
159 | Authentication AOS-W Instant 6.3.1.1-4.0 | User Guide
Blacklisting Clients Manually
Manual blacklisting adds the MAC address of a client to the blacklist. These clients are added into a permanent
blacklist. These clients are not allowed to connect to the network unless they are removed from the blacklist.
Adding a Client to the Blacklist
You can add a client to the blacklist manually using AOS-W Instant UI or CLI.
In the AOS-W Instant UI
1. Click the Security link from the top right corner of the AOS-W Instant main window.
2. Click the Blacklisting tab.
3. Under the Manual Blacklisting, click New .
4. Enter the MAC address of the client to be blacklisted in the MAC address to add text box.
5. Click OK. The Blacklisted Since tab displays the time at which the current blacklisting has started for the client.
6. To delete a client from the manual blacklist, select the MAC Address of the client under the Manual Blacklisting,
and then click Delete.
In the CLI
To blacklist a client:
(Instant Access Point)(config)# blacklist-client <MAC-Address>
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
To view the blacklisted clients:
(Instant Access Point)# show blacklist-client
Blacklisted Clients
-------------------
MAC Reason Timestamp Remaining time(sec) AP name
--- ------ --------- ------------------- -------
00:1c:b3:09:85:15 user-defined 17:21:29 Permanent -
Blacklisting Users Dynamically
The clients can be blacklisted dynamically when they exceed the authentication failure threshold or when a
blacklisting rule is triggered as part of the authentication process.
Authentication Failure Blacklisting
When a client takes time to authenticate and exceeds the configured failure threshold, it is automatically blacklisted
by anOAW-IAP.
Session Firewall Based Blacklisting
In session firewall based blacklisting, an ACL rule is used to enable the option for automation blacklisting. when the
ACL rule is triggered, it sends out blacklist information and the client is blacklisted.
Configuring Blacklist Duration
You can set the blacklist duration using AOS-W Instant UI or CLI.
In the AOS-W Instant UI
To set a blacklist duration:
1. Click the Security link from the top right corner of the AOS-W Instant main window.
2. Click the Blacklisting tab.
Kommentare zu diesen Handbüchern