Subscribe to our RSS Feeds
Hello, this is a sample text to show how you can display a short information about you and or your blog. You can use this space to display text or image introduction or to display 468 x 60 ads and to maximize your earnings.

Monday, September 13, 2010

Design Structured Cabling Systems and IT wireless Network Infrastructures

Introduction

Designing a Structured Cabling System - a ten step HOWTO guide

Steps

Below we have provided a ten step introductory guide for the Design of Structured Cabling Systems and IT Network Infrastructures. (see structured cabling schematic)

Step 1: Which group of standards will you conform to?

European Union CENELEC EN standards America ANSI/TIA/EIA standards Canada CSA standards Australia/New Zealand AS/NZ standards Rest of the World ISO/IEC standards

The three principle design standards give the details of how to design and specify a structured cabling standard, they are;

ISO 11801
EN 50173
TIA/EIA 568-A or 568-B

BICSI


These standards in turn however refer to hundreds of other standards relating to component specifications, fire performance, testing methods, containment systems etc.

Step 2: Horizontal cabling - Basic rules

Four-pair cables are run from user positions to a patch panel. At the patch panel, patchcords link into the active LAN equipment or into backbone cabling. The user position has a wall outlet or floor outlet, and this links into the PC on your desk via another patchcord. The outlet is a called a TO (Telecommunications Outlet) and contains an eight way plug meeting IEC 60603-7, more commonly referred to as an RJ-45.

  • Two outlets per work area
  • Two outlets per 10 square metres of useable floor space
  • Outlets to be within 3 metres of the user station
  • Both outlets to be RJ 45
  • Max cable run to be 90 m
  • Max total length of patchcords at both ends of the link to be 10 m
  • Cable and RJ45 to be Cat5e grade

Options

Cat 3 or optical fibre can be used

If optical fibre, select 50/125 or 62.5/125 multimode

If using fibre select SC or ST connectors

Cat 6/Class E can be specified

Cat 5e Cable can be unscreened, UTP, Foil screened, FTP, or Foil and Braid screened S-FTP.

Cable fire performance can be:

  1. IEC 332-1
  2. IEC 332-1, IEC 754, IEC 1034
  3. IEC 332-3-c. IEC 754, IEC 1034
  4. UL 910 plenum

Each grade, in ascending order, has a better performance in fire situations but at a correspondingly higher price.

The exact density of cables, number of outlets and their position is up to the end user, or else at the proposal of the installer/designer

Step 3: Backbone Cabling

All of the horizontal cables are star-wired back to Telecommunications Closets or Floor Distributors where they are terminated in patch panels. These patch panels are connected together via the building backbone cabling which can be up to 500 metres long. It can be copper cable but is more likely to be optical fibre, either multimode or singlemode. The kind of cables and the number of cores needs to be decided.If fibre is chosen, a loss budget should help you make your decision

Step 4: Campus Cabling

The campus cabling links different buildings together. It can be up to 1500 m long. It can be copper cable but is more likely to be optical fibre, either multimode or singlemode. The kind of cables and the number of cores needs to be decided.

Step 5: Positioning and design of Telecommunications Closets to link horizontal and backbone cabling.

Positioning and design of the equipment room as a central focus for the main computing, LAN and PABX equipment.

Positioning and design of the Service Entrance facility whereby outdoor cables are terminated and the point of demarcation between customer owned equipment and the PTT cables is defined.

Step 6: Cable containment system

How will the cables be protected? Within buildings the choices are:

  • Cable trays
  • wire basket/raceway
  • cable ladders
  • J hooks
  • conduit
  • dado rails
  • PVC trunking
  • built-in underfloor duct
  • raised floors
  • suspended ceilings

The following must be taken into account:

  • the density and volume of cables to be organised
  • the aesthetic appearance of the cabling within offices and other visible areas
  • economics of different schemes
  • proximity to power cables and other potential sources of interference
  • firestopping

Useful standards are:

  • TIA/EIA 569 Commercial building standard for telecommunications pathways and spaces
  • EN 50174 Information technology – cabling installation

For external applications the choices are:

  • underground cable ducts
  • direct buried cable trench
  • concrete cable trough
  • self supporting aerial cable
  • supported aerial cable, i.e. catenary or messenger wire
  • fixed to building exteriors

In all cases the designer must ensure that all civils work has been carried out, rights of way established and availability of cable ducts and manholes established. Aerial cable routes must keep a minimum distance away from power cables and all external cables must be selected for the environment and temperature ranges in which they are expected to survive. External copper cables usually need to be protected by overvoltage and fault current devices where they enter a building.

Step 7: Cable Administration system

The cabling and its containment system need to be clearly identified and their locations, routes and capabilities recorded in a cable administration system. This usually involves a logical numbering scheme that can be applied to all cables, outlets, patch panels and even containment systems. Various colour schemes are also available.

These schemes can be paper based but for the larger installations then a computer based system is advisable. There are several proprietary solutions on the market which offer various database and graphical methods for keeping track of cabling assets. Some systems are also active in that they can detect moves and changes and automatically update the database.

Useful standards are:

  • TIA/EIA-606 Administration standard for the telecommunications infrastructure of commercial buildings
  • EN 50174 Information technology – cabling installation

Step 8: Earthing Scheme

All exposed metallic elements of the cable system and cable containment system need to be earthed (grounded) for safety and also electromagnetic compatibility requirements. If screened cables are used then special attention must be given to effective bonding of the screening elements. Poorly earthed screened cabling may behave worse than unscreened cabling.

An electrically ‘clean’ earth must be available at all points where the cabling is terminated, but especially within telecommunication closets, equipment rooms and service entrances. A clean earth is usually defined as a conductive element with not more than 1 volt rms potential difference between it and the real earth down below. Copper cabling linking two different buildings can suffer from earth loops if the ground potential is different. Non-metallic optical cabling is usually picked for problem areas such as these.

Some useful standards are:

  • PrEN50303 Application of equipotential bonding and earthing at premises with information technology equipment
  • PrEN50174-2 Information Technology, Cabling installation, part 2, Installation, planning and practices inside buildings
  • TIA/EIA-607 Commercial Building Grounding and Bonding Requirements for Telecommunications

Step 9: Testing regime

All cables must be tested to demonstrate compliance with the standards and specification to which they were bought. Testing can be split into copper cable testing and optical fibre testing. Ideally all cables should be 100% tested.

Copper cables.

There are five manufacturers of hand held copper cable testers that will automatically test the installed cable plant for all the expected parameters. By the use of a remote injector, the cabling is tested from both ends, which is a condition of the standards. The cabling has to pass all of the suite of tests to be awarded and overall pass. Points to remember are;

What is being tested? the channel (i.e. end-to-end including all the patchcords) or the basic link (i.e. the permanently installed cable from outlet to patchpanel). The test figures are different for each setting. It is usually more practical to test the basic link (also referred to as the permanent link).

What level is being tested? The tester should normally be set to Cat5e link or Class E link if Category 6 cable is being used.

The results are stored electronically and must be in a format recognisable by the cable management software that comes with the tester. There are now numerous test standards and draft standards. The most influential is likely to be;

IEC 61935 Generic specification for the testing of balanced generic cabling in accordance with ISO/IEC 11801

The tests required are; IEC 61935 Wire Map X Attenuation X; NEXT pair to pair X; NEXT Powersum X; ELFEXT air to pair X; ELFEXT Powersum X; Return Loss X; Propagation Delay X; Delay Skew X;DC Loop Resistance X. Cable length and ACR are also useful additions to this set of tests.

Optical cables

All that needs to be tested with short distance multimode optical cables is attenuation. This can be achieved by a device called a light source and power meter. This device will simply measure the absolute loss across the optical link. This then has to be compared with the design value of attenuation. If the tested value is less than the design value then the link can be seen to be acceptable.

Optical Time Domain Reflectometers can give a great deal of information about optical fibres, but for short haul multimode fibre they are an expensive overkill that gives results that need expert interpretation. An OTDR remains an essential tool for fault finding.

Step 10: Final thoughts

Is the design of the cabling system in-step with the LAN aspirations of the end user? For example, Cat5e is the minimum performance grade suitable for gigabit Ethernet. Standard Cat5 cable may not have sufficient delay skew performance for RGB video systems however. Cat 6 cabling will give a longer service life due to its higher performance, but at an initial higher cost.

Some optical fibre LANs, e.g. gigabit Ethernet cannot transmit over the full distance allowed in standards based optical structured cabling. These LAN limitations have to be taken into account. The next generation of 10 gigabit Ethernet will need a new generation of optical fibre to make it work.

The best way to ensure success in a structured cabling installation is to use properly trained people to design, implement and test the system. The RCDD qualification from BICSI is the only qualification which covers all aspects of structured cabling design and implementation.

The above information is offered as a summary of ISO 11801 and related standards. It is not a definitive design guide and does not replace study and implementation of the Standards themselves. The publisher accepts no responsibility for inaccuracies or omissions. To purchase the full Standards go to your national standards body, e.g. British Standards Institution, Nederlands Normalisatie Instituut etc. or ISO.



Wireless Network Management

Wireless Network Management refers to use of software tools designed to enhance performance, reliability and security of wireless networks particularly by diagnosing, detecting and reducing sources of radio frequency interference. Unlike in case of wired networks, where the redundancy of the equipment can be applied to mitigate the impact of performance problems and network failures to some extent, the wireless networking have a very limited options owing to availability of very limited wireless spectrum and the effects of wireless interference.

The factors that can have impact on the wireless network performance include traffic flows, working of the network topologies and network protocols, hardware, software and also, the environmental conditions. Therefore, often the Wireless users can be subjected to problems such as lack of coverage, intermittent discontinuity and difficult to monitor security aspects.

Wireless Network Management systems help to ensure network availability, as well as to provide other maintenance tasks, such as performance monitoring, testing, and fault management.

Some of the tools for Wireless Network management are Colubris MultiService Access Points (Maps), Airwave Management Platform (AMP) and Wireless Management Suite, wireless network management spectrum analysis software from Cognio Inc., Radio IP MTG, Cisco’s suite of Wireless Network management products etc.

Friday, September 10, 2010

Wireless Network and Router Security Tips

Reminded by the latest Cisco security alert, many network managers do not realize that their routers can be the jump point to attack. Router operating systems are just as vulnerable to hacker mischief as network operating systems. Most medium to small sized companies do not employ router engineers, or outsource this function on a need to do basic. And because of this, network administrators, and managers, either do not know enough to secure the router or do not have time. Listed below are the 10 basic router security tips.

1. Update your router's OS. Just like network operating systems, router operating systems need to be updated to correct programming oversights, flaws, and buffer overflow issues. Always check with your router manufacture for current updates and OS versions.

2. Change the default password. As much as 80 % of security incidents are caused by weak or default passwords, (This is according to CERT at Carnegie Mellon University) Avoid using common passwords and use mixed case letters as a stronger password policy .

3. Disable HTTP configuration and SNMP. The HTTP configuration part of your router may be easier to configure for a busy network admin, but it is also a security problem for routers. If your router has a command line configuration, disable the HTTP config mode and use it. If you are not using SNMP on your router, then there is no need to have it enabled. Cisco has a SNMP vulnerability with GRE tunnel attacks.

4. Block ICMP ping requests. Ping and other ICMP functions are useful tools for both the network admin and the hacker. ICMP enabled on your router can be used by hacker to identify information to target your network for attack.

5. Disable Telnet use from the Internet. In most cases you do not need an active telnet session from an Internet interface. Access to your router's configuration is more secure if accessed internally.

6. Disable IP directed broadcast. IP directed broadcast can allow Denial of Service (DOS) attacks on your equipment. A router's memory and CPU can be maxed out from too many requests, which can result in a buffer overflow entry.

7. Disable IP source routing and IP redirects. Redirects allow packets to come in from one interface and leave by another. You don't want engineered packets to redirect to a private internal network.

8. Packet filtering. Packet filtering routes only the types of packet you want to enter your network. Many companies only allow 80 (http) and 110/25 (email). Additionally you can block and allow IP Addresses and Ranges.

9. Review Security Logs. By simply taking the time to review your log files you will see obvious patterns of attack, and or even vulnerabilities. You will be surprised to how much activity your router is subject to.

10. Unnecessary Services. Unnecessary services should always be disable, whether they are on a router, server, or workstation. By default, Cisco devices up through IOS version 11.3 offer the "small services": echo, chargen, and discard. These services, especially their UDP versions, are infrequently used for legitimate purposes, but can be used to launch denial of service and other attacks that would otherwise be prevented by packet filtering.

Troubleshooting Wireless Network Connections

In this article we will look at how to tackle some common wireless network problems that people come across. This document will outline the steps you should take if you encounter one of the mentioned issues.

Check the wires and wireless network adapter

Checking that all your wires are plugged in at the router and from the plug is one of the first things you should do – provided of course that you have access to them. Verify that the power cord is connected and that all the lights of the router and cable/DSL modem are on. This may seem like a ridiculous suggestion but you should never disregard the obvious. You’d be surprised at how your configuration can be perfect, and after a while of playing around with settings you realize that the network cable leading from the router to the cable modem has come undone slightly.

You will also want to check that your wireless network adapter is switched on. Some laptops come with a small blue or red button on the side while others require you to enable it from the operating system. In Windows, go to device manager and check that your wireless network adapter is enabled. If you have a PCMCIA or USB wireless adapter try removing it and then re-inserting it while Windows is running so it will re-detect it. The lights on the adapter give an indication of whether there is a problem. On mine, I have two lights; one is orange to signify that the PCMCIA card has power and the other is green to show if a connection has been established. A blinking green light means that I am not in range of a wireless access point or there is a problem with connectivity, whereas a stable light means a connection has been established successfully. Take a look at your device documentation as these sorts of details will vary with each product.

Driver Compatibility

It is important to make sure that you have installed the correct device driver for your wireless network adapter. This can cause all sorts of problems or your adapter not to function at all. A friend of mine recently set up his own wireless network at home but complained to me that his wireless network connection was going “crazy”. Upon inspection I realized that he had configured his router properly but installed the 5v instead of the 3v driver on his laptop PCMCIA network card. Once the correct driver was installed, everything began to run smoothly. It just goes to show how even the smallest detail can make all the difference so make sure you have the correct driver installed!

Low Signal Strength

There are a number of factors that can cause the signal of your access point to deteriorate and the performance of your network to fall under par. Practically any appliance that operates on the same frequency level (2.4 GHz) as 802.11b or 802.11g can cause interference with your wireless network. Be sure to keep cordless phones, microwaves and other electrical equipment at least 1m away from the access point. Try changing channels on the access point and test it out on one of the clients. To change the radio channel on the access point login to the configuration (usually a web based interface) and go to the Wireless Settings (will vary depending on vendor) section, select a different channel and save settings. On the client, go to Device Manager, right click your wireless network adapter and go to Properties. In the advanced tab select the Channel Property and change the Value to the same number as the one you chose on the Access Point. Disable and then re-enable the wireless connection.


Access Point Location

You may also want to try changing the position of your access point antenna to improve performance. Play around with its position and see if you notice a difference. I find that if I point the antenna sideways or downwards I have better reception on the floor below. The following images demonstrate what I mean.


Antenna pointing upwards (default)


Antenna pointing sideways

The location of your access point is vital. Try and place it in a central location, as much as possible avoiding physical obstructions and reflective surfaces. Remember that wireless signals bounce of windows and mirrors, thus decreasing the range. Experiment with different locations until you find one that is practical and promising. Most people, including myself, like placing it near the ceiling since most obstructions are nearer to the floor.

It’s always a good idea to monitor the performance of your signal by using a diagnostic utility. This will help you to identify how strong your signal is in different locations and whether other electrical equipment is interfering. Run the utility when the microwave or cordless phone is in use and see if you notice a difference. Usually your access point will come with its own monitoring utility.

Installing a repeater for a performance boost

If you’re looking for a boost you can always choose to install a repeater. The job of a repeater is to receive the signal, regenerate it and rebroadcast it therefore extending the range of your wireless network. This would sit somewhere between your Access Point and your wireless client. Some repeaters, like the Range Expander series from LinkSys, don’t require it to be directly connected to the network via a cable. However, if security is an issue for you then be careful as some of these ignore certain security methods such as MAC address filtering. Also, some repeaters will only repeat wireless signals coming from its own product family, i.e.: if you have a D-Link Wireless Router you will have to get a D-Link repeater. The image below demonstrates the job of a repeater.


The Access Point transmits the signal. As it travels it decreases, until it hits the repeater and gets boosted. The newly transmitted signal is then received by an in-range wireless client.

Changing the Antenna

Changing the antenna of your access point can increase signal range and overall performance. Typical access points come with a 2dB or 4dB gain antenna but there are one’s available with 8, 14 and even 24dB. Antenna gain is measured in dBi (decibels-isotropic) which basically means how powerful the antenna is and how far it can provide a signal. Directional antennas are suitable for environments where you have a direct line of site from one access point to another and from access point to client; the signal travels in a straight line. Omni-Directional antennas distribute their signal in a circular 360 degrees motion over a horizontal pane, which is ideal for square areas.

Install Windows XP SP2

If you are using Windows XP on your wireless client - as I’m sure most of you are – installing Service Pack 2 would be a good idea. Check the Microsoft Website for download details. Windows XP Service Pack 2 comes with enhanced wireless support such as a new network setup wizard, built in support for WPA (Wi-Fi Protected Access), an updated Wireless Network Connection dialog box and amongst others, a rather nifty repair feature.

To utilize the repair feature all you have to do is right click the connection and select Repair or click the button on the support tab of the status dialog box. This will disable and then re-enable the connection (which clears many of the error conditions on wireless network adapters), clear the NetBT cache and flush the DNS cache. I often find that if my connection signal becomes low after a long period of activity, pressing the Repair button will boost it up to “Good” or “Very Good” depending on my location.

Network Settings

DHCP Addresses

DHCP configuration errors may also cause problems when connecting to a wireless network. Some of the newer access points on the market come with their own DHCP server which usually assigns addresses in the 192.168.0.x range. If your wired network uses a different range then you will probably find that wireless network clients are able to obtain an IP address and ping the access point but communication with other clients will not work. Your access point configuration interface should allow you to set which address scope to use. Set this to be the same as that of your other clients. You can also just disable the DHCP server on the access point and allow clients to obtain an address from the normal DHCP Server on your network.

Encryption Keys

Double check and re-enter your WEP/WPA encryption keys. Wireless Encryption will vary depending on which type of network you are connecting to. In Windows XP, on the Association tab of your wireless network properties dialog box, verify that your network key has been entered correctly and is valid for the network you are attempting to connect to.

MAC Address Filters

A great form of security to allow restricted access to your network. As I had explained in An Introduction to Wireless Networking Part 1, MAC Address Filters are a list of MAC addresses belonging to the clients that are allowed access to the network. This will only permit clients with the specified MAC Addresses to communicate with the network. Having said this, it may be the reason to your problem. Verify that the problematic client’s MAC is in the address list. If the network card had to be changed or a new device purchased recently, be sure to add it to the list.

Conclusion

After having read this article you should be familiar with common wireless network connections problems and what you can do to fix them. I hope that you will now be able to follow these steps when a wireless problem occurs and take the necessary action in solving such issues. Look out for Part 3 of my Introduction to wireless networking series in which I will take a closer look at security, give you some wireless network tips and tricks and also update you on the latest wireless networking news.

Top 10 things to know about network administration

If you're just getting started in the networking field, you've got a lot to learn, and with the rate of changes in networking technology, you can expect to always have a lot to learn, but here are ten essential topics that you should concentrate on (and if you are not just getting started, here are some things to review):

  1. The OSI model: Memorize it. It's almost a cliché, but understanding it is critical.
  2. TCP/IP concepts: Learn to think in binary and get a firm grasp on bitmasks, subnetting, gateways (like the "default gateway") and how addresses are constructed (the network portion, the host portion, etc).
  3. Stacks: Read about how the network stack is implemented on hosts. Get a good feel for what each component (the NIC, firmware, device drivers, the OS, etc) is responsible for. Once you understand this, troubleshooting is easy.
  4. Layer 2: Learn how switches operate and how they're different from hubs and routers. Understand bridging, and get a general idea of what Spanning Tree Protocol does. Learn the difference between a collision domain and a broadcast domain, and then study VLANs.
  5. Routing: Learn a routing protocol. Start with RIP, because it's easy. You don't need to be a guru, just get a general idea about how routers can exchange information about the network.
  6. Services: Understand the role of DNS and DHCP and WINS and know their alternatives, like the host and lmhost files and static addressing.
  7. Find yourself some good networking reference material. Whatis.com is a great for deciphering arcane acronyms.
  8. Security: Read a little about how firewalls operate and other security technologies like VPNs. Understand the difference between authentication, authorization and accounting.
  9. Output: Learn how to get status and information out of your networking devices. A good place to start is with the "show" commands (which will be featured in next week's tip).
  10. Finally, do a walkthrough: follow data as it goes from one application to another. How does it get from the application, to being segmented, packetized, framed, and routed? How does your computer know what IP address to send the packet to? (DNS) How does it know what MAC address to send it to? (ARP) How does it know how big to make the frame? (MTU) How does a switch know which port to forward your packet out on? (FDB) How does a router know which interface to use? (routing table) If you can answer these questions, you're well on your way to being competent and productive.

wireless application service provider

A wireless application service provider (WASP) is part of a growing industry sector resulting from the convergence of two trends: wireless communications and the outsourcing of services. A WASP performs the same service for wireless clients as a regular application service provider (ASP) does for wired clients: it provides Web-based access to applications and services that would otherwise have to be stored locally. The main difference with WASP is that it enables customers to access the service from a variety of wireless devices, such as a smartphone or personal digital assistant (PDA).

Although the business world is increasingly mobile, many corporations are resisting the idea of wireless communication, because of concerns about set-up and maintenance costs and the need for in-house expertise. WASPs offer businesses the advantages of wireless service with less expense and fewer risks. Because mobile applications are subscribed to, rather than purchased, up-front costs are lower; because the WASP provides support, staffing and training costs are lower.

WASP services may include:

  • Constant system monitoring
  • Diagnostics and resolution
  • User support
  • Text formatting for various devices
  • Problem detection and reporting

There are still issues to be resolved. Coverage areas remain limited, for example, and data synchronization among devices can be problematic. Nevertheless, WASPs provide an easier, safer, and cheaper way for organizations to add mobile components, and a number of major companies are opting for them. UPS, Sprint, and eBay are among the early subscribers to WASP services. Interestingly, some ASPs have begun to offer WASP services, while others are purchasing them.



Wireless Security Filtering

Filtering

Managing access to a WLAN through WEP keys or authentication is one viable security measure. You can also configure access to be restricted according to device; to do this, you use the Media Access Control (MAC) address or Internet Protocol (IP) address. For example, you can employ filtering on your APs to keep out clients who do not have an authorized client adapter. Without an explicitly approved MAC address on the network adapter, it doesn't matter if the correct username and password are presented because the AP does not allow access.

Simply put, filtering checks a wireless client's MAC or IP address against a list of authorized MAC or IP addresses maintained on the AP. When a client tries to connect to the AP, it must be on the list. If it is not, the client cannot connect.

Filtering should not be the only security measure, however. Both MAC and IP addresses can be spoofed, thus circumventing this layer of security.

MAC Filtering

You can set up a MAC filter two ways:

  • To pass traffic to and from all MAC addresses except those you specify.

  • To block traffic to and from all MAC addresses except those you specify.

Furthermore, you can apply these filters to either or both the Ethernet and radio ports and to incoming or outgoing traffic.

Note

Be careful when setting MAC filters. If you incorrectly apply the setting, you can easily lock yourself out of the AP. If this does occur, use the command-line interface (CLI) to disable filters, and then go in and correct your mistake.

MAC filters are managed on the MAC Address Filters page ; simply follow these steps:

Step 1. On the AP's web page, click Services on the menu to the left of the page.

Step 2. Click Filters in the list of services.

Step 3. Click the Mac Address Filters tab on the Apply Filters page.

After you reach the Apply Filters page, you can enable MAC address filters.

Note

Be aware that software often changes. The version of the AP firmware you use might differ from what is shown here, but the steps are similar.

Setting MAC Filters

To configure a MAC filter, follow these steps:

Step 1. To create a new MAC address filter, click Create > Edit Filter Index > . To edit a filter, select the filter number from the menu.

Step 2. In the Filter Index field, identify the filter with a number between 700 and 799. This number is used to assign an access control list (ACL) for the filter.

Step 3. Enter a MAC address in the Add MAC Address field. The address is entered as three groups of four characters, separated by periods (for example, 0125.4275.7879).

Step 4. Use of the Mask entry field enables the filter to check against certain bits, but not others. For example, if you have several clients whose MAC addresses all end in the same four bits, you can use the mask to allow any clients whose MAC address matches those four bits. If you want to force an exact match of the MAC address, in the Mask entry field, enter FFFF.FFFF.FFFF. If you just want to check the last four bits, enter FFFF.FFFF.0000.

Step 5. Choose Action > Forward or choose Action > Block.

Step 6. Click Add. The MAC address you entered has been added to the Filters Classes field. You can remove this address by selecting it and clicking Delete Class.

Step 7. Choose Default Action > Forward All or Default Action > Block All. You must establish the default action for this filter, and it must be the opposite of the action for at least one of the MAC addresses in the filter. For example, if you chose Forward for several MAC addresses, you should select Block All as the filter's default action.

Step 8. Click Apply.

Step 9. Click the Apply Filters tab.

Step 10.Select the filter number from one of the MAC drop-down menus. The filter can be applied to either the Ethernet port, the radio ports, or both. You can also apply the filter to incoming traffic, outgoing traffic, or both.

Step 11. Click Apply.

Note

You need to restart the system, so that all clients are appropriately filtered.

IP Filtering

You can also limit access to your AP with IP filters. IP filtering can be applied based on IP address, IP protocol, and IP port. This allows or prevents the use of specific protocols through the AP's Ethernet and radio ports. Like MAC filtering, you can also set up the filter to allow or deny sending or receiving traffic from the AP based on IP address.You can set up IP filters to allow combinations of all three IP filtering components (address, protocol, and port).

IP filters are managed on the IP Filters page.

To reach the IP Filters page, follow these steps:
Step 1. On the AP's web page, click Services on the menu to the left of the page.

Step 2. Click Filters in the list of services.

Step 3. Click the IP Filters tab.

After you reach this page, you can enable IP filters.
Setting IP Filters

To configure an IP address filter, follow these steps:

Step 1. To create a new IP address filter, select Create > Edit Filter Index > . To edit a filter, select the filter number from the menu.

Step 2. In the Filter Name field, identify the filter with a name.

Step 3. Select Default Action > Forward All or Default Action > Block All from the Default Action. You must establish the default action for this filter and it must be the opposite of the action for at least one of the IP filters. For example, if you chose Forward for several IP addresses, you should select Block All as the filter's default action.

Step 4. To filter a specific IP address, enter that address under the IP Address section. The Destination Address field is used to filter traffic going to an address; the Source Address filters filter traffic coming from a given IP address.

Note

If you intend to block traffic to all IP addresses except those specified, make sure you include the IP address of your own computer in the list of specified exceptions; otherwise, your computer is shut out from the AP.

Step 5. The Mask entry field allows the filter to check against certain bits, but not others. Type the subnet mask in this field. The mask is used if you are filtering everything to or from a subnet.

Step 6. Select Action > Forward or select Action > Block.

Step 7. Click Add. The IP address you entered has been added to the Filters Classes field. This address can be removed if you select it and click Delete Class.

Step 8. To filter an IP protocol, select one of the protocols from the IP protocol drop-down menu, or select the Custom radio button and enter the number of an existing ACL in the Custom field. Enter an ACL number from 0 to 255.

Step 9. Select Action > Forward or select Action > Block.

Step 10. Click Add. The protocol appears in the Filters Classes field. This field is at the bottom of the page and is shown in Figure 8-4. This filter can be removed if you click Delete Class.

Step 11. To filter a TCP or UDP port protocol, select one of the common port protocols from the TCP Port or UDP Port drop-down menus, or you can select the Custom radio button and enter the number of an existing protocol in one of the Custom fields. Enter a protocol number from 0 to 65535.

Step 12. Select Action > Forward or select Action > Block.

Step 13. Click Add. The protocol appears in the Filters Classes field. This filter can be removed if you click Delete Class.

Step 14. Click Apply.

Step 15. Click the Apply Filters tab.

Step 16. Select the filter names from one of the IP drop-down menus. The filter can be applied to the Ethernet port, the radio ports, or both. You can also apply the filter to incoming traffic, outgoing traffic, or both.

Step 17. Click Apply.