Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
7-9
Access Control Lists (ACLs)
Overview
permitting or denying traffic based on the WLAN from which it arrives
Perhaps your Wireless Edge Services xl Module places all wireless traffic
in the same VLAN, VLAN 16. However, one WLAN grants guests access,
and you want to prohibit guest access to VLAN 2, which include servers
holding sensitive information.
When you configure the extended IP ACL to control traffic that arrives on
the VLAN 16 interface, add a rule that does the following:
denies traffic destined to the VLAN 2 subnetwork
specifically selects traffic from the guest WLAN
Make sure that this rule has a lower precedence order than any rule that
permits traffic to VLAN 2.
As you configure ACLs, remember that they always have an implicit “deny
any” operation at the end; any traffic not specifically permitted by the rules
within an ACL will be denied.