Creating an Access Control Policy

You can use the Access Control policy to create multiple wireless networks with different access control components.

Complete the following steps to create an Access Control policy:
  1. Add the Access Control service to your tenant account. From the navigation bar, select Network Control > Service Catalog. Alternatively, you can select Network Control > My Services, then click Add Service.
  2. Find the Access Control tile and click Add.
    The Add Access Control page is displayed. By default, Wi-Fi is selected for Access Control Type, and Access Control Set is selected for Wi-Fi Access Control Profile.
  3. Click Next.
    The Add Access Control Policy page is displayed.
  4. Enter the Policy Name.
  5. (Optional) Enter a Description.
  6. Configure the Access Control Components.
    Note: By default, access control component profiles are disabled.
    Access Control Components
  7. Toggle the Layer 2 switch on and select a profile from the drop-down list.
    If a Layer 2 profile is not defined, click Add New, complete the fields in the Layer 2 Settings sidebar, and click Save. Then select the newly created profile from the drop-down list.
    1. Enter a Policy Name.
    2. (Optional) Enter a Description.
    3. In the Access field, choose one of the following options:
      • Allow connections: Allows the specified MAC addresses to connect.
      • Block connections: Prevents the specified MAC addresses from connecting.
    4. Select a MAC Address from the list.
      If the required MAC address is not listed, click Add. The Add MAC Address sidebar is displayed.
      • Enter MAC addresses.
        Note: You can add multiple MAC addresses by separating them with a comma or semicolon. You can add up to 128 MAC addresses.
      • Click Save.
  8. Toggle the Layer 3 switch on and select a profile from the drop-down list.
    If a Layer 3 profile is not defined, click Add New, complete the fields in the Layer 3 Settings sidebar, and click Save. Then select the newly created profile from the drop-down list.
    1. Enter a Policy Name.
    2. (Optional) Enter a Description.
    3. Select Default Access and choose one of the following options:
      • Allow Traffic: Allows traffic from the specified source.
      • Block Traffic: Blocks traffic from the specified source.
    4. Select a rule from the Layer 3 Rules list by clicking the radio button.

      If the Layer 3 Rules you need are not listed, click Add.

      The Add Layer 3 Rule sidebar is displayed. Complete the following to create a new Layer 3 Rule.
      • Description: Enter a description for the rule.
      • Access: Select one of the following options:
        • Allow Traffic: Allows upstream traffic.
        • Block Traffic: Denies upstream traffic.
      • Protocol: Select the protocol that you want to use for the new traffic rule from the drop-down list. The following protocols are available.
        • TCP: Transmission Control Protocol.
        • UDP: User Datagram Protocol.
        • UDPLITE: Lightweight User Datagram Protocol, which is a connectionless protocol that allows even a damaged data payload to be delivered rather than being discarded.
        • ICMP (ICMPV4): Internet Control Message Protocol, which is an error-reporting protocol used by network devices to generate error messages to the source IP address, when issues in the network prevent delivery of IP packets.
        • IGMP: Internet Group Management Protocol, which is a communications protocol used by hosts on IPv4 networks to establish multicast group memberships.
        • ESP: Encapsulating Security Payload is a protocol that provides authentication, integrity, and confidentiality of network packets in IPv4 and IPv6 networks.
        • AH: Authentication Header protocol, which is used to authenticate SNMP.
        • SCTP: Stream Control Transmission Protocol is a communications protocol that operates at the transport layer.
      • Source:
        • Select one of the following options:
          • Any IP Address: Allows or denies upstream traffic from any IP address.
          • Subnet Network Address: Enter the source network address and source mask.
          • IP Address: Enter the specific IP address.
        • Port: Enter a port number or a range of ports (for example, 22-34).
          Note:

          If you select the ICMP protocol in the previous step, you do not need to specify ports for the source and the destination. Therefore, the option to select ports is not displayed.

      • Destination:
        • Select one of the following options:
          • Any IP Address: Allows or denies upstream traffic to any IP address.
          • Subnet Network Address: Enter the destination network address and destination mask.
          • IP Address: Enter the specific IP address.
        • Port: Enter a port number or a range of ports (for example, 22-34).
          Note:

          If you select the ICMP protocol in the previous step, you do not need to specify ports for the source and the destination. Therefore, the option to select ports is not displayed.

      • Click Save.
  9. Toggle the Device & OS switch on and select a profile from the drop-down list.
    If a Device & OS profile is not defined, click Add New, complete the fields in the Device & OS Access Settings sidebar, and click Save. Then select the newly created profile from the drop-down list.
    1. Enter a Policy Name.
    2. Enter a Description.
    3. Select Default Access and choose one of the following options:
      • Allow Traffic: Allows traffic from any device not matching a specific rule.
      • Block Traffic: Denies traffic from any device not matching a specific rule.
    4. Select a rule from the Rules list by clicking the radio button.

      If the rule you need is not listed, click Add.

      The Add Application Rule sidebar is displayed.
      Complete the following to create a new rule.
      • Rule Name: Enter the name of the rule.
      • Access: Select one of the following options:
        • Allow Traffic: Allows traffic from device.
        • Block Traffic: Denies traffic from device.
      • Device Type: Select a device type from the drop-down list. Currently, the supported devices are Laptop, Smartphone, Tablet, VoIP, Gaming, Printer, and IoT device.
      • OS or Manufacturer: Select the OS vendor for the device from the drop-down.
        Note: The OS type field is populated based on the type of device. For example, if the device type is selected as Gaming, the OS or Manufacturer drop-down displays the following options: All, GameCube, Wii, PlayStation, Xbox, and Nintendo.
      • Rate Limit: Configure the From Client and To Client rate limits using the sliders.
        Note: Maximum rate limit ranges from 0.1 Mbps to 200 Mbps.
      • VLAN: Enter the VLAN ID.
      • Click Save.
  10. Toggle the Applications switch on and select a profile from the drop-down list.
    If an Application profile is not defined, click Add New, complete the fields in the Application Access Settings sidebar, and click Save. Then select the newly created profile from the drop-down list.
    1. Enter a Policy Name.
    2. Enter a Description.
    3. Select a rule from the Rules list by clicking the radio button.

      If the rule you need is not listed, click Add.

      The Add Application Rule sidebar is displayed. Complete the following steps to create a new rule, and then click Save:
      • Rule Name: Enter the name of the rule.
      • Rule Type: Select one of the following options:
        • System Defined: Complete the following fields.
          • Application Category: Select the category of application from the list.
          • Application Name: Enter the name of the application.
        • User Defined: Complete the following fields.
          • Application Name: Enter the name of the application.
          • Port Mapping Only: Selecting this option disables the IP Mode, IPv4 Destination IP, and Netmask fields.
          • IP Mode: Select IPv4 or IPv6.
          • IPv4 Destination IP: This field is displayed when the IP Mode is set to IPv4. Enter the destination IP.
          • Netmask: Enter the subnet mask value. This field is displayed when the IP Mode is set to IPv4.
          • IPv6 Destination IP: This field is displayed when the IP Mode is set to IPv6. Enter the destination IP.
          • Prefix Length: This field is displayed when the IP Mode is set to IPv6. Enter the prefix length.
          • Destination Port: Enter the port number.
          • Protocol: Select TCP or UDP.
      • Access Control: Select one of the following options:
        • Block Applications: Blocks the user-added application.
        • Rate Limit: Select the checkbox and configure the Max uplink rate and Max downlink rate limits using the sliders.
          Note: Maximum rate limit ranges from 0.25 Mbps to 20 Mbps.
        • QoS: Complete the following fields.
          • Uplink Marking: Select from 802.1p, DSCP, or Both, and select from Best effort, Video, Voice, or Background. By default, 802.1p and Background are selected.
          • Downlink Priority: Select from Best effort, Video, Voice, or Background. By default, Voice is selected.
    4. Click Save.
  11. Toggle the Client Rate Limit switch on, then select one or both of the Upload Limit and Download Limit options and configure using the sliders.
    Note: Maximum client rate limit ranges from 1 Mbps to 200 Mbps.
  12. Click Finish.
    An Access Control policy is created and is displayed on the Access Control page.