Wireless Access

 View Only
Expand all | Collapse all

AOS 10/New Central: Role Based VLAN assignment not working

This thread has been viewed 39 times
  • 1.  AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 03, 2026 04:18 PM

    I'm piloting a small device group with AOS 10.4.11_94853 and the New Central interface...  I've created a role and set its VLAN ID, but it I keep getting dropped into the WLAN Profile's "Default VLAN" instead of the VLAN assigned to my role.

    The only way I can get it to drop users into the appropriate VLAN is to use the WLAN Profile's "VLAN Assignment Rules"

    Am I missing something?  I thought Role-Based VLAN assignment was the preferred method in AOS 10?

    Thank you!



    -------------------------------------------


  • 2.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 03, 2026 07:28 PM

    well the authentication server should tell the AP to use the user role based on the policy. So in your case are you authenticating users on the WLAN?

    Generally the user connects to dot1x WLAN and the RADIUS server will send accept and Aruba-user-role VSA matching with the configured user-role.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 04, 2026 05:05 PM

    I have 2 separate WLAN profiles:  One using Central NAC with an Entra backed Identity Store, and the other is MPSK-AES with Central NAC... Neither one is dropping users into the desired VLAN.

    Am I correct to assume that I should just stick to Dynamic VLAN rules on the WLAN profile?

    Thank you!

    -------------------------------------------



  • 4.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 04, 2026 07:34 PM

    for this to work, you need to configure user roles with assigned VLANs. If you have this in place then you need to call it in from your Central NAC authz policies.

    Overview of authentication and authorization policies in Central NAC



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 06, 2026 10:40 AM

    I have tried to assign the VLAN using a Central NAC Authorization Policy, but I do not have a "VLAN ID" attribute option like what is shown in the documentation you referenced...  The only option I get is "Session Timeout" as shown here:

    -------------------------------------------



  • 6.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 06, 2026 07:40 PM

    I am not sure why you don't see VLAN id attribute in CNAC authz policies, But generally I use user-roles.

    you can assign VLAN id in your roles too. see here my contractor role has VLAN id 12



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 7.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 07, 2026 04:49 PM

    Using the VLAN ID from the User-Role would be my preferred method, but it is ignoring that setting and putting the users into the default VLAN of the WLAN profile instead...  I'm lost as to why that is taking precedence over the user-role.

    Thank you! 

    -------------------------------------------



  • 8.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 07, 2026 09:40 PM

    Have you done all the configuration in New Central ? including the WLAN configuration?



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 9.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 08, 2026 05:03 PM

    Yes sir... Everything was done through New Central...  I followed along with this Aruba lab guide.  The only thing that differed was the roles themselves.  The guide mentions using some pre-built lab roles that obviously didn't exist in my system, so I created one at the Library level and then assigned it to "Campus Access Point" with a Global scope:

    -------------------------------------------



  • 10.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 08, 2026 10:28 PM

    check if at the device levels you can see the user roles that you want. if they are there then it must be the authorization policy that is configured in Central NAC. 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 11.  RE: AOS 10/New Central: Role Based VLAN assignment not working
    Best Answer

    Posted Apr 09, 2026 09:49 AM

    Roles have to be assigned to Global (for now). Also, roles have to have a Role Policy associated, which may be on Site Level (but Global also works).

    In the screenshot, the Role-BYOD has no reference from a policy.

    Roles that don't have an associated policy (that has to be assigned to the device function and site of the device) will not be propagated to an AP.

    If Role-BYOD is not on your AP, add a policy for the Role-BYOD and check again.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 12.  RE: AOS 10/New Central: Role Based VLAN assignment not working

    Posted Apr 09, 2026 03:19 PM

    That was it... Thank you!!!

    I was unable to associate the BYOD role to the sys_allow_all policy, so I created a new policy that mirrored it and assigned that to my role... Now my users are dropping into the desired (role-based) VLAN rather than the default from the WLAN profile.

    Thank you both for all of your time and assistance!

    -------------------------------------------