
Configuring Policies
Filtering Rules
SCALANCE WLC711
User Guide, V8.11, 07/2012, C79000-G8976-C260-03 5-3
For more information about rate control profiles, go to “Working with Bandwidth Control
Profiles” on page 7-15 for more information.
Filtering Rules
Optionally, you can define filter rules for the policy. The policy name should match filter ID
values set up on the RADIUS servers.
If you do not define filter rules, then the system uses the default filter for authenticated users.
However, if you require user-specific filter definitions, then the filter ID configuration identified
the specific policy that should be applied to the user.
You can configure a filter definition to be static on the SCALANCE IWLAN Controller itself, or to
be dynamically provisioned if RADIUS authentication is used. The standard RADIUS attribute
can be used to identify a specific filter definition to apply to incoming/outgoing user traffic upon
successful authentication of the user during authentication. You can configure up to three types of
filters, depending on your network assignment type.
For information about configuring exception filters, refer to go to “Exception Filtering” on
page 4-11
Filtering Rules for a Non-authenticated Filter
Defining non-authenticated filters allows administrators to identify destinations to which a
mobile user is allowed to access without incurring an authentication redirection. Typically, the
recommended default rule is to deny all. Administrators should define a rule set that will permit
users to access essential services:
• DNS (IP of DNS server)
• Default Gateway (VNS Interface IP)
Any HTTP streams requested by the client for denied targets will be redirected to the specified
location.
The non-authenticated filter should allow access to the Captive Portal page IP address, as well as
to any URLs for the header and footer of the Captive Portal page. This filter should also allow
network access to the IP address of the DNS server and to the network address—the gateway of
the Topology. The gateway is used as the IP for an internal Captive Portal page.
Status
Synchronize Click to enable synchronize configuration.
Table 5-1 VLAN & Class of Service Tab - Fields and Buttons (continued)
Field/Button Description
Table 5-2 Filter Types
Filter Type AAA Network Assignment SSID Assignment
Exception filter Yes Yes
Non-authenticated filter - Yes
Default filter Yes Yes
Kommentare zu diesen Handbüchern