ZyWALL 2 Series User’s Guide

 

 

Table 7-2 MAC Address Filter

 

 

 

 

 

LABEL

DESCRIPTION

 

 

 

 

 

 

Active

Select or clear the check box to enable or disable MAC address filtering.

 

 

 

Enable MAC address filtering to have the router allow or deny access to wireless stations

 

 

 

based on MAC addresses. Disable MAC address filtering to have the router not perform

 

 

 

MAC filtering on the wireless stations.

 

 

Association

Define the filter action for the list of MAC addresses in the MAC address filter table.

 

 

 

Select Deny to block access to the router, MAC addresses not listed will be allowed to

 

 

 

access the router. Select Allow to permit access to the router, MAC addresses not listed

 

 

 

will be denied access to the router.

 

 

MAC

Enter the MAC addresses (in XX:XX:XX:XX:XX:XX format) of the client computers that are

 

 

Address

allowed or denied access to the ZyWALL in these address fields.

 

 

 

 

 

 

Apply

Click Apply to save your changes back to the ZyWALL.

 

 

 

 

 

 

Reset

Click Reset to begin configuring this screen afresh.

 

 

 

 

 

7.6802.1x Overview

The IEEE 802.1x standard outlines enhanced security methods for both the authentication of wireless stations and encryption key management. Authentication can be done using the local user database internal to the ZyWALL or an external RADIUS server for an unlimited number of users.

7.6.1 RADIUS

RADIUS is based on a client-sever model that supports authentication and accounting, where access point is the client and the server is the RADIUS server. The RADIUS server handles the following tasks among others:

Authentication

Determines the identity of the users.

Accounting

Keeps track of the client’s network activity.

RADIUS user is a simple package exchange in which your ZyWALL acts as a message relay between the wireless client and the network RADIUS server.

Types of RADIUS Messages

The following types of RADIUS messages are exchanged between the access point and the RADIUS server for user authentication:

Wireless LAN Screens

7-7