Wireless Access

last person joined: 9 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Control Plane Security

This thread has been viewed 6 times
  • 1.  Control Plane Security

    Posted May 31, 2017 09:04 AM

    Hi,

    .

    Can anyone tell me what implications might occur should Control Plane Security be enabled within a large production enviroment?

     

    The production enviroment currently has Control Plane Security disabled and a solution I have labbed using Bridge mode for a particular problem requires Control Plane Security to be enabled.

     

    Many thanks,

    Shaun



  • 2.  RE: Control Plane Security

    EMPLOYEE
    Posted May 31, 2017 09:41 AM

    You are looking at a 20 minute outage minimum to reboot APs twice and distribute keys to them..  It could even be more than that...



  • 3.  RE: Control Plane Security

    Posted May 31, 2017 09:59 AM

    Hi Colin,

     

    Thanks for you help,

     

    Can you also tell me if we'd have any problems with APs not being supported please?

     

    The reason I ask is because I've stumbled across the following recent thread and it has given me the shivers since the production enviroment also uses AP-105s and the first reply was to try disabling CPsec.

     

    https://community.arubanetworks.com/t5/Wireless-Access/Can-t-provision-the-AP105-on-Aruba-3200/td-p/297754

     

    Many thanks,

    Shaun



  • 4.  RE: Control Plane Security
    Best Answer

    EMPLOYEE
    Posted May 31, 2017 10:17 AM

    The access points have to reboot and rediscover the controller, so if you removed or changed discovery methods for your network, your AP possibly will not be able to come up.  If you are worried about that, you should just provision the few APs that you need to be bridged as RAPs.  Enabling CPSEC for an entire network is alot of risk just to allow some APs to be bridged.



  • 5.  RE: Control Plane Security

    Posted May 31, 2017 10:21 AM

    Perfect, thanks Colin