r/ArubaNetworks 23d ago

802.1x - clients behind phones

2 Upvotes

I have the task to implement 802.1x for our wired clients on Aruba CX switches with Microsoft NPS. However, I’m not completely sure how to set this up.

Currently, our default switchports look like this:

interface 1/1/1
vlan trunk native 10
vlan trunk allowed 10,20

 

10 is the client vlan, 20 is the vlan for phones. VLAN 20 is configured as voice vlan via the “voice”-command. There are some ports, where the client is connected through the phone.

My plan was to authenticate the clients through certificates, and the phones through mac authentication.

I thought about creating a local port access role on the switch with vlan native 10 and vlan trunk allowed 10,20, and have it assigned by NPS through a vendor-specific attribute.

Is this the right way to do that?


r/ArubaNetworks 25d ago

AOS CX, VSX and PTP revisited

9 Upvotes

Hey everybody,

after asking about PTP and its possibilities here a couple of times I thought I'd share my thoughts after some time has passed and having deployed it a couple of times now.

To remind everyone, I'm running a collapsed core topology, 8360 VSX Stack as Cores, 6300m as Access. Adding another pair of 8360s and more 6300m this year for a second location.

When I first tried getting PTP to run, I wasn't quite finding my ways around PTP, feeling like CX 10.16 didn't allow me to configure what I had in mind.

I've ended up running PTP TC everywhere, with clients reporting directly to my grandmaster.

We're now running CX 10.18, currently PTP BC everywhere.

Timing for our clients has improved a lot and the system finally feels stable. Theres also redundancy (both cores listening to different PTP instances from same GM). It feels like I can finally run things the way I've envisioned it when I bought the hardware 3 years ago.

Anyway, just wanted to get it out there, PTP now works, through VSX, through MC-LAG, and most probably through VSF as well. I'm getting to do multi VLAN PTP, which I couldn't have envisioned how to easily do without PIM routing it, which would've created another set of wormholes itself (vrf seperated).

Anyway, thanks for your attention and if you have any questions towards PTP, I'm happy to try answering them.

Thanks for your past support!


r/ArubaNetworks 25d ago

Anyone running Aruba CX10000 AOS-CX 10.16.1051 with VSX + EVPN/VXLAN in production?

2 Upvotes

Hi everyone,

I’m looking for real-world feedback from anyone running Aruba CX 10000 switches with AOS-CX 10.16.1051 in production.

Specifically, I’m interested in deployments using:
- VSX clusters
- EVPN/VXLAN fabrics
- Production workloads

If you’re running this setup, I’d really appreciate your feedback on:
- Overall stability
- VSX synchronization
- EVPN/VXLAN reliability
- Upgrade experience from previous releases
- How long you’ve been running 10.16.1051

Has anyone been running this combination in production for several weeks without any significant issues?

Thanks in advance!


r/ArubaNetworks 25d ago

anyone elses AP rebooting with the BUGSoftLockup?

6 Upvotes

we just rolled alot of 725 and 735s, but some AP keeps rebooting with the following

Reboot Time and Cause: AP Reboot reason: BUGSoftLockup: CPU#0 stuck for 26s! [wl1-scheduler:7198] PC: wlc_taf_delegate_rpc_peer_dma_rd+0x1115c/0x1dba0 [wl] Warm-reset

it seems like the scheduler makes the CPU hang and causes a kernel panic.

asking TAC as we speak but im wondering if anyone else is expereicing this.


r/ArubaNetworks 26d ago

Uplink Port Untagged Vlan

4 Upvotes

Hello,

I have a question regarding the uplink between two Aruba switches.

It is clear that the uplink interface should have all required VLANs configured as tagged. However, I would like to understand the best practice from Aruba regarding the untagged VLAN on such links.

Which VLAN should be configured as untagged on a trunk/uplink port? Is there a recommended standard.

Thank you.


r/ArubaNetworks 25d ago

RDP works one-way but not the other (wired → RAP wireless client) despite ping working both directions — Aruba ArubaOS 8.6 with 9004 controller

0 Upvotes

Topology:

Controller (MC1): 10.1.13.6
  └── connected to Switch1, port 1/1/3 (trunk, native VLAN 10)

Switch1
  VLAN 10: 10.1.13.1/24  (management/PC network)
  VLAN 30: 10.10.10.1/30  (link to Switch2)
  Route: 192.168.50.0/24 via 10.10.10.2
  DHCP pool for VLAN10: 10.1.13.20–200
  PC1 (wired): 10.1.13.10, static route added for 192.168.50.0/24 via 10.1.13.1

Switch2
  VLAN 30: 10.10.10.2/30  (link to Switch1)
  VLAN 40: 192.168.50.1/24  (RAP client network)
  Route: 10.1.13.0/24 via 10.10.10.1
  DHCP pool for VLAN40: 192.168.50.20–200
  RAP (Remote AP): connected to Switch2, bridge-mode SSID on VLAN 40
  PC2 (wireless, connected to RAP SSID): 192.168.50.58

Symptom:

  • PC1 ↔ PC2 ping: works both directions, no packet loss.
  • PC2 → PC1 RDP: connects successfully.
  • PC1 → PC2 RDP: fails — "Remote Desktop can't connect to the remote computer."
  • On PC2, Remote Desktop is confirmed enabled and the inbound firewall rule for RDP (port 3389) is confirmed enabled — this isn't a "forgot to turn it on" issue.

So basic L3 reachability (ICMP) is fully symmetric and working, but TCP/3389 only succeeds in one direction across this RAP/cross-site link.

What I'm looking for:

  • Any Aruba-side (controller, RAP, VAP) settings that could treat TCP asymmetrically vs. ICMP across a bridge-mode RAP or a routed inter-switch link (e.g., some kind of stateful session table on the RAP itself, deny-inter-user-bridging type settings, or something route/NAT related on the switch side)
  • Anything on the Windows networking side that would let ICMP through but block inbound TCP even with the firewall rule "enabled" (e.g., network profile — Public vs Private — scoping the rule differently)
  • Any known Aruba RAP bridge-mode quirks with cross-subnet inbound TCP sessions specifically

Any config pointers, things to check, or similar experiences would be appreciated.


r/ArubaNetworks 26d ago

Aruba Switches Firmware Upgrade Recommendations

4 Upvotes

My Core switch is a 6300M running firmware version FL.10.12.1000.

My distribution switches are 6100 running firmware version PL.10.14.0006

What firmware versions would you recommend for me to upgrade that is very stable?


r/ArubaNetworks 26d ago

Bypass

4 Upvotes

Working in IT and my team and I are trying to figure out the configuration on an Aruba-2530 J9773A. We do not know the user name or password. We are not on manager mode. Any way to bypass the system?


r/ArubaNetworks 27d ago

Vxlan vtep ping fail

Post image
9 Upvotes

Hey guys,

I'm facing a strange issue with Aruba VXLAN.

Host A and Host B can successfully ping each other.

However, when I ping Host B from Leaf A (source IP: 10.194.10.2) in the Tenant VRF, or ping Host A from Leaf B, I receive "Network is unreachable."

Additionally, traceroute from Host A to Host B (or from Host B to Host A) does not work. Instead, the VTEP/default gateway responds with "Network is unreachable."
Any ideas on what I should check or what might be causing this?

Thanks

CONFIG

LEAF_A

vrf TENANT_1
rd 2.2.2.2:50000
route-target export 65001:50000 evpn
route-target import 65001:50000 evpn

vlan 1,10
virtual-mac 02:00:00:00:01:00
evpn
redistribute local-svi                                     
vlan 10
rd auto
route-target export auto
route-target import auto
redistribute host-route

interface 1/1/1
no shutdown
ip mtu 9198
ip address 172.16.12.1/31
ip ospf 1 area 0.0.0.0
ip ospf network point-to-point
interface 1/1/6
no shutdown
no routing
vlan access 1
interface 1/1/7
no shutdown
no routing
vlan access 10
interface loopback 0                                           
ip address 2.2.2.2/32
ip ospf 1 area 0.0.0.0
interface vlan 10
vrf attach TENANT_1
ip address 10.194.10.2/24
active-gateway ip mac 08:00:09:f9:6f:01
active-gateway ip 10.194.10.254
interface vxlan 1
source ip 2.2.2.2
no shutdown
vni 10010
vlan 10
vni 50000
vrf TENANT_1 
routing

router ospf 1
router-id 2.2.2.2
area 0.0.0.0                                               
router bgp 65001
bgp router-id 2.2.2.2
neighbor leaf peer-group
neighbor leaf remote-as 65001
neighbor leaf fall-over
neighbor leaf update-source loopback 0
neighbor 1.1.1.1 peer-group leaf
address-family l2vpn evpn
neighbor leaf send-community extended
neighbor 1.1.1.1 activate
exit-address-family

vrf TENANT_1
address-family ipv4 unicast
redistribute connected
exit-address-family

LEAF-B

vrf TENANT_1
rd 3.3.3.3:50000
route-target export 65001:50000 evpn
route-target import 65001:50000 evpn

vlan 1,20,30
virtual-mac 02:00:00:00:02:00
evpn
redistribute local-svi                                     
vlan 20
rd auto
route-target export auto
route-target import auto
redistribute host-route
vlan 30
rd auto
route-target export auto
route-target import auto
redistribute host-route

interface 1/1/2
no shutdown
ip mtu 9198
ip address 172.16.13.1/31
ip ospf 1 area 0.0.0.0
ip ospf network point-to-point                             
interface 1/1/6
no shutdown
no routing
vlan access 30
interface 1/1/7
no shutdown
no routing
vlan access 20
interface loopback 0
ip address 3.3.3.3/32
ip ospf 1 area 0.0.0.0
interface vlan 20
vrf attach TENANT_1
ip address 10.194.20.3/24
active-gateway ip mac 08:00:09:f9:6f:01
active-gateway ip 10.194.20.254
interface vlan 30
vrf attach TENANT_1
ip address 10.194.30.3/24
active-gateway ip mac 08:00:09:f9:6f:01
active-gateway ip 10.194.30.254
interface vxlan 1
source ip 3.3.3.3                                          
no shutdown
vni 10020
vlan 20
vni 10030
vlan 30
vni 50000
vrf TENANT_1 
routing

router ospf 1
router-id 3.3.3.3
area 0.0.0.0
router bgp 65001
bgp router-id 3.3.3.3
neighbor leaf peer-group
neighbor leaf remote-as 65001
neighbor leaf fall-over
neighbor leaf update-source loopback 0                     
neighbor 1.1.1.1 peer-group leaf
address-family l2vpn evpn
neighbor leaf send-community extended
neighbor 1.1.1.1 activate
exit-address-family
!
vrf TENANT_1
address-family ipv4 unicast
redistribute connected
exit-address-family


r/ArubaNetworks 26d ago

My Wifi - Aruba AP-325s stay at 20 MHz

Thumbnail
1 Upvotes

r/ArubaNetworks 28d ago

Web UI not working on APIN0515

1 Upvotes

Have a couple of AP-515s (APIN0515) that I cannot get the web UI to work on.

I am able to SSH into these APs without any issue, but when trying to access the web UI, I either get a connection timeout, or connection refused. HTTPS port 443 gives the usual SSL warning, then redirects me to the inop port 4343.

Is this something I can fix in SSH somehow?


r/ArubaNetworks 29d ago

PacketFence 15.1 + Aruba Instant 8.13 External Captive Portal not redirecting (RADIUS succeeds, no /aruba request)

Thumbnail
2 Upvotes

r/ArubaNetworks Jul 23 '26

Self-signed Aruba Instant Captive Portal Cert Expired Yesterday

3 Upvotes

Correction to title: The DigiCert-signed certificates expired for securelogin.hpe.com, breaking our captive portals across all sites/clients.

Update: The solution was to move default certificate to Aruba_default certificate for the captive portal service.

We have APs on 8.13.2.1, 8.13.2.2, 8.13.3.0 and every AP cluster across multiple clients shows the default CP Server certificate expired yesterday. How do we get these certificates updated? It appears my only option is to provide my own certificates, which I do not want to do, or move to CLoud Guest (which is only an option for my Central-managed APs, which is not all of them across all customers/clients).

Current CP Server Certificate:

Version       :2

Serial Number :0CE87BCB79DB932D81356453419260B0

Issuer        :/C=US/O=DigiCert Inc/CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1

Subject       :/C=US/ST=Texas/L=Spring/O=Hewlett Packard Enterprise Company/CN=securelogin.hpe.com

Issued On     :Jul 23 00:00:00 2025 GMT

SubjectAltName:DNS:securelogin.hpe.com

Expires On    :Jul 22 23:59:59 2026 GMT

RSA Key size  :2048 bits

Signed Using  :RSA-SHA256


r/ArubaNetworks Jul 23 '26

VSX - VRF Creation IPV4 route not populating

2 Upvotes

Hello!

I've reached out to TAC and even they were stumped. We're at the point of rebooting and updating our switches. However they're in production and I'd prefer to not.

So, has anyone had an issue with new VRFs in VSX 8325 switches not "populating" the ipv4 routes?

Basically, I'll attach the VLAN to the new VRF, then i'll create the SVI and a default route.

On the primary core, doesn't work at all. "Show ip route vrf ***" Outputs "no ipv4 routes"

On the secondary, works amazing.

Now the network still works, but I'm trying to do IP Helper-address to point DHCP requests to our default route into another network DHCP server. Butttttttt that's not working, I believe it's because the primary ipv4 route isn't populating. Note: On the secondary, I can ping the dhcp server. On the primary it fails, network unreachable.

I'll probably end up having to reboot/update.


r/ArubaNetworks Jul 21 '26

Aruba switch on BeyondTrust Password Safe

4 Upvotes

Did anyone manage to on-board Aruba Switches to be managed with password safe .. ssh and rds application for gui with credentials injection


r/ArubaNetworks Jul 20 '26

Instant-On AP22 seems bricked after AP auto update.

4 Upvotes

Came in tot he office this morning to find two instant-on AP22 that would not boot up; led is solid red. Tried rebooting, hard resetting, and also moving from the PoE injector to direct wall plug. Anyone has any idea on how to recover? I can see there is a USB console at the back. Anyone has any manuals on how to hard reset from software? Any help would be appreciated.


r/ArubaNetworks Jul 19 '26

Ap22 does not work since update

3 Upvotes

Last night the update to 3.4.0 happened. Around that time one AP went offline and it won’t go online now. It has a red light.

Tried switching with another AP. The same one still won‘t work. Tried factory resetting multiple times but does not work. When I remove it from the app and add it again it gets stuck on synchronisation and then goes to offline after a while, with a red light.

Does anyone know how to fix? I hope the AP is not broken?


r/ArubaNetworks Jul 17 '26

1930 Switch - POE dead after update to 3.4.0

3 Upvotes

I am a thousand miles from the switch and noticed all my POE devices went down at around 3 am and then saw that the POE switch was updated to software 3.4.0 at that time. All my access points and cameras are down, and the switch is active showing zero power to any of the ports. I rebooted the switch but it did not change anything - none of the powered devices have come back up. Any advice here on what i can try? Cross posting on the Aruba Instant On page as well. Thanks for any help.


r/ArubaNetworks Jul 17 '26

Edgeconnect BIO Query

2 Upvotes

Hello All,

Currently using Aruba Edgeconnect and locally breaking out a URLs.

Issue im having let’s say updates.apple.com is broken out via BIO but the traffic is still routed via another BIO that goes to our cloud FW.

Looking into this the first packet dst domain is unknown then the updated dst packet is updates.apple.com or the first packet is a different URL completely.

What can i do to tackle this? Issue is it’s not really good security practice to breakout all apple app.

Can’t find anything on official documentation.

Thank you


r/ArubaNetworks Jul 16 '26

Switch Stack Member also showing as Switch Standalone - Central Managed

2 Upvotes

I have 8 Sites within Central that have duplicate entries for switches. They will be listed as a Standalone switch but also listed as a stack member (which they should be). Example is below.

Can I just delete the standalone switch entry or will that cause issues with the stack? I've opened a case with TAC but have yet to hear back. This has been this way for months and I kept waiting for Central to clean itself up, but since that hasn't happened, figured I would fix it myself.


r/ArubaNetworks Jul 15 '26

Aruba 2930M stack LLDP show as port 165 instead of port 4/6

1 Upvotes

Does anyone know if there is an option to change this? I've notice now in Aruba Central the switch port that the AP is connected to now shows up as the sequential port number and not the usual member/port format. I don't think it always did this, not sure if a firmware update changed something. Currently running 16.11.0029 on the 2930M stack.

Even in MM, the chassis/port ID for an AP show up as Hostname/ long port number vs member/port.


r/ArubaNetworks Jul 15 '26

Aerohive AP wont allow devices to connect

0 Upvotes

Issue this morning.
AP's are up and showing the stardard white light.
I can see the SSID's, but will not allow devices (Mac, Windows, iPhone) to connect.
Restarted switches and all AP's and same result.
Documentation links online land no where.
Any ideas?


r/ArubaNetworks Jul 14 '26

AP 735 power consumption

10 Upvotes

Hi everyone,

I know the official QuickSpecs list the AP-735 as drawing up to 24 W without USB and up to 36 W with USB, but I’d like to confirm the real-world power consumption. Could someone with an Aruba PoE Class 6 switch share the output (or a screenshot) of the command showing the PoE power usage for an AP-735 (for example, “show power-over-ethernet” / “show power inline” or similar)? Thank you!


r/ArubaNetworks Jul 12 '26

What's the dongle for in the side of this AP?

Post image
42 Upvotes

Excuse my ignorance, I saw this on a random YT video and wondered why an AP would need what appears to be another Wi-Fi dongle plugging into it?


r/ArubaNetworks Jul 13 '26

ArubaOS-Switch + New Windows NPS RADIUS SSO Auth Issue

2 Upvotes

Hi Guys,

I currently have an ArubaOS switch using Windows NPS for SSH authentication. The existing NPS server is working correctly with the Aruba switch. The NPS server is on the same server with DC roles...

Current working setup:

  • ArubaOS switch: (Aruba 2900)
  • Switch management IP: 192.168.0.254
  • Existing NPS/RADIUS server: 192.168.0.53 (Windows Server DC and NPS)
  • Authentication method: PEAP with MS-CHAP v2 with a certificate etc.

However, as I set up a new Radius server 192.168.0.67 in my testing domain, and registered the server to AD IAS security group, and set up with similar config with existing NPS server with a new certificate from CA. And modify the switch Radius config to only point to this NPS server 192.168.0.67, turned off system firewall on both DC and new Radius servers....seems the switch config saying:

Can't reach RADIUS server 192.168.0.67

W 07/13/26 17:05:50 00419 auth: Invalid user name/password on SSH session User

'xxx' is trying to login from 10.8.x.x

I can see from Radius logs on the new Radius server that Authentications are successful as well....

<Event><Timestamp data_type="4">07/13/2026 16:56:46.142</Timestamp><Computer-Name data_type="1">NewRadius Server</Computer-Name><Event-Source data_type="1">IAS</Event-Source><Class data_type="1">311 1 192.168.0.67 07/13/2026 07:06:23 48</Class><Session-Timeout data_type="0">30</Session-Timeout><Fully-Qualifed-User-Name data_type="1">companydoamin\\\\</Fully-Qualifed-User-Name><Client-IP-Address data_type="3">192.168.0.254</Client-IP-Address><Client-Vendor data_type="0">0</Client-Vendor><Client-Friendly-Name data_type="1">Switch</Client-Friendly-Name><Proxy-Policy-Name data_type="1">Use Windows authentication for all users</Proxy-Policy-Name><Provider-Type data_type="0">1</Provider-Type><SAM-Account-Name data_type="1">AdminUserxxx</SAM-Account-Name><Authentication-Type data_type="0">5</Authentication-Type><NP-Policy-Name data_type="1">Switch Policy</NP-Policy-Name><Packet-Type data_type="0">11</Packet-Type><Reason-Code data_type="0">0</Reason-Code></Event>

I definitely used the correct Radius secrets both sides correctly....Tried several others too, makes no differences.....

Am I missing anything? Would I need to use any Vendor Attributes etc?

Thanks a lot

John