ADTRAN BlueSecure Controller Spezifikationen

Stöbern Sie online oder laden Sie Spezifikationen nach Vernetzung ADTRAN BlueSecure Controller herunter. ADTRAN BlueSecure Controller Specifications Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 376
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - BlueSecure™ Controller

BlueSecure™ ControllerSetup and Administration GuideSoftware Release Version: 6.5Document Version: 6.5Bluesocket, Inc. 10 North Avenue Burlington, MA

Seite 2

xContentsFiguresFigures xFigure 1-1: The Role of the Bluesocket BSC in a Wireless LAN ... 1-2Figure 1-2: The Bluesocket Secur

Seite 3

Chapter 5: Authentication Using Internal Database5-45. To enable RADIUS accounting for this user, select the name of the external RADIUS accounting se

Seite 4 - Networks

Defining MAC Address AuthenticationBlueSecure™ Controller Setup and Administration Guide 5-5You may be prompted to restart the BSC. We recommend that

Seite 5

Chapter 5: Authentication Using Internal Database5-6Acceptable MAC address delimiters are colons (00:03:4a:3b:4F:02) or hyphens (00-03-4a-3b-4F-02).Th

Seite 6

Defining MAC Address AuthenticationBlueSecure™ Controller Setup and Administration Guide 5-7You may be prompted to restart the BSC. We recommend that

Seite 7 - Secure Mobility® MatriX

Chapter 5: Authentication Using Internal Database5-8

Seite 8

BlueSecure™ Controller Setup and Administration Guide 6-16Authentication Using External ServersFollow the procedures given in this chapter if you are

Seite 9

Chapter 6: Authentication Using External Servers6-2An Overview of External User AuthenticationIn external server user authentication, an external serv

Seite 10 - Figures x

RADIUS AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-3To configure an external RADIUS authentication server and define the rul

Seite 11 - Contents

Chapter 6: Authentication Using External Servers6-4Name Enter a meaningful name for the external RADIUS authentication server.)Note: As described in t

Seite 12

RADIUS AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-5See “RADIUS Accounting” on page 7-1 to configure a new RADIUS accounting

Seite 13

ContentsBlueSecure™ Controller Setup and Administration Guide xiFigure 4-23:Admin Interface in Network Routing Table ...

Seite 14

Chapter 6: Authentication Using External Servers6-63. The Default Redirect URL field on the General HTTP Settings page (see “HTTP Server Settings” on

Seite 15 - About This Guide

LDAP/Active Directory AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-7To configure an external LDAP/Active Directory authentica

Seite 16

Chapter 6: Authentication Using External Servers6-8Displaying the New LDAP/active directory server page1. Click the User authentication tab in the BSC

Seite 17 - Terminology

LDAP/Active Directory AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-9on page 7-1 to configure a new RADIUS accounting server f

Seite 18 - Glossary

Chapter 6: Authentication Using External Servers6-10The user can click on the link to go the URL, but they are not automatically redirected to that li

Seite 19

SIP2 AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-11Displaying the New SIP2 server page1. Click the User authentication tab i

Seite 20 - Protected Side

Chapter 6: Authentication Using External Servers6-12Alternatively, you can select the Create … option to open a window that enables you to define a ne

Seite 21 - BlueSecure Access Points

NTLM AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-13Displaying the New NTLM server page1. Click the User authentication tab i

Seite 22 - RF Management

Chapter 6: Authentication Using External Servers6-14returned to the New NTLM server page where you can select the role from the drop-down list.2. Opti

Seite 23 - Transparent Authentication

Transparent NTLM AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-15Displaying the New Transparent NTLM Windows server page1. Cli

Seite 24 - Web-based User Logins

xiiContentsFigure 10-14: IPSec CSR Generated Page... 10-23Figure 10-15: Miscellaneous Settings Pa

Seite 25 - BlueSecure Controller Models

Chapter 6: Authentication Using External Servers6-164. NTLM username to ignore (Optional): Enter any generic, client-supplied NTLM login ID that shoul

Seite 26 - Bluesocket BSC-600

Transparent 802.1x AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-17Transparent 802.1x Authentication802.1x is an IEEE standard

Seite 27

Chapter 6: Authentication Using External Servers6-18New Transparent 802.1x server page1. Click the User authentication tab in the BSC administrator co

Seite 28 - Single BSC Configuration

The BSC Internal 802.1x Authentication ServerBlueSecure™ Controller Setup and Administration Guide 6-19• RFC822 - Use for TLS EAP methods only. This i

Seite 29 - Failover BSCs

Chapter 6: Authentication Using External Servers6-20Figure 6-8: Edit the Local 802.1x Server Page

Seite 30 - POWERFAULTDA TA ALARM

The BSC Internal 802.1x Authentication ServerBlueSecure™ Controller Setup and Administration Guide 6-21or TTLS Protocol and pass the inner authenticat

Seite 31 - Installation

Chapter 6: Authentication Using External Servers6-224. Many other LDAP servers (e.g. Windows 2000/2003 Server Active Directory LDAP server) are not de

Seite 32 - Safety Precautions

Kerberos AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-23Saving the settingsClick Save to store the information to the BSC dat

Seite 33

Chapter 6: Authentication Using External Servers6-24The Port number should be 88, the value assigned to Kerberos by the Internet Assigned Number Autho

Seite 34 - Chapter 2: Installation

Cosign AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-25Cosign client web servers do not need to run SSL; sniffed cookies will

Seite 35

ContentsBlueSecure™ Controller Setup and Administration Guide xiiiFigure 14-20: Configuring Load Sharing on a Node ...

Seite 36

Chapter 6: Authentication Using External Servers6-26Displaying the New Cosign server page1. Click the User authentication tab in the BSC administrator

Seite 37 - LED 100/Status Link/Activity

Pubcookie AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-27Alternatively, you can select the Create New… option to open a windo

Seite 38

Chapter 6: Authentication Using External Servers6-28Displaying the New Pubcookie server page1. Click the User authentication tab in the BSC administra

Seite 39 - PoE Activity

Pubcookie AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-295. Key server address: Enter the Pubcookie key server IP address.6.

Seite 40

Chapter 6: Authentication Using External Servers6-30You may be prompted to restart the BSC. We recommend that you do not restart the BSC until you hav

Seite 41

CAS AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-31Once primary authentication is complete, the CAS redirects the user's

Seite 42

Chapter 6: Authentication Using External Servers6-32c) Enter the appropriate value to check against the specified attribute in the Value field.d) Sele

Seite 43

Transparent Certificate AuthenticationBlueSecure™ Controller Setup and Administration Guide 6-33To configure transparent certificate authentication:Di

Seite 44 - Powering Down Your BSC

Chapter 6: Authentication Using External Servers6-34Mapping Transparent Certificate attributes to roles3. Define the rules to determine if the user is

Seite 45 - Power Supply Connector

Testing an External Authentication ServerBlueSecure™ Controller Setup and Administration Guide 6-354. Enter the password associated with the entered u

Seite 46

xivContentsTablesTable 1-1: Bluesocket BSC Model Specifications ... 1-9Table 2-1: BSC-1200 Status LEDs...

Seite 47

Chapter 6: Authentication Using External Servers6-36

Seite 48

BlueSecure™ Controller Setup and Administration Guide 7-17RADIUS Accounting Remote authentication dial-in user service (RADIUS) software includes both

Seite 49

Chapter 7: RADIUS Accounting7-2Defining a RADIUS Accounting ServerTo define a new RADIUS accounting server:1. Click the User Authentication, Authentic

Seite 50

Attributes Sent to External RADIUS Accounting Server by BSCBlueSecure™ Controller Setup and Administration Guide 7-3You might be prompted to restart t

Seite 51

Chapter 7: RADIUS Accounting7-4

Seite 52 - Changing Your Login Password

BlueSecure™ Controller Setup and Administration Guide 8-18Roles and Role ElementsThis chapter describes the use of roles and role elements on the BSC:

Seite 53

Chapter 8: Roles and Role Elements8-2Defining User Roles to Enforce Network Usage PoliciesThe BSC uses role-based authorization to define which networ

Seite 54

Role InheritanceBlueSecure™ Controller Setup and Administration Guide 8-3You can configure the BSC to support enterprise guest access by defining loca

Seite 55 - Obtaining Online Help

Chapter 8: Roles and Role Elements8-4• It reduces the number of administrative changes you need to make to roles. If you need to make changes to the b

Seite 56 - Site Map

Defining a RoleBlueSecure™ Controller Setup and Administration Guide 8-5Name Enter a meaningful name for the role. Typically, this will be the name of

Seite 57 - Error Checking on Page Forms

BlueSecure™ Controller Setup and Administration Guide xvAbout This GuideThe BlueSecure™ Controller Setup and Administration Guide provides complete in

Seite 58 - Table Control Click to

Chapter 8: Roles and Role Elements8-6• Per user - Each user logged in with this role can transmit the entire bandwidth. For example, if 1 Mbps is spec

Seite 59 - Console Fonts

Defining a RoleBlueSecure™ Controller Setup and Administration Guide 8-7Alternatively, as with network services, destinations, and schedules, you can

Seite 60 - Font Control Click to

Chapter 8: Roles and Role Elements8-84. Configure the Transparent 802.1x server to do role placement based on the username:In this case the Domain is

Seite 61

Defining a RoleBlueSecure™ Controller Setup and Administration Guide 8-9routes all tagged traffic to the protected-side VLAN and is useful if you want

Seite 62

Chapter 8: Roles and Role Elements8-101. The Redirect URL Attribute field on either the RADIUS page or the LDAP page accessed on the User Authenticati

Seite 63

Creating Destinations and Destination GroupsBlueSecure™ Controller Setup and Administration Guide 8-11single device within the network; all the device

Seite 64 - Chapter 4: Networks

Chapter 8: Roles and Role Elements8-12You might be prompted to restart the BSC. We recommend that you do not restart the BSC until you have completely

Seite 65

Creating Network Services and Services GroupsBlueSecure™ Controller Setup and Administration Guide 8-132. Select Destination Group from the Create dro

Seite 66

Chapter 8: Roles and Role Elements8-14• LDAP - Lightweight directory access protocol• H.323 - ITU-T standard for sending voice (audio) and video using

Seite 67

Creating Network Services and Services GroupsBlueSecure™ Controller Setup and Administration Guide 8-15Name Enter a meaningful name for the network se

Seite 68

About This Guidexviauthentication, NTLM authentication, transparent NTLM authentication, transparent 802.1x authentication, the BSC internal 802.1x au

Seite 69

Chapter 8: Roles and Role Elements8-16Incoming/Outgoing Priority - You can configure a priority for traffic coming into the BSC or going out from the

Seite 70

Creating Schedules and Schedule GroupsBlueSecure™ Controller Setup and Administration Guide 8-171. Click the User Roles tab in the BSC administrator c

Seite 71

Chapter 8: Roles and Role Elements8-181. Click the User Roles tab in the BSC administrator console, and then click the Schedules tab.2. Select Schedul

Seite 72 - List DHCP Servers

Creating Locations and Location GroupsBlueSecure™ Controller Setup and Administration Guide 8-195. Click Save to store the information to the BSC data

Seite 73

Chapter 8: Roles and Role Elements8-20For example, you might have defined “VLAN 15” that includes all access points on the shop floor. You can then cr

Seite 74 - Mark this Checkbox

Creating Locations and Location GroupsBlueSecure™ Controller Setup and Administration Guide 8-211. Click the User Roles tab in the BSC administrator c

Seite 75

Chapter 8: Roles and Role Elements8-22

Seite 76

BlueSecure™ Controller Setup and Administration Guide 9-19Voice Over WLAN SupportMore and more organizations are now using IP phones that pass voice t

Seite 77

Chapter 9: Voice Over WLAN Support9-2Configuring General VoWLAN SettingsClick the Voice tab in the BSC administrator console, and then click the Gener

Seite 78

Configuring VoWLAN QoSBlueSecure™ Controller Setup and Administration Guide 9-3Polycom/Avaya IP phone settingsMark the Enable support for Polycom/Avay

Seite 79

BlueSecure™ Controller Setup and Administration Guide xvii• Appendix C, "Endpoint Scanning," provides procedures for configuring endpoint sc

Seite 80

Chapter 9: Voice Over WLAN Support9-4

Seite 81 - WAN or VPN

BlueSecure™ Controller Setup and Administration Guide 10-110General BSC Operational SettingsYou may modify the following BSC protocols and functions u

Seite 82

Chapter 10: General BSC Operational Settings10-2HTTP Server SettingsTo modify the BSC HTTP server settings:Displaying the HTTP Settings page1. Click t

Seite 83

HTTP Server SettingsBlueSecure™ Controller Setup and Administration Guide 10-3Login Redirects Comma separated list of HTTP/proxy ports to monitor - En

Seite 84

Chapter 10: General BSC Operational Settings10-4Root CA URL - URL where the certificate authority (CA) credential is stored. Your browser can use the

Seite 85

Intrusion Detection SystemBlueSecure™ Controller Setup and Administration Guide 10-5BlueProtect Endpoint ScanningOptional. Enable BlueProtect Endpoint

Seite 86

Chapter 10: General BSC Operational Settings10-6Normal State By default, a user host will start in the Normal State unless or otherwise blocked. The a

Seite 87

Intrusion Detection SystemBlueSecure™ Controller Setup and Administration Guide 10-7these roles or create your own IDS role to assign to blocked users

Seite 88 - Configuring the Primary BSC

Chapter 10: General BSC Operational Settings10-8Enable IDS Mark this checkbox to activate the BSC Intrusion Detection System.Thresholds Violation Thre

Seite 89

Automatic Backup of the BSC DatabaseBlueSecure™ Controller Setup and Administration Guide 10-9SNMP Agent Start the selected version of SNMP agent (v2c

Seite 90 - Configuring Static Routes

About This GuidexviiiA Glossary is included in this document that defines many terms and acronyms associated with the BlueSecure Controller, the BlueS

Seite 91

Chapter 10: General BSC Operational Settings10-10Displaying the Auto Backups page1. Click the General tab in the BSC administrator console, and then c

Seite 92 - Configuring Multicast Routing

Mail Server AccessBlueSecure™ Controller Setup and Administration Guide 10-11Displaying the BSC Time Settings page1. Click the General tab in the BSC

Seite 93 - Configuring AppleTalk Routing

Chapter 10: General BSC Operational Settings10-12tab, Email tab to configure the BSC to login to your mail server securely. You can either specify the

Seite 94 - Routing Information

Public Access NetworksBlueSecure™ Controller Setup and Administration Guide 10-13Address of mail server for SMTP port redirectionIn some public access

Seite 95

Chapter 10: General BSC Operational Settings10-14Event Logging and Connection TrackingThe BSC provides two types of logging facilities:• Event logging

Seite 96

Event Logging and Connection TrackingBlueSecure™ Controller Setup and Administration Guide 10-15• Enable Connection Tracking - If this checkbox is mar

Seite 97

Chapter 10: General BSC Operational Settings10-16If cleared, no connection tracking data is logged. Default value: Disabled.)Note: Connection tracking

Seite 98 - Local BSC User Authentication

Threshold ValuesBlueSecure™ Controller Setup and Administration Guide 10-17Threshold ValuesYou can specify threshold values that trigger the output of

Seite 99

Chapter 10: General BSC Operational Settings10-18Warm Start A restart of BSC services.Cold Start A complete reboot of BSC.Config Change Any change to

Seite 100

Domain Name System (DNS) SettingsBlueSecure™ Controller Setup and Administration Guide 10-19Managed-side DNS proxyEnable DNS Proxy? - If this checkbox

Seite 101

BlueSecure™ Controller Setup and Administration Guide 1-11An Overview of the BlueSecure ControllerThis chapter introduces you to the BlueSecure family

Seite 102

Chapter 10: General BSC Operational Settings10-20• admin - Administrator login page at the specified host name and interface. Default host name: admin

Seite 103

Digital CertificatesBlueSecure™ Controller Setup and Administration Guide 10-21• BSC secure web login page (SSL) - As with any secure web page (SSL),

Seite 104

Chapter 10: General BSC Operational Settings10-22the server digital certificate). If you are using mutual authentication, mark the BSC Client Certific

Seite 105

Digital CertificatesBlueSecure™ Controller Setup and Administration Guide 10-235. When the provider returns the signed certificate, upload it to the B

Seite 106 - RADIUS Authentication

Chapter 10: General BSC Operational Settings10-24Miscellaneous BSC OptionsUse the Miscellaneous page in the administrator console to configure miscell

Seite 107

Miscellaneous BSC OptionsBlueSecure™ Controller Setup and Administration Guide 10-25the Active Connections page (see “Monitoring Active User Connectio

Seite 108

Chapter 10: General BSC Operational Settings10-26Serial Console AccessAllow access via serial port? - By default, administrators are allowed to access

Seite 109

BlueSecure™ Controller Setup and Administration Guide 11-111Web LoginsThis chapter covers the following topics:• Customizing the User Login Page• The

Seite 110

Chapter 11: Web Logins11-2Customizing the User Login PageYou can customize the appearance of the web page that users see at login to maintain your org

Seite 111

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-3The default user login page along with the page elements that

Seite 112

iiCopyright NoticeCopyright © 2001- 2009 Bluesocket, Inc. All rights reserved.No part of this document may be reproduced in any form or by any means,

Seite 113

Chapter 1: An Overview of the BlueSecure Controller1-2An Introduction to the BlueSecure WLAN SolutionThe BlueSecure Controller (BSC) product family—BS

Seite 114 - SIP2 Authentication

Chapter 11: Web Logins11-4Figure 11-3: Create New Custom Login Page

Seite 115

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-5Name Enter a meaningful name for the custom user login page y

Seite 116 - NTLM Authentication

Chapter 11: Web Logins11-6The Number of active sessions per username/authentication type applies to External Server Authentication methods only.HTML b

Seite 117

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-7Displaying the GUI Customization Page1. Click the Web Logins

Seite 118

Chapter 11: Web Logins11-8Spacing Specify the remaining spacing options, if necessary:Pixels between the form and the customized HTML - Spacing in pix

Seite 119

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-9Example Here is a test page for testing all custom variables.

Seite 120

Chapter 11: Web Logins11-10Redirecting Clients to an External Server for AuthenticationComplete the “Edit redirection for custom login Default” page t

Seite 121 - 1. 2. 3. 4.5

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-11Currently Micros-Fidelio Opera 4 PMS, Authorize.net SIM, Aut

Seite 122

Chapter 11: Web Logins11-12BSC uses the email address internally as the account name, different from the user’s credit card account name). After the u

Seite 123

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-13Authorize.net AIMThe following setup is required to use the

Seite 124

An Introduction to the BlueSecure WLAN SolutionBlueSecure™ Controller Setup and Administration Guide 1-3Thus, unregistered users can be directed to a

Seite 125

Chapter 11: Web Logins11-14• On the BSC side, set “Server Address” to test.authorize.net and check off (turn on) “Enable test mode” • On the Authorize

Seite 126

Customizing the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-15Displaying the Hotspot Account Generation Page1. Click the W

Seite 127 - Kerberos Authentication

Chapter 11: Web Logins11-16Response URL must be configured in the Merchant Interface.This will also cause error checking responses to be displayed dir

Seite 128 - Cosign Authentication

Uploading Image/Media Files for the User Login PageBlueSecure™ Controller Setup and Administration Guide 11-17entering an anonymous email account (lik

Seite 129

Chapter 11: Web Logins11-18The topleftlogo file can be any GIF, JPEG or PNG file with a recommended size of 133x64 pixels.• Normal - All other image a

Seite 130

Translating User Login PagesBlueSecure™ Controller Setup and Administration Guide 11-19• Chinese-Traditional (zh-TW/Big5)•Czech (UTF-8)• Dutch (UTF-8)

Seite 131 - Pubcookie Authentication

Chapter 11: Web Logins11-20Defining a User Login Page LanguageDisplaying the Create a User Login PageFigure 11-12: Create a User Login Page Language P

Seite 132

Translating User Login PagesBlueSecure™ Controller Setup and Administration Guide 11-21To define a new user login page language:1. Click the Web Login

Seite 133

Chapter 11: Web Logins11-22• Thank-You page - Enter any HTML code to disable URL redirection after login. The HTML is displayed in a standard Thank Yo

Seite 134 - CAS Authentication

Installing a Custom SSL Login CertificateBlueSecure™ Controller Setup and Administration Guide 11-23• “Requesting a Certificate” on page 11-23.• “Uplo

Seite 135

Chapter 1: An Overview of the BlueSecure Controller1-4BSAPs are simple to configure (“zero touch”) and require only minimal provisioning to make them

Seite 136

Chapter 11: Web Logins11-24The CSR generated page appears as shown in Figure 11-14.To delete a CSR and start over, click Delete CSR of the left side o

Seite 137

Installing a Custom SSL Login CertificateBlueSecure™ Controller Setup and Administration Guide 11-25• The host name is the same one you entered in you

Seite 138

Chapter 11: Web Logins11-262. Upload the certificate as follows:a) Mark the BSC Client Certificate radio button.b) Click Browse, locate the file for t

Seite 139 - 7. Click Submit

Installing a Custom SSL Login CertificateBlueSecure™ Controller Setup and Administration Guide 11-27The SSL Certificate Generation page appears as sho

Seite 140

Chapter 11: Web Logins11-28Installing a Wildcard (*) SSL Certificate on Multiple BSCsBefore installing a wildcard SSL certificate on multiple BSCs, yo

Seite 141 - RADIUS Accounting

BlueSecure™ Controller Setup and Administration Guide 12-112BlueSecure Access PointsThis chapter covers the following topics:•Overview• Deploying BSAP

Seite 142 - Chapter 7: RADIUS Accounting

Chapter 12: BlueSecure Access Points12-2OverviewBluesocket manufactures a line of next-generation “thin” access points that work in conjunction with B

Seite 143 - Attribute Description

Deploying BSAPs on the Same Layer-2 Subnet as the BSCBlueSecure™ Controller Setup and Administration Guide 12-3)Note: Connect only the recommended num

Seite 144

Chapter 12: BlueSecure Access Points12-4See “Configuring the BSC DHCP Server” on page 4-11 for information about running a DHCP server on the BSC. See

Seite 145 - Roles and Role Elements

How a BSAP Discovers BSCsBlueSecure™ Controller Setup and Administration Guide 12-5• Protocol 97 and TCP/UDP Port 33333 traffic is allowed between BSA

Seite 146 - An Overview of Roles

The BlueSecure WLAN Solution End-user ExperienceBlueSecure™ Controller Setup and Administration Guide 1-5VoIP Protocols/VoWLAN SupportYou can configur

Seite 147 - Managed Side Protected Side

Chapter 12: BlueSecure Access Points12-6How a BSAP Selects a Home BSCWhen a BSAP discovers multiple BSCs to which it may connect, it uses the followin

Seite 148 - Defining a Role

Uploading BSAP Firmware FilesBlueSecure™ Controller Setup and Administration Guide 12-7model can have one Default firmware and one Alternative firmwar

Seite 149

Chapter 12: BlueSecure Access Points12-8Configuring Global Miscellaneous Non-Radio SettingsThe Wireless Global System Settings page is used to specify

Seite 150

Configuring Global Miscellaneous Non-Radio SettingsBlueSecure™ Controller Setup and Administration Guide 12-9The Bluesocket Sales team maps customers

Seite 151

Chapter 12: BlueSecure Access Points12-10Enable Front User Port - Mark the Enable Front User Port checkbox to enable the front ethernet port on the Wi

Seite 152

Configuring Global Radio SettingsBlueSecure™ Controller Setup and Administration Guide 12-113. Select the Sensor Frequency Band in which to scan (BSAP

Seite 153

Chapter 12: BlueSecure Access Points12-12

Seite 154 - Creating Role Elements

Configuring Global Radio SettingsBlueSecure™ Controller Setup and Administration Guide 12-13Advanced Settings for the 802.11b/g/n RadioMark the Displa

Seite 155

Chapter 12: BlueSecure Access Points12-142. Mark the Antenna Diversity radio button to specify whether the antenna is automatically selected based on

Seite 156 - Creating Destination Groups

Configuring Global Radio SettingsBlueSecure™ Controller Setup and Administration Guide 12-15Load Balancing Enter the Average user count per AP, which

Seite 157

Chapter 1: An Overview of the BlueSecure Controller1-6Web-based User LoginsWhen leveraging the BSC's native authentication directory, or an exter

Seite 158 - Creating a Network Service

Chapter 12: BlueSecure Access Points12-16• 1 = Enabled2. BSAP1700: MIMO Network Density: Network Density refers to how many wireless networks are depl

Seite 159

Configuring Global Radio SettingsBlueSecure™ Controller Setup and Administration Guide 12-17Saving the settings7. Click Save to save the BSAP radio se

Seite 160

Chapter 12: BlueSecure Access Points12-18802.11a/n Radio ConfigurationSee “802.11b/g/n Radio Configuration” on page 12-10 for settings not described h

Seite 161 - Creating a Schedule

Editing Settings for an Individual BSAPBlueSecure™ Controller Setup and Administration Guide 12-19Operational ModeSelect one of the following from the

Seite 162

Chapter 12: BlueSecure Access Points12-20• Only Use Selected SSIDs - The BSAP will use only those SSIDs selected in the Select SSID picklist.)Note: On

Seite 163 - Creating Schedule Groups

Creating SSIDsBlueSecure™ Controller Setup and Administration Guide 12-21the BSAP and all wireless clients. The PSK mode uses either TKIP or AES for p

Seite 164 - Creating User Location Groups

Chapter 12: BlueSecure Access Points12-22TKIP (This option cannot be used with 802.11n when connecting at rates above 54Mhz). Temporal Key Integrity P

Seite 165

Creating SSIDsBlueSecure™ Controller Setup and Administration Guide 12-23The SSID is case sensitive and can consist of up to 32 alphanumeric character

Seite 166

Chapter 12: BlueSecure Access Points12-243. Enter keys as 10 hexadecimal digits (0 to 9 and A to F) for 64 bit keys, 26 hexadecimal digits for 128 bit

Seite 167 - Voice Over WLAN Support

Creating BSAPsBlueSecure™ Controller Setup and Administration Guide 12-25Displaying the Create new AP pageClick the Wireless tab in the BSC administra

Seite 168

BlueSecure Controller ModelsBlueSecure™ Controller Setup and Administration Guide 1-7a user on any authentication server. Typically, guest roles are c

Seite 169 - Configuring VoWLAN QoS

Chapter 12: BlueSecure Access Points12-26Display Specify which login page to display to users logging into the BSC on the managed interface via this B

Seite 170

Enabling BSAP ServiceBlueSecure™ Controller Setup and Administration Guide 12-27• Configured APs - The BSC accepts connections from only those BSAPs t

Seite 171

Chapter 12: BlueSecure Access Points12-28• Autochannel BG - Mark/unmark this checkbox to enable/disable the BSC to dynamically change the 802.11b/g/n

Seite 172 - HTTP Server Settings

Displaying Configured BSAPsBlueSecure™ Controller Setup and Administration Guide 12-29Displaying Configured BSAPsAfter you have created BSAPs as descr

Seite 173

Chapter 12: BlueSecure Access Points12-30• Click to accept all the DynamicRF recommendations for channel and power.The configuration will be saved t

Seite 174

BlueSecure™ Controller Setup and Administration Guide 13-113RF Intrusion Detection and ContainmentThe BSC detects and protects against rogue devices,

Seite 175 - Intrusion Detection System

Chapter 13: RF Intrusion Detection and Containment13-2Identifying Authorized RF Stations on Your NetworkTo better track rogue devices on your network,

Seite 176 - Monitoring

Configuring RF AlarmsBlueSecure™ Controller Setup and Administration Guide 13-3• Rogue - This station is not authorized to be on the network and an al

Seite 177 - Configuration Procedure

Chapter 13: RF Intrusion Detection and Containment13-4Client BSSID Changed Mobile station has changed its BSSID. D Client Limit Maximum client limit p

Seite 178 - SNMP Agent

Configuring RF AlarmsBlueSecure™ Controller Setup and Administration Guide 13-5Configuration Procedure1. Click the Wireless tab in the BSC administrat

Seite 179

Chapter 1: An Overview of the BlueSecure Controller1-8Mobility® MatriX WLAN deployment, providing centralized management and control of configuration

Seite 180 - System Time and Date Settings

Chapter 13: RF Intrusion Detection and Containment13-6• Severe - This is the highest alert level and is usually associated with a WLAN intrusion, e.g.

Seite 181 - Mail Server Access

Configuring AutocontainmentBlueSecure™ Controller Setup and Administration Guide 13-72. Mark the Enable Autocontainment checkbox to enable RF autocont

Seite 182 - Public Access Networks

Chapter 13: RF Intrusion Detection and Containment13-8

Seite 183

BlueSecure™ Controller Setup and Administration Guide 14-114Secure Mobility® MatriXThis chapter provides procedures for configuring a large-scale wire

Seite 184

Chapter 14: Secure Mobility® MatriX14-2An Overview of the Secure Mobility MatriXWhere multiple BlueSecure Controllers are deployed across multiple WLA

Seite 185

Secure Mobility®BlueSecure™ Controller Setup and Administration Guide 14-3General Configuration ProcedureFollow these high-level steps to configure a

Seite 186

Chapter 14: Secure Mobility® MatriX14-4How Secure Mobility WorksThe following figure illustrates how Secure Mobility works. For simplicity, two wirele

Seite 187 - Threshold Values

Secure Mobility®BlueSecure™ Controller Setup and Administration Guide 14-5A single BSC in the Secure Mobility configuration is configured as the Mobil

Seite 188

Chapter 14: Secure Mobility® MatriX14-6subnet. BSC protected interfaces that are not connected to a router may be on the same subnet. The following fi

Seite 189 - Figure 10-11: DNS Proxy Page

Secure Mobility®BlueSecure™ Controller Setup and Administration Guide 14-7communicating with each other, thus providing an extra layer of security. Th

Seite 190 - Digital Certificates

BlueSecure Controller ModelsBlueSecure™ Controller Setup and Administration Guide 1-9option is available to support direct connection of PoE access po

Seite 191

Chapter 14: Secure Mobility® MatriX14-8a) Enter the IP address of the protected interface on the Node and an optional description in the fields provid

Seite 192

Secure Mobility®BlueSecure™ Controller Setup and Administration Guide 14-9be any text string you choose, as long as it is the same for all BSCs in the

Seite 193

Chapter 14: Secure Mobility® MatriX14-10• Last Update - ID of last status update.• Last Update Message - Last message concerning Secure Mobility confi

Seite 194 - Miscellaneous BSC Options

ReplicationBlueSecure™ Controller Setup and Administration Guide 14-11A Comparison of Standard and Cascaded ReplicationIn addition to the standard rep

Seite 195

Chapter 14: Secure Mobility® MatriX14-12Step 1: Set Up Replication on the MasterSelect one BSC as the Replication Master. You can also set up a second

Seite 196

ReplicationBlueSecure™ Controller Setup and Administration Guide 14-13d) Optional. If you are configuring the replication feature to support a Load Sh

Seite 197 - Web Logins

Chapter 14: Secure Mobility® MatriX14-145. Mark the Acquire a snapshot from the master? checkbox to configure the Replication Node to upload the datab

Seite 198 - Custom HTML Code

ReplicationBlueSecure™ Controller Setup and Administration Guide 14-156. Do not restart the BSC until instructed to do so at the end of this procedure

Seite 199

Chapter 14: Secure Mobility® MatriX14-162. If you are supporting VoIP, make sure that you override the replicated IP addresses for the SpectraLink/Ava

Seite 200 - Chapter 11: Web Logins

Load SharingBlueSecure™ Controller Setup and Administration Guide 14-17Load SharingUse the BSC load sharing feature in environments where many wireles

Seite 201

Chapter 1: An Overview of the BlueSecure Controller1-10Typical BlueSecure WLAN Solution Network ConfigurationsTypically, you will install and configur

Seite 202

Chapter 14: Secure Mobility® MatriX14-18Network RequirementsEnsure that your BSC network meets the following requirements before you configure the BSC

Seite 203

Load SharingBlueSecure™ Controller Setup and Administration Guide 14-19sharing feature on up to six members of the local replication configuration inc

Seite 204

Chapter 14: Secure Mobility® MatriX14-20b) Select a weight (1 to 5) from the Weight drop-down menu to assign the LSG member.A low weight (e.g. 1) mean

Seite 205

Load SharingBlueSecure™ Controller Setup and Administration Guide 14-21• Enter a subnet mask in the Managed side netmask that specifies which bits in

Seite 206

Chapter 14: Secure Mobility® MatriX14-224. Mark the ID radio button that corresponds to the load sharing ID for the Load Sharing Node.5. Specify the L

Seite 207 - Create New Account

Load SharingBlueSecure™ Controller Setup and Administration Guide 14-23You must allocate physical and virtual address carefully according to the subne

Seite 208 - Virtual Terminal N/A

Chapter 14: Secure Mobility® MatriX14-24In the event of a down interface on a Load Sharing Group member, the Load Sharing Master will reassign the tra

Seite 209 - Authorize.net

Load SharingBlueSecure™ Controller Setup and Administration Guide 14-25Load Sharing Status SummaryYou can also display a quick visual snapshot of your

Seite 210

Chapter 14: Secure Mobility® MatriX14-26

Seite 211

BlueSecure™ Controller Setup and Administration Guide 15-115StatusThis chapter covers the following topics:• Monitoring Active User Connections• Viewi

Seite 212

Typical BlueSecure WLAN Solution Network ConfigurationsBlueSecure™ Controller Setup and Administration Guide 1-11authentication for those devices by f

Seite 213 - Figure 11-10: Guest DNA

Chapter 15: Status15-2Monitoring Active User ConnectionsYou can monitor and display active user connection status and other user information, such as

Seite 214 - Translating User Login Pages

Monitoring Active User ConnectionsBlueSecure™ Controller Setup and Administration Guide 15-3• Role - Role assigned to this connection. To change a use

Seite 215

Chapter 15: Status15-4• Packets Dropped - Count of packets dropped due to blocked port(s).• Port N - Count of packets dropped on this blocked port.• S

Seite 216

Monitoring Active User ConnectionsBlueSecure™ Controller Setup and Administration Guide 15-5If you are monitoring BlueSecure Access Points connected t

Seite 217

Chapter 15: Status15-6• Associations - Wireless clients that have associated to the BSAP. Click (+) to expand the list of associations or (-) to colla

Seite 218

Monitoring Active User ConnectionsBlueSecure™ Controller Setup and Administration Guide 15-7Sensor IP or Sensor Location columns are visible, the colu

Seite 219 - Requesting a Certificate

Chapter 15: Status15-8You must have the Macromedia Flash (Version 6 or later) browser plug-in installed and a VBScript-enabled browser [e.g., Microsof

Seite 220

Monitoring Active User ConnectionsBlueSecure™ Controller Setup and Administration Guide 15-9User connections are displayed on the horizontal axis and

Seite 221

Chapter 15: Status15-103. Click Filter to apply the filters you have defined. The Filter Users dialog closes and the graphical monitoring tool is refr

Seite 222 - Recovering the Private Key

Displaying a BSC Status SummaryBlueSecure™ Controller Setup and Administration Guide 15-11alphanumeric characters in event descriptions, choose Search

Seite 223

BlueSecure™ Controller Setup and Administration Guide iiiContentsFigures ...

Seite 224

Chapter 1: An Overview of the BlueSecure Controller1-12Within either single- or multiple-BSC networks, you can set up pairs of redundant BSCs (must be

Seite 225

Chapter 15: Status15-12Displaying BSC Secure Mobility® StatusIf you have configured the BSC Secure Mobility feature to enable users to roam across sub

Seite 226 - Overview

Displaying Power over Ethernet (PoE) StatusBlueSecure™ Controller Setup and Administration Guide 15-13Displaying Power over Ethernet (PoE) StatusFor t

Seite 227

Chapter 15: Status15-14Using Pre-defined Report DefinitionsThe following pre-defined report definitions are available to generate your BSC report:• To

Seite 228

Generating and Displaying BSC ReportsBlueSecure™ Controller Setup and Administration Guide 15-15• Log Level - Restricts collected data to records of a

Seite 229 - How a BSAP Discovers BSCs

Chapter 15: Status15-16Alternatively, you can generate a report for a specific time period. To do so, select Specific Time Period from the drop down a

Seite 230 - Uploading BSAP Firmware Files

Performing Standard Network Diagnostic TestsBlueSecure™ Controller Setup and Administration Guide 15-17To specify display or delivery of the report, c

Seite 231

Chapter 15: Status15-18Displaying the Task Execution MenuClick the Status tab in the BSC administrator console, click the Diagnostics tab, and then cl

Seite 232

Performing Standard Network Diagnostic TestsBlueSecure™ Controller Setup and Administration Guide 15-19Purge DHCP leasesMark this checkbox to purge ex

Seite 233

Chapter 15: Status15-20Capturing Network Traffic DataThe BSC allows you to capture network traffic data on any of its physical or VLAN interfaces, fil

Seite 234

Capturing Network Traffic DataBlueSecure™ Controller Setup and Administration Guide 15-216. Optional. To delete a traffic capture file, select the nam

Seite 235

BlueSecure™ Controller Setup and Administration Guide 2-12InstallationThis chapter provides complete installation procedures for the BlueSecure family

Seite 236

Chapter 15: Status15-22

Seite 237

BlueSecure™ Controller Setup and Administration Guide 16-116MaintenanceThis chapter covers the following topics:• Restarting, Rebooting, and Shutting

Seite 238

Chapter 16: Maintenance16-2Restarting, Rebooting, and Shutting Down the BSCMany configuration settings in the BSC do not take effect until you restart

Seite 239

Configuration Backup and RestoreBlueSecure™ Controller Setup and Administration Guide 16-3BackupAll BSC configuration information is stored in its int

Seite 240

Chapter 16: Maintenance16-41. Click the Maintenance tab and then click Configuration Backup/Restore. The BSC configuration backup and restore page app

Seite 241 - Saving the

Configuration Backup and RestoreBlueSecure™ Controller Setup and Administration Guide 16-5To reset all BSC configuration settings back to their defaul

Seite 242 - 802.11a/n Radio Configuration

Chapter 16: Maintenance16-6Un-registered;1;Allow;Any;Any;Outgoing;192.168.100.18/255.255.255.255;Any;Any;Un-registered;1;Allow;Any;Any;Outgoing;abc.go

Seite 243

Upgrading to a New Version of Runtime SoftwareBlueSecure™ Controller Setup and Administration Guide 16-73. After the database is backed up, click the

Seite 244 - Creating SSIDs

Chapter 16: Maintenance16-8e) Restart services on each BSC you have upgraded.3. Re-configure each original Node BSC as a Node and configure it to rece

Seite 245 - BSAP Data Encryption Options

Switching Between BSC Runtime Software VersionsBlueSecure™ Controller Setup and Administration Guide 16-9The Manage Patches for BSC page appears as sh

Seite 246 - SSID Configuration Procedure

Chapter 2: Installation2-2Overview of the Installation ProcedureYou must complete the following steps to install the Bluesocket BSC:1. Prior to beginn

Seite 247

Chapter 16: Maintenance16-103. Click Switch, and then reboot the BSC manually when prompted.Exporting and Importing BSC Bulk Data FilesYou can export

Seite 248 - Creating BSAPs

Exporting and Importing BSC Bulk Data FilesBlueSecure™ Controller Setup and Administration Guide 16-115. Select the local data fields to export by mar

Seite 249

Chapter 16: Maintenance16-12)Note: When importing values, the BSC shows the values before it adds them to the configuration information. It will give

Seite 250 - Enabling BSAP Service

LicensesBlueSecure™ Controller Setup and Administration Guide 16-13BlueProtectThe license is supplied by Bluesocket as part of your BlueSecure Control

Seite 251

Chapter 16: Maintenance16-14BSAP 1840When purchasing BSAP-1840 APs, there are three SKUs: two hardware SKUs (same hardware, different serial numbers)

Seite 252

LicensesBlueSecure™ Controller Setup and Administration Guide 16-15failover, the license file is automatically copied between the primary and failover

Seite 253 - Displaying Configured BSAPs

Chapter 16: Maintenance16-16

Seite 254

BlueSecure™ Controller Setup and Administration Guide A-1AAn Overview of Virtual LANsThe Bluesocket BSC supports multiple VLANs on both the managed an

Seite 255

Appendix A: A-2LANs vs. VLANsA LAN is a broadcast domain composed of hubs, switches, or bridges that are physically wired to each other and to multipl

Seite 256

BlueSecure™ Controller Setup and Administration Guide A-3number. VLAN interfaces support all of the authentication types and services supported by the

Seite 257 - Configuring RF Alarms

Safety PrecautionsBlueSecure™ Controller Setup and Administration Guide 2-3• Do not allow liquid to enter the Bluesocket BSC chassis, and do not opera

Seite 258 - Alarm Description

Appendix A: A-4To configure a termination VLAN properly, do not configure a VLAN interface on the protected side with a VLAN ID that corresponds to a

Seite 259

Enforcing Network Usage Policies with VLANsBlueSecure™ Controller Setup and Administration Guide A-5Enforcing Network Usage Policies with VLANsIn addi

Seite 261

BlueSecure™ Controller Setup and Administration Guide B-1BProvisioning Network DHCP Servers to Support BSAPsThe BSAP needs the IP address of the home

Seite 262

Appendix B: B-2OverviewYou can deploy BSAPs on a routed network with Layer-3 connectivity to the BSC as shown in the following figure.In this deployme

Seite 263

BlueSecure™ Controller Setup and Administration Guide B-3The DHCP Vendor Classes dialog appears. 2. Click Add... and the New Class dialog appears, for

Seite 264

Appendix B: B-44. Click OK to close the New Class dialog. You will see that the BSAP vendor class is listed in the DHCP Vendor Classes dialog, for exa

Seite 265

BlueSecure™ Controller Setup and Administration Guide B-54. In the Option Type dialog:a) Enter a descriptive name in the Name field.b) Select Encapsul

Seite 266 - How Secure Mobility Works

Appendix B: B-6)Note: If you wish to prioritize certain BSCs to connect to, a failover option is allowed in the IP separated list. By prepending the l

Seite 267 - Network Requirements

BlueSecure™ Controller Setup and Administration Guide B-7More than one BSC IP address can be specified, separated by commas or semi-colons. The length

Seite 268 - WG-2100 Wireless Gateway

Chapter 2: Installation2-4BSC-2200/3200/5200 Displays, Controls, and ConnectorsThe following figure shows the Bluesocket BSC-5200 front and rear panel

Seite 270

BlueSecure™ Controller Setup and Administration Guide C-1CEndpoint ScanningBlueProtect ensures that a client device is a trusted end-point by performi

Seite 271

Appendix C: Endpoint ScanningC-2OverviewA “trusted end-point” refers to a client device that has been verified to be free of worm or virus infection a

Seite 272 - Replication

Client Browser RequirementsBlueSecure™ Controller Setup and Administration Guide C-3HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Install CheckAn

Seite 273

Appendix C: Endpoint ScanningC-4Applet Loader PageThe Applet Loader Page has two responsibilities.1. The page gracefully handles non-compatible enviro

Seite 274

Creating a BlueProtect PolicyBlueSecure™ Controller Setup and Administration Guide C-5)Note: Any URL that appears in this window will be automatically

Seite 275

Appendix C: Endpoint ScanningC-65. Select the Save button.6. To configure Antivirus, Antispyware, or Firewall settings, click the link for your platfo

Seite 276

Creating a BlueProtect PolicyBlueSecure™ Controller Setup and Administration Guide C-7Figure C-2: Edit BlueProtect Policy

Seite 277

Appendix C: Endpoint ScanningC-8RemediationWhen an endpoint fails the security policy scan, the administrator can block the endpoint until it is in co

Seite 278 - Tracking Replication Status

Assigning a BlueProtect Policy to a User RoleBlueSecure™ Controller Setup and Administration Guide C-9without credentials from getting to Remediation

Seite 279 - Load Sharing

BSC-2100 Displays, Controls, and ConnectorsBlueSecure™ Controller Setup and Administration Guide 2-5Admin Port Use the Admin port to manage your contr

Seite 280

Appendix C: Endpoint ScanningC-10Figure C-3: Client Display when Required Products Not InstalledFigure C-4: Overriding a Client Role

Seite 281

BlueSecure™ Controller Setup and Administration Guide D-1DSerial Port Access to Essential FunctionsOn a rare occasion, you may temporarily lose access

Seite 282

Appendix D: D-2Listing of Accessible Functions• 1) dbinit - Restore all values in the BSC back to their defaults.• 2) ifconfig - Show the NIC settings

Seite 283

BlueSecure™ Controller Setup and Administration Guide D-3Figure D-1: Recommended Null-modem Serial Cable PinoutL RPin ConnectionsL-SH R-SHL-1 L-7, R-8

Seite 284

Appendix D: D-4

Seite 285

BlueSecure™ Controller Setup and Administration Guide E-1EContacting Bluesocket, Inc.This appendix provides complete information for contacting Blueso

Seite 286 - Physical Protected

Appendix E: E-2Obtaining Technical SupportBluesocket is committed to providing complete technical support to its customers.If you have a question conc

Seite 287

BlueSecure™ Controller Setup and Administration Guide Glossary-1Glossary!802.11 x - A series of IEEE specifications for LANs, currently 802.11b, 802.1

Seite 288

GlossaryGlossary-2Authentication - Process whereby the identity of a person or process is verified. The BSC authenticates users by matching submitted

Seite 289

GlossaryBlueSecure™ Controller Setup and Administration Guide Glossary-3EAP-FAST (EAP-Flexible Authentication via Secure Tunneling) - A publicly acces

Seite 290 - Displaying Active User Status

Chapter 2: Installation2-6LCD The BSC provides a 2x16 character, liquid crystal display (LCD) to display the IP address configured for its protected i

Seite 291 - Forcing a User Logout

GlossaryGlossary-4Managed Remote Subnet - A BSC network configuration in which the local wireless subnet uses a router that does not use NAT and the B

Seite 292 - Chapter 15: Status

GlossaryBlueSecure™ Controller Setup and Administration Guide Glossary-5RRADIUS (Remote Authentication Dial-In User Service) - An authentication and a

Seite 293

GlossaryGlossary-6

Seite 294 - Monitoring RF IDS Alarms

BlueSecure™ Controller Setup and Administration Guide Index-1IndexSymbols.BLUE file 16-3, 16-4.DEBUG file 16-4.DMP file 15-20Numerics802.11i preauthen

Seite 295

Index-2IndexAllow ICMP to protected Interface? 10-26Allow user logins 11-5Answer failed DNS queries? 10-19Antenna type, configuring fixed or external

Seite 296

IndexBlueSecure™ Controller Setup and Administration Guide Index-3models 1-7network configurations 1-10specifications 1-9Bluesocket SSL certificate, i

Seite 297

Index-4IndexDate setting, configuring the BSC’s 10-10Debug file, creating 16-4Debugging the BSC 16-4Default gateway IP address for remote clients to r

Seite 298 - Viewing the BSC Event Log

IndexBlueSecure™ Controller Setup and Administration Guide Index-5Enable MAC Device 5-5Enable QoS for this Service 8-15Enable show Cisco CDP Neighbors

Seite 299 - Figure 15-9: BSC Summary Page

Index-6IndexH.323 protocol, running as a BSC network service 8-14Heart beat 4-27Help button, enabling on the user login page 11-5Home BSC, how a BSAP

Seite 300

IndexBlueSecure™ Controller Setup and Administration Guide Index-7LLanguage code 10-4Languages, changing on the user login page 11-5LCD 2-4, 2-6, 2-7L

Seite 301

BSC-1200 Displays, Controls, and ConnectorsBlueSecure™ Controller Setup and Administration Guide 2-7Status LEDs The following table summarizes the sta

Seite 302

Index-8IndexManaged side of the network 1-2Managed virtual interface, configuring 4-23MatriX, secure mobilitygeneral configuration procedure 14-3overv

Seite 303 - Creating a BSC Report

IndexBlueSecure™ Controller Setup and Administration Guide Index-9PPage controls, using 3-13Pass-through VLANs A-3Passwordadministrator account 3-2cha

Seite 304

Index-10IndexQQuality of service (QoS), defining for a network service 8-15Quarantined role for IDS 10-8Question mark (?) link 3-9RRack requirements 2

Seite 305 - Icon Click to

IndexBlueSecure™ Controller Setup and Administration Guide Index-11RFC822 6-19Rogue, identifying an RF station as 13-3Role elements, creating 8-10Role

Seite 306

Index-12IndexSorting administrator console data 3-12Sorting table data 3-12Space requirements 2-10Specifications for the BSC 1-9Specifications, BSC 1-

Seite 307

IndexBlueSecure™ Controller Setup and Administration Guide Index-13Trash can icon, using 3-11Troubleshooting your BSC’s configuration 16-4Trusted cert

Seite 308

Index-14Indexcreating on the protected side 4-5initiation A-4overview of A-1pass-through A-3termination A-3Vocera IP phone traffic, passing through th

Seite 309

Chapter 2: Installation2-8Admin Port Use the Admin port to manage your controller without needing to be connected to the managed or protected ports.

Seite 310

Preparing Your NetworkBlueSecure™ Controller Setup and Administration Guide 2-9On/Off Control Connect the BSC-600 to its power source, and then press

Seite 311 - Maintenance

ivContentsBSC-2100 Displays, Controls, and Connectors ... 2-5BSC-1200 Displays, Controls, and Connectors ...

Seite 312 - Chapter 16: Maintenance

Chapter 2: Installation2-10• Ensure that your wireless devices (laptops, PDAs, etc.) are configured to receive IP addresses via DHCP.• Ensure that you

Seite 313

Mounting the BlueSecure Controller ChassisBlueSecure™ Controller Setup and Administration Guide 2-111. Choose a level, stable desktop that will suppor

Seite 314 - Show Tech

Chapter 2: Installation2-12Rack-mounting the BlueSecure ControllerYou may install the Bluesocket BSC in any two-post equipment rack or cabinet that co

Seite 315 - Export Firewall Policies

Connecting the BlueSecure Controller to Your NetworkBlueSecure™ Controller Setup and Administration Guide 2-13up the BSC by following the procedure gi

Seite 316 - Export BSAP-1840 Licenses

Chapter 2: Installation2-145. (BSC-600, BSC-2100, and BSC-2200/3200/5200 only). Press the Power button on front panel.As the BSC powers up, its coolin

Seite 317 - Figure 16-5: BSC Update Page

LED Run Time Mode for BSC-600 and BSC-1200BlueSecure™ Controller Setup and Administration Guide 2-15Follow these steps to enable IEEE 802.3af Power-ov

Seite 318 - Software Patches

Chapter 2: Installation2-16The fault light will be lit for a few seconds after an AP is disconnected.

Seite 319 - Uninstalling a Patch

BlueSecure™ Controller Setup and Administration Guide 3-13Administrator ConsoleThe BlueSecure Controller provides an intuitive, easy-to-use, administr

Seite 320 - Exporting Data Files

Chapter 3: Administrator Console3-2Logging Into the Administrator Console for the First TimeYou may access the Bluesocket BSC administrator console us

Seite 321 - Importing Data Files

Using and Managing Administrator AccountsBlueSecure™ Controller Setup and Administration Guide 3-35. Acknowledge License AgreementA dialog appears dis

Seite 322 - Licenses

ContentsBlueSecure™ Controller Setup and Administration Guide vRecovery State...

Seite 323 - BlueProtect

Chapter 3: Administrator Console3-4• monitor - enables you to view but not change current BSC parameter settings. The default password for the monitor

Seite 324 - BSAP 1840

Using and Managing Administrator AccountsBlueSecure™ Controller Setup and Administration Guide 3-5Changing an Administrator PasswordTo change the pass

Seite 325

Chapter 3: Administrator Console3-6Changing Your Login PasswordFor security purposes, we recommend that you periodically change the password you use t

Seite 326

Installing the Bluesocket SSL CertificateBlueSecure™ Controller Setup and Administration Guide 3-7)Note: As an alternative to installing the Bluesocke

Seite 327 - An Overview of Virtual LANs

Chapter 3: Administrator Console3-8An Overview of the Tabs on the ConsoleInformation in the BSC administrator console is presented as a series of tabb

Seite 328 - Tagging Formats

Obtaining Online HelpBlueSecure™ Controller Setup and Administration Guide 3-9Voice Configure how voice traffic is passed through and managed by the B

Seite 329 - Termination VLANs

Chapter 3: Administrator Console3-10Site MapClick on the Site Map link to display a clickable site map (the Site Map link is located in the upper righ

Seite 330 - Initiation/Switched VLANs

Error Checking on Page FormsBlueSecure™ Controller Setup and Administration Guide 3-11Error Checking on Page FormsRequired form elements are marked wi

Seite 331

Chapter 3: Administrator Console3-12Sorting and Filtering Table DataThe following table describes use of the column heading links and drop-down filter

Seite 332 - Appendix A:

Paging Through DataBlueSecure™ Controller Setup and Administration Guide 3-13Select the column(s) you wish to hide and then click Remove highlighted i

Seite 333

viContentsCreating a Schedule ... 8-17Creating Schedule Groups...

Seite 334

Chapter 3: Administrator Console3-14Downloading Administrator Console DataYou can download the administrator console page data you are currently viewi

Seite 335

Restarting the BSC to Activate Configuration InformationBlueSecure™ Controller Setup and Administration Guide 3-15Restarting the BSC to Activate Confi

Seite 336 - Appendix B:

Chapter 3: Administrator Console3-16

Seite 337

BlueSecure™ Controller Setup and Administration Guide 4-14NetworksThis chapter coves the following topics:• Defining the BSC Protected Physical Interf

Seite 338

Chapter 4: Networks4-2Defining the BSC Protected Physical InterfaceYou must configure the BSC to communicate with the protected (i.e., wired) side of

Seite 339

Defining the BSC Protected Physical InterfaceBlueSecure™ Controller Setup and Administration Guide 4-3Obtain IP settings from a DHCP server for the in

Seite 340

Chapter 4: Networks4-4interface as a trunk port. One ISP should be reachable from the protected physical interface and one from the protected VLAN.1.

Seite 341 - Endpoint Scanning

Defining the BSC Protected Physical InterfaceBlueSecure™ Controller Setup and Administration Guide 4-52. Physically configure links, choosing one of t

Seite 342 - About Rules

Chapter 4: Networks4-6VLAN Settings 1. Ensure you have set up the protected physical interface as described in “Defining the BSC Protected Physical In

Seite 343 - Java Agent

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-7Configuring a Protected Virtual Interface (Optional)This

Seite 344 - Configuring Landing Page Text

ContentsBlueSecure™ Controller Setup and Administration Guide viiRF Intrusion Detection/RF Containment ... 12-3

Seite 345 - Creating a BlueProtect Policy

Chapter 4: Networks4-8- If you are not running a DHCP server on your network, or if you want to conserve IP addresses or “hide” users on a private IP

Seite 346 - Appendix C: Endpoint Scanning

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-9It is possible to configure client addressing on the man

Seite 347

Chapter 4: Networks4-10)Note: You must assign a fixed address to the managed interface.IP Address & NetmaskTo assign a fixed IP address to the man

Seite 348 - Remediation

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-11so, select the default user role from the Default role

Seite 349 - Client Examples

Chapter 4: Networks4-12NAT the addresses to the protected interface addressMark this checkbox to activate Network Address Translation (NAT) to map all

Seite 350

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-13Address range to excludeOptional. If you have IP addres

Seite 351

Chapter 4: Networks4-14Dynamic DNS Mechanism by which the DNS server learns the assigned IP address and fully qualified domain name of a wireless clie

Seite 352 - Access Procedure

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-15Use the Fixed IP address assignments table ( as shown i

Seite 353 - Pin Connections

Chapter 4: Networks4-16)Note: Use care when choosing a specific role rather than Authenticate. The Specific Role option allows network transmission vi

Seite 354 - Appendix D:

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-173. Supply the following information for each managed si

Seite 355 - Contacting Bluesocket, Inc

viiiContentsVerifying Your Load Sharing Configuration ... 14-23Chapter 15 StatusMonitoring Active User Connections ...

Seite 356 - Obtaining Technical Support

Chapter 4: Networks4-181. Set up the managed physical interface as described in “Configuring a DHCP Relay Agent” on page 4-9 and in “Configuring the B

Seite 357

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-19• VLAN Type - The type of VLAN to create. Currently the

Seite 358 - Glossary-2

Chapter 4: Networks4-202. Select Managed-side Remote Subnet from the Create drop-down list on the Network page. The Create a Managed Remote Subnet pag

Seite 359

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-21• Netmask of Remote Subnet - When handing out addresses

Seite 360 - Glossary-4

Chapter 4: Networks4-22• Address range to dynamically assign - Optional. Enter range of addresses that DHCP can assign within a network address space

Seite 361 - Pass-through VLAN

Configuring the BSC Managed InterfaceBlueSecure™ Controller Setup and Administration Guide 4-23associated with the option in the Code field, and selec

Seite 362 - Glossary-6

Chapter 4: Networks4-243. The Enable checkbox is marked by default to make the managed virtual interface available to wireless clients. Clearing the c

Seite 363 - Numerics

Configuring Failover ParametersBlueSecure™ Controller Setup and Administration Guide 4-253. Gateway: Allows connectivity to the Admin port through the

Seite 364

Chapter 4: Networks4-26)Note: On a BSC-600 or BSC-1200, the admin interface must be disabled in order to use the failover feature.)Note: On a BSC-600

Seite 365 - Configuration to restore 16-4

Configuring Failover ParametersBlueSecure™ Controller Setup and Administration Guide 4-271. Click the Network tab in the BSC administrator console, an

Seite 366

ContentsBlueSecure™ Controller Setup and Administration Guide ixLANs vs. VLANs...

Seite 367

Chapter 4: Networks4-28• Primary machine identifier - Enter the MAC address of the primary BSC. In the event of a failover, this entry is used to iden

Seite 368

Configuring Static RoutesBlueSecure™ Controller Setup and Administration Guide 4-29To enable outbound administrator traffic from the Admin interface,

Seite 369 - MAC ACL Attribute 6-5

Chapter 4: Networks4-304. Enter the IP address of the gateway through which traffic is routed to the destination network in the Route Gateway field. T

Seite 370

Configuring AppleTalk RoutingBlueSecure™ Controller Setup and Administration Guide 4-31You can configure a default Rendezvous Point for group address

Seite 371

Chapter 4: Networks4-32where to send each packet of data. Each physical network must have one or more seed routers that broadcast the routing informat

Seite 372 - Index-10

Configuring AppleTalk RoutingBlueSecure™ Controller Setup and Administration Guide 4-33Configuration ProcedureYou must enable at least two BSC interfa

Seite 373

Chapter 4: Networks4-34b) Specify what version of AppleTalk is to be supported, Phase 1 or Phase 2, by selecting an option from the Phase menu.c) For

Seite 374 - Index-12

BlueSecure™ Controller Setup and Administration Guide 5-15Authentication Using Internal DatabaseFollow the procedures given in this chapter if:• You a

Seite 375 - VLAN ID 4-6, 4-18, 8-20

Chapter 5: Authentication Using Internal Database5-2Local BSC User AuthenticationYou can create local users and assign each to a previously defined ro

Seite 376 - Index-14

Creating/Editing/Deleting a Local User AccountBlueSecure™ Controller Setup and Administration Guide 5-34. To edit an existing user account, click the

Kommentare zu diesen Handbüchern

Keine Kommentare