Central NAC Caveats

This section describes the caveats to be noted when using Central NAC in HPE Aruba Networking Central.

Some of the known issues in Central NAC are listed in the following table:

Table 1: Known Issues

Issue ID Description
CNX-108245

Re-ordering of rules is only supported if there are fewer than 10 rules in a policy.

Re-ordering of conditions within a rule is only supported if there are fewer than 10 conditions in a rule.

CNX-116420

Only BYOC certificates with Certificate:SubjectAltName.0:OtherName-msUPN can be used in policy evaluation.

CNX-199590

At least one IAP or switch must be onboarded to HPE Aruba Networking Central before performing any update or delete operation on a Passpoint Air Pass provider.

CNX-204889

Policy evaluation fails when the Authentication:Source attribute is set to Identity Provider. This issue occurs in BYOC and UEM workflows.

CNX-207247

The session timeout functionality is not working with HPE Comware (H3C) switches.

CNX-230654

MAC caching does not work for pre-registered visitor accounts.

CNX-231274

In overlay mode, separate Captive Portal Authentication profiles must be created for each wired and wireless network. Configuring both overlay wired and wireless within the same authentication profile is not supported and will not function correctly.

CNX-245652

In overlay mode, configuring multiple port profiles within a single authentication profile does not function correctly.

CNX-241999

A custom message configured for registration purpose is sent only when a user self-registers. It is not sent when an administrator manually provisions a user account or updates an existing account.

CNX-259149

With the Simultaneous Session Limit feature, Access Points fail to send the RADIUS Accounting Stop message when sessions end unexpectedly (for example, during an AP reboot). This causes Central NAC to retain stale active sessions and incorrectly enforce session limits. As a result, users may be blocked from connecting their devices, with the error, User exceeded Simultaneous limit. Workaround: Wait for approximately an hour for the stale session to expire and restore access.

CNX-255820

Users can exceed the configured maximum session/device limit by reconnecting devices within a short interval (for example, within ~1000 seconds in MPSK scenarios). In such cases, the Access Point (AP) may not trigger a full re-authentication for the reconnecting device, allowing it to join the network without invoking Central NAC policy enforcement and thereby bypassing session limit controls.

CNX-254187

Using the same ESSID across different scopes with different authentication types is not supported.

  • Dynamic authorization will fail if one Azure tenant is used across Cloud Auth or HPE Aruba Networking Central tenants.

    Workaround: If the same Azure tenant is used in multiple identity store configurations across Classic Central and HPE Aruba Networking Central, a unique client application should be created for each configuration.

    To register a new application on Entra, see Registering CloudAuth in Entra ID Portal.

  • The MAC authentication options (Perform MAC Authentication Before 802.1X and MAC Authentication Fail-Through) for creating WLAN should not be used for wireless networks. These options are applicable only for wired networks.

  • Uninstalling the old HPE Aruba Networking Onboard app will remove the current provisioned network configuration.

  • When using Air Pass in overlay mode, ensure to scope WLAN at both the Device Group and Site levels.

    RADSEC Tunnel Instability

    An AOS-CX switch intermittently flaps the RADSEC tunnel approximately every five minutes in AOS-CX 10.15. The RADSEC server is configured using a Fully Qualified Domain Name (FQDN). The DNS server resolves this FQDN to a different IP address during each resolution cycle, which occurs every five minutes by default. As a result, the RADSEC tunnel is repeatedly disconnected and re-established.

  • On Ubuntu versions 22.04, 24.04, and 25.04, the HPE Aruba Networking Onboard app installs successfully but the UI might fail to launch due to missing Qt5 libraries.

    Workaround: Install the required dependencies using:

    sudo apt install qtbase5-dev qtchooser qttools5-dev-tools libqt5svg5-dev

  • Auto-upgrade may fail on Linux systems due to a modified and expired GPG key, causing installer validation errors.

    Workaround: Manually import the new GPG key into the client. You can download the HPE Aruba Networking Public GPG keys from this location.

  • After upgrading to HPE Aruba Networking Onboard App version 1.6, the More button appears alongside Refresh and Delete for network profiles. On initial click, the app may display an error due to the unavailable self-service portal API, which prevents fetching network credentials.

    Workaround: Click the Refresh button to retry fetching the self-service portal information. After refresh, click More again, to view the list of network credentials.

  • In Android devices, when provisioning a network profile via the HPE Aruba Networking Onboard App, the old user certificates are not replaced after SSID change and remain under user credentials even after profile deletion.

    Workaround: Manually remove old certificates from User Credentials after changing the SSID or deleting the profile to ensure proper cleanup.

  • When choosing the sys_central_nac under the MAC authentication server group, the Challenge Handshake Authentication Protocol (CHAP) method is not supported.

Resolved Issues

The following are the resolved issues in this release:

Table 2: Resolved Issues

Issue ID Description

CNX-84243

CNX-92924

Only the first authentication profile in Central NAC correctly displayed the onboarding URL. This issue occurred because same network was used with multiple authentication profiles. The fix ensures that all authentication profiles displayed the onboarding URL.

CNX-85773

If entities like roles, SSIDs or tags are deleted from the Central NAC configuration page, no error is shown on UI.

CNX-89267

The Authorization Policies page displayed the identity store used by the policy, but the policy was not updated in the Identity Management page. The fix ensures that the policies are updated in the Identity Management page.

CNX-92595

In Central NAC, users were unable to update the client secret for an identity store. The fix ensures that users are able to update the client secret.

CNX-86126

CNX-93369

In Central NAC, users were unable to create a policy with empty rules and pre-conditions. The fix ensures that users can create policies with no rules or pre-conditions.

CNX-94262

When multiple identity stores were configured for the same tenant, Central NAC displayed 'Unsupported identity store configuration' error. This issue occurred because Central NAC was unable to process webhook notifications received from any Azure tenant. The fix ensures that Central NAC is able to process webhook notifications and works as expected.

CNX-99629

A default session timeout period of 8 hours was set for all sessions in Central NAC as the session-timeout period was not supported. The fix ensures that the session timeout is supported for any given value.

CNX-97991

In Central NAC, for rules and policies, users were unable to delete all conditions and add new conditions simultaneously. The fix ensures that users are able to simultaneously delete and add conditions.

CNX-98109

 

In Central NAC an error occurred when an attribute was updated in an existing condition. The fix ensures that the attributes can be updated in an existing condition.

CNX-103088

The policy count in the authorization policies table always displayed zero. The fix ensures that the authorization policies table is updated when a new policy is added.

CNX-106658

The MAC registration table displayed only first 100 MAC addresses although the count was more. The fix ensures that infinite scrolling is available in the MAC registration table to display any number of records.

CNX-109484

In Central NAC users were unable to update the rule positions within a policy. The fix ensures that users can update the rule positions.

CNX-111310

Users were unable to delete a single condition in a rule and had to delete the entire rule. The fix ensures that users can delete a single condition in a rule.

CNX-112632

Users were unable to edit a policy without an identity store. The fix ensures that users are able edit a policy without an identity store.

CNX-180759

Port Bounce now supports AOS-S and HPE Comware switches.

CNX-211047

If an Air Pass profile is configured with an OpenRoaming provider and non-US sites, removing the OpenRoaming provider from the profile will also remove the non-US sites from the profile.

CNX-211084

Users faced severe delays to receive the Air Pass approval while creating an Air Pass profile. This issue occurred when large number of sites were selected. The fix ensures improved performance with processing time reduced to 5 minutes.

CNX-220435

The Central NAC UI failed to display error messages for invalid file type and invalid file name. This issue occurred during the bulk import of MAC address or MPSK CSV files. The fix ensures that the UI validates and displays error messages as expected.

CNX-221066

Validation failures occurred during the bulk import of MAC address MPSK CSV files. This issue occurred when users upload files with spaces in the file name. The fix ensures that file names with spaces do not result in validation failure.

CNX-199699

An incorrect SCEP URL was displayed when an existing BYOC or EAP authentication profile was updated to an UEM-based profile. The fix ensures that the correct SCEP URL is displayed.  

CNX-105101

Dynamic Authorization with BYOC resulted in disconnected user sessions. This issue occurred when a user was deleted, suspended or when user group membership was changed in an identity store. The fix ensures that Dynamic Authorization with BYOC does not disconnect a user session.

CNX-140039

Central NAC supports the Enhanced Open Network.

  • The HPE Aruba Networking Onboard App works on ARM-based chips running Windows 11 version.