Resolved Issues

The following are the resolved issues in this release:

Table 1: Resolved Issues in February 12th 2026 Release

Issue ID Description

CNX-59189

When a client was placed into a special role after authentication failures, DHCP and DNS failures were not shown in the CNX client experience because the system reported only a single, higher-priority L2 authentication failure and did not account for role-specific L3 and L4 health. The fix ensures that clients assigned to special roles correctly display their DHCP and DNS health status.

CNX-98998

Device inventory APIs did not support filter operations on deviceGroupName and SiteName. The fix ensures that these filter operations are now fully supported.

CNX-151651

In the Configuration Overview page under Roles & Policies > Security Policies > Network Policies, the Move Down option was not displayed until the screen or the browser was refreshed. The fix ensures that the Move Down option is available by default.

CNX-171090

Devices became unreachable over SSH and Telnet when a static routing profile containing IPv6 routes and an IPv4 default gateway was deleted via the UI. The issue occurred because the deletion also removed the default gateway, leaving no valid route for remote access. The fix prevents unintended removal of the default gateway when deleting a static routing profile.

CNX-174105

Global Mobility AP user-admin profile overrode site-level profiles. If the global default (initially empty) was set to the same username as a site profile, APs accepted the global password instead of site credentials, allowing a single global change to affect all sites and preventing site admins from tracing or restoring intended credentials. The fix prevents global user-admin profile changes from overriding site-specific AP credentials.

CNX-178386

The configuration state of the switch is stuck at Init due to missing VSF link configuration. The audit log misreported the cause of issue to be a configuration import failure. The fix ensures that the audit log reports the cause of the issue to be the missing VSF link configuration.

CNX-183922

After onboarding a device to a Site and a Group, when users create an NTP server profile at the Group scope and try to assign an alias, it failed with a validation error. The fix ensures that the alias is successfully created.

CNX-187876

Users were unable to add ACL rules under Site > Roles & Policies > Create Policy. This limitation prevented the users from creating and managing ACL configurations via the UI.

The fix ensures that ACL rules can be added in the UI.

CNX-193722

A stand-alone interface profile update appeared to succeed but failed to push VLAN trunk/access configuration to the switch interface; the device API showed updated uplink/downlink ports but the switch interface configuration and UI were not updated. The fix ensures that stand-alone interface profile update succeeds.

CNX-197213

Creating more than one passpoint location configuration profile for a Site caused the following error: Configuration changes are blocked for the device(s): [<Device ID>] due to exceeding capacity limitations for the following paths: ('/aruba-radius-location:radius-location/profile'), limit= ('Maximum Capacity for capacity-global 1 for/aruba-radius-location:radius-location/profile',) The fix ensures that more than one passpoint location cannot be created.

CNX-197878

The GRE protocol 0 is reserved for special use error was displayed when configuring the GRE tunnel on an AP. This issue occurred when the protocol was set to 0, causing the AP to reject the command with an execution error. The fix ensures that the AP accepts the GRE protocol value and does not display the execution error.

CNX-200184

In HPE Aruba Networking Central, stale nas-id entries in the switch were causing configuration restore failures after deletion of AAA server groups under Library > Security > Authentication Server Group. This issue occurred because the nas-id entries were not properly cleared during deletion and newly created server groups were incorrectly associated with the outdated stale entries. The fix ensures that nas-id entries are properly cleared when server groups are deleted, preventing configuration restore failures and ensuring proper configuration behavior.

CNX-200725

When a DHCP pool profile was assigned to the Device scope level, the profile was not removed from the DDNS server configuration at the Global scope level when a user deleted the profile. The fix ensures the profile is removed from the DDNS server configuration as expected.

CNX-201439

The VLAN mismatch alerts were generated incorrectly after the MTU values were changed. The issue occurred on the Alerts page because stale interface status records were present, which led to discrepancies when MTU values changed and triggered alerts. The issue was fixed by clearing stale interface status records and updating the Alerts page logic to refresh and validate interface status after MTU changes, preventing false alerts.

CNX-202513

Monitored devices running AOS-S.16.11.0018 incorrectly report their health status on the Network and the Health Metrics page. The fix ensures that the health status is accurately displayed on the UI.

CNX-202614

The 2530 switch failed to encrypt the password although encrypt credentials are enabled. This issue occurred when users tried to configure a MAC authentication profile using the CLI command, aaa port-access mac-based password. The fix ensures that the password appears encrypted.

CNX-202930

When a source interface profile with loopback support is configured for AOS-S switches by navigating to Configuration > System > Source Interface, the switch became non-responsive. This issue occurred when the loopback support interface ID assigned was greater than 8. The fix ensures that the switch is configured correctly and works as expected.

CNX-203247

Deleting an existing overlay configuration failed when multiple WLAN SSIDs were mapped to the same captive portal profile and assigned the same pre-authentication role. The system displayed the error message Delete for unexpected req_xpath="/aruba-role:roles/role[name='Pre-Authentication Role']/session-parameters . This issue was observed when attempting to delete the second overlay WLAN SSID, because the captive portal profile was disassociated from the Pre-Authentication Role after the first overlay WLAN SSID was deleted. The fix ensures that the mapping between the captive portal profile and the pre-authentication role is not removed until all associated overlay WLAN SSIDs are deleted.

Note:

If an existing setup is experiencing this issue, the captive portal details configured in the pre-authentication role that is referenced by the WLAN SSIDs must be added before attempting to delete the WLAN SSID.

CNX-204764

When a role was updated from a VLAN ID to a named VLAN through the API, the bandwidth contract configuration was removed from the gateway. The fix ensures that the bandwidth contract configuration is available in the gateway.

CNX-207864

In the Configuration Health device‑specific error page, the configuration profile Name filed is displayed as Unknown. The fix ensures that the profile name is fetched from the assigned configuration profile and displayed accurately.

CNX-209656

When an sw‑port‑profile was applied, the IPv4 address was removed, causing the device to go out of sync while configuring IPv4 relay through the port profile. The fix introduces proper IPv4 relay handling with accurate validation, ensuring that valid configurations are preserved.

CNX-210972

When a policy rule was created with address-family IPv6 and role option type ADDRESS_LOCAL, the configuration is accepted; however, internally, it's still mapped to IPv4 address, resulting in the configuration not being pushed to the controller. The fix ensures that policy rules cannot be created with address-family IPv6 and role option type ADDRESS_LOCAL.

CNX-210987

Client details were not displayed when navigating from the Global View>Top N clients hyperlink. The fix ensures that navigation includes the required site_id in the response contract so the UI displays client details correctly.

CNX-211275

In an External Tunnel Captive Portal SSID deployment using CPPM VSA, the Gateway did not apply the pre-auth captive role returned by CPPM and instead placed clients into the post-authentication default role, impacting the intended captive portal pre-auth flow. This issue occurred because the user-role scope was limited only to the Gateway, and the role was not automatically enforced on the Gateway (or other device types such as APs or switches) until an explicit firewall policy was created, the user-role was associated to that policy, and the policy was scoped to the intended device type—which was expected Day-1 behavior across device categories. The issue was resolved by creating the required explicit firewall policies or rules for the pre-auth roles, associating the roles to the firewall policy, and scoping the policy correctly, after which the Gateway successfully applied the pre-auth role for unknown clients and transitioned them to the post-auth role after captive portal acknowledgment.

CNX-211280

Cluster setup failed due to an incorrect NTP error that appeared even after Secure NTP was turned off. The issue occurred on the NTP Configuration page of cluster management. The fix ensures that only the appropriate NTP details based on the final selection are passed allowing the setup to complete successfully.

CNX-211510

When configuring webhooks in the API Gateway > Webhooks section with an invalid API key or token, the system displays an incorrect error message Invalid target URL instead of displaying Invalid API key or Invalid token. The fix ensures that an appropriate error message is displayed.

CNX-211935

When upgraded from 3.0.1.0 to 3.0.2.0 or later versions, version synchronization failed when new nodes were added due to a missing package name in the sync metadata. When this issue occurred, the HPE Networking Technical Assistance Center (TAC) was contacted through the HPE Networking Support Portal for assistance. The fix ensures successful version synchronization when new nodes are introduced.

CNX-211947

When users queried Give list of 802.11r capable clients in Networking Copilot, the Clients table incorrectly displayed a summary stating no 802.11r capable clients were found, even though 802.11r capable clients were actually present in the table. The fix ensures that the table summary text is corrected to accurately reflect the presence of 802.11r clients.

CNX-211980

In the HPE Aruba Networking Central, the STP anomaly recommender displayed an incorrect hyperlink for stacked switches. The fix ensures that the correct hyperlink is generated for the switch stack.

CNX-212676

WLAN overlay profiles could not be assigned to Device Groups if the associated server group contained authentication server aliases. The fix allows successful assignment when aliases are configured correctly.

CNX-212801

When creating user profiles at different scopes (Global, Site, and Device), switching to the Device scope for APs displayed all profiles instead of only those applicable to that scope. The fix ensures that the Device scope now correctly displays only the user profiles applicable to it.

CNX-212989

The scope management Sites table did not follow the expected default sorting behavior for newly created sites, scope containers, and device groups. New entries appeared at the top of the table instead of being appended to the end. Update and delete workflows functioned correctly, and temporarily navigating away from and back to the table restored the proper order. The fix ensures that newly created entries now follow the correct sorting algorithm and appear in the expected position.

CNX-213694

The webhook table displayed the Times Triggered, Last Triggered By, and Last Triggered On columns even though the webhook statistics was not implemented. The fix ensures that the columns are not visible until the implementation is complete.

CNX-214745

In the Gateway device context, the Top Clients usage list displayed incorrect client entries. This issue occurred because the site-level clients were being shown in Top Clients usage list as if they belonged to the Gateway device context. The fix ensures that the Top Clients usage list displays correct client entries for gateway devices.