Figure 21: A Cluster of Master Controllersusing Control Plane Security
To create a controller cluster,yo u must first define the root master controller and set an IPsec key or select a
certificate for communications between the cluster root and cluster members.
NOTE:You m ustuse the command-li ne interfaceto configure certificate authentication for cluster members. The WebUI supports
clusterauthentication using IPsec keys only. If your masterand l ocal Dell controllers use a pre-shared keyfor authentication, they
createthe IPsec tunnel using IKEv1. If your master and local Dell controllers use certificates forauthentication, the IPsec tunnel is
createdusing IKEv2.
Creating a Cluster Root
Use the WebUI to identify a controller as a clusterroot and usean IP sec key to secure communication between the
clusterroot and clustermembers. Use the command-line interface to create a cluster root usi ngan I Psec key, factory-
installedcertific ate or custom certificate.
To create a cluster root using the WebUI:
1. Access the WebUI of the controlleryou want to beco met hecluster root, and navigate
toConfiguration>Controller.
2. Click the Cluster Sett ing tab.
3. For the cluster role, select Root.
4. In t heCluster Member IPsec Keys section, enter thes witch IP address of a memberco ntrollerin the cluster. If
you want to use a single key for allmember Dell controllers,use the IP address 0.0.0.0.
5. In t heIPsec Key and Retype IPsec Key fields, enter the IPsec key for communication between the specified
membercontroller and the cluster root.
6. Click Add.
7.

Optional

: repeatsteps 4-6 to add another member controllerto the cluster.
8. Click Apply to save yours ettings
To create a clusterroo t via the CLI, access the command-linei nterfaceof the controller you want to become the
root of the controller cluster,then issue one of t hefollowing commands.
lTo authenticate cluster members using a custom certificate:
cluster-member-custom-cert member-mac <mac> ca-cert <ca> server-cert <cert> suite-b <gcm-
128 | gcm-256>]
lTo authenticate cluster members using a factory-installedcertifi cate.
cluster-member-factory-cert member-mac <mac>
lTo authenticate cluster members using an IPsec key:
cluster-member-ip <ip-address> ipsec <key>
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide ControlPlane Security |91