BelAir20E User Guide
Wi-Fi AP Security
April 2, 2012
Confidential
Document Number BDTM02201-A01 Standard
The
enabled
setting for the
set acl
command means that only the wireless
clients on the ACL can access the network. All other clients are denied access.
The
disabled
setting means that all wireless clients can access the network. See
“AP Secure Port Mode” on page 112
Typically, you enable ACL mode only after you have added all the desired MAC
addresses to the control list.
CAUTION!
When used with multiple SSIDs, this method affects wireless clients attempting
to associate with any of the SSIDs.
Use the
show ssid table
command to determine
<ssid_index>
.
Controlling
Inter-client
Communication
If wireless bridging is enabled for an SSID, then by default wireless clients
associated to an AP and using that SSID can communicate to one another
(assuming they are able to determine the IP addresses of their peer wireless
clients).
For security reasons in a public network environment, it may be desirable to
block inter-client communications.
CAUTION!
Provisioning inter-client communication can affect the wireless clients
associated with all the SSIDs of that BelAir20E unit.
The goal is to prevent communications between associated wireless clients and
still allow them to connect to the Internet. To do this, use one of the following
methods.
Manual Provisioning of Gateway MAC Addresses
The following method offers the precise control of SSID communications:
1 Determine the MAC address of the Internet gateway(s) or router(s) in your
network.
2 Disable wireless bridging for each AP in your network.
3 Disable inter-AP wireless client communications:
a Add the previously determined gateway MAC address or addresses to the
secure MAC white list. This allows wireless clients to communicate with
the Internet. The secure MAC white list typically contains the MAC
address of the gateway interfaces.
b If the DHCP server for your network is on a different machine than the
gateway, add the MAC address of the DHCP server machine to the
secure MAC white list.
c Enable
secure port
mode for each of the APs in your network.