User Guide: AMF Security Controller version 1.8.0

Device



Device menu lets you view and manage network devices.


Device List

This page shows the list of networks registered in AT-SESC's database.



Table 1: Target columns for search and sort operations
Item Name Search Sort Note
Device ID × ×  
Tag × ×  
Note × ×  
Number of Policies × ×  
Number of Interfaces × ×  
Interface: MAC Address* × × * This column is not displayed on the screen.
Interface: Name* × × * This column is not displayed on the screen.
Interface: Note* × × * This column is not displayed on the screen.

Table 2: Displayed columns
Item Name Description
Device ID ID (Name) of the device to register.
Tag Secondary name of the device for administrative use.
Note Arbitrary string (comment) for the device.
Number of Policies Number of security policies applied to the device.
Number of Interfaces Number of MAC addresses (interfaces) associated with the device.

Table 3: Buttons
Item Name Description
Page Top
Add Device Open the Add Device page.
Active Device List Open the Active Device List page.
Export to CSV Start downloading of a list of devices in CSV format.
Device List
Heading Row
Delete Selected Delete all the checked devices.
Each Row
Edit Open the Update Device page for the selected device.
Delete Delete the device.
Note
Refer to CSV File in Appendix for CSV Files.

Add Device

This page lets you add a new device to the database.


Table 4: Sample Configuration Data
Item Name Description
Device ID (Mandatory) ID (Name) of the device to register.
Device ID must be unique.
Max 255 characters
Tag Secondary name of the device.
It can be used by administrators to easily distinguish, categorize or filter devices.
Max 255 characters
Note Arbitrary string (comment) for the device.
Max 255 characters.

Table 5: Displayed columns
Item Name Description
Interfaces
Interfaces List of MAC addresses (interfaces) associated with the device.
MAC Address Interface MAC address of the device.
Name Administrative name of the interface (MAC address).
Note Arbitrary string (comment) for the interface (MAC address).
Policies
Policies List of security policies which are being applied to the device.
Priority A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to OpenFlow Switches or AMF Members, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AT-SESC assigns the device to.
Location A matching criterion of the MAC address for its access location. Either an OpenFlow Switch ID and a Switch Port or a Location ID.
Schedule A Schedule ID.

Table 6: Buttons
Item Name Description
Interfaces
Add Open the Edit Interface dialog to register new interface for the device.
Each Row
Edit Open the Edit Interface dialog to edit the selected interface.
Delete Mark to delete the MAC address (interface) associated with the device. The interface to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the interface.
Policies
Add Open the Edit Policy dialog to register new security policy for the device.
Each Row
Edit Open the Edit Policy dialog to edit the selected security policy.
Delete Mark to delete the security policy attached to the device. The security policy to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the security policy.
Page Bottom
Submit Add a new device with the input information on this page and subordinate dialogs by committing the information for the newly added device.
Cancel Cancel the operation for adding a new device.
Note
Interfaces and security policies marked with DEL is deleted when the "Submit" button is clicked. Once you click the "Submit" button, you cannot undo the delete operations.

Edit Interface

This dialog lets you add a new MAC address (interface) to the device or update an existing MAC address (interface) associated with the device.


Table 7: Configurable fields
Item Name Description
MAC Address (Mandatory) MAC address of the interface. MAC address must be unique.
Valid formats are as follows
xx:xx:xx:xx:xx:xx, xx-xx-xx-xx-xx-xx, xxxx.xxxx.xxxx
Name Administrative name of the interface.
Max 255 characters.
Note Arbitrary string (comment) for the interface.
Max 255 characters.

Table 8: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the interface information.
Cancel Cancel the operation of adding or updating the interface information.

Edit Policy

This dialog lets you add a new security policy to the device or update an existing security policy attached to the device.


Table 9: Configurable fields
Item Name Description
Priority (Mandatory) A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to OpenFlow Switches or AMF Members, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AT-SESC assigns the device to.
Maximum 100 IDs of the existing networks are shown in the dropdown list. If you enter text in the field, Network IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Network ID, VLAN ID or Note (it shows maximum 100 elements). From the dropdown list, select a Network ID.
If the registered device is connected to OpenFlow Switches or AMF Members, it is connected to the VLAN subnet configured in the network. If the network is not registered in the device (if this setting is blank or the VLAN ID is set to 0 in the network security policy setting), the OpenFlow Switch uses untagged VLAN (subnet without VLAN) and AMF Member Is connected to the VLAN set for the AMF Member. The connection to the VLAN subnet is realized by sending as a tagged VLAN with the set VLAN ID when it is sent to the upper network of the connected OpenFlow Switches and AMF Members.
You have to add the network before assigning a device to the network. Refer to Policy Settings > Add Network for the instruction on how to register a network.
Location Specify a location where the device can access the network.
Maximum 100 IDs of the existing locations are shown in the dropdown list. If you enter text in the field, location IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Location ID or Note (it shows maximum 100 elements). From the dropdown list, select a Location ID.
If you specify Location, the UnAuth Group can access the network only from OpenFlow Switches and AMF Members in the location.
If you do not specify Location, the UnAuth group can access the network from all OpenFlow Switches and AMF Members.
You have to add the location before specifying it for a device. Refer to Policy Settings > Add Location for the instructions on how to add locations.
Schedule Specify a schedule when the device can access the network.
Maximum 100 IDs of the existing schedules are shown in the dropdown list. If you enter text in the field, Schedule IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Schedule ID or Note (it shows maximum 100 elements). From the dropdown list, select a Schedule ID.
If you specify a Schedule for a device, the device can access the network only when the schedule is effective. If you do not specify a schedule, a device can always access the network.
You have to add the schedule before specifying it for a device. Refer to Policy Settings > Add Schedule for the instruction on how to register a schedule.
OpenFlow Switch Specify an OpenFlow Switches from which a device can access the network.
Maximum 100 IDs of the existing switches are shown in the dropdown list. If you enter text in the field, switch IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Switch ID, Datapath ID, Upstream Port or Note (it shows maximum 100 elements). From the dropdown list, select a Switch ID.
If an OpenFlow Switch is specified for the device, Location for the device is not used.
When OpenFlow Switch is specified but a switch port is not, the device can access the network through any port on the switch.
Switch Port Specify a switch port through which the device can access the network.
It is ignored if an OpenFlow Switch is not specified.
Indefinite expiration date. Disable timeout of the flow for the device.
This option is useful for devices which do not transmit packets by themselves (e.g. Multifunctional Printers).
Note
If OpenFlow Switch has access to untagged VLAN (subnet without VLAN) and AMF Member to the VLAN set as AMF Member, depending on the switch setting, the device may be able to connect to the equipment on the control plane.
Note
If a device policy has "OpenFlow Switch", "Switch Port" and "Indefinite expiration date." configured, a flow entry for the device is automatically added to the OpenFlow Switch when the switch establishes a connection to AT-SESC.
Thus a passive device can be authenticated without sending packets.

Table 10: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the security policy information.
Cancel Cancel the operation for adding or updating policy.

Update Device

This page lets you update the information of an existing device.


Table 11: Configurable fields
Item Name Description
Device ID (Mandatory) ID (Name) of the device to register.
Device ID must be unique.
Max 255 characters
Tag Secondary name of the device.
It can be used by administrators to easily distinguish, categorize or filter devices.
Max 255 characters
Note Arbitrary string (comment) for the device.
Max 255 characters.

Table 12: Displayed columns
Item Name Description
Interfaces
Interfaces List of MAC addresses (interfaces) associated with the device.
MAC Address Interface MAC address of the device.
Name Administrative name of the interface (MAC address).
Note Arbitrary string (comment) for the interface (MAC address).
Policies
Policies List of security policies which are being applied to the device.
Priority A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to OpenFlow Switches or AMF Members, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AT-SESC assigns the device to.
Location A matching criterion of the MAC address for its access location. Either an OpenFlow Switch ID and a Switch Port or a Location ID.
Schedule A Schedule ID.

Table 13: Buttons
Item Name Description
Interfaces
Add Open the Edit Interface dialog to register new interface for the device.
Each Row
Edit Open the Edit Interface dialog to edit the selected interface.
Delete Mark to delete the MAC address (interface) associated with the device. The interface to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the interface.
Policies
Add Open the Edit Policy dialog to register new security policy for the device.
Each Row
Edit Open the Edit Policy dialog to edit the selected security policy.
Delete Mark to delete the security policy attached to the device. The security policy to be deleted is indicated with the DEL mark on the left side of its record line.
Revert Clear the DEL mark on the security policy.
Page Bottom
Submit Update the device with the input information on this page and subordinate dialogs by committing the information for the existing device.
Cancel Cancel the operation for updating the device.
Note
Interfaces and security policies marked with DEL is deleted when the "Submit" button is clicked. Once you click the "Submit" button, you cannot undo the delete operations.

Edit Interface

This dialog lets you add a new MAC address (interface) to the device or update an existing MAC address (interface) associated with the device.


Table 14: Configurable fields
Item Name Description
MAC Address (Mandatory) MAC address of the interface. MAC address must be unique.
Valid formats are as follows
xx:xx:xx:xx:xx:xx, xx-xx-xx-xx-xx-xx, xxxx.xxxx.xxxx
Name Administrative name of the interface.
Max 255 characters.
Note Arbitrary string (comment) for the interface.
Max 255 characters.

Table 15: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the interface information.
Cancel Cancel the operation of adding or updating the interface information.

Edit Policy

This dialog lets you add a new security policy to the device or update an existing security policy attached to the device.


Table 16: Configurable fields
Item Name Description
Priority (Mandatory) A priority value of the security policy. It must be an integer in the range of 0 to 255.
When multiple security policies are set, if the interface registered on the device is connected to OpenFlow Switches or AMF Members, it is determined whether the security policy with the lowest priority value matches in order.
Network ID of the network which AT-SESC assigns the device to.
Maximum 100 IDs of the existing networks are shown in the dropdown list. If you enter text in the field, Network IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Network ID, VLAN ID or Note (it shows maximum 100 elements). From the dropdown list, select a Network ID.
If the registered device is connected to OpenFlow Switches or AMF Members, it is connected to the VLAN subnet configured in the network. If the network is not registered in the device (if this setting is blank or the VLAN ID is set to 0 in the network security policy setting), the OpenFlow Switch uses untagged VLAN (subnet without VLAN) and AMF Member Is connected to the VLAN set for the AMF Member. The connection to the VLAN subnet is realized by sending as a tagged VLAN with the set VLAN ID when it is sent to the upper network of the connected OpenFlow Switches and AMF Members.
You have to add the network before assigning a device to the network. Refer to Policy Settings > Add Network for the instruction on how to register a network.
Location Specify a location where the device can access the network.
Maximum 100 IDs of the existing locations are shown in the dropdown list. If you enter text in the field, location IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Location ID or Note (it shows maximum 100 elements). From the dropdown list, select a Location ID.
If you specify Location, the UnAuth Group can access the network only from OpenFlow Switches and AMF Members in the location.
If you do not specify Location, the UnAuth group can access the network from all OpenFlow Switches and AMF Members.
You have to add the location before specifying it for a device. Refer to Policy Settings > Add Location for the instructions on how to add locations.
Schedule Specify a schedule when the device can access the network.
Maximum 100 IDs of the existing schedules are shown in the dropdown list. If you enter text in the field, Schedule IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Schedule ID or Note (it shows maximum 100 elements). From the dropdown list, select a Schedule ID.
If you specify a Schedule for a device, the device can access the network only when the schedule is effective. If you do not specify a schedule, a device can always access the network.
You have to add the schedule before specifying it for a device. Refer to Policy Settings > Add Schedule for the instruction on how to register a schedule.
OpenFlow Switch Specify an OpenFlow Switches from which a device can access the network.
Maximum 100 IDs of the existing switches are shown in the dropdown list. If you enter text in the field, switch IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Switch ID, Datapath ID, Upstream Port or Note (it shows maximum 100 elements). From the dropdown list, select a Switch ID.
If an OpenFlow Switch is specified for the device, Location for the device is not used.
When OpenFlow Switch is specified but a switch port is not, the device can access the network through any port on the switch.
Switch Port Specify a switch port through which the device can access the network.
It is ignored if an OpenFlow Switch is not specified.
Indefinite expiration date. Disable timeout of the flow for the device.
This option is useful for devices which do not transmit packets by themselves (e.g. Multifunctional Printers).
Note
If OpenFlow Switch has access to untagged VLAN (subnet without VLAN) and AMF Member to the VLAN set as AMF Member, depending on the switch setting, the device may be able to connect to the equipment on the control plane.
Note
If a device policy has "OpenFlow Switch", "Switch Port" and "Indefinite expiration date." configured, a flow entry for the device is automatically added to the OpenFlow Switch when the switch establishes a connection to AT-SESC.
Thus a passive device can be authenticated without sending packets.

Table 17: Buttons
Item Name Description
Bottom of the dialog
Submit Add or update the security policy information.
Cancel Cancel the operation for adding or updating policy.


MAC Address List

This page shows a list of MAC addresses registered in AT-SESC's database.


Table 18: Target columns for search and sort operations
Item Name Search Sort Note
MAC Address × ×  
Name × ×  
Device ID × ×  
Note × ×  
Device: Tag* × × * This column is not displayed on the screen.
Device: Note* × × * This column is not displayed on the screen.

Table 19: Displayed columns
Item Name Description
MAC Address MAC address which is registered in AT-SESC's database.
Name Administrative name of the interface (MAC address).
Device ID ID of the device which is associated with the MAC address.
When clicked, the Update Device page for the device is displayed.
Note Arbitrary string (comment) for the MAC Address.

Table 20: Buttons
Item Name Description
Page Top
Active Device List Open the Active Device List page.
MAC Address List
Heading Row
Delete Selected Delete all the checked MAC addresses.
Each Row
Edit Open the Update Device page for a device associated with the MAC address.
Delete Delete the MAC address.


Active Device List

This page shows a list of the devices which are connected to the OpenFlow Switches managed by AT-SESC, and the devices which are authenticated or applied actions by AMF Application Proxy.

If you have set up Account Group, the MAC Addresses of the following devices are listed: Of the devices connected to the OpenFlow Switch and AMF Member managed by AT-SESC, the devices under OpenFlow Switch and AMF Member belonging to the Account Group to which the logged-in Account belongs.

The page also lets administrators manually run actions such as block or quarantine to selected devices.
For the devices which are applied actions by AMF Application Proxy, information retrieved from an AMF Master is listed.

Those elements are collectively referred to as security policies. Here is a list of elements of security policies: Because AMF Application Proxy Whitelist and Blacklist operate independently, Information shown on the Device > Active Device List page may be different from the status held by Edge Nodes.
When a device authenticated by AMF Application Proxy Whitelist becomes unauthenticated without a linkdown event, information on the device is deleted from Edge Nodes but it remains "Authorized" on the Device > Active Device List page.


Table 21: Target columns for search, filter and sort operations
Item Name Search Filter Sort Note
MAC Address * × * Only the strings after "mac=" and "ip=" can be matched.
Device ID *1 *2 *1 "Unregistered" cannot be matched. For devices connected or detected in the UnAuth Group, only strings after "group=" can be matched.
*2 Sorted in the order of "Unregistered", "UnAuth Group ID", "Empty" and "Device ID".
Connected Switch *1 *2 *1 For OpenFlow Switches, only IPv4 Address after "ip=", Switch Port Number after "port=", OpenFlow Port Number in parenthesis and link status of the ports can be matched. For AMF nodes, only the strings after "id=" and the Port Number in parenthesis after "port=" can be matched.
*2 OpenFlow Switches can be only sorted by the string after "ip=" while AMF nodes can be only sorted by the string after "id=". Sorting by the string after "port=" is not supported.
Connecting Network *1 *2 *1 Only VLAN ID after "vlan=" and Network ID after "id=" can be matched. "Untagged" and "No Connection" cannot be matched.
*2 Sorted in the order of "No Connection", "Empty", "vlan=Untagged" and "vlan=1-4094". Sorting by Network ID is not supported.
Status × × * * * Sorted in the order of "Authorized", "Blocked", "Link-Down", "Quarantined", "Authentication Failed", "Detected", "IP-Filter" and "Log-Only".


Table 22: Displayed columns
Item Name Description
MAC Address MAC address managed by AT-SESC.
When the device is blocked by an IP address, the IP address is also displayed.
When you click the MAC or IP address, the Active Device Detail page for the device is displayed.
Device ID ○ OpenFlow
ID of the device which is associated with the MAC address.
  • If there is a device associated with the MAC address, the device's Device ID is displayed regardless of the device's security policy.
    When clicking the Device ID, the Update Device page is displayed.
  • If there is no device associated with the MAC address and the connection matches a security policy of any UnAuth Group, a group ID is displayed in "group=Group ID" format.
    When clicking a Group ID, the Group > Update UnAuth Group page is displayed.
  • If there is no device associated with the MAC address and the connection does not match security policies of the UnAuth Group, the Device ID is shown as "Unregistered".
  • When there is no device with the MAC address and Switch ID is not registered, the "Register" button is displayed. When the Switch ID is registered, the "Register" button and the "Static Register" button is displayed.

○ AMF Application Proxy
ID of the device which is associated with the MAC address.
  • If there is a device associated with the MAC address, the device's Device ID is displayed regardless of the device's security policy.
    When clicking the Device ID, the Update Device page is displayed.
  • If there is no device associated with the MAC address and the connection matches a security policy of any UnAuth Group, a group ID is displayed in "group=Group ID" format.
    When clicking a Group ID, the Group > Update UnAuth Group page is displayed.
  • If there is no device associated with the MAC address and the connection does not match security policies of the UnAuth Group, the Device ID is shown as "Unregistered".
  • If there is no device with the MAC address, the "Register" button is displayed.
Connected Switch ○ OpenFlow
Displays the following items of the OpenFlow Switch to which the device is connected: IPv4 address, OpenFlow Switch port name, OpenFlow port number. When Account Group is set, only OpenFlow Switches belonging to the Account Group to which the logged-in Account belongs are displayed.
IPv4 Address is shown in the form of "ip=IPv4 address". Clicking an address after "ip=", the Switches > OpenFlow Switch Detail page is displayed.
If the switch is registered in AT-SESC's database, its Switch ID is also displayed in the form of "id=Switch ID". When clicking a string after "id=", the Switches > Update OpenFlow Switch page is displayed.
The OpenFlow Port Number and Port Name of the connected OpenFlow Switch are displayed in the format of "port=OpenFlow Port Number (Port Name)". A link status of a port is either up or down for AlliedWare Plus switches. A link status is always up for AT-TQ series wireless LAN access points.

○ AMF Application Proxy
Edge node to which authentication and AMF Action are applied by AMF Application Proxy Whitelist, and the Port Name of the edge node Switch. When Account Group is set, only AMF Members belonging to the Account Group to which the logged-in Account belongs are displayed.
Edge Node is displayed in the format "id=Edge Node Name".
The IPv4 Address of the Edge Node Switch is displayed in the format of "ip=IPv4 Address". Also, the port name of the edge node Switch is displayed in the format of "port=(Port Name)".
If the AMF Action displayed in the status is "IP filter", the port name is not displayed.
Connecting Network ○ OpenFlow
VLAN ID and Network ID of the network to which the MAC address is connected.
VLAN ID and Network ID are shown in the form of "vlan=VLAN ID" and "id=Network ID" respectively.
When clicking a string after "id=", the Policy Settings > Update Network page is displayed.
Those elements are collectively referred to as security policies. Here is a list of elements of security policies: A blocked device is shown with "No Connection".

○ AMF Application Proxy
VLAN ID and Network ID of the network to which the MAC address is connected.
VLAN ID and Network ID are shown in the form of "vlan=VLAN ID" and "id=Network ID" respectively.
When clicking a string after "id=", the Policy Settings > Update Network page is displayed.
No Connecting Network is displayed for devices which are applied actions.
Status ○ OpenFlow
Current status of the MAC address.
  • Authorized: a device matching a registered security policy for the device or the UnAuth Group, or a device permitted by an external system or an administrator operation. When the device is allowed by an external system or an administrator's operation, ID of the action which is performing the permit operation is shown in the form of "action=Action ID" with the "Delete" button beside it.
  • Blocked: a device which is separated from the network by an external system or an administrator's operation. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page. It is possible to permit a blocked MAC address to access a quarantine network by an instruction from an external system or an administrator.
  • Quarantined: a device which is moved to a quarantine network by the request of an external system or an administrator. ID of the action which is performing the quarantine operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network other than the quarantine network unless the action is deleted by the "Delete" button. It is possible to deny access to any network from a quarantined MAC address by an instruction from an external system or an administrator.
  • Authentication Failed: a device which is not authenticated because it is not associated with a registered MAC address nor does not match any security policy.
  • Detected: a device detected by the UnAuth Group with the detect-only option enabled.
  • Log-Only: a device for which logs are generated without being applied any action. ID of the action which is performing the notification operation is shown in the form of "action=Action ID" with the "Delete" button beside it.
Clicking a Status opens the Active Device Detail page for the device.
For "Authorized", "Blocked", "Quarantined" or "Log-Only" actions, you can go to the Policy Settings > Action Detail page for the action by clicking its Action ID (a string after "action=").
Those elements are collectively referred to as security policies. Here is a list of elements of security policies:
○ AMF Application Proxy
Current status of the MAC address.
  • Authorized: Authenticated: a device matching a registered security policy for the device or the UnAuth Group.
  • Blocked: a device which is blocked at layer 2 (MAC) level by AMF Application Proxy. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page.
  • Link-Down: a device which is blocked by a linkdown event of the connected switch port. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page.
  • IP-Filter: a device which is blocked at layer 3 (IP) level by AMF Application Proxy. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page.
  • Quarantined: a device which is moved to a quarantine network by AMF Application Proxy. ID of the action which is performing the quarantine operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network other than the quarantine network unless the action is deleted by the "Delete" button.
  • Authentication Failed: a device which is not authenticated because it is not associated with a registered MAC address nor does not match any security policy.
  • Detected: a device detected by the UnAuth Group with the detect-only option enabled.
  • Log-Only: a device for which logs are generated without being applied any action. ID of the action which is performing the notification operation is shown in the form of "action=Action ID" with the "Delete" button beside it.
Clicking a Status opens the Active Device Detail page for the device.
For "Blocked", "Link-Down", "IP-Filter", "Quarantined" and "Log-Only" action, ID of the action which is performing the action is shown in the form of "action=Action ID" with the "Delete" button beside it. You can go to the Policy Settings > Action Detail page by clicking a string after "action=".
Format and meaning of a port name in the Connected Port column differs depending on the model of the AMF node or OpenFlow Switch.

Note
To confirm a link status (up or down) of the "Connected Switch", both Proxy Node and Edge Nodes must have AlliedWare Plus firmware version 5.4.8-1.x or later installed.
The link status is always "unknown" when the firmware version is 5.4.9-0.x or earlier.
Note
An action ID (a string after "action=" in "Status") and the "Delete" button are only shown if the Proxy Node and Edge Nodes run firmware version 5.4.9-1.x or later.

Table 23: Connected Port Name
Port Name Description
AlliedWare Plus Devices
portX.Y.Z X - always "1"
Y - Expansion bay number. "0" for a base (non-expansion) port.
Z - Port number printed on the product. It is different from OpenFlow port number.
AT-TQ series wireless access point
wlanX radio interface.
athX radio interface.
On AlliedWare Plus switches, OpenFlow Port Number depends on the switch's configuration. It can be confirmed on the Switches > OpenFlow Switch Detail page's OpenFlow Port List.

Table 24: Buttons (* means "for OpenFlow")
Item Name Description
Page Top
Search Devices * Open the Search Devices dialog.
Once the search began, the label of the "Search Device" button changes to "Cancel Search". Progress of the search operation is displayed in the "Search Progress" text box under the button.
Cancel Search * Cancel the search operation.
It's only available when the search is in progress.
Action List Open the Policy Settings > Action List page.
Export to CSV Start downloading of a list of devices in CSV format.
Refresh Refresh the Active Device List page.
Active Device List
Heading Row
Disconnect Selected ○ OpenFlow
Temporarily disconnect all the checked MAC addresses from the network.
Because this operation is temporary, disconnected devices can reconnect to the network as they have appropriate permissions.

○ AMF Application Proxy
This operation is not for a device which is applied an AMF action. However, the operation is applicable if the same MAC address is also listed for OpenFlow.

Those elements are collectively referred to as security policies. Here is a list of elements of security policies: ○ AMF Application Proxy Whitelist
Temporarily disconnect all the checked MAC addresses from the network.
Because this operation is temporary, disconnected devices can reconnect to the network as they have appropriate permissions.
Each Row
Device ID Submit (Only displayed when the MAC address is unregistered)
Open the Add Device dialog to add the MAC address as a new device or an additional interface of an existing device.
You can select whether to add the address as a new device or to associate it with an existing device on the Add Device dialog.
Static Register (Only displayed when the MAC address is unregistered and the OpenFlow Switch it is connected to is registered)
Open the Device > Add Device page to add the MAC address as a new device. The MAC Address are added with the OpenFlow Switch's IPv4 address and its port as its location.
Status Delete (Only displayed if an action is running on the MAC address)
Delete the action.
End of Each Row Disconnect ○ OpenFlow
Temporarily disconnect the MAC addresses from the network.
Because this operation is temporary, disconnected devices can reconnect to the network as they have appropriate permissions.

○ AMF Application Proxy
This operation is not for a device which is applied an AMF action. However, the operation is applicable if the same MAC address is also listed for OpenFlow.

Those elements are collectively referred to as security policies. Here is a list of elements of security policies: ○ AMF Application Proxy Whitelist
Temporarily disconnect the MAC addresses from the network.
Because this operation is temporary, disconnected devices can reconnect to the network as they have appropriate permissions.
Block * Block the traffic from the MAC address.
The MAC address cannot access the network unless the action is deleted.
The "Block" button is disabled when the MAC address is being blocked.
Quarantine * Move the MAC address to the quarantine network.
The "Quarantine" button is disabled when the MAC address is being quarantined.
Note
Refer to CSV File in Appendix for CSV Files.

OpenFlow's Quarantine VLAN ID can be configured on the System Settings > OpenFlow Settings page.

Add Device

By clicking the "Register" button for an unregistered MAC address on the Device > Active Device List page, you can add the MAC address as a new device or associate the MAC address with an existing device.


Table 25: Configurable fields
Item Name Description
Register this MAC Address as a new device. Add the MAC address specified on the Active Device List page as an interface of a new device.
Add this MAC Address to an existing device. Add the MAC address specified on the Active Device List page as an additional interface of an existing device.
Device When you select "Add this MAC Address to an existing device.", specify a Device ID to which the MAC address is associated.
Maximum 100 device IDs are shown in the dropdown list. If you enter text in the field, device IDs in the dropdown list are dynamically filtered to the ones which contain the input text in Device ID, Tag or Note (it shows maximum 100 elements). From the dropdown list, select a Device ID for the device.

Table 26: Buttons
Item Name Description
Bottom of the dialog
Submit Add a new MAC address as a new device or a new interface of an existing device.
The Device > Add Device page is displayed if you selected "Add the MAC address as an interface of a new device.", while the Device > Update Device page is displayed if you selected "Add this MAC Address to an existing device.".
On the Add Device or the Update Device page, the MAC address is automatically added to the "Interfaces" for the device. Enter additional data such as Device ID, Tag, Note, security policies and other interfaces as required, then click "Submit".
Cancel Cancel the operation for adding the MAC address.

Search Devices

When you click the "Search Devices" button on the Device > Active Device List page, the following dialog appears and lets you specify a range of IP addresses to search.


Table 27: Input Fields
Item Name Description
Search Range Enter an IPv4 address or an IPv4 address range to search for devices.
An IPv4 address range can be specified in one of the following formats.
xxx.xxx.xxx.xxx-xxx.xxx.xxx.xxx (The first and the last address in the range)
xxx.xxx.xxx.xxx/xx (A base IPv4 address and a mask length)
xxx.xxx.xxx.xxx or xxx.xxx.xxx.xxx/32 (A single IP address)
Probe ARP or ARP Select a search method from "Probe ARP" and "ARP". Also specify a Sender IP when using ARP.
Sender IP Specify this only when you select "ARP".
OpenFlow Switches / AMF Members ○ OpenFlow
Specify OpenFlow Switches to send out search packets by selecting Switch IDs from the list on the Switches > OpenFlow Switch List page. Multiple OpenFlow Switches can be specified by separating each ID with a semicolon (;). When no Switch ID is specified, all connected OpenFlow Switches send out search packets.

○ AMF Application Proxy
Specify AMF Member names to send out search packets. Multiple AMF Members can be specified by separating each name with a semicolon (;). When no AMF Member is specified, all connected AMF Members send out search packets.
Note
Make sure to specify a Sender IP which is not used in the target address range.


Table 28: Buttons
Item Name Description
Bottom of the dialog
Search Start search on the input IPv4 address(es).
Clicking the "Search" button brings you back to the Active Device List page. Once the search began, the label of the "Search Device" button changes to "Cancel Search". Progress of the search operation is displayed in the "Search Progress" text box under the button.
Cancel Cancel the search operation.

Active Device Detail

When clicking a MAC address or "Status" on the Device > Active Device List page, detailed information of the selected device is displayed.


Table 29: Displayed columns
Item Name Description
MAC Address MAC address which is registered in AT-SESC's database.
IPv4 Address IPv4 address of the device. It is displayed only if it is known.
Device ID ID of the device which is associated with the MAC address.
  • If there is a device associated with the MAC address, the device's Device ID is displayed regardless of the device's security policy.
    When clicking the Device ID, the Update Device page is displayed.
  • If there is no device associated with the MAC address and the connection matches a security policy of any UnAuth Group, a group ID is displayed in "group=Group ID" format.
    When clicking a Group ID, the Group > Update UnAuth Group page is displayed.
  • If the MAC address is not registered and does not match any security policies for the UnAuth Group, this column shows nothing.
Status Current status of the MAC address.

○ OpenFlow
  • >Authorized: a device whose MAC address matched a security policy for a registered device or the UnAuth Group.
  • Blocked: a device whose traffic is blocked by an external system or an administrator's operation. ID of the action which is performing the block operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network unless the action is deleted by the "Delete" button on this page or the Policy Settings > Action List page. It is possible to permit a blocked MAC address to access a quarantine network by an instruction from an external system or an administrator.
  • Quarantined: a device which is moved to a quarantine network by the request of an external system or an administrator. ID of the action which is performing the quarantine operation is shown in the form of "action=Action ID" with the "Delete" button beside it. The device cannot access the network other than the quarantine network unless the action is deleted by the "Delete" button. It is possible to deny access to any network from a quarantined MAC address by an instruction from an external system or an administrator.
  • Authentication Failed: a device which is not authenticated because it is not associated with a registered MAC address nor does not match any security policy.
  • Detected: a device detected by the UnAuth Group with the detect-only option enabled.
  • Log-Only: a device for which logs are generated without being applied any action. ID of the action which is performing the notification operation is shown in the form of "action=Action ID" with the "Delete" button beside it.
○ AMF Application Proxy
  • >Authorized: a device whose MAC address matched a security policy for a registered device or the UnAuth Group.
  • Blocked: a device which is blocked at layer 2 (MAC) level by AMF Application Proxy.
  • Link-Down: a device which is blocked by a linkdown event of the connected switch port.
  • IP-Filter: a device which is blocked at layer 3 (IP) level by AMF Application Proxy.
  • Quarantined: a device which is moved to a quarantine network by AMF Application Proxy.
  • Authentication Failed: a device which is not authenticated because it is not associated with a registered MAC address nor does not match any security policy.
  • Detected: a device detected by the UnAuth Group with the detect-only option enabled.
  • Log-Only: a device for which logs are generated without being applied any action.
Updated Date / Time The last time the status of the device changed.
Connecting Network VLAN ID and Network ID of the network to which the MAC address is connected.
VLAN ID and Network ID are shown in the form of "vlan=VLAN ID" and "id=Network ID" respectively. When clicking a string after "id=", the Policy Settings > Update Network page is displayed.
Action Originator Shows the name of a system which requests the device authentication or running action on the device.
Action Reason Shows a reason which is provided by the Action Originator.
If the action is triggered by a notification from an interacting application, contents of the notification syslog message or SNMP trap message is shown.
Note
To view "Action Originator" and "Action Reason" on AMF Application Proxy, Proxy Node and Edge Nodes must have AlliedWare Plus firmware version 5.4.9-1.x or later installed.

Table 30: Buttons
Item Name Description
Page Top
Back Go back to the Active Device List page.
Refresh Refresh the Active Device Detail page.


14 Jun 2021 09:30