Wireless Access

last person joined: 15 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Does ACL white lists block traffic through the controller or only to the controller

This thread has been viewed 2 times
  • 1.  Does ACL white lists block traffic through the controller or only to the controller

    Posted Apr 22, 2016 11:10 AM

    Hi,

    I am reading the manual time after time, but cannot understand if the ACL white list will block/rate limit only traffic to the controller or also through the controller. It seems to be a feature that do not require PEFNG, but apply to all traffic hitting the controller.

     

    Maybe my brain has to be improved :-)

     



  • 2.  RE: Does ACL white lists block traffic through the controller or only to the controller

    EMPLOYEE
    Posted Apr 22, 2016 11:25 AM

    It depends where ACLs are applied.

     

    In general:

    ACLs applied to a ROLE only affect users in that role.

    ACLs applied to a physical interface affect all traffic going through that interface.

     

     



  • 3.  RE: Does ACL white lists block traffic through the controller or only to the controller

    Posted Apr 22, 2016 11:34 AM

    Hmm,

    This type of ACL does not have a name or number so how do I apply it to a role or interface?

    I have seen that I can apply a bandwisth contract to a role (with PEFNG a.f.a.i.k.), but not the white list. Can you refer to a manual page where this is done?

     

    (config-fw-cp) #ipv4 permit 10.10.10.10 2.2.2.2 proto ftp bandwidth-contract name mycon
    tract

     

    Thanks!



  • 4.  RE: Does ACL white lists block traffic through the controller or only to the controller

    Posted Apr 22, 2016 11:36 AM

    and my question still remains. 

    All traffic thrrough the controller or only to the controller?



  • 5.  RE: Does ACL white lists block traffic through the controller or only to the controller

    EMPLOYEE
    Posted Apr 22, 2016 11:45 AM

    The specific command in your example is traffic to and from the management plane (control plane) of the controller.  The equivalent in the real world is called a service acl.  It has no effect on the users on a controller, but mainly devices that would communicate with a controller, like access points, management users who would SSH and WEB into the controller to configure it, etc.

     

    Information on that specific command is here:  http://www.arubanetworks.com/techdocs/ArubaOS_6.4.4.x_WebHelp/Web_Help_Index.htm#ArubaFrameStyles/1CommandList/firewall_cp.htm