User's Manual

hwc_vnsconfiguration.fm
Virtual Network configuration
Configuring filtering rules for a VNS
A31003-W1050-U100-2-7619,
March 2008
HiPath Wireless Controller, Access Points and Convergence Software V5 R1 , C20/C2400 User Guide 205
6.9.4.2 Filtering rules for an AAA child group VNS
If you defined a child group for an AAA VNS, it will have the same authentication
parameters and filter IDs as the parent VNS. However, you can define different
filtering rules for the filters IDs in the child configuration from those in the parent
configuration.
6.9.4.3 Filtering rules between two wireless devices
Traffic from two wireless devices that are on the same VNS and are connected to
the same Wireless AP will pass through the HiPath Wireless Controller and
therefore be subject to filtering policy. You can set up filtering rules that allow each
wireless device access to the default gateway, but also prevent each device from
communicating with each other.
Add the following two rules to a filter ID filter, before allowing everything else:
In Out Allow IP / Port Description
x x Intranet IP, range Deny all access to an IP range
x x Port 80 (HTTP) Deny all access to Web browsing
x x Intranet IP Deny all access to a specific IP
x x x *.*.*.*. Allow everything else
Table 19 Default filter example A
In Out Allow IP / Port Description
x Port 80 (HTTP) on host IP Deny all incoming wireless devices
access to Web browsing the host
x Intranet IP 10.3.0.20, ports
10-30
Deny all traffic from the network to the
wireless devices on the port range,
such as TELNET (port 23) or FTP (port
21)
x x Intranet IP 10.3.0.20 Allow all other traffic from the wireless
devices to the Intranet network
x x Intranet IP 10.3.0.20 Allow all other traffic from Intranet
network to wireless devices
x x *.*.*.*. Deny everything else
Table 20 Default filter example B