What's New in AOS-10.8.1.0

This section provides an overview of the new features and enhancements added to HPE Aruba Networking Wireless Operating System 10.

Table 1: New Features in AOS-10.8.1.0

Features

Description

Rogue AP Aware (Radio Profile Enhancement)s

Rogue AP Aware is a configurable setting under the Radio Profile. When this feature is enabled on a radio, the Adaptive Management (AM) module evaluates rogue AP conditions during periodic radio environment checks.

App Enforcement for IPv6 traffic flows

This release introduces IPv6 support for app or web-based Access Control List (ACL) enforcement. Administrators can now configure and apply firewall policies to IPv6 applications, ensuring consistent security and traffic management across both IPv4 and IPv6 protocols ensuring the same level of visibility and control for IPv6 traffic as previously available for IPv4.

BLE Central with Persistent Bonding on 7xx Series APs

7xx Series APs now support a BLE Central implementation with persistent bonding, enabling secure, encrypted connections to BLE peripherals. The feature supports up to 10 concurrent central connections and 64 stored bonds, allowing devices to reconnect seamlessly across reboots without re-pairing. Built on the Zephyr BLE stack, it includes robust connection management, automatic reconnection, and comprehensive logging for improved scalability and reliability.

Support for Multiple RadSec Profiles on APs

Added support for multiple RadSec profiles on access points, allowing APs to connect securely to multiple RadSec-enabled AAA servers. Each RadSec destination can now be mapped to a distinct client certificate and CA trust chain, including TPM-based, EST-delivered, or manually uploaded certificates. This enhancement enables multi-PKI deployments, improves AAA redundancy, and supports advanced use cases such as M&A scenarios, segmented security domains, and hybrid RadSec backends.

Support for SAE-based authentication on MPSK

MPSK now supports SAE-based authentication, enabling per‑MAC password retrieval during the SAE handshake before association. This enhancement aligns password handling with SAE requirements by computing the Commit Element using client MAC, BSSID, and password token early in the connection process.

BLE GATT Support for Container-Based Apps on AP-Based IoT Connector

AP-based IoT Connectors now support BLE GATT operations for container-based applications, enabling IoT apps to run directly on Access Points to connect to, read from, and write to BLE devices and sensors. This enhancement brings feature parity with VM-based IoT Connectors, allowing customers to deploy fully AP-native IoT solutions without relying on external virtual infrastructure.

MTU Discovery Enhancement for AOS‑10 Campus APs

This enhancement improves the MTU discovery mechanism for AOS‑10 Access Points operating in Campus mode by enabling full end‑to‑end path MTU discovery to the Gateway. The updated behavior now supports both:

  • Increasing MTU above 1500 bytes (current behavior)

  • Decreasing MTU below 1500 bytes (new behavior).

  • Supporting MTU discovery below 1500 bytes enables Campus deployments that better align with, and potentially exceed, the capabilities available in AOS‑8.

    Packet Size Considerations:

    • The minimum TCP payload size is relatively small.

    • For UDP traffic, the commonly accepted client payload size is 576 bytes.

    • This value represents the client data payload, not the full packet size transmitted between the AP and Gateway.

    Adaptive Discovery Approach

    The recommended approach is to:

    • Initiate path MTU discovery at 1500 bytes.

    • Dynamically adjust the MTU upward or downward based on probe success or failure.

    • Allow probing down to a minimum aligned with the 576‑byte UDP client payload, ensuring compatibility with common client behavior.

  • Manual onboarding of gateways

    Starting from AOS-10.8.1.0, HPE Aruba Networking AOS-10 hardware Gateways now support onboarding to Classic Central On‑Premises over IPv6 manually and monitoring through Classic Central On‑Premises starting from AOS-10.8.1.0. To enable these capabilities, gateways running AOS-10.8.1.0 must be configured as dual-stack.

    DPI App Inspection and WebCC support for IPv6 traffic flows

    Introduces DPI App Inspection and Web Content Classification (WebCC) support for IPv6 traffic in AOS-10.x gateways.

    Starting with AOS-10.8.1, AP7xx platforms support the Dual Image Core Function , enabling simultaneous support for AOS-10.x and AOS-8.x. New AP7xx access points ship from the factory with both images preloaded, while existing AP7xx devices must be upgraded to AOS-10.8.1 to automatically download the AOS-8.x image from the Activate server. By default, the AP boots into AOS-10.x, and during factory reset it automatically detects AOS-8.x-based deployment environments. When an Instant AP, controller-based, or Classic Central (CoP) scenario is identified, the AP seamlessly switches to the AOS-8.x image without requiring manual intervention, other manual switch to AOS-8.x in CLI or OTP UI.

    Enhancement to IP Management System

    The maximum DHCP pool limit is increased to 64 from 20. The count includes both system IP pools and DHCP shared pools.

    Enhancement to the following show crypto commands:

    • show crypto ipsec sa peer

    • show crypto-local ipsec-map

    Perfect Forward Secrecy (PFS) is enabled by default for SD-Branch Hub and Spoke tunnels. PFS ensures that past session keys remain secure even if server’s long-term private key is compromised.

    Enhancement to Key Management

    You can select MPSK SAE to establish a shared secret per client without sending the pre-shared key, improving protection against offline attacks and password leak vulnerabilities in WPA3 Personal mode.

    Enhancement to the show console-settings command

    Introduced the Login Timeout parameter in the console. Administrators can set the timeout to 0 to disable the feature, or configure a duration ranging from 5 to 1440 minutes (24 hours). When a timeout is configured, users are required to log in again once the specified time has elapsed.

    Extended PLMN Support for Passpoint Deployments

    The maximum number of Public Land Mobile Networks (PLMNs) that can be configured and advertised for a single SSID has been increased from 36 to 42 to support large-scale Passpoint deployments.

    Firmware Upgrade Warning Banner for 9xxx Gateways

    A new warning banner now appears during 9xxx gateway firmware upgrades, notifying users that upgrades may take 15 to 40 minutes and emphasizing not to power off the device during the process to prevent damage.

    On-Premises Datacenter Redundancy for AOS-10 Gateways

    Datacenter redundancy ensures high availability for AOS-10 gateways by enabling support for dual HPE Aruba Networking Central On-Premises cluster setups. This capability allows gateways to be configured with primary and secondary clusters, ensuring a seamless transition in the event of a primary cluster failure.

    Enhancement to 9xxx Gateways

    Enhanced 9xxx gateways now include drop count and drop reason fields in the session table, providing per-session visibility into packet drops for improved troubleshooting. These fields are displayed across all datapath session CLI outputs and are supported for IPv4 sessions only.

    New Hardware Platforms

    The following are the newly supported HPE Aruba Networking APs in the AOS-10.8.1.0 release:

    • AP-721H (dual-radio, tri-band)

    • AP-723H

    • AP-725H

    The AP-721H, AP-723H, and AP-725H are Wi-Fi 7 (IEEE 802.11be) capable hospitality access points.

    LDAP AAA Load Balancing Support

    LDAP AAA load balancing is introduced as part of AAA server groups, and the existing server-group framework is extended to LDAP. With this capability, you can define an LDAP server group and distribute authentication requests across multiple LDAP servers.

    Dynamic Deny-List Enhancements

    Deny-listing has been enhanced by increasing the total deny-list capacity per AP from 512 entries (128 static + 384 dynamic) to 4096 entries (128 static + 3968 dynamic), significantly improving the system’s ability to handle a large number of authentication failures. In addition, a new configurable option has been introduced under the IDS profile (disabled by default) that allows clients identified by IDS for DoS style activity to be added to the dynamic deny-list when enabled.