User Guide: AMF Security mini version 2.6.1

What is AMF Security mini



Where does AMF Security mini Fit In

AMF-SECurity (AMF-SEC) is our solution to streamline network operations and enhance security in office environments.
AMF Security mini is the SDN controller that is the core of the solution, and it realizes the cooperation between our products supporting the AMF (Allied Telesis Management Framework) and various business security related applications.
Note
When registering data such as device IDs or MAC Addresses in AMF Security mini, refer to the Reference section as well.

What is AMF Application Proxy

The AMF Application Proxy controls traffic from edge devices which are connected to AMF Members (Edge Nodes) where AMF Master (Proxy Node) authenticates the devices by querying AMF Security mini (the AMF Application Proxy Whitelist).
It is also possible for AMF Security mini to notify the AMF Proxy Node of suspected node and make Edge Nodes to block the devices (the AMF Application Proxy Blacklist).
Note
◼ AMF Application Proxy Whitelist and AMF Application Proxy Blacklist
・ A Proxy Node also can be an Edge Node (Only supported models).
・ Cannot be linked with AMF controller.
You can use Whitelist only, Blacklist only, or both.
To use the AMF Application Proxy, you have to configure all of AMF Security mini, Proxy Node and Edge Nodes.

What does AMF Security mini Manage (the AMF Application Proxy Whitelist)

AMF Security mini can centrally control the network access from various devices by utilizing the port authentication feature on the AMF Members it manages.
The AMF Application Proxy Whitelist is an AMF-SEC (AMF-SECurity)'s integration feature where AMF devices ask the AMF Security mini system's whitelist server if a specific device can be allowed access to the network.
If a device meets those conditions, it is allowed to join the logical network defined by a VLAN ID.

The MAC address interface of the device is managed by connecting, blocking, and isolating based on the security policy assigned to the device.
A device can have more than one MAC address interface.
Assuming that a device has two MAC addresses - one for a wireless interface and the other for a wired interface, both of them can access the same network if they meet the conditions for Location and Schedule.
Table 1: Configurable Security Policies (the AMF Application Proxy Whitelist)
Device Information
Device network-capable equipment which connects to an AMF Member
MAC Address a MAC address of the device interface
: (multiple items can be defined)
Security Policies Network a VLAN segment (VLAN ID) to which a device is assigned.
Location a physical location where a device can access the network.
AMF Member a switch in the location.
Switch Port a port on the switch from which a device can access the network.
: (multiple items can be defined)
Schedule a range of time during a device can access the network (Start Date / Time, and End Date / Time).
(multiple items can be defined)

Configuring AMF Master (Proxy Node) and AMF Members (Edge Nodes)

The following are required settings for the AMF node to be managed.
For detailed settings, refer to the AlliedWare Plus Product's command reference manual.
Depending on the AlliedWare Plus Product model you use for a Proxy Node, you may have to install the proper license on the products.

Configuring AMF Security mini

To use AMF Application Proxy Whitelist on AMF Security mini, you have to configure an IP Address, level 15 (privileged) username and password ,and pre-shared key (PSK) of the AMF Master (Proxy Node) on AMF Security mini.
  1. Open the AMF > AMF Application Proxy Settings page.
  2. Click "Add".
  3. Enter an IP Address of the AMF Master (Proxy Node) in "IPv4 Address".
  4. Enter a username and a password for a level 15 (privileged) user account on the AMF Master (Proxy Node).
  5. In Pre-shared key, enter the pre-shared key set in the key parameter of the "application-proxy whitelist server" command of the AMF Master (Proxy Node).
  6. Click "Submit".
Note
When you finish this configuration, AMF Security mini starts regular queries to the AMF Master (Proxy Node) at 30 seconds interval.

Blocking with AMF Application Proxy (AMF Application Proxy Blacklist)

Notifying Proxy Node of Suspected Node Information

AMF Security mini notifies the Proxy Node of suspected node when it receives the information from a security software/hardware or an action is added by an administrator on the Policy Settings > Add Action page. The suspected node's information is stored on AMF Security mini and can be viewed on the Policy Settings > Action List page.
AMF Security mini does not notify the proxy node of the information again.
Note
If the proxy node holding the suspected node information reboots, the information is removed from the proxy node.
Because the proxy node cannot receive the information from AMF Security mini again, the proxy node cannot relearn the suspected node automatically.
To manually tell the proxy node about the suspected node, follow the steps below.
1. Open the Policy Settings > Action List page.
2. Click the "Export to CSV" button to save a CSV file.
3. Open the System Settings > System Information page.
4. Click the "Import" button for the Authentication Data item to open the "Upload Authentication Data" dialog.
5. Click the "Choose File" button, select the saved CSV file, and click the "Submit" button.

AMF Actions

When AMF Security mini notifies the Proxy Node of suspected nodes, it can also specify a blocking action (AMF action).
AMF Security mini can specify the following AMF actions.
When "Quarantine", "Drop Packets", "Link-Down", "IP-Filter", or "Log-Only" are set, these AMF actions are executed with priority over the AMF actions set on the edge node side.
When "AMF Dependency" is set, the AMF action is not sent from AMF Security mini and the AMF action set on the edge node side is executed.
Note
If AMF Security mini and AMF Master receive suspected node information from multiple sources (e.g. external applications), specify the same AMF action for all the sources.
The AMF Action for each application can be specified in the "Rules" section on the System Settings > Trap Monitor Settings page.
To change the AMF action for a suspected node which has already been registered on the Policy Settings > Action List page, delete the existing action and recreate it.
Note
Even if the device is permitted by the whitelist, if it is the target of AMF Action, the communication from the corresponding device is processed according to the action.

Unblocking Suspected Nodes

To unblock a suspected node (delete the suspected node information), delete the corresponding action on the Policy Settings > Action List page. When the action is deleted, AMF Security mini tells the proxy node to delete the suspected node information.
Note
You can also unblock the suspected node by running commands on the proxy node. But in this case, the proxy node does not request AMF Security mini to delete the node information. So AMF Security mini keeps the suspected node information. If you want to delete it, manually delete the action on the Policy Settings > Action List page.
Refer to the AlliedWare Plus Product's command reference manual for the commands.

Displaying and Emailing Blocking Status of the Suspected Node

Status of the suspected node which has been applied an AMF action by an edge node can be view on the Device > Active Device List page.
AMF Security mini regularly gets this information from the proxy node at 30 seconds interval.
You can also send emails by setting the AMF Security mini email notification settings on the System Settings > Email Notification Settings page.
Note
When AMF Security mini queries the proxy node and finds that suspected node information is changed (e.g. a node moved to other switch and got blocked there again), AMF Security mini updates the information on the Device > Active Device List page and sends an email notification.

Configuring AMF Master (Proxy Node) and AMF Members (Edge Nodes)

The following are required settings for the AMF node to be managed.
For detailed settings, refer to the AlliedWare Plus Product's command reference manual.
Depending on the AlliedWare Plus Product model you use for a Proxy Node, you may have to install the proper license on the products.

Configuring AMF Security mini

To use AMF Application Proxy Blacklist, you have to configure an IP Address, level 15 (privileged) username and password of the AMF Master (Proxy Node) on AMF Security mini.
  1. Open the AMF > AMF Application Proxy Settings page.
  2. Click "Add".
  3. Enter an IP Address of the AMF Master (Proxy Node) in "IPv4 Address".
  4. Enter a username and a password for a level 15 (privileged) user account on the AMF Master (Proxy Node).
  5. Click "Submit".
Note
When you finish this configuration, AMF Security mini starts regular queries to the AMF Master (Proxy Node) at 30 seconds interval.
Refer to System Settings / Trap Monitor Settings for how to configure integration options with external applications.

AMF Application Proxy Function on TQ and TQR

The AMF Application Proxy function of TQ and TQR controls communication by having AMF Security mini authenticate wireless terminals connected to TQ and TQR (AMF Application Proxy Whitelist function).
When AMF Security mini receives the IP Address of a suspected terminal from an external application, it queries AT-Vista Manager EX for the corresponding MAC Address. The MAC Address held by the AWC plugin is then retrieved and sent to TQ and TQR, where communication control of the terminal is performed (AMF Application Proxy Blacklist function).

Supported actions are Drop Packets, Quarantine, and Log (only log output without controlling communication of the corresponding device).

Note
Hereafter, content common to both TQ and TQR is referred to as TQ. If there are differences between TQ and TQR, they are explicitly noted.
Note
Supported actions vary by product and version. Refer to Target Products and Versions for products and compatible versions.
Note
AMF Application Proxy to be set in TQ can be set from AWC Plug-in (it cannot be done from the TQ management page). The configuration of the AMF Application Proxy function for TQR varies depending on the versions of AT-Vista Manager EX and TQR in use. Refer to Target Products and Versions for details.
When using the AMF Application Proxy function with either TQ or TQR, there are settings that must be configured outside of the AWC plugin. Refer to the documents for TQ/TQR and the AWC Plug-in as well.
Note
When using the AT-VST-APL / AT-VST-VRT version of AT-Vista Manager EX, AMF Security mini contacts the AWC Plug-in directly.
Note
Authentication when a wireless terminal is connected is performed in the order of "Authentication by AMF Application Proxy (AMF Security mini)" → "Authentication set by security of VAP (multi-SSID) setting". If both authentications are not successful, the wireless terminal is not allowed to connect.
Note
The following items are not supported by TQ's AMF Application Proxy.
・ Location policy
・Schedule policy
・session-timeout
・Obtaining authentication information on TQ
・IP Address display of node
・Search Devices
・Account Group
Note
Once the connection between the connected AMF Master is set to be disconnected, if the device already managed by TQ's AMF Application Proxy (devices displayed on the Device > Active Device List page) exists, the authentication and action of that device remain applied. However, it is deleted from the Devices > Active Device List page.

The following applies to the settings and operations of AMF Security mini.

System Settings > Network Settings page
Uploading or deleting the SSL Certificate of the Web server
System Settings > Logging Settings page
System Time Settings > Date > Time Settings page
System Settings > System Information
Hostname
System Settings - Import
System Settings - Reset
Services - Restart All
System Settings > Trap Monitor Settings page
Device Lookup
System Settings > Email Notification Settings page
System Settings > Action Log
Clear Action Log
AMF > AMF Application Proxy Settings page
AMF Master
White-List Settings
Uploading or deleting the SSL Certificate of the Web server
AMF > TQ Setting page

This also applies to restarting the AMF Security mini instance (Stop → Start) on the AW+ Web GUI / Vista Manager mini - AMF Security mini page, and restarting AW+.

Target Products and Versions

To use this function, the following products and compatible versions are required.

TQ Series

Table 2: AT-TQ7403
Corresponding products Corresponding version
AT-TQ7403 10.0.4-0.1 or later
AT-Vista Manager EX (AWC Plug-in) 3.12.0 (3.12.0) or later
AMF Security mini 2.2.1 or later
Table 3: AT-TQ6403 GEN2/AT-TQm6403 GEN2
Corresponding products Corresponding version
AT-TQ6403 GEN2/AT-TQm6403 GEN2 9.0.4-0.1 or later
AT-Vista Manager EX (AWC Plug-in) 3.12.0 (3.12.0) or later
AMF Security mini 2.2.1 or later
Table 4: AT-TQ6702e GEN2
Corresponding products Corresponding version
AT-TQ6702e GEN2 9.0.4-3.1 or later
AT-Vista Manager EX (AWC Plug-in) 3.13.1 (3.13.1) or later
AMF Security mini 2.2.1 or later
Table 5 : AT-TQ3403/AT-TQm3403
Corresponding products Corresponding version
AT-TQ3403/AT-TQm3403 11.0.5-0.1 or later
AT-Vista Manager EX (AWC Plug-in) 3.14.0 (3.14.0) or later
AMF Security mini 2.2.1 or later
Table 6: AT-TQ7613
Corresponding products Corresponding version
AT-TQ7613 12.0.5-0.1 or later
AT-Vista Manager EX (AWC Plug-in) 3.15.0 (3.15.0) or later
AMF Security mini 2.2.1 or later

TQR Series

AT-TQ6702 GEN2-R
Table 7: AT-TQ6702 GEN2-R (5.5.4-0.x and 5.5.4-1.x)
Corresponding products Corresponding version
AT-TQ6702 GEN2-R 5.5.4-0.x and 5.5.4-1.x
AT-Vista Manager EX (AWC Plug-in) 3.12.x (3.12.x)
AMF Security mini 2.2.1 or later
Note
The AMF Application Proxy function for TQR is configured via the TQR Command Line Interface (CLI) or Web GUI. Settings cannot be configured from the AWC plugin.
Table 8: AT-TQ6702 GEN2-R (5.5.4-2.3 or later)
Corresponding products Corresponding version
AT-TQ6702 GEN2-R 5.5.4-2.3 or later
AT-Vista Manager EX (AWC Plug-in) 3.13.1 (3.13.1) or later
AMF Security mini 2.2.1 or later
Note
The AMF Application Proxy function for TQR is configured via the TQR Command Line Interface (CLI) or Web GUI. However, if you are configuring the VAP for TQR using the AWC plugin, perform the configuration from the AWC plugin.
AT-TQ7403-R
Table 9: AT-TQ7403-R (5.5.4-2.1)
Corresponding products Corresponding version
AT-TQ7403-R 5.5.4-2.1
AT-Vista Manager EX (AWC Plug-in) 3.12.x (3.12.x)
AMF Security mini 2.2.1 or later
Note
The AMF Application Proxy function for TQR is configured via the TQR Command Line Interface (CLI) or Web GUI. Settings cannot be configured from the AWC plugin.
Table 10: AT-TQ7403-R (5.5.4-2.3 or later)
Corresponding products Corresponding version
AT-TQ7403-R 5.5.4-2.3 or later
AT-Vista Manager EX (AWC Plug-in) 3.13.1 (3.13.1) or later
AMF Security mini 2.2.1 or later
Note
The AMF Application Proxy function for TQR is configured via the TQR Command Line Interface (CLI) or Web GUI. However, if you are configuring the VAP for TQR using the AWC plugin, perform the configuration from the AWC plugin.

Behavior when using TQ dynamic VLAN

For TQ's AMF Application Proxy, when WPA Enterprise is selected for the security of VAP (multi-SSID) setting of TQ, the VLAN ID given to the wireless terminal at the time of authentication differs depending on whether the dynamic VLAN is disabled or enabled.
When dynamic VLAN is disabled:
If the wireless terminal is authenticated by AMF Security mini and the VLAN ID is assigned by AMF Security mini, the VLAN to which the wireless terminal belongs is the VLAN ID of AMF Security mini. If the VLAN ID is not assigned by AMF Security mini, the wireless terminal belongs to the VLAN ID of VAP.
Note
The settings of AMF Security mini when the VLAN ID is not assigned by AMF Security mini are as follows.
・Set the network with VLAN ID 0 in the policy setting (isolated VLAN ID)
・Do not set the network
When dynamic VLAN is enabled:
Authenticate the wireless terminal with AMF Security mini, and then authenticate with the RADIUS server on the WPA Enterprise side. The VLANs to which the wireless terminal belongs are as follows:
However, if the VLAN ID of the isolated VLAN is assigned by AMF Security mini, it belongs to the isolated VLAN ID assigned by AMF Security mini regardless of the presence or absence of the VLAN ID of the dynamic VLAN.
Table 11: VLAN to which the wireless terminal belongs
AMF Security mini Granted VLAN ID VLAN ID given by the RADIUS server VLAN to which the wireless terminal belongs
Yes Yes VLAN ID given by the RADIUS server
None None VAP VLAN ID
None Yes VLAN ID given by the RADIUS server
Yes None AMF Security mini Granted VLAN ID
Note
The settings without VLAN ID in AMF Security mini are as follows.
・Set the network with VLAN ID 0 in the policy setting (isolated VLAN ID)
・Do not set the network
◼ Operation when VLAN ID 1 is assigned to TQ
The behavior when VLAN ID 1 is assigned to TQ depends on the setting of the management VLAN tag of TQ.
For details, refer to the TQ document posted on our website.

Critical mode

In the critical mode, you can select the processing of the newly connected wireless terminal when a failure such as a power failure occurs in the AMF Security mini.
Invalid:
All newly connected wireless terminals is denied connection because they cannot be authenticated by AMF Security mini.
The wireless terminal that was already connected can still communicate.
Enabled:
Allows newly connected wireless terminals without AMF Security mini authentication.
Normally, after successful authentication of AMF Security mini, the authentication set in the security of VAP (Multi SSID) setting is performed. In this case, proceed to the authentication set in the security of the VAP (multi-SSID) setting without performing the authentication by AMF Security mini.
The VLAN to which the wireless terminal belongs is the VLAN determined when the authentication set in the security of the VAP (multi-SSID) setting is successful.

Redirect-URL Action

When Redirect-URL Action is applied to a wireless device, that wireless device is connected to the quarantine network, similar to the quarantine action. After that, the Web access of the wireless terminal is redirected to the external page (URL) set by the TQ corresponding to Redirect-URL Action, and the content of the external page is displayed on the web browser.
When using Redirect-URL Action, the product/version used must be compatible with Redirect-URL Action. Please do not use Redirect-URL Action in products that do not support the intended action. Also, there is no setting item in AW+ AMF Application Proxy. OpenFlow is a common action with TQ's AMF Application Proxy, but do not use it because it is not supported.
In AMF Security mini, it is possible to set a site for Redirect-URL Action (Web Site For Quarantined Device) and specify it on an external page. Site settings for Redirect-URL Actions are performed on the AMF > Redirect-URL Settings page. The protocol of this site is HTTP.
Note
This website only supports redirected access, and does not support normal web servers.
Redirect-URL related setting for TQ is done by AT-Vista Manager EX's AWC Plug-in.
If AMF Security is used as a site for Redirect-URL Action, the external page URL setting of Redirect-URL with the AWC Plug-in is as follows.
http://(AMF Security mini IP Address):(configured port number)/index.html
For example, if the IP Address set for AMF Security mini is "192.168.1.10" and the port number set on the AMF > Redirect-URL Settings page is "8000", specify the following:
http://192.168.1.10:8000/index.html

Supported OpenFlow Switches

List of OpenFlow Switch models supported by AMF Security mini can be found on the release notes of AMF Security mini, switches and wireless access points.
Please find those documents on our website.
http://www.allied-telesis.co.jp/

Application Integration Solutions

AMF Security mini can be used with other applications such as threat detection, device management and HR management in order to further enhance network administration efficiency and security.
The latest information on the services or applications which can be integrated into AMF Security system is published under the AMF-SEC Technology Partner Program. Contact our sales engineer for the Technology Partner Program.

07 Oct 2025 12:05