ZyXEL NWA-3500 User Guide - Page 63

Using MAC Filters and L-2 Isolation Profiles

Page 63 highlights

Chapter 3 Tutorial 3.4.5 Test the Setup Next, test your setup to ensure it is correctly configured. • Log into each AP's Web configurator and click ROGUE AP > Rogue AP. Click Refresh. If any of the MAC addresses from Section 3.4.1 on page 57 appear in the list, the friendly AP function may be incorrectly configured - check the ROGUE AP > Friendly AP screen. If any entries appear in the rogue AP list that are not in Section 3.4.1 on page 57, write down the AP's MAC address for future reference and check your e-mail inbox. If you have received a rogue AP alert, email alerts are correctly configured on that NWA. • If you have another access point that is not used in your network, make a note of its MAC address and set it up next to each of your NWAs in turn while the network is running. Either wait for at least ten minutes (to ensure the NWA performs a scan in that time) or login to the NWA's Web configurator and click ROGUE AP > Rogue AP > Refresh to have the NWA perform a scan immediately. • Check the ROGUE AP > Rogue AP screen. You should see an entry in the list with the same MAC address as your "rogue" AP. • Check the LOGS > View Logs screen. You should see a Rogue AP Detection entry in red text, including the MAC address of your "rogue" AP. • Check your e-mail. You should have received at least one e-mail alert (your other NWAs may also have sent alerts, depending on their proximity and the output power of your "rogue" AP). 3.5 Using MAC Filters and L-2 Isolation Profiles This example shows you how to allow certain users to access only specific parts of your network. You can do this by using multiple MAC filters and layer-2 isolation profiles. 3.5.1 Scenario In this example, you run a company network in which certain employees must wirelessly access secure file servers containing valuable proprietary data. You have two secure servers (1 and 2 in the following figure). Wireless user "Alice" (A) needs to access server 1 (but should not access server 2) and wireless user "Bob" (B) needs to access server 2 (but should not access server 1). Your NWA-3500/NWA-3550 User's Guide 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408

Chapter 3 Tutorial
NWA-3500/NWA-3550 User’s Guide
63
3.4.5
Test the Setup
Next, test your setup to ensure it is correctly configured.
Log into each AP’s Web configurator and click
ROGUE AP
>
Rogue AP
. Click
Refresh
. If any of the MAC addresses from
Section 3.4.1 on page 57
appear in
the list, the friendly AP function may be incorrectly configured - check the
ROGUE AP
>
Friendly AP
screen.
If any entries appear in the rogue AP list that are not in
Section 3.4.1 on page
57
, write down the AP’s MAC address for future reference and check your e-mail
inbox. If you have received a rogue AP alert, email alerts are correctly
configured on that NWA.
If you have another access point that is not used in your network, make a note
of its MAC address and set it up next to each of your NWAs in turn while the
network is running.
Either wait for at least ten minutes (to ensure the NWA performs a scan in that
time) or login to the NWA’s Web configurator and click
ROGUE AP
>
Rogue AP
>
Refresh
to have the NWA perform a scan immediately.
Check the
ROGUE AP
>
Rogue AP
screen. You should see an entry in the list
with the same MAC address as your “rogue” AP.
• Check the
LOGS
>
View Logs
screen. You should see a
Rogue AP
Detection
entry in red text, including the MAC address of your “rogue” AP.
• Check your e-mail. You should have received at least one e-mail alert (your
other NWAs may also have sent alerts, depending on their proximity and the
output power of your “rogue” AP).
3.5
Using MAC Filters and L-2 Isolation Profiles
This example shows you how to allow certain users to access only specific parts of
your network. You can do this by using multiple MAC filters and layer-2 isolation
profiles.
3.5.1
Scenario
In this example, you run a company network in which certain employees must
wirelessly access secure file servers containing valuable proprietary data.
You have two secure servers (
1
and
2
in the following figure). Wireless user
“Alice” (
A
) needs to access server
1
(but should not access server
2
) and wireless
user “Bob” (
B
) needs to access server
2
(but should not access server
1
). Your