beautypg.com

Brocade Mobility Access Point System Reference Guide (Supporting software release 5.5.0.0 and later) User Manual

Page 323

background image

Brocade Mobility Access Point System Reference Guide

313

53-1003100-01

5

Select Use DHCP to Obtain Gateway/DNS Servers to learn default gateway, name servers and the
domain name on just this interface. Once selected, specify an IP address and mask in dot decimal
format.

Define the NAT Direction as either Inside, Outside or None.

Inside - The inside network is transmitting data over the network its intended destination.
On the way out, the source IP address is changed in the header and replaced by the
(public) IP address.

Outside - Packets passing through the NAT on the way back to the LAN are searched
against the records kept by the NAT engine. There the destination IP address is changed
back to the specific internal private class IP address in order to reach the LAN over the
network.

None - No NAT activity takes place. This is the default setting.

Select OK to save the changes to the basic configuration. Select Reset to revert to the last saved
configuration.

Select the Security tab.

FIGURE 163

OSPF Virtual Interface - Security screen

Use the Inbound IP Firewall Rules drop-down menu to select the IP access and deny rules to apply
to the OSPF dynamic route.

4. Either select an existing IP firewall policy or use the default set of IP firewall rules. The firewall

inspects OSPF route traffic flows and detects potential attacks on the dynamic route not visible
to traditional wired firewall appliances. Select the Create icon to define a new set of IP firewall
rules that can be applied to the OSPF route configuration. Selecting Edit allows for the
modification of an existing IP firewall rules configuration. For more information, see

Wireless

Firewall on page 8-531

.

Select the VPN Crypto Map to use with this VLAN configuration. Use the drop-down menu to apply
an existing crypto map configuration to this VLAN interface. Use the Create icon to create a new
VPN Crypto Map or use the Edit icon to edit an existing VPN Crypto Map configuration before
applying it to this VLAN.