MSM7xx Controllers Configuration Guide v6.4.0

All APs must have VSCs with the same name, SSID, and wireless protection settings.
Wireless protection must be WPA, or 802.1X authentication must be enabled.
NOTE: RADIUS accounting is not supported when this option is enabled.
Wireless security filters
APs feature an intelligent bridge that can apply security filters to safeguard the flow of wireless
traffic. These filters limit both incoming and outgoing traffic as defined below and force the APs
to exchange traffic with a specific upstream device.
When access control is enabled, available options are:
The controlled AP will only allow user traffic that is addressed to the controller. All other traffic is
blocked. Make sure that the controller is set as the default gateway for all users. If not, all user
traffic will be blocked by the AP.
The default wireless security filters defined below are active.
When access control is disabled, available options are:
Configure security filter settings using the available options as described in the following section.
Settings
Restrict wireless traffic to
This setting defines the upstream device to which the AP will forward wireless traffic. If you are
using multiple VLANs, each with a different gateway, use the MAC address option.
Access points default gateway: This sends traffic to the default gateway assigned to the
AP. The default wireless security filters are in effect for wireless traffic.
MAC address: Specify the MAC address of the upstream device to which all traffic is to
be forwarded. The default wireless security filters are in effect for wireless traffic.
Custom: Use this option to define custom wireless security filters and a custom target
address for the upstream device. Refer to the Custom section that follows for details.
Default wireless security filter definitions
The following filters are defined by default.
Incoming wireless traffic filters
Applies to traffic sent from wireless users to the AP.
Accepted
Any IP traffic addressed to the controller.
PPPoE traffic (The PPPoE server must be the upstream device.)
126 Working with VSCs