Dell PowerConnect W Clearpass 100 Software Podręcznik Użytkownika Strona 160

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 159
160160 | Roles and Policies
Dell PowerConnect W-Series Aruba Instant 6.2.1.0-3.3 | User Guide
You can also configure source based routing to allow client traffic on one SSID to reach the Internet through the
corporate network, while the other SSID can be used as an alternate uplink.
Enabling Source NAT
To enable source NAT:
1. Select an existing wireless or wired profile. Depending on the network profile selected, the Edit <WLAN-Profile>
or Edit Wired Network window is displayed.
You can also configure access rules in the Access tab of the New WLAN and New Wired Network
windows when configuring a new profile.
2. In the Access tab, slide to Network-based using the scroll bar to specify access rules for the network.
3. Click New to add a new rule. The New Rule window is displayed.
4. In the New Rule window, select Access control from the drop-down list.
5. Select Source-NAT to allow changes to the source IP address.
6. Select a service from the list of available services.
7. Specify the destination.
8. If required, enable other parameters such as Log, Blacklist, Classify media, Disable scanning, DSCP tag, and
802.1p priority.
9. Click OK.
Configuring Source-Based Routing
To configure source-based routing:
1. Ensure that an L3 subnet with the netmask, gateway, VLAN, and IP address is configured, For more information
on configuring L3 subnet, see Configuring L3-Mobility on page 180.
2. Ensure that the source IP address is associated with the IP address configured for the L3 subnet.
3. Create an access rule for the SSID profile with Source NAT action as described in Enabling Source NAT on page
160. The source NAT pool is configured and source based routing entry is created.
Examples for Access Rules
This section provides procedures to create the following access rules.
l Allow POP3 Service to a Particular Server on page 160
l Allow TCP Service to a Particular Network on page 161
l Deny FTP Service except to a Particular Server on page 161
l Deny bootp Service except to a Particular Network on page 161
Allow POP3 Service to a Particular Server
To configure POP3 service to a particular server:
1. Select an existing wireless or wired profile. Depending on the network profile selected, the Edit <WLAN-Profile>
or Edit Wired Network window is displayed.
You can also configure access rules in the Access tab of the New WLAN and New Wired Network
windows when configuring a new profile.
2. In the Access tab, slide to Network-based using the scroll bar to specify access rules for the network.
3. Click New to add a new rule. The New Rule window is displayed.
Przeglądanie stron 159
1 2 ... 155 156 157 158 159 160 161 162 163 164 165 ... 295 296

Komentarze do niniejszej Instrukcji

Brak uwag