User’s Manual
WHG Controller / HSG Gateway ENGLISH
Group is a user role profile which defines the accessibility of a user to different
Service Zones and in turn defines the QoS properties as well as network policy
when access is granted. Each and every connected user will belong to a Group,
determined by the type of user account used for authentication. If the administrator
does not assign a new account to any specific Group or for users not required to
authenticate, they will belong to a catch-all group named “None” by default.
Policy is the second tier of user control once a user’s Group profile has been
determined. Policy defines the firewall rules, privileges, login schedule, routing rules
and session limit which will be enforced to users of a particular Group. A user may
only belong to one Group but can be governed by different policies while accessing
different Service Zones.
For users belonging to the “None” group or users not explicitly assigned a network
Policy, they will be governed by a default catch-all policy named ‘Global-Policy’. The
Global-Policy is a base policy which will be applied to all users if not applied with
another policy.
The following Figure is an example that depicts the relationship between Service
Zone, Group and Policy. In this example, Students and faculties logging into Service
Zone 1 will be governed by Policy-A. Guests only have access to Service Zone 3,
and will be bounded by Policy-C. Faculties have the access to both Service Zone 1
and Service Zone 2 under two different policies.