Cloud Managed Networks

 View Only
  • 1.  Central: CX switches and Authentication Server Groups

    Posted Feb 09, 2026 08:07 AM

    Hi,

    Is it  possible to have multiple named RADIUS/TACACS server groups in Central for switches? From what I can tell, you can only add a servers into predefined groups (cloud, radius, tacacs), but not create a new server group using the central GUI? The below is all I see and there is no + sign to add another group as you can from the switch. 

    I can create the server group by using 'MultiEdit' (not ideal) and configuring the servers and the group as you usually would if it was not a central managed switch, but the group still doesn't show in central under 'device>security>authentication servers>server groups'. It is also not visible in any the places you'd want to reference it e.g. 'device>system>administrator>authentication' or 'device>security>authentication>802.1x authentication'. 

    Am I missing something? I'd have thought this would be something simple/others would have stumble across this alrady. 

    For additional information behind the 'why' of this post: We have radius servers already servicing things like management access to the switch. We're looking to apply AAA to the ports using CPPM, but as I can't specify the group, I can't control which radius severs to send things to. 



    -------------------------------------------


  • 2.  RE: Central: CX switches and Authentication Server Groups

    Posted Feb 10, 2026 06:08 AM

    I don't believe you can have multiple server groups in the UI of Classic Central.


    New Central has full support for multiple Server groups, but converting switches to New Central should only be done after carefull evaluation as there are quite a few features that are not supported yet, and New Central removes the fallback option of using CLI/muliteditor. In other words:  there are no workarounds for using switch features not supported in the UI yet.

    -------------------------------------------



  • 3.  RE: Central: CX switches and Authentication Server Groups

    Posted Feb 10, 2026 08:29 PM

    yes with New Central you can have multiple server groups. This is what i have setup in my lab



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: Central: CX switches and Authentication Server Groups

    Posted Feb 11, 2026 09:18 AM
    Edited by kb1 Feb 11, 2026 09:31 AM

    @AP-e172d8 I'm using old central, but what you've got there is exactly what I need, shame it's not in old central. 

    I also found that if i apply any authentication related config to the port e.g. concurrent auth via the GUI, it undoes my RADIUS group that i created via multiedit.

    Basically, not great!

    -------------------------------------------



  • 5.  RE: Central: CX switches and Authentication Server Groups

    Posted Feb 11, 2026 09:30 AM
    Edited by kb1 Feb 11, 2026 09:31 AM

    @TM-cf9237 my subsequent digging his found the same. 

    Do you know where you can find the features missing from new-central? It's currently on the 'do not even consider' pile, I'd feel exposed without having a multiedit option, the confidence just isn't there. 

    -------------------------------------------



  • 6.  RE: Central: CX switches and Authentication Server Groups

    Posted Feb 11, 2026 09:43 AM
    Edited by TM-cf9237 Feb 11, 2026 09:44 AM

    Unfortunately no. I don't think there is compiled list of every AP/Switch/Gateway feature that has not yet been made available in the UI.

    It would be a TREMENDOUSLY long list at this point. Even "simple" things are missing - like fx. the ability to enable 10G support on all MACSEC 25G ports of the 8360 series switches.
    So If you have those switches you need to make sure you have enough ports to leave the MACSEC ports unused if you only have 10Gbe Infrastructure.

    -------------------------------------------