Configuring MPSK

To create an MPSK profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the Menu icon.

  2. In the Central NAC card, click Manage.

    The NAC Monitoring page is displayed.

  3. Click the Configuration icon.

    The configuration view appears, which displays the Authentication Profiles, Authorization Policies, Identity Management, Visitors, and Messaging cards.

  4. In the Authentication Profiles card, click Manage.

  5. Click Create Profile.

  6. In the Create Profile side panel, configure the following parameters:

    • Name—Enter a name of the profile.

    • Description—Enter a description of the authentication profile.

    • Authentication Type—Choose MPSK.

    • Network—From the Network drop-down list, select the network to be configured with this profile.

    • Identity Store—Select the required identity store from the drop-down list.

  7. Under MPSK Settings enter the following details:

    • Organization Name—Enter the name used in onboarding workflows.

    • Pre-Shared Key (PSK) Format—Choose Passphrase or Random Password to configure the format of the pre-shared key.

  8. Expiration Policy—Administrators can configure an expiration policy for user-owned MPSK passwords. Parameters for expiration policy appears only with the Central NAC subscription license. The following are the parameters:

    • Expiration Period—Select the period when the pre-shared key will expire after it is created or reset. Choose a pre-configured option from the drop-down like 1 month, 3 months, 6 months, or 1 year. For the custom option, you can choose the time period as hours, days, weeks, months, or years.

    Note:

    For user-owned MPSKs, users will receive advanced warnings and a final notification, via email, about their MPSK password expiration:

    • An alert seven days before expiration.

    • A reminder one day before expiration.

    • A notification when the password expires.

  9. Click Create.

    The authentication profile is created and is listed in the Authentication Profiles page.

  10. Click Copy URL under User Onboarding to share the onboarding URL with users to retrieve their MPSK passwords.

    Note:

    This option will be available only if an external identity store is selected.

Viewing Web Portal

Administrators can view and access the web portal from the Authentication Profiles page.

  1. In the Authentication Profiles page, hover over an MPSK profile and click the ellipsis icon.

    A pop-up menu is displayed.

  2. Click View Portal.

    The captive portal page opens in a new browser window.