6 - 32 WiNG 5 Access Point System Reference Guide
12.Save the changes to the new MAC rule, or reset to the last saved configuration as needed.
13.Set the following
Trust Parameters
:
14.Set the following
Wireless Client Deny
configuration:
Action
The following actions are supported:
Log
- Creates a log entry that a Firewall rule has allowed a packet to either
be denied or permitted.
Mark
- Modifies certain fields inside the packet, and then permits them.
Therefore, mark is an action with an implicit permit.
Mark, Log
- Conducts both mark and log functions.
Precedence
Use the spinner control to specify a precedence for this MAC Firewall rule
between 1-1500. Access policies with lower precedence are always
applied first to packets.
VLAN ID
Enter a VLAN ID representative of the shared SSID each user employs to
interoperate within the network (once authenticated by the access point’s
local RADIUS server). The VLAN ID can be between1 and 4094.
Match 802.1P
Configures IP DSCP to 802.1p priority mapping for untagged frames. Use
the spinner control to define a setting between 0-7.
Ethertype
Use the drop-down menu to specify an Ethertype of either ipv6, arp, wisp,
monitor 8021q. An EtherType is a two-octet field within an Ethernet frame.
It is used to indicate which protocol is encapsulated in the payload of an
Ethernet frame.
Description
Provide a description (up to 64 characters) for the rule to help differentiate
it from others with similar configurations.
ARP Trust
Select the radio button to enable ARP Trust on this WLAN. ARP packets
received on this WLAN are considered trusted and information from these
packets is used to identify rogue devices within the network. This setting
is disabled by default.
Validate ARP
Header Mismatch
Select the radio button to check for a source MAC mismatch in the ARP
header and Ethernet header. This setting is enabled by default.
DHCP Trust
Select the radio button to enable DHCP trust on this WLAN. This setting is
disabled by default.
Wireless Client
Denied Traffic
Threshold
If enabled, any associated client which exceeds the thresholds configured
for storm traffic is either deauthenticated or blacklisted depending on the
selected Action. The threshold range is 1-1000000 packets per second.
This feature is disabled by default.
Action
If enabling a wireless client threshold, use the drop-down menu to
determine whether clients are deauthenticated when the threshold is
exceeded, or blacklisted from connectivity for a user defined interval.
Selecting None applies no consequence to an exceeded threshold.
Содержание WiNG 5
Страница 1: ...Motorola Solutions WiNG 5 Access Point System Reference Guide ...
Страница 2: ......
Страница 10: ...viii WiNG 5 Access Point System Reference Guide ...
Страница 16: ...1 4 WiNG 5 Access Point System Reference Guide ...
Страница 28: ...2 12 WiNG 5 Access Point System Reference Guide ...
Страница 48: ...3 20 WiNG 5 Access Point System Reference Guide ...
Страница 197: ...Device Configuration 5 137 Figure 5 78 Profile Management Settings screen ...
Страница 335: ...Device Configuration 5 275 Figure 5 155 Profile Overrides Management Settings screen ...
Страница 348: ...5 288 WiNG 5 Access Point System Reference Guide ...
Страница 350: ...6 2 WiNG 5 Access Point System Reference Guide Figure 6 1 Configuration Wireless ...
Страница 448: ...6 100 WiNG 5 Access Point System Reference Guide ...
Страница 492: ...8 32 WiNG 5 Access Point System Reference Guide ...
Страница 538: ...9 46 WiNG 5 Access Point System Reference Guide ...
Страница 564: ...11 10 WiNG 5 Access Point System Reference Guide ...
Страница 606: ...12 42 WiNG 5 Access Point System Reference Guide ...
Страница 732: ...13 126WiNG 5 Access Point System Reference Guide Figure 13 67 Access Point Certificate Trustpoint screen ...
Страница 762: ...A 2 WiNG 5 Access Point System Reference Guide ...
Страница 801: ......