Creating a Device Policy

You can control how devices installed with certain OS configurations can be connected to the network, and also control what they can be allowed to do within the network. Using the device policy service, the system can identify the type of client attempting to connect, and perform control actions such as allowing or blocking access, rate limiting, and VLAN tagging based on the OS rule.
To create a device policy:
  1. Click Security > Access Control and select Device Policy.
    This displays Summary and Profiles options.
  2. Select Profiles tab.
    This displays Device Policy Service page.

    Note: The Summary tab displays the device policy services in chart and graph format. Profiles can be filtered based on frequency, duration, APs and zone.

    Create Device Policy Service

  3. Enter the policy service details in the General Options section:
    1. Name: Enter a name for the device policy.
    2. Description: Enter a short description for this device policy.
    3. Default Access: Select either Allow or Block. This is the default action that the system will take if no rules are matched.
    4. Under Rules section, define the device policy rules. For more information, refer Creating Device Policy Rules.
    5. Click OK.

    Note: You can also edit, clone, and delete a service by selecting the options Configure, Clone, and Delete respectively, from the Device Policy tab.

Enabling Device Policy Service

Enable device policy service. To enable the new device policy perform the following steps:
  1. Click Network tab on the main menu.
  2. Select Wireless LANs.
  3. Select Create/Configure tab.
  4. Scroll down to Firewall Options to enable the firewall profile.