Filtering for a WM-AD
Summit WM20 User Guide, Software Release 4.2
91
Within each type of filter, define a sequence of filtering rules. The filtering rule sequence must be
arranged in the order that you want them to take effect. Each rule is defined to allow or deny traffic in
either direction:
●
In
– From a wireless device in to the network
●
Out
– From the network out to a wireless device
Final Filter Rule
The final rule in any filter should act as a catch-all for any traffic that did not match a filter. This final
rule should either allow all or deny all traffic, depending on the requirements for network access. For
example, the final rule in a non-authenticated filter for Captive Portal is typically deny all. A final allow
all rule in a default filter will ensure that a packet is not dropped entirely if no other match can be
found.
A default rule of deny all is automatically created by the system for initial filter definitions. The
administrator can change the action to allow all. However, a default filter rule cannot be removed. Since
a default filter rule provides a catch-all default behavior for packet handling, all applicable user defined
filter rules must be defined prior to this rule.
Each rule can be based on any one of the following:
●
Destination IP address or any IP address within a specified range that is on the network subnet (as a
wildcard)
●
Destination ports, by number and range
●
Protocols (UDP, TCP, etc.)
Filtering Sequence
The filtering sequence depends on the type of authentication used:
●
No authentication (network assignment by SSID)
Only the default filter will apply. Specific network access can be defined.
●
Authentication by captive portal (network assignment by SSID)
The non-authenticated filter will apply before authentication. Specific network access can be defined.
The filter should also include a rule to allow all users to get as far as the Captive Portal Web page
where the user can enter login identification for authentication. When authentication is returned, the
filter ID group filters are applied. If no filter ID matches are found, then the default filter is applied.
The filter ID group is an optional behavior specification. If a filter ID is not returned, or an invalid
one is returned, the default filter group is applied.
●
Authentication by AAA (802.1x)
AAA assignment requires that user authentication is completed using the 802.1x/EAP protocol
before a user is granted access to a network resource. Therefor, the enforcement of non-authenticated
traffic rules is not applicable. When authentication is returned, then the filter ID group filters are
applied. A WM-AD can have a subgoup with Login-LAT-Group ID that has its own filtering rules.
The Login-LAT-Group indicates that a user session should be associated with a more specific WM-
AD (a child WM-AD). The sub-WM-AD provides a different topology definition than the parent
WM-AD, as well as having its own set of filter definitions. Filter IDs returned in association with a
Login-LAT-Group definition are applied to the user, in relation to the sub-WM-AD indicated by the
Login-LAT-Group specification. If no filter ID matches are found, then the default filter is applied.
Содержание Summit WM20
Страница 8: ...Table of Contents Summit WM20 User Guide Software Release 4 2 8 ...
Страница 20: ...About this Guide Summit WM20 User Guide Software Release 4 2 20 ...
Страница 54: ...Configuring the Summit WM Controller Summit WM20 User Guide Software Release 4 2 54 ...
Страница 96: ...WM Access Domain Services Summit WM20 User Guide Software Release 4 2 96 ...
Страница 150: ...WM Access Domain Services Configuration Summit WM20 User Guide Software Release 4 2 150 ...
Страница 168: ...Availability and Controller Functionality Summit WM20 User Guide Software Release 4 2 168 ...
Страница 172: ...Working With Third Party APs Summit WM20 User Guide Software Release 4 2 172 ...
Страница 184: ...Working With the Summit WM Series Spy Summit WM20 User Guide Software Release 4 2 184 ...
Страница 194: ...Working With Reports and Displays Summit WM20 User Guide Software Release 4 2 194 ...
Страница 216: ...Performing System Maintenance Summit WM20 User Guide Software Release 4 2 216 ...