User Guide: AMF Security mini version 1.7.0

Device



Device menu lets you view and manage network devices.


Device List

This page shows the list of networks registered in AMF Security mini's database.



Table 1: Target columns for search and sort operations
Item Name Search Sort Note
Device ID × ×  
Tag × ×  
Note × ×  
Number of Policies × ×  
Number of Interfaces × ×  
Interface: MAC Address* × × * This column is not displayed on the screen.
Interface: Name* × × * This column is not displayed on the screen.
Interface: Note* × × * This column is not displayed on the screen.

Table 2: Displayed columns
Item Name Description
Device ID ID (Name) of the device to register.
Tag Secondary name of the device for administrative use.
Note Arbitrary string (comment) for the device.
Number of Policies Number of security policies applied to the device.
Number of Interfaces Number of MAC addresses (interfaces) associated with the device.

Table 3: Buttons
Item Name Description
Page Top
Add Device Open the Add Device page.
Active Device List Open the Active Device List page.
Export to CSV Start downloading of a list of devices in CSV format.
Device List
Heading Row
Delete Selected Delete all the checked devices.
Each Row
Edit Open the Update Device page for the selected device.
Delete Delete the device.
Note
Refer to CSV File in Appendix for CSV Files.

Add Device

This page lets you add a new device to the database.


Table 4: Sample Configuration Data
Item Name Description
Device ID (Mandatory) ID (Name) of the device to register.
Device ID must be unique.
Max 255 characters
Tag Secondary name of the device.
It can be used by administrators to easily distinguish, categorize or filter devices.
Max 255 characters
Note Arbitrary string (comment) for the device.
Max 255 characters.

Table 5: Displayed columns
Item Name Description
Interfaces
Interfaces List of MAC addresses (interfaces) associated with the device.
MAC Address Interface MAC address of the device.
Name Administrative name of the interface (MAC address).
Note Arbitrary string (comment) for the interface (MAC address).
Policies
Policies List of security policies which are being applied to the device.
Priority A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to the AMF Member, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AMF Security mini is assign the device to.
Location ID (Name) of the location.
Schedule A Schedule ID.

Table 6: Buttons
Item Name Description
Interfaces
Add Open the Edit Interface dialog to register new interface for the device.
Each Row
Edit Open the Edit Interface dialog to edit the selected interface.
Delete Mark to delete the MAC address (interface) associated with the device. The interface to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the interface.
Policies
Add Open the Edit Policy dialog to register new security policy for the device.
Each Row
Edit Open the Edit Policy dialog to edit the selected security policy.
Delete Mark to delete the security policy attached to the device. The security policy to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the security policy.
Page Bottom
Submit Add a new device with the input information on this page and subordinate dialogs by committing the information for the newly added device.
Cancel Cancel the operation for adding a new device.
Note
Interfaces and security policies marked with DEL is deleted when the "Submit" button is clicked. Once you click the "Submit" button, you cannot undo the delete operations.

Edit Interface

This dialog lets you add a new MAC address (interface) to the device or update an existing MAC address (interface) associated with the device.


Table 7: Configurable fields
Item Name Description
MAC Address (Mandatory) MAC address of the interface. MAC address must be unique.
Valid formats are as follows
xx:xx:xx:xx:xx:xx, xx-xx-xx-xx-xx-xx, xxxx.xxxx.xxxx
Name Administrative name of the interface.
Max 255 characters.
Note Arbitrary string (comment) for the interface.
Max 255 characters.

Table 8: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the interface information.
Cancel Cancel the operation of adding or updating the interface information.

Edit Policy

This dialog lets you add a new security policy to the device or update an existing security policy attached to the device.


Table 9: Configurable fields
Item Name Description
Priority (Mandatory) A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to the AMF Member, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AMF Security mini is assign the device to.
Maximum 100 IDs of the existing networks are shown in the drop-down list. If you enter text in the field, Network IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Network ID, VLAN ID or Note (it shows maximum 100 elements). From the drop-down list, select a Network ID.
If the registered device is connected to the AMF Member, the device is connected to the VLAN subnet configured in the network. If the network is not registered in the device (if this setting is blank or the VLAN ID is set to 0 in the network security policy setting), the device is connected to the VLAN set for the AMF Member.
The connection to the VLAN subnet is realized by sending as a tagged VLAN with the set VLAN ID when it is sent to the upper network of the connected the AMF Member.
You have to add the network before assigning a device to the network.
Refer to Policy Settings > Add Network for the instruction on how to register a network.
Location Specify a location where the device can access the network.
Maximum 100 IDs of the existing locations are shown in the drop-down list. If you enter text in the field, location IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Location ID or Note (it shows maximum 100 elements). From the drop-down list, select a Location ID.
If you specify a Location, UnAuth Group can access the network only from AMF Members in the Location.
If no Location is selected, it is accessible to all AMF Members.
You have to add the location before specifying it for a device.
Refer to Policy Settings > Add Location for the instructions on how to add a location.
Schedule Specify a schedule when the device can access the network.
Maximum 100 IDs of the existing schedules are shown in the drop-down list. If you enter text in the field, Schedule IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Schedule ID or Note (it shows maximum 100 elements). From the drop-down list, select a Schedule ID.
If you specify a Schedule for a device, the device can access the network only when the schedule is effective. If no Schedule is selected, it is always accessible.
You have to add the schedule before specifying it for a device.
Refer to Policy Settings > Add Schedule for the instruction on how to register a schedule.
OpenFlow Switch Not supported in this version.
Switch Port Not supported in this version.
Indefinite expiration date. Not supported in this version.
Note
If the VLAN set in the AMF Member is accessible, the device may be able to connect to the equipment on the control plane depending on the switch settings.

Table 10: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the security policy information.
Cancel Cancel the operation for adding or updating policy.

Update Device

This page lets you update the information of an existing device.


Table 11: Configurable fields
Item Name Description
Device ID (Mandatory) ID (Name) of the device to register.
Device ID must be unique.
Max 255 characters
Tag Secondary name of the device.
It can be used by administrators to easily distinguish, categorize or filter devices.
Max 255 characters
Note Arbitrary string (comment) for the device.
Max 255 characters.

Table 12: Displayed columns
Item Name Description
Interfaces
Interfaces List of MAC addresses (interfaces) associated with the device.
MAC Address Interface MAC address of the device.
Name Administrative name of the interface (MAC address).
Note Arbitrary string (comment) for the interface (MAC address).
Policies
Policies List of security policies which are being applied to the device.
Priority A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to the AMF Member, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AMF Security mini is assign the device to.
Location ID (Name) of the location.
Schedule A Schedule ID.

Table 13: Buttons
Item Name Description
Interfaces
Add Open the Edit Interface dialog to register new interface for the device.
Each Row
Edit Open the Edit Interface dialog to edit the selected interface.
Delete Mark to delete the MAC address (interface) associated with the device. The interface to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the interface.
Policies
Add Open the Edit Policy dialog to register new security policy for the device.
Each Row
Edit Open the Edit Policy dialog to edit the selected security policy.
Delete Mark to delete the security policy attached to the device. The security policy to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the security policy.
Page Bottom
Submit Update the device with the input information on this page and subordinate dialogs by committing the information for the existing device.
Cancel Cancel the operation for updating the device.
Note
Interfaces and security policies marked with DEL is deleted when the "Submit" button is clicked. Once you click the "Submit" button, you cannot undo the delete operations.

Edit Interface

This dialog lets you add a new MAC address (interface) to the device or update an existing MAC address (interface) associated with the device.


Table 14: Configurable fields
Item Name Description
MAC Address (Mandatory) MAC address of the interface. MAC address must be unique.
Valid formats are as follows
xx:xx:xx:xx:xx:xx, xx-xx-xx-xx-xx-xx, xxxx.xxxx.xxxx
Name Administrative name of the interface.
Max 255 characters.
Note Arbitrary string (comment) for the interface.
Max 255 characters.

Table 15: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the interface information.
Cancel Cancel the operation of adding or updating the interface information.

Edit Policy

This dialog lets you add a new security policy to the device or update an existing security policy attached to the device.


Table 16: Configurable fields
Item Name Description
Priority (Mandatory) A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to the AMF Member, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AMF Security mini is assign the device to.
Maximum 100 IDs of the existing networks are shown in the drop-down list. If you enter text in the field, Network IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Network ID, VLAN ID or Note (it shows maximum 100 elements). From the drop-down list, select a Network ID.
If the registered device is connected to the AMF Member, the device is connected to the VLAN subnet configured in the network. If the network is not registered in the device (if this setting is blank or the VLAN ID is set to 0 in the network security policy setting), the device is connected to the VLAN set for the AMF Member.
The connection to the VLAN subnet is realized by sending as a tagged VLAN with the set VLAN ID when it is sent to the upper network of the connected the AMF Member.
You have to add the network before assigning a device to the network.
Refer to Policy Settings > Add Network for the instruction on how to register a network.
Location Specify a location where the device can access the network.
Maximum 100 IDs of the existing locations are shown in the drop-down list. If you enter text in the field, location IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Location ID or Note (it shows maximum 100 elements). From the drop-down list, select a Location ID.
If you specify a Location, UnAuth Group can access the network only from AMF Members in the Location.
If no Location is selected, it is accessible to all AMF Members.
You have to add the location before specifying it for a device.
Refer to Policy Settings > Add Location for the instructions on how to add a location.
Schedule Specify a schedule when the device can access the network.
Maximum 100 IDs of the existing schedules are shown in the drop-down list. If you enter text in the field, Schedule IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Schedule ID or Note (it shows maximum 100 elements). From the drop-down list, select a Schedule ID.
If you specify a Schedule for a device, the device can access the network only when the schedule is effective. If no Schedule is selected, it is always accessible.
You have to add the schedule before specifying it for a device.
Refer to Policy Settings > Add Schedule for the instruction on how to register a schedule.
OpenFlow Switch Not supported in this version.
Switch Port Not supported in this version.
Indefinite expiration date. Not supported in this version.
Note
If the VLAN set in the AMF Member is accessible, the device may be able to connect to the equipment on the control plane depending on the switch settings.

Table 17: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the security policy information.
Cancel Cancel the operation for adding or updating policy.


MAC Address List

This page shows a list of MAC addresses registered in AMF Security mini's database.


Table 18: Target columns for search and sort operations
Item Name Search Sort Note
MAC Address × ×  
Name × ×  
Device ID × ×  
Note × ×  
Device: Tag* × × * This column is not displayed on the screen.
Device: Note* × × * This column is not displayed on the screen.

Table 19: Displayed columns
Item Name Description
MAC Address MAC address which is registered in AMF Security mini's database.
Name Administrative name of the interface (MAC address).
Device ID ID of the device which is associated with the MAC address.
When clicked, the Update Device page for the device is displayed.
Note Arbitrary string (comment) for the MAC Address.

Table 20: Buttons
Item Name Description
Page Top
Active Device List Open the Active Device List page.
MAC Address List
Heading Row
Delete Selected Delete all the checked MAC addresses.
Each Row
Edit Open the Update Device page for a device associated with the MAC address.
Delete Delete the MAC address.


Active Device List

This page shows a list of the devices which are connected to the AMF Member managed by AMF Security mini system, and the devices which are authenticated or applied actions by AMF Application Proxy.
For the devices which are applied actions by the AMF Application Proxy, information retrieved from an AMF Master is listed.

Because AMF Application Proxy Whitelist and Blacklist operate independently, Information shown on Device > Active Device List page may be different from the status held by Edge Nodes.
When a device authenticated by AMF Application Proxy Whitelist becomes unauthenticated without a linkdown event, information on the device is deleted from Edge Nodes but it remains "Authorized" on the Device > Active Device List page.


Table 21: Target columns for search, filter and sort operations
Item Name Search Filter Sort Note
MAC Address * × * Only the strings after "mac=" and "ip=" can be matched.
Device ID *1 *2 *1 "Unregistered" cannot be matched. For devices connected or detected in an UnAuth group, only strings after "group=" can be matched.
*2 Sorted in the order of "Unregistered", "UnAuth Group ID", "Empty" and "Device ID".
Connected Switch *1 *2 *1 The strings after "id=" and Switch Port Number after "port=" can be matched.
*2Only sorted by the string after "id=". Sorting by the string after "port=" is not supported.
Connecting Network *1 *2 *1 Only VLAN ID after "vlan=" and Network ID after "id=" can be matched. "Untagged" and "No Connection" cannot be matched.
*2 Sorted in the order of "No Connection", "Empty", "vlan=Untagged" and "vlan=1-4094". Sorting by Network ID is not supported.
Status × × * * * Sorted in the order of "Authorized", "Blocked", "Link-Down", "Quarantined", "Authentication Failed", "Detected", "IP-Filter" and "Log-Only".


Table 22: Displayed columns
Item Name Description
MAC Address MAC address managed by AMF Security mini.
When the device is blocked by an IP address, the IP address is also displayed.
When you click the MAC or IP address, the Active Device Detail page for the device is displayed.
Device ID ○ The AMF Application Proxy
ID of the device which is associated with the MAC address.
  • If there is a device associated with the MAC address, the device's Device ID is displayed regardless of the device's security policy.
    When clicking the Device ID, the Update Device page is displayed.
  • If there is no device associated with the MAC address and the connection matches a security policy of any UnAuth Group, a group ID is displayed in "group=Group ID" format.
    When clicking a Group ID, the Group > Update UnAuth Group page appears.
  • If there is no device associated with the MAC address and the connection does not match security policies of UnAuth Groups, the Device ID is shown as "Unregistered".
  • If there is no device with the MAC address, a "Register" button is displayed.
Connected Switch ○ The AMF Application Proxy
Edge node to which authentication and AMF Action are applied by the AMF Application Proxy Whitelist, and the Port Name of the edge node Switch.
Edge Node is displayed in the format "id=Edge Node Name".
The IPv4 Address of the Edge Node Switch is displayed in the format of "ip=IPv4 Address". Also, the port name of the edge node Switch is displayed in the format of "port=(Port Name)".
If the AMF Action displayed in the status is "IP filter", the port name is not displayed.
Connecting Network ○ The AMF Application Proxy
VLAN ID and Network ID of the network to which the MAC address is connected.
VLAN ID and Network ID are shown in the form of "vlan=VLAN ID" and "id=Network ID" respectively.
When clicking a string after "id=", the Policy Settings > Update Network page is displayed.
No Connecting Network is displayed for devices which are applied actions.
Status ○ The AMF Application Proxy
Current status of the MAC address.
  • Authorized: Authenticated: a device matching a registered security policy for the device or an UnAuth Group.
  • Blocked: a device which is blocked at layer 2 (MAC) level by the AMF Application Proxy. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page.
  • Link-Down: a device which is blocked by a linkdown event of the connected switch port. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page.
  • IP-Filter: a device which is blocked at layer 3 (IP) level by the AMF Application Proxy. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page.
  • Quarantined: a device which is moved to a quarantine network by the AMF Application Proxy. ID of the action which is performing the quarantine operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network other than the quarantine network unless the action is deleted by the "Delete" button.
  • Authentication Failed: a device which is not authenticated because it is not associated with a registered MAC address nor does not match any security policy.
  • Detected: a device detected by an UnAuth Group with the detect-only option enabled.
  • Log-Only: a device for which logs are generated without being applied any action. ID of the action which is performing the notification operation is shown in the form of "action=Action ID" with the "Delete" button beside it.
Clicking a Status opens the Active Device Detail page for the device.
For "Blocked", "Link-Down", "IP-Filter", "Quarantined" and "Log-Only" action, ID of the action which is performing the action is shown in the form of "action=Action ID" with the "Delete" button beside it. You can go to the Policy Settings > Action Detail page by clicking a string after "action=".
Format and meaning of a port name in the Connected Port column differs depending on the model of the AMF node.


Table 23: Connected Port Name
Port Name Description
AlliedWare Plus Devices
portX.Y.Z X - always "1"
Y - Expansion bay number. "0" for a base (non-expansion) port.
Z - Port number printed on the product.
AT-TQ series wireless access point
wlanX radio interface.
athX radio interface.

Table 24: Buttons
Item Name Description
Page Top
Search Devices Open the Search Devices dialog.
Once the search began, the label of the "Search Device" button changes to the "Cancel Search" button. Progress of the search operation is displayed in the "Search Progress" text box under the button.
Cancel Search Cancel the search operation.
It's only available when the search is in progress.
Action List Open the Policy Settings > Action List page.
Export to CSV Start downloading of a list of devices in CSV format.
Refresh Refresh the Active Device List page.
Active Device List
Heading Row
Disconnect Selected ○ The AMF Application Proxy
This operation is not for a device which is applied an AMF action.

○ The AMF Application Proxy Whitelist<br7> Temporarily disconnect all the checked MAC addresses from the network.
Because this operation is temporary, disconnected devices can reconnect to the network as they have appropriate permissions.
Each Row
Disconnect ○ The AMF Application Proxy
This operation is not for a device which is applied an AMF action.

○ The AMF Application Proxy Whitelist<br7> Temporarily disconnect the MAC addresses from the network.
Because this operation is temporary, disconnected devices can reconnect to the network as they have appropriate permissions.
Note
Refer to CSV File in Appendix for CSV Files.


Add Device

By clicking the "Register" button for an unregistered MAC address on the Device > Active Device List page, you can add the MAC address as a new device or associate the MAC address with an existing device.


Table 25: Configurable fields
Item Name Description
Register this MAC Address as a new device. Add the MAC address specified on the Active Device List page as an interface of a new device.
Add this MAC Address to an existing device. Add the MAC address specified on the Active Device List page as an additional interface of an existing device.
Device When you select the "Add this MAC Address to an existing device.", specify a Device ID to which the MAC address is associated.
Maximum 100 device IDs are shown in the drop-down list. If you enter text in the field, device IDs in the drop-down list are dynamically filtered to the ones which contain the input text in Device ID, Tag or Note (it shows maximum 100 elements). From the drop-down list, select a Device ID for the device.

Table 26: Buttons
Item Name Description
Bottom of the dialog
Submit Add a new MAC address as a new device or a new interface of an existing device.
The Device > Add Device page is displayed if you selected the "Add the MAC address as an interface of a new device.", while the Device > Update Device page is displayed if you selected the "Add this MAC Address to an existing device.".
On the Add Device or the Update Device page, the MAC address is automatically added to the "Interfaces" for the device. Enter additional data such as Device ID, Tag, Note, security policies and other interfaces as required, then click the "Submit" button.
Cancel Cancel the operation for adding the MAC address.

Search Devices

When you click the "Search Devices" button on the Device > Active Device List page, the following dialog appears and lets you specify a range of IP addresses to search.


Table 27: Configurable fields
Item Name Description
Search Range Enter an IPv4 address or an IPv4 address range to search for devices.
An IPv4 address range can be specified in one of the following formats.
xxx.xxx.xxx.xxx-xxx.xxx.xxx.xxx (The first and the last address in the range)
xxx.xxx.xxx.xxx/xx (A base IPv4 address and a mask length)
xxx.xxx.xxx.xxx or xxx.xxx.xxx.xxx/32 (A single IP address)
Probe ARP or ARP Select a search method from "Probe ARP" and "ARP". Also specify a Sender IP when using ARP.
Sender IP Specify this only when you select "ARP".
OpenFlow Switches / AMF Members ○ The AMF Application Proxy
Specify AMF Member names to send out search packets. Multiple AMF Members can be specified by separating each name with a semicolon (;). When no AMF Member is specified, all connected AMF Members send out search packets.
Note
Make sure to specify a Sender IP which is not used in the target address range.


Table 28: Buttons
Item Name Description
Bottom of the dialog
Search Start search on the input IPv4 address(es).
Clicking the "Search" button brings you back to the Active Device List page. Once the search began, the label of the "Search Device" button changes to the "Cancel Search" button. Progress of the search operation is displayed in the "Search Progress" text box under the button.
Cancel Cancel the search operation.

Active Device Detail

When clicking a MAC address or "Status" on the Device > Active Device List page, detailed information of the selected device is displayed.


Table 29: Displayed columns
Item Name Description
MAC Address MAC address which is registered in AMF Security mini's database.
IPv4 Address IPv4 address of the device. It is displayed only if it is known.
Device ID ID of the device which is associated with the MAC address.
  • If there is a device associated with the MAC address, the device's Device ID is displayed regardless of the device's security policy.
    When clicking the Device ID, the Update Device page is displayed.
  • If there is no device associated with the MAC address and the connection matches a security policy of any UnAuth Group, a group ID is displayed in "group=Group ID" format.
    When clicking a Group ID, the Group > Update UnAuth Group page appears.
  • If the MAC address is not registered and does not match any security policies for UnAuth Groups, this column shows nothing.
Status Current status of the MAC address.

○ The AMF Application Proxy
  • >Authorized: a device whose MAC address matched a security policy for a registered device or an UnAuth Group.
  • Blocked: a device which is blocked at layer 2 (MAC) level by the AMF Application Proxy.
  • Link-Down: a device which is blocked by a linkdown event of the connected switch port.
  • IP-Filter: a device which is blocked at layer 3 (IP) level by the AMF Application Proxy.
  • Quarantined: a device which is moved to a quarantine network by the AMF Application Proxy.
  • Authentication Failed: a device which is not authenticated because it is not associated with a registered MAC address nor does not match any security policy.
  • Detected: a device detected by an UnAuth Group with the detect-only option enabled.
  • Log-Only: a device for which logs are generated without being applied any action.
Updated Date / Time The last time the status of the device changed.
Connecting Network VLAN ID and Network ID of the network to which the MAC address is connected.
VLAN ID and Network ID are shown in the form of "vlan=VLAN ID" and "id=Network ID" respectively. When clicking a string after "id=", the Policy Settings > Update Network page is displayed.
Action Originator Shows the name of a system which requests the device authentication or running action on the device.
Action Reason Shows a reason which is provided by the Action Originator.
If the action is triggered by a notification from an interacting application, contents of the notification syslog message or SNMP trap message is shown.

Table 30: Buttons
Item Name Description
Page Top
Back Go back to the Active Device List page.
Refresh Refresh the Active Device Detail page.


18 Jan 2021 10:56