|
802.1X Authentication
|
Starting from this release, the authentication is an independent process.
|
|
802.11ad Support
|
802.11ad, also known as WiGig, is a multi-gigabit technology that allows managed devices to communicate at multi gigabit speeds over a 60 . This technology comprises two radios, 5 and 60 .
|
|
802.11ax Support
|
802.11ax, also known as High-Efficiency (HEW), is a multi-gigabit technology that allows managed devices to communicate on both the 2.4 and 5 frequency .
|
|
802.11w Support for Tunnel Mode
|
The 802.11w standard is now supported in tunnel mode with a Virtual AP configured with WPA3 security mode.
|
|
Adding AP's MAC address in redirection URL
|
An AP's address is added to the redirection when external servers are used.
|
|
Admin Password Recovery
|
Starting from this release, ArubaOS allows you to disable the default password recovery feature and create an alternate password recovery user to reset the admin password.
|
|
Analytics Integration with Airmatch
|
ArubaOS is now integrated with Aruba's Network Analytics and Assurance solution, NetInsight. The analytics engine in NetInsight can push radio profile recommendations, channel-bandwidth recommendations, and regulatory domain profile recommendations to an AP.
|
|
AP Packet Capture
|
AP Packet Capture feature allows you to manually start capturing AP packets on an access point that is UP and download the files easily using the WebUI.
|
|
ARM Profile Configuration
|
The following profile configuration parameters are available only on standalone controllers and legacy Master controller.
Assignment
Allowed bands for 40 MHz channels
80 MHz support
Max TX EIRP
Min TX EIRP
|
|
Auto-Provisioning of APs
|
Starting from this release, ArubaOS supports auto-provisioning of APs by assigning pre-defined rules to new APs. This feature also enables bulk provisioning of APs with different attributes.
|
|
Backward Compatibility
|
ArubaOS introduces the Backward Compatibility feature that enables managed devices to receive register requests on the older port 80. This option is beneficial when managed devices and Instant APs have not been upgraded to ArubaOS 8.4.0.0 simultaneously in a network.
|
|
ClientInsight for ArubaOS
|
ClientInsight is designed to support the next generation data-driven wireless network automation. It is an integration of ClientMatch and NetInsight.
|
|
Configuring AirMatch
|
A toggle switch is added to enable the Automatically deploy AirMatch optimizations setting in the WebUI.
|
|
Configuring ClientMatch
|
A single checkbox is added to enable or disable both 2.4 and 5 radio settings in the WebUI.
|
|
Configuring Concurrent Sessions
|
A check is added to limit the number of concurrent sessions that an administrator account can maintain.
|
|
Configuring Multizone
|
Starting from this release, ArubaOS supports configuration of either or both IPv4 and IPv6 addresses in one data zone of an AP MultiZone profile.
|
|
Configuring Preferred Uplink
|
Starting ArubaOS 8.4.0.0 ethernet port1 can be configured as the primary uplink and ethernet port0 can be configured as the downlink interface, in an active-standby uplink mode of deployment. This enhancement is supported in AP-318, AP-374, AP-375, and AP-377.
|
|
Dashboard Monitoring
|
The following changes are introduced:
New Dashboard page is not supported in the Master controller mode.
The Access Points table contains a delete option to remove unprovisioned or unused access points.
|
|
Dynamic Segmentation
|
The Dynamic Segmentation solution is Aruba's ability to assign policy (roles), to a wired port based on the
access method of a client.
Starting from this release IPv6 support for Aruba Dynamic Segmentation solution is available.
|
|
Enhanced Open Security
|
ArubaOS supports enhanced open security that reduces exposure of user data to passive traffic snooping.
|
|
Enhancement to 802.1X Supplicant Support on an AP
|
Starting from this release, ArubaOS allows you to add an as a suffix to an AP name or a group of APs for factory certificates with supplicant support.
|
|
Enhancements to AP Heartbeat
|
Starting from this release, ArubaOS provides additional security by enabling the controller to age out the APs based on the AP heartbeat interval.
|
|
Enhancements to Uplink Configuration
|
The uplink configuration is simplified and enhanced to configure multiple paths to the Concentrator for a branch office network by allowing you to specify the link type and link names.
|
|
EST Support for Cluster
|
The cluster members use enrolled certificate for tunnel authentication instead of using factory certificates.
|
|
External
|
Starting from this release, ArubaOS supports External for IPv6.
|
|
Green AP
|
Starting from this release, ArubaOS supports Green AP feature where based on the feeds, the feature dynamically enables, disables, or reduces functionality of an allocated AP to reduce the consumption of energy.
|
|
Hub and Spoke VPN Support
|
ArubaOS provides support for Hub and Spoke which enables automatic tunnel establishment with the concentrators for managed devices in a branch network.
|
|
Implementing Management User Audits
|
The administrator can track the following details:
Location of the last successful login
Date and time stamp of the last successful login
Number of successful attempts over a period of time
Number of unsuccessful attempts since the last successful login
|
|
Implementing Password Validation
|
When a based management user changes the password, a check is added to ensure that there is at least a difference of 8 characters between the new password and the old password.
|
|
IoT
|
ArubaOS supports applications through multiple transport mechanisms, payload encoding, payload content, and periodicity of information updates.
|
|
IP Conflict detection
|
Starting from this release, APs can detect and resolve an IP conflict.
|
|
IPsec Support
|
A Remote AP supports IPv6 clients in Split-Tunnel forwarding mode in a VAP profile.
|
|
Jumbo Frame Support
|
Starting from this release, ArubaOS supports Jumbo Frames on Mobility Controller Virtual Appliance. For more information, see the ArubaOS Virtual Appliance Installation Guide.
|
|
License Management with ASP
|
ArubaOS License Automation feature is supported where the Mobility Master obtains the ArubaOS licenses from ASP or automatically. The users need not manually add the licenses on the Mobility Master.
|
|
Maintaining Standard Mandatory Notice and Consent Banner
|
Starting from this release, the managed device must retain the Standard Mandatory Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log on for further access.
|
| Mesh auto role detection
|
ArubaOS introduces the mesh auto parameter under mesh role. Mesh auto enables auto-detection of mesh point or mesh portal based on system initialization or operation.
|
|
Netdestination and Netservice Aliases
|
Starting from this release, ArubaOS WebUI supports configuration of Netdestination and Netservice aliases.
|
|
Optional AP Configuration Settings
|
The following changes are introduced:
Support for IPv6 address between the AP and the location server (AeroScout/).
A new parameter, AP USB Power mode, to enable or disable the port on various AP platforms
that have external ports.
|
|
Provisioning 4G USB Modems on Remote Access Points
|
Remote APs support the use of AT&T ZTE MF861 and Inseego U730L modems to provide internet backhaul on a network.
|
|
Remote AP support with Cluster behind NAT
|
Remote APs can map the managed device’s private address to a public space by obtaining the private IP and public IP address mapping from a cluster. Therefore, the cluster behind is supported with Remote APs.
|
|
RF Management Configuration
|
The following management configuration parameters are available only on the Mobility Master.
Max Channel Bandwidth
Min Channel Bandwidth
Min EIRP
Max EIRP
eirp-offset
|
|
RTP Traffic without Changing DSCP Value
|
ArubaOS allows passing the traffic without changing the value set by the end user device.
|
|
Scheduled Cluster Upgrade
|
ArubaOS allows scheduling upgrade of clusters at a scheduled time.
|
|
Scheduling Upgrade
|
ArubaOS allows scheduling upgrade of managed devices and clusters at scheduled time.
|
|
SES-imagotag ESL System
|
ArubaOS introduces the support for SES-imagotag’s Electronic Shelf Label (ESL) system.
|
|
Support for Captive
Portal URL VSA
|
ArubaOS supports Aruba-Captive-Portal-URL attribute to dynamically redirect users to home page.
|
|
Support for channels 169 and 173
|
ArubaOS supports channel 169 and 173 for outdoor APs on 5 channel.
|
|
Support for ClearPass Policy Manager Downloadable User Roles in Cluster Deployments
|
ArubaOS supports downloadable user roles for tunneled and wireless users in cluster deployments.
|
|
Support for Multiple PPPoE uplinks
|
Starting from this release, the managed device can be configured to support the same IP address over multiple uplinks.
|
|
Support for Redirect-DNS
|
User can redirect the domain to a dedicated server in IPv4 and IPv6 domain.
|
|
Support for Smart AMON
|
feeds are now made programmable and cloud friendly to help minimize the telemetry traffic between the controller and the Cloud.
|
|
Support for Traps
|
A controller's traps can now be sent over Websocket.
|
|
Support for Static IP Routing using Automatic VPN Tunnel
|
ArubaOS supports forwarding of IP routes using the tunnel to Concentrator that is established using the Hub and Spoke configuration in a branch network.
|
|
Support for trusted and untrusted VLANs
|
A single IPv4 and IPv6 Layer-2 tunnel can carry both trusted and untrusted .
|
|
Support for Unicode Characters
|
Support for unicode characters in is added.
|
|
Support for Wired AP mode
|
ArubaOS supports Wired AP mode to bridge the port E1 and port E0 wired traffic.
|
|
Support for WPA3
|
ArubaOS supports WPA3-based security enhancements including SAE and WPA3-Enterprise.
|
|
Traffic Analysis
|
The Web Content Classification (WebCC) feature supports
classification of both IPv4 and IPv6 sessions.
|
|
Using ZTP with DHCP to provision Managed Devices
|
The managed device can get the information required for provisioning from a server instead of Activate. Option 43 of can be used for broadcasting the master information to the managed devices.
|
|
VIA Client Audit
|
Starting from this release, when a user authenticates and accesses the VIA client, a notification with details about the last successful logon date and time stamp is provided.
|
|
VIA Unique Identifier
|
Client's address is used as the unique identifier when authentication is sent to ClearPass Policy Manager.
|
|
VIA VPN Client Capability
|
The VIA client provides a new Vendor Identifier string to enable forwarding of Layer-2 tunnel.
|
|
VIA VPN client visibility
|
The client users are separately displayed on the WebUI for client visibility. A separate GSM channel is added to support this feature and the users are published only to existing user and ip_user channels.
|
|
WebUI enhancements
|
The following enhancements are introduced in the WebUI:
Drag and Drop
Edit Action
|
|
WIDS AMPDU Optimization
|
Starting from this release, you can configure to reduce the number of frames copied for the purpose of aggregate optimization from the AP system profile.
|
|
WMM DSCP mapping
|
mapping supports IPv6 packets only in the upstream direction of the decrypt tunnel mode.
|
|
Zeroizing TPM Keys
|
Starting from this release, you can zeroize a cryptographic module, this involves erasing sensitive parameters such as electronically stored data, cryptographic keys, and critical security parameters from a controller or an AP to prevent disclosure of information if the equipment is permanently and irreversibly decommissioned.
|