Users Guide

Table Of Contents
65| Control Plane Security Dell Networking W-Series ArubaOS 6.5.x| User Guide
disconnected from the network. To clear a local controller whitelist entry on a master controller that is still
connected to the network, select that individual whitelist entry and delete it using the delete option.
In the WebUI
To purge a controller whitelist:
1. Navigate to Configuration > Controller.
2. Select the Control Plane Security tab.
3. To clear the Local Controller whitelist: In the Local Switch List For AP Whitelist Sync section, click
Purge.
Or,
4. To clear the Master Controller whitelist: In the Master Switch List For AP Whitelist Sync section, click
Purge.
In the CLI
To purge a controller whitelist:
(host) #whitelist-db cpsec-master-switch-list purge
(host) #whitelist-db cpsec-local-switch-list purge
Working in Environments with Multiple Master Controllers
This section describes the configuration steps required in a multiple master controllers network.
Configuring Networks with Clusters of Master Controllers
If your network includes multiple master controllers each with their own hierarchy of APs and local controllers,
you can allow APs from one hierarchy to failover to any other hierarchy by defining a cluster of master
controllers. Each cluster has one master controller as its cluster root, and all other master controllers as cluster
members. The master controller operating as the cluster root creates a self-signed certificate, then certifies its
own local controllers and APs. Next, the cluster root sends a certificate to each cluster member, which in turn
certifies its own local controllers and APs. Because all controllers and APs in the cluster have the same trust
anchor, the APs can switch to any other controller in the cluster and still remain securely connected to the
network.
Figure 7 A Cluster of Master Controllers using Control Plane Security