WESM zl Management and Configuration Guide WT.01.03 and greater

1-40
Introduction
ProCurve Wireless Edge Services zl Module
Figure 1-14. Setting up VLANs to Ensure the Firewall Checks Wireless Traffic
ACLs. In addition to screening traffic for signs of an attack, the Wireless Edge
Services zl Modules firewall can enforce policies that you create. These
policies are called ACLs, and they affect traffic inbound on an interface.
Note IP ACLs applied to VLAN interfaces only affect traffic routed to another VLAN.
ACLs applied to physical interfaces affect all inbound traffic.
You can create the following types of ACLs:
MAC standard ACLs
MAC extended ACLs
standard IP ACLs
extended IP ACLs
As discussed in “MAC Authentication” on page 1-28, MAC standard ACLs filter
traffic according to the source MAC address. These ACLs act as authentica-
tion: rather than control which network services a user can access, MAC ACLs
either allow or block traffic from a station entirely.