You're right it's confusing! I tried assigning the wlan to the device groups, but no joy.
I put the AP into the gateway group (after enabling AP support), the AP is up but now the radios are disabled!
-------------------------------------------
Original Message:
Sent: May 22, 2026 09:49 AM
From: willembargeman
Subject: New Central MPSK issues
For Bridge mode SSID's there is no AAA profile created. This is only for tunneled SSID's.
Regarding the assignment. That is the most important and confusing part at this moment.
Make sure the gateways and APs are assigned to the same group at this moment. If you assign the profile Global the SSID is not broadcasted. Also make sure the VLAN is assigned to the scope or higher level (global).
There is an option to use auto-site and that will give the possibility to assign tunneled WLAN profiles globally. However, this is correctly an allow-listed feature. I think is good to discuss this with your HPE Networking SE.
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
------------------------------
Original Message:
Sent: May 22, 2026 09:32 AM
From: cauliflower
Subject: New Central MPSK issues
Thanks for the info Willem.
I recreated the wlan and this time there is an AAA profile, so that's an improvement. When I went through the process again I realised that I may have left it in bridged mode instead of tunnel, so that might explain the AAA profile anomaly I guess?
So now I have the wlan and I created an auth profile in CentralNAC that references it.
The wlan is scoped to Global at the moment - this would be our ideal as we want to have our 4 basic wlans inherited everywhere below. However the SSID is now not broadcasting! I have a feeling my colleague had an issue like this some time ago (unfortunately he is on holiday) and the issue was something to do with the client VLAN referenced in the wlan. I can't remember exactly but I guess if the gateways test that VLAN and it isn't reachable then the SSID doesn't get broadcast? Does that ring any bells with you?
Guy
Original Message:
Sent: May 22, 2026 07:39 AM
From: willembargeman
Subject: New Central MPSK issues
It's correct that 'show ap database' doesn't show any AP. With AOS10 the Gateways are 'just' used for traffic termination. The APs are controlled by Central.
Did you create the WLAN profile at library level and assigned the WLAN profile to the Group? At this moment the group most contain both the Gateways and APs.
You are correct. An AAA profile should be auto created during the WLAN profile creation. That is probably the reason why you see MAC auth failures. There is always (also for an open SSID) MAC auth between the AP and Gateway.
Can you try to create a new SSID and see if the AAA profile is created? If not, I suggest to open a TAC case
------------------------------
Willem Bargeman
Systems Engineer Aruba
ACEX #125
Original Message:
Sent: May 22, 2026 06:52 AM
From: cauliflower
Subject: New Central MPSK issues
A quick follow up on this - we have a test version of the MPSK wlan set up in our dev workspace and strangely that does have an AAA profile which looks like it has been auto-generated as the name has a long seemingly random number suffixed, that profile has MAC auth server set to be CentralNAC. But there's no equivalent AAA profile for the MPSK wlan that I set up in our 'live' workspace. Seems like there should be?