User's Guide

Table Of Contents
Configuring the HiPath Wireless Controller
hwc_startup.fm
Configuring the HiPath Wireless Controller for the first time
9034530-02, March 2010
68 HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide
Locally at Controller, will no longer be able to target ESA0 to gain management
access to the system. In order to allow access for users connected on such a
topology, the given topology configuration itself must have allow management
traffic enabled and users will only be able to target the topology interface
specifically.
On the HiPath Wireless Controller’s L3 interfaces (associated with either
physical, Routed, or Bridged Locally at Controller topologies), the built-in
exception filter prohibits invoking SSH, HTTPS, or SNMP. However, such traffic
is allowed, by default, on the management port.
If management traffic is explicitly enabled for any interface, access is implicitly
extended to that interface through any of the other interfaces (VNS). Only traffic
specifically allowed by the interface’s exception filter is allowed to reach the
HiPath Wireless Controller itself. All other traffic is dropped. Exception filters are
dynamically configured and regenerated whenever the system's interface
topology changes (for example, a change of IP address for any interface).
Enabling management traffic on an interface adds additional rules to the
exception filter, which opens up the well-known IP(TCP/UDP) ports,
corresponding to the HTTPS, SSH, and SNMP applications.
The interface-based built-in exception filtering rules, in the case of traffic from
wireless users, are applicable to traffic targeted directly for the topology L3
interface. For example, a filter specified by a Policy may be generic enough to
allow traffic access to the HiPath Wireless Controller's management (for
example, Allow All [*.*.*.*]). Exception filter rules are evaluated after the user's
assigned filter policy, as such, it is possible that the policy allows the access to
management functions that the exception filter denies. These packets are
dropped.
To enable SSH, HTTPS, or SNMP access through a physical data interface:
1. From the main menu, click Wireless Controller Configuration. The HiPath
Wireless Controller Configuration screen is displayed.
2. In the left pane, click Topology. The Topologies tab is displayed.