WESM zl Management and Configuration Guide WT.01.28 and greater

12-81
Wireless Network Management
MAC Filters (Local MAC Authentication)
Figure 12-57.Associating ACLs with WLANs
Note that it is possible to prevent a station from associating to one WLAN but to
allow the station to associate to another.
Just as you can make an ACL a member of more than one WLAN, you can associate
more than one ACL to a WLAN. The module filters traffic first against the ACL with
the lowest index number, then against the ACL with the next lowest number, and so
on. Parsing stops with the first successful match to an ACL.
In Figure 12-57, network administrators have created four ACLs. The first ACL
denies a single station, the second and third ACLs allow stations, and the fourth ACL
denies all stations. The network administrators made all these ACLs members of the
WLAN called MyWLAN.
With this configuration, only the stations allowed by ACLs 2 and 3 can connect to
MyWLAN. Notice that the network administrators have numbered the ACL that
denies all stations as 100. They can add ACLs to allow other stations, and as long
as these ACLs have an index number lower than 100, the Wireless Edge Services zl
Module will process them before it processes the ACL that denies all stations.