Adding a Rule

To add a rule for an authorization policy, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the Menu icon.

  2. In the Central NAC card, click Manage.

    The NAC Monitoring page is displayed.

  3. Click the Configuration icon.

  4. Navigate to the Authorization Policies card and click Manage.

  5. In the Authorization Policies table, hover over the row, click the ellipsis icon, and click Add Rule.

    The Create Rule panel is displayed on the right.

    Note:

    To add a higher priority rule, hover over an existing rule, click the ellipsis icon and choose Add Rule Above. To add a lower priority rule, choose Add Rule Below.

  6. Configure the following parameters:

    • Name—Enter a name for the rule.

    • Description—Enter description.

      • Conditions—Select the matching criteria for this rule. Select the attribute, operator, and a value from each of the drop-down list.

        Note:
        • User groups appear at the bottom of the attribute list with the name of the identity store within parenthesis. These are arranged in an alphabetic order. If a user group is associated with more than one identity store, all the identity stores are listed in the parenthesis.

        • When creating a rule for a MAC Address with condition as MAC Address is equal to, you can also specify a MAC address without adding any delimiters.

        • The following attributes are displayed for a custom policy type:

        User policy

        • Client Tags

        • Client Category

        • User Groups

        Client policy

        • Client Tags

        • Client Category

    • Actions—Select one of the options, Allow Access or Deny Access.

    • Role—Select a role from the drop-down list. For more information about roles, see Creating a Role

    • Attributes—Select attributes listed in the drop-down and enter specific details in the text box below:

      • Allow MAC Caching—Select Yes or No to enable or disable MAC caching.

      • Session Timeout (hours)—Enter the number of sessions timeout duration in hours.

      • Simultaneous Sessions Limit—Enter the number of sessions that can be used. This limit applies to all authentication types that perform user-based authentication and is not specific to any particular method (such as MPSK).

      • VLAN ID—Enter a numeric VLAN ID.

      • Vendor Specific Attributes—Click this to view a list of vendors such as Juniper, Cisco, and so on. Click on a vendor to select the vendor specific attributes. The selected attributes are added and are listed under the Attributes.

    Note:

    HPE Aruba Networking Central foundation license has a default session timeout of eight hours. Only subscription license users can customize this time period.

  7. Click Create.

    The rule is created and appears under the policy in the Authorization Policies table.

    Note:

    For each authorization policy, a maximum of 32 rules can be created. The Create Rule button is disabled once this limit is reached.