What's New in AOS-10.8.0.0

This section provides an overview of the new features and enhancements added to HPE Aruba Networking Wireless Operating System 10.

Table 1: New Features in AOS-10.8.0.0

Features

Description

Session idle timeout for established TCP session

The established TCP session idle timeout is now configurable in a range of 300 seconds (5 minutes) and 43,200 seconds (12 hours). Sessions that remain idle longer than the configured timeout will be removed from the session table.

Configuring Crypto Password Policy Profile

AOS-10.x enhances security for password-based Pre-Shared Keys (PSKs) by introducing a profile that configures the PSK composition according to specified requirements. This profile enables the configuration of individual parameters and applies them seamlessly as part of the PSK validation process. This feature is available only in the disaster recovery CLI mode.

Zoom video call support in UCC application

AOS-10.x now enables the UCC application to detect Zoom video calls, classify them as real-time traffic, and apply appropriate QoS policies for prioritization. It also provides full visibility of Zoom video sessions in Central/CNX, including generating detailed Call Detail Records (CDRs) for monitoring and reporting.

DHCP Pool Support for VIA VPN Clients

AOS-10.x now supports assigning IP addresses to VIA VPN clients using centralized DHCP pools. This allows VIA users to be placed in VLANs defined by their user roles. This simplifies DHCP scope management and eliminates the need for local pool configuration.

New ppk-mandatory CLI Command

AOS-10.x introduces the ppk-mandatory CLI command, providing a configuration knob on the Responder to enforce mandatory Post-Quantum Preshared Key (PPK) setup on the Initiator during IKEv2 negotiation.

Enhanced Named VLAN Capacity for Access Points

In AOS-10.x, support for the number of named VLANs assignable on Access Points (APs) has been significantly expanded. Previously, APs supported a maximum of 128 named VLANs, which was insufficient for large-scale deployments. With this update, APs can now support up to 512 named VLANs, except for the 300 Series APs, which will continue to support a maximum of 32 VLAN names. This enhancement allows network administrators to map user groups to specific VLANs based on policy, regardless of physical site location, improving network design flexibility and supporting larger, more complex deployments.

Expanded System Limits for 9xxx Series Gateway Platforms

In AOS-10.x, system limits for the 90xx and 91xx gateway platforms, including models such as 9004, 9004-LTE, 9012, 9106, and 9114, have been enhanced to support more scalable and flexible deployments. While the maximum number of supported users remains unchanged (e.g., 2048 users on the 9004 and 9012), the system now supports significantly higher limits for user-related tables. Specifically, the station table has been increased to twice the number of users, and the user table entries have been expanded to eight times the number of users. These enhancements are designed to support IPv6 and cluster deployment scenarios, improving stability and future-proofing the platforms for high-density environments.

ESSID supports leading spaces in bridge mode

AOS-10.x now supports leading spaces in ESSID for bridge mode on Underlay networks. Tunnel mode for Overlay networks is not supported currently.

Increased netdestination entries for Platforms in the 9xxx Series

The number of supported netdestination entries is increased to 2048 for 9xxx gateway platforms.

 

Support for SNMP monitoring capabilities for Microbranch (MB) and Underlay devices.

AOS-10.8.0.0 now supports SNMP monitoring on MB APs along with existing AOS-8 MIBs. SNMP support was available earlier across all personas except for MB, which posed challenges for Managed Service Providers (MSPs) in regions where SNMP-based monitoring is a standard practice. These MSPs do not want to modify their existing infrastructure. This update enables SNMP configuration on MB APs via CLI and API without requiring new MIB files or changes to the UI.

Support for client isolation per VLAN on Gateway Clusters

AOS-10.x now supports client isolation per VLAN on AOS-10 Gateway Clusters, enhancing network security and segmentation. Unlike the previous global firewall-based approach, this update allows per-VLAN enable or disable control, enabling more granular management over client traffic isolation. It supports isolation for wireless, wired, and UBT clients, ensuring consistent behavior across all gateways in a cluster. Additionally, it includes configuration options for allowed addresses.

Support for the AP Health IE

AOS-10.x introduces support for the AP Health IE (Information Element) feature, enabling Access Points (APs) to broadcast their operational status and the cause of any failures if they cannot connect to Classic Central. Diagnostic information is included as an Information Element (IE) within beacon frames and sent across all available SSIDs—such as OTP, Recovery, Bridged, and Tunneled—which can be interpreted by nearby HPE Aruba Networking APs or third-party applications.

HPE Aruba Networking APs within range can receive these beacon frames and relay the AP Health IE data to Classic Central. Once the affected AP reconnects to Classic Central, it discontinues broadcasting the health IE. This approach enables administrators and installers to detect connectivity issues remotely, without requiring physical access or authentication credentials.

By default, the AP Health IE feature is active; however, it can be disabled—except for the OTP and Recovery SSID, which always transmits the IE. This simplifies AP troubleshooting, shortens resolution times, and increases deployment efficiency.

DPP support (Device Provisioning Protocol)

The DPP feature is now supported on the AP-7xx series access points from AOS-10.8.0 release.

Support enhancement for the Aruba-Captive-Portal-URL VSA (ID 43)

Overlay support for the Aruba-Captive-Portal-URL VSA (ID 43) enhances consistency between Overlay and Underlay deployments, ensuring reliable captive portal redirection across AOS-10.

Flexible radio configuration support

This feature offers increased flexibility in radio operation modes, allowing administrators to optimize performance for various deployment scenarios. It enables greater control over radio allocation, enhancing coverage and capacity in high-density environments.

The following are the Flex Radio Configuration:

  • Added support for AP-730 Series, AP-750 Series, and AP-760 Series.
  • Flex-Dual-Band for AP-760 Series (dual-band or single-band modes).

  • Flex-Tri-Band for AP-735 and AP-755 (tri-band or dual-band modes).

Configure APN with username and password on Skylark and 9004-LTE modems

Skylark and 9004-LTE modems connected to AOS-10 gateways now support configuration of APN settings with a username and password. This ensures that authentication details pass securely to the modem for proper cellular uplink configuration. This enhancement improves compatibility with a broader range of mobile network providers and deployment scenarios.

Enhancement to Broadcom APs

Wireless and IoT co-existence is now supported for Broadcom-based 600 Series Access Points.

Overlay Captive-Portal role assignment

Overlay Captive Portal authentication now uses the post-auth role configured on the AP for the BSSID, avoiding role transmission to the AP due to role count limitations.

Restored ACL User Alias to Single-User Mapping

The original behavior of the user alias in ACLs for HPE Aruba Networking Gateways running AOS-10.3.1.0 and earlier versions has been restored. The alias now refers to a single user’s IP address, preventing unintended user-to-user communication and ensuring ACL policies function as intended while maintaining proper security and segmentation.

Support for Developer Mode on AP-based IoT Connectors

AOS-10.8.0.0 supports developer mode on AP-based IoT connectors. This feature allows the developer to interact with the IoT Operations API Gateway on the AP and fully complements API endpoints (see IoT Ops Application Developer Portal for list of supported APIs) to facilitate testing.

Cellular Operations Support on WebUI for BR-150

AOS-10.8.0.0 implements the following enhancements to the BR-150 WebUI:

  • Specify cellular settings when the default settings do not work (such as APN and PLMN)

  • Provision of an eSIM

  • Upgrade the modem firmware

  • CNX connection troubleshooting

Support for IPv6 Telemetry for Firewall Sessions

AOS-10.8.0.0 implements the following enhancements to the Telemetry for Firewall Sessions:

  • DPI classification and AppRF reporting now support IPv6 sessions.

  • IPv6 telemetry uses the same pipeline and protobuf format as IPv4 for unified reporting.

Support for Automatic Private IP Addressing

AOS-10.8.0.0 now supports Automatic Private IP Addressing (APIPA). APIPA allows a device to assign itself an IP address in the event that a DHCP server is not available or does not exist on the network, without additional configuration.

Support for LACP Fallback on Gateway LAN Ports

AOS-10.8.0.0 now supports the LACP fallback feature on port channels with multiple interfaces. When this feature is enabled and a port channel is down, member Ethernet interfaces are converted into Layer 2 interfaces, thus inheriting the Layer 2 VLANs from the port-channel interfaces. The port channel becomes operational when the LACP PDUs are received on one or more member interfaces.

It is advised that the Spanning Tree Protocol is enabled to avoid Layer 2 loops in networks.

Recovery SSID Configuration Support

Recovery SSID is introduced for AOS-10 Access Points, providing a secure mechanism to access the AP local web server when APs cannot connect to Central. The Recovery SSID acts as a temporary WLAN, enabling administrators to regain access and restore uplink connectivity. When active, the Recovery SSID provides access to a troubleshooting portal hosted on the AP for debugging.

The following new parameters are added:

  • New WLAN Profile Type: The Recovery option is added alongside Access. For more information on creating a WLAN profile, see WLAN Profile.

  • Recovery WLAN Timer: Configurable back off timer via AP System Profile. For more information on creating an AP system profile, see AP System Profile.

IP-SLA and SLA-Based Routing Enhancements

Aruba Microbranch now adds IP‑SLA health checks to SSE forwarding to prevent traffic blackholing when a Policy‑Based Routing (PBR) next‑hop has a broken upstream path. Microbranch APs now run IP‑SLA probes to IPs or URLs defined by Cloud Connect, and use the probe results to dynamically select the appropriate next‑hop, ensuring traffic is forwarded only over reachable SSE paths for a consistent quality of experience. For more information, see Microbranch Deployment Workflow and Configuring NextHop List.

Enhanced IoT Channel Visibility with Operational Channel Field

A new read-only Operational Channel field has been added to AP CLI showing the actual IoT channel assigned by the Vusion server. This enhancement gives immediate visibility into the real operating channel.

Enhanced Gateway Key Caching for Fast Roaming

Currently, the roaming timing requirement of <100 milliseconds is too short to fetch keys from Cloud KMS. This enhancement leverages the local gateway cluster to store cache entries that APs can access with minimal latency. It introduces a gateway-local key cache, GWKMS, to enable fast 802.11r key retrieval by using local gateway caching. The enhancement ensures high availability through replication, supports fallback to Cloud KMS, and includes monitoring and admin controls. GWKMS runs as a dedicated process with an in-memory cache, PAPI-based message flows for key operations, and secure IPsec communication with APs. It also supports cluster replication via GSM channels, bucket mapping for active/standby roles, and robust failover handling. This feature is enabled by default in AOS-10.8.0.0 APs and can be disabled using the Central Backend API. On the AP CLI, you can enable or disable it with the following commands:
  • gateway-key-caching-disable

  • no gateway-key-caching-disable (default)