Creating a Restricted AP Access Profile

The Access Point (AP) is a critical node in the network that can be at risk of the malicious attacks as some of its ports are open. The Restricted AP Access Profile addresses this kind of risk and enhances AP security.
Restricted AP Access protects the AP in the following ways.
  1. By blocking access to the standard well know open ports on the AP, such as:
    • Port- 22 (TCP -IPv4 & IPv6) - For SSH Operation
    • Port- 23 (TCP - IPv4 & IPv6) - For Telnet Operation
    • Port- 80 (TCP - IPv4 & IPv6) - For HTTP Operation
    • Port- 443 (TCP - IPv4 & IPv6) - For HTTPs Operation
    • Port- 161 (UDP -IPv4 & IPv6) - For SNMP Operation
  2. By blocking access to the Internal ports on the AP (used mainly for Ruckus internal communication), such as:
    • Wirless Internet Service Provider roaming (WISPr) internal ports
      • Port 9997 (http) : [Subscriber portal]
      • Port 9998 (https): [Subscriber portal]
      • Port 1997 (http): [Captive Portal Listening Server]
      • Port 1998 (https): [Captive Portal Listening Server]
    • Walled Garden internal Ports
      • Port 8090 (http) : [Subscriber portal]
      • Port 8099 (https) : [Subscriber portal]
      • Port 18090 (http) : Captive Portal Listening Server /Redirect server listen port]
      • Port 18099 (https): Captive Portal Listening Server/Redirect server listen port]
    • Speedflex Port 18301
    • Proxy Web server for Unauthorized UEs 8100
    • DNSMASQ 53
  3. By providing a mechanism to block any ports or port range to restrict access.
  4. By allowing the AP to be accessed by authorized users.

To create a Restricted AP Access profile, perform the following steps.

  1. Click Security > Access Control > Restricted AP Access.
    This displays the Restricted AP Access screen.
  2. In the Restricted AP Access screen, select a zone from the system tree, and click Create
    This displays Create Restricted AP Access Profile screen.

    Create Restricted AP Access Profile

  3. Enter the following:
    1. Name: Type a name to identify the Restricted AP Access Profile.
    2. Description: Type a short description for the Restricted AP Access Profile.
    3. Blocked Port List: Select the protocol (TCP, UDP or Both) from the Protocol drop-down, and enter the port number in the Port field and click Add to add the entries or click Cancel to re-type and add the entry. The protocol and the port get listed in the table below the Blocked Port List. Select an entry and click Delete to remove the values in the table.
    4. Block well known ports: Click the toggle button to enable blocking all well known ports.
    5. IP Address Whitelist: When Restricted AP Access is enabled, network devices may use a non-whitelisted IPv6 IP address for Restricted AP Access related operations, which may cause unexpected result. So, it is recommended to add IPv6 IP addresses manually.
  4. Click OK.
You have created the Restricted AP Access profile.