Central NAC Caveats
This section describes the caveats to be noted when using Central NAC in HPE Aruba Networking Central.
Some of the known issues in Central NAC are listed in the following table:
| Issue ID | Description |
|---|---|
| CNX-108245 |
Re-ordering of rules is only supported if there are fewer than 10 rules in a policy. Re-ordering of conditions within a rule is only supported if there are fewer than 10 conditions in a rule. |
|
CNX-116420 |
Only BYOC certificates with Certificate:SubjectAltName.0:OtherName-msUPN can be used in policy evaluation. |
|
CNX-199590 |
At least one IAP or switch must be onboarded to HPE Aruba Networking Central before performing any update or delete operation on a Passpoint Air Pass provider. |
|
CNX-204889 |
Policy evaluation fails when the Authentication:Source attribute is set to Identity Provider. This issue occurs in BYOC and UEM workflows. |
|
CNX-207247 |
The session timeout functionality is not working with HPE Comware (H3C) switches. |
|
CNX-230654 |
MAC caching does not work for pre-registered visitor accounts. |
|
CNX-231274 |
In overlay mode, separate Captive Portal Authentication profiles must be created for each wired and wireless network. Configuring both overlay wired and wireless within the same authentication profile is not supported and will not function correctly. |
|
CNX-245652 |
In overlay mode, configuring multiple port profiles within a single authentication profile does not function correctly. |
|
CNX-241999 |
A custom message configured for registration purpose is sent only when a user self-registers. It is not sent when an administrator manually provisions a user account or updates an existing account. |
|
CNX-259149 |
With the Simultaneous Session Limit feature, Access Points fail to send the RADIUS Accounting Stop message when sessions end unexpectedly (for example, during an AP reboot). This causes Central NAC to retain stale active sessions and incorrectly enforce session limits. As a result, users may be blocked from connecting their devices, with the error, User exceeded Simultaneous limit. Workaround: Wait for approximately an hour for the stale session to expire and restore access. |
|
CNX-255820 |
Users can exceed the configured maximum session/device limit by reconnecting devices within a short interval (for example, within ~1000 seconds in MPSK scenarios). In such cases, the Access Point (AP) may not trigger a full re-authentication for the reconnecting device, allowing it to join the network without invoking Central NAC policy enforcement and thereby bypassing session limit controls. |
|
CNX-254187 |
Using the same ESSID across different scopes with different authentication types is not supported. |
-
Dynamic authorization will fail if one Azure tenant is used across Cloud Auth or HPE Aruba Networking Central tenants.
Workaround: If the same Azure tenant is used in multiple identity store configurations across Classic Central and HPE Aruba Networking Central, a unique client application should be created for each configuration.
To register a new application on Entra, see Registering CloudAuth in Entra ID Portal.
-
The MAC authentication options (Perform MAC Authentication Before 802.1X and MAC Authentication Fail-Through) for creating WLAN should not be used for wireless networks. These options are applicable only for wired networks.
-
Uninstalling the old HPE Aruba Networking Onboard app will remove the current provisioned network configuration.
-
When using Air Pass in overlay mode, ensure to scope WLAN at both the Device Group and Site levels.
RADSEC Tunnel Instability
An AOS-CX switch intermittently flaps the RADSEC tunnel approximately every five minutes in AOS-CX 10.15. The RADSEC server is configured using a Fully Qualified Domain Name (FQDN). The DNS server resolves this FQDN to a different IP address during each resolution cycle, which occurs every five minutes by default. As a result, the RADSEC tunnel is repeatedly disconnected and re-established.
-
On Ubuntu versions 22.04, 24.04, and 25.04, the HPE Aruba Networking Onboard app installs successfully but the UI might fail to launch due to missing Qt5 libraries.
Workaround: Install the required dependencies using:
sudo apt install qtbase5-dev qtchooser qttools5-dev-tools libqt5svg5-dev
-
Auto-upgrade may fail on Linux systems due to a modified and expired GPG key, causing installer validation errors.
Workaround: Manually import the new GPG key into the client. You can download the HPE Aruba Networking Public GPG keys from this location.
-
After upgrading to HPE Aruba Networking Onboard App version 1.6, the More button appears alongside Refresh and Delete for network profiles. On initial click, the app may display an error due to the unavailable self-service portal API, which prevents fetching network credentials.
Workaround: Click the Refresh button to retry fetching the self-service portal information. After refresh, click More again, to view the list of network credentials.
-
In Android devices, when provisioning a network profile via the HPE Aruba Networking Onboard App, the old user certificates are not replaced after SSID change and remain under user credentials even after profile deletion.
Workaround: Manually remove old certificates from User Credentials after changing the SSID or deleting the profile to ensure proper cleanup.
-
When choosing the sys_central_nac under the MAC authentication server group, the Challenge Handshake Authentication Protocol (CHAP) method is not supported.
Resolved Issues
The following are the resolved issues in this release:
| Issue ID | Description |
|---|---|
|
CNX-84243 CNX-92924 |
Only the first authentication profile in Central NAC correctly displayed the onboarding URL. This issue occurred because same network was used with multiple authentication profiles. The fix ensures that all authentication profiles displayed the onboarding URL. |
|
CNX-85773 |
If entities like roles, SSIDs or tags are deleted from the Central NAC configuration page, no error is shown on UI. |
|
CNX-89267 |
The Authorization Policies page displayed the identity store used by the policy, but the policy was not updated in the Identity Management page. The fix ensures that the policies are updated in the Identity Management page. |
|
CNX-92595 |
In Central NAC, users were unable to update the client secret for an identity store. The fix ensures that users are able to update the client secret. |
|
CNX-86126 CNX-93369 |
In Central NAC, users were unable to create a policy with empty rules and pre-conditions. The fix ensures that users can create policies with no rules or pre-conditions. |
|
CNX-94262 |
When multiple identity stores were configured for the same tenant, Central NAC displayed 'Unsupported identity store configuration' error. This issue occurred because Central NAC was unable to process webhook notifications received from any Azure tenant. The fix ensures that Central NAC is able to process webhook notifications and works as expected. |
|
CNX-99629 |
A default session timeout period of 8 hours was set for all sessions in Central NAC as the session-timeout period was not supported. The fix ensures that the session timeout is supported for any given value. |
|
CNX-97991 |
In Central NAC, for rules and policies, users were unable to delete all conditions and add new conditions simultaneously. The fix ensures that users are able to simultaneously delete and add conditions. |
|
CNX-98109
|
In Central NAC an error occurred when an attribute was updated in an existing condition. The fix ensures that the attributes can be updated in an existing condition. |
|
CNX-103088 |
The policy count in the authorization policies table always displayed zero. The fix ensures that the authorization policies table is updated when a new policy is added. |
|
CNX-106658 |
The MAC registration table displayed only first 100 MAC addresses although the count was more. The fix ensures that infinite scrolling is available in the MAC registration table to display any number of records. |
|
CNX-109484 |
In Central NAC users were unable to update the rule positions within a policy. The fix ensures that users can update the rule positions. |
|
CNX-111310 |
Users were unable to delete a single condition in a rule and had to delete the entire rule. The fix ensures that users can delete a single condition in a rule. |
|
CNX-112632 |
Users were unable to edit a policy without an identity store. The fix ensures that users are able edit a policy without an identity store. |
|
CNX-180759 |
Port Bounce now supports AOS-S and HPE Comware switches. |
|
CNX-211047 |
If an Air Pass profile is configured with an OpenRoaming provider and non-US sites, removing the OpenRoaming provider from the profile will also remove the non-US sites from the profile. |
|
CNX-211084 |
Users faced severe delays to receive the Air Pass approval while creating an Air Pass profile. This issue occurred when large number of sites were selected. The fix ensures improved performance with processing time reduced to 5 minutes. |
|
CNX-220435 |
The Central NAC UI failed to display error messages for invalid file type and invalid file name. This issue occurred during the bulk import of MAC address or MPSK CSV files. The fix ensures that the UI validates and displays error messages as expected. |
|
CNX-221066 |
Validation failures occurred during the bulk import of MAC address MPSK CSV files. This issue occurred when users upload files with spaces in the file name. The fix ensures that file names with spaces do not result in validation failure. |
|
CNX-199699 |
An incorrect SCEP URL was displayed when an existing BYOC or EAP authentication profile was updated to an UEM-based profile. The fix ensures that the correct SCEP URL is displayed. |
|
CNX-105101 |
Dynamic Authorization with BYOC resulted in disconnected user sessions. This issue occurred when a user was deleted, suspended or when user group membership was changed in an identity store. The fix ensures that Dynamic Authorization with BYOC does not disconnect a user session. |
|
CNX-140039 |
Central NAC supports the Enhanced Open Network. |
-
The HPE Aruba Networking Onboard App works on ARM-based chips running Windows 11 version.