Security Dashboard in List View in a Site Context

The Security dashboard in the List view provides a tabular representation of all the blocked session reported by Aruba access points, Aruba CX switches and Aruba gateways managed via HPE Aruba Networking Central.

On the Security dashboard, the Time Range drop-down allows you to view and analyze historical data of blocked sessions only for periods of 3 hours, 1 day, and 7 days.

Figure 1: Security Dashboard in List View

The Security table displays the following information:

 

Table 1: Security Table Parameters

Parameter Description

Session Capture Time

Displays the date and time when the session was captured in HPE Aruba Networking Central.

Client Name

Displays the name of the client.

Source IP

Displays the IP address of the client that initiated this session.

Destination IP

Displays the destination IP address of the server or endpoint receiving the traffic.

Destination Port

Displays the Layer 4 port used for the session.

Application

Displays the specific application identified for this session.

Note:

This column can be empty if the session is denied before classifying the application.

Role

Displays the assigned user role.

Action

Displays the type of action taken on the session. For example, Allowed or Blocked.

Total Usage

Displays the total data used.

Security Risk

Displays the type of reputation of the session.

URL

Displays the URL that was accessed during the session.

Protocol

Displays the type of communication protocol used for the session.

Category

Displays the application category.

Blocked Reason

Displays the cause of the blocked session. The cause may be one of the following:

  • ACL—Session blocked due to access control rules.
  • Deep Packet Inspection—Session blocked due to application classification based on Deep Packet Inspection and associated policies; usually applies to any pre-defined or custom applications.
  • Web Classification—Session blocked based on Web Content Classification or Web Reputation and associated policies; usually applies to web sites and web URLs.
  • IP Reputation—Session blocked based on IP Reputation policies, usually applies to IP addresses.
  • Geo Location—Session blocked based on Geo Location policies, usually applies to geographic location of source or destination IP address.
  • Others—Session blocked due to any other reasons not covered above, including session and network ACLs.

Session Attempts

Displays the total count of attempts between same source and destination.

Bytes Sent

Display the total amount of data sent in bytes.

Bytes Received

Display the total amount of data received in bytes.

Device

Displays the name of the device sending the session information.

TLS Server Version

Displays the Transport Layer Security (TLS) version. This column is not available for APs and gateways. TLS Version is applicable only on Aruba CX switches running AOS 10.14 or higher versions.

Geo Location

Displays the country name based on the destination IP address of the session.

Source VRF

Displays the source VRF.

Client Username

Displays the username of the client.

Client MAC Address

Displays the MAC address of the client.

Tags

Displays the tags associated to the client

WLAN

Displays the name of the WLAN to which the client is connected.

Type

Displays the type of client. For example, Wireless or Wired.

VLAN

Displays the VLAN number.

LAN Latency

Displays the latency of the LAN, measured in milliseconds(ms).

WAN Latency

Displays the latency of the WAN, measured in milliseconds(ms).

End to End Latency

Displays the end to end latency, measured in milliseconds(ms).

Rx Packets

Displays the number of Rx packets.

Tx Packets

Displays the number of Tx packets.

Encapsulation

Indicates whether the session traffic is tunneled to a gateway from an AP.

Note:

Devices running AOS-8.x do not export Destination Port, Protocol, or Sessions Attempt in telemetry data. As a result, these fields appear as NULL or UNKNOWN on the Security page.

Search Bar

On the Security page, you can filter sessions from the Security table depending on your criteria. You can enter keywords in the search bar to find a specific session from the Security table. In the search bar, you can search and filter the Security table using only the application name and device name.

Additionally, you can use the quick filters to filter sessions as per Blocked and Allowed type, or any combination of the options.

Note:

On the Security page, the default Action quick-filter is set to Blocked.

Figure 2: Search Bar

Filters

In the Security page, click the filter icon to view the Filters pop-up window that allows you to filter sessions based on Session Capture Time, Well-known Destination Port, Protocol, Role, Security Risk, Category, and Geo Location.

Note:

The time range in the Session Capture Time slider corresponds to the time range selected in the Time Range drop-down on the Security Dashboard in List view.

To remove the filters from the Filters pop-up window, click Clear and then click Apply. Additionally, you can click Clear Filters on the Security page to remove the filters.

Table 2: Filters Pop-Up Window

Table Utilities

You can sort, customize the column visibility, and adjust the width of the columns displayed in the table, as required.

  • To sort a column either in ascending or descending, complete the following steps:

    1. Click the column name that you wish to sort.

    2. Perform either of the following:

      • To sort in ascending order, click the up arrow icon.

      • To sort in descending order, click the down arrow icon.

    Note:

    You can sort the Session Capture Time, Total Usage, Bytes Sent, and Bytes Received columns in the Security table.

  • To adjust the width of the columns, complete the following steps:

    1. Hover over the left or right edge of the column that you wish to adjust.

      You can identify the edge of the column when the mouse pointer changes to the adjust shape.

    2. Click and drag the edge to adjust the width of the column.

  • To customize columns and reset column sizes, complete the following steps:

    1. Click the Table Menu icon.

      The Actions menu is displayed.

    2. Click Customize Columns.

      The Customize Columns pop-up window is displayed.

      1. Complete either or both of the following steps as required:

        • Select the column names to enable or disable the visibility of that column in the table.

        • Click and hold the action icon next to the column you wish to move, and drag it to a new position.

        • Click Apply.

        • Click Reset to Defaults to clear the column visibility settings.

      2. Click Reset Column Sizes to reset the column widths.

      3. Click Export to export the Security table data.

        Note:

        The exported .csv file contains all the data from the columns in the Security table. It is named as export-session-list-table-TIMESTAMP.csv.

Session Details

Clicking on a row of a Security table displays the Session details page for viewing more information about an allowed or blocked session.

The Session details table displays the following information:

 

Table 3: Session Details Table Parameters

Parameter Description

Security

Source Role

Displays the assigned user role.

Reason

Displays the reason why the session was blocked.

Geo Location

Displays the country name based on the destination IP address of the session.

Source VRF

Displays the source VRF.

Action

Displays the type of action taken on the session. For example, Allowed or Blocked.

Risk Score

Displays the risk score of the session.

Domain

Displays the root domain URL.

Client Info

Client Name

Displays the name of the client.

User Name

Displays the name of the user.

WLAN

Displays the name of the WLAN to which the client is connected.

VLAN

Displays the VLAN number.

MAC Address

Displays the MAC address of the client.

Tags

Displays the tags associated to the client

Type

Displays the type of client. For example, Wireless or Wired.

Detail Summary

Application Name

Displays the name of the application.

LAN Latency

Displays the latency of the LAN, measured in milliseconds(ms).

Tx Packets

Displays the number of Tx packets.

Note: Access points do not report packet counts. This field is not populated for AP clients.

End to End Latency

Displays the end to end latency, measured in milliseconds(ms).

WAN Latency

Displays the latency of the WAN, measured in milliseconds(ms).

Rx Packets

Displays the number of Rx packets.

Note: Access points do not report packet counts. This field is not populated for AP clients.

Category

Displays the category of the session.

Encapsulation

Indicates whether the session traffic is tunneled to a gateway from an AP.

Note:

The Policy column does not display any information for any sessions.

Role-Based Access Control (RBAC) for Firmware Visibility

For more information on RBAC, see Role-Based Access Control (RBAC).

Where a user is restricted from viewing, the following message is displayed:

Figure 3: RBAC for Firmware Visibility