Alcatel-Lucent IAP93 Podręcznik Użytkownika Strona 169

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 168
169 | Roles and Policies AOS-W Instant 6.3.1.1-4.0 | User Guide
Access Control List Rules
You can use Access Control List (ACL) rules to either permit or deny data packets passing through the OAW-IAP.
You can also limit packets or bandwidth available to a set of user roles by defining access rules. By adding custom
rules, you can block or allow access based on the service or application, source or destination IP addresses.
You can create access rules to allow or block data packets that match the criteria defined in an access rule. You can
create rules for either inbound traffic or outbound traffic. Inbound rules explicitly allow or block the inbound network
traffic that matches the criteria in the rule. Outbound rules explicitly allow or block the network traffic that matches
the criteria in the rule. For example, you can configure a rule to explicitly block outbound traffic to an IP address
through the firewall.
The OAW-IAP clients are associated with user roles, which determine the client’s network privileges and the
frequency at which clients re-authenticate. AOS-W Instant supports the following types of ACLs:
l ACLs that permit or deny traffic based on the source IP address of the packet.
l ACLs that permit or deny traffic based on source or destination IP address, source or destination port number.
You can configure of up to 64 access control rules for a firewall policy.
Configuring Access Rules
You can configure access rules using AOS-W Instant UI or CLI.
In the Instant UI
1. Navigate to the WLAN wizard or Wired settings window:
l To configure access rules for a WLANSSID, in the Network tab, click New to create a new network profile or
edit to modify an existing profile.
l To configure access rules for a wired profile, More>Wired. In the Wired window, click New under Wired
Networks to create a new network or click Edit to select an existing profile.
2. Click the Access tab.
3. Slide to Network-based using the scroll bar to specify access rules for the network.
4. Click New to add a new rule. The New Rule window is displayed.
5. In the New Rule window, specify the following parameters:
Field Description
Rule type Select a rule type, for example Access control from the drop-down list.
Action Select any of following attributes:
l Select Allow to allow access users based on the access rule.
l Select Deny to deny access to users based on the access rule.
l Select Destination-NAT to allow changes to destination IP address.
l Select Source-NAT to allow changes to the source IP address.
Service
Select a service from the list of available services. You can allow or deny access to any or all
of the following services based on your requirement:
l any—Access is allowed or denied to all services.
l custom—Available options are TCP, UDP, and Other. If you select the TCP or UDP options,
enter appropriate port numbers. If you select the Other option, enter the appropriate ID.
l adp—Application Distribution Protocol
Table 30:
Access Rule Configuration Parameters
Przeglądanie stron 168
1 2 ... 164 165 166 167 168 169 170 171 172 173 174 ... 334 335

Komentarze do niniejszej Instrukcji

Brak uwag