677| Advanced Security DellPowerConnect W- Series ArubaOS 6.2 | User Guide
Securing Controlle r-to-Controller Communication
xSecc an be used to secure data and control traffic passed between two Dell controllers. The only requirement is that
both Dell controllersbe members of the same VLAN. To establish a point-to-point tunnel between the two Dell
controllers,you need to configure the following for the connecting ports on each controller:
lThe MAC addresso ft hexSec tunnel termination point. This would be the MAC address of the “other”
controller.
lA 16-byte shared key used to authenticate the Dell controllersto each other. You must configure the same shared
key on both Dell controllers.
lThe VLAN IDs for the VLANs that will extend across both the Dell controllers via the xSec.Fi gure279 shows an
examplenetwork where two Dell controllers are connected to the same VLAN, V LAN 1. On controller1, y ou
configurethe MAC address of controller2 for the xSec tunnelt ermination point. On controller2, y ou configure
the MAC address of controller1 for the xSec tunnel termination point. On both Dellco ntrollers,you configure
the same 16-byte shared keyand the ID s for theV LANs which are allowedto pass through the xSectunnel.
Figure 279: Controller-to-ControllerxSecE xample

Configuring Co ntrollers for xSec

The followingsecti ons describehow to use the WebUI or CLI to configure the port that connects to the wired
network on which theo therco ntrolleris installed. Other chapters in this manualdescribe the configuration of
VLANs.
In the WebUI
1. On each controller, navigate to the Configuration > Network > Port page.
2. Click on the port to be configured.
3. Select the VLA N fromthe drop-down list.
4. Co nfigurethe xSec point-to-point setti ngs:
a. Enter the MAC addresso f thet unneltermination point (the “other” controller’s MAC address).
b. Enter the key (for example, 123456789 8765432) used by xSec to establish the tunnel between the Dell
controllers.
c. Select the VLANs that would be allowedacross the point-to-point connection from the Allowed VLANs drop-
down menu,and click the <-- button.
5. Click A pply.
In the CLI
For Controller1:
interface gigabitethernet|fastethernet slot/port
vlan 1
xsec point-to-point 10:11:12:13:14:15 1234567898765432 allowed vlan 101,200,250
For Controller2:
interface gigabitethernet|fastethernet slot/port