Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-28
Introduction
ProCurve Wireless Edge Services xl Module
Figure 1-11. RADIUS MAC Authentication
Local MAC Authentication. RADIUS MAC authentication allows you to
control stations centrally. Alternatively, you can control traffic locally with
MAC standard ACLs. On the Wireless Edge Services xl Module, these ACLs
are called filters and are configured separately from other ACLs.
You configure the following ACLs and associate them with WLANs:
Deny ACLs—Stations are prevented from connecting to your network.
Allow ACLs—Stations are permitted to connect to your network.
The module processes ACLs in order of index number, stopping when it first
finds a match. It filters out any stations selected by a deny list before these
stations associate with a particular WLAN. The module allows all stations
either selected by an allow list or not selected by any list to associate. Whether
the station can forward traffic in the WLAN depends on whether it completes
any further authentication required by the WLAN.
For example, suppose you configure MAC authentication filters and apply
them to a WLAN; you also enable 802.1X authentication on that WLAN. When
a station attempts to connect to the WLAN, the module first checks the
station’s MAC address. If the ACLs allow the station to associate to the WLAN,
the module lets it proceed to authenticate using 802.1X.
The Wireless Edge Services xl Module can store and apply up to 1,000 ACLs.
Any kind of encryption supported on the module is supported on a WLAN that
uses local MAC authentication because these standards are configured
entirely separately.
For information about configuring MAC ACLs, see Chapter 13: Wireless
Network Management.