T Techclick ← All lessons
HPE Aruba Networking · Evidence desk · Interactive lesson

Prove Aruba is working — first tool + proof field

01:40. Slack: “Is Aruba even working?” The CIO is already in the channel. A phone photo of Wi-Fi bars is not proof. This desk is five official surfaces — Central / controller client Status, 802.1X and MAC auth logs, role assigned, AP / controller health, ClearPass Access Tracker when NAC is in the path — each mapped to one ticket, one first click, and one field you paste before you reboot an AP.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

After this page you can

Quick answer (say this out loud)

Client Status answers “did this MAC even land a session?” Auth logs answer “did 802.1X or MAC-auth fail, and at which Failure Stage?” Role answers “what did they become — AP Role / Gateway Role / user-table Role, and who derived it?” AP / controller health answers “is the radio or managed device even up?” Access Tracker answers “what did ClearPass Accept or Reject, and which Enforcement Profile sent Aruba-User-Role?” A green Wi-Fi icon is not a role. An Accept is not the right role. An Up AP is not a healthy client.

1. Why “is it working?” is five questions

Operators collapse five failures into one sentence. The laptop never associated. 802.1X rejected. The role is logon instead of contractor. The AP is Down on the managed device. ClearPass sent the wrong Enforcement Profile. Those are five first clicks.

This page is the night-shift desk for proof. The factory taught the session: associate → authenticate → role → VLAN → role ACL → RF last. Here you learn the five tools you actually open, in order, when someone asks you to prove Aruba is working.

Hero · five tiles, one ticket
Night-shift operations desk with five glowing Aruba proof tiles on a wall monitor
Notice: five tiles, not one “Aruba dashboard.” You pick the tile that matches the question, then you quote one field.
Interview line

If they say “prove Aruba is working,” do not say “I opened Central.” Say: “I prove the session with client Status, the handshake with Failure Stage or show auth-tracebuf, the enforcement word with AP Role / Role and role-how, the radio with AP status, and NAC with Access Tracker Login Status plus Enforcement Profiles.”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you reboot a healthy AP at 02:00.

1 · Client Status

Central Manage → Clients (List). Proves whether this MAC is Connecting, Connected, Offline, Failed, or Blocked. Controller twin: show user-table. Does not prove the role is correct or that ClearPass sent it.

2 · Auth logs

Central Client Details → Failed Wireless Client Events, column Failure Stage. Controller twin: show auth-tracebuf mac <mac> (and failures). Proves 802.1X / MAC-auth / association / key-exchange / DHCP / captive-portal. Does not prove AP Role.

3 · Role assigned

Central columns AP Role and Gateway Role. Controller: show user-table field Role plus verbose role-how. Proves what they became and how it was derived. Does not prove the radio is up.

4 · AP / controller health

Central Manage → Devices → Access Points (Online / Offline). Controller: show ap database status up|down. Proves the AP exists and is up on that managed device. An Up AP is not a Connected client.

5 · Access Tracker

ClearPass Monitoring → Live Monitoring → Access Tracker. Proves NAC: Login Status (Accept / Reject / Timeout) + Enforcement Profiles + Output Aruba-User-Role. Open this only when RADIUS / ClearPass is in the path.

Hard words, once

Status = Central connection state. Failure Stage = why a Failed wireless client stopped. role-how = AOS derivation code (1–8). Aruba-User-Role = RADIUS VSA (1) on the Access-Accept. Health 0–100 is a pointer, not a role.

Flow 1 · five tools, one question each
Write user + MAC + UTC first · then pick the tool Is Aruba working? five questions, not one Client Status Session landed? Connected / Failed Manage → Clients or show user-table not a role verdict Auth logs 802.1X / MAC? Failure Stage auth-tracebuf Client Details → Failed not an AP reboot Role assigned What did they become? AP Role · Role role-how 1–8 Clients list / user-table not AirMatch AP health Radio / MD up? Online / Offline status up | down Devices → Access Points not a user allow Access Tracker What did NAC send? Login Status Enforcement Profiles Live Monitoring NAC path only Empty user-table is data. It usually means the session never landed — or you are on the Conductor. Do not invent a role ACL from an empty table. Start at Status, then the managed device that owns the AP.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the session, then the handshake, then the role, then the radio, then NAC. I do not reboot an AP, rewrite a user-role, or blame AirMatch until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open the RF planner or the Enforcement Profile editor until a diamond says so.

Path · pick the branch before the menu
Abstract diamond splitting into five Aruba proof paths
Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Session on the wire? or already inside? Laptop / “Wi-Fi down” Client Status Connected / Failed Auth rejected Failure Stage 802.1X / MAC Connected, app fail AP Role / Role role-how Whole floor dark AP / MD health status up | down NAC in the path Access Tracker Login Status Status = Failed or empty user-table → stop. There is no AP Role to chase. Fix association / 802.1X / the managed device that owns the AP. Then re-open Role. Diamond = decision. Do not lock a channel from the bottom box. Classic Central path is Manage → Clients. New Central still starts at the Clients list. Confirm the UI you operate.

Read the diamond first. A Failed client never starts in AirMatch. Connected + wrong app never starts in AP reboot. Empty user-table on the Mobility Conductor never starts in a role ACL.

4. How to choose — first tool + proof field

Print this next to Central. If you cannot recite the proof field, you are not ready to change anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
Laptop / “am I even on Aruba?” / Wi-Fi icon looks odd Central Manage → Clients (filter MAC / username). Controller: show user-table Status = Connecting / Connected / Offline / Failed / Blocked — or a user-table row for that MAC A channel lock or AP reboot
802.1X or MAC-auth failed after an AAA change Central All Clients → Client Details → Failed Wireless Client Events. Controller: show auth-tracebuf mac <mac> Failure Stage (Association / MAC authentication / 802.1X / Key exchange / DHCP / Captive Portal) — hover for the error type AirMatch / RF planner
Wi-Fi connected; file share / VLAN / app denied Same Clients list, columns AP Role + Gateway Role. Controller: show user-table + verbose role-how AP Role / Role name + role-how (1–8). Then datapath only if the role is the one you expected A site survey
Whole floor / wing dark after 02:00 Central Manage → Devices → Access Points. Controller: show ap database status down (filter group) AP status up or down · Health Bar Online count · which managed device the AP registered with A user-role rewrite
NAC in the path — Accept but wrong access, or Reject ClearPass Monitoring → Live Monitoring → Access Tracker Login Status + Service + Enforcement Profiles + Output Aruba-User-Role Rebooting a healthy AP
Conductor caveat (official)

AOS 8 Mobility Conductor holds config and services. It does not terminate client datapath. show user-table on the Conductor is often empty even when the campus is fine. Official show ap database can filter switch <managed-device-ip> so you land on the box that actually owns the AP. Empty table on the wrong box is not “Aruba is down.”

role-how codes (AOS 8 show user-table verbose) — official derivation table
CodeOfficial meaningWhat you say on the bridge
1AAA profile default roleFallback from the AAA profile — not a ClearPass VSA
2Role derived from user rulesController user-rule matched
3Role derived from UDRUser-derived role
4Default role for authentication typedot1x / mac / captive default — often logon
5Role derived from server rulesServer derivation on the NAD
6HPE Aruba Networking VSAAruba-User-Role landed — now check the name
7Dot1X profile role802.1X profile default, not the server
8Dot1X server derived roleServer-side 802.1X derivation

Source: HPE Aruba CLI Bank — show user-table. Quote the code. Do not guess “ClearPass sent it” when role-how is 1 or 4.

5. Runbook Side A → B → C

Side A proves the session and the handshake. Side B proves the role and the radio. Side C proves NAC when ClearPass is in the path. On a messy Sev-2, do them in this order until a field lights up.

Side A — Session + auth (Central or controller)

  1. Prove the MAC has a session

    Classic Central: filter to the site, then Manage → Clients, List view. Search the username or MAC. Official columns include Client Name, Status, IP Address, VLAN, Connected To, AP Role, Gateway Role, Health. Quote Status. Connecting / Connected / Offline / Failed / Blocked are the documented values (Failed and Blocked are wireless-only). Source: All Clients Monitoring in List View; Clients (unified).

  2. If you are on a controller, use the official table — not a screenshot

    show user-table (filter mac / authentication-method dot1x|mac). Official columns: Name, Role, Age(d:h:m), Auth, AP name. Empty table: confirm you are not on the Mobility Conductor, then show ap database switch <md-ip> to find the managed device that registered the AP. Source: CLI Bank — show user-table; show ap database.

  3. If Status is Failed, read Failure Stage — do not reboot

    Click the client → Client Details → Failed Wireless Client Events. Official Failure Stage values: Association error, MAC authentication error, 802.1X authentication error, Key exchange error, DHCP error, Captive Portal error. Hover the stage for the error type. Controller twin: show auth-tracebuf mac <mac> and show auth-tracebuf failures. Source: Failed Wireless Client Events; Client Connectivity troubleshooting; CLI Bank — show auth-tracebuf.

  4. If both 802.1X and MAC-auth ran, do not invent a second RADIUS

    Official Client Details note: when a client connects through 802.1X and MAC authentication, Central displays only the IP address of the server that performed 802.1X. Quote that server IP. Do not declare “MAC-auth has no server” from a blank MAC-auth IP.

central.arubanetworks.com · Manage → Clients
Training mock · not live

Manage / Clients / List view

All Clients

aa:bb:cc:dd:ee:ff
Failed
Pune-Lab
Last 15 minutes
Client NameStatusIP AddressVLANConnected ToAP RoleHealth
finance.userConnected10.10.8.2120AP-LAB-16authenticatedGood 82
aa:bb:cc:dd:ee:ffFailedAP-LAB-17

Source: HPE Aruba TechDocs — All Clients; All Clients Monitoring in List View (Client Name, Status, IP Address, VLAN, Connected To, AP Role, Gateway Role, Health Poor 0–30 / Fair 31–70 / Good 71–100). Status values: Connecting, Connected, Offline, Failed, Blocked. Lab identities only. Training mock · not live.

central.arubanetworks.com · All Clients → Client Details → Failed Wireless Client Events
Training mock · not live

All Clients / Client Details / Failed Wireless Client Events

Failed Wireless Client Events

aa:bb:cc:dd:ee:ff
AP-LAB-17
Time (UTC)SSIDFailure StageAuth
01:42:11Corp802.1X authentication errordot1x
01:41:58CorpAssociation error
Hover Failure Stage (official): type of error.
Controller twin: show auth-tracebuf mac aa:bb:cc:dd:ee:ff
show auth-tracebuf failures

Source: HPE Aruba TechDocs — Failed Wireless Client Events or Reasons; Client Connectivity troubleshooting (Failure Stage: Association, MAC authentication, 802.1X authentication, Key exchange, DHCP, Captive Portal). CLI Bank — show auth-tracebuf [count | failures | mac]. Training mock · not live.

Side B — Role + AP / controller health

  1. Quote AP Role (and Gateway Role if a gateway is in the path)

    On the same Clients list, official columns are AP Role (“Role assigned by the AP”) and Gateway Role (“Role assigned by the Aruba Gateway”). Click the client for Overview. A Connected client with AP Role = logon or authenticated when you expected contractor is a role ticket, not an RF ticket. Source: All Clients; Wireless Client Details.

  2. On the controller, quote Role + role-how

    show user-table field Role, then verbose for role-how. Code 6 means the HPE Aruba VSA landed — the name still has to match a local user-role. Codes 1 and 4 mean a default / AAA fallback. Do not blame ClearPass until role-how says the VSA actually arrived. Source: CLI Bank — show user-table.

  3. If the floor is dark, prove AP status — not the client Health score

    Central Health Bar / Manage → Devices → Access Points → Online (or Offline) in List view. Controller: show ap database status down, optionally group <ap-group>. Official status values are up and down. Device Health on the operate dashboard is a pointer to that list. Client Health 0–100 (Poor / Fair / Good) is a different column — it is not AP Online. Source: The Health Bar; Monitoring with Central VSG; show ap database.

Controller — fields you write in the ticket
Path:            show user-table   /   show user-table mac aa:bb:cc:dd:ee:ff
Quote:           Name + Role + Auth + AP name
Then verbose:    role-how   (1–8, official derivation codes)
Auth filter:     authentication-method dot1x | mac | opensystem | psk | web
If empty:        show ap database switch <managed-device-ip>
AP health:       show ap database status down   (optional: group <ap-group>)

Side C — ClearPass Access Tracker (only if NAC is in the path)

  1. Open Access Tracker, not the Enforcement Profile editor

    Path: Monitoring → Live Monitoring → Access Tracker. Official filters include Request ID, Source, Username, NAS IP Address, NAS Name, Service, Host MAC Address, Auth Type, Auth Method, Roles, Enforcement Profiles. Filter Username or Host MAC + the UTC window. Source: Live Monitoring: Access Tracker (ClearPass 6.11 / 6.10).

  2. Read Login Status, then Service, then Enforcement Profiles

    Login Status is Accept, Reject, or Timeout. That is the RADIUS outcome. Then quote Service (which policy pipeline matched) and Enforcement Profiles (what was applied). Accept + the wrong profile is still a policy miss.

  3. Open RADIUS Request Details → Output for the VSA

    Official session-details page: click the request, then the Output tab — attributes sent to the NAD. For an Aruba controller / AP / gateway, the VSG template is Aruba RADIUS Enforcement with Type Radius:Aruba, Name Aruba-User-Role (1). Letter case must match the NAD user-role. If Output has no Aruba-User-Role, the NAD will land a default (role-how 1 or 4). Source: Viewing Access Tracker Session Details; VSG Client Services Configuration.

clearpass.lab.example · Monitoring → Live Monitoring → Access Tracker
Training mock · not live

Monitoring / Live Monitoring / Access Tracker

Access Tracker

finance.user
aa:bb:cc:dd:ee:ff
10.10.4.1
Accept
Request IDUsernameServiceLogin StatusEnforcement Profiles
W00001242-01-labfinance.user802.1X WirelessAcceptOWL_Authenticated
W00001241-01-labguest.kioskMAC Auth WiredReject
RADIUS Request Details → Output (lab):
Type: Radius:Aruba Name: Aruba-User-Role (1) Value: authenticated
Desk expected: contractor — Accept + wrong VSA is still a policy miss.

Source: ClearPass 6.11 — Monitoring → Live Monitoring → Access Tracker (Request ID, Username, NAS IP Address, Service, Login Status Accept/Reject/Timeout, Enforcement Profiles); Viewing Access Tracker Session Details (Output tab); VSG — Aruba RADIUS Enforcement / Aruba-User-Role (1). Lab identities only. Training mock · not live.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

TicketSymptomFirst toolProof field
AEVD-01Laptop: “Wi-Fi is broken, Aruba is down”Manage → Clients / show user-tableStatus Connected / Failed / Offline — or no row
AEVD-02After an AAA change, Corp 802.1X failsClient Details → Failed Events / show auth-tracebufFailure Stage = 802.1X authentication error
AEVD-03Connected on Corp; file share denied; RSSI fineClients list AP Role / user-table RoleAP Role + role-how (then datapath only if role is expected)
AEVD-04Floor 4 dark since 02:00; client list empty for that AP groupManage → Devices → Access Points / show ap database status downAP status down · which managed device
AEVD-05NAC on; Access-Accept; desk expected contractorAccess TrackerLogin Status + Enforcement Profiles + Output Aruba-User-Role

AEVD-01 — Prove the session (Client Status)

01:42 · P2. Priya on a hotel-adjacent campus SSID. Phone photo of Wi-Fi bars. L1 already booked a site survey and drafted an AP reboot for AP-LAB-17.

First tool: Manage → Clients, search her MAC. Controller: show user-table mac aa:bb:cc:dd:ee:ff on the managed device that owns the AP — not on the Conductor.

If Failed / Offline / no row: quote Status. There is no AP Role to hunt. Next is Failure Stage (AEVD-02) or AP health (AEVD-04) — not AirMatch.

If Connected: you proved the session. Now you are allowed to read AP Role, VLAN, and Connected To. Status is not the role.

Trap

Do not trust a colleague’s Central filter set to a different site. The proof is this MAC, this UTC window. Empty user-table on the Mobility Conductor is expected — move to the managed device.

AEVD-02 — Prove the handshake (auth logs)

02:05 · P2. After last night’s AAA profile push, Corp 802.1X fails for one laptop. Someone wants “disable 802.1X and use PSK until morning.”

First tool: Client Details → Failed Wireless Client Events. Filter that MAC. Controller: show auth-tracebuf mac aa:bb:cc:dd:ee:ff and show auth-tracebuf failures.

Proof field: Failure Stage = 802.1X authentication error (not Association, not DHCP). Hover for the error type. That stage is the ticket. If the stage is MAC authentication error, you are on a MAC-auth SSID / port — do not debug PEAP.

Close

I would not convert Corp to PSK. I would quote Failure Stage + the UTC stamp, then open Access Tracker only if NAC is the authenticator. A reconnect that stays Failed with no new event means you are on the wrong client or the wrong window.

AEVD-03 — Prove the role (AP Role / Role + role-how)

02:20 · P2. finance.user is Connected on Corp. RSSI looks fine. File share 10.20.0.10 fails. L1 wants a channel walk.

First tool: Clients list AP Role (and Gateway Role if traffic hits a gateway). Controller: show user-tableRole, then verbose role-how.

Proof field: AP Role = authenticated, role-how = 6 (VSA) or 1 (AAA default). The factory taught: role is the enforcement word. If the role is already the intended contractor role, then read datapath (show datapath session) for the ACL hit. If the role is wrong, datapath will only confirm the wrong role is doing its job.

Close

I would not start a site survey at −58 dBm. I would quote Role + role-how. RF is allowed only after those two agree with the intended design. See the session factory for why role comes before RF.

AEVD-04 — Prove the radio (AP / controller health)

02:40 · P1. Floor 4 lost Corp after 02:00. Clients list for that AP group is empty. L1 wants AirMatch disabled and every AP rebooted.

First tool: Manage → Devices → Access Points, or Health Bar → Access Points → Online. Controller: show ap database group <floor4-group> status down.

Proof field: AP status flipped to down on the managed device that should own those CAPs. Simultaneous 02:00 death of a whole group is almost never “everyone’s 802.1X cookie expired together.” If every AP is still up and clients are Failed, you are back on AEVD-02 — do not reboot Up APs.

Trap

Client Health 42 is Poor (0–30) / Fair (31–70). That score is not AP Offline. Do not declare a floor outage from one laptop’s Health bar.

AEVD-05 — Prove NAC (Access Tracker)

03:00 · P2. Contractor cannot reach staff VLAN. Central Status = Connected, AP Role = authenticated. Someone wants both ClearPass nodes restarted.

First tool: ClearPass Monitoring → Live Monitoring → Access Tracker. Filter Username / Host MAC + last 30 minutes.

Proof field: Login Status = Accept, Service = 802.1X Wireless, Enforcement Profiles = OWL_Authenticated, Output Aruba-User-Role (1) = authenticated. The NAD did what it was told. Fix the profile (or the service order that picked it). If Login Status = Reject, quote Alerts / Error Code — a node restart will not rewrite a reject policy. If there is no request, the NAS never sent RADIUS — that is Side A / AAA on the controller, not ClearPass.

Close

I would not restart a healthy ClearPass pair. I would paste Request ID + Login Status + Enforcement Profiles + the Output VSA. Letter case on Aruba-User-Role must match the NAD. A missing VSA explains role-how 1 or 4.

7. Traps + close-the-ticket proof

Proof · named field, then Closed
Operations desk with abstract green health checks and one highlighted Aruba proof field
Notice: the close is a named column on a timestamp, not a screenshot of the user’s Wi-Fi settings pane.
You seeWeak closeStrong close
Status = Failed / empty user-table“Aruba is down” / reboot AP-LAB-17Quote Status; open Failure Stage or AP status; confirm managed device
Status = Connected, still failing“Aruba is fine”You only proved the session. Read AP Role / role-how
AP Role looks populated“Policy is working”Name the role and role-how. Wrong role is still a miss
AP status = Up“SSID must be fine”Up is the radio registration. Status Failed can still sit on an Up AP
Access Tracker Accept“NAC is fine” / restart ClearPassQuote Enforcement Profiles + Output Aruba-User-Role
No Access Tracker rowClearPass is downNAS never sent RADIUS — auth-tracebuf / AAA on the NAD first
Client Health 42Floor Sev-1 / disable AirMatchHealth is 0–100 on the client. Prove AP status and the hop separately
Empty user-table on Conductor“No one is associated”Conductor is not the datapath. show ap database switch <md-ip>
802.1X + MAC both configuredTwo RADIUS servers must answerOfficial: Central shows only the 802.1X server IP
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. Client Status proves the session. Failure Stage / auth-tracebuf proves the handshake. AP Role / Role + role-how proves enforcement. AP status proves the radio. Access Tracker proves NAC. I do not reboot an AP, rewrite a user-role, or disable AirMatch until that field is on the ticket. Factory model: role is the enforcement word.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

User: “Is Aruba even working?” You have not opened a role ACL yet. First proof?

Correct: b. Official session check. Failed / empty means there is no AP Role to hunt. Re-read Side A step 1 and AEVD-01.
Q2

An AAA change shipped an hour ago. Corp 802.1X fails for one laptop. Which proof field closes AEVD-02?

Correct: a. Official Failure Stage values include 802.1X authentication error. Health is 0–100. AirMatch is RF last. Re-read Side A steps 3–4 and AEVD-02.
Q3

Floor 4 went dark at 02:00. Clients for that AP group are empty. First tool + field?

Correct: c. Empty clients is the clue the radios or the managed device never landed. AP status up/down is the official pair. Cookies stagger. Re-read Side B step 3 and AEVD-04.
Q4

finance.user is Connected on Corp. File share fails. RSSI is −58 dBm. First tool + proof?

Correct: b. Role is the enforcement word. Connected is the session. RSSI is not a role. Re-read Side B and AEVD-03. Factory: role before RF.
Q5

Central Status is Connected. AP Role is authenticated. The desk expected contractor. NAC is in the path. What do you do first?

Correct: d. Accept + wrong VSA is still a policy miss. Restarting healthy nodes is change-control. Re-read Side C and AEVD-05.
Q6

show user-table is empty on the box you logged into. What is that allowed to mean?

Correct: a. Official Conductor vs managed-device split. Empty table is data. Re-read the Conductor caveat, Flow 2 bottom box, and AEVD-01.

Sources

Related: Blog 1 · Aruba session factory · ClearPass policy pipeline · WLAN SSID and roles · Central Live Troubleshooting · HPE Aruba practice hub