BelAir20E User Guide
Wi-Fi AP Security
April 2, 2012
Confidential
Document Number BDTM02201-A01 Standard
These commands add and remove a MAC address from the secure MAC white
list. The MAC address can optionally be qualified with a mask and a traffic
descriptor as follows:
• The mask is specified with the
secure-mac-mask
option. Use
ff
to indicate
bits to accept. Use
00
to indicate bits to ignore. For example, a MAC
address of 00:0d:67:0c:21:90 with a mask of ff:ff:ff:00:00:00 specifies all MAC
addresses beginning with 00:0d:67. You can also customize the mask to
exactly suit your needs by using values other than
ff
or
00
.
• The traffic descriptor can be one of
all
,
untagged
or a VLAN ID. Use a
VLAN ID to specify the traffic of a particular VLAN. Use
untagged
to specify
only untagged traffic. Use
all
to specify all traffic.
When configured in secure port mode, the AP forwards to the associated
wireless clients only those Layer 2 (Ethernet) frames for which the source MAC
address and VLAN matches an entry its white list. The white list can contain up
to 32 entries. If a VLAN is not specified, it is assumed to have a value of zero.
In effect, while in this mode the AP acts as a firewall for all Layer 2 frames
arriving from inside the network for the wireless clients. The secure MAC
white list should only contain the MAC addresses of the gateway interfaces.
Thus, wireless clients associated to other APs in the network are prevented
from communicating with locally associated clients.
Note 1: The secure MAC white list is different from the list described in
“Wireless Client Access Control List” on page 109
only the listed MAC addresses are allowed to associate with an AP. The
secure MAC white list controls data forwarding to the wireless clients
from remote entities in the network.
Note 2: If the gateway and DHCP servers on your networks are on different
machines, you must put the MAC addresses of both machines on the
secure MAC white list.
The content of the secure MAC white list takes effect only when the AP secure
port mode is enabled.
AP Secure Port Mode
/interface/wifi-<n>-<m>/set ssid <ssid_index> secure-port
{enabled|disabled}
Use the
show ssid table
command to determine
<ssid_index>
.
To prevent wireless clients associated with different APs from communicating
with each other, you must enable the secure port mode on each of the APs in
your network.