Specifications

About Security Access Control Lists
RoamAbout Mobility System Software Configuration Guide 15-3
YoucannotperformACLfunctionsthatincludepermitting,denying,ormarkingwithaClassof
Service(CoS)levelonpacketswithamulticastorbroadcastdestinationaddress.
Order in Which ACLs are Applied to Traffic
MSSprovidesdifferentscopes(levelsofgranularity)forACLs.YoucanapplyanACLtoanyof
thefollowingscopes:
•User
•VLAN
•Virtualport(physicalportsplusspecificVLANtags)
•PhysicalPort(networkportsorDistributedMPs)
MSSbeginscomparingtraffictoACLsintheorderthescopesarelistedabove.IfanACL
is
mappedtomorethanoneofthesescopes,thefirstACLthatmatchesthepacketisappliedand
MSSdoesnotcomparethepackettoanymoreACLs.Forexample,ifdifferentACLsaremapped
tobothauserandaVLAN,andauserstrafficcanmatchbothACLs,
onlytheACLmappedtothe
userisapplied.
Traffic Direction
AnACLcanbemappedatanyscopetoeithertheinboundtrafficdirectionortheoutboundtraffic
direction.ItisthereforepossiblefortwoACLstobeappliedtothesametrafficasittraversesthe
system:oneACLisappliedontheinbounddirectionandtheotherisapplied
ontheoutbound
direction.WhenyoumapanACLtooneofthescopeslistedabove,youalsospecifythetraffic
directiontowhichtheACLapplies.
Selection of User ACLs
IdentitybasedACLs(ACLsmappedtousers)takeprecedenceoverlocationbasedACLs(ACLs
mappedtoVLANs,ports,virtualports,orDistributedMPs).
ACLscanbemappedtoauserinthefollowingways:
Locationpolicy(inacloroutaclisconfiguredonthelocationpolicy)
•Usergroup(attrfilteridacl
name.inorattrfilteridaclname.outisconfiguredontheuser
group)
•Individualuserattribute(attrfilteridaclname.inorattrfilteridaclname.outisconfigured
ontheindividualuser)
•SSIDdefault(attrfilteridaclname.inorattrfilteridaclname.outis
configuredontheSSID’s
serviceprofile)
TheusersACLcomesfromonlyoneofthesesources.Thesourcesarelistedinorderfromhighest
precedencetolowestprecedence.Forexample,ifauserassociateswithanSSIDthathasadefault
ACLconfigured,butalocationpolicyisalsoapplicableto
theuser,theACLconfiguredonthe
locationpolicyisused.