User's Guide

Table Of Contents
Configuring a VNS
hwc_vnsconfiguration.fm
Configuring Policy
9034530-02, March 2010
360 HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide
6.10.6 Defining filter rules for Wireless APs
You can also apply filter rules on the Wireless AP. Applying filter rules at the
Wireless AP helps restrict unwanted traffic at the edge of your network. The
Wireless APs can support up to a maximum of 32 filters rules per group. Filtering
at the Wireless AP can be configured with the following Topology types:
Bridge Traffic Locally at the AP – If filtering at the Wireless AP is enabled
on a Bridge Traffic Locally at the AP topology, the filtering is applied to traffic
in both the uplink and downlink direction — the uplink direction is from the
wireless device to the network, and downlink direction is from the network to
the wireless device.
•Routed and Bridge Traffic Locally at the HWC – If filtering at the Wireless
AP is enabled on a Routed or Bridge Traffic Locally at the HWC topoloty, the
filtering is applied only to traffic in the UL direction. The filters applied in the
UL direction at the Wireless AP can be the same or different from filters
applied at the HiPath Wireless Controller.
Wireless AP filtering
When filtering at the Wireless AP is enabled, Wireless APs obtain client filter
information from the HiPath Wireless Controller. In addition, direct inter-Wireless
AP communication allow Wireless APs to exchange client filter information as
clients roam from one Wireless AP to another. This allows the system to achieve
a very fast roaming time. To take advantage of inter-Wireless AP communication,
you should configure the network so that Wireless APs in the mobility domain can
communicate with each other through the Wireless AP's Ethernet interface. Also,
multicast traffic with an IP address of 224.0.1.178 should be allowed between
Wireless APs.
To define filter rules to be applied by Wireless APs:
1. From the main menu, click Virtual Network Configuration. The Virtual
Network Configuration screen is displayed.
2. In the left pane expand the Policies pane and click the Policy you want to
edit, or click the New button to create a new Policy. The Policy tab is
displayed.
In Out Allow IP / Port Description
x x x [Intranet IP] Allow access to the Gateway IP address of the
VNS only
x x [Intranet IP, range] Deny all access to the VNS subnet range (such
as 0/24)
x x x *.*.*.*. Allow everything else
Table 34 Rules between two wireless devices