User's Guide

Table Of Contents
hwc_vnsconfiguration.fm
Configuring a VNS
Configuring Policy
9034530-02,
March 2010
HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide 353
Non-authenticated
Default
Configuring filtering rules for a Non-authenticated filter
The rules for a Non-authenticated filter enable you to identify and manage the
destinations to which a mobile device is allowed to gain access without
undergoing an authentication redirection. Typically, the recommended default
rule is to deny all. Administrators must define the rules that will permit users to
access essential services such as the following:
DNS
Default Gateway (VNS interface IP for routed VNSs)
Any HTTP streams requested by the client for denied targets will be redirected to
the specified location.
Configuring filtering rules for Default filter
The Default filter is applied by default (automatically) after the authentication of
the wireless device under the following circumstances:
No match is found in the Exception filter rules
No filter ID attribute value is returned by the authentication server for the
device
No Policy name match to the filter ID value is found
In order to ensure that a packet is not dropped entirely under the above
circumstances, the final rule in the Default filter must be Allow All.
Configuring filtering rules/Policy in the case of AAA network assignment
The AAA network assignment type offers the following two default filters:
Default
Exception
In AAA network assignment type, a Non-authenticated filter becomes
unnecessary because the users are already authenticated.
6.10.3 Configuring Filter Rules for a Policy
Defining non-authenticated filters allows administrators to identify destinations to
which a mobile user is allowed to access without incurring an authentication
redirection. Typically, the recommended default rule is to deny all. Administrators
should define a rule set that will permit users to access essential services:
DNS (IP of DNS server)