ManagingClientQoSACLs
D-Link UnifiedAccessPointAdministrator’sGuide
November2011 Page131
UnifiedAccessPointAdministrator’sGuide
ManagingClientQoSACLs
ACLsareacollectionofpermitanddenyconditions,calledrules,thatprovidesecuritybyblockingunauthorized
usersandallowingauthorizeduserstoaccessspecificresources.ACLscanblockanyunwarrantedattemptsto
reachnetworkresources.
TheUAPsupportsupto50IPv4,IPv6,andMACACLs.
IPv4andIPv6ACLs
IPACLsclassifytrafficforLayers3and4.
EachACLisasetofupto10rulesapplied totrafficsentfromawirelessclientortobereceivedbyawireless
client.Eachrulespecifieswhetherthecontentsofagivenfieldshouldbeusedtopermitor
denyaccesstothe
network.Rulescanbebasedonvariouscriteriaandmayapplytooneoremorefieldswithina packet,suchas
thesourceordestinationIPaddress,thesourceordestinationL4port,ortheprotocolcarriedinthepacket.
MACACLs
MACACLsareLayer2ACLs.Youcanconfiguretherulestoinspectfieldsofaframesuchasthesourceor
destinationMACaddress,theVLANID,ortheClassofService802.1ppriority.Whenaframeentersorexitsthe
APport(dependingonwhethertheACLisapplied
intheupordowndirection),theAPinspectsthefr ameand
checkstheACLrulesagainstthecontentoftheframe.Ifanyoftherulesmatchthecontent,apermitordeny
actionistakenontheframe.
ACLConfigurationProcess
ConfigureACLsandrulesontheClientQoSACLpage(steps1–5),andthenapplytherulestoaspecifiedVAP
ontheAPQoSParameterspage(step6).
UsethefollowinggeneralstepstoconfigureACLs:
1. SpecifyanamefortheACL.
2. SelectthetypeofACLto
add.
3. AddtheACL
4. AddnewrulestotheACL.
5. Configurethematchcriteriafortherules.
6. ApplytheACLtooneormoreVAPs.
ForanexampleofhowtoconfigureanACL,see“ACLConfiguration”onpage174
ToconfigureanACL,clicktheClientQoSACLtab.