Creating a Layer 3/Layer 4/IP Address Access Control List
In addition to Layer 2/MAC-address based ACLs, RUCKUS Unleashed also provides access control options at Layer 3 and Layer 4.
You can configure the access control options based on a set of criteria, including:
Complete the following steps to create a Layer 3/Layer 4/IP address-based ACL.
-
UI path for UnleashedFrom the main menu, select .
- In the Wireless Access Control page, click . The ACL Add page is displayed.
- Enter a name for the ACL, and (optionally) enter a description.
- Under Default Mode, select Deny all by default or Allow all by default to set the default access privilege that you want to grant all users by default.
- Under Rules, click Add Rule to add a new rule or select an existing rule and click Edit in the Actions column.
- Define each access policy by
configuring a combination of the following attributes:
- Order: Select the priority assigned to the rule from the drop-down list.
- Description: Optionally, enter a description.
- Type: The access privilege (allow or deny) that this policy grants.
- Source Address: Enter an IP subnet and netmask of the network source from which you want to allow or deny access. The IP address must be in the format A.B.C.D/M, where M is the subnet mask.) Otherwise, select Any. For example, if you enter 192.168.0.1/24, the rule allows or denies the entire Class C subnet. To allow or deny a single host, use /32 as the netmask.
- Destination Address: Enter an IP subnet and netmask of the network target to which you want to allow or deny access. (The IP address must be in the format A.B.C.D/M, where M is the subnet mask.) Otherwise, select Any. For example, if you enter 192.168.0.1/24, the rule allows or denies the entire Class C subnet. To allow or deny a single host, use /32 as the netmask.
- Application: If you select a specific application from the list, the Protocol and Destination Port options are automatically filled with the relevant values and are not configurable.
- Protocol: Enter a network protocol number (from 0 through 254), as defined by the IANA (http://www.iana.org/assignments/protocol-numbers/protocolnumbers.xhtml) to allow or deny. Otherwise, select Any.
- Source Port: Enter a valid source port number (from 1 through 65534) or port range (for example, 80-443).
- Destination Port: Enter a valid destination port number (from 1 through 65534) or port range (for example, 80-443).
- Click Add to add a new
rule.
To change the order in which rules are implemented, click the
icon on a specific row to move the rows up or down. Alternatively, you
can select a specific rule and click Move Up or
Move
Down to move the rows.You can also edit, clone, or delete rules by selecting a specific rule checkbox, then clicking Edit, Clone, or Delete options, respectively.
- Click Add to add the
ACL. You can create up to 32 Layer 3/Layer 4/IP address-based access control rules.
