RBAC Support

Central NAC supports a set of built-in roles with different privileges and access permissions. With role based access (RBAC) support, administrators can configure the Central NAC Guest Operator role and assign this role to specific users and provide access permissions.

Table 1: Roles and Permissions

Role

Permissions

Central NAC Guest Operator

User has complete access to the visitors module in Central NAC. User can perform all operations in the visitors module, like view (read only), create, update, and delete (read write).

Central NAC Administrator

Administrator has complete access to all menu options as well as the monitoring and configuration pages. Admin can view (read only), create, update, and delete (read write) authorization policies and rules, authentication profiles, and identity stores.

Note:

Central Administrators and custom roles with Resource Restriction Policies (RRP) policy will not have write access to HPE Aruba Networking Central Library. They can create local configurations and assign (scope map and scope unmap) at the permitted scopes. For more information, see Resource Restriction Policies in the HPE Greenlake Cloud User Guide

Users with read-only access cannot perform any configuration tasks. Due to restricted permissions, certain actions are unavailable. If a user attempts such an action, a warning message is displayed indicating that the user does not have sufficient permissions.