User's Manual Part 2

76JadeOSUserManual
10.7ACL
User access is mainly to issue ACL based on SSID, MAC, flow threshold, bandwidth
control. ACL is important in building secure network, and mainly supports the fol
lowingfunctions:
¾ ACLbasedonMACaddress
Configure ACL based on MAC address in AC, which achieve the blacklist and
whitelistbasedonMACaddress.
Forexample:
Addmac11:22:33:44:55:6intoblacklist:
(JadeOS) (AP MAC ACL Profile “mac-acl-prof-1”)#list-type deny
(JadeOS) (AP MAC ACL Profile “mac-acl-prof-1”)#mac 11:22:33:44:55:66
Addmac11:22:33:44:55:6intowhitelist:
(JadeOS) (AP MAC ACL Profile “mac-acl-prof-1”)#list-type accept
(JadeOS) (AP MAC ACL Profile “mac-acl-prof-1”)#mac 11:22:33:44:55:66
¾ Supporttodisconnectnetworkautomaticallybasedonidletrafficmonitor;you
canconfiguretimeandthedefaultvalueis300s.theconfiguringcommandisas
follows:
idle-timeout <300-15300>
¾ SupportACLbasedontrafficthresholdandthedefaultvalueis1KB:
idle-threshold <0-1048576>
ConfiguringACL
ConfiguringACLbasedonIPaddressinACachievesuseraccesscontr ol. Configuring
differentAClsinACcancontroldifferentuseraccess,forexample:youcanmakeuser
inthespecifiedIPsegmentaccessthespecifiednetworksegment.ForACLbasedon
IPaddressisaccordingtoSSID,youcanconfiguredifferentACLsindifferentSSID.
FunctionssupportedbyACL:
¾ MatchsourceIPaddressandnetworksegment
¾ MatchdestinationIPaddressandnetworksegment
¾ MatchspecifiedIPprotocolandrange
¾ MatchsourceportanddestinationportofUDP/TCPprotocol
¾ Supporttheoperationof‘permitand‘denyaccordingtotheaboverules
Configurationcommand:
anyanyanydeny/permit