Siemens HiPath C10 User Manual page 154

C10/c100/c1000 ap26 series wireless controller, access points and convergence software, v4.0
Hide thumbs Also See for HiPath C10:
Table of Contents

Advertisement

hwc_vnsconfiguration.fm
Virtual Network configuration
Configuring filtering rules for a VNS
match is determined. Therefor, these user-defined rules are evaluated before the system's own
generated rules. As such, these user-defined rules may inadvertently create security lapses in
the system's protection mechanism or create a scenario that filters out packets that are
required by the system.
Use exception filters only if absolutely necessary. It is recommended to avoid
>
defining general allow all or deny all rule definitions since those definitions can easily
be too liberal or too restrictive to all types of traffic.
The exception rules are evaluated in the context of referring to the specific controller's interface.
The destination address for the filter rule definition is typically defined as the interface's own IP
address. The port number for the filter definition corresponds to the target (destination) port
number for the applicable service running on the controller's management plane.
The exception filter on an VNS applies only to the destination portion of the packet. Traffic to a
specified IP address and IP port is either allowed or denied. Adding exception filtering rules
allows network administrators to either tighten or relax the built-in filtering that automatically
drops packets not specifically allowed by filtering rule definitions. The exception filtering rules
can deny access in the event of a DoS attack, or can allow certain types of management traffic
that would otherwise be denied. Typically, Allow Management is enabled
To define filtering rules for an exception filter:
1.
From the main menu, click Virtual Network Configuration. The Virtual Network
Configuration screen appears.
2.
In the left pane Virtual Networks list, click the VNS you want to define filter ID values for.
The Topology tab is displayed.
3.
Click the Filtering tab.
4.
From the Filter ID drop-down list, select Exception.
154
HiPath Wireless Controller, Access Points and Convergence Software V4.0, C10/C100/C1000 User Guide
A31003-W1040-U101-1-7619, July 2006 DRAFT

Advertisement

Table of Contents
loading

Table of Contents