Aruba Central User guide

Category
Software
Type
User guide

This manual is also suitable for

Aruba
SD-WAN Solution
User Guide
Copyright Information
© Copyright 2020 Hewlett Packard Enterprise Development LP.
Open Source Code
This product includes code licensed under the GNU General Public License, the GNU Lesser General
Public License, and/or certain other open source licenses. A complete machine-readable copy of the
source code corresponding to such code is available upon request. This offer is valid to anyone in
receipt of this information and shall expire three years following the date of the final distribution of
this product version by Hewlett Packard Enterprise Company. To obtain such source code, send a
check or money order in the amount of US $10.00 to:
Hewlett Packard Enterprise Company
6280 America Center Drive
San Jose, CA 95002
USA
Contents
Contents
Contents 3
About This Document 7
Intended Audience 7
Related Documents 7
Conventions 7
Terminology Change 8
Contacting Support 8
Aruba SD-Branch Solution 9
Why SD-WAN? 9
Key Features and Benefits 9
Understanding SD-WAN 10
What are the Solution Requirements? 11
Supported SD-Branch Components 12
Getting Started 15
Onboarding Devices to Aruba Central 15
Assigning Subscriptions to Aruba Gateways 16
Assigning Gateways to a Group 19
Assigning Gateways to Sites 20
Assigning Labels to Gateways 20
Assigning a Group Role to an Aruba Gateway Group 21
Connecting Aruba Gateways to Aruba Central 21
Recovering an Aruba Gateway 23
Configuring Communication Ports 24
Certificates 24
Provisioning Aruba Gateways in Aruba Central 27
Different Modes of Configuring Gateways and Gateway Groups 27
Configuring Branch Gateway Groups Using the Guided Setup 28
Configuring Branch Gateways Using the Guided Setup 41
Configuring VPN Concentrator Group Using the Guided Setup 48
Configuring VPN Concentrators Using the Guided Setup 58
Deploying Aruba Virtual Gateways 71
Features Supported by Virtual Gateway 71
Virtual Gateway Redundancy 71
Software Image for Virtual Gateways 71
Deploying Aruba Virtual Gateways in AWS 71
Deploying Aruba Virtual Gateways in Microsoft Azure 92
Deploying Aruba Virtual Gateways in VMware ESXi (Unmanaged Mode) 135
Provisioning Virtual Gateways to Groups 143
Troubleshooting Deployment Issues 144
High Availability Support for Aruba Virtual Gateways 144
Monitoring Virtual Gateways 151
Configuring an SD-Branch Network Using the Advanced Setup 152
Aruba SD-WAN Solution | User Guide 3
Contents | 4
Configuration Checklist 152
Configuring Address Pools for Aruba Gateways 152
Uploading Bulk Configuration Template 159
Configuring System Information on Aruba Gateways 159
Creating a New User with Certificate Authentication 169
Enabling Console Block 170
Configuring Servers for Management User Authentication 173
Configuring VLANs on Aruba Gateways 176
Configuring SLB using NAT 181
Configuring Ports 184
Configuring Uplinks 189
Managing 9004-LTE Branch Gateway 194
Configuring WAN Health Check 198
Configuring WAN Interface Bandwidth Priorities 200
Configuring the SD-WAN Overlay Network 202
Configuring the SD-WAN Hub Mesh Topology 209
Configuring Site-to-Site VPN 211
Configuring Site-to-Site VPN with GRE Tunnel 216
Configuring IKE Policies 223
Routing 228
Example of a Prefix List 235
Example of an OSPF Route Map 237
Example of a BGP Prefix List 247
Creating a Route Map 249
Configuration Example 251
Aggregating Routes 253
Configuring Policies for PBR 266
Configuring Policies for Dynamic Path Steering 269
SaaS Application Traffic Management with SaaS Express 273
Configuring Aruba Gateways for Application Visibility and Control 280
Enforcing a Common Security Policy for Wired and Wireless Users 289
Configuring Firewall Policies and ACLs 289
Configuring User Roles for Clients 302
Configuring Authentication Profiles 306
Applying Policies to Gateway Interfaces 332
SDBranch Redundancy 334
Configuring Aruba Gateways for Certificate-Based Authentication 340
Configuring Aruba Gateways for SNMP-Based Reporting 345
Viewing Gateway Configuration Status 346
Managing Configuration Overrides 346
Configuring Aruba Gateways for Syslog Message Collection 347
SD-WANOverlay Tunnel and Route Orchestration 351
Configuring Overlay Network Using SD-WANOrchestrator 351
Cloud Survivability 354
Advertising Overlay Routes 355
Monitoring SD-WAN Overlay Tunnels and Routes 362
Aruba SD-Branch Integration with Zscaler Cloud Security Service 385
Integrating SD-Branch with ZIA 386
Setting up Tunnels to ZIA 386
Additional References 390
Configuring Prisma Access 390
Aruba SD-WAN Solution | User Guide 5
Aruba SD-Branch Integration with Zscaler through Cloud Connect Service 397
Additional References 398
Configuring ZIA for API Access in Zscaler Admin Portal 398
Onboarding a Cloud Provider Account in Aruba Central 399
Orchestrating Tunnels to the Nearest ZIA Public Service Edge 400
Configuring Zscaler Nexthop List 401
Adding Nexthop List to PBR Policy 402
Verifying Tunnel Status 402
Aruba SD-Branch Integration with Prisma Access 403
Deployment Scenarios 403
Branch Gateways to Prisma Access 403
Regional Hub to Prisma Access 404
Supported IKE and IPSec Cryptographic Profiles 405
Aruba SD-Branch Integration with Check Point 407
Supported IKE and IPsec Cryptographic Profiles 407
Configuration Steps 407
Configuring Check Point for SD-Branch Integration 408
Configuring Aruba Gateways for Integration with Check Point 410
Aruba SD-Branch Integration with Symantec WSS 416
Integration Overview 416
Role-Based and Application-Based Routing 417
Supported IKE and IPSec Cryptographic Profiles 418
Configuring Symantec WSS 419
Micro Branch Redundancy Architectures 426
Supported Topologies 426
Configuring a Micro Branch with Instant APs 429
Configuring Support for Aruba VIA Service 434
Configuring VIA 434
Configuring VPN IP Pool 434
Defining IKEv1 Shared Secret 436
Configuring VIA User Role 436
Creating VIA Server Group for Authenticating VIA Users 436
Configuring VIA Authentication Parameters 437
Loading and Applying VIA Certificates 439
Configuring and Attaching VIA Connection Profile 439
Uploading VIA Installer to VPN Concentrator 444
Provisioning Gateways Using ConfigurationTemplates 446
Important Points to Note 446
Configuring Gateways Using a Template 446
Creating a Template Group 446
Assigning a Gateway to a Template Group 447
Creating a Configuration Template for Gateways 447
Customizing a Template Using Variable Definitions 449
Sample Template and Variables Files 451
Verifying Configuration Status 455
Backing up and Restoring Templates 455
Contents | 6
Monitoring SD-Branch 456
Monitoring Gateway 456
BGP Details >Neighbors 468
BGP Details >Routes 470
Device Info 482
WANSummary 484
WANAvailability 484
VPNAvailability 484
Usage 484
Throughput 484
Compression 484
Health Status 485
WAN Health—Global 508
WAN Health—Site 511
Monitoring Sites in the Topology Tab 512
Before You Begin 513
Grouping VPNCs 513
Viewing the Topology Tab 513
Monitoring SaaS Express 521
Gateway Alerts 524
Reports 526
Maintenance 537
Troubleshooting Devices 537
Enabling Gateway Logs 537
Gateway Diagnostic Tests 539
Updating Software Images on Aruba Gateways 545
Configuring Aruba Gateways for Syslog Message Collection 545
APIs 549
Chapter 1
About This Document
About This Document
This user guide describes the Aruba Software-Defined WAN (SD-WAN)Solution and provides detailed
instructions for setting up, configuring, and managing SD-WAN Gateways from Aruba Central.
Intended Audience
This guide is intended for network administrators who manage and monitor branch networks.
Related Documents
In addition to this document, see the following documents for more details on the SD Branch devices and
Aruba Central:
nAruba Central Help Center
nArubaOS User Guide
nHPE-ArubaOS Switch Management and Configuration Guide
nAruba ClearPass Policy Manager User Guide
Conventions
Table 1 lists the typographical conventions used throughout this guide to emphasize important concepts:
Type Style Description
Italics This style is used to emphasize important terms and to mark the titles of books.
System items This fixed-width font depicts the following:
nSample screen output
nSystem prompts
Bold nKeys that are pressed
nText typed into a GUI element
nGUI elements that are clicked or selected
Table 1: Typographical Conventions
The following informational icons are used throughout this guide:
nIndicates helpful suggestions, pertinent information, and important things to remember.
nIndicates a risk of damage to your hardware or loss of data.
nIndicates a risk of personal injury or death.
Aruba SD-WAN Solution | User Guide 7
About This Document | 8
Terminology Change
As part of advancing HPE's commitment to racial justice, we are taking a much-needed step in overhauling
HPE engineering terminology to reflect our belief system of diversity and inclusion. Some legacy products
and publications may continue to include terminology that seemingly evokes bias against specific groups of
people. Such content is not representative of our HPE culture and moving forward, Aruba will replace
racially insensitive terms and instead use the following new language:
Usage Old Language New Language
Campus Access
Points +
Controllers
Master-Slave Conductor-Member
Instant Access
Points
Master-Slave Conductor-Member
Switch Stack Master-Slave Conductor-Member
Wireless LAN
Controller
Mobility Master Mobility Conductor
Firewall
Configuration
Blacklist, Whitelist Denylist, Allowlist
Types of
Hackers
Black Hat, White Hat Unethical, Ethical
Contacting Support
Main Site arubanetworks.com
Support Site support.arubanetworks.com
Airheads Social Forums and Knowledge
Base
community.arubanetworks.com
North American Telephone 1-800-943-4526 (Toll Free)
1-408-754-1200
International Telephone arubanetworks.com/support-services/contact-support/
Software Licensing Site lms.arubanetworks.com
End-of-life Information arubanetworks.com/support-services/end-of-life/
Security Incident Response Team Site: arubanetworks.com/support-services/security-bulletins/
Email: aruba-sirt@hpe.com
Table 2: Contact Information
Chapter 2
Aruba SD-Branch Solution
Aruba SD-Branch Solution
The Aruba SD Branch solution offers the best-in-class wireless and wired infrastructure and management
orchestration features with the SD-WAN capabilities. The SD Branch solution extends the SD-WAN concept
to all elements in the branch to deliver a full stack solution that addresses the business challenges of
distributed enterprises. Coupled with Aruba Central, the solution provides a cloud-hosted environment for
simplified operations and improved agility.
Why SD-WAN?
A traditional branch setup supports client connectivity requirements across different geographical locations
for various types of business operations. The sites in remote geographical locations serve as branch offices,
while the headquarters or main office serves as a data center that hosts network resources to store, manage,
and distribute data. The main office also hosts a centralized Virtual Private Network(VPN) management
system to aggregate traffic from the remote branch sites. A Wide Area Network (WAN) —with Multiprotocol
Label Switching (MPLS), T1, T3, Broadband, or Cellular links—is used for connecting multiple local area
networks to a central corporate network or data centers separated by distance.
Due to an increase in the number of client devices at the remote sites and the new bandwidth requirements,
branch office networks are expected rapidly scale to provide uninterrupted user experience. A traditional
branch infrastructure with multiple appliances, different operating systems, and management tools only
adds to the cost, involves a maintenance overhead, and demands skilled IT personnel.
The Aruba SD-WANsolution simplifies your branch deployments with a single management interface for
administering, managing, and monitoring your branch networks. It also provides a unified policy
enforcement framework with operational ease.
Key Features and Benefits
The SD-WANsolution comes with the following key capabilities:
nZero Touch Provisioning of devices—Ability to self-provision without operator's intervention.
nCentralized overlay management and control—A single cloud-based network management interface for
managing and monitoring SDBranch devices. Aruba Central, the cloud based network management
system, supports unified management of SDbranch devices with ZTP and hierarchical configuration.
nIPsec based Automatic VPN Tunnels—Support for high-performance and automatic IPsec VPN for secure
overlay networking.
nUnified security policy for wired, wireless, and WAN—Support for a common security policy framework
based on user roles for WAN, WLAN, and LAN users.
nDynamic path selection—Support for dynamically steering traffic or a service request to the best available
path. For example, you can configure a policy to dynamically route the real-time voice and video traffic on
the link with the lowest latency and jitter, and the bulk file traffic on the link with the maximum bandwidth.
nDeep Packet Inspection and Web Content Classification—Support for monitoring and analyzing application
usage by clients.
Aruba SD-WAN Solution | User Guide 9
Aruba SD-Branch Solution | 10
nVisibility, analytics, and troubleshooting—Dashboards for monitoring branch health, device performance,
and client connectivity metrics. Alerts, reports, and audit trails for monitoring and troubleshooting network
performance issues.
nPolicy-based Routing—In addition to the traditional destination-based routing, the SD Branch devices
support routing client traffic based on user role or type of application, For example, traffic generated from
the guest devices can be routed directly to the internet, while traffic from the employees can be routed to
the MPLS network.
For more information about how SD-WAN works, see Understanding SD-WAN.
Understanding SD-WAN
The SD-WAN solution includes a new set of devices called Aruba Gateways that inter-operate Aruba Switches
and Instant APs to provide a full-fledged WAN architecture.
Based on the size of your branch setup, you can choose device combination that best suits your
requirement:
nMedium to large branches—For branches that require more than 24 ports, you can use a combination of
Branch Gateways and one or more Aruba switches at the branch site, with ArubaGateways as
VPNConcentrator at the data center.
nSmall to medium branches—For branches that require less than 24 ports (including all
WANandLANports), you can deploy Branch Gateways at the branch sites, with ArubaGateways as
VPNConcentrator at the data center.
nMicro branches—For micro branches, you can deploy an Instant AP cluster at the branch site, with
ArubaGateway as the VPNConcentrator at the data center.
See Supported SD-Branch Components for information on Aruba Gateways that can be deployed as
VPNCs.
Figure 1 shows a typical deployment topology of an SD Branch with Branch Gateways and a micro branch
with Instant APs:
Figure 1 SD Branch Topology
Figure 2 illustrates the communication flow between Aruba Central, branch sites, and data center.
Aruba SD-WAN Solution | User Guide 11
Figure 2 Aruba Central and Cloud Communication
Figure 3 shows all elements in an SD Branch and the SD-WANdata flow.
Figure 3 Aruba SD-WANData Flow
What are the Solution Requirements?
Aruba SD-Branch Solution | 12
The ArubaGateways are the most important components of the Aruba SD-Branch Solution. The SD-WAN
Gateway portfolio includes and Aruba Branch Gateways and VPN Concentrators.
At the Branch Site
The following are the components in a branch:
nBranch Gateways—Function at the branch to optimize and control WAN, LAN, and cloud security
services.
nSwitches—Function with Branch Gateways to detect and isolate rogue APs, and blacklist rogue devices.
nInstant APsFunction as VPNclients at branch sites. The client data traffic from these APs are aggregated
by the VPN Concentrator located at the data center
At the Data Center
At the data center, you can deploy ArubaGateways as VPNConcentrator. For data center redundancy, you
can deploy two VPNconcentrators in the active-standby or active-active mode.
The following are the components operational at the Data Center:
nVPNCA VPN Concentrator functions as a VPNmanagement system that aggregates data traffic from
the branches and terminates IPsec VPNtunnels.
nVirtual GatewayThe headend gateway at the enterprise data center can be hosted as a virtual
appliance. The virtualised instance enterprise data center gateway in public or private cloud is referred to
as Virtual Gateway. Aruba Virtual Gateways function as VPNConcentrators.
For a list of supported Gateways, Switches, and APs, see Supported SD-Branch Components.
In the Cloud
A valid Aruba Central subscription is required to avail cloud-based administration, management,
configuration and monitoring of SD branch components such as Branch Gateways, VPN Concentrators,
Instant APs, and Aruba Switches.
Supported SD-Branch Components
The Aruba SD-WAN Gateway portfolio includes Aruba Gateways that function as Branch Gateways and
VPNConcentrators.
The following table lists the Aruba Gateway platforms and ArubaOS software versions that function as
Branch Gateways:
Platform Minimum Supported
Software Version
Latest Software
Version
Recommended
Software Version
Aruba 9004-LTE ArubaOS 8.5.0.0-2.1.0.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.5.0.0-2.1.0.0
Aruba 9012 ArubaOS 8.5.0.0-2.0.0.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.5.0.0-2.0.0.4
Table 3: Supported Aruba Gateways
Aruba SD-WAN Solution | User Guide 13
Platform Minimum Supported
Software Version
Latest Software
Version
Recommended
Software Version
Aruba 9004 ArubaOS 8.5.0.0-1.0.7.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.5.0.0-2.0.0.4
Aruba7210, 7220,
and 7240XM
ArubaOS 8.5.0.0-2.0.0.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.5.0.0-2.0.0.4
Aruba7030 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7024 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7010 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7008 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7005 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0 ArubaOS 8.4.0.0-2.0.0.4
The following table lists the Aruba Gateway platforms and ArubaOS software versions that function as VPN
Concentrators:
Platform Minimum Supported
Software Version
Latest Software
Version
Recommended Software
Version
Aruba7280 ArubaOS 8.4.0.0-1.0.6.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7240XM ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7220 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba7210 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
vGW-4G ArubaOS 8.4.0.0-1.0.6.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
vGW-2G ArubaOS 8.4.0.0-1.0.6.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
vGW-500M ArubaOS 8.4.0.0-1.0.6.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba 7030 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Table 4: Supported Aruba VPN Concentrators
Aruba SD-Branch Solution | 14
Platform Minimum Supported
Software Version
Latest Software
Version
Recommended Software
Version
Aruba 7024 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Aruba 7010 ArubaOS 8.1.0.0-1.0.4.0 ArubaOS 8.6.0.4-
2.2.0.0
ArubaOS 8.4.0.0-2.0.0.4
Table 4: Supported Aruba VPN Concentrators
Aruba Virtual Gateways also function as VPNConcentrators. The minimum supported software version
for Virtual Gateways is ArubaOS 8.1.0.0-1.0.4.1.
Data sheets and technical specifications for the supported Gateways are available at:
https://www.arubanetworks.com/products/networking/gateways-and-controllers/
The following table lists the hardware platforms and ArubaOS software versions for Aruba Switches and
Instant APs that can be deployed in the branch:
SD Branch Component Hardware Platforms Minimum Software
Version
Aruba Switches Aruba 3810 Switch Series KB.16.05.0007 or later
Aruba 5400R Switch
Series
KB.16.05.0007 or later
Aruba 2920 Switch Series WB.16.05.0007 or later
Aruba 2930F Switch
Series
WC.16.05.0007 or later
Instant APs Aruba310 Series and 300
SeriesInstant APs
ArubaInstant 6.5.3.x
ArubaInstant 8.3.0.0 or
later
Table 5: SD Branch Site Devices
Chapter 3
Getting Started
Getting Started
To start using the SD-WAN solution, ensure that you have a valid Aruba Central subscription and licenses for
the SD-Branch devices.
nIf you are an existing Aruba Central customer with a valid subscription key and device licenses, access the
Aruba Central UI and complete the provisioning tasks.
nIf you are an existing Aruba customer with valid device licenses, but not an Aruba Central customer, sign up
for Aruba Central. After a successful registration, Aruba sends a verification e-mail with a link to the Aruba
Central portal. For more information, see Aruba Central Help Center.
Aruba Central offers a 90 day evaluation subscription for customers who want to try the Aruba cloud
solution for managing their networks. When you sign up for Aruba Central, an evaluation subscription
is automatically assigned, unless you purchased a subscription. To purchase subscriptions, contact the
Aruba support team.
Gateway Provisioning Tasks
Complete the following provisioning tasks to bring up your devices in the Aruba Central management
interface:
nOnboard Devices
nAssign Subscriptions
nAssign Devices to Sites
nAssign Labels
nAssign Groups
nAssigning a Group Role or Persona
nProvision Gateways
nOpen Firewall Ports for Device Communication
Onboarding Devices to Aruba Central
If you are a registered Aruba Central portal user, Aruba Central automatically retrieves the devices associated
with your account and adds it to the device inventory. To verify, if the devices are added to Aruba Central's
device inventory, navigate to Global Settings >Device Inventory in the Aruba Central UI.
The users with the evaluation subscription may have to add the devices manually using their Aruba
Activate credentials.
nIf the devices are listed in the inventory, proceed to assign devices to groups, labels, and sites.
nIf the devices do not show up in the inventory, click Sync Now to synchronize the inventory with the
Activate database.
nIf the devices do not show up in the inventory even after the sync operation, manually add these devices.
Aruba SD-WAN Solution | User Guide 15
Getting Started | 16
Manually Adding Devices to Inventory
To manually add the devices, on the Device Inventory page, click one of the device addition options
described in the following table:
Device Addition
Method Description
Add by MAC
Address/Serial Number
Allows you to add devices based on MAC address and serial numbers. You can
add up to 32 devices.
Add with Cloud Activation
Key
Allows you to add multiple devices from a single purchase order by using the
cloud activation key. To add devices:
1. Enter the Cloud Activation Key and MAC address of the device.
2. Click Add. Aruba Central retrieves all devices that belong to the same
purchase order and displays the list.
Add Using Activate Allows you to retrieve the devices associated with an Activate user account.
To add devices:
1. Enter the username and password of the Activate user account.
2. Click Add. The devices associated with the Activate account are retrieved
and added to the list of devices displayed on the Device Inventory page.
NOTE: You can use this option only once. After the devices are added, Aruba
Central does not allow you to modify or re-import the devices using your Aruba
Activate credentials.
Table 6: Adding Devices
Assigning Subscriptions to Aruba Gateways
For Aruba gateways to start functioning, you must onboard them to the device inventory in Aruba Central
and ensure that a valid subscription is assigned to each gateway. A valid subscription allows the gateway to
be managed by Aruba Central.
This section includes the following topics:
nGateway Subscriptions
nGateway Subscriptions with Security License
nVirtual Gateway Subscriptions
Gateway Subscriptions
Aruba Central supports the following types of subscriptions for gateways:
nDM AssignedDisplays whether the device management subscription has been assigned.
nUnassignedSelect gateway(s) and select Unassigned from the drop-down list to unassign the
subscription.
nFoundationThis subscription can be assigned to these gateways:
oAruba 70xx series
oAruba 72xx series
oAruba 90xx series
Aruba SD-WAN Solution | User Guide 17
nFoundation-Base—This subscription can be assigned to Aruba70xx series and Aruba 90xx series
Gateways. Gateway devices with the Foundation-Base capacity subscription can support up to 75 client
devices per branch.
When the client capacity reaches the threshold:
oAruba Central triggers the Gateway base license capacity limit exceeded alert.
oIf the notification options for the Gateway base license capacity limit exceeded alert is configured,
Aruba Central sends an email notification with a list of Aruba gateways that exceed the client capacity
threshold. You can also configure alerts to trigger an incident using Webhook. .
nAdvancedThis subscription is available for all Aruba gateways. It allows users to use advanced features
and services such as SaaS Express. This subscription can be assigned to these gateways:
oAruba 70xx series
oAruba 72xx series
oAruba 90xx series
Gateway Subscriptions with Security License
The following gateway subscriptions are packaged along with security license that includes the Intrusion
Detection and Prevention System (IDPS) feature. These subscriptions can be assigned to Aruba IDPS
supported gateways:
nFoundation with Security—All features of a Foundation subscription along with security license.
nFoundation-Base with Security—All features of a Foundation-Base capacity subscription along with
security license.
nAdvanced with Security—All features of an Advanced subscription along with security license.
You can evaluate Aruba IDPS with Advanced with Security subscription for a period of 90 days.
Assigning Subscriptions to Gateways
To assign subscription to a gateway, complete the following steps:
1. In the Account Home page, under Global Settings, click Subscription Assignment.
The Subscription Management page is displayed.
2. Under Gateway Subscriptions, select the device to which you want to assign a subscription.
3. Expand the drop-down in the Assignment column for the selected device.
4. Select the subscription; for example, Foundation.
5. To assign subscription to multiple devices:
a. Select the devices in the table.
b. Click Batch Assignment.
c. Select the subscription to assign.
When a subscription assigned to a gateway expires, Aruba Central automatically assigns a valid subscription
from the same subscription category.
Getting Started | 18
When you assign a subscription with security license, the gateways reboot to enable the traffic
inspection engine for the first time. It is recommended that you apply the security license after
business hours, as this might result in a downtime in the network.
When assigning subscriptions, if you change a subscription with security license to a subscription
without a security license, you must reboot the gateway manually to release the CPU resources that
were assigned to the traffic inspection engine. It is recommended to reboot the gateway after
business hours, as this might result in a down time in the network.
Virtual Gateway Subscriptions
Aruba Virtual Gateway is a virtual instance of headend gateway for SD-WAN. Aruba Central supports
licenses based on the bandwidth capacity for virtual gateways. All license assignments are undertaken by
the virtual gateway orchestration app.
Aruba Central supports VGW licenses that cater to a variety of requirements. The options include one, three,
and five year periods and the bandwidth options are 500 Mbps, 2 Gbps, and 4 Gbps capacity licenses.
The base SKUs available are: VGW-500M, VGW-2G, and VGW-4G. The availability of SKUs is also dependent
on the installation consuming the license.
The account maintains a pool of VGW licenses, upon license expiry or if the license pool has no licenses left
(all consumed) the license is unassigned from the account. When deployed without valid or paid licenses,
four evaluation (90 day) licenses of each base SKU is allocated to every customer account.
License consumption can be tracked in the Key Management or Subscription Assignment pages.
The list of licenses available against consumed licenses are also displayed during the deployment of a virtual
gateway.
When the client capacity reaches the threshold:
nAruba Central triggers the Gateway base license capacity limit exceeded alert.
nIf the notification options for the Gateway base license capacity limit exceeded alert is configured,
Aruba Central sends an email notification with a list Aruba virtual gateways that exceed the client capacity
threshold. You can also configure alerts to trigger an incident using Webhook. .
For Paid licenses email notifications are sent out in 30 day intervals starting at 90th day before
expiration and the last notification a day before the expiry of the license.
For Evaluation licenses email notifications are sent out on the 30th day before expiration and a day
before the expiry of the license.
Assigning Subscriptions to Virtual Gateways
1. Under Virtual Gateway, select the device to which you want to assign a subscription.
2. Expand the drop-down in the Assignment column for the selected device.
3. Select the subscription SKU. For example, VGW-500MB.
4. To assign subscription to multiple devices:
Aruba Central automatically assigns a valid subscription to a virtual gateway. When a subscription
expires, Aruba Central automatically assigns a valid subscription from the same subscription
category.
For more information on available SKUs, contact yourArubaSalesSpecialist.
Aruba SD-WAN Solution | User Guide 19
Assigning Gateways to a Group
A group in Aruba Central is a primary configuration element that acts like a container. In other words, groups
are a subset of one or several devices that share common configuration settings. Aruba Central supports
assigning devices to groups for the ease of configuration and maintenance. For example, you can create a
common group for Branch Gateways that have similar configuration requirements.
Aruba Gateway Groups for SD-WAN Deployments
The device groups in Aruba Central support the following features:
nCombining Branch Gateways of identical characteristics and configuration requirements under a single
group.
nCreating groups according to your branch requirements.
oYou can create separate groups for the small, medium, and large sized branches.
oYou can also create separate groups for the branch sites in different geographical locations; for example,
East Coast and West Coast branch sites. If these groups have similar characteristics with minor
differences, you can create the first group and then clone it.
oYou can use either a single group for all the devices or deploy devices in multiple groups. For example,
you can deploy 7008controllers and Aruba 2930F Switch Series with 24 ports in a single group for every
branch.
oYou can also deploy 7005controller and Aruba 2930F Switch Series with 24 ports in one group and
provision 7008controller with Aruba 2930F Switch Series with 48 ports in another group.
nProvisioning Branch Gateways and VPN Concentrators in separate groups. As the configuration
requirements for Branch Gateways and VPNConcentrators are different, the Branch Gateways and
VPNConcentrators must be assigned to different groups.
nCombining different types of devices under a group. For example, a group can have Instant APs, switches,
and SD-WAN gateways. .
Important Points to Note
nThe groups in Aruba Central are not device-specific, so you can provision Branch Gateways, switches, and
Instant APs in a single group. However, VPNConcentrators and Branch Gateways must be assigned to
different groups.
nA device can be part of only one group at any given time.
nAfter assigning the SD-WAN gateways to groups, you must set the group persona or role as Branch
Gateway or VPN Concentrator.
To assign gateways to a group, complete the following steps:
1. In the Network Operations app, set the filter to Global.
The dashboard context for the selected filter is displayed.
2. Under Maintain, click Organization >Groups.
The Groups page is displayed. By default, the Groups page is displayed.
3. Under Manage Groups, from the devices table on the right, select the gateway that you want to
assign to a new group.
4. Drag and drop the device to the group to which you want to assign the device.
5. Click Yes in the confirmation dialog box.
Getting Started | 20
If the group is not available in the list, click New Group to create a new group, and then drag and drop
the gateways to the group that you just created.
Assigning Gateways to Sites
A site in Aruba Central refers to a physical location where a set of devices are installed; for example, campus,
branch, or a venue. You can create a branch or campus site; for example Branch A or Campus A, for a
specific geographical location and assign devices to it. You can use these sites as filters for viewing your
deployment topology, monitoring network and device health.
To assign gateways to a site, complete the following steps:
1. In the Network Operations app, set the filter to Global.
The dashboard context for the selected filter is displayed.
2. Under Maintain, click Organization >Sites and Labels.
The Sites and Labels page is displayed. By default, the Sites page is displayed.
3. Under Manage Sites, locate the site to which you want to assign a device.
You can also add a new site by clicking New Site and providing details, such as site name and
address.
4. Click Unassigned to view devices that are not assigned to any site.
5. Select one or several devices from the list of devices.
6. Drag and drop the devices to the site on the left.
7. Click Yes in the confirmation dialog box.
For more information, see Sites in Aruba Central documentation.
Assigning Labels to Gateways
In Aruba Central, labels refer to the tags attached to a device provisioned in the network. You can use labels
for tagging devices to a specific area in a physical location, to an owner or a specific branch, or a business
unit. You can use these labels as filters for monitoring branch and device health, and generating reports.
To assign a label to a gateway, complete the following steps:
1. In the Network Operations app, set the filter to Global.
The dashboard context for the selected filter is displayed.
2. Under Maintain, click Organization >Sites and Labels.
The Sites and Labels page is displayed. By default, the Sites page is displayed.
3. Use the toggle switch to access the Labels page.
4. Locate the label to which you want to assign a device. You can also create a new label by clicking
Add Label and providing a label name.
5. In the table that lists the labels, you can perform one of the following actions:
nClick All Devices to view all devices.
nClick Unassigned to view all the devices that are not assigned to any labels.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42
  • Page 43 43
  • Page 44 44
  • Page 45 45
  • Page 46 46
  • Page 47 47
  • Page 48 48
  • Page 49 49
  • Page 50 50
  • Page 51 51
  • Page 52 52
  • Page 53 53
  • Page 54 54
  • Page 55 55
  • Page 56 56
  • Page 57 57
  • Page 58 58
  • Page 59 59
  • Page 60 60
  • Page 61 61
  • Page 62 62
  • Page 63 63
  • Page 64 64
  • Page 65 65
  • Page 66 66
  • Page 67 67
  • Page 68 68
  • Page 69 69
  • Page 70 70
  • Page 71 71
  • Page 72 72
  • Page 73 73
  • Page 74 74
  • Page 75 75
  • Page 76 76
  • Page 77 77
  • Page 78 78
  • Page 79 79
  • Page 80 80
  • Page 81 81
  • Page 82 82
  • Page 83 83
  • Page 84 84
  • Page 85 85
  • Page 86 86
  • Page 87 87
  • Page 88 88
  • Page 89 89
  • Page 90 90
  • Page 91 91
  • Page 92 92
  • Page 93 93
  • Page 94 94
  • Page 95 95
  • Page 96 96
  • Page 97 97
  • Page 98 98
  • Page 99 99
  • Page 100 100
  • Page 101 101
  • Page 102 102
  • Page 103 103
  • Page 104 104
  • Page 105 105
  • Page 106 106
  • Page 107 107
  • Page 108 108
  • Page 109 109
  • Page 110 110
  • Page 111 111
  • Page 112 112
  • Page 113 113
  • Page 114 114
  • Page 115 115
  • Page 116 116
  • Page 117 117
  • Page 118 118
  • Page 119 119
  • Page 120 120
  • Page 121 121
  • Page 122 122
  • Page 123 123
  • Page 124 124
  • Page 125 125
  • Page 126 126
  • Page 127 127
  • Page 128 128
  • Page 129 129
  • Page 130 130
  • Page 131 131
  • Page 132 132
  • Page 133 133
  • Page 134 134
  • Page 135 135
  • Page 136 136
  • Page 137 137
  • Page 138 138
  • Page 139 139
  • Page 140 140
  • Page 141 141
  • Page 142 142
  • Page 143 143
  • Page 144 144
  • Page 145 145
  • Page 146 146
  • Page 147 147
  • Page 148 148
  • Page 149 149
  • Page 150 150
  • Page 151 151
  • Page 152 152
  • Page 153 153
  • Page 154 154
  • Page 155 155
  • Page 156 156
  • Page 157 157
  • Page 158 158
  • Page 159 159
  • Page 160 160
  • Page 161 161
  • Page 162 162
  • Page 163 163
  • Page 164 164
  • Page 165 165
  • Page 166 166
  • Page 167 167
  • Page 168 168
  • Page 169 169
  • Page 170 170
  • Page 171 171
  • Page 172 172
  • Page 173 173
  • Page 174 174
  • Page 175 175
  • Page 176 176
  • Page 177 177
  • Page 178 178
  • Page 179 179
  • Page 180 180
  • Page 181 181
  • Page 182 182
  • Page 183 183
  • Page 184 184
  • Page 185 185
  • Page 186 186
  • Page 187 187
  • Page 188 188
  • Page 189 189
  • Page 190 190
  • Page 191 191
  • Page 192 192
  • Page 193 193
  • Page 194 194
  • Page 195 195
  • Page 196 196
  • Page 197 197
  • Page 198 198
  • Page 199 199
  • Page 200 200
  • Page 201 201
  • Page 202 202
  • Page 203 203
  • Page 204 204
  • Page 205 205
  • Page 206 206
  • Page 207 207
  • Page 208 208
  • Page 209 209
  • Page 210 210
  • Page 211 211
  • Page 212 212
  • Page 213 213
  • Page 214 214
  • Page 215 215
  • Page 216 216
  • Page 217 217
  • Page 218 218
  • Page 219 219
  • Page 220 220
  • Page 221 221
  • Page 222 222
  • Page 223 223
  • Page 224 224
  • Page 225 225
  • Page 226 226
  • Page 227 227
  • Page 228 228
  • Page 229 229
  • Page 230 230
  • Page 231 231
  • Page 232 232
  • Page 233 233
  • Page 234 234
  • Page 235 235
  • Page 236 236
  • Page 237 237
  • Page 238 238
  • Page 239 239
  • Page 240 240
  • Page 241 241
  • Page 242 242
  • Page 243 243
  • Page 244 244
  • Page 245 245
  • Page 246 246
  • Page 247 247
  • Page 248 248
  • Page 249 249
  • Page 250 250
  • Page 251 251
  • Page 252 252
  • Page 253 253
  • Page 254 254
  • Page 255 255
  • Page 256 256
  • Page 257 257
  • Page 258 258
  • Page 259 259
  • Page 260 260
  • Page 261 261
  • Page 262 262
  • Page 263 263
  • Page 264 264
  • Page 265 265
  • Page 266 266
  • Page 267 267
  • Page 268 268
  • Page 269 269
  • Page 270 270
  • Page 271 271
  • Page 272 272
  • Page 273 273
  • Page 274 274
  • Page 275 275
  • Page 276 276
  • Page 277 277
  • Page 278 278
  • Page 279 279
  • Page 280 280
  • Page 281 281
  • Page 282 282
  • Page 283 283
  • Page 284 284
  • Page 285 285
  • Page 286 286
  • Page 287 287
  • Page 288 288
  • Page 289 289
  • Page 290 290
  • Page 291 291
  • Page 292 292
  • Page 293 293
  • Page 294 294
  • Page 295 295
  • Page 296 296
  • Page 297 297
  • Page 298 298
  • Page 299 299
  • Page 300 300
  • Page 301 301
  • Page 302 302
  • Page 303 303
  • Page 304 304
  • Page 305 305
  • Page 306 306
  • Page 307 307
  • Page 308 308
  • Page 309 309
  • Page 310 310
  • Page 311 311
  • Page 312 312
  • Page 313 313
  • Page 314 314
  • Page 315 315
  • Page 316 316
  • Page 317 317
  • Page 318 318
  • Page 319 319
  • Page 320 320
  • Page 321 321
  • Page 322 322
  • Page 323 323
  • Page 324 324
  • Page 325 325
  • Page 326 326
  • Page 327 327
  • Page 328 328
  • Page 329 329
  • Page 330 330
  • Page 331 331
  • Page 332 332
  • Page 333 333
  • Page 334 334
  • Page 335 335
  • Page 336 336
  • Page 337 337
  • Page 338 338
  • Page 339 339
  • Page 340 340
  • Page 341 341
  • Page 342 342
  • Page 343 343
  • Page 344 344
  • Page 345 345
  • Page 346 346
  • Page 347 347
  • Page 348 348
  • Page 349 349
  • Page 350 350
  • Page 351 351
  • Page 352 352
  • Page 353 353
  • Page 354 354
  • Page 355 355
  • Page 356 356
  • Page 357 357
  • Page 358 358
  • Page 359 359
  • Page 360 360
  • Page 361 361
  • Page 362 362
  • Page 363 363
  • Page 364 364
  • Page 365 365
  • Page 366 366
  • Page 367 367
  • Page 368 368
  • Page 369 369
  • Page 370 370
  • Page 371 371
  • Page 372 372
  • Page 373 373
  • Page 374 374
  • Page 375 375
  • Page 376 376
  • Page 377 377
  • Page 378 378
  • Page 379 379
  • Page 380 380
  • Page 381 381
  • Page 382 382
  • Page 383 383
  • Page 384 384
  • Page 385 385
  • Page 386 386
  • Page 387 387
  • Page 388 388
  • Page 389 389
  • Page 390 390
  • Page 391 391
  • Page 392 392
  • Page 393 393
  • Page 394 394
  • Page 395 395
  • Page 396 396
  • Page 397 397
  • Page 398 398
  • Page 399 399
  • Page 400 400
  • Page 401 401
  • Page 402 402
  • Page 403 403
  • Page 404 404
  • Page 405 405
  • Page 406 406
  • Page 407 407
  • Page 408 408
  • Page 409 409
  • Page 410 410
  • Page 411 411
  • Page 412 412
  • Page 413 413
  • Page 414 414
  • Page 415 415
  • Page 416 416
  • Page 417 417
  • Page 418 418
  • Page 419 419
  • Page 420 420
  • Page 421 421
  • Page 422 422
  • Page 423 423
  • Page 424 424
  • Page 425 425
  • Page 426 426
  • Page 427 427
  • Page 428 428
  • Page 429 429
  • Page 430 430
  • Page 431 431
  • Page 432 432
  • Page 433 433
  • Page 434 434
  • Page 435 435
  • Page 436 436
  • Page 437 437
  • Page 438 438
  • Page 439 439
  • Page 440 440
  • Page 441 441
  • Page 442 442
  • Page 443 443
  • Page 444 444
  • Page 445 445
  • Page 446 446
  • Page 447 447
  • Page 448 448
  • Page 449 449
  • Page 450 450
  • Page 451 451
  • Page 452 452
  • Page 453 453
  • Page 454 454
  • Page 455 455
  • Page 456 456
  • Page 457 457
  • Page 458 458
  • Page 459 459
  • Page 460 460
  • Page 461 461
  • Page 462 462
  • Page 463 463
  • Page 464 464
  • Page 465 465
  • Page 466 466
  • Page 467 467
  • Page 468 468
  • Page 469 469
  • Page 470 470
  • Page 471 471
  • Page 472 472
  • Page 473 473
  • Page 474 474
  • Page 475 475
  • Page 476 476
  • Page 477 477
  • Page 478 478
  • Page 479 479
  • Page 480 480
  • Page 481 481
  • Page 482 482
  • Page 483 483
  • Page 484 484
  • Page 485 485
  • Page 486 486
  • Page 487 487
  • Page 488 488
  • Page 489 489
  • Page 490 490
  • Page 491 491
  • Page 492 492
  • Page 493 493
  • Page 494 494
  • Page 495 495
  • Page 496 496
  • Page 497 497
  • Page 498 498
  • Page 499 499
  • Page 500 500
  • Page 501 501
  • Page 502 502
  • Page 503 503
  • Page 504 504
  • Page 505 505
  • Page 506 506
  • Page 507 507
  • Page 508 508
  • Page 509 509
  • Page 510 510
  • Page 511 511
  • Page 512 512
  • Page 513 513
  • Page 514 514
  • Page 515 515
  • Page 516 516
  • Page 517 517
  • Page 518 518
  • Page 519 519
  • Page 520 520
  • Page 521 521
  • Page 522 522
  • Page 523 523
  • Page 524 524
  • Page 525 525
  • Page 526 526
  • Page 527 527
  • Page 528 528
  • Page 529 529
  • Page 530 530
  • Page 531 531
  • Page 532 532
  • Page 533 533
  • Page 534 534
  • Page 535 535
  • Page 536 536
  • Page 537 537
  • Page 538 538
  • Page 539 539
  • Page 540 540
  • Page 541 541
  • Page 542 542
  • Page 543 543
  • Page 544 544
  • Page 545 545
  • Page 546 546
  • Page 547 547
  • Page 548 548
  • Page 549 549

Aruba Central User guide

Category
Software
Type
User guide
This manual is also suitable for

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI