BelAir20E User Guide
Wi-Fi AP Security
April 2, 2012
Confidential
Document Number BDTM02201-A01 Standard
Automatic Discovery of Gateway MAC Addresses
The following method automates MAC address provisioning:
1 Disable wireless bridging for each AP in your network.
2 Disable inter-AP wireless client communications:
a Enable the
auto-secure gateway
feature for each of the APs in your
network.
b Enable
secure port
mode for each of the APs in your network.
Determining the MAC
Address of the Internet
gateway
This step is only required if you want to manually provision the MAC addresses
of the Internet gateway(s) or router(s) in your network.
Determining the MAC address of your Internet gateway(s) depends on the type
of equipment you are using. Refer to your equipment’s User Manual for the
specific details.
You will need the MAC address of your gateways later to provision the secure
MAC white list of the APs configured in
secure port
mode.
Disabling or Enabling AP
Wireless Bridging
/interface/wifi-<n>-<m>/set ssid <ssid_index> wireless-bridge
{enabled|disabled}
Use the
show ssid table
command to determine
<ssid_index>
.
Disabling wireless bridging for an AP prevents wireless clients associated to that
particular AP from communicating with one another.
It does not prevent a wireless client associated with one AP (AP “A”) from
communicating with a wireless client associated with another AP (AP “B”). The
secure port
mode prevents this. See
“AP Secure Port Mode” on page 112
.
By default, wireless bridging is
enabled
.
Disabling Inter-AP
Wireless Client
Communication
Disabling inter-AP wireless client communications involves setting up a secure
MAC white list and enabling secure port mode for each AP.
Secure MAC White List
/interface/wifi-<n>-<m>/add secure-mac-address <mac-address-string>
[secure-mac-mask <mac-mask-string>]
[all | untagged | <vlan-id>]
/interface/wifi-<n>-<m>/del secure-mac-address <mac-address-string>
[all | untagged | <vlan-id>]
Use these commands only if you want to manually provision the MAC
addresses of the Internet gateway(s) or router(s) in your network.