Specifications

Security Options 63
Chapter 5
what came before – at best, ACLs can look at the “SYN” flag in a TCP packet,
treating the session as new if the flag is set and treating the session as
“established” if it is not. This works for “normal” traffic but is ineffective
against many types of attack traffic.
Traffic policies in an Alcatel Wi-Fi switch are dynamic, meaning that address
information in the rules can change as the policies are applied to users. For
example, a traffic policy containing the alias “user” can be created. After the
policy is applied to a particular user, this alias is automatically changed to
match the IP address assigned to the user. An ACL is typically a static packet
filter, with IP addresses hard coded into the rule.
Traffic policies are bi-directional. While ACLs are normally applied either to
traffic inbound to an interface or outbound from an interface, traffic policies
automatically work in both directions. Traffic policy configuration can be
simpler than ACL configuration for this reason, since the administrator does
not need to worry about building consistent input and output ACLs.
Configuring Traffic Policies
To configure traffic policies, navigate to Configuration > Security > Policies as
shown in the figure below.
FIGURE 5-3 Traffic Policies