Users Guide

Table Of Contents
Dell Networking W-Series ArubaOS 6.5.x | User Guide Control Plane Security | 50
Chapter 2
Control Plane Security
ArubaOS supports secure IPsec communications between a controller and campus or remote APs using public-
key self-signed certificates created by each master controller. The controller certifies its APs by issuing them
certificates. If the master controller has any associated local controllers, the master controller sends a
certificate to each local controller, which in turn sends certificates to their own associated APs. If a local
controller is unable to contact the master controller to obtain its own certificate, it is not be able to certify its
APs, and those APs cannot communicate with their local controller until master-local communication has been
reestablished. You create an initial control plane security configuration when you first configure the controller
using the initial setup wizard. The ArubaOS initial setup wizard enables control plane security by default, so it is
very important that the local controller be able to communicate with its master controller when it is first
provisioned.
Some AP model types have factory-installed digital certificates. These AP models use their factory-installed
certificates for IPsec, and do not need a certificate from the controller. Once a campus or remote AP is certified,
either through a factory-installed certificate or a certificate from the controller, the AP can failover between
local controllers and still stay connected to the secure network, because each AP has the same master
controller as a common trust anchor.
Starting with ArubaOS 6.2, the controller maintains two separate AP whitelists; one for campus APs and one for
Remote APs. These whitelists contain records of all campus APs or remote APs connected to the network. You
can use a campus or AP whitelist at any time to add a new valid campus or remote AP to the secure network, or
revoke network access to any suspected rogue or unauthorized APs.
The control plane security feature supports IPv4 campus and remote APs only. Do not enable control plane security
on a controller that terminates IPv6 APs.
When the controller sends an AP a certificate, that AP must reboot before it can connect to its controller over a
secure channel. If you are enabling control plane security for the first time on a large network, you may
experience several minutes of interrupted connectivity while each AP receives its certificate and establishes its
secure connection.
HPPlatform interoperating with Dell Controllers
Following HP TPM based switches can now inter-operate with the Dell controllers and create the IKE / IPSec
tunnels.
l 2930F
l 5400R/v3 3810
l 5400R/v2 (compat. mode)
l 3800
l 2920
l 2530
l 2620
l 5400/v2
l 5400/v1
l 3500