Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-40
Introduction
ProCurve Wireless Edge Services xl Module
The Wireless Edge Services xl Module applies an ACL to traffic that arrives
on a particular interface:
You can apply one IP ACL to a VLAN interface.
Traffic arrives on a VLAN interface in these two circumstances:
The Wireless Edge Services xl Module maps a wireless frame to that
VLAN.
In other words, the module decapsulates the frame received from a
WLAN, removes the 802.11 header, and adds an Ethernet header with
a tag for that VLAN. The VLAN assignment might originate in a static
setting for the entire WLAN or from a dynamic assignment received
from a RADIUS server.
The Wireless Edge Services xl Module receives the traffic on its uplink
port from the wireless services-enabled switch; the traffic is tagged
for the VLAN interface.
You can apply one IP ACL and one MAC extended ACL to each physical
interface.
The two physical interfaces are the internal uplink and downlink ports.
The ACL applies to all traffic that arrives on the port in any VLAN. In
addition to imposing other filters, an ACL applied to the downlink port
can filter traffic according to WLAN.
To control traffic that arrives on the downlink port with a MAC extended
ACL, the Wireless Edge Services xl Module examines the 802.11 header
and the Ethernet header after the packet is bridged. For traffic that arrives
on the uplink port, the MAC extended ACL applies to the Ethernet header.
Figure 1-15 shows where ACLs affect traffic. For more information about
ACLs, see Chapter 7: Access Control Lists (ACLs).