Traffic Filters

About this task

The Traffic Filter table displays services (SSH, Telnet, ping, and SNMP) that Extreme Networks devices permit between connected clients. The table displays the name of the traffic filter, a description (if one was configured), and identifies the SSID using the filter (Used by). Hover over a number in the Used by column to see more information.

By default, Extreme Networks devices permit SSH and pings to access the mgt0 interface through the Ethernet and wireless interfaces to which you bind SSIDs.

You can control which management and diagnostic services a device can receive, and whether the device permits traffic between connected clients. You can apply traffic filters to Ethernet interfaces (in backhaul or access mode), to the wireless backhaul interface, and to the wireless access interface of individual SSIDs. These options permit certain types of traffic to reach the mgt0 interface through Ethernet interfaces eth0, eth1, red0, or agg0 (through the wireless backhaul interface), and through select SSIDs.

You can add, clone or modify, and delete traffic filters using the icons above the table. From either the network policy workflow, or Common Objects > Security > Traffic Filters, complete the following steps to configure a traffic filter.

Procedure

  1. Select the add icon above the table.
  2. Enter a name for the filter.
  3. Enter a description.
    Although optional, descriptions can be helpful when troubleshooting your network.
  4. Select or clear check boxes to permit or deny specific types of management and diagnostic access to the mgt0 interface and permit traffic between connected clients.
    Enable SSH: Permit an SSH connection to the mgt0 interface. By default, SSH is enabled.
    Enable Telnet: Permit a Telnet connection to the mgt0 interface. By default, Telnet traffic is disabled.
    Enable Ping: Permit ICMP echo requests (pings) to reach the mgt0 interface. By default, pinging mgt0 is allowed.
    Enable SNMP: Permit an SNMP connection to the mgt0 interface. By default, SNMP is disabled.
    Enable Inter-station Traffic (for APs only): Permit inter-station traffic between APs.
  5. Select Save.