Specifications
About Security Access Control Lists
RoamAbout Mobility System Software Configuration Guide 15-3
YoucannotperformACLfunctionsthatincludepermitting,denying,ormarkingwithaClassof
Service(CoS)levelonpacketswithamulticastorbroadcastdestinationaddress.
Order in Which ACLs are Applied to Traffic
MSSprovidesdifferentscopes(levelsofgranularity)forACLs.YoucanapplyanACLtoanyof
thefollowingscopes:
•User
•VLAN
•Virtualport(physicalportsplusspecificVLANtags)
•PhysicalPort(networkportsorDistributedMPs)
MSSbeginscomparingtraffictoACLsintheorderthescopesarelistedabove.IfanACL
is
mappedtomorethanoneofthesescopes,thefirstACLthatmatchesthepacketisappliedand
MSSdoesnotcomparethepackettoanymoreACLs.Forexample,ifdifferentACLsaremapped
tobothauserandaVLAN,andauser’strafficcanmatchbothACLs,
onlytheACLmappedtothe
userisapplied.
Traffic Direction
AnACLcanbemappedatanyscopetoeithertheinboundtrafficdirectionortheoutboundtraffic
direction.ItisthereforepossiblefortwoACLstobeappliedtothesametrafficasittraversesthe
system:oneACLisappliedontheinbounddirectionandtheotherisapplied
ontheoutbound
direction.WhenyoumapanACLtooneofthescopeslistedabove,youalsospecifythetraffic
directiontowhichtheACLapplies.
Selection of User ACLs
Identity‐basedACLs(ACLsmappedtousers)takeprecedenceoverlocation‐basedACLs(ACLs
mappedtoVLANs,ports,virtualports,orDistributedMPs).
ACLscanbemappedtoauserinthefollowingways:
• Locationpolicy(inacloroutaclisconfiguredonthelocationpolicy)
•Usergroup(attrfilter‐idacl
‐name.inorattrfilter‐idacl‐name.outisconfiguredontheuser
group)
•Individualuserattribute(attrfilter‐idacl‐name.inorattrfilter‐idacl‐name.outisconfigured
ontheindividualuser)
•SSIDdefault(attrfilter‐idacl‐name.inorattrfilter‐idacl‐name.outis
configuredontheSSID’s
serviceprofile)
Theuser’sACLcomesfromonlyoneofthesesources.Thesourcesarelistedinorderfromhighest
precedencetolowestprecedence.Forexample,ifauserassociateswithanSSIDthathasadefault
ACLconfigured,butalocationpolicyisalsoapplicableto
theuser,theACLconfiguredonthe
locationpolicyisused.