Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
129d2b8
Create index.md
jazzyj123 Nov 14, 2024
e154633
Delete website/integrations/services/aruba-orchestrator directory
jazzyj123 Nov 14, 2024
c7fa82b
Create index.md
jazzyj123 Nov 14, 2024
3146fdb
Update index.md
jazzyj123 Nov 14, 2024
7b24ec8
Update index.md
jazzyj123 Nov 14, 2024
440da1e
Added Aruba Orchestrator
jazzyj123 Nov 14, 2024
5446c1e
Merge pull request #1 from jazzyj123/jazzyj123-Aruba-Orchestrator-v1
jazzyj123 Nov 14, 2024
e0ca85a
Delete website/integrations/services/Aruba-Orchestrator directory
jazzyj123 Nov 14, 2024
2208b92
Create index.md
jazzyj123 Nov 14, 2024
9b60806
Merge branch 'goauthentik:main' into main
jazzyj123 Nov 14, 2024
4243a33
Update sidebarsIntegrations.js
jazzyj123 Nov 14, 2024
a3dc199
Update index.md (#2)
jazzyj123 Nov 14, 2024
f152fef
Added Aruba Orchestrator v3 (#3)
jazzyj123 Nov 14, 2024
fea1dda
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
4f4db49
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
f277e57
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
36bd0fb
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
4be3994
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
1083c88
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
81e8c94
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
e9bb97a
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 20, 2024
60f7072
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 21, 2024
5b93816
Update website/integrations/services/aruba-orchestrator/index.md
jazzyj123 Nov 21, 2024
e4b836c
Update index.md
jazzyj123 Nov 21, 2024
5918a9d
Update index.md
jazzyj123 Nov 21, 2024
91acc99
Update index.md
jazzyj123 Nov 22, 2024
90ca493
Update index.md
jazzyj123 Nov 22, 2024
cf91b8b
run prettier and a tweak
Nov 27, 2024
f8f1006
fighting
Nov 27, 2024
ecdd6e5
again
Nov 27, 2024
c7f909e
Merge branch 'main' into main-jazz
rissson Nov 28, 2024
7c3e550
prettier
rissson Nov 28, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
78 changes: 78 additions & 0 deletions website/integrations/services/aruba-orchestrator/index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
---
title: Integrate with Aruba Orchestrator
sidebar_label: Aruba Orchestrator
---

# Aruba Orchestrator

<span class="badge badge--secondary">Support level: Community</span>

## What is Aruba Orchestrator

> Aruba Orchestrator is a network management platform used to centrally manage, configure, monitor, and automate Aruba network devices and services. It provides tools for network visibility, policy management, and performance monitoring, simplifying the administration of complex and distributed network environments.
>
> -- https://www.hpe.com/us/en/aruba-edgeconnect-sd-wan.html

## Preparation

The following placeholders are used in this guide:

- `arubaorchestrator.company` is the FQDN of the Aruba Orchestrator install.
- `authentik.company` is the FQDN of the authentik install.
- `SSL Certificate` is the name of the SSL certificate used to sign outgoing responses.

## authentik Configuration

1. Log in to authentik as an admin, and go to the Admin interface.
2. Create a new SAML Property Mapping under **Customisation** -> **Property Mappings**:

- **Name**: `Aruba Orchestrator RBAC`
- **SAML Attribute Name**: `sp-roles`
- **Expression**: Use the expression below but amend the group name as desired.

```
if ak_is_group_member(request.user, name="authentik Admins"):
result = "superAdmin"
return result
```

- Save the settings.

3. Create a new SAML Provider under **Applications** -> **Providers** using the following settings:
- **Name**: Aruba Orchestrator
- **Authentication Flow**: Use your preferred authentication flow (e.g., default-authentication-flow`)
- **Authorization Flow ID**: `default-provider-authorization-explicit-consent (Authorize Application)`
- Protocol settings:
- - **ACS URL**: `https://arubaorchestrator.company/gms/rest/authentication/saml2/consume`
- - **Issuer**: `https://arubaorchestrator.company/gms/rest/authentication/saml2/consume`
- - **Service Provider Binding**: Post
- Advanced protocol settings:
- - **Signing Certificate**:`SSL Certificate`
- - **Property Mappings**:`default` + `sp-roles`
- Leave everything else as default and save the settings.
4. Download the signing certificate under **Applications** -> **Providers** -> **Aruba Orchestrator** .
5. Create a new application under **Applications** -> **Applications**, pick a name and a slug, and assign the provider that you have just created.

## Aruba Orchestrator Configuration

1. Log in to the Aruba Orchestrator.
2. Create a new Remote Authentication Server under **Orchestrator** -> **Authentication** -> **Add New Server**.
- **Type**: `SAML`
- **Name**: `authentik`
- **Username Attribute**: `http://schemas.goauthentik.io/2021/02/saml/username`
- **Issuer URL**: `https://arubaorchestrator.company/gms/rest/authentication/saml2/consume`
- **SSO Endpoint**: `https://authentik.company/application/saml/<slug>/sso/binding/init/` (replace \<slug\> with application slug name)
- **IdP X509 Cert**: (paste in the downloaded signing certificate)
- **ACS URL**: `https://arubaorchestrator.company/gms/rest/authentication/saml2/consume`
- **EdgeConnect SLO Endpoint**: `https://arubaorchestrator.company/gms/rest/authentication/saml2/logout`
- **iDP SLO Endpoint**: (optional)
- **EdgeConnect X.509 Cert SLO**: (optional)
- **Roles Attribute**: `sp-roles` (optional)
- **Appliance Access Group Attribute**: (optional)
- **Default role**: (optional)

## Verification

1. Go to `https://arubaorchestrator.company`.
2. Click **Log In Using authentik** on the login screen and authorize with authentik.
3. You will be redirected to the home screen of the Aruba Orchestrator.
1 change: 1 addition & 0 deletions website/sidebarsIntegrations.js
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,7 @@ module.exports = {
type: "category",
label: "Networking",
items: [
"services/aruba-orchestrator/index",
"services/firezone/index",
"services/fortigate-admin/index",
"services/fortigate-ssl/index",
Expand Down