BelAir100SN User Guide
Wi-Fi AP Security
May 31, 2010
Confidential
Document Number BDTM11001-A01 Released
Controlling
Inter-client
Communication
If wireless bridging is enabled for an SSID, then by default wireless clients
associated to an AP and using that SSID can communicate to one another
(assuming they are able to determine the IP addresses of their peer wireless
clients).
For security reasons in a public network environment, it may be desirable to
block inter-client communications.
CAUTION!
Provisioning inter-client communication can affect the wireless clients
associated with all the SSIDs of that BelAir100SN unit.
The goal is to prevent communications between associated wireless clients and
still allow them to connect to the Internet. To do this, use one of the following
methods.
Manual Provisioning of Gateway MAC Addresses
The following method offers the precise control of SSID communications:
1 Determine the MAC address of the Internet gateway(s) or router(s) in your
network.
2 Disable wireless bridging for each AP in your network.
3 Disable inter-AP wireless client communications:
a Add the previously determined gateway MAC address or addresses to the
secure MAC white list. This allows wireless clients to communicate with
the Internet. The secure MAC white list typically contains the MAC
address of the gateway interfaces.
b Enable
secure port
mode for each of the APs in your network.
Automatic Discovery of Gateway MAC Addresses
The following method automates MAC address provisioning:
1 Disable wireless bridging for each AP in your network.
2 Disable inter-AP wireless client communications:
a Enable
secure port
mode for each of the APs in your network.
b Enable the
auto-secure gateway
feature for each of the APs in your
network.
Determining the MAC
Address of the Internet
gateway
This step is only required if you want to manually provision the MAC addresses
of the Internet gateway(s) or router(s) in your network.