Hi Guy and Colin,
A customer noticed that when he changed the AP name in the whitelist on the MM, it did not propagate. I came across this post and checked the whitelist sync. It also turned out to be disabled. However, the disable-whitelist-sync parameter is not set (checked with show configuration effective on /mm and /mm/mynode).
I did this installation in 2018 and remember vaguely having issues with renaming APs. But we had to move fast, so we just deleted the whitelist and put in a new one to be able to move on. This was a greenfield Aruba install on version 8.2 (at the time, upgraded up to 8.5 in the time since past). I can't remember touching the sync setting, it's not in my notes and I was not even aware of it before I read this article...
Will ask the customer to toggle the setting and see what happens.
Regards,
Dante
------------------------------
Dante Klerkx
------------------------------
Original Message:
Sent: Oct 17, 2019 03:49 AM
From: Guy Goodrick
Subject: AOS8 whitelist sync
Morning Colin,
I/we had no intention of touching it until it became apparent that it was disabled! We're not sure how that happened, it must have been during the upgrade/migration process.
It looks like re-enabling it has had the desired effect - the sequence numbers now match (across all MCs except the cluster leader - I will ask TAC if that's normal). However there were still disparities - there were some APs showing as unapproved on the MCs that were showing as certified on the MM. So it seems that enabling sync didn't trigger a complete sync'ing of the existing entries - new entries do appear to be being sync'd though. So it was easy enough to run the commands on the MM to certify those APs and these changes were pushed down to the MCs successfully.
It sort of feels like purging the MC whitelist entries and starting again would be the cleanest solution, but I'm not about to do that on the live system!
Thanks for your help.
Guy