Wired Intelligent Edge

 View Only
last person joined: 16 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Netedit Improvement?

This thread has been viewed 77 times
  • 1.  Netedit Improvement?

    MVP
    Posted Nov 23, 2020 02:14 PM

    Hey,

    We're trying to get NetEdit up and going, but there are a couple of things that are bugging me.  

    1. Authentication
       How can a product that's release version 2.0 exist without at least some sort of RADIUS/TACACS+/LDAP authentication method?  I'd venture a guess that every company implementing NE as a solution have systems in for auth, and having to create and manage users, or worse - sharing admin user access is not going to work for very long.

    2. User timeout
      Why can't I set the timeout length in the GUI and have that stay put when I do an update?  A 20 minute timeout for user auth is way too short for me, especially while I'm working to get things configured while I also go about the daily tasks of supporting our users.  I log in to this thing dozens of times per day because I get interrupted and have to work on other things.

    3. UI consistency
      There's an Action menu throughout.  Sometimes, there are actions that can be performed, and sometimes it's just a worthless button on the page.

    Firmware repository:

    Diagnostics:


    Settings-Attributes:

    Plans:


    Devices:

    Seems like where there aren't any useful buttons, you could  move to just include the buttons that you can push as an item instead of submenu.

    4. Licensing
      Seems like it's difficult to find where to put the license in.  We purchased ~35 device licenses, but I didn't get them emailed to me, and I don't know where to add them if I do get them.



    That #1 is a pretty big deal, and because of that, #2 becomes a huge annoyance (though I've updated server.servlet.session.timeout and netedit.user.session.max-age to see if that helps).  Do we have a timeline on getting some real user auth going?
    ​​​​​

    ------------------------------
    Phillip Horn
    ------------------------------


  • 2.  RE: Netedit Improvement?

    EMPLOYEE
    Posted Nov 24, 2020 04:33 AM
    Hello Phillip,

    We hear you loud and clear for item #1. This is a key missing feature that I have been requesting myself for long time.
    Product management is very aware of this.

    Regarding item#2, you need to modify the following NetEdit file (through linux shell) : ​/opt/netedit/config/application.properties
    ############### Session configuration ###################
    # Session idle timeout is 20 minutes
    server.servlet.session.timeout=1200
    server.servlet.session.cookie.name=id
    # Turn off URL tracking
    server.servlet.session.tracking-modes=cookie
    #########################################################

    Set server.servlet.session.timeout to a higher value.

    For item#3, it is grayed in submenu when this is un-valid action.

    For item#4, license model is "honor based", but I assume you should have received information on your order. Please reach out to your local Aruba contact
    or support to verify this point.

    ------------------------------
    Vincent Giles
    ------------------------------



  • 3.  RE: Netedit Improvement?

    MVP
    Posted Nov 24, 2020 07:34 AM
    Hey Vincent,

    Thanks for the reply.  I understand that you're working on #1, great! - do we have any kind of timeline for availability?​​
    I did get #2 changed and that's much better.  Formal request: put that setting in the web GUI and make sure it's retained during an upgrade.  It didn't stay when I went from V2.09 to V2.10​

    For #3 - I ​get that the grayed items aren't valid.  What I mean is for example on the Settings-Attributes: screen, why is there an ACTION button when there's literally one item on that menu.  Can you not just put the button in the spot where the action button is if there is only 1 or 2 items?  It seems to me that the items called "Column Settings" and "Export All" should be their own buttons that don't necessarily live on the Action menu.  I'm not a UX designer, but I do use stuff, and that [action menu] just makes me click it every time I see it.  I'll eventually learn the system, but I click a lot of Action menus and there's not much to act on for many of them..

    For #4 - I'll check in with my people on this.  It shows as 'shipped', but I didn't get anything.  I am guessing that I would get an email with a license activation deal similar to the AP licenses, but I didn't get a thing. :) 

    Thanks again.
    PH​

    ------------------------------
    Phillip Horn
    ------------------------------



  • 4.  RE: Netedit Improvement?

    MVP
    Posted Dec 04, 2020 06:01 PM
    A couple more suggestions to improve the experience of using NetEdit..
     1. SSL Certificate for the web needs to be easily importable.  We use a wildcard cert and while I will go to the cli and install it (as soon as I find the guide again), it would be nice to have it in the GUI.
     2. The layout of the web elements need to stay put when I make changes.  Every time I log in, I press the hamburger on the top left to open the list of words, because I don't know what those icons mean.  A wrench and a cogwheel could both be settings.  When I click Devices, the list of devices has columns that I pull around so I can see the "Name" of the device and so that I can see all of the Serial Number and Mac Address, because by default, they are too narrow to show those.  Now, there's a ton of room in the "Current Firmware" column, and the Managed/Status/NAE columns..  But Name/Mac/Serial are too short. (Yes - I know, when I shrink back the hamburger 'Menu', they get right sized, but why don't they right size when I pop that out).
     3. Discover Devices.  So this is a cool feature, but it seems either broken or not quite done yet.  
        a. When I want to add a single switch, I choose the subnet /32, but it still forces me to enter a Seed Address.  ??
       b. When the scan is done, where is the notification that it's good to go?  Where's the notification that it didn't find anything?  I accidentally found it in the logs, but it can get lost.  Should be some sort of button to show me the log filtered to discoveries or something to show me what happened. 
       c.  Show me the link to "Managed Subnets" when I'm in devices so I can see where a "managed subnet" has already located a device.  Here's a log line "Device '10.91.0.56' not discovered since corresponding MAC address 64e881-xxxxxx is already associated with device '10.99.1.71'.  But I didn't initiate any scan on 10.91.xx.xx, why did that message show up?  How do I find if the switch I'm trying to add as say 10.99.1.11 is already listed somewhere else - because I can't get it to show up?
      d.  Re: Managed Subnets, when I'm in the Discover Devices interface, I can see the list of managed subnets, but I can't edit them, and there's no easy way to know where to go and edit them (from that screen).  Would be nice to have a button - 'edit managed subnets' to take me there.
      e.  Multi-edit - I have several 'managed subnets' for example, that are old and I need to remove, but I have to do it one click at a time. click. minus. click. minus.
    <tangent> [because I can't use the management port on access switches, since fiber to our buildings doesn't really allow data/mgmt split for access, so I have to set up management on data plane, but using DHCP to connect initially is super handy - so I have to use a different subnet because it won't let me set a static address when there's already a DHCP even though it's a different VRF?, so I have to put them in on a different network, discover them in NetEdit, and add the config, then change the device to the corrected vlan after the ports are configured.</tangent>

    If someone knows some ways I should be doing something different, I'm open to hear it.

    Thanks!


    ------------------------------
    Phillip Horn
    ------------------------------



  • 5.  RE: Netedit Improvement?

    MVP
    Posted Dec 04, 2020 06:29 PM
    Addendum:

    When using the editor and choosing a configuration selection, I can 'Choose starting configuration' and select "Other Device's Running"
    This is great - however, the list of selectable devices includes only the IP/Mac/Serial/Version/Model/Modified.  I'm looking for a hostname here - where's the hostname?  I see queries and that looks like a powerful tool that I might get to use one day, but, uh, right now I just want to start with the config in Sharp and move on.  Instead, I'm looking for an IP address, that I now have to look up, either in NetEdit or Airwave or my trusty Excel sheet...
    Add hostname as a column?  Allow us to pick which columns we want?

    Thanks!

    ------------------------------
    Phillip Horn
    ------------------------------



  • 6.  RE: Netedit Improvement?

    EMPLOYEE
    Posted Dec 07, 2020 05:50 AM
    Because this is great feedback and suggestions, could you please work with your partner or local Aruba SE to get requests for enhancement filed in the Aruba Innovation Zone? That will ensure each item is seen by the product team so they can consider adding this in new versions.

    There is a link to the Innovation Zone on the Aruba Support Portal, and it is accessible for partners and Aruba internal.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
    ------------------------------



  • 7.  RE: Netedit Improvement?

    MVP
    Posted Dec 07, 2020 10:10 PM
    Thanks for the advice, Herman.  I think I was able to post the ideas to the innovation zone in the correct area.  Hopefully everyone can see them.

    Now for the latest NetEdit drama.  :)
    Today I added ~10 switches (3x6300, 7x6200) to NetEdit using the management interface (Because DHCP).  Once in, I can easily update firmware, then post a basic config to the master switch while adding the VSF member 2/3 info. 
    On the 6300s, I pre-configured them with IPs in the data plane, then set up the stack and had the cables connected.  The switches reboot, and what used to be 3x6300 now all show up as the single "main" IP.  
    On the 6200s (3x), I was trying to save a step and configured both the data IP and the stack at the same time.  When the switches rebooted, I had to go in to NetEdit to change the 'Address' to match the new IP.  I got a log message:
    Message
    Device '10.99.0.31' has the same MAC address 64e881-cf7800 as existing device '10.91.0.75'. Device '10.99.0.31' will be reconciled with '10.91.0.75' and deleted.

    But the switch didn't show up.  I had to go through changing all 3 IPs to get it to come back.  Not sure why, but I would expect that it would show me the switch rather than hiding it completely with that error.

    ------------------------------
    Phillip Horn
    ------------------------------