ZyXEL Communications ZyWALL 2 Series User Manual

Page of 614
ZyWALL 2 Series User’s Guide 
Wireless LAN Screens 
7-7 
Table 7-2 MAC Address Filter 
LABEL
 
DESCRIPTION
 
Active
 
Select or clear the check box to enable or disable MAC address filtering. 
Enable MAC address filtering to have the router allow or deny access to wireless stations 
based on MAC addresses. Disable MAC address filtering to have the router not perform 
MAC filtering on the wireless stations.
 
Association  
Define the filter action for the list of MAC addresses in the MAC address filter table.  
Select Deny to block access to the router, MAC addresses not listed will be allowed to 
access the router. Select Allow to permit access to the router, MAC addresses not listed 
will be denied access to the router. 
MAC 
Address
 
Enter the MAC addresses (in XX:XX:XX:XX:XX:XX format) of the client computers that are 
allowed or denied access to the ZyWALL in these address fields. 
 
Apply 
Click Apply to save your changes back to the ZyWALL. 
Reset 
Click Reset to begin configuring this screen afresh. 
7.6 802.1x 
Overview 
The IEEE 802.1x standard outlines enhanced security methods for both the authentication of wireless stations 
and encryption key management. Authentication can be done using the local user database internal to the 
ZyWALL or an external RADIUS server for an unlimited number of users. 
7.6.1 RADIUS  
RADIUS is based on a client-sever model that supports authentication and accounting, where access point is 
the client and the server is the RADIUS server. The RADIUS server handles the following tasks among 
others: 
         
Authentication  
Determines the identity of the users. 
         
Accounting 
Keeps track of the client’s network activity.  
 
RADIUS user is a simple package exchange in which your ZyWALL acts as a message relay between the 
wireless client and the network RADIUS server.  
Types of RADIUS Messages 
The following types of RADIUS messages are exchanged between the access point and the RADIUS server 
for user authentication: