Creating a Policy
Some of the configuration is subject to licensing. For more details, see Licensing.
To create an authorization policy, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the Menu
icon. -
In the Central NAC card, click Manage.
The NAC Monitoring page is displayed.
-
Click the Configuration
icon. -
In the Authorization Policies card, click Manage.
-
Click .
-
In the Create Policy side panel, configure the following parameters:
-
Name—Enter a name of the policy.
-
Description—Enter a description of the policy.
-
Enabled—Enable the policy. By default, this check box is selected.
-
Policy Type—Select a policy type from the drop-down list to preload the policy configuration.
Note:-
Foundation license users can only select between User or Client policy.
-
Subscription license users can choose from User or Client or Custom policy type. Custom policies provide additional flexibility in configuring pre-conditions, identity stores, and attributes.
-
-
Authorization Context—Select the identity store from the Identity Provider drop-down list.
Note:The identity store options will be available based on the selected Policy Type.
-
If the policy type is User, the Identity Provider displays only corporate identity stores. If there is only one corporate identity store present, then it is pre-selected.
-
If the policy type is Client, the Identity Provider displays the MAC Address Store. The MAC Address Store is pre-selected.
-
If the policy type is Custom, the Identity Provider displays all identity stores. Selecting an identity store is optional for a Custom Policy Type.
-
-
Under Pre-conditions, select the required conditions for the policy. This can be done only for a custom policy type.
For instance:
-
Select the attribute Authentication Type
-
Select the operator is equal to
-
Select the value EAP-TLS
When you add a Site in the pre-condition, a search bar appears in the site drop-down. This allows you to search for a specific site. As you type in the search bar, the site list dynamically filters the results and displays only the sites that match the entered text. The list of sites appear in batches as you scroll to the bottom of the list and continues appearing until the full list is shown.
To add another condition, click the Add Condition icon.
Similarly, you can select the attribute, operator, and value for the condition. For more information on choosing the pre-conditions, see Attributes and Operators.
Note:For foundation and subscription license users, the pre-conditions are pre-defined and fixed. Users cannot add, update, or delete the pre-conditions. Only for custom policy type, the pre-conditions can be modified.
-
-
-
Click Create.
The policy is created and is listed in the Authorization Policies page.
Note:-
A maximum of 100 policies can be created. The Create Policy button is disabled once this limit is reached.
-
In the policies table, hover over an existing policy > click the ellipsis
icon and choose Add Policy Above to add a higher priority policy or choose Add Policy Below to add a lower priority policy.
-