Users Guide

Table Of Contents
436 | Control Plane Security Dell PowerConnect W-Series ArubaOS 6.1 | User Guide
certified on the network will also be included in the campus AP whitelist, but these APs will appear in an
unapproved state.
Use the campus AP whitelist to grant valid APs secure access to the network, or to revoke access from suspected
rogue APs. When you revoke or remove an AP from the campus AP whitelist on a controller that uses control
plane security, that AP will not be able to communicate with the controller again, except to obtain a new
certificate.
You can add an AP to the campus AP whitelist via the WebUI or command-line interface. To add an entry via the
WebUI, use the following procedure.
1. Access the WebUI, and navigate to Configuration>AP Installation.
2. Click the Campus AP Whitelist tab.
3. To add a new AP to the whitelist, click New.
4. Define the following parameters for each campus AP you want to add to the campus AP whitelist.
5. Click Add to add the information to the campus AP whitelist.
6. Click Apply to save your changes.
To add an AP to the Campus AP whitelist via the command-line interface, issue the command
whitelist-db cpsec add mac-address <macaddr> description <description>
Viewing Entries in the Campus AP Whitelist
Once you have added an entry in the Campus AP whitelist, that entry will be updated with additional
information as the status of the AP changes. To view current information for an AP in the campus AP whitelist via
the WebUI:
1. Access the WebUI, and navigate to Configuration>AP Installation.
2. Click the Campus AP Whitelist tab. The Campus AP whitelist table includes the following information for
each AP entry.
NOTE: If you manually add APs to the campus AP whitelist (rather than automatically adding the APs via the automatic certificate
provisioning feature), make sure that the whitelist has been synchronized to all other controllers on the network before enabling
control plane security.
Table 80 Configure Campus AP Whitelist Parameters
Parameter Description
AP MAC Address MAC address of a campus AP that should support secure communications to and from
its controller.
Description (Optional) Use this field to add a brief description of the campus AP.
Table 81 View Campus AP Whitelist Parameters
Parameter Description
AP MAC Address MAC address of the campus AP.
Cert Type The type of certificate used by the AP.
switch-cert: The campus AP is using a certificate signed by the controller.
factory-cert: the campus AP is using a factory-installed certificate. This option
should only be used for AP model typesW-AP105, the W-AP120 Series and the
W-AP130 Series.