Users Guide

Table Of Contents
Controller Role Campus AP Whitelist
Master Controller
Whitelist
Local Controller
Whitelist
On a (standalone)
master controller
with no local
controllers:
The campus AP whitelist
contains entries for the secure
campus APs associated with
that controller.
The master
controller whitelist is
empty, and does not
appear in the WebUI.
The local controller
whitelist is empty,
and does not appear
in the WebUI.
On a master
controller with local
controllers:
The campus AP whitelist
contains an entry for every
secure campus AP on the
network, regardless of the
controller to which it is
connected.
The master
controller whitelist is
empty, and does not
appear in the WebUI.
The local controller
whitelist contains an
entry for each
associated local
controller.
On a local
controller:
The campus AP whitelist
contains an entry for every
secure campus AP on the
network, regardless of the
controller to which it is
connected.
The master
controller whitelist
contains the MAC
and the IP addresses
of the master
controller.
The local controller
whitelist is empty,
and does not appear
in the WebUI.
Table 16: Control Plane Security Whitelists
Figure 6 Local Controller Whitelist on a Master Controller
If your deployment includes both master and local controllers, then the campus AP whitelist on every
controller contains an entry for every secure AP on the network, regardless of the controller to which it is
connected. The master controller also maintains a whitelist of local controllers using control plane security.
When you change a campus AP whitelist on any controller, that controller contacts the other connected
controllers to notify them of the change.
The master controller whitelist on each local controller contains the IP and MAC addresses of its master
controller. If your network has a redundant master controller, then this whitelist contains more than one entry.
You rarely need to delete the master controller whitelist. Although you can delete an entry from the master
controller whitelist, you should do so only if you have removed a master controller from the network.
Campus AP Whitelist Synchronization
The current sequence number in the AP Whitelist Sync Status field shows the number of changes to the
campus AP whitelist made on that controller. Each controller compares its campus AP whitelist against
whitelists on other controllers every two minutes by default. If a controller detects a difference, it sends its
Dell Networking W-Series ArubaOS 6.5.x | User Guide Control Plane Security |
62