Setting Up Filter Control - HP ProCurve 420 Management And Configuration Manual

Table of Contents

Advertisement

N o t e

Setting up Filter Control

The access point can employ VLAN ID and network traffic frame filtering to
control access to network resources and increase security.
Access and Frame Filtering. You can prevent communications between
wireless clients associated to the access point, only allowing traffic between
clients and the wired network. You can also prevent any wireless client from
performing any access point configuration through any of its management
interfaces, including web, Telnet, or SNMP access. Frame filtering can also be
enabled to control specific Ethernet protocol traffic that is forwarded to or
from wireless clients.
VLAN ID Filtering. The access point can enable the support of VLAN-
tagged traffic passing between wireless clients and the wired network. Up to
64 VLAN IDs can be mapped to specific wireless clients, allowing users to
remain within the same VLAN as they move around a campus site. This feature
can also be used to control access to network resources from wireless clients,
thereby improving security.
A VLAN ID (a number between 1 and 4094) can be assigned to each client after
successful authentication using IEEE 802.1X and a central RADIUS server.
The user VLAN IDs must be configured on the RADIUS server for each user
authorized to access the network. If a user does not have a configured VLAN
ID, the access point assigns the user to its own configured native VLAN ID.
When setting up VLAN IDs for each user on the RADIUS server, be sure to use
the RADIUS attributes and values as indicated in the following table.
Number
RADIUS Attribute
64
Tunnel-Type
65
Tunnel-Medium-Type
81
Tunnel-Private-Group-ID
VLAN IDs on the RADIUS server can be entered as a hexadecimal number or
an ASCII string, as set by the VLAN ID Format (see page 5-43). The specific
configuration of RADIUS server software is beyond the scope of this guide.
Refer to the documentation provided with the RADIUS server software.
Access Point Configuration

Setting up Filter Control

Value
VLAN (13)
802
VLANID (1 to 4094 as hexadecimal
or an ASCII string)
5-47

Advertisement

Table of Contents
loading

Table of Contents