What's New in this Release

This section lists the new features, enhancements, or hardware platforms introduced in ArubaOS.

New Features

Table 1: New Features in ArubaOS 8.8.0.0

Enhancements

Description

ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. Hits Table Enhancements

ArubaOS 8.8.0.0 implements an enhancement to the hits-indices allocation by not allocating hits-indices for Expanded-ACEs by default and only allocate when the ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port./user-role is being debugged for firewall Firewall is a network security system used for preventing unauthorized access to or from a private network. hits. A new CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. command, acl-debug alias-rule-hits type, is introduced to allocate hits-indices for debugging purpose.

Ability to Specify NTP Server Using FQDN 

ArubaOS now allows users to add NTP Network Time Protocol. NTP is a protocol for synchronizing the clocks of computers over a network. servers using a hostname/FQDN Fully Qualified Domain Name. FQDN is a complete domain name that identifies a computer or host on the Internet. instead of an IP address.

AP Failover to Different Cluster

ArubaOS now allows to disable the Ethernet Ethernet is a network protocol for data transmission over LAN. link and/or PoE Power over Ethernet. PoE is a technology for wired Ethernet LANs to carry electric power required for the device in the data cables. The IEEE 802.3af PoE standard provides up to 15.4 W of power on each port. PSE of the wired downlink ports during AP failover. ArubaOS also configures the wired port down time after the AP fails over to backup cluster or falls back to the primary cluster.

AirGroup Version

ArubaOS now supports AirGroup version1 (older AirGroup) and version2 (redesigned AirGroup) on the Mobility Master. On boot, the Mobility Master runs AirGroup version1 by default and can be switched to run AirGroup version2.

Configure an EST Profile

The output is modified to specify the keytype in a csr attribute. The default server configuration is accepted first during the enrollment/re-enrollment process. If the server does not provide the csr attribute, then the user configured csr_attribute is accepted.

Captive Portal DUR Restriction

With this enhancement, users can push Captive Portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. profiles along with the user role from CPPM.

Changes to Firmware Upgrade

Starting from this release, ArubaOS allows a firmware upgrade without changing the default boot option.

Cluster Live Upgrade Optimization

Live upgrade feature is enhanced to handle failures more gracefully and take less time to upgrade a cluster.

Cluster Live Upgrade Updates

Cluster live upgrade is now supported with IPv6 setup.

Datazone Redundancy Support

Datazone now supports redundancy to avoid a long time service outage and the user can configure a backup controller or cluster for a datazone configuration.

Dashboard Monitoring- Access Devices

The following changes are introduced:

The Infrastructure dashboard in the WebUI displays the following additional information for an AP that is down:

Timestamp—Displays the date and time from when the AP is down.

Reason—Displays the reason due to which the AP is down.

An Outer IP addresses column is added to the Access Points table.

The Security dashboard in the WebUI displays a new field Match Source under Detected Radios table, which provides information about the various types of sources used for manual reclassification of monitored APs.

Deny Inter-User Bridging

This feature prevents the forwarding of Layer-2 traffic between wired or wireless users even when the users are on different controllers in a cluster.

Discovering Disconnected Antennas

The show ap antenna status command has been introduced to display the operational antenna status of APs. This command helps in identifying broken or disconnected antennas and thus, helps in faster troubleshooting.

DPI Classification to Support App-based PBR

ArubaOS now supports an ability to classify applications from the first packet. This allows Aruba to use application classification information for Policy Based Routing (PBR Policy-based Routing. PBR provides a flexible mechanism for forwarding data packets based on polices configured by a network administrator.) and Dynamic Path Steering (DPS).

Dynamic Packet Event Capture

ArubaOS now supports Dynamic Packet Capture. This feature automates packet captures on the AP, based on anomalous events detected by the APs.

Enabling DHCPv6 Relay-Option (Option 18 and Option 37)

The DHCPv6 Relay-Option (Option 18 and Option 37) feature allows the DHCPv6 relay agent to insert circuit and remote specific information in the form of a TLV Type-length-value or Tag-Length-Value. TLV is an encoding format. It refers to the type of data being processed, the length of the value, and the value for the type of data being processed. (type-length-value) into the client message, which is forwarded to the DHCPv6 server.

Enhancements to 530 Series and 550 Series Access Points

The 530 Series and 550 Series access points are now optimized for better power management based on the following scenarios:

For more information, see Aruba 530 Series Campus Access Points Installation Guide and Aruba 555 Access Point Installation Guide.

Enhancements to Air Slice

Air Slice is now supported on 500 Series, 500H Series, 510 Series, 530 Series, 570 Series and AP-555 access points.

Enhancements to Auth Requests From IKE Internet Key Exchange. IKE is a key management protocol used with IPsec protocol to establish a secure communication channel. IKE provides additional feature, flexibility, and ease of configuration for IPsec standard.

ArubaOS now addresses VIA Virtual Intranet Access. VIA provides secure remote network connectivity for Android, Apple iOS, Mac OS X, and Windows mobile devices and laptops. It automatically scans and selects the best secure connection to the corporate network. and native VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. scalability issues by increasing the max queue size for auth requests from IKE Internet Key Exchange. IKE is a key management protocol used with IPsec protocol to establish a secure communication channel. IKE provides additional feature, flexibility, and ease of configuration for IPsec standard. across all platforms.

Enhancements to Dual 5GHz Mode Option on 340 Series APs

ArubaOS now allows to control the two radios separately in dual 5 GHz Gigahertz. mode of 340 Series access points. Hence, you can use different 802.11a 802.11a provides specifications for wireless systems. Networks using 802.11a operate at radio frequencies in the 5 GHz band. The specification uses a modulation scheme known as orthogonal frequency-division multiplexing (OFDM) that is especially well suited to use in office settings. The maximum data transfer rate is 54 Mbps. radio profiles—dot11a-radio-profile for radio 0 and dot11a-secondary-radio-profile for radio 1 in dual 5 GHz Gigahertz. mode.

Enhancements to Fast BSS Transmission

Fast BSS Basic Service Set. A BSS is a set of interconnected stations that can communicate with each other. BSS can be an independent BSS or infrastructure BSS. An independent BSS is an ad hoc network that does not include APs, whereas the infrastructure BSS consists of an AP and all its associated clients. transition is now operational with WPA3-Enterprise CNSA mode with GCM-256 encryption.

Enhancements to HE Pooling

AirMatch now allows efficient use of available channels by dedicating specific number of channels to HE and non-HE radios.

Enhancements to Mesh Scanning Process

ArubaOS now allows users to configure how often the topology mesh scanning should be performed to find a better mesh link.

Fast Roaming with Mesh APs

ArubaOS now supports fast roaming for APs deployed in a wireless mesh network in fast moving environments, such as buses or the subway. To support fast roaming, mobility mesh points perform a scan of other mesh points in the background, and then choose the best neighbor to connect from all the neighbors.

Firewall Policies

A description field has been added to capture the reason why an ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. was created.

GRE tunnel traffic Load distribution

The traffic load passing through a GRE Generic Routing Encapsulation. GRE is an IP encapsulation protocol that is used to transport packets over a network. tunnel can now be distributed across multiple CPUs instead of one to load balance the traffic.

IoT Authentication Type

ArubaOS introduces a new IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. authentication type, Client Credentials. The new authentication type can be configured in the IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. transport profile.

IoT Support for Azure IoT Hub

ArubaOS introduces a new transport type, Azure-IoTHub to send IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. data to the Azure IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. Hub. The new transport type can be configured in the IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. transport profile.

IoT Dashboard

The IoT dashboard in the WebUI of the Mobility Controller displays the IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. data transport and information of the IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. devices in the network.

IoT Support for EnOcean Sensors

ArubaOS now supports all sub-1-GHz Gigahertz. USB Universal Serial Bus. USB is a connection standard that offers a common interface for communication between the external devices and a computer. USB is the most common port used in the client devices. -based sensors from EnOcean.

IoT Support for per Frame Filtering

ArubaOS now supports applying transport profile filters to each frame rather than on the device.

IoT Support for BLE Data forwarding for all Device Classes

ArubaOS now allows forwarding of BLE Bluetooth Low Energy. The BLE functionality is offered by Bluetooth® to enable devices to run for long durations with low power consumption. data for all device classes.

IoT Support for Google Sensors

ArubaOS now supports Google sensors. Google is a leading provider of BLE Bluetooth Low Energy. The BLE functionality is offered by Bluetooth® to enable devices to run for long durations with low power consumption.-based electronic devices.

IoT Support for Minew Sensors

ArubaOS now supports Minew sensors. Minew is a leading provider of BLE Bluetooth Low Energy. The BLE functionality is offered by Bluetooth® to enable devices to run for long durations with low power consumption.-based electronic devices.

IoT Support for Solu-M Newton USBG2 GW

ArubaOS now supports Solu-M Newton USBG2 GW device.

Command modified to allow users to see the L3 redundant peer controller details along with active and standby controller details.

Microsoft Teams

ArubaOS now supports classification, prioritization, and visibility of Microsoft Teams voice and video calls differently from Skype for Business voice and video calls in a wireless environment. ArubaOS detects Teams calls initiated from the Teams client and also over the web browser.

NSS CPU Central Processing Unit. A CPU is an electronic circuitry in a computer for processing instructions. Usage

The output of the show ap debug system-status command displays the NSS CPU Central Processing Unit. A CPU is an electronic circuitry in a computer for processing instructions. usage. The NSS CPU Central Processing Unit. A CPU is an electronic circuitry in a computer for processing instructions. usage will be displayed only for AP-534, AP-535, and AP-555 access points.

Per-AP Override

The per-AP override feature allows to configure specific configuration at per-AP level to override AP group level settings in the WebUI.

QOSMOS Image Upgrade

The QOSMOS proto bundle has been upgraded to 1.500-20 version.

Reserving IP Addresses

ArubaOS now allows to manually reserve IP addresses from a DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network.  pool for specific devices or MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. addresses in a large deployment. With manual IP reservation, managed devices can assign the same IP address to a client whenever it requests for a network connection.

RTLS Real-Time Location Systems. RTLS automatically identifies and tracks the location of objects or people in real time, usually within a building or other contained area. Payload

ArubaOS 8.8.0.0 increments the output parameter, TAG of the show amon-sender stats-counters-all command to indicate the RTLS Real-Time Location Systems. RTLS automatically identifies and tracks the location of objects or people in real time, usually within a building or other contained area. frames received from the AMON Advanced Monitoring. AMON is used in Aruba WLAN deployments for improved network management, monitoring and diagnostic capabilities. receiver.

Role-based Robust Age-out Mechanism for Wired Clients

ArubaOS 8.8.0.0 introduces a Role-based Robust Age-out Mechanism for wired passive clients where a wired client, such as a printer, will not be deleted from the system without its network un-reachability being verified by ICMP Internet Control Message Protocol. ICMP is an error reporting protocol. It is used by network devices such as routers, to send error messages and operational information to the source IP address when network problems prevent delivery of IP packets. first.

Session ACL on IPsec Map

Support for session ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. on IPSec map allows to control the traffic flowing inside the IPSec tunnel by defining permit or deny ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. rules as part of the session ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port..

SNMP Trap Group

The SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention.  trap groups allow to select specific traps to be configured within the group.

SNMP Trap on VLAN Probe Failure

A new SNMP Simple Network Management Protocol. SNMP is a TCP/IP standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more. It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention.  trap, wlsxClusterVlanProbeStatus, is generated when VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. probe fails.

Specify 802.1X auth timeout

ArubaOS now allows configuration of the 802.1X 802.1X is an IEEE standard for port-based network access control designed to enhance 802.11 WLAN security. 802.1X provides an authentication framework that allows a user to be authenticated by a central authority. authentication timeout option as suitable for customer environments.

Support for New Modem

7000 Series and 9000 Series controllers now support GTC Generic Token Card. GTC is a protocol that can be used as an alternative to MSCHAPv2  protocol. GTC allows authentication to various authentication databases even in cases where MSCHAPv2  is not supported by the database. Netstick GLU-194ST USB Universal Serial Bus. USB is a connection standard that offers a common interface for communication between the external devices and a computer. USB is the most common port used in the client devices. Modem.

Support for 802.11mc Fine Timing Measurement Responder Mode

802.11mc Fine Timing Measurement (FTM) responder mode can be enabled on 500 Series, 500H Series, 510 Series, 530 Series, 550 Series, 560 Series, and 570 Series access points.

Support for SES-Imagotag Cloud TLS Authentication

ArubaOS now allows an AP to authenticate with SES-Imagotag ESL server and verify the TLS Transport Layer Security. TLS is a cryptographic protocol that provides communication security over the Internet. TLS encrypts the segments of network connections above the Transport Layer by using asymmetric cryptography for key exchange, symmetric encryption for privacy, and message authentication codes for message integrity.  FQDN Fully Qualified Domain Name. FQDN is a complete domain name that identifies a computer or host on the Internet.. ArubaOS also supports channel 127 for SES Imagotag ESL.

Support for DHCP Pool for VIA VPN users

ArubaOS now supports getting a VIA Virtual Intranet Access. VIA provides secure remote network connectivity for Android, Apple iOS, Mac OS X, and Windows mobile devices and laptops. It automatically scans and selects the best secure connection to the corporate network. client IP address from an external DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network.  server instead of internal L2TP Layer-2 Tunneling Protocol. L2TP is a networking protocol used by the ISPs to enable VPN operations. pool.

Support for Web-Server Configuration and Custom Certificate in APs

To provide enhanced security, the following configurations available on controllers are applied to APs automatically when a virtual AP is created with captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. authentication in bridge forwarding mode:

Web server profile configuration

Custom certificate

Troubleshooting Ethernet Related Issues

The output of the show ap debug system-status and show ap tech-support commands now display details related to ethernet ports. This helps in troubleshooting issues related to ethernet ports.

Updates to the UCC Unified Communications and Collaboration. UCC is a term used to describe the integration of various communications methods with collaboration tools such as virtual whiteboards, real-time audio and video conferencing, and enhanced call control capabilities. Table

The Custom SIP Session Initiation Protocol. SIP is used for signaling and controlling multimedia communication session such as voice and video calls.  entry is replaced with the actual application name or protocol in the Services/Wireless Calls (UCC Unified Communications and Collaboration. UCC is a term used to describe the integration of various communications methods with collaboration tools such as virtual whiteboards, real-time audio and video conferencing, and enhanced call control capabilities.) table column ALG Application Layer Gateway. ALG is a security component that manages application layer protocols such as SIP, FTP and so on. .

Upgrading using Mobility Master File Server

The flash storage on the Mobility Master is used as a file server for live upgrade and this locally stored image will be downloaded by the managed devices using HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. protocol.

Uplink MU-MIMO Transmission

ArubaOS now supports the uplink MU-MIMO Multi-User Multiple-Input Multiple-Output. MU-MIMO is a set of multiple-input and multiple-output technologies for wireless communication, in which users or wireless terminals with one or more antennas communicate with each other. transmission of 802.11ax protocol for AP-535 and AP-555 access points. The uplink MU-MIMO Multi-User Multiple-Input Multiple-Output. MU-MIMO is a set of multiple-input and multiple-output technologies for wireless communication, in which users or wireless terminals with one or more antennas communicate with each other. transmission helps in achieving throughput gains when applications need to upload a large amount of data.

VoIP Aware Scan Timer

ArubaOS now allows users to set the VoIP Voice over IP. VoIP allows transmission of voice and multimedia content over an IP network. Aware Scan Timer range between 50 ms–1000 ms.

WebUI Support for Users with ap-provisioning Role

ArubaOS now extends WebUI support for users with ap-provisioing role.

WebUI Support to Display Redundant Mobility Masters

Starting from ArubaOS 8.8.0.0, the WebUI displays the list of all Mobility Masters including Layer 2 and Layer 3 Redundancy Mobility Masters in the Mobility Master node hierarchy. Also, the text Active is displayed next to the name of the Mobility Master indicating that the particular Mobility Master is active. This text is displayed only when redundancy is configured.

Wi-Fi Uplink Support in Tri-Radio and Dual 5 GHz Mode

ArubaOS now allows Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. Uplink feature on AP-345 access points in dual 5 GHz Gigahertz. mode, and on AP-555 access points in tri-radio mode.

WMS Reclassification

For each classification type that is sent to an AP, the AP now sends a PROBE_RAP_ACK message to inform WMS that it has received the classification type.

Zero-Wait Dynamic Frequency Selection

Dynamic Frequency Selection (DFS Dynamic Frequency Selection. DFS is a mandate for radio systems operating in the 5 GHz band to be equipped with means to identify and avoid interference with Radar systems.), a mandate for radio systems operating in the 5 GHz Gigahertz. band Band refers to a specified range of frequencies of electromagnetic radiation. to identify and avoid interference with Radar Radio Detection and Ranging. Radar is an object-detection system that uses radio waves to determine the range, angle, or velocity of objects. systems now supports the zero-wait feature. The zero-wait DFS Dynamic Frequency Selection. DFS is a mandate for radio systems operating in the 5 GHz band to be equipped with means to identify and avoid interference with Radar systems. feature provides seamless change of channels and avoids the one minute outage when APs change channels. Hence, stations do not lose its connectivity when an AP moves to a DFS Dynamic Frequency Selection. DFS is a mandate for radio systems operating in the 5 GHz band to be equipped with means to identify and avoid interference with Radar systems. channel.