Controlling Device Permissions: Blocking And Acls; Wlan Acls And Block Lists; Configuring Access Control Lists - Ruckus Wireless ZoneDirector 1100 User Manual

Smart wi-fi controllers that support up to 1000 aps
Hide thumbs Also See for ZoneDirector 1100:
Table of Contents

Advertisement

Controlling Device Permissions: Blocking and
ACLs
Access controls can be configured to control access to both your wireless network and to the
ZoneDirector interface itself. For network access, ZoneDirector features a block list as well as
access control lists (ACL) to control access to the network.

WLAN ACLs and Block Lists

ZoneDirector provides two methods of controlling access to your wireless LANs:
Block List: When users log into a ZoneDirector network, their client devices (for example,
notebook computers and smart phones) are recorded and tracked. If, for any reason, you
need to block a client device from network use, you can do so via the ZoneDirector Web
interface. For more on configuring the block list, see
Access Control Lists: Access control lists (ACLs) establish which devices are allowed to
associate to a ZoneDirector-managed AP. By using the Configure > Access Control
options, you can define Layer 2 ACLs (MAC address ACLs), which can then be applied to
one or more ZoneDirector WLANs. You can also create L3/L4 ACLs (to restrict access by IP
address). ACLs are either allow-only or deny-only; that is, an ACL can be set up to allow
only specified clients or to deny only specified clients.
Take note of the following ZoneDirector rules:
The block list is system-wide and is applied to all WLANs in addition to the per-WLAN ACL.
If a MAC address is listed in the system-wide block list, it will be blocked even if it is an
allowed entry in an ACL. Thus, the block list takes precedence over an ACL.
MAC addresses that are in the deny list are blocked at the AP, not at ZoneDirector.

Configuring Access Control Lists

You can build L2/MAC and L3/L4 access control lists to establish which devices are allowed to
associate to the APs. You can configure these options on the Configure > Access Control page.
NOTE There is a system-wide block list that is applied to all WLANs in addition to the per-
WLAN ACLs. The entries of the system-wide block list are added when the Admin chooses to
block clients from the Monitor/Currently Active Clients panel. The Admin can remove entries
from the system-wide block list via Configure > Access Control > Block Clients list. If a MAC
address is listed in the system-wide block list, it will be blocked even if it is an allowed entry in
another ACL list.
Configuring Security and Other Services

Controlling Device Permissions: Blocking and ACLs

"Blocking Client Devices"
on
page
81.
77

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zonedirector 3000Zonedirector 5000

Table of Contents