Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-38
Introduction
ProCurve Wireless Edge Services xl Module
You have created a unique VLAN for wireless stations, which is unknown
to devices within the wired network. NAT allows the Wireless Edge
Services xl Module to masquerade as the source of all wireless traffic, so
devices in the wired network direct all return traffic for the wireless
network to the module.
For more information about NAT, see “NAT” on page 1-41 and Chapter 8:
Configuring Network Address Translation (NAT).
Figure 1-14 illustrates this network design.
Figure 1-14. Setting up VLANs to Ensure the Firewall Checks Wireless Traffic
ACLs. In addition to screening traffic for signs of an attack, the Wireless Edge
Services xl Module’s firewall can enforce policies that you create. These
policies are called ACLs, and they affect traffic when it arrives on an interface.
Unlike attack checking (which affects only routed packets), an ACL filters
traffic when the module bridges frames from a WLAN to a VLAN—as long as
you have applied the ACL to that VLAN interface.