Wired Intelligent Edge (Campus Switching and Routing)

Downloadable User Role (DUR) with Netdestinations in ArubaOS Switches


You might have a requirement where you need to allow certain types of traffic to a set of destinations rather than just denying or permitting traffic as a whole in a Downloadable User Role. Starting from version WC.16.06.0006 Aruba Switches support Netdestinations and Netservices within DUR using which you can use to achieve this use-case .



We can define a Netdestination and NetService within a DUR which will allow us to achieve this use case. 


You need to configure the DUR (Downloadable User Role) as shown below to allow UDP 1812,1813, FTP, DHCP,DNS,SSH,SMTP and TCP port 5000 traffic to a set of destinations shown below 

netdestination "YT-Net"

network position 1

network position 2

network position 3

network position 4

network position 5


netservice "allowrad" udp 1812 1813

netservice "allowftp" tcp 21

netservice "allowdhcp" udp 67 68

netservice "allowdns" udp 53

netservice  "service-ftp" tcp 20 21

netservice  "svc-ssh" tcp 22

netservice  "svc-smtp" tcp 25 465

netservice "port5k" tcp 5000

class ipv4 "allow-service"

12 match alias-src "any" alias-dst "YT-Net" alias-srvc allowrad

14 match alias-src "any" alias-dst "YT-Net" alias-srvc allowftp

16 match alias-src "any" alias-dst "YT-Net" alias-srvc allowdhcp

18 match alias-src "any" alias-dst "YT-Net" alias-srvc service-ftp

20 match alias-src "any" alias-dst "YT-Net" alias-srvc svc-ssh

22 match alias-src "any" alias-dst "YT-Net" alias-srvc svc-smtp

24 match alias-src "any" alias-dst "YT-Net" alias-srvc port5k


policy user "allow-service"

10 class ipv4 "allow-service" action permit


aaa authorization user-role name "netdestrole"

policy "allow-service"

vlan-id 20


In the ClearPass you need to chose Aruba Downloadable Enforcement 

The Role configuration mode is Advanced and and the product is ArubaOS-Switch as shown below 



You need to click on attributes and select the Attribute Name as HPE-CPPM-Role(27) and paste the content of the DUR in the Value as shown below



Note : This article assumes that the other pieces of configuration required for DUR are already in place. If you need assistance configuring DUR you can use the link below to configure DUR 




Once this DUR is returned you would be able to see the DUR on the Switch when you execute the command 

"show port-access clients detailed"

Version history
Revision #:
1 of 1
Last update:
‎02-26-2019 07:19 AM
Updated by:
Search Airheads
Showing results for 
Search instead for 
Did you mean: