![Extreme Networks Summit WM20 Скачать руководство пользователя страница 132](http://html.mh-extra.com/html/extreme-networks/summit-wm20/summit-wm20_user-manual_2454473132.webp)
WM Access Domain Services Configuration
Summit WM20 User Guide, Software Release 4.2
132
Filtering Rules for an AAA Child Group WM-AD
If you defined a child group for an AAA WM-AD, it will have the same authentication parameters and
filter IDs as the parent WM-AD. However, you can define different filtering rules for the filters IDs in
the child configuration from those in the parent configuration.
Filtering Rules Between Two Wireless Devices
Traffic from two wireless devices that are on the same WM-AD and are connected to the same Wireless
AP will pass through the Summit WM Controller and therefore be subject to filtering policy. You can
set up filtering rules that allow each wireless device access to the default gateway, but also prevent each
device from communicating with each other.
Add the following two rules to a filter ID filter, before allowing everything else:
Enabling Multicast for a WM-AD
A mechanism that supports multicast traffic can be enabled as part of a WM-AD definition. This
mechanism is provided to support the demands of VoIP and IPTV network traffic, while still providing
the network access control.
Define a list of multicast groups whose traffic is allowed to be forwarded to and from the WM-AD. The
default behavior is to drop the packets. For each group defined, you can enable Multicast Replication by
group.
NOTE
Before enabling multicast filters and depending on the topology of the WM-AD, you may need to define which
physical interface to use for multicast relay. Define the multicast port on the
IP Addresses
screen. For more
information, see
“Setting up the Data Ports” on page 42
.
x
x
Intranet IP 10.3.0.20
Allow all other traffic from Intranet network to
wireless devices
x
x
x
*.*.*.*.
Allow everything else
Table 11: Rules Between Two Wireless Devices
In
Out
Allow
IP / Port
Description
x
x
x
[Intranet IP]
Allow access to the Gateway IP address of the WM-AD only
x
x
[Intranet IP, range]
Deny all access to the WM-AD subnet range (such as 0/24)
x
x
x
*.*.*.*.
Allow everything else
Table 10: Default Filter Example B (Continued)
In
Out
Allow
IP / Port
Description
Содержание Summit WM20
Страница 8: ...Table of Contents Summit WM20 User Guide Software Release 4 2 8 ...
Страница 20: ...About this Guide Summit WM20 User Guide Software Release 4 2 20 ...
Страница 54: ...Configuring the Summit WM Controller Summit WM20 User Guide Software Release 4 2 54 ...
Страница 96: ...WM Access Domain Services Summit WM20 User Guide Software Release 4 2 96 ...
Страница 150: ...WM Access Domain Services Configuration Summit WM20 User Guide Software Release 4 2 150 ...
Страница 168: ...Availability and Controller Functionality Summit WM20 User Guide Software Release 4 2 168 ...
Страница 172: ...Working With Third Party APs Summit WM20 User Guide Software Release 4 2 172 ...
Страница 184: ...Working With the Summit WM Series Spy Summit WM20 User Guide Software Release 4 2 184 ...
Страница 194: ...Working With Reports and Displays Summit WM20 User Guide Software Release 4 2 194 ...
Страница 216: ...Performing System Maintenance Summit WM20 User Guide Software Release 4 2 216 ...