Users Guide

Table Of Contents
390 | Control Plane Security Dell PowerConnect ArubaOS 5.0 | [User Guide
controller to act as the primary controller, you can increase that controller’s priority after the settings have been
resynchronized
Troubleshooting Control Plane Security
Certificate Problems
If an AP has a problem with its certificate, check the state of the AP in the campus AP whitelist. If the AP is in
either the certified-hold-factory-cert or certified-hold-controller-cert states, you may need to manually change
the status of that AP before it can be certified.
z certified-hold-factory-cert: An AP is put in this state when the controller thinks the AP has been certified with
a factory certificate yet the AP requests to be certified again. Since this is not a normal condition, the AP will
not be approved as a secure AP until a network administrator manually changes the status of the AP to verify
that it is not compromised. If an AP is in this state due to connectivity problems, then the AP will recover and
will be out of this hold state as soon as connectivity is restored.
z certified-hold-controller-cert: An AP is put in this state when the controller thinks the AP has been certified
with a controller certificate yet the AP requests to be certified again. Since this is not a normal condition, the
AP will not be approved as a secure AP until a network administrator manually changes the status of the AP to
verify that it is not compromised.If an AP is in this state due to connectivity problems, then the AP will
recover and will be out of this hold state as soon as connectivity is restored.
Disabling Control Plane Security
If you disable control plane security on a standalone or local controller, all APs connected to that controller will
reboot then reconnect to the controller over a clear channel.
If your disable control plane security on a master controller, APs directly connected to the master controller will
reboot then reconnect to the master controller over a clear channel. However, its local controllers will continue to
communicate with their APs over a secure channel until you save your configuration on the master controller.
Once you save the configuration, the changes are pushed down to the local controllers. At that point, any APs
connected to the local controllers will also reboot and reconnect over a secure channel.
Verify Whitelist Synchronization
To verify that a network of master and local controllers are correctly sharing their campus AP whitelists, check the
sequence numbers on the master and local controller whitelists.
z The sequence number value on a master controller should be the same as the remote sequence number on the
local controller.
z The sequence number value on a local controller should be the same as the remote sequence number on the
master controller.