MSM7xx Controllers Configuration Guide v6.4.0

When used with 802.1X
authentication
When used with MAC-based
authentication
When used
alone
Filter actionClient address
Access is granted or denied based
on result of 802.1X authentication.
Access is granted or denied
based on result of MAC-based
Access is
denied.
AllowClient
address is not
authentication. (Not supported
on access-controlled VSCs.)
in the MAC
address list.
Access is granted or denied based
on result of 802.1X authentication.
Access is granted or denied
based on result of MAC-based
authentication.
Access is
granted.
BlockClient
address is not
in the MAC
address list.
Wireless IP filter
When this option is enabled, the VSC only allows wireless traffic that is addressed to an IP address
that is defined in the list. All other traffic is blocked, except for:
DNS queries (i.e., TCP/UDP traffic on port 53)
DHCP requests/responses
A maximum of two addresses can be defined. Each address can target a specific device or a
range of addresses.
Examples
To only allow traffic addressed to a gateway at the address 192.168.130.1, define the filter as
follows:
Address = 192.168.130.1
Mask = 255.255.255.255
To only allow traffic addressed to the network 192.168.130.0, define the filter as follows:
Address = 192.168.130.0
Mask = 255.255.255.0
DHCP server
This option is only available if the controller is configured as a DHCP server on the Controller >>
Network > Address allocation page.
A separate DHCP server can be enabled on each VSC to provide custom addressing that is different
from the base DHCP subnet that is determined by the LAN port IP address.
134 Working with VSCs