Administrator Guide

Table Of Contents
want to locate in these fields, then click Search. The campus APwhitelist displays a list of APs that match
your search criteria. Select the checkbox of the APthat you want to delete, then click Delete.
In the CLI
To delete an AP from the campus AP whitelist:
(host) #whitelist-db cpsec del mac-address <name>
Purging a Campus AP Whitelist
Before adding a new local controller to a network using control plane security, purge the campus AP whitelist
on the new controller. After adding the new controller to the hierarchy, the entries in the campus AP whitelist
of the new controller merge into the whitelist for all other master and local controllers. If you add any old or
invalid AP entries to the campus AP whitelist, all controllers in the hierarchy will trust those APs, creating a
potential security risk. For additional information on adding a new local controller using control plane security
to your network, see Replacing a Local Controller on page 138
In the WebUI
To purge a campus AP whitelist:
1. Navigate to Configuration > Wireless > AP Installation.
2. Click the Whitelist tab.
3. Click the Entries>> button.
4. Click Purge.
In the CLI
To purge a campus AP whitelist:
(host) #whitelist-db cpsec purge
Offloading a Controller Whitelist to ClearPass Policy Manager
This feature allows to externally maintain APwhitelist in a ClearPass Policy Manager (CPPM)server. The
controller, if configured to use an external server, can send a RADIUS access request to a CPPM server. The
MAC address of the AP is used as a username and password to construct the access request packet. The CPPM
server validates the RADIUS message and returns the relevant parameters for the authorized APs.
The following supported parameters are associated with the following VSAs. The CPPMserver sends them in
the RADIUS access accept packet for authorized APs:
l ap-group: Dell-AP-Group
l ap-name: Dell-Location-ID
The following defaults are used when any of the supported parameters are not provided by the CPPM server in
the RADIUS access accept response:
l ap-group: The default ap-group is assigned to the AP.
l ap-name: The MAC address of the APis used as the AP name.
There is no change in the RAP role assignment. The RAP is assigned the role that is configured in the VPN
default-rap profile.
In the WebUI
To assign a CPPM server to a RAP:
1. Configure a CPPM server using the controller WebUI:
a. Navigate to Configuration > Security > Authentication > Servers.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Control Plane Security | 130