Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide Control Plane Security | 381
Figure 67 Local Controller Whitelist on a Master Controller
If your deployment includes both master and local controllers, then the campus AP whitelist on every controller
contains an entry for every secure AP on the network, regardless of the controller to which it is connected. The
master controller also maintains a whitelist of local controllers using control plane security. When you change a
campus AP whitelist on any controller, that controller contacts the other connected controllers to notify them of
the change.
The master controller whitelist on each local controller contains the IP and MAC addresses of its master
controller. If your network has a redundant master controller, then this whitelist will contain more than one entry.
The master controller whitelist rarely needs to be deleted. Although you can delete an entry from the master
controller whitelist, you should do so only if you have removed a master controller from the network.
Campus AP Whitelist Synchronization
The current sequence number in the AP Whitelist Sync Status field shows the number of changes to the campus
AP whitelist made on that controller. By default, each controller compares its campus AP whitelist against
whitelists on other controllers every two minutes. If a controller detects a difference, it will send its changes to the
other controllers on the network. If all other controllers on the network have successfully received and
acknowledged all whitelist changes made on that controller, every entry in the sequence number column in the
local controller or master controller whitelists will have the same value as the sequence number displayed in the
AP Whitelist Sync Status field. If a controller in the master or local controller whitelist has a lower sequence
number, that controller may still be waiting to complete its update, or its update acknowledgement may not have
yet been received. In the example in Figure 67, the master controller has a current sequence number of 3, and
each sequence number in its local controller whitelist also shows a value of 3, indicating that both local controllers
have received and acknowledged all three campus AP whitelist changes made on the master controller. For
additional information on troubleshooting whitelist synchronization, see “Verify Whitelist Synchronization” on
page390.
On a master controller
with local controllers:
The campus AP whitelist contains an
entry for every secure campus AP on
the network, regardless of the
controller to which it is connected.
The master controller
whitelist is empty, and does
not appear in the WebUI.
The local controller
whitelist contains an entry
for each associated local
controller.
On a Local controller: The campus AP whitelist contains an
entry for every secure campus AP on
the network, regardless of the
controller to which it is connected.
The master controller
whitelist contains the MAC
and IP address of the
master controller.
The local controller
whitelist is empty, and
does not appear in the
WebUI.
Table 73 Control Plane Security Whitelists
Controller Role Campus AP Whitelist
Master Controller
Whitelist
Local Controller
Whitelist