Troubleshooting Firewall Sessions for a Client

To navigate to the Firewall Sessions in the Troubleshooter in a Site dashboard, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, select a site from the Sites menu.

    The Site dashboard is displayed with network, clients, applications, security, and alerts information for the site.

  2. Alternatively, you can click the Expand icon on the Sites menu to search for a site from the list.

  3. Click the required site name from the search results.

    The Site dashboard is displayed with network, clients, applications, security, and alerts information for the site.

  4. Click Clients in the Site dashboard.

    The Clients page is displayed in the default List view.

  5. To access the Troubleshoot page, follow one of these steps:

    • Hover over the specific AP on which you want to perform the troubleshooting test. The Troubleshooter icon will is displayed.

    • Click anywhere on the row of the selected AP. The side panel for the selected AP is displayed on the left.

    • Click directly on the AP you wish to troubleshoot. The selected AP context page is displayed.

  6. On the Clients table, click anywhere on the particular client row.

    The selected client panel is displayed on the left.

  7. Alternatively, on the Clients table, click on the particular client on which you want to perform the troubleshooting test.

    The selected client context page is displayed.

  8. Click the Troubleshooter icon.

    The Troubleshoot page is displayed.

  9. Click Firewall Sessions.

    The Firewall Sessions page is displayed.

The Firewall Sessions table displays the following information:

 

Table 1: Firewall Sessions Table Parameters

Parameter Description

Receive Time

Displays the date and time when the session was captured in HPE Aruba Networking Central.

Source IP

Displays the IP address of the client that initiated this session.

Destination IP

Displays the destination IP address of the server or endpoint receiving the traffic.

Source Port

Displays the source port number used by the source device.

Destination Port

Displays the destination port number used by the target application

Protocol

Displays the type of communication protocol used for the session.

Application

Displays the list of applications in the session.

Flags

Displays the TCP flags.

Total Packets

Displays the number of packets transferred in the session.

State

Displays the state of the connection state. For example, Active, Inactive, Denied.

Action

Displays the type of action taken on the session. For example, Allowed or Blocked.

WebCC Category

Displays the Web Content Classification (WebCC) category.

Reputation

Displays the trust level of the domain or URL in the session.

Reputation Score

Displays the score representing domain or web content risk level.

Application Category

Display the category of the application.

Search Bar

In the search bar, you can search the Firewall Sessions table using only the IP address. When you search by IP address, it searches for new sessions from the clients that match source or destination IP.

You can use the quick filters to search firewall sessions by both Action and Status categories. In the Actions category, you can filter for Blocked or Allowed sessions, while in the Status category, you can select Active, Inactive, or Denied sessions.

Figure 1: Session filters

Filters

In the Firewall Sessions page, click the filter icon to view the Filters pop-up window that allows you to filter firewall sessions for clients.

You can filter the firewall sessions for gateways based on Source Port, Destination Port, and Protocol criterias.

To remove the filters from the Filters pop-up window, click Clear and then click Apply. Additionally, you can click Clear Filters in the Firewall Sessions page to remove the filters. These filters support both searching and scrolling to search for specific filters.

Figure 2: Filters Pop-up for Clients

Table Utilities

You can sort, customize the column visibility, and adjust the width of the columns displayed in the table, as required.

  • To sort a column either in ascending or descending order in the table, complete the following steps:

    1. Click the column name that you want to sort.

    2. Perform either of the following:

      • To sort in ascending order, click the up arrow icon.

      • To sort in descending order, click the down arrow icon.

    Note:

    You can sort the Receive Time, Source IP, Destination IP, Source Port, Destination Port, Application, Protocol, Domain and Total Usage columns in the Firewall Sessions table for a client.

  • To adjust the width of the columns, complete the following steps:

    1. Hover over the left or right edge of the column that you want to adjust.

      You can identify the edge of the column when the mouse pointer changes to the adjust shape.

    2. Click and drag the edge to adjust the width of the column.

    3. You can click Reset Column Sizes in the Actions menu to reset the column widths.

  • The Table Menu icon allows you to customize columns and reset column sizes of the table.

    • To customize columns and reset column sizes, complete the following steps:

      1. Click the table menu icon.

        The Actions menu is displayed.

      2. Click Customize Columns.

        The Customize Columns pop-up window is displayed.

      3. Complete either or both of the following steps as required:

        • Select the column names to enable or disable the visibility of that column in the table.

        • Click and hold the action icon next to the column you want to move, and drag it to a new position.

      4. To clear your column visibility settings, click Reset to Defaults.

      5. Click Apply.

        The adjusted columns are displayed in the table.