allot hermaster and local Dell controllers as soon as the new controlleris added to the hierarchy. If any old or invalid
AP entries are added to the campus AP whitelist, all Dell controllersin the hierarchy begins trusting those APs,
creating a potential security risk.Fo radditi onalinformation on adding a new local controller usingco ntrolplane
security to your network, see "Replacing a Local Controller" on page 93
To purgea co ntroller’scampus AP whitelist via t heWebUI:
1. Access the master controller WebUI, and navigate to Configuration>AP Installation .
2. Click the CampusAP Whitelist tab.
3. Click Purge.
To purgea campus AP whitelistvia the command-line interface, issue the command:
whitelist-db cpsec purge
Managing Whiteli sts on Master and Loca l Controllers
Every controllerusing the control plane security feature maintains a campusA P whitelist, a local switch whitelist
and a master switch whitelist. The contents of these whitelists vary, depending upon the role of the controller, as
shown in the figure below.

ControllerRole Campus AP Whitelist Master Switch

Whitelist

Local Switch

Whitelist

Ona (standalone) master
controller with no local
Dell controllers:
Thecam pus AP whitelist contains
entriesfor the secure campus APs
associatedwith that controller.
Them asterswitch
whitelist is empty, and
doesnot appear i n the
WebUI.
Thel ocal switch whitelist
isem pty, and does not
appeari n theW ebUI.
Ona master controller
with local Dell
controllers:
Thecam pus AP whitelist contains an
entryfor every secure campus AP on
thenetwork, regardl essof the
controller tow hich it is connected.
Them asterswitch
whitelist is empty, and
doesnot appear i n the
WebUI.
Thel ocal switch whitelist
containsan entry for
eachassociated local
controller.
Ona Local control ler: Thecam pus AP whitelist contains an
entryfor every secure campus AP on
thenetwork, regardl essof the
controller tow hich it is connected.
Them asterswitch
whitelist contains the
MACand IP addressof
themaster controller.
Thel ocal switch whitelist
isem pty, and does not
appeari n theW ebUI.

Table18 :

ControlPlane Security Whitelists

Figure 19: Local Switch Whitelist on a Master Controller
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide ControlPlane Security | 87