That was it... Thank you!!!
I was unable to associate the BYOD role to the sys_allow_all policy, so I created a new policy that mirrored it and assigned that to my role... Now my users are dropping into the desired (role-based) VLAN rather than the default from the WLAN profile.
-------------------------------------------
Original Message:
Sent: Apr 09, 2026 09:49 AM
From: Herman Robers
Subject: AOS 10/New Central: Role Based VLAN assignment not working
Roles have to be assigned to Global (for now). Also, roles have to have a Role Policy associated, which may be on Site Level (but Global also works).
In the screenshot, the Role-BYOD has no reference from a policy.
Roles that don't have an associated policy (that has to be assigned to the device function and site of the device) will not be propagated to an AP.
If Role-BYOD is not on your AP, add a policy for the Role-BYOD and check again.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Apr 08, 2026 05:03 PM
From: scott
Subject: AOS 10/New Central: Role Based VLAN assignment not working
Yes sir... Everything was done through New Central... I followed along with this Aruba lab guide. The only thing that differed was the roles themselves. The guide mentions using some pre-built lab roles that obviously didn't exist in my system, so I created one at the Library level and then assigned it to "Campus Access Point" with a Global scope:


Original Message:
Sent: Apr 07, 2026 09:39 PM
From: ariyap
Subject: AOS 10/New Central: Role Based VLAN assignment not working
Have you done all the configuration in New Central ? including the WLAN configuration?
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
Original Message:
Sent: Apr 07, 2026 04:49 PM
From: scott
Subject: AOS 10/New Central: Role Based VLAN assignment not working
Using the VLAN ID from the User-Role would be my preferred method, but it is ignoring that setting and putting the users into the default VLAN of the WLAN profile instead... I'm lost as to why that is taking precedence over the user-role.
Thank you!
Original Message:
Sent: Apr 06, 2026 07:40 PM
From: ariyap
Subject: AOS 10/New Central: Role Based VLAN assignment not working
I am not sure why you don't see VLAN id attribute in CNAC authz policies, But generally I use user-roles.
you can assign VLAN id in your roles too. see here my contractor role has VLAN id 12

------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
Original Message:
Sent: Apr 06, 2026 10:39 AM
From: scott
Subject: AOS 10/New Central: Role Based VLAN assignment not working
I have tried to assign the VLAN using a Central NAC Authorization Policy, but I do not have a "VLAN ID" attribute option like what is shown in the documentation you referenced... The only option I get is "Session Timeout" as shown here:

Original Message:
Sent: Apr 04, 2026 07:33 PM
From: ariyap
Subject: AOS 10/New Central: Role Based VLAN assignment not working
for this to work, you need to configure user roles with assigned VLANs. If you have this in place then you need to call it in from your Central NAC authz policies.
Overview of authentication and authorization policies in Central NAC
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
Original Message:
Sent: Apr 04, 2026 05:05 PM
From: scott
Subject: AOS 10/New Central: Role Based VLAN assignment not working
I have 2 separate WLAN profiles: One using Central NAC with an Entra backed Identity Store, and the other is MPSK-AES with Central NAC... Neither one is dropping users into the desired VLAN.
Am I correct to assume that I should just stick to Dynamic VLAN rules on the WLAN profile?
Thank you!
Original Message:
Sent: Apr 03, 2026 07:28 PM
From: ariyap
Subject: AOS 10/New Central: Role Based VLAN assignment not working
well the authentication server should tell the AP to use the user role based on the policy. So in your case are you authenticating users on the WLAN?
Generally the user connects to dot1x WLAN and the RADIUS server will send accept and Aruba-user-role VSA matching with the configured user-role.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.