
5-38
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring and Applying Access Control Lists
Configuring and Applying Access Control Lists
An access control list (ACL) is a set of rules used to limit access to a particular interface (for example,
if you want to restrict a wireless client from pinging the management interface of the controller). After
ACLs are configured on the controller, they can be applied to the management interface, the AP-manager
interface, any of the dynamic interfaces, or a WLAN to control data traffic to and from wireless clients
or to the controller central processing unit (CPU) to control all traffic destined for the CPU.
You may also want to create a preauthentication ACL for web authentication. Such an ACL could be used
to allow certain types of traffic before authentication is complete.
Note If you are using an external web server with a 2000 or 2100 series controller or the controller network
module within a Cisco 28/37/38xx Series Integrated Services Router, you must configure a
preauthentication ACL on the WLAN for the external web server.
You can define up to 64 ACLs, each with up to 64 rules (or filters). Each rule has parameters that affect
its action. When a packet matches all of the parameters for a rule, the action set for that rule is applied
to the packet.
Note All ACLs have an implicit “deny all rule” as the last rule. If a packet does not match any of the rules, it
is dropped by the controller.
You can configure and apply ACLs through either the GUI or the CLI.
Using the GUI to Configure Access Control Lists
Follow these steps to configure ACLs using the controller GUI.
Step 1 Click Security > Access Control Lists > Access Control Lists to open the Access Control Lists page
(see Figure 5-23).
Figure 5-23 Access Control Lists Page
This page lists all of the ACLs that have been configured for this controller.
Note If you want to delete an existing ACL, hover your cursor over the blue drop-down arrow for that
ACL and choose Remove.
Commentaires sur ces manuels