Configuring Egress Filtering Mode

The controller can be configured to support Policy Manager‘s Egress Role mode. Egress Role refers to taking the ingress filters assigned to a port, exchanging the source and destination addresses with each other in each role rule and applying the result to the traffic egressing the port.

The ExtremeWireless solution applies egress filtering mode to WLAN (Wireless Local Area Network) services. When egress filtering is enabled, any role that is applied to a station on the WLAN service will have its outbound filters replaced with rules in which the source and destination addresses of the inbound filters are swapped.

The same role can be assigned to stations on WLAN services that have egress filtering mode enabled and on WLAN services that have it disabled.

  • For stations that are on WLAN services with egress filtering mode enabled, the roles outbound filters will be replaced by ones derived from the inbound policy rules.
  • For stations that are on WLAN services with egress filtering disabled, the outbound filters of the role will be applied as defined. In other words the same role can be applied in two different ways at the same time, based on the egress filter mode settings of the WLAN services it is used with.

The global Egress Filtering Mode setting overrides the individual WLAN service Egress Filtering Mode setting. By default, the global setting is set to Use WLAN. In this mode, egress filtering can be enabled for some WLAN services and not others. Set the Egress Filtering Mode setting from the Advanced configuration dialog of each WLAN service.

Changing the global setting does not alter each individual WLAN egress filtering mode setting, although the global setting can override the individual setting. Changing the global setting does not alter the outbound policy rules of each role. Each role‘s policy rules are stored on the controller as they were entered. Changing the global egress filtering mode flag does, however, affect how a role‘s rules are interpreted when they are applied.

Rule-Based Redirection

Rule-based redirection requires explicit enablement. For new installations, Rule-based Redirection is enabled by default. For upgrades from releases prior to v10.11, ExtremeWireless preserves the previous captive portal redirection method of triggering redirect off denied HTTP/HTTPS for non-authenticaticated roles. For more information, see Rule-Based Redirection.
Note

Note

The option to disable Rule-based Redirection is available for backward capability only.
Click to expand in new window
Enabling Rule-based Redirection
Graphics/Rule-based_redirection_enable.png