
Summit WM-Series Switch Software and your network
Summit WM-Series WLAN Switch and Altitude Access Point Software Version 1.0 User Guide
21
Policy: packet filtering
Policy refers to the rules that allow different network access to different groups of users. The Summit
WM-Series Switch Software system can link authorized users to user groups. These user groups then
can be confined to predefined portions of the network.
In the Summit WM-Series Switch Software system, policy is carried out by means of packet filtering,
within a WM-AD.
In the Summit WM-Series Switch user interface, you set up a filtering policy by defining a set of
hierarchical rules that allow (or deny) traffic to specific IP addresses, IP address ranges, or services
(ports). The sequence and hierarchy of these filtering rules must be carefully designed, based on your
enterprise’s user access plan.
The authentication technique selected determines how filtering is carried out:
● If authentication is by SSID and Captive Portal, a non-authenticated filter will allow all users to get
as far as the Captive Portal web page, where login occurs. When authentication is returned, then
filters are applied, based on user ID and permissions.
● If authentication is by AAA (802.1x), users will already have logged in and have been authenticated
before being assigned an IP address. At this point, filters are applied, based on user ID and
permissions.
Mobility and roaming
The 802.11 standard allows a wireless device to preserve its IP connection when it roams from one
access point to another on the same subnet. However, if a user roams to an access point on a different
subnet, the user is disconnected.
Summit WM-Series Switch Software has functionality that supports mobility on any subnet in the
network. Wireless device users can roam between Altitude APs on any subnet without having to renew
the IP connection.
The Summit WM-Series Switch stores the wireless device’s current session information, such as IP
address and MAC address. If the wireless device has not disassociated, then when it requests network
access on a different Altitude AP, the Summit WM-Series Switch can match its session information and
recognize it as still in a current session.
In addition, a Summit WM-Series Switch can learn about other Summit WM-Series Switches on the
network, and then exchange client session information. This enables a wireless device user to roam
seamlessly between different Altitude APs on different Summit WM-Series Switches.
Komentáře k této Příručce