ZyXEL NWA-3163 User Guide - Page 63

Con the SERVER_1 Network

Page 63 highlights

Chapter 3 Tutorials Each SSID profile already uses a different pre-shared key. In this example, you will configure access limitations for each SSID profile. To do this, you will take the following steps. 1 Configure the SERVER_1 network's SSID profile to use specific MAC filter and layer-2 isolation profiles. 2 Configure the SERVER_1 network's MAC filter profile. 3 Configure the SERVER_1 network's layer-2 isolation profile. 4 Repeat steps 1 ~ 3 for the SERVER_2 network. 5 Check your settings and test the configuration. To configure layer-2 isolation, you need to know the MAC addresses of the devices on your network, which are as follows. Table 5 Tutorial: Example Network MAC Addresses DEVICE LABEL MAC ADDRESS NWA Z BB:AA:99:88:77:66 Secure Server 1 1 AA:99:88:77:66:55 Secure Server 2 2 99:88:77:66:55:44 Workstation C 88:77:66:55:44:33 Switch D 77:66:55:44:33:22 Security gateway E 66:55:44:33:22:11 To configure MAC filtering, you need to know the MAC addresses of the devices Alice and Bob use to connect to the network, which are as follows. Table 6 Tutorial: Example User MAC Addresses USER MAC ADDRESS Alice 11:22:33:44:55:66 Bob 22:33:44:55:66:77 3.5.4 Configure the SERVER_1 Network First, you will set up the SERVER_1 network which allows Alice to access secure server 1 via the network switch. You will configure the MAC filter to restrict access to Alice alone, and then configure layer-2 isolation to allow her to access only the network router, the file server and the Internet security gateway. NWA-3160 Series User's Guide 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Chapter 3 Tutorials
NWA-3160 Series User’s Guide
63
Each SSID profile already uses a different pre-shared key.
In this example, you will configure access limitations for each SSID profile. To do
this, you will take the following steps.
1
Configure the
SERVER_1
network’s SSID profile to use specific MAC filter and
layer-2 isolation profiles.
2
Configure the
SERVER_1
network’s MAC filter profile.
3
Configure the
SERVER_1
network’s layer-2 isolation profile.
4
Repeat steps 1 ~ 3 for the
SERVER_2
network.
5
Check your settings and test the configuration.
To configure layer-2 isolation, you need to know the MAC addresses of the devices
on your network, which are as follows.
To configure MAC filtering, you need to know the MAC addresses of the devices
Alice and Bob use to connect to the network, which are as follows.
3.5.4
Configure the SERVER_1 Network
First, you will set up the
SERVER_1
network which allows Alice to access secure
server 1 via the network switch.
You will configure the MAC filter to restrict access to Alice alone, and then
configure layer-2 isolation to allow her to access only the network router, the file
server and the Internet security gateway.
Table 5
Tutorial: Example Network MAC Addresses
DEVICE
LABEL
MAC ADDRESS
NWA
Z
BB:AA:99:88:77:66
Secure Server 1
1
AA:99:88:77:66:55
Secure Server 2
2
99:88:77:66:55:44
Workstation
C
88:77:66:55:44:33
Switch
D
77:66:55:44:33:22
Security gateway
E
66:55:44:33:22:11
Table 6
Tutorial: Example User MAC Addresses
USER
MAC ADDRESS
Alice
11:22:33:44:55:66
Bob
22:33:44:55:66:77