<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L3/L4 User Traffic Profiles in vSCG in SmartZone and Virtual SmartZone</title>
    <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2629#M20</link>
    <description>Thanks for your reply!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;But in order to access the internet the client would have to communicate with its default gateway. These rules above would deny that type of traffic?</description>
    <pubDate>Tue, 24 Mar 2015 13:12:24 GMT</pubDate>
    <dc:creator>samuel_eng</dc:creator>
    <dc:date>2015-03-24T13:12:24Z</dc:date>
    <item>
      <title>L3/L4 User Traffic Profiles in vSCG</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2627#M18</link>
      <description>Hi, I would like to create a User Traffic Profile in the vSCG that will only allow access to the internet and no local LAN access. Then apply this to a WLAN. How to achieve this?</description>
      <pubDate>Tue, 24 Mar 2015 10:07:17 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2627#M18</guid>
      <dc:creator>samuel_eng</dc:creator>
      <dc:date>2015-03-24T10:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: L3/L4 User Traffic Profiles in vSCG</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2628#M19</link>
      <description>Hi Samuel,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you are trying to allow internet access only you can go into the L3/L4 traffic policy list and set the policy to "allow all by default". Then you want to add deny rules for all private IP ranges on all protocols, these include:&lt;BR /&gt;&lt;BR /&gt;10.0.0.0/8&lt;BR /&gt;192.168.0.0/16&lt;BR /&gt;172.16.0.0/12&lt;BR /&gt;&lt;BR /&gt;This should prevent a customer from reaching any Private IP ranges.&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;BR /&gt;&lt;BR /&gt;Rob</description>
      <pubDate>Tue, 24 Mar 2015 13:09:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2628#M19</guid>
      <dc:creator>rob_krumm</dc:creator>
      <dc:date>2015-03-24T13:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: L3/L4 User Traffic Profiles in vSCG</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2629#M20</link>
      <description>Thanks for your reply!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;But in order to access the internet the client would have to communicate with its default gateway. These rules above would deny that type of traffic?</description>
      <pubDate>Tue, 24 Mar 2015 13:12:24 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2629#M20</guid>
      <dc:creator>samuel_eng</dc:creator>
      <dc:date>2015-03-24T13:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: L3/L4 User Traffic Profiles in vSCG</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2630#M21</link>
      <description>Hi Samuel,&lt;BR /&gt;&lt;BR /&gt;That will not be the case. We will block traffic based on the destination address in the IP packet, not which device the packet has been passed to.&lt;BR /&gt;&lt;BR /&gt;So if you try to ping an address on the internet, the destination IP in the packet will be the IP address of the website you are trying to reach and we will allow it through.&lt;BR /&gt;&lt;BR /&gt;If on the other hand, you are trying to ping the router, or another AP, or maybe another client, the destination address will be private and we will drop the traffic at the AP.&lt;BR /&gt;&lt;BR /&gt;Hope this clarifies!&lt;BR /&gt;&lt;BR /&gt;Rob</description>
      <pubDate>Tue, 24 Mar 2015 13:26:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/L3-L4-User-Traffic-Profiles-in-vSCG/m-p/2630#M21</guid>
      <dc:creator>rob_krumm</dc:creator>
      <dc:date>2015-03-24T13:26:53Z</dc:date>
    </item>
  </channel>
</rss>

