BelAir100SN User Guide
Wi-Fi AP Security
May 31, 2010
Confidential
Document Number BDTM11001-A01 Released
address and VLAN matches an entry its white list. The white list can contain up
to 32 entries. If a VLAN is not specified, it is assumed to have a value of zero.
In effect, while in this mode the AP acts as a firewall for all Layer 2 frames
arriving from inside the network for the wireless clients. The secure MAC
white list should only contain the MAC addresses of the gateway interfaces.
Thus, wireless clients associated to other APs in the network are prevented
from communicating with locally associated clients.
Note 1: The secure MAC white list is different from the list described in
“Wireless Client Access Control List” on page 108
only the listed MAC addresses are allowed to associate with an AP. The
secure MAC white list controls data forwarding to the wireless clients
from remote entities in the network.
The content of the secure MAC white list takes effect only when the AP secure
port mode is enabled.
AP Secure Port Mode
/interface/wifi-<n>-<m>/set ssid <ssid_index> secure-port
{enabled|disabled}
Use the
show ssid table
command to determine
<ssid_index>
.
To prevent wireless clients associated with different APs from communicating
with each other, you must enable the secure port mode on each of the APs in
your network.
By default, the secure port mode is
disabled
.
Note: Typically, you provision the secure MAC white list before enabling the
secure port mode. This ensures that wireless clients that are already
associated do not lose their connection to the Internet.
Auto-secure Gateway
/interface/wifi-<n>-<m>/set ssid <ssid_index>
auto-secure-gateway {enabled|disabled}
Use this command only if you want to automatically discover the MAC
addresses of the Internet gateway(s) or router(s) in your network. To use this
command, you must set the ROUTER_IP option on the DHCP server in your
network.
Use the
show ssid table
command to determine
<ssid_index>
.
This command starts the process of detecting the MAC addresses of the
gateway for each VLAN in the system. Once it determines the MAC address, it
adds it to the secure MAC white list. This feature also continuously monitors