
96 | Wireless Network Profiles AOS-W Instant 6.3.1.1-4.0 | User Guide
You can configure up to 64 access rules for an employee, voice , or guest network using the AOS-W Instant UI or
CLI.
In the AOS-W Instant UI
To configure access rules for an employee or voice network:
1. In the Access Rules tab, set slider to any of the following types of access control:
l Unrestricted— Select this to set unrestricted access to the network.
l Network-based— Set the slider to Network-based to set common rules for all users in a network. The Allow
any to all destinations access rule is enabled by default. This rule allows traffic to all destinations. To define
an access rule:
a. Click New.
b. Select appropriate options in the New Rule window.
c. Click OK.
l Role-based— Select Role-based to enable access based on user roles. For role-based access control:
n Create a user role if required. For more information, see Configuring User Roles.
n Create access rules for a specific user role. For more information, see Configuring Access Rules on page
169. You can also configure an access rule to enforce Captive portal authentication for an SSIDthat is
configured to use 802.1X authentication method. For more information, see Configuring Captive Portal
Roles for an SSID on page 123.
n Create a role assignment rule. For more information, see Configuring Derivation Rules on page 178.
2. Click Finish.
In the CLI
To configure access control rules for a WLAN SSID:
(Instant Access Point)(config)# wlan access-rule <name>
(Instant Access Point)(Access Rule <name>)# rule <dest> <mask> <match> <protocol> <start-port>
<end-port> {permit |deny | src-nat | dst-nat {<IP-address> <port> | <port>}}[<option1....optio
n9>]
(Instant Access Point)(Access Rule <name>)# end
(Instant Access Point)# commit apply
To configure access control based on the SSID:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name>)# set-role-by-ssid
(Instant Access Point)(SSID Profile <name>)# end
(Instant Access Point)# commit apply
To configure role assignment rules:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name>)# set-role <attribute>{{equals|not-equals|starts-wi
th|ends-with|contains|matches-regular-expression}<operator><role>|value-of}
(Instant Access Point)(SSID Profile <name>)# end
(Instant Access Point)# commit apply
To configure a pre-authentication role:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name>)# set-role-pre-auth <pre-authentication-role>
(Instant Access Point)(SSID Profile <name>)# end
(Instant Access Point)# commit apply
To configure machine and user authentication roles
(Instant Access Point)(config)# wlan ssid-profile <name>
Kommentare zu diesen Handbüchern