Service/Application drop-down list, the corresponding Service parameter is displayed. You can also create a new service by clicking the New Service option under Service. For more information, see Creating a Service.

    • Service/Application/Application Category/Web Category/Reputation—Select one from the drop-down list.

    • Action—Select an action from the drop-down list.

    • Time Profile—Allows you to apply the rule only during certain times (e.g., business hours).

    • Log—Enable logging for traffic that matches this rule.

    • QoS—Select Quality of Service options for both dropdowns: DSCP and 802.1P.

      • DSCP —Differentiated Services Code Point for prioritizing traffic.

      • 802.1P —Layer 2 priority marking for traffic classification.

    • Create Another—Quickly create another rule after saving this one.

  18. Click Create.

    The new rule is added to the specified role-based policy.

Note:
  • Network administrators can create complex policies based on their deployment requirements. Policies rules can be any combination of Access Role, Network, Host, Network Destination and Service/Application.

  • Multiple rules can be configured within the policy and have the ability to order the rules as required.

  • The configuration activities are recorded in the Audit Trail page. You can view the policy configuration being provisioned to the device by selecting the Action - In Progress row and selecting View Details from the ellipsis icon.

Figure 27: Audit Trail for Configuration Activities

Additional Resources

Refer to this section for resources to help with AOS-CX switch configuration.

Configuring CLI Viewer

The CLI viewer provides access to both the Running and Candidate configuration of the device. The Running Config displays the current configuration on the CX switch, while the Candidate Config shows the configuration provisioned by Central.

Note:

CLI viewer is only available at the Device level.

To use the CLI viewer functionality, complete the following steps:

  1. Click on your switch selection, under Devices. The CLI Viewer and CLI Snippets tabs appear on the upper right-hand corner.

  2. Click on CLI Viewer.

    Note:

    Devices with large configurations may take longer to load.

  3. Once in CLI Viewer, you are provided with two tabs and one CLI screen:

    1. Candidate Config - located on the left-hand side, displays desired configuration for the switch based on the Uplink Port Profile and Downlink Port Profile selections made

    2. Running Config - located on the right-hand side, displays current configuration on the switch

    3. CLI screen - located directly beneath Candidate and Running Configtabs, displays CLI configuration for the device

  4. Click in to search within the Candidate or Running Config tabs, and hit enter. Results will be highlighted in orange.

  5. Copy or download the Candidate or Running Config by selecting one of the two icons at the upper right-hand corner of the CLI Viewer.