Resolved Issues

The following are the resolved issues in this release:

Table 1: Resolved Issues in January 15th 2026 Release

Issue ID Description

CNX-85656

The Troubleshooter page did not allow the user to specify a source IP and interface while running a ping test. This issue occurred because source VLAN IP and VRF name, from which the test was initiated, were not supported.

The fix ensures that the source IP and interface options are supported while running the ping tests.

CNX-115374

When the user disconnected and reconnected a wired client to a gateway, the Tunneling column under Clients table displayed None, and the Tunnel ID column displayed 0. The fix ensures that the Tunnel/ Tunnel ID does not have discrepancy.

CNX-140941

After a configuration rollback or device recovery, the VLAN name DEFAULT_VLAN was being pushed to the device instead of the expected DEFAULT_VLAN_1. The fix ensures that the correct VLAN name is pushed to the device.

CNX-148713

The redirect URL field was accepting any URL string as long as it was prefixed with http:// or https:// . The fix adds regular expressions to validate URLs for basic security checks and valid IPv4 and IPv6 addresses.

CNX-161015

Users were unable to perform search in the Profiles page. This issue occurred as the search string was removed when a device was added or removed from Devices group. The fix ensures that users are able to perform search operation when a device is added or removed from the Devices group.

CNX-166179

When creating a Syslog Server profile through the UI or API, the system does not allow duplicate IP addresses, even if the categories are different. The fix ensures that the profiles are created with duplicate IP addresses for different categories.

CNX-169956

Intermittently, the client health dashboard displayed Connected/Good for a few alerts, although failures were seen for those clients. The fix ensures that client health is displayed correctly.

CNX-173102

The timezones listed in AP System. Switch System, and Gateway System profiles were inconsistent. The fix ensures that consistent timezones are listed in AP System. Switch System, and Gateway System profiles.

CNX-177971

On the Alerts page, multiple wireless client deny-listed alerts were generated. However, some of these alerts did not auto-clear as expected, even if no new alerts are triggered for over an hour. The fix ensures that alerts are auto-cleared as expected.

CNX-182621

CNX-182319

CNX-210458

Client Trends API displayed an empty response for invalid inputs. The invalid input combinations were expected to return an error response with a relevant message field in the response payload. However, the behavior returned a 200 status code with an empty response body instead. The fix ensured that the correct response message was displayed in case of any error.

CNX-185818

The Link-Node-View topology view was not horizontally symmetrical. The fix ensures that the Link-Node-View topology view is horizontally symmetrical.

CNX-187240

When the destination value of an IP class entry was updated, the patch response was an error and the configuration did not update. The fix ensures that the configuration is successful when the destination value of an IP class entry is updated.

CNX-188851

A few APs running firmware versions prior to 10.7.2.0 displayed a constant 100% retry rate for the Retries metric in the Frames graph of the expanded Connectivity Performance card. The fix ensures that Retries metric now displays the correct retry rate data.

CNX-190226

When navigating to the Configuration dashboard for a site, the Configuration Health status for the switch temporarily displayed as Out of Sync, even though the switch was connected. This issue occurred because of the following reasons:

  • Deletion of the global L2 VLAN failed, or

  • After unassigning or deletion of the VLAN at the global scope, the VLAN was not removed from the switch

The fix ensures that the VLAN is successfully removed from the global scope and the changes are synchronized with the switch.

CNX-190276

The References tab on an Alias profile showed referring profiles only at the scope where the alias was directly mapped, and appeared empty in child scopes. The fix ensures that when viewing the References tab for an alias (or any referred configuration profile) at any scope in the hierarchy, all profiles using that alias/ referred configuration are displayed if they are effective at the scope.

CNX-191288

Deleting a WLAN SSID profile using the DELETE /network-config/v1alpha1/wlan-ssids/{ssid} API did not remove the associated system-generated profiles. The fix ensures that the system displays a validation error to delete the overlay WLAN first and then the WLAN SSID.

CNX-195958

A multi-select of sites was not possible when sites were searched in the side panel; only the latest searched site was selected. The fix ensures that whatever sites are searched and selected show up in the multi-site selection list.

CNX-197934

When the user modified VLAN characteristics in Device > VLANs & Networks > VLAN (Mobility Gateway), the gateway entered a CONFIG FAILURE state. This issue occurred because the uplink VLAN Admin State was not learned as part of the gateway onboarding. This issue was resolved by manually enabling the Admin State for the particular uplink VLAN.

CNX-197993

When an L3 VLAN IP address was configured as a VRRP IP in a VRRP profile, the system did not perform the required validation check. As a result, the configuration was accepted and was pushed to the device without any validation error. The fix ensures that the system performs the required validation check when an L3 VLAN IP address is configured as a VRRP IP in a VRRP profile.

CNX-198011

The validation error was missing when an L3 VLAN IP, an alias with a static IP mapped to an L3 VLAN was set as the Default Gateway IP in the Default Gateway Profile. Instead of displaying the validation error, the system configured and pushed the Default Gateway Profile to the device. This fix ensures that the validation error is now displayed when the L3 VLAN IP, the alias with static IP mapped to the L3 VLAN, is set as the Default Gateway IP in the Default Gateway Profile.

CNX-200184

In HPE Aruba Networking Central, stale nas-id entries in the switch were causing configuration restore failures after deletion of AAA server groups under Library > Security > Authentication Server Group. This issue occurred because the nas-id entries were not properly cleared during deletion and newly created server groups were incorrectly associated with the outdated stale entries. The fix ensures that nas-id entries are properly cleared when server groups are deleted, preventing configuration restore failures and ensuring proper configuration behavior.

CNX-200692

For AOS-S switches, PIM configurations were not supported for firmware versions below 16.11.0028. The fix ensures that PIM configurations work for all firmware versions.

CNX-200814

The UXI Status showed 100% good status (Green) whereas, the Application Health showed 100% fair status (Orange). The fix ensures that both the UXI Status and Application Health are synchronized.

CNX-200856

In HPE Aruba Networking Central, when the ISL is configured as a LAG interface via the VSX intent service, the payload frequently omits essential LAG interface details in the port-channel-interface section. This results in incomplete CLI commands for trunk group creation, leading to missing port assignments and corrupted configurations on PVOS platforms. While CX switches accept such configurations by default, PVOS systems do not handle them properly, causing invalid setups. The fix involves updating the VSX intent service to check for the presence and consistency of LAG interface configuration with ISL settings. If inconsistencies or missing details are detected, the intent service now adds an audit trail, logs an error, and halts further processing to avoid generating invalid configurations.

CNX-201412

MSP-tenant tokens consistently failed with a 401 Invalid Access Token error, preventing API Gateway (APIGW) statistics from being displayed in the MSP workspace dashboard. The fix ensures that the API Gateway statistics are displayed correctly on the MSP workspace dashboard.

CNX-201678

In Device Scope > Interfaces > Port Profile, the IP client-tracker option, which is not supported for PVOS switches in the AOS-S persona, was incorrectly available under Telemetry section. The fix ensures that Telemetry section is removed from Port Profile along with the IP client-tracker and IP Tracking Client Limit options.

CNX-201869

In the Network Overview > Sites card > Site name > Topology page, parent devices were not displayed in the connection path. This lead to discrepancies between the device connections shown in the link Topology API and the Connectivity card. This issue specifically occurs in the following scenarios:

  • When a Mobility Gateway is part of the connection path.

  • When an unmanaged device exists between two managed devices with assigned personas.

The fix ensures that parent devices are displayed in the connection path.

CNX-202066

Setting the Global > System > Switch System > Create Profile > Dot1X Radius Auth Method to LOCAL through the UI triggered an error message indicating: the authentication method does not support the server group parameter or corrupted configuration file. This issue occurred because the LOCAL authentication method did not allow specifying a server group parameter, leading to a configuration failure and preventing successful deployment. The fix ensures successful configuration and deployment.

CNX-202127

On the CNX Network Overview > Site > Health Metrics page, when viewing client data over a 7-day or longer period in either the Site or Device context, the client list in the last sample under the distribution chart appeared empty. This issue occurred in both contexts and affected data visibility for extended time ranges. The fix ensures that the system works as expected.

CNX-202602

In Scope Management, selected items across pages were not preserved when editing site collections or device groups with many sites, 150–200, using paginated dropdowns. This caused the view selected list to show fewer items than intended, resulting in a poor user experience. The fix ensures that selections are now retained across all pages in the updated UI.

CNX-202603

CNX-202602

When a user attempted to update a site collection that had 50 or more associated sites, not all sites were displayed when the user scrolled down the Sites drop-down list or used the search function. The fix ensures that the drop-down list and search functionality to all associated sites are consistently displayed during updates.

CNX-202790

When setting the certificate on the AP device through HPE Aruba Networking Central, the certificate was only uploaded to the HPE Aruba Networking Central Certificate Manager, and the AP did not receive the configuration. This occurred because the system required the certificate to exist on both HPE Aruba Networking Central and Classic Central under the same name for proper AP certificate setup. The fix ensures the configuration process correctly manages certificates uploaded to both HPE Aruba Networking Central and Classic Central.

CNX-203271

On the Audit Trail page, logs were not repopulated in the table when the search filter was cleared. This issue occurred because the scope reference of the table filter did not get updated. The issue was resolved by refreshing the browser to repopulate the table.

CNX-203339

When a VLAN was created at the site level, and then added to a VSX profile, the WebUI did not allow device level L3 VLAN updates. This issue occurred as the VLANs that were created at the site scope and added to the VSX profiles triggered device level overrides for L3 VLANs without notifying the WebUI service. VLAN configurations, through the VSX Profile, created a layer 3 configuration at the device level if no override was created prior to executing the VSX workflow. If the VLAN was scoped later at the device level, an error was displayed. The fix ensures that that the VLAN was successfully configured.

CNX-203629

When custom SLA profiles are updated by updating the Differentiated Services Code Point (DSCP) values on the Dynamic Application Prioritization (DAP) UI, all SLA parameters apart from DSCP values are removed from the custom SLA profile. The fix ensures that existing parameters in the SLA profile are retained when updating the custom SLA profile.

CNX-203847

The API endpoint /network-services/v1alpha1/sitemaps/{site-id}/floors/{floor-id}/ap-ranging-scans/start exceeded the maximum allowed nesting level of 2 and was not compliant with HPE naming standards. The endpoint is now simplified by removing deep nesting. The new format is /network-services/v1alpha1/ap-ranging-scans?site-id={site-id}&floor-id={floor-id}.

CNX-204320

Setting DSCP 46 for voice or 34 for video using the HPE Aruba Networking Central WebUI on any SLA profile (custom or default) will remove the legacy UCC CLI entries from the running configuration on versions greater than ArubaOS 10.7.2. This fix ensures DSCP settings are applied consistently via the HPE Aruba Networking Central and prevents redundant legacy UCC CLI entries from appearing in the running configuration.

CNX-204516

CNX-177971

On the Alerts page, the system generated multiple wireless client deny-listed alerts. However, some of these alerts failed to auto-clear as expected, even when no new alerts had been triggered for over an hour. The fix ensures that the system clears the alerts successfully.

CNX-204589

When overriding an existing authentication server profile with the Save as a local profile option enabled, the system did not display the expected warning message: Modification of parameter auth-server-address is not supported on Switch. This caused the unintended creation of a ghost server entry with the previous IP address in the switch configuration. This issue was resolved by deleting the existing authentication server profile before creating a new one with the required changes to key parameters such as auth-server-address.

CNX-205089

There was a mismatch of values displayed on the WebUI for traffic priority and the values applied on APs running versions earlier than 10.7.2. This issue occurred on the UCC page. The audio mapped to the video conference profile showed a different on the WebUI, but a lower value was applied, and video mapped to the voice profile displayed a higher value, but a different value was applied. The fix ensures that the WebUI displays the correct values for older device versions and applies matching values to the devices based on the selected profile.

CNX-205184

The health metrics in a site context were not displayed as per threshold on the Health Metrics page. The fix ensures that the health metrics are displayed as per the threshold.

CNX-205718

When 6 GHz is enabled in the New HPE Aruba Networking Central WLAN SSID profile WebUI, the Key Management control only allowed WPA3-Personal for Personal mode and blocked other key-management options. Unlike Classic Central, the WebUI did not prompt the user to select WPA3 when an incompatible key management method was chosen.

The fix ensures that the WebUI allows users only to choose a supported key-management method when 6 GHz is selected.

CNX-208177

Certificate usage profiles failed to apply to Access Points running AOS-10 on HPE Aruba Networking Central. The fix ensures that certificate usage profiles are applied to all target devices.

CNX-208260

During the initial onboarding of access points to HPE Aruba Networking Central, an application mismatch occurred between the UI and the access points when applications were mapped to global custom Service Level Agreements (SLAs). This is expected behavior because Foundation licenses do not support pushing custom SLAs to access points.

CNX-208410

During the onboarding of switches that are part of a VSF stack, any existing VSF renumber or VSF force auto-join configuration present in the running configuration is discarded when the switches are onboarded to HPE Aruba Networking Central. This is expected behavior and occurs because, by default, the first member in the stack becomes the conductor, the second member becomes the standby conductor, and all remaining switches are assigned the member role.

CNX-208793

HPE Aruba Networking Centralallowed foundation license users to map default applications to custom SLAs and edit DSCP values, but the AP continued to apply the default SLA/DSCP settings, causing a mismatch between the UI and AP. The fix ensures that a clear message is displayed that custom SLA/DSCP changes only apply to advanced license users.

CNX-209688

CNX-210673

The time picker drop-down on the Audit Trail UI displays extra characters (##) in the options list. The fix ensures that the time option displays the proper format without additional symbols.

CNX-210571

Neighbors NBAPI failed when queried for a tpd device without a site-id. The fix ensures that HPE Aruba Networking Central now supports neighbors NBAPI query for tpd devices.

CNX-211768

The support connection file upload failed in version 3.0.2.0. The issue occurred in both the CLI and WebUI when creating the support connection. It was caused by changes in the minio library. The fix ensures that the support connection file upload is successful.