Cloud Managed Networks

 View Only
  • 1.  Downloadable User Role in Classic Central for SD-Branch can't find it

    Posted Nov 26, 2025 11:52 AM

    I am configuring an SD-Branch with 9004s with the APs tunneling to the controllers. I wanted to see if I could use downloadable user roles on these devices but am stuck.

    When trying to follow along with the techdocs, I see step 8, 9 below:

    Step 8 says: The Access tab is displayed

    Step 9 says: Turn on the Downloadable Role toggle switch to allow downloading of pre-existing user roles. The CPPM Settings table with NameCPPM Username, and Actions columns related to the radius servers are displayed.

    When I try to do this myself, there is no "Downloadable Role" toggle switch (see below)

    A screenshot of a computer

AI-generated content may be incorrect.

    Ignoring this part, I went along and try to at least configure the RADIUS settings in Central

    A screenshot of a computer

AI-generated content may be incorrect.

    I think I can remember a few months back that there was a similar checkbox as I am familiar with in AOS8 called: "Download Role from CPPM", unfortunately, this box is nowhere to be found.

    A screenshot of a computer

AI-generated content may be incorrect.

    I cannot find anything in the documentation and the search option in Central isn't giving me anything either.

    One interesting observation is that when I configure a gateway in the "default" group I do see the checkbox (see below)

    A screenshot of a computer

AI-generated content may be incorrect.

    It would be great if someone can guide me through the steps to activate the downloadable user role for SD-Branch.



    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------


  • 2.  RE: Downloadable User Role in Classic Central for SD-Branch can't find it

    Posted Nov 26, 2025 05:17 PM

    downloadable user roles is only for Instant APs not AOS10 APs. the online help you references indicates that it is for IAPs but the wording can be improved.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Downloadable User Role in Classic Central for SD-Branch can't find it

    Posted Nov 27, 2025 10:17 AM

    Hi Ariyap,

    Thanks for clarifying this,  that helps a lot. I understand that with SD-Branch some policy enforcement happens at the branch, but it still feels like a gap that this isn't clearly documented. It would be really helpful if the documentation explicitly stated which capabilities (security, policy enforcement, segmentation, etc.) are managed centrally vs those that can be pushed through ClearPass for example. Unfortunately, this happens too often.



    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------



  • 4.  RE: Downloadable User Role in Classic Central for SD-Branch can't find it

    Posted Nov 27, 2025 05:44 PM

    sure I'll feed it back to improve the wording.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------