Creating a Layer 3/Layer 4/IP Address Access Control List

In addition to Layer 2/MAC-address based ACLs, RUCKUS Unleashed also provides access control options at Layer 3 and Layer 4.

You can configure the access control options based on a set of criteria, including:

  • Destination IP address
  • Application
  • Protocol
  • Destination port

Complete the following steps to create a Layer 3/Layer 4/IP address-based ACL.

  1. UI path for Unleashed
    From the main menu, select Security > Wireless Access Control > L3/4/IP Address Access Control.
  2. In the Wireless Access Control page, click Add > L3/4/IP Address Access Control. The ACL Add page is displayed.
  3. Enter a name for the ACL, and (optionally) enter a description.
  4. Under Default Mode, select Deny all by default or Allow all by default to set the default access privilege that you want to grant all users by default.
  5. Under Rules, click Add Rule to add a new rule or select an existing rule and click Edit in the Actions column.
  6. Define each access policy by configuring a combination of the following attributes:
    • Order: Select the priority assigned to the rule from the drop-down list.
    • Description: Optionally, enter a description.
    • Type: The access privilege (allow or deny) that this policy grants.
    • Source Address: Enter an IP subnet and netmask of the network source from which you want to allow or deny access. The IP address must be in the format A.B.C.D/M, where M is the subnet mask.) Otherwise, select Any. For example, if you enter 192.168.0.1/24, the rule allows or denies the entire Class C subnet. To allow or deny a single host, use /32 as the netmask.
    • Destination Address: Enter an IP subnet and netmask of the network target to which you want to allow or deny access. (The IP address must be in the format A.B.C.D/M, where M is the subnet mask.) Otherwise, select Any. For example, if you enter 192.168.0.1/24, the rule allows or denies the entire Class C subnet. To allow or deny a single host, use /32 as the netmask.
    • Application: If you select a specific application from the list, the Protocol and Destination Port options are automatically filled with the relevant values and are not configurable.
    • Protocol: Enter a network protocol number (from 0 through 254), as defined by the IANA (http://www.iana.org/assignments/protocol-numbers/protocolnumbers.xhtml) to allow or deny. Otherwise, select Any.
    • Source Port: Enter a valid source port number (from 1 through 65534) or port range (for example, 80-443).
    • Destination Port: Enter a valid destination port number (from 1 through 65534) or port range (for example, 80-443).
  7. Click Add to add a new rule.

    To change the order in which rules are implemented, click the icon on a specific row to move the rows up or down. Alternatively, you can select a specific rule and click Move Up or Move Down to move the rows.

    You can also edit, clone, or delete rules by selecting a specific rule checkbox, then clicking Edit, Clone, or Delete options, respectively.

  8. Click Add to add the ACL.
    You can create up to 32 Layer 3/Layer 4/IP address-based access control rules.

Configuring a Layer 3/Layer 4/IP Address-Based ACL