Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-43
Introduction
ProCurve Wireless Edge Services xl Module
The Wireless Edge Services xl Module performs NAT in much the same way,
and you can use the module to ready traffic for transmission on the Internet.
Other typical uses include:
isolating wireless and wired traffic and preserving IP addresses
You should guard the threshold between the wireless and wired network
rigorously. As mentioned before, one of the best ways to protect the wired
network is to create VLANs specifically for wireless traffic. The module
can handle all necessary functions for those VLANs, including DHCP
services and routing.
The module should also perform dynamic source NAT on addresses in
the VLAN for wireless users, translating all wireless stations’ IP
addresses to its own IP address on the wired network. This step ensures
that, even though the VLAN for wireless users does not exist in the wired
network, return traffic finds its way to the module and back onto the
wireless network.
Another benefit of using dynamic source NAT on wireless traffic is that
the wireless stations do not consume IP addresses in the wired network.
They all share a single IP address on the wired network—the IP address
of the Wireless Edge Services xl Module.
Concealing IP addresses in the private, wired network from wireless users
You can configure the Wireless Edge Services xl Module to translate the
source IP addresses of traffic that originates on your private, wired
network. To allow access to specific private servers, you must also
configure destination NAT, which translates the IP address advertised in
the wireless network back to the private address on the wired network.
relaying traffic destined for a particular server to a different server
For example, wireless stations might send requests to one server on the
Internet, but you want to force the stations to communicate with a
different server. In this case, you configure static destination NAT to
translate packets destined to the first server to the server of your choice.
PKI and Digital Certificates
The Wireless Edge Services xl Module’s security capabilities often require it
to authenticate itself with a digital certificate and the data it sends with a
digital signature.