Dell PowerConnect W-IAP92 Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 257

Dynamic Blacklisting, Authentication Failure Blacklisting, Session Firewall Based Blacklisting

Page 257 highlights

Figure 202 - Manual Blacklisting 4. Click Ok. The Blacklisted Since tab displays the time at which the current blacklisting started for the client. 5. To delete a client from the manual blacklist, select the MAC Address of the client under the Manual Blacklisting window and then click Delete. Dynamic Blacklisting The clients can be blacklisted dynamically when they exceed the authentication failure threshold or a blacklisting rule was triggered as part of the authentication process. Authentication Failure Blacklisting When the time taken by a client fails to authenticate exceeds the configured threshold, the client is automatically blacklisted by a W-IAP. Session Firewall Based Blacklisting In session firewall based blacklisting, an ACL rule is used to enable the option for automation blacklisting. when the ACL rule is hit, it would send out blacklist information and the client would be blacklisted. To set the blacklist duration: 1. Select the PEF link and then select Blacklisting tab. l Auth failure blacklist time- Enter the duration since the blacklisting has been triggered when the authentication failure threshold is exceeded. l PEF rule blacklisted time- Enter the duration since the blacklisting has been triggered when a blacklisting rule has been triggered. NOTE: In the Networks tab, click the New link and navigate to New WLAN > VLAN > Security page to enable Blacklisting. Set a value between 1 to 10 in the max authentication failures field for the selected SSID. To enable session firewall based blacklisting, click New and navigate to WLAN Settings > VLAN > Security > Access window and enable the Blacklist option of the corresponding ACL rule. Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide 257 | Policy Enforcement Firewall

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

Figure 202
- Manual Blacklisting
4.
Click
Ok
.
The
Blacklisted Since
tab displays the time at which the current blacklisting started for the
client.
5.
To delete a client from the manual blacklist, select the MAC Address of the client under the
Manual Blacklisting
window and then click
Delete
.
Dynamic Blacklisting
The clients can be blacklisted dynamically when they exceed the authentication failure threshold
or a blacklisting rule was triggered as part of the authentication process.
Authentication Failure Blacklisting
When the time taken by a client fails to authenticate exceeds the configured threshold, the client
is automatically blacklisted by a W-IAP.
Session Firewall Based Blacklisting
In session firewall based blacklisting, an ACL rule is used to enable the option for automation
blacklisting. when the ACL rule is hit, it would send out blacklist information and the client
would be blacklisted.
To set the blacklist duration:
1.
Select the
PEF
link and then select
Blacklisting
tab.
l
Auth failure blacklist time
— Enter the duration since the blacklisting has been triggered
when the authentication failure threshold is exceeded.
l
PEF rule blacklisted time
— Enter the duration since the blacklisting has been triggered
when a blacklisting rule has been triggered.
NOTE: In the
Networks
tab, click the
New
link and navigate to
New WLAN > VLAN >
Security
page to enable Blacklisting. Set a value between 1 to 10 in the max authentication
failures field for the selected SSID. To enable session firewall based blacklisting, click
New
and navigate to
WLAN Settings > VLAN > Security > Access
window and enable the
Blacklist
option of the corresponding ACL rule.
Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
257
|
Policy Enforcement Firewall