
Filtering rules for a WM-AD
Summit WM-Series WLAN Switch and Altitude Access Point Software Version 1.0 User Guide
89
6 Highlight the new filtering rule and fill in (or leave unchecked) the three checkboxes in the
combinations that define the traffic access:
For Captive Portal, to allow access to the defined IP address, check all three boxes on.
7 Edit the order of a filtering rule by highlighting the line and clicking on the Up and Down buttons.
The filtering rules are executed in the order defined here.
8 To save the filtering rules, click on the Save button.
Non-authenticated filters: examples
A basic Non-Authenticated filter for Captive Portal should have three rules in this order:
If you put URLs in the header and footer of the Captive Portal page, you must include a filtering rule to
allow traffic to each of these URLs. Put these rules above the “deny everything” rule.
Here is another example of a Non-Authenticated Filter that adds two more filtering rules: one denies
access to a specific IP address, and the next rule allows only HTTP traffic, before denying all other
access:
In: Click checkbox on to refer to traffic from the wireless device that is trying to get on
the network (“going to” the network)
Out: Click checkbox on to refer to traffic from the network host that is trying to get to a
wireless device. (“coming from” the network)
Allow: Click checkbox on to allow. Leave unchecked to disallow.
In Out Allow IP / Port Description
x x x IP address of the Default
Gateway
Allow all incoming wireless devices access to the default
gateway of the WM-AD.
x x x IP address of the DNS
Server
Allow all incoming wireless devices access to the DNS
server of the WM-AD.
x x *.*.*.* Deny everything else.
In Out Allow IP / Port Description
x x x IP address of the Default
Gateway
Allow all incoming wireless devices access to the default
gateway of the WM-AD.
x x x IP address of the DNS
Server
Allow all incoming wireless devices access to the DNS
server of the WM-AD.
x x [a specific IP address, or
address plus range]
Deny all traffic to a specific IP address, or to a specific
IP address range (such as :0/24).
x x x *.*.*.*:80 Allow all port 80 (HTTP) traffic.
x x *.*.*.* Deny everything else.
Commentaires sur ces manuels