Dell PowerConnect W-IAP3WN Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 155

Instant Firewall

Page 155 highlights

Chapter 14 Instant Firewall A firewall is a system designed to prevent unauthorized Internet users from accessing a private network connected to the Internet. It defines access rules and monitors all data entering or leaving the network and blocks data that does not satisfy the specified security policies. Dell W-Instant implements a W-Instant Firewall feature that uses a simplified firewall policy language. An administrator can define the firewall policies on an SSID or wireless LAN such as the Guest network or an Employee network. At the end of the authentication process, these policies are uniformly applied to users connected to that network. The W-Instant Firewall gives you the flexibility to limit packets or bandwidth available to a particular class of users. Instant Firewall manages packets according to the first rule the packet matches. 1. In the Networks tab, click the New link. The New WLAN window appears. 2. Navigate to Access tab to specify the access rules for the network. 3. Slide to Network-based using the scroll bar and click New to add a new rule. The New Rule window consists of the following options: l Rule type- Select the rule type (Access control, VLAN assignment) from the drop-down list. NOTE: This release of W-Instant supports configuration of up to 64 access control rules. l Action- Select Allow, Deny, or Destination-NAT from the drop-down list to allow or deny traffic with the specified service type and destination. l Log- Select this check box if you want a log entry to be created when this rule is triggered. Instant firewall supports firewall based logging function. Firewall logs on W-IAP are generated as syslog messages. l Blacklist- Select this check box if you want the client to be blacklisted when this rule is triggered. The blacklisting lasts for the duration specified as Auth failure blacklist time on the Blacklisting tab of the PEF window. See "Client Blacklisting" on page 255 for more information. l Classify media- Select this check box if you want to prioritize video and voice traffic. When enabled, deep packet inspection is performed on all non-NATed traffic, and the traffic is marked as follows: l Video: Priority 5 (Critical) l Voice: Priority 6 (Internetwork Control) l Disable scanning- Select this check box if you want ARM scanning to be paused when this rule is triggered, to optimize performance. NOTE: This feature only takes effect if ARM scanning is enabled, from the ARM tab of the RF dialog. Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide 155 | Instant Firewall

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
155
|
Instant Firewall
Chapter 14
Instant Firewall
A firewall is a system designed to prevent unauthorized Internet users from accessing a private
network connected to the Internet. It defines access rules and monitors all data entering or leaving
the network and blocks data that does not satisfy the specified security policies.
Dell W-Instant implements a W-Instant Firewall feature that uses a simplified firewall policy
language. An administrator can define the firewall policies on an SSID or wireless LAN such as the
Guest network or an Employee network. At the end of the authentication process, these policies
are uniformly applied to users connected to that network. The W-Instant Firewall gives you the
flexibility to limit packets or bandwidth available to a particular class of users. Instant Firewall
manages packets according to the first rule the packet matches.
1.
In the
Networks
tab, click the
New
link. The
New WLAN
window appears.
2.
Navigate to
Access
tab to specify the access rules for the network.
3.
Slide to
Network-based
using the scroll bar and click
New
to add a new rule.
The New Rule window consists of the following options:
l
Rule type—
Select the rule type (Access control, VLAN assignment) from the drop-down list.
NOTE: This release of W-Instant supports configuration of up to 64 access control rules.
l
Action—
Select
Allow
,
Deny
, or
Destination-NAT
from the drop-down list to allow or deny
traffic with the specified service type and destination.
l
Log—
Select this check box if you want a log entry to be created when this rule is triggered.
Instant firewall supports firewall based logging function. Firewall logs on W-IAP are generated
as syslog messages.
l
Blacklist—
Select this check box if you want the client to be blacklisted when this rule is
triggered. The blacklisting lasts for the duration specified as
Auth failure blacklist
time on the
Blacklisting tab of the
PEF
window. See
"Client Blacklisting" on page 255
for more
information.
l
Classify media
— Select this check box if you want to prioritize video and voice traffic. When
enabled, deep packet inspection is performed on all non-NATed traffic, and the traffic is
marked as follows:
l
Video: Priority 5 (Critical)
l
Voice: Priority 6 (Internetwork Control)
l
Disable scanning
— Select this check box if you want ARM scanning to be paused when this
rule is triggered, to optimize performance.
NOTE: This feature only takes effect if ARM scanning is enabled, from the ARM tab of the RF
dialog.