Controller Based WLANs

 View Only
last person joined: one year ago 

APs, Controllers, VIA

How do I address the issue where APs have a “Denied” flag on the controller? 

Jul 05, 2014 02:23 AM

Question:  How do I address the issue where APs have a “Denied” flag on the controller?

 

Product and Software: This article applies to all Aruba APs and ArubaOS 5.0 and later.


In a new deployment, the AP might have a "Denied" flag on the controller. This happens if we have CPsec enabled on the controller.
To check for flags, issue the "show AP database" command:

 

1441_image001.png

 

 

When an AP tries to come up on the controller when CPsec is enabled, the AP tries to establish an IPsec tunnel to the controller to start the communication. The controller validates the certificate in the AP against the internal whitelist. So unless you add the AP in the campus whitelist, it will show up as "Denied".

 

 

You can get rid of this problem in three ways.

 

  • Disable the Control-plane security.

 

Using the WebUI

1441_image002.png

 

 

Using the CLI

1441_image003.png

 

 

  • Enable "Auto Cert Provisioning" with CPsec enabled under the CPsec configuration tab.

 

  • With CPsec enabled and "Auto Cert Provisioning" disabled, add the APs in the campus whitelist and select the appropriate option to change the state of the AP.

To check the campus whitelist, issue this command:

 

If you have APs that have factory certificates (AP-105, AP-12x, AP-13x), select them from the campus whitelist and update them.

 

1441_image005.png

 

 

If you have legacy AP like AP-61, which do not have factory certificates, select "approved-ready-for-cert".

1441_image006.png

 

 

After this update, the AP generates the CSR and tries to communicate with the controller.

1441_image007.png

 

 

This can take a while. After generating the CSR successfully, the AP comes up on the controller.

1441_image008.png

 

 

Statistics
0 Favorited
21 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.