User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
116
4.1.9 Encrypted Zone Cleartext Traffic
By default, the Mesh Point does not allow cleartext traffic to
pass on encrypted interfaces.
In order for configured cleartext devices (access points and/or
Trusted Devices) to be permitted access on an encrypted
interface,
cleartext must be turned
on
.
Disabling cleartext traffic on encrypted interfaces after AP
management rules or Trusted Devices have been configured
will not remove them from the configuration. Because these
cleartext devices cannot decrypt encrypted traffic, however, the
Mesh Point will not be able to communicate directly with them
until cleartext traffic is permitted on encrypted interfaces.
View the current cleartext setting on the Mesh Point with the
show command:
> show cleartext
On
Enable/disable cleartext traffic in the encrypted zone with the
set command:
# set cleartext on|off
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
4.1.10 Encrypted Zone Management Settings
Access to the Mesh Point’s management interface via an
encrypted interface on the Mesh Point can be globally
controlled. When encrypted management access is globally
allowed, you can additionally permit authorized cleartext
devices on encrypted interfaces to manage the Mesh Point.
4.1.10.1 Encrypted Interface Management Access
By default, the Mesh Point allows the management interface to
be accessed on encrypted non-bridging interfaces by local
Secure Client devices or through remote Fortress devices or
network bridging links. View the current management access
setting for encrypted interfaces with the
show command:
> show clientmanagement
On
Encrypted interface client management applies to any
connection to an encrypted interface on the current Mesh
Point, including:
connections through a remote Fortress Mesh Point
bridging links between networked Fortress Mesh Points
authorized cleartext devices when clearmanagement
(below) is enabled.
local Fortress Secure Client connections