Creating a Port Profile

To create a Port Profile, complete the following steps:

  1. On the Aruba Instant On web application home page, select Profiles from the left navigation pane. By default, the Port Profile table is displayed.
  2. Under Profiles > Ports, click Create Port Profile.
  3. Under Identify the Profile page, configure the following:
    • Name—Enter a name for the port profile.
    • Port Options—The Speed/Duplex option displays the link speed and how the port handles the traffic in both directions (Half or Full-Duplex). In the Advanced Options section, additional port-level configurations are available.

      The Limit broadcast and Multicast Storms configuration is an optional setting, and is enabled by default. Use the checkbox to enable or disable the Limit broadcast and Multicast Storms configuration. This configuration does not apply to the gateways.

  4. Click Next.

    The Port Security and Authentication page is displayed.

  5. This is an optional setting. Under Port Security and Authentication > Security > Port Security, select a security option.

    You can select multiple options for port security type. The different types of port securities options are:

    • DHCP and ARP Protections (Untrusted Port)—Requires at least one wired network to be enabled with DHCP and ARP attack protections. Not applicable to gateways, access points, and 1830 series switches.
    • Port Isolation (Protected port)— Not applicable to gateways, access points, and 1830 series switches.
  6. Under Port Security and Authentication > Security > Spanning Tree Protection, select a Spanning Tree Protection (STP) option.

    It is a security feature that disables a port if it receives Bridge Protocol Data Units (BPDUs), which are control packets used by (STP). You must select one option for the list of Spanning Tree Protection options. STP do not apply to gateways and access points.

    • No spanning tree protections (default)—The default spanning tree protection settings without the BPDU option.
    • Filter spanning tree protocol (BPDU filter)—Filters incoming and outgoing BPDUs on the port.
    • Block spanning tree protocol (BPDU guard)—Stops the incoming and outgoing BPDUs received on the port.
    • Root bridge protection (Root guard)—Protects the designated root bridge by preventing unauthorized ports from becoming a root bridge.
  7. Under Port Security and Authentication > Authentication > 802.1X Authentication, you must select the authentication type from the list of options displayed:
    • No authentication (default)—No authentication is applied. This is the default option selected.
    • Port-based—Enables port-based 802.1X authentication. Port-based authentication is not applicable to gateways, and 1830 series switches.
    • Client-based—Enables client-based 802.1X authentication. Client-based authentication does not apply to gateways, access points, and 1830 series switches.

      This is an optional setting. When Client-based is selected as the 802.1X Authentication type, an additional Authentication Options section is displayed. You can select one of the following options:

      • 802.1X + MAC Authentication—Enables a secondary attempt at MAC-based authentication if the initial 802.1X request times out. If 802.1X is explicitly refused by the server (for example, during an invalid credentials), MAC authentication is not attempted.
      • Unauthenticated User Guest Access—Enables a fallback to a wired guest network for clients that fail 802.1X authentication. This requires a wired Guest Network to be configured on the Instant On site. On enabling this option the guest network is displayed as Untagged guest network under the Network Assignment > Included Networks section of the port configuration.
  8. Click Next.

    The Power Management page is displayed. The Power Management page allows you to configure the Power over Ethernet (PoE) functionality and related power settings for ports that power other devices.

  9. Under the Power Management > Power Allocation, select the PoE option.

    The different power allocation options available are:

    • No Power over Ethernet—The PoE supply to devices connected to the switch is disabled. Only on selecting No Power over Ethernet, other power management options are not displayed such as Port Priority, and Power Management Options.
    • Usage (default)—The power allocated to the port is based on usage and is unrestricted. By default, usage is selected.
    • Class—Allocates power based on the device’s PoE standard.

    Power allocation by usage does not apply to access points, which always use class.

  10. Under the Power Management > Port Priority, assigns a priority level to the port profile.

    Determines PoE delivery order during budget constraints Critical > High > Low.

    Port priority does not apply to access points.

  11. Under the Power Management > Power Mode, select the power behavior applied to eligible ports during a reboot.

    The available options are:

    • Always On(default)—Maintains PoE on eligible ports throughout a reboot, unless input power is lost.
    • Quick—Restores PoE on eligible ports as soon as the hardware restarts, before the switch has fully started.
    • Normal—Applies power to the ports only after the configuration is restored.

    Power Mode applies only to the Instant On 1840 and 1940 Switch Series.

  12. This is an optional setting. Under the Power Management > Power Management Options > Power Schedule, use the checkbox to either enable or disable the power schedule.

    If enabled, the PoE supply to the port profile is determined by the power schedule. When the Power Schedule option is enabled, the View Power Schedule link is displayed. Click View power schedule option to view the power schedule applicable to this port profile.

    For more information on configuring Power Schedule, see Power Management.

  13. Click Next.

    The Network Assignment page is displayed.

  14. In the Network Assignment page, select the networks the port profile supports.
    • Untagged Network—The traffic received and sent from the default network without using a VLAN tag. To custom map the port profile to an untagged VLAN, click the untagged network drop-down list and select a network. Only one untagged network can be assigned to a port profile.
    • Tagged networks assignment—The port receives and sends traffic from the default network using the management VLAN tag. Select one of the options:
      • All networks—To select all the tagged networks. If All networks option is selected, then the list of tagged networks is not displayed.
      • Select networks—Allows you to manually select the tagged VLAN networks. When Select networks option is selected, the Tagged Networks list is displayed. To custom map the port profile to a tagged VLAN, select the check boxes against the networks listed under Tagged Networks. A maximum of 22 tagged networks can be mapped to a port at a time.
  15. Click Next.

    The Port Assignment page is displayed.

  16. Under the Port Assignment > Device drop-down list, select a device.

    The port associated with the selected device is displayed. Select the port to which you want to assign the port profile.

    You can assign the port profile to multiple devices and ports. Click on the device drop-down list to select a device. A check mark appears on the top-right corner of the selected port and the port gets added to the Selected Ports list.

    • Assign to All— Apply the profile to all ports on the device.
    • Remove All— Remove the profile from all ports on the device.
  17. Click Create Port Profile.

    The new port profile is displayed in the port profile table.