You are here: CLI_commands > New Commands and Modified Commands in Aruba Instant
Previous TopicNext Topic

What is New in Aruba Instant

This section lists the new and modified commands in the Aruba Instant release.

New Commands

The following commands are added in the Aruba Instant release:

Table 1: New Commands in



console Allows you to enable or disable access to the IAP console.
dpi Enables deep packet inspection (DPI) support and allows you to configure DPI for wired or wireless network users.
inbound-firewall Allows you to configure inbound firewall rules.

Enables accounting privileges on TACACS+ servers for management users in Instant.


Allows you to run tests for RF troubleshooting.

NOTE: In this release, this command is not available in IAP-224/225, and IAP-274/275 platforms.

show console-settings Displays if the console access is enabled or disabled on an IAP.
show dhcp subnets Displays subnet details and gateway IP address for the distributed L2 and L3 networks.
show dpi Displays the DPI configuration details.
show dpi-stats Displays DPI statistics for application, application category, web category and web reputation parameters.
show ap dot11k-beacon-report Displays the beacon report details for the 802.11k clients of an IAP.
show ap dot11k-nbrs Displays neighbors for the 802.11k clients of an IAP.
show inbound-firewall-rules Displays the inbound firewall rule details.
show rft trans-id Displays transaction IDs for the RF test profiles.
show rft profile Displays the profile parameters for the RF tests.
show xml-api-server Displays the XML API server configuration details
wlan tacacs-server Configures a TACACS+ server to authenticate management users in Instant.
xml-api-server Integrates an XML API Interface with an IAP.
zonename Configures zone settings on an IAP.

Modified Commands

The following commands are modified in the Aruba Instant release:

Table 2: Modified Commands in



airgroup This command now allows you to enable DLNA and mDNS (Bonjour services) support on an IAP for the AirGroup enabled clients.
airgroupservice This command now allows you to configure services such as Chromecast, DLNA media, and DLNA print services.
ip dhcp This command now allows you to enable or disable split tunnel for Centralized, L2 clients .
l2tpv3 session This command now allows you enable default l2 specific sublayer for the L2TPV3 sessions.
show airgroup This command now includes the DLNA and MDNS options to filter the output based on the DLNA and Bonjour services (mDNS) configuration status.
show airgroupservice The output of this command now displays the disallowed roles and VLANs for the mDNS and DLNA services.
show access-rule


The output of this command displays the access rules created for DPI.

show access-rule-all
show auth-survivability The debug-log option is added to the command syntax. On running the show auth-survivability debug-log command, the logs for troubleshooting the authentication survivability are displayed.
show dhcps config The output of this command now displays split-tunnel status for centralized,L2 and and DNS caching status for local or local,l2 profiles.
show vpn This command now displays the IAP-VPN retry counter details when the tunnels keyword is used.
wlan access-rule This command now allows you to configure access rules for deep packet inspection. The rule command allows you to create access rules to allow or deny access to certain application, application categories, website categories, and URLs based on security rating. In the current release, you can also configure inbound firewall rules based on source subnet.
wlan ssid-profile This command now allows you to configure AP zone, WMM DSCP traffic mapping, backup authentication server with termination enabled, and enable fast roaming features such as 802.11k and 802.11v. The command also allows you to disable bridging and routing traffic between the clients connected to the same SSID.
arm The maximum threshold value of Client Match has been increased to 255. The previous maximum threshold limit was 20.