Known Issues

The following are the known issues:

Table 1: Known Issues

Issue ID

Description

CNX-141247

When rebooting a switch, if the management module gets stuck in Service OS and its state is reported as Present, the Management Module alert is not raised in the WebUI.

CNX-17280

The search functionality does not work for all fields in the Ports table for a switch.

CNX-18981

The Devices table does not auto-refresh when a user navigates to the unified devices page.

CNX-20753

The HPE Aruba Networking Central WebUI incorrectly allows the modification of an alias type when the alias is referenced in a policy rule.

CNX-21827

When users create or delete policies, the number of items above the Policies table shows an incorrect value.

CNX-22046

The HPE Aruba Networking Central WebUI incorrectly shows the Assign button when unassigning roles from scope. When a user clicks the Assign button, the Roles are assigned successfully pop-up message is displayed.

CNX-71991

CNX-73769

The expanded view of the Connectivity card of an AP displays the Connection data not available message instead of Connection data not supported. This issue is seen for APs that run unsupported firmware version that is lesser than ArubaOS 8.11 and ArubaOS 10.5.

CNX-39215

The Connectivity Performance card shows incorrect usage value. This issue occurs when deploying VSF stack members to a site.

CNX-39348

The Clients table and graph displays only one named VLAN although multiple VLANs are assigned to a client.

CNX-42167

The Wired Interface card in the HPE Aruba Networking Central WebUI shows two rows for the 8325 interface instead of the actual three-row physical switch.

CNX-42704

When using the timeline widget to go back in time and view a switch-disconnect alert, the device count in the Alerts context and the Network context do not match.

CNX-45198

In the sites dashboard page, the site context and the Health card are displayed with a delay. The delay occurs when some graphical APIs take more time than usual to load.

CNX-45328

A user cannot use MultiEdit to configure special roles, device profiles, MAC groups, UBT or app visibility in HPE Aruba Networking Central WebUI.

CNX-46391

The bell, help, and user icons at the top of the HPE Aruba Networking Central WebUI are unresponsive.

CNX-46894

The Timeline widget does not display alert bars for different lineages.

CNX-47462

The HPE Aruba Networking Central WebUI incorrectly accepts wrong subnet when creating or updating a network alias.

CNX-47580

The Link Speed Mismatch alert is not generated when the configured speed and interface speed are mismatched.

CNX-48360

When users navigated to the Alerts page, the Alerts table do not refresh. The table displays outdated data until users manually refresh it.

CNX-48988

The site Usage graph shows spikes or valleys for the client counts at the site level.

CNX-49263

The Network context on the Alerts page does not show all devices that are rejected by the MAC authentication server.

CNX-49445

A client that successfully completed MAC authentication is shown as a failed client in the Clients table. This issue occurs when the client performs a successful MAC authentication and an unsuccessful 802.1X authentication.

CNX-51083

Deleting the site does not delete the site configurations applied to the devices that were part of the deleted site.

CNX-52239

In the Gateway Connectivity card, the uplinks are not completely visible if there are four uplinks.

CNX-52912

While using Firefox browser, users cannot drag and drop the sunburst by holding the mouse button. The sunburst drag is only possible when the mouse button is released, and it can be dropped at the desired position by clicking the mouse again.

CNX-53450

The expanded view of the Connectivity card for gateways displays the incorrect uplink image.

CNX-53625

While dragging and dropping the topology sunburst, multiple sunburst images appear.

CNX-55673

When a user creates a duplicate policy rule within the same policy, the HPE Aruba Networking Central WebUI displays both the rules in the Role-Based Policies table instead of replacing the original rule.

CNX-57450

On the expanded Wired Interfaces card, unmanaged device (gateway) neighbor information such as neighbor role and neighbor classification is not shown.

CNX-57502

The affected clients are unavailable on the Alerts > Clients page for the 802.1X Authentication Server Timeout and 802.1X Authentication Rejected by Server alerts.

CNX-57665

In the Connectivity card, Connection Steps does not display separate timestamp for client association and inconsistently, displays DNS connection timestamp.

CNX-58393

In the alerts List page, the association alerts form a new group or lineage whenever there is a change in the cluster category.

CNX-58447

The Port Summary field in the expanded Wired Interface card of a gateway displays the uplinks port count, but the uplinks filter option is unavailable in the filter list of the Ports Table.

CNX-58885

The Temperature chart of the Hardware expanded card for a switch displays incorrect temperature values.

CNX-64527

Reference mapping is incorrect for mobility and VPNC gateways when the device group configuration is overridden by device configuration. Reference mapping for branch gateway to branch gateway group is fine, however reference mapping for mobility gateway to mobility gateway group and VPNC to VPNC group is incorrect; the mapping shows from mobility gateway to branch gateway group and VPNC to branch gateway group.

CNX-65307

The Clone Reports page displays the Next button instead of Save when editing a parameter.

CNX-67079

HPE Aruba Networking Central incorrectly allows configuration of mutually exclusive features such as dot1x/mac-auth and port-security on the same interface of some AOS-CX switches.

CNX-67314

CNX-88615

CNX-99514

In HPE Aruba Networking Central, PVLAN primary and secondary VLANs, along with secondary ports, exceed the maximum capacity limit. When the maximum capacity limit is exceeded, the excess VLANs and ports are shut down by the switch daemon. This affects the traffic for clients that are already connected to the excess VLANs and ports.

Workaround: Remove the excess VLANs. The exact details of the VLANs that are shut down due to the capacity violation can be viewed using the show private-vlan inconsistency CLI command or from the switch event logs.

CNX-67321

The center component of the Topology sunburst is not aligned correctly.

CNX-67437

When a group configuration with a shared payload is pushed to a device in a HPE Aruba Networking Central group, the push fails and the configuration status of the device is displayed as Not in sync (Internal error).

Workaround: Do not configure duplicate VLANs when they are passed as a range, as this causes the range to be set to OVSDB , which results in the internal server error.

CNX-67868

When the interface health of AOS-S switch is Poor due to port flap and the client gets disconnected or port is shutdown, the health recovery takes up to 15 minutes.

CNX-69100

When a CX switch is added to a CNX group, a Yang dependency is observed to update and delete port-access security violation action NOTIFY when action SHUTDOWN is configured. This occurs because recovery-timer is dependent on shutdown-recovery-enable, which is further dependent on setting action to SHUTDOWN.

CNX-70475

When you create a captive portal and assign it to a group with two AP-515 on the same site, APs receive the configuration correctly. But, when you change the assignment by setting the profile to global, one AP deletes the captive portal profile while the other AP keeps the configuration.

CNX-71523

In the PDF reports, a gray border appears around the KPI widgets when the emailed PDF report is opened without a PDF application.

CNX-72012

The Connectivity card on the client dashboard page does not display the gateway node in the overlay client datapath. This issue occurs when there is no direct connection between the Access Point and the Gateway or a direct connection between the Access Point, Switch, and then the Gateway.

CNX-73781

In the unified clients page, the connection steps in the Connectivity card are updated with a delay of 20 minutes during the DHCP timeout failure.

CNX-74260

Users are unable to delete an AP system profile from the Devices > Profile Management > System card > System Information table. This issue is seen when a globally created profile is edited at the device level.

Workaround: Refresh the web page to see the delete icon.

CNX-74475

Channel and power leaves do not take effect with MUST statement in YANG define.

CNX-74507

When the overlay tunnel is switched between gateways in cluster mode, the tunnel health status shows as Poor with old gateway details, though the tunnel status is Up with the new gateway.

CNX-76291

If a configuration is mapped to more than one device function and a scope in the library, HPE Aruba Networking Central shows only single device function at a specific scope.

CNX-77966

The Wired Interfaces card of an AOS-CX switch does not display the list of VLANs when multiple extended access VLANs are applied for the access ports of the switch.

CNX-78202

The Topology sunburst displays thin dotted lines around the center device when you navigate to VSX children.

CNX-79102

The auth-server-global-config API has a timeout which can be used to set the timeout for both RADIUS and RadSec at a global level. When the enable_RadSec is set to true, the RadSec timeout is configured and if it is set to false, the RADIUS timeout is configured. Therefore, to configure radius-server timeout and radius server TLS timeout, configure different authentication profiles.

CNX-79545

The Connectivity card always displays the interface edge health status of managed and unmanaged AP devices in green (good health).

CNX-79612

The Connectivity card displays the same image to indicate an unmanaged device in the connection path for all device types.

CNX-80608

Users cannot delete a role in HPE Aruba Networking Central if the SSIDs were created in 3.x compatible groups in Classic Central.

Workaround: To delete the role in HPE Aruba Networking Central, complete the following steps:

  1. GET https://apigw-<URL>.cloud.hpe.com/cnxconfig/v1/policies/sys_allow_all

  2. Append the position value at the end of the DELETE call as given below:

    DELETE https://apigw-<URL>.cloud.hpe.com/cnxconfig/v1/policies/sys_allow_all/security-policy/policy-rule/1

  3. Delete the role from the HPE Aruba Networking Central WebUI.

    For more information, see Deleting a Role.

CNX-80657

Dependencies in the profile do not map automatically when the SSID scope is reduced.

CNX-81131

VSX pair of devices appear apart on the topology sunburst, if one of the two devices has multiple sub-devices.

CNX-83044

The hostname of a device is incorrectly displayed in the Devices table after it is updated in the Profiles > Library > System > System Information page.

CNX-84012

In AP System profile, the Static Channel drop-down list for the non-Preferred Scan Channels (PSC) 6 GHz radio band fails to display dynamic options based on the selected county code.

CNX-84368

In Reports > Create Report > Preference > Additional Filters > Include Devices section, the search option does not appear as expected.

CNX-85086

During switch port flaps, there is a delay in updating the health status in the Experience card for a client.

CNX-85747

Onboarding an AOS-CX switch fails. This issue occurs when the server URL is not configured in the EST profile for the AOS-CX switch.

CNX-86033

Users are unable to remove some device configurations using the WebUI or API. This issue occurs when the configuration has leaf references to another API.

Workaround: Ensure that there are no leaf references to another API, before removing configurations using the WebUI or API.

CNX-87063

A site is not listed in the Sites card of the Network Overview page though it is listed on the Scope Management page.

CNX-87491

The Health card displays incorrect reason for the health status of sites. It shows the reason as 0 devices are offline though one or more devices are offline.

CNX-87541

Pushing a new secondary IP address to an applicable interface replaces all the existing secondary IP addresses instead of adding the new address to the interface.

CNX-88144

Under the Assign Profile side panel for Named VLANs in HPE Aruba Networking Central, users are unable to assign scope to devices that include different device functions. This issue occurs because the scope assignment workflow assigns all selected scopes to all device functions, instead of allowing specific mappings.

CNX-90016

When a device is unassigned from a site and a group, a delay is observed in updating the Devices table.

CNX-90375

The Scope Management page displays device details even after a device is unassigned from the Central application.

CNX-90913

The Experience card wrongly displays the Failed, Unknown, last seen 30 minutes ago message for a client on Unified Client List.

CNX-90920

When a device is unassigned from Central, that is configured as the Service Manager (SM) on HPE GreenLake, the device is not displayed in the Device Inventory table or as part of Scope Management in the HPE Aruba Networking Central WebUI. However, it continues to be part of Site/Device Groups monitoring in Classic Central in its offline state.

Workaround: To synchronize HPE Aruba Networking Central with Classic Central, assign the device back to the Service Manager (SM) on HPE GreenLake. After that, un-assign the device from the Site/Device Groups and then re-assign it to any Site/Device Groups in Classic Central.

CNX-91324

In HPE Aruba Networking Central, when you navigate to device context page under Scope Management, and click the Device tab, search for device deployment type and partial string for device groups and device model does not display any data.

CNX-91543

When a read-only user performs any admin operation task, like deploying access points manually, or removing any access point from the floorplan, the error banner message is displayed incorrectly.

CNX-91738

The Gateway dashboard page displays the status of the VLAN tunnels as Up when the destination IP address is 0.0.0.0.

CNX-92491

When a gateway persona is added or removed from an existing gateway at a site. The change is not reflecting in the topology graph.

CNX-92715

The Downtime Details widget in Device Uptime report displays a 25 to 30-minute difference in downtime duration.

CNX-92721

The widget description shows the following issues in the resource utilization report:

  • Static threshold details are not visible

  • Threshold value is not updated

CNX-93397

The alert details is inconsistent between NOC Alert Card and Alert Expanded card.

CNX-93863

When a device is added to a new site in Classic Central, a delay is observed in updating the Devices table in the Configuration page in HPE Aruba Networking Central.

CNX-94993

Creating a VLAN profile in HPE Aruba Networking Central under Configuration> Profile Management > VLANs & Networks > VLAN does not display the option to create a New Network ACL in the Inbound and Outbound Network Access List drop-down lists. This issue occurs when configuring Policy for Switch Specific Parameters.

CNX-94972

Link-local next hop cannot be used in HPE Aruba Networking Central as source interface option is currently unavailable in the WebUI.

CNX-96452

There is a mismatch in the value for number of sites where APs disconnected. This occurs in the expanded view of Sites Reporting AP Disconnected card and Alerts card on the Overview page.

CNX-97918

An error message Unsatisfied range - value '31' is out of the allowed range is displayed when the value for poe-max-power parameter exceeds 30. This issue arises on specific AOS-S device profiles because the range limits are set from 1 to 30. HPE Aruba Networking Centralenforces stricter validations to prevent erroneous configurations.

Workaround: Retry the power setting for the AOS-S device by specifying a value within the defined range of 1 to 30.

CNX-98260

User is unable to configure Radsec client certificate and AP1X client certificate to AP.

CNX-98636

User is unable to click some segments of the topology sunburst view.

CNX-98713

The sorting functionality is not working for the columns displayed on the expanded LAN tunnels card for an AP.

CNX-99705

Search is not supported for the device Type column in the scope management Devices table. However, you can filter the list by device Type.

CNX-100536

When a user tries to configure PoE on some unsupported ports, a required error message is not displayed.

CNX-100886

When an AP hostname is edited in HPE Aruba Networking Central, the Devices table does not show the edited hostname.

CNX-101269

There is no option to upload certificates through the HPE Aruba Networking Central WebUI.

Workaround: Users can upload certificates through the Classic Central WebUI.

CNX-103513

The Hardware card of the switch displays only the number of the fan while reporting errors. It does not display the name of the fan.

CNX-106423

The status of a wired client connected to a gateway is displayed as online in the client dashboard page, even when the gateway is offline.

CNX-106500

Enabling routing on the Ethernet interface of an onboarded device fails when a debugging configuration is already present on the interface. This causes the device to go into a configuration conflict state.

Workaround: Reset all configurations on the device interface and apply a new routing configuration.

CNX-106607

Deleting any NTP server profile disables NTP service on a switch, even when multiple NTP server profiles are set up for the switch.

CNX-108040

Creating a Fault Monitor profile using API with a combination of Notify and Notify and Disable actions for different Fault Types, does not reflect the same configuration in the HPE Aruba Networking Central WebUI.

CNX-108273

The expanded view of Capacity card on the Gateway cluster dashboard does not display the role and hostname of the members associated with cluster, and the legends are not displayed below the chart.

CNX-108343

When a gateway with a wired client connected is moved from one site to another, only the gateway is successfully moved. The wired client continues to appear in the old site for more than 30 minutes instead of being updated to the new site.

CNX-108761

In Client List > Client Details > Connectivity Datapath, tunnel arc is missing in the connectivity datapath for Port-Based Tunnel (PBT) clients. This issue occurs because the GRE tunnel information is not available from the Gateway.

CNX-110196

At site context, when you expand the Connectivity card for any wireless or wired client to view the connection details, under Connection Steps the Completed In value for Association time does not display any value.

CNX-110553

Updates to an SSID profile are synchronized partially to the APs.

CNX-110955

CNX-111020

CNX-111499

CNX-111501

The DNS alerts displayed all the impacted URLs in the impacted URL list instead of top five URLs.

CNX-111912

Users are unable to delete the IPv6 addresses under the Routed Only Port (ROP) interface on an AOS-CX switch. This issue occurs when the IPv6 address is configured with the Extended Unique Identifier-64 (EWebUI) option.

CNX-111987

The Network > Devices page in the List view displays the configuration status of a few switches in Conflict state. This issue occurs when you apply lag on a AOS-CX switch interface at interface level.

CNX-112353

In HPE Aruba Networking Central, when an ospfv2 configuration is applied on the L2 interface of a switch after successfully pushing an ospfv2 configuration via API, the switch goes into a conflict state and prevents any additional configuration push.

CNX-113802

Roles and Policy configuration fails through API. This issue occurs if there is a case mismatch in the API code.

CNX-114037

The Action card on the Sites > Alerts page does not display any information about underlay SSID, when both overlay and underlay SSIDs are affected in the same site.

CNX-114041

The Action card did not display any information about the Bridge type SSID, but the clients generate alerts for Overlay and Underlay type SSIDs in the same site.

CNX-114044

The Action card on the Sites > Alerts page does not display underlay SSID details. This issue occurs when alerts are generated for overlay and underlay SSIDs in a cluster in the same site.

CNX-114875

An error message is displayed when a profile is created with the Authentication Server Group and the Fallback to Local Authentication option is selected.

CNX-115512

At client context for gateways, the Tunnel ID column displays incorrect values for wired clients.

CNX-115523

The HPE Aruba Networking Central > Audit Trail page displays the action log for cloning a report in the format Report with name <'report name (1)'> created instead of Report with name <'report name (1)'> cloned from report name with <'report name'>.

CNX-116190

When certain unsupported scenarios are pushed to the device via full configuration, the device remains in a "Config Status - Conflict" state. The device does not recover even after the unsupported configurations are removed from the database, and no default or supported configurations are pushed to the device. The unsupported scenarios include:

  • Applying an ACL with unsupported configuration for a specific interface or ingress/egress direction on a specific device.
  • Attaching an ACL to a VLAN when it is associated with a VNI for unsupported devices.
  • Creating an ACL with an unsupported TCP flag matching rule for a specific device.

CNX-116655

In HPE Aruba Networking Central, AOS-S 802.1X alerts are not triggered even after relevant Events and Alert conditions are met.

CNX-116716

The History card on the Sites > Alerts page is unavailable for Interface CRC Error, Interface Fragmented Error, and Interface Alignment Error alerts.

CNX-117790

NBAPI did not support the two-factor type authentication CLI command for AOS-S switches in HPE Aruba Networking Central.

CNX-119052

Users are unable to delete the roles created as part of the Overlay SSID WLAN workflow.

CNX-119091

The Protocol and Port policy rule does not support AP devices under the Policy > Rule > Service/Application page.

CNX-120098

The side panel of an installed PSM extension instance displays the Configuration synchronization status as Operational even when the extension instance is inactive.

CNX-120781

When an Override default role is created in the WLAN profile, the policies and rules are not applied for this role automatically.

Workaround: Add the policies and rules manually.

CNX-123257

The role list under WLAN > Access > Option displays unnecessary roles belonging to other device types.

CNX-123702

The Health Card in the Access Point and Gateway dashboard did not display the last configuration sync status.

CNX-124128

For APs and Gateways under the device list view, HPE Aruba Networking Central does not display the current configuration status.

CNX-124231

HPE Aruba Networking Central incorrectly displays the Temperature health status as greyed out for third-party switches in the Hardware card.

CNX-124520

In User Administration, a username as Manager with Read Only role gives a corrupt file download. This is an expected behavior as Manager as a username cannot be set as an Operator.

CNX-126581

CNX-126567

The Configuration > Profile Management > Devices page in HPE Aruba Networking Central displays (none) as the hostname for gateway devices if the System Information profile is not created at the Global level.

CNX-126678

HPE Aruba Networking Central displays an error when users try to create a Certificate Usage profile through the Library > Security > Certificate Usage page.

CNX-128152

On requesting a full configuration in 7xxx series gateway devices the device enters a configuration failure state. This occurs after creating a new auth-server profile in 7xxx series gateway devices.

CNX-129059

The DEBUG command parameters are not correctly displayed in Swagger, even when the command parameters are set and configured successfully.

CNX-129708

When assigning a scope for a WLAN profile with an ESSID, the Device Groups scope is not available in the Scope Level drop-down list.

CNX-130075

In HPE Aruba Networking Central, the devices are reverting to default configurations and configurations are being pushed to devices. However, the Audit logs display is empty when the global scope is unmapped.

CNX-131701

Duration value displays as 0 for cleared Mismatch Alerts.

CNX-133785

CNX-135534

AP does not inherit the global default configuration upon deletion of the device-level password. This occurs because of an issue with SSI module overrides. After the deletion, default configuration is not reapplied.

Workaround: Perform full-sync to apply global-level configuration on the device.

CNX-133825

The newly configured STP value in AOS-CX switches is not reflecting in the app.monitoring.cx.device.enriched.state.compacted topic.

CNX-134345

When the device was moved from Greenfield+ to the CNX site, the system internal-vlan-range and single local user CLIs were removed from the device.

CNX-134640

There is a discrepancy in the alerts displayed on the Health Card at the device context and site context. Additionally, the navigation to the Alerts list from the Health Card at the site context is inconsistent. Upon clicking the hyperlink, the navigation filters and displays only the most recent alert instead of the complete list relevant to the selected context. This issue is observed because the support for device and site contexts is not fully implemented.

CNX-134909

Deleting a VSF profile in HPE Aruba Networking Central does not convert the related switch stack device type to a standalone switches device type, and blocks subsequent configurations.

CNX-136631

The tunnel down status for the tunnel flap does not update the status bar in the Gateway Monitoring page. This issue occurs because the system does not reflect accurate historical state changes.

CNX-143123

The Hardware card on the switch monitoring page does not display the temperature health metrics. This issue occurs when there is a delay in receiving the statistics from OpsRamp.

CNX-143998

In HPE Aruba Networking Central, users are unable to configure device-level templates before onboarding the devices.

CNX-144944

Telemetry features like CIPT and DFP which are part of the Default system profile, are not overridden in the WebUI whenever there are any changes made through the Yang or the API. Even though telemetry is part of this page, this issue occurs, as CIPT, DFP, and switch system are three independent profiles (objects) and the logic is different from System profile fields.

CNX-145018

When onboarding a non-default switch profile to HPE Aruba Networking Central, the profile is replaced with the default profile. In this case, user must save the configuration and reboot the switch for the changes to take effect.

CNX-145267

The HPE Aruba Networking Central does not automatically update VRRP Router profiles when they are already linked to an interface. To make changes, users must either remove the profile's association before editing it or create a new profile under Configuration > VLANs & Network > VRRP Router with the desired modifications and reapply it. When performing a POST call with a payload containing an invalid IPv4 address for the syslog server in the Gateway component of the Central NextGen Experience platform, the call incorrectly succeeds without validation.

CNX-145484

Deleting the logging profile fails to remove all remote syslog servers from the device. This issue occurs because CNC cannot distinguish between entries it blocked due to violations and those it should allow.

CNX-145524

The tooltip in the latency graph shows the timestamp for Min-Max and Average, instead of values. This issue occurs if there are missing data points in UXI or Application Performance graphs.

CNX-146503

When creating an alias profile, you cannot configure an IPv6 address as Network Destination for an Instant AP through the WebUI.

CNX-147444

Users are unable to configure OSPF message-digest on an interface using the API due to a conflict error. This issue occurs because the configuration does not include the md-password-type: PLAIN_TEXT key-value pair in the request payload.

Workaround: To avoid a conflict error, users must provide the md-password-type and the md-password when configuring OSPF message-digest on a CX switch's Ethernet interfaces or any other interface through the API. Similarly, when configuring OSPF message-digest on SVI or other interfaces, the password-type and the password must be provided.

CNX-148853

The vendor class identifier field is missing in HPE Aruba Networking Central.

CNX-148918

When Device Fingerprinting (DFP) profile is enabled at the device level in Devices > Profiles > System > Switch System > Enable Device Fingerprinting Profile, the DFP configuration is not pushed to the AOS-S switch. This issue occurs because the DFP profile is not supported in an Ethernet interface.

CNX-149774

The gateway chord diagram under the Gateway page topology view and the Wired Interfaces card on the gateway Network dashboard do not display the LLDP information for offline switches in HPE Aruba Networking Central.

CNX-149882

Reverse translation with ciphertext parameter fails for Network Analytics Engine (NAE) agent when the configuration is pushed to the switch in HPE Aruba Networking Central.

CNX-149991

The source port field is missing in the Create Rule side panel. This issue occurs when the user adds a rule by selecting Protocol and Port from the Service/Application drop-down list and entering TCP or UDP as the protocol.

CNX-150726

Telco Profiles do not support priority1 value ads per the standard, and it is impossible to configure it via CLI, but a suitable error message is not displayed in Postman.

CNX-151394

While filtering the Asset Tag Inventory table using the filter icon, the filter is cleared when the side panel closes.

CNX-151637

Configuring DHCP pool profiles for gateways using the API encounters unexpected error. This issue arises because the range parameter is optional for the API configuration, whereas it is mandatory in the WebUI. When configuring range/scope mapping through API, the range parameter is not mandatory, and that is causing a disparity between the API and the WebUI behavior.

CNX-152163

When users create a network policy using aliases that include both IPv4 and IPv6 addresses for the source or destination, the configuration push to AOS-S switch fails.

CNX-153323

In HPE Aruba Networking Central, modified configurations revert to default after upgrading the software version.

CNX-155052

Widgets in Preferences > Customise Report Content page do not apply the radioFrequency filter. For example, when the filter is set to 6 GHz, the report still includes widgets related to 2.4 GHz and 5 GHz. This issue occurs since the custom report logic selects widgets based on the KPI widget configuration rather than the filter input.

CNX-155581

Users are unable to scope map a WLAN to an AP group when a role is created as part of the WLAN workflow. This issue occurs when users create a WLAN profile under Library > Wireless > WLAN and tries to add a new role during the process. The new role does not have a scope mapping, which prevents the WLAN from being mapped to an AP group.

Workaround: Go to Roles & Policies tab and scope map the role to the AP group. Then, return to the WLAN configuration and scope map the WLAN to an AP group.

CNX-155847

In Network Usage reports, the Max & Average WLAN Usage KPI includes WLAN entries with Total Usage of 0 bps, as part of reporting requirement.

CNX-156075

In Report > Create Report > Preference page, users with limited access are able to view all the sites in the Sites drop-down list.

CNX-156183

When configuring the Spanning Tree Protocol (STP) profile for a AOS-S switch using the HPE Aruba Networking Central WebUI or the switch console, the config restore procedure fails to remove Root Guard, Admin Edge, BPDU Filter, and BPDU Guard configurations. This issue occurs when the configurations are set to a non-default priority value.

CNX-156735

In Switch > Network > Wired Interfaces page, the interface usage is not calculated for third-party devices, even though interface utilization and speed are displayed in the Wired Interfaces card.

CNX-158188

When a POST request is made with a payload containing an invalid IPv4 address for the syslog server configuration in gateways, the request is incorrectly accepted without proper validation.

CNX-158230

The Advanced Time Slicing option is not available for the Max & Average WLAN Usage and Top Devices by Wireless Usage KPIs in Network Usage reports.

CNX-159085

In HPE Aruba Networking Central, when a WLAN SSID profile is pre-provisioned, the associated tunnel specification is not being pushed to APs as expected. This results in APs not receiving the required tunnel configuration during onboarding.

Workaround: Before applying any configuration, ensure that at least one AP is already onboarded. This allows the configuration to be successfully propagated to the relevant services.

CNX-160793

User cannot configure non-default values for CDP , LLDP, and DHCP protocols in DFP (Device Fingerprint) profile through the user interface.

CNX-161963

The Devices table does not display any devices and an error message, Failed to retrieve content, is displayed when the user clicks on the Offline Device quick filter, Sites > Network > Unified Device List (UDL) view.

CNX-162577

CNX-162578

When creating an AAA Profile on the Configuration > Profiles Management > Security > AAA Profile page, if the profile name starts or ends with a space, the configuration is pushed to the gateway; however, the device enters a configuration failure state.

CNX-164334

In HPE Aruba Networking Central, the device count in the expanded Sites card differs from the count displayed in the Device Health column.

CNX-164465

The Authentication Server Group profile with spaces does not update in the Captive Portal Authentication profile for the overlay WLAN.

CNX-166146

The search function available upon expanding the VLAN card returns no results when searching by VLAN name. Even if the VLAN name exists in the list, the search functionality fails to display any matching results. This issue occurs within the Network context of a switch.

CNX-166242

When the LTE internal port is configured as a backup uplink, the Gateway > Network > Wired Interfaces tile displays Port Internal LTE as Not Connected, even though the USB LTE port is physically connected. The issue occurs because of the mismatch between the actual connection status of the USB LTE port and the uplink configuration status.

CNX-166376

The VSX profile creation fails on AOS-CX switches in specific scenarios with the validation error Validation failure: Client IP Tracker configuration should be removed before configuring the link as an Inter-Switch Link. This issue occurs when configuring VSX profiles using LAG interfaces because the configuration applies at the group or site level and not at the device level. The IP Client Tracker is automatically enabled during LAG interface creation on the WebUI. When such interfaces are used as Inter-Switch Links (ISLs) in VSX configuration, a validation error is encountered due to incompatibility between IP tracking and VSX ISL requirements.

Workaround: When configuring LAGs for VSX, ensure that the IP Client Tracker is set to Disable on the WebUI to avoid conflicts with default behavior.

CNX-167461

The AOS-S stack displays incorrectly as unmanaged in the topology view. This issue occurs when neighboring devices are in a different site and after the specific AOS-S stack goes offline and is deleted from the Unified Device List (UDL).

CNX-169934

The active alerts for a device does not clear automatically after the device is unassigned from Classic Central.

CNX-170190

HPE Aruba Networking Central fails to display Passpoint content in the Global > Wireless > Passpoint page.

CNX-171420

In HPE Aruba Networking Central, the expanded WLAN card in the Unified Device List (UDL) > summary view displays an incorrect band under the Band column.

CNX-172025

Third Party Devices (TDP) devices identified by OpsRamp are not displayed in the Topology view. The Topology sunburst only displays the TPD entries derived from LLDP relationships of a managed device.

CNX-172101

Device-specific CLI configurations—such as IP address, ipv6 address, and IP helper address—are currently allowed to be pushed from higher-level scopes like site, global, or other non-device-specific contexts via the aruba-interface-vlan.yang model.

CNX-172321

Under Profiles > Devices page, AP hostname changes to device MAC address automatically without any user intervention. The Audit Trail page displays the Source value as System.

CNX-173176

In the Link Node topology view, the Keepalive link between VXS pair devices is not displayed in the WebUI.

CNX-173410

Listed Interface Tunnel CLIs are not supported in HPE Aruba Networking Central

CNX-176756

The AP Connected 10/100 Mbps alert remains active even when the access point is disconnected. Despite the AP being physically disconnected, the alert fails to transition to the cleared list as expected.

CNX-179481

In the Link Node topology view, overlapping nodes may appear in the topology when devices with the same device functions are configured and connected directly to each other at a site.

CNX-179533

Under Network > Unified Device List summary page, the WLAN Band count is displayed incorrectly.

CNX-182307

In site and device context, when we have more than 5 different client roles, the distribution chart shows the number of clients only for the first 4 client roles. The other category does not show any client count.

CNX-182631

When VSF interfaces connected to peers with MACsec enabled fail to autojoin, an AMS error code is generated and handled appropriately. However, the WebUI incorrectly displays the error as Unrecognized.

CNX-182638

Global search does not return results for device function or persona related queries.

CNX-182916

Users with administrator privileges encounter operation failures when attempting to edit or delete sites, site collections, and device groups. This issue occurs because these actions are blocked due to the missing scope assignments in the Role-Based Resource Profile (RRP).

CNX-183399

Gravity WebUI does not display the VSF link error as Interface link down or recommendation text, when there is group speed mismatch on vsf interface.

CNX-183922

When users create an NTP Server alias profile at Library, Global or Site scope and assign the alias to the NTP-profile at Device Group-level, the configuration push to the device fails. This issue occurs due to incorrect scope‑map resources in the Device Group–level configuration.

CNX-184048

The BGP WebUI is missing source protocol option and lacks support for specific aggregate route features, causing configuration limitations.

CNX-184251

The ClientTrends API occasionally returns a data sample that falls outside the expected time range defined by the start-query-time and end-query-time parameters.

CNX-184350

The Configuration Health card displays incorrect information about the device configuration status.

CNX-184428

In an Overlay WLAN Edit workflow with Named VLAN, when a VLAN ID within a VLAN Alias is changed, the VLAN ID is not automatically scope mapped.

CNX-185045

Devices are not visible in the Link Node topology view but displays correctly in the sunburst view.

CNX-185306

Two C2C clusters with the same name, located at different sites, are incorrectly displaying data under a single cluster context instead of being separated.

Workaround: While creating a cluster, ensure that the cluster name is unique in the account.

CNX-185319

In Library > Roles and Policies, the NetService feature is only supported for AOS-S specific personas and not for shared personas when creating a policy.

CNX-185786

In Site dashboard > Topology icon > Link Node View, when a link is selected, the side panel does not display the VLAN description associated with the selected link.

CNX-186266

In the Site > Topology > Link Node topology view, the Link Health status is not updated when the devices are offline.

CNX-186269

The Link Node topology view displays an incorrect value for Speed between the links. Although the AOS-CX port connected to PVOS1 is disabled, the speed between PVOS1—PVOS2 and PVOS2—IAP1 links continue to show 1 Gbps. This issue occurs because the topology service consumes outdated interface data that reports active speeds despite the link being inactive.

CNX-187420

The Link Node topology view of an unmanaged device, after it has been disconnected from a gateway, continues to appear as connected, even though the gateway CLI does not show any active devices.

CNX-187777

Under Profiles, if user creates a default gateway without selecting the Gateway Parameters checkbox, and the checkbox is later enabled while editing the profile, the Metric field does not automatically populate with its default value.

CNX-187813

WebUI changes for VRF gateway profiles are blocked due to pending GraphQL API integration, dependent on YANG implementation.

CNX-188281

On executing the Get Top N Clients By Usage API call, the response displays inconsistent client names across different timeframes compared to the information displayed in the Top Clients card in the clients Summary view.

CNX-188531

In HPE Aruba Networking Central, in the Configuration Health device-specific error page, the profile names of some capacity violation configuration items in the Validation Blocker error category are not displayed.

CNX-188553

The context information does not update properly when the customer uses the browser’s back or forward buttons after switching between different device contexts. This issue occurs when the customer navigates to the Site > Topology page and then tries to navigate between device contexts. This action causes the displayed context to become inconsistent with the actual sequence of device selection, resulting in the page displaying incorrect information.

CNX-189205

If a user selects the IPv6 and Gateway options when creating an alias, the Uplink VLAN option is displayed under Gateway Parameters, although gateways do not support uplink VLANs for IPv6 addresses.

CNX-190639

Split ports, and their statuses, are not shown in the Wired Interfaces card.

CNX-191206

In Library > Named Objects > Aliases > Edit Alias, the References tab for an alias of type DNS shows the Policy and Rules table, which is not applicable. Only the Profile table should be visible, since a DNS-type alias is referenced exclusively in DNS profiles.

CNX-191356

WLAN profile deletion fails when it is mapped to an override role, and the WebUI displays unclear error messages. This issue occurs in the WLAN profile management when the profile is scoped to multiple sites. It is due to a limitation in processing bulk unmap requests and resolving role references during scope mapping.

Workaround: Unassign one scope at a time. Currently, unassigning multiple scopes at a time is not supported.

CNX-191640

Console Attempts, Lockout Time, Login Retrieve, and Delay Seconds are not getting pushed to the device.

CNX-191732

In Network Overview > Sites card > Site name > Topology > Link Node View, while removing uplinks from the mobility gateway through the CLI, the changes take over 20 minutes to reflect.

CNX-191954

AIOps is generating false VLAN Mismatch alerts for LAG and VSX interfaces, even when VLANs are configured and allowed on both switches.”

CNX-192064

In HPE Aruba Networking Central the AOS-S switch crashes when an OSPFv2 profile is deleted via NBAPI under specific configuration conditions. This issue occurs when the deletion request includes a payload with a description field and was sent in rapid succession.

CNX-192628

<Pritish>

When an overlay WLAN with auto role is configured with a manual cluster profile created at device group, users are unable to assign scope to the overlay WLAN profile using the API.

Workaround: Configure this profile from the WebUI. However, your auto role will be mapped to the global scope.

CNX-193017

A DNS Profile can be created and scope mapped without Resolver IP or Alias entries even though, in the WebUI, a Resolver IP is mandated.

CNX-193129

The frame errors from the Connectivity Performance expanded card are disabled due to the unreliability of Rx error metrics. These metrics are influenced by complex environmental factors—such as signal levels, sensitivity, BSS energy detection thresholds, BSS color, and chip vendor design—and do not consistently indicate poor channel quality. With the rise of spatial reuse technologies, access points are increasingly resilient to overlapping BSS interference. As a result, the frame errors graph is removed, and alternative radio metrics such as channel utilization, noise floor, and Tx retries are suggested for better environmental evaluation.

CNX-193820

The topology Link-Node view component does not register click or double-click events on nodes and edges within a specific area. This issue occurs because, even when the component is collapsed, it still occupies the full expanded width in the background. As a result, mouse-over and click interactions are blocked in the affected portion of the topology view.

CNX-193870

In Network Overview > Sites card > Site name > Topology > Link Node View, side panel displays inconsistent information for edges linked to unmanaged devices when unmanaged device is a parent. This issue occurs because the Link Node View side panel for unmanaged parent devices only displays source and destination device names and ports, resulting in incomplete information.

CNX-193957

When a bad VLAN configuration is rectified on a port via API or WebUI, the application continues to display the target switch state as Config Status - Conflict. However, the DB has the correct VLAN configuration.

Workaround: Update the VLAN configuration and run a Full Config Push.

CNX-194363

In Network Overview > Sites card > Site name > Topology > Link Node View, side panel displays only limited information such as MAC and Vendor for Unmanaged devices. The detailed device information is displayed under Description field as one string. This issue occurs when the unmanaged device broadcasts the LLDP information to managed devices.

CNX-194554

The option to configure Change of Authorization (CoA) on AAA profile is not supported on gateways.

CNX-195370

When the ISL dead timer is set to a value less than 10 seconds while configuring a VSX profile via API or WebUI in Sites > Profiles > High Availability > VSX, the configuration fails with an error message Full push failed with error even though CX products support ISL dead timer in range of 2-20 seconds. As a result, the switch remains in a Config Status - Conflict state. This issue occurs because the system incorrectly interprets warning messages as error messages.

Workaround: The ISL dead timer must be set between 10 - 20 seconds.

CNX-195625

There is a mismatch in the health statuses of Access Points (or WLANs) and their corresponding sub-components. This mismatch takes place because the sampling frequency of APs does not match the frequency of other components. This results in a delay in database updates.

Workaround: Wait up to 10 minutes for the health status to sync.

CNX-196580

When configuring an overlay SSID at the Device Group, Site, or Site Collection level, selecting a default role manually is required. However, if the selected default role is manual and the associated WLAN GW-Cluster is scoped to a Device Group, the system throws the following error: Cannot find object of module aruba-role.

CNX-196629

The AP IEP basic mode profiles are not currently integrated with the DP framework in the Common Config WebUI.

CNX-196633

The DP CX Basic IEP module is not fully integrated with the Device profile framework.

CNX-197016

On the Health Metrics LAN, WAN, System tabs, the health status updates may be delayed up to 9 minutes when there is a change in the alerts status or severity.

CNX-197152

In the Profiles List, for a VLAN Profile referring to the Description Alias, the Description row is not visible.

CNX-197241

HPE Aruba Networking Central allows configuring the same IP address on both a Layer 3 VLAN interface and a Layer 3 GRE tunnel without any validation check. In this case, a configuration failure occurs on the gateway with the following error message: IP Address Matches with an Interface IP.

CNX-197978

In VLANs & Networks > VLAN, the Port Profile feature allows configuration of VLANs that were not available in the HPE Aruba Networking Central library, on trunk ports. It causes devices to go in out-of-sync state when unavailable VLANs are configured.

CNX-199108

Creating OSPF profiles over NBAPI with a no-advertise-range leaf specified throws an exception: HPE_GL_ERROR_INTERNAL_SERVER_ERROR.

CNX-199156

In the Health Metrics, WLAN tab, when all radios are disabled, the subcategory health graph is empty.

CNX-199271

Global search in HPE Aruba Networking Central is intermittently failing across clusters and returns a Failed to Retrieve Content error.

CNX-199495

In HPE Aruba Networking Central, in the Configuration Health device-specific error page, when an uninitialized alias violation exists, only the first subsequent capacity violation is displayed. Additional capacity violations appear only after the initial violation is resolved.

CNX-199524

The details displayed on the Health Metrics page of a site dashboard does not match the health data available in the KPI charts.

CNX-199576

On the Summary view of the Unified Device List (UDL) page, within the expanded Radios card > Radios table, the frame Retries and Drops values are displayed as zero (0) for unsupported firmware versions, instead of a hyphen.

CNX-199710

The Configuration Health dashboard does not list CNC violation errors if the dashboard already displays uninitialized alias violation errors.

CNX-199721

In Devices > VLANs & Networks > VLANs, users cannot unassign or remove the VLANs that are configured through VSX at either Site scope or Global scope level on aggregation switches.

Workaround: Configure new VLANs without VSX.

CNX-199746

When default policy rules are configured with default rule service in HPE Aruba Networking Central, only new APs , which are onboarded after the configuration, inherit the rules. Existing APs, which are onboarded before the configuration, do not inherit these rules.

CNX-199829

In the Health Metrics, LAN tab, the state and stats information for not connected interfaces is displayed. However, this information is missing from the Wired Interface card in the device context.

CNX-200070

In Sites > Roles & Policies > Network Policies, Network destination rules are not functioning properly in CNX Library under NACL and QOS policies for AOS-S devices when creating policies. This issue occurs when creating rules that use netgroup as source and destination, and netservice as configuration.

CNX-200975

The CONFIG_FAILURE error message is displayed in the site collection when configuring a fifth L3 VLAN with an IPv4 alias. This issue occurs because the existing DHCP VLANs configured at higher scopes (Global level) are not accounted for, which leads to a miscalculation of the DHCP client count. Only four DHCP-enabled VLANs are allowed, which causes the configuration to exceed the permitted limit and results in a failure.

CNX-201163

Pushing an invalid split port configuration to an AOS-CX device triggers the following errors:

  • This operation cannot be performed until interface {name} is split.

  • Invalid input: {name}.

While child ports are created, the port is marked as conflicted.

Workaround: Manually remove child ports using APIs then push a valid split port configuration.

CNX-201274

The Switches data under Network Overview > Sites card > Site name > Health Metrics displayed incorrect information. Data from before the cluster upgrade was displayed in the health bar even though historical or migrated data should not be visible.

The fix ensures that only data collected after the cluster upgrade is displayed in the health bar.

CNX-201275

After the cluster upgrade, the Health Metrics page displays historical data before the upgrade time.

CNX-201339

Users can create a new local single-instance profile and assign it to a scope to override the Global default profile; however, the configuration cannot be pushed to the AP due to a Capability and Capacity error. Currently, users can only modify the Global default profile at a lower level and save it as a local profile. Local profiles created before the Capability and Capacity change will continue to work, but it is not recommended to update these profiles or add new devices, as doing so will also trigger a Capability and Capacity error.

CNX-201594

When an alias is configured without default values (causing uninitialized aliases), target devices become blocked. When default values are added, the device becomes unblocked but no notification is triggered to config health.

CNX-201717

When you search for Basic OSPF Configuration Steps in Networking CoPilot, the router ID includes special characters.

CNX-201731

On the Health Metrics page for the selected site, the hardware health graph is not plotted for a VSF stack switch that is offline prior to the upgrade. For such offline switches, the aggregate device health and category health are published.

CNX-201759

In the Reports page, users are not receiving translated report content over an email when exporting reports into PDF or CSV format or when using the Send Email feature. This issue occurs because the language translation support is currently limited to only HTML format.

CNX-202115

When a device is removed on HPE GreenLake, the devices site and groups are unassigned on HPE Aruba Networking Central while remaining unchanged on Classic Central.

Workaround: When the device is added back to HPE GreenLake, unassign and then re-assign the devices to the intended sites or groups on Classic Central.

CNX-202156

The field  Loop Prevention > VLANs in Port Interface configuration and Ethernet configuration profiles is not supported by AOS-S.

CNX-202222

The getClientConnectionsInfo API incorrectly counts successful and failed attempts when a client retries MAC authentication with invalid RADIUS credentials. Each retry logs connected, disconnected, and failed events, inflating both success and failure counts in the Client Details > Network Planet > Connections card.

CNX-202234

In HPE Aruba Networking Central, within the Configuration > System card, the Dynamic DNS (DDNS) profile for gateways disassociates the DHCP pool from the DDNS profile when full configuration is received for gateway.

CNX-202440

CNX-201917

The uplink information on the Wired Interfaces card displays incorrect data. This issue occurs because the uplink information is now based on the new Link Node topology, creating a discrepancy between the actual parent in the Link Node View and the uplink ports shown in the Wired Interface card. This discrepancy will occur only if a change reference point was selected previously.

CNX-202487

Creating an admin profile at the site level with an existing device level username wrongly applies the site level configuration to the device, overriding the device profile. This issue occurs in the Admin Profile configuration page because the username conflict check is not present between site and device scopes.

Workaround: Use unique username for site-level admin profiles. If a conflict occurs, delete the site-level profile and re-apply the device-level configuration.

CNX-202659

After the cluster upgrade, a mismatch occurs between the device count displayed in the Sites > Devices table and the Health Metrics page. The device count in the Sites > Devices table is correct. The mismatch occurs because access points that are offline before the cluster upgrade are not included in the device count on the Health Metrics page. Only access points that go down after the cluster upgrade are considered.

CNX-203223

SSH configuration push fails for gateway when creating an SSH profile with AES_CTR and HMAC_SHA1 disabled, due to capacity limitations.

CNX-204733

When you onboard an AP running version 10.7.2.0 or later, or perform a delete operation to restore default settings, the DAP WebUI displays the default DSCP values. However, these displayed values do not correspond to the actual DSCP values used for session prioritization.

CNX-205495

HPE Aruba Networking Central does not enforce address-family consistency when policy rules are configured. This allows IPv6 address aliases or net-groups to be used even when the policy’s address-family is set to, or defaults to IPv4, and the same issue occurs when IPv4 objects are used with an IPv6 address-family. The issue occurs because of a missing or inadequate validation at configuration level.

Workaround: Manually verify the types of address objects and address-family type before applying the configuration to the gateway.

CNX-205897

Mapping a captive portal profile to a role via the network-config API does not push the updated role configuration to the gateway. This issue occurred because the updated central role state is not propagated to the gateway.

Workaround: Manually apply or push the updated role configuration to the gateway.

CNX-207131

Users are able to delete user roles despite being assigned to a policy using APIs.

CNX-207485

Users are unable to unassign or delete profiles or user accounts that contain the text admin in their name. This issue occurs on the User Administration page and affects both profile management and function or scope unassignment. Profiles or usernames that do not include admin continue to work as expected and can be modified or deleted without issue.

CNX-208402

The client channels are displayed incorrectly in the Unified Client list.

CNX-208451

In Network Overview > Sites card > Site name > Topology, parent devices that share the same child nodes collapse incorrectly. Only one of the parents shows a collapse control and collapsing it creates or displays a device group exclusively for that parent. The other parent, despite having the same child relationships, shows no collapse option, resulting in inconsistent and confusing node‑level collapse behavior.

CNX-208900

The unmanagedDevice NBAPI may return a valid response when queried for a device that is managed. This occurs because unmanaged device entries are not being cleaned up when their status changes to managed, leading to stale data in the API response.

CNX-208939

HPE Aruba Networking Central switch temperature metrics are missing in UDL because OpsRamp is sending metrics every 15 minutes instead of the 5-minute interval.

CNX-210288

When DAP is enabled, communication between two clients on the same AP is reported as a single client because DPI/AppRF identifies only the source client, leading to incorrect client counts and missing throughput.

CNX-210629

In the Clients list view, the VLAN name is not displayed for clients connected to gateways.

CNX-210881

In HPE Aruba Networking Central, the newly created Sites, Site Collection, or Device groups (standalone deployment only) appear at the top of the table instead of sorting it according to the default order.

Workaround: Click the column header to sort or navigate to a different tab and then return to the original table view.

CNX-210932

When a policy is configured with mixed IPv4 and IPv6 rules, the device does not preserve the mixed order after the configuration is pushed and the position is not reflected correctly in the show rights output.

CNX-211387

The offline device count in the Universal Device List (UDL) does not match on HPE Aruba Networking Central and Classic Central. The mismatch is caused by deleting devices from HPE Aruba Networking Central, Classic Central, or HPE GreenLake.

  • Devices deleted on Classic Central, are not removed on HPE Aruba Networking Central

  • Devices deleted on HPE Aruba Networking Central, are not removed on Classic Central

  • If the device is deleted on HPE GreenLake, the device is removed on HPE Aruba Networking Central but not Classic Central

The Classic Central and HPE Aruba Networking Central do not communicate about device deletions.

CNX-211640

When configuring IP Prefix-Priority, some switch platforms require a minimum number of prefix entries. If fewer prefixes are submitted than the platform supports or requires, the switch may become out of sync and unable to apply the configuration correctly.

Workaround: To restore the switch, it must be removed from HPE Aruba Networking Central, the invalid configuration must be cleared, and then the device should be re-onboarded.

CNX-211760

In HPE Aruba Networking Central, when navigating to Sites > Configuration > select a scope > System > Switch System > Edit Profile > Auth Survivability section, the option to remove the oldest cached data first (FIFO) when the authentication survivability cache memory is full is not available. The cache replace mode determines how successfully cached roles are retained when multiple roles are cached. This enables the switch to authorize clients using their previously assigned roles when the RADIUS server is unreachable, instead of assigning a generic Critical role or denying access.

CNX-212101

For a user-based tunneled client, the Role and VLAN information displayed in the Connected Clients card does not match information shown in the Clients table. <Moved to Mar26 RI>

CNX-212104

The Unified Client component fails to display role, speed, and duplex values correctly in the stats pipeline. While the assigned role appears in the Clients Table, it is missing from the Client Distribution chart, and speed/duplex metrics are absent from the Connectivity Performance card.

CNX-212808

In Classic Central, users with Aruba Central view edit role are unable to edit or delete the client’s notes.

CNX-213290

When users modify settings on a network port that is part of LAG (port-channel), the system correctly blocks the change and shows an error internally. However, the web WebUI does not display this error or any message, which can be confusing. This issue occurs because the web interface is not configured properly to display errors.

CNX-214610

Editing validated NAE scripts is not supported. Modifying a script after validation may result in undefined or inconsistent behavior on switch devices.

Workaround: Delete the existing script and create a new script that includes the required changes.

CNX-214800

When editing webhooks in the API Gateway > Webhooks section, the API key or OIDC details (Client ID, Client Secret, and Well-known URL) are displayed as blank instead of being masked.

CNX-215200

In the Device dashboard page, the Configuration Status in the Health card is displayed as Out of Sync. This issue occurs when, at the Global scope, a new VLAN is created with DHCP configuration while an existing VLAN is already configured with DHCP.

Workaround: You must disable DHCP on the existing VLAN before configuring a new VLAN with DHCP enabled.

CNX-215781

On the HPE Aruba Networking Central landing page, the entire area around the Alerts and Clients count in the side panel is clickable. Currently, the entire surrounding region is interactive, whereas only the count and its circular icon are expected to be clickable.

CNX-216429

On the Site dashboard page, the Health card displays incorrect information. The health bar and the health percentage shown in the hover pop-up do not reflect the actual site health.

CNX-216876

On the Site > Insights > AI-Powered Network Optimization page, the chart padding is not displayed properly when no data is available within the selected timeline.

CNX-216974

HPE Aruba Networking Central global search shows an incorrect offline switch count and creates a discrepancy between Classic Central and HPE Aruba Networking Central results. The issue occurs because HPE Aruba Networking Central does not ingest or retain telemetry for devices that were already offline before allowlisting or for long-offline devices whose data is lost due to consumer group changes, leading to incomplete offline device visibility in HPE Aruba Networking Central.

CNX-217310

The helper address created at the site scope is not being deleted when it is overridden at the device group scope.

CNX-217637

Admin users with restricted site access can view certain monitoring telemetry outside of the scope group they are assigned in GreenLake.

CNX-217652

In the Access Point Firmware Recommendation page under Sites > Insights > AI-Powered Network Optimization, the recommended firmware release dates shown in the tool tip for the Popularity of Recommended Firmware card does not match the actual dates listed in the release notes.

CNX-218869

The RFC server does not automatically update in the AAA Authentication profile of the gateway when the existing authentication server is changed from Radius to Radius+COA.

Workaround: After editing the authentication server, you need to update the same server in the WLAN again. This will prompt the WLAN to fetch the updates and subsequently update the RFC server in the AAA Authentication profile.

CNX-220108

When you edit the VLAN ID for the overlay WLAN, the old VLAN is removed, and the new VLAN is added to the gateway's scope. Consequently, the gateway will no longer retain the old VLAN.

Workaround: To retain the VLAN configuration on the gateway, you can configure the VLAN in one of the following ways:

  • Create the VLAN as a local object under the gateway persona with the appropriate scope.

  • Create the VLAN at the global scope under the gateway persona.

  • Configure the VLAN under the Named VLAN.

CNX-220603

The VSX create and delete notification integrations into InterfaceProfile are not functioning as intended.

CNX-221300

After migration, tunnels fail to establish between the Access Point (AP) and the Gateway device when the “AUTO‑SITE‑CLUSTER‑MGW” cluster profile is configured under the WLAN profile at the Site Collection scope.

CNX-221686

The CX configuration WebUI does not currently support NTP authentication configuration.

CNX-221713

When a device goes offline and triggers an alert, the alert is initially displayed correctly on the alert trend chart in the Health Metrics page at the time it occurs. However, after the device reconnects, the previously recorded alert is removed from the alert trend timeline. This behavior results in the loss of historical alert data and leads to an inaccurate representation of alert trends.

CNX-221869

The Link-Node view displays an overlapped topology and shows an error when elements are selected. This issue is caused by VSX pairs and neighboring switches lacking proper device functions, which leads to incorrect parent/child identification.

CNX-221979

Users that do not have access to sites are able to view floorplans in it.

CNX-225089

After onboarding the switch to an HPE Aruba Networking Central group, the device enters a Blocked state when client-limit configurations (such as AAA and port-security) applied through port profiles or interface profiles exceeds the supported values defined for the switch (for example, exceeding 32 on 6100/4100i or platform-specific limits). Correcting or removing the configuration did not recover the device, and it remains in the Blocked state.

Workaround: Select each interface individually and reset it to default.

CNX-225136

Dual-stack wired gateway clients lists either an IPv4 and IPv6 address in the client list or details page but not both. This is because the WIRED_USER_INFO telemetry sent by the device only accommodates one IP address (IPv4 or IPv6). Based on the format of the received IP address, the IPv4 or the IPv6 address field is populated in the client list and in the client details page.

CNX-225615

When testing the telemetry data with DAP and AirExpress enabled, the data is not updated for the first 15 minutes on the Health Metrics page. After this period, all metrics (shown on Throughput, Clients, and Health charts) are refreshed every 2-3 minutes.

CNX-225921

When a 6000‑series switch is onboarded to HPE Aruba Networking Central and assigned to a site with existing port‑access roles and policies, port‑access policy classes remain in a user configuration currently being processed state. This occurs when the configuration is pushed via HPE Aruba Networking Central/REST.

Workaround: Attach a AAA profile with either 802.1X, MAC-Auth, or both enabled to at least one interface of the switch to clear the warning.

CNX-226079

In the global context, multiple user operations in the Alerts table intermittently failed or remained stuck in the Processing state. This fix ensures that user operations in the Alerts table complete successfully.

CNX-226180

When assigning a gateway Port profile that uses an alias referencing a VLAN profile, the assignment fails with a Vlan <id> referenced in '<alias>' does not exist error message even though the profile exists in Library. This issue occurs because scope-mapping cannot update an alias and its dependent profiles in the same operation, so the referenced VLAN profile is not created in the target scope when the alias or port-profile is applied.

Workaround: Scope-map L2-VLANs before scope-mapping a Port profile with switchport alias.

CNX-226317

The delete operation for an overlay WLAN fails when its auto‑generated role is changed to a local profile. This issue occurs on the gateway Device Group configuration page. It happens because the application incorrectly allows an auto‑generated role to be changed to a local profile within the same scope, creating a broken link that prevents the WLAN from being deleted.

CNX-226320

Users must select all line modules when creating an Interface Profile in Modular + Custom mode, even if the configuration only applies to some modules. This issue occurs because the system requires an exact topology match for Custom Interface Profiles, which necessitates selecting all line modules for the profile to match the device’s chassis layout.

CNX-226322

When an Interface profile is created in the Custom mode for switch stacks or chassis with a fixed number of modules, HPE Aruba Networking Central does not allow modifications to that profile if there is a change in hardware, such as the addition or removal of a line card. This limitation also applies to stack-type Interface profiles, where any addition or removal of modules in the VSF stack prevents further modification of the associated profile.

Workaround: To ensure the correct implementation of an interface profile, complete either of the following steps:

  • Create an Interface profile in the Custom mode that aligns with the updated hardware configuration.

  • Create an Interface profile in the Automatic mode for switch stacks or chassis with frequently changing topology.

CNX-226686

On CX switches, when a trunk is configured using the keyword 'all', the interface automatically inherits any newly created VLANs. However, if the trunk is configured with specific VLAN IDs or ranges, it is restricted to those defined values and does not automatically include unconfigured or future VLANs.

CNX-227560

When an alias is changed from TRUNK to ACCESS mode, the system correctly updates VLAN mode but fails to remove ACLs associated with the old trunk VLANs, leaving invalid and potentially risky configuration on the gateway interface.

CNX-228578

In HPE Aruba Networking Central, the client-connected interfaces on a CX switch do not display correct port associations in the client dashboard. Although two clients are physically connected on different ports, the system incorrectly reports both clients as being on the same port.

CNX-228888

A Net Destination UI for IPv6 automatically deletes both colons (::) when trying to delete a single colon.

CNX-229503

In Profiles > System > Switch System, power redundancy configurations are not updated on devices due to incompatible power supply combinations. This issue occurs because the system prunes unsupported configurations without generating alerts or audit trail entries, preventing administrators from being aware of the configuration push failure.

CNX-230196

When a VLAN is used as an access VLAN on an interface, the system prevents its deletion and displays an error: Validation Failure: VLAN '<ID>' cannot be deleted because it is referenced by Interface Ethernet '<Interface>' in the hierarchy. However, if the VLAN is configured as a trunk VLAN with native VLAN as 1, the deletion succeeds silently, and the interface is configured to trunk all, with no warning or error messages. After deletion, the UI continues to display the deleted VLAN under the VLAN column, resulting in stale information.

CNX-232129

In getNeighbours NBAPI response, siteName is returned as null and siteID is Incorrect for unmanaged neighbor. This issue occurs when the managed device reporting the unmanaged neighbor is moved between sites or reported by multiple devices across different sites.

CNX-232448

While configuring the port profile for a wired AP port in the overlay network through the HPE Aruba Networking Central, the Accounting Interval field is incorrectly displayed as a mandatory field.

CNX-232467

Users are unable to perform the following functions in the VSF WebUI:

  • Replace a faulty VSF member

  • Create a VSF stack without a standby member

  • Configure VSF link description

CNX-232777

Hyperlinks under Site > Clients > Top Clients, are accessible only when GDPR is enabled.

CNX-233604

Rogue devices on the floorplan manager WebUI overlap due to having the same location. If a rogue device's location cannot be ascertained by location services, the location is assumed to be the same as the associated AP.

CNX-233880

When users try to modify an IPv6 address on the Configuration Overview > Library > Named Objects > Net Destination page, the Edit option appears with a delay. This issue occurs because the WebUI processes IPv6 address changes slowly, resulting in slower rendering of the Edit field.

CNX-233886

When configuring a net destination IPv6 network on the WebUI, invalid configurations do not trigger an error message.

CNX-234162

<Elizabeth>

When a VLAN is deleted on the primary device while the secondary device is out of sync due to a failed configuration sync, the secondary retains stale VLAN metadata. This causes UI deletion attempts to fail because of VSX reference errors.

CNX-234819

When configuring an IPv6 net destination network on the WebUI, VLANs do not function correctly for the gateway.

CNX-235803

The number of sites displayed on the expanded Sites card doesn’t match the count shown on the Sites tab under the Configuration menu.

CNX-236502

In VSF, a configuration push from Classic Central to the switch triggered a port configuration loss.

CNX-238771

Device import fails because the User Based Tunneling (UBT) configuration does not pass schema validation. This issue occurs when required fields are missing or contain invalid values, especially the primary-controller-ip in UBT zones, resulting in a 400 error.

Workaround: When importing the device along with the UBT zone configuration, ensure that both primary and backup UBT controller IPs are properly defined.

CNX-240036

In Library > Element Profiles > VLANs & Networks > VRRP Router, the webUI for VRRP configuration does not allow mapping multiple VRRP profiles to a ROP interface, while the CLI supports mapping multiple VRRP instances to the same interface. This issue occurs because the webUI allows only one VRRP profile to be mapped to the interface.

Workaround: Create multiple VRRP instances within a single profile and map that profile to the interface.

CNX-240198

When creating a Host Alias after deleting an IPv6 alias, the UI displays the IPv6 option, but the value field displays IPv4 fields for entering values.

Workaround: Navigate back to Library > Alias, then create the alias again.

CNX-242947

Location override and HTTPS certificate configurations were removed from the New HPE Aruba Networking Central On-Premises CLI after performing a firmware upgrade via HTTPS. This issue occurs because the full configuration push failed to preserve the hpe-anw-central location-override and crypto pki ta-profile root-cert settings, prompting an automatic rollback to the previous configuration.

CNX-243465

Intermittently, the relationship between the gateway and an unmanaged device is not established because the gateway is unable to detect the system capabilities enabled on the unmanaged neighbor device.

CNX-243465

In Topology view, if a gateway fails to establish a relation due to invalid or unsupported LLDP capabilities, the unmanaged device is not displayed.

CNX-243616

The Device Inventory CSV export currently combines the device name and device status into a single column, whereas in the UI and UDL CSV export, these are displayed separately in distinct columns.

CNX-243858

Intermittently, the relationship between the gateway (GW) and an unmanaged device is not established because the gateway is unable to detect the system capabilities enabled on the unmanaged neighbor device.

CNX-244309

During live upgrade operations on gateways, upgrades scheduled and cancelled are not displayed in the audit trail.

CNX-245385

Sites created in Scope Management (including duplicates) are not appearing in Site Health, resulting in inconsistent site data across the system.

CNX-246004

Users are unable to replace a Port profile with LAG ID with another Port profile.

Workaround: To replace a Port profile, follow these steps:

  1. Remove the existing Port profile with LAG ID from the associated interfaces.

  2. Assign the newly created Port profile to the interfaces.

CNX-248351

After configuring an IPv4 address on an interface and exporting the configuration as a CSV file, the Instance Name column may not show the correct interface identifier when opened in Excel.

Workaround: Open the CSV file in Notepad or any text editor to view the correct interface identifier.

CNX-248674

Users reported an Invalid Token error when creating a webhook in HPE Aruba Networking Central, which appears to be related to authentication issues used during webhook configuration.

CNX-250907

Users are unable to update the LAG ID in an existing Port profile.

Workaround: To modify the LAG ID for interfaces already associated with a Port profile, follow these steps:

  1. Create a new Port profile with the required LAG ID.

  2. Remove the existing Port profile from the associated interfaces.

  3. Assign the newly created Port profile with the required LAG ID to the interfaces.

CNX-251113

When the Create Alias API (POST /network-config/v1alpha1/aliases/{name}) is executed with an IPv6 address value, the API call is executed successfully and the alias is created at the library level without triggering the expected custom validation error.

CNX-251608

The following issues are observed:

  • When executing the Create Alias API (POST /network-config/v1alpha1/aliases/{name}), the API call succeeds without displaying a custom validation error even when the IPv6 address specified in the device-address field for the ALIAS_IPV6_SYSTEM_VLAN alias type is not part of an L3 interface.

  • If a gw-system-profile references an alias profile in which an IPv6 address is configured using the ALIAS_IPV6_SYSTEM_VLAN alias type, and the gw-system-profile is subsequently updated to reference a different alias profile that does not contain an IPv6 address, the previously configured IPv6 address is not removed from the gateway.

CNX-251978

When the gateway is initially configured in dual-stack mode with both IPv4 and IPv6 addresses, and is later updated to use only an IPv4 address by setting the ipv6-device-vlan-alias field to null using the PATCH /network-config/v1alpha1/gw-system/{name} API call, the IPv6 address is not removed from the gateway.

CNX-252232

Some users could encounter a Maximum 63 characters passphrase error message while updating an existing MPSK profile.

Workaround: Re-enter the passphrase manually when updating an MPSK role.

CNX-252535

Newly created overlay (Tunnel/Mixed mode) WLANs do not form tunnels after being assigned to a device group. This issue occurs when an overlay (Tunnel/Mixed mode) WLAN is scope-mapped to a device group before any devices are present in the group.

Workaround: Ensure that at least one device is present in the device group before scope-mapping an overlay (Tunnel/Mixed mode) WLAN to the device group.

CNX-252678

Target devices with non-compliant firmware show Config Out-of-Sync when onboarded to and managed by HPE Aruba Networking Central.

Workaround: Apply a firmware policy to the device and wait for the firmware update to push configuration successfully.

CNX-253386

User-based tunneling (UBT) clients are displayed as non-tunneled after opting out of GDPR. This is because client telemetry is event-based.

Workaround: Disconnect and reconnect the client to trigger an event in the client telemetry pipeline.

CNX-253419

GDPR opt-out is not functioning as expected for Gateway wired clients because Gateway client telemetry is event-based only. Since telemetry data is generated and sent only when specific events occur, the GDPR opt-out setting is not applied in the same manner as it is for continuously reporting telemetry, resulting in telemetry events still being observed from affected clients.

CNX-254385

On the Switch Firmware Recommendation insight page, the Popularity of Recommended Firmware section fails to load and displays an error message Failed to retrieve content even when firmware recommendations are available.

CNX-255455

A Syslog profile that references a VLAN as the source interface is accepted even when the VLAN has no IP configured, without generating a validation error.

CNX-255748

When executing a configuration CLI command using an invalid or non-existent device serial number, the API returns an HTTP 200 OK status code instead of an appropriate error response (such as 4xx).

CNX-255959

VSF stack members go out of sync after onboarding in the HPE Aruba Networking Central, and the UI displays an incorrect VSF topology. The issue occurred because the system pushes an unsupported profile basic command from the default configuration to devices running firmware versions that do not support it, resulting in a configuration push failure and leaving the device out of sync.

CNX-257369

Users are unable to access the NBAPI link for Live Upgrade status. This issue occurs because the Live Upgrade is not available in HPE Aruba Networking Central.

CNX-257766

Deleting trunk VLANs does not clear the corresponding entries from the switch interface UI, causing full configuration push failures. This issue occurs because the interface continues to reference non-existent VLANs.

CNX-257839

Although the HPE Aruba Networking Central WebUI provides a delete option, users are unable to delete mesh clusters from AP devices.

CNX-257903

Users see an error message in AP config health when Classic Central HotFix is upgraded to the fixed tag.

CNX-260412

In the WebUI, the Interface Loopback profile does not display the configured IP address when the profile is created using the POST /network-config/v1alpha1/loopback-interfaces/{id} API. This issue occurs because the WebUI relies on the ipv4-config and ipv6-config containers to retrieve IP address information, while the API also allows individual configuration of IP-related parameters such as ipv4, ipv4-prefix, ipv6-address, ipv6-addresses, link-local, and secondary-ip. As a result, IP address details configured through these individual parameters are not displayed in the WebUI.

Workaround: To ensure consistent behavior between the API and the WebUI and to enable the correct display of IP address information in the Interface Loopback profile, configure IP-related parameters using only the ipv4-config and ipv6-config containers. Individual IP-related parameters (ipv4, ipv4-prefix, ipv6-address, ipv6-addresses, link-local, and secondary-ip) are deprecated.

CNX-260682

In some Client Connectivity Metrics queries, the site name is displayed as a plain text instead of a clickable hyperlink.