Alcatel-Lucent IAP93 Podręcznik Użytkownika Strona 172

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 171
Configuring a Source NAT Access Rule
The source NAT action in access rules allows the user to override the routing profile entries. For example, when a
routing profile is configured to use 0.0.0.0/0 , the client traffic on an SSID in L3 mode access to the corporate
network is sent to the tunnel. When an access rule is configured with Source NAT action, the users can specify the
service, protocol, or destination to which the source NAT is applied.
You can also configure source based routing to allow client traffic on one SSID to reach the Internet through the
corporate network, while the other SSID can be used as an alternate uplink. You can create an access rule to
perform source NAT by using the AOS-W Instant UI or CLI.
In the AOS-W Instant UI
To configure a source NAT access rule:
1. Navigate to the WLAN wizard or Wired settings window:
l To configure access rules for a WLANSSID, in the Network tab, click New to create a new network profile or
edit to modify an existing profile.
l To configure access rules for a wired profile, More>Wired. In the Wired window, click New under Wired
Networks to create a new network or click Edit to select an existing profile.
2. Click the Access tab.
3. To configure access rules for the network, slide to Network-based. To configure access rules for user roles,
slide to Role-based .
4. To create a new rule for the network, click New. To create an access rule for a user role, select the user role and
then click New. The New Rule window is displayed.
5. In the New Rule window:
6. Select Access control from the Rule type drop-down list.
7. Select Source-NAT from the Action drop-down list, to allow changes to the source IP address.
8. Select a service from the list of available services.
9. Select the required option from the Destination drop-down.
10. If required, enable other parameters such as Log, Blacklist, Classify media, Disable scanning, DSCP tag, and
802.1p priority.
11. Click OK and then click Finish.
In the CLI
To configure source NAT access rule:
(Instant Access Point)(config)# wlan access-rule <access_rule>
(Instant Access Point)(Access Rule "<access_rule>")# rule <dest> <mask> <match> <protocol> <sp
ort> <eport> src-nat
(Instant Access Point)(Access Rule "<access_rule>")# end
(Instant Access Point)# commit apply
Configuring Source-Based Routing
To allow different forwarding policies for different SSIDs, you can configure source-based routing. The source-based
routing configuration overrides the routing profile configuration and allows any destination or service to be configured
to have direct access to the Internet (bypassing VPN tunnel) based on the ACL rule definition. When source-based
routing is enabled, the Virtual Controller performs source NATby using its uplink IP address.
To configure source-based routing:
1. Ensure that an L3 subnet with the netmask, gateway, VLAN, and IP address is configured, For more information
on configuring L3 subnet, see Configuring L3-Mobility on page 201.
2. Ensure that the source IP address is associated with the IP address configured for the L3 subnet.
AOS-W Instant 6.3.1.1-4.0 | User Guide Roles and Policies | 172
Przeglądanie stron 171
1 2 ... 167 168 169 170 171 172 173 174 175 176 177 ... 334 335

Komentarze do niniejszej Instrukcji

Brak uwag