Concept Guide

Table Of Contents
112 | Wireless Network Profiles Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide
Profile on page 98, Configuring VLAN Settings for a WLAN SSID Profile on page 102, and Configuring Security
Settings for a WLAN SSID Profile on page 104.
You can configure up to 128 access rules for an employee, voice , or guest network using the Instant UI or CLI.
In the Instant UI
To configure access rules for an employee or voice network:
1. In the Access Rules tab, set slider to any of the following types of access control:
l Unrestricted Select this option to set unrestricted access to the network.
l Network-based Set the slider to Network-based to set common rules for all users in a network. The
Allow any to all destinations access rule is enabled by default. This rule allows traffic to all
destinations. To define an access rule:
a. Click New.
b. Select appropriate options in the New Rule window.
c. Click OK.
l Role-based Select this option to enable access based on user roles. For role-based access control:
n Create a user role if required. For more information, see Configuring User Roles.
n Create access rules for a specific user role. For more information, see Configuring ACL Rules for
Network Services on page 189. You can also configure an access rule to enforce captive portal
authentication for an SSIDthat is configured to use 802.1X authentication method. For more
information, see Configuring Captive Portal Roles for an SSID on page 147.
n Create a role assignment rule. For more information, see Configuring Derivation Rules on page 206.
2. Click Finish.
In the CLI
To configure access control rules for a WLAN SSID:
(Instant AP)(config)# wlan access-rule <name>
(Instant AP)(Access Rule <name>)# rule <dest> <mask> <match> {<protocol> <start-port> <end-
port> {permit|deny|src-nat|dst-nat{<IP-address> <port>| <port>}}| app <app> {permit| deny}|
appcategory <appgrp>| webcategory <webgrp> {permit| deny}| webreputation <webrep>
[<option1....option9>]
(Instant AP)(Access Rule <name>)# end
(Instant AP)# commit apply
To configure access control based on the SSID:
(Instant AP)(config)# wlan ssid-profile <name>
(Instant AP)(SSID Profile <name>)# set-role-by-ssid
(Instant AP)(SSID Profile <name>)# end
(Instant AP)# commit apply
To configure role assignment rules:
(Instant AP)(config)# wlan ssid-profile <name>
(Instant AP)(SSID Profile <name>)# set-role <attribute>{{equals|not-equals|starts-with|ends-
with|contains|matches-regular-expression}<operator><role>|value-of}
(Instant AP)(SSID Profile <name>)# end
(Instant AP)# commit apply
To configure a pre-authentication role:
(Instant AP)(config)# wlan ssid-profile <name>
(Instant AP)(SSID Profile <name>)# set-role-pre-auth <role>
(Instant AP)(SSID Profile <name>)# end
(Instant AP)# commit apply