HPE Aruba Networking Wireless Operating System 10 Capacity Licenses

The HPE Aruba Networking 9240 gateways support license based capacity limits instead of building separate hardware platforms for different capacity requirements. There are three capacity levels:

  • Base (no license)

  • Silver license

  • Gold license

The following tables list the differences in the license types supported on the HPE Aruba Networking 9240 gateway.

Table 1: Technical Specifications —Throughput

Performance

Base

Silver

Gold

Firewall Throughput (Gbps)

20

30

40

Encrypted Throughput GRE (Gbps)

20

30

40

Encrypted Throughput AES-CBC-128 (Gbps)

20

30

38

Encrypted Throughput AES-CBC-256 (Gbps)

20

30

39

Encrypted Throughput AES-GCM-128 (Gbps)

20

30

40

Encrypted Throughput AES-GCM-256 (Gbps)

20

30

40

Encrypted Throughput AES-CCM (Gbps)

20

28

30

Table 2: Technical Specifications—HPE Aruba Networking Wireless Operating System 10

AOS-10 Specifications

Base

Silver

Gold

Maximum Clients

32K

48K

64K

Maximum Clients per Cluster

128K

192K

256K

Max APs

4K

8K

16K

Max APs per Cluster

8K

16K

32K

Active Firewall sessions

4M

4M

4M

Concurrent IPsec Tunnels (Minimum)

32K

64K

128K

Concurrent GRE Tunnels (Minimum)

8K

16K

32K

The minimum software version that supports capacity licenses is AOS-10.6.0.0.

Important Points

HPE Aruba Networking 9240 gateways with Silver or Gold capacity license do not support IDPS Intrusion Detection and Prevention System (IDPS) monitors, detects, and prevents threats in the inbound and outbound traffic. Aruba IDPS provides an extra layer of protection that actively analyzes the network and takes actions on the traffic flows based on the defined rules. It inspects data packets, and if any threat is identified, acts real-time to prevent it.. Only the 9240 Base model supports the IDPS feature and its functionalities, with the following security licenses:

For more information on supported gateways for IDPS, see Preparing to add IDPS-Supported Gateways.

Table 3: IDPS—SKU for Aruba 9240 Gateways with Capacity License

SKU for 9240 with Capacity License

Base

Silver

Gold

SD-Branch Foundation

Yes

Yes

Yes

SD-Branch Foundation with Security

Yes

No

No

SD-Branch Advanced

Yes

Yes

Yes

SD-Branch Advanced with Security

Yes

No

No

Gateway WLAN Advanced

Yes

Yes

Yes

Gateway WLAN Advanced with Security

Yes

No

No

Key Features

The key features of the Capacity license for HPE Aruba Networking 9240 platforms are:

How Capacity License Works

Capacity licenses must be manually applied or updated on the 9240 gateways using CLI.

Capacity license management through HPE GreenLake portal and Classic Central will be added in a future release.

The license is generated in the HPE Networking Support Portal and is also emailed to the customer. The customer copies the license and pastes on the gateway's console, after which the capacity license remains on the gateway. In the case of write erase, the capacity license remains on the gateway. In the case of write erase all, the capacity license is removed from the gateway. You must log into HPE Networking Support Portal or get the license keys from the email and copy-paste the license again on the gateway.

For more information on configuring HPE Aruba Networking 9240 gateway capacity licenses, see Configuring Capacity Licenses on HPE Aruba Networking 9240 Gateways.

For Gateway IDS Intrusion Detection System. IDS monitors a network or systems for malicious activity or policy violations and reports its findings to the management system deployed in the network./IPS Intrusion Prevention System. The IPS monitors a network for malicious activities such as security threats or policy violations. The main function of an IPS is to identify suspicious activity, log the information, attempt to block the activity, and report it. , the Security license and Gold/Silver Capacity licenses are mutually exclusive for the 9240 gateway. The Capacity license (applicable only to 9240 models) defines the maximum IDPS throughput, while the Security license provides IDPS capability with a predefined performance limit. Since they represent different entitlement models, they cannot coexist on the gateway. If both are assigned, the Security license takes precedence. To activate the Capacity license, remove or unassign the Security license and reboot the gateway; the Capacity license will then take effect. For more information, see Can I use both the security license and capacity license together for IDPS?.