Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
What's New in AOS-8
This section lists the new features, enhancements, and hardware platforms introduced in each major AOS-8 release.
LSR stands for Long Supported Release, while SSR stands for Short Supported Release.
Check with your local sales representative on managed devices and access points availability in your country.
|
Enhancements |
Description |
|---|---|
|
Addition of the new show amon-sender profile-messages command |
The command displays the mgmt-server profiles and their corresponding AMON Advanced Monitoring. AMON is used in Aruba WLAN deployments for improved network management, monitoring and diagnostic capabilities. messages, providing more visibility into the monitoring data. |
|
DPDK 22.11.7 Upgrade for x86 Platforms and 9106 Platforms |
DPDK is upgraded to version 22.11.7 in all x86-based platforms and new 9106 platforms to enhance stability. |
|
Increased the size of error.log files |
Increased the size of the error.log files from 0.28 MB to 4.5 MB in order to facilitate troubleshooting in all platforms. |
|
WebUI Accessibility Improvements |
This release includes enhancements in accessibility features.
|
|
Support for Ubuntu 24.04 LTS |
AOS-8.13.1.0 adds support for Ubuntu 24.04 LTS, enabling smoother integration with the Linux kernel, and enhancing security and stability. |
|
Toolchain Enhancement for x86-Based Controllers |
AOS-8.13.1.0 introduces an update to the cross-compiler toolchain used for building AOS-8.x images on x86-based controllers. The previous GCC 4.9.4 compiler has been replaced with GCC 10.3, offering improved build reliability, compatibility, better optimization, and enhanced debuggability. The new toolchain also includes expanded support for both IPv4 and IPv6. |
|
Hardware |
Description |
|---|---|
|
Support for 9106 Controllers in AOS-8.x |
Starting with AOS-8.13.1.0, the 9106 controller is now supported in AOS-8.x. This enhancement brings the platform into parity with other x86-based controllers within the AOS-8.x ecosystem. The 9106 can now be deployed as a Branch Gateway, Mobility Controller, or VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. Concentrator, delivering performance and scale comparable to the 7205 controller, with the potential to exceed it depending on deployment conditions. Support for this platform includes full integration with both AirWave and Central On-Premise. The 9106 SKUs (S0B85A, S0B86A) are preloaded with AOS-10.x and cannot be downgraded to AOS-8.x. This is intentionally blocked by the software to preserve system integrity. |
|
Enhancements |
Description |
|---|---|
|
Overview of Reauthentication for IKEv2 Security Associations |
AOS-8.13.0.0 adds an additional layer of security to VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. tunnels by ensuring that devices periodically re-verify their identities, protecting networks from unauthorized accesses. Also, it enhances the IKE Internet Key Exchange. IKE is a key management protocol used with IPsec protocol to establish a secure communication channel. IKE provides additional feature, flexibility, and ease of configuration for IPsec standard. SA Security Association. SA is the establishment of shared security attributes between two network entities to support secure communication. structure and global statistics to support reauthentication. New counters are added to track reauthentication events, such as:
|
|
Web Server Access Logging to Assist Attack Detection |
AOS-8.13.0.0 implements webserver access logging of events to help assist attack detection. These logs may be useful in detecting attacks such as, but is not limited to:
|
|
AOS-8.13.0.0 now supports TLS Transport Layer Security. TLS is a cryptographic protocol that provides communication security over the Internet. TLS encrypts the segments of network connections above the Transport Layer by using asymmetric cryptography for key exchange, symmetric encryption for privacy, and message authentication codes for message integrity. 1.3 for webserver and API Application Programming Interface. Refers to a set of functions, procedures, protocols, and tools that enable users to build application software. interactions. |
|
|
Addition to the provision-ap command |
The provision-ap command introduces three new parameters: aruba-modem-user, aruba-modem-passwd, and aruba-modem-auth. |
|
This enhancement extends 6 GHz Gigahertz. standard power radio support using FCO for indoor locations of standard power access points. While many of these platforms include a GPS Global Positioning System. A satellite-based global navigation system. chip and support GNSS, they may face challenges in receiving GNSS signals indoors with the necessary level of accuracy to use for standard power operations. To address this, a SP AP without a GPS Global Positioning System. A satellite-based global navigation system. location can now use a neighboring AP that does have a GPS Global Positioning System. A satellite-based global navigation system. location for FCO, or through multiple neighbors, using RSSI Received Signal Strength Indicator. RSSI is a mechanism by which RF energy is measured by the circuitry on a wireless NIC (0-255). The RSSI is not standard across vendors. Each vendor determines its own RSSI scale/values. or FTM measurements, so that the standard power AP can provide the necessary data to the FCO to enable its 6 GHz Gigahertz. radio. |
|
|
Starting with AOS-8.13.0.0, the drop-ipv4-options and no drop-ipv4-options parameters are added to the firewall Firewall is a network security system used for preventing unauthorized access to or from a private network. command to enable or disable all IPv4 packet options. When enabled, IPv4 packets are dropped if the IPv4 header length is greater than 20 bytes. Additionally, a new counter for Drop IPv4 Options is included in the output of the show datapath command, which counts the number of IPv4 packets dropped when this feature is enabled. This functionality is also available by selecting the Deny IPv4 options checkbox under the Global Settings accordion on the Configuration > Services > Firewall Firewall is a network security system used for preventing unauthorized access to or from a private network. page of the WebUI. This feature is available only on Controllers. |
|
|
Enhanced Security for IPSec Tunnels with SHA256 Support |
AOS-8.13.0.0 adds support for IPSec tunnels with SHA256 algorithm provided that both the tunnel endpoints support SHA256. The preferred integrity algorithm is SHA256 going forward. If the initiator starts communicating with HMAC-SHA256, then the responder will reply back with HMAC-SHA256. If either the initiator or responder does not support HMAC-SHA256, tunnels will be formed with HMAC-SHA1. |
|
RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources. Location Delivery Service Enhancement |
Starting with AOS-8.13.0.0, two Civic Address (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.-types) elements which are part of the Location-Data attribute, are added. The new CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.-types are CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.-type 19 (House Number) and CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.-type 34 (Primary Road Name). For more information, see Generic RADIUS Location Information Delivery Service. |
|
Qosmos SDK upgrade |
Starting with AOS-8.13.0.0 Qosmos SDK is upgraded to SDK-5.10.0-35 PB1.740.0-20. |
|
IPSec Tunnels with mandatory Post-Quantum Preshared Key (PPK) |
Starting with AOS-8.13.0.0 IPSec tunnels can be set to require PPK configuration on the initiator and responder. This feature can be enabled by running the crypto-local isakmp ppk-mandatory command on the responder. When ppk-mandatory is enabled, both the responder and initiator are expected to have the PPK configured. Otherwise, the tunnel will not come up. The ppk-mandatory parameter will not have any effect if it is enabled on the initiator, it is applicable only on the responder. For more information, visit Configuring a VPN with Postquantum Preshared Keys in the User Guide. |
|
This feature is a security improvement for Password-based Pre-Shared Key. The solution creates a profile to configure the composition of the PSK Pre-shared key. A unique shared secret that was previously shared between two parties by using a secure channel. This is used with WPA security, which requires the owner of a network to provide a passphrase to users for network access. based on the requirements. For more information, visit Configuring Crypto Password Policy Profile in the User Guide. |
|
|
From AOS-8.13.0.0, controllers use DTLS Datagram Transport Layer Security. DTLS communications protocol provides communications security for datagram protocols. v1.2 protocol when DTLS Datagram Transport Layer Security. DTLS communications protocol provides communications security for datagram protocols. security is turned on to secure the traffic between controllers and servers like AirWave (from version 8.3.0.3). DTLS Datagram Transport Layer Security. DTLS communications protocol provides communications security for datagram protocols. v1 is disabled by default in FIPS Federal Information Processing Standards. FIPS refers to a set of standards that describe document processing, encryption algorithms, and other information technology standards for use within non-military government agencies, and by government contractors and vendors who work with these agencies. AirWave server. |
|
|
Support for configuring SHA2 hash function |
Added support for configuring SHA2 hash function in the following commands:
|
|
Starting from AOS-8.13.0.0, IPM Intelligent Power Monitoring. IPM is a feature supported on certain APs that actively measures the power utilization of an AP and dynamically adapts to the power resources. and ITM are enabled by default. For more information, see Intelligent Power and Temperature Monitoring. |
|
|
ARM Adaptive Radio Management. ARM dynamically monitors and adjusts the network to ensure that all users are allowed ready access. It enables full utilization of the available spectrum to support maximum number of users by intelligently choosing the best RF channel and transmit power for APs in their current RF environment. enhancement to support Non-Preferred Scanning Channels |
Two configuration options are introduced to support the setting of Non-Preferred Scanning Channels (non-PSCs) in the 6 GHz Gigahertz. spectrum. Refer to the CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. Reference Guide for the new init-scan-mode and psc-channel-assignment commands. |
|
Enhancements |
Description |
|---|---|
|
Added Support for Telematrix IP Phones with AP-505H Access Points |
Improved AP-505H PSE port compatibility with early generation Telematrix IP phones. |
|
Denylist clients in case of a security context override attempt with the denylist-sco-attack parameter |
The aaa-profile command now accepts the denylist-sco-attack parameter, which enables denylisting for clients that attempt to perform a security context override, improving security against malicious authenticated clients. The default value of this parameter is set to disabled. |
|
RADIUS Authentication Server Profile Configurations Added to AirGroup Version 2 |
The AirGroup version 2 module now accepts RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources. authentication profile changes such as nas-IP and source-interface through the aaa authentication-server radius command. Rather than depending on the Mobility Conductor's settings, this feature allows for specific authentication-related configurations to be applied to managed devices. The configuration varies depending on the AirGroup mode used:
|
|
Several 802.11ax performance metrics statistics have been enhanced in this release. |
|
Enhancements |
Description |
|---|---|
|
Enhancement to the show ap monitor ap-list command |
A new sub-parameter, verbose is added to the show ap monitor ap-list ap-name <ap-name> command. The output of the show ap monitor ap-list ap-name <ap-name> verbose command displays additional information about flags and the flag, W is introduced to identify the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. direct devices. This flag will be displayed only if the detection of WIFI-Direct P2P groups is enabled in the IDS Intrusion Detection System. IDS monitors a network or systems for malicious activity or policy violations and reports its findings to the management system deployed in the network. unauthorized device profile. |
|
The dump-auto-uploading-profile parameter is introduced to configure settings for automatically uploading dump files to the controller when Transfer Enable is open and when the Server IP is not configured in the dump collection profile. |
|
|
Installation of AOS-8 Using ISO Mounting |
The ISO mounting procedure can now be used to install AOS-8. |
|
Support for OVS-DPDK on KVM Hypervisor |
AOS-8 now provides support for configuring OVS-DPDK on Oracle Linux 7.9 using KVM Hypervisor. |
|
AOS-8 provides support for UNII-4 channels (169-177) on 610 Series access points (AP-615) only when the operational mode of the AP is set to 2.4GHz-and-5GHz static mode. |