Users Guide

Table Of Contents
438 | Control Plane Security Dell PowerConnect W-Series ArubaOS 6.1 | User Guide
2. Click the Campus AP Whitelist tab.
3. Select the checkbox by the entry for the AP you want to edit, then click Modify.
If your campus AP whitelist is large and you cannot immediately locate the AP entry you want to edit, select
the Search link by the upper right corner of the whitelist. The Campus AP Whitelist tab will display several
fields that allow you to search for an AP with a specified MAC address, certificate type or state. Specify the
values that match the AP you are trying to locate, then click the Search button. The whitelist will display a list
of APs that match your search criteria. Select the AP from this list, then click Modify.
4. Update the AP’s whitelist entry with the new settings. Some of the configurable parameters were available
when you first defined the entry, and are described in Table 80 above. When you modify an existing whitelist
entry, you can also configure the following additional parameters that were not configurable when you first
created the entry.
Cert-type: The type of certificate used by the AP.
switch-cert: The campus AP is using a certificate signed by the controller.
factory-cert: the campus AP is using a factory-installed certificate. This option should only be
used for AP model types W-AP105, the W-AP120 Series and the W-AP130 Series.
State: When you click the State drop-down list to modify this parameter, you may choose one of the
following options:
approved-ready-for-cert: AP has been approved state and is ready to receive a certificate.
certified-factory-cert: AP is certified and has a factory-installed certificate.
Revoke: Click the Revoke checkbox to revoke an AP’s secure status. When you select this checkbox, you
will also be allowed to enter a brief comment explaining why the AP is being revoked.
5. Click Update to update the campus AP whitelist entry with its new settings.
To modify an entry in the campus AP whitelist via the command-line interface, issue the following commands:
whitelist-db cpsec modify mac-address
cert-type switch-cert|factory-cert
description <description>
mode disable|enable
revoke-text <revoke-text>
state approved-ready-for-cert|certified-factory-cert
Revoking an AP via the Campus AP Whitelist
You can revoke an invalid or rogue AP either by opening the modify menu and modifying the AP’s revoke status
(as described in the section above), or by selecting the AP in the campus whitelist and revoking it’s secure status
directly, without modifying any other parameters or entering a description of why that AP was revoked. When you
revoke an AP’s secure status in the campus AP whitelist, the whitelist will retain the AP’s status information. To
revoke an invalid or rogue AP and permanently remove the AP from the whitelist, you must delete that entry.
To revoke an AP via the WebUI:
1. Access the master controller WebUI, and navigate to Configuration>AP Installation.
2. Click the Campus AP Whitelist tab.
3. To revoke one or more secure campus APs, select the checkbox by the entry for each AP whose secure status
should be revoked, then click Revoke.
If your campus AP whitelist is large and you cannot immediately locate the AP entry you want to revoke, select
the Search link by the upper right corner of the whitelist. The Campus AP Whitelist tab will display several
fields that allow you to search for an AP with a specified MAC address, certificate type or state. Specify the
values that match the AP you are trying to locate, then click the Search button. The whitelist will display a list
of APs that match your search criteria. Select the AP from this list, then click Revoke.
To revoke an AP via the command-line interface, issue the command: