ipv6 firewall
ipv6 firewall
attack-rate {ping <number>|session <number>|tcp-syn <number>}
deny-inter-user-bridging |
drop-ip-fragments |
enable-per-packet-logging |
enforce-tcp-handshake |
prohibit-ip-spoofing |
prohibit-rst-replay |
session-idle-timeout <seconds> |
session-mirror-destination {ip-address <ipaddr>}|{port <slot/<port>}
Description
This command configures firewall options on the controller for IPv6 traffic.
Syntax
Parameter
Description
Range
Default
attack-rate
Sets rates which, if exceeded, can indicate a denial of service
attack.
ping
Number of ICMP pings per second, which if exceeded, can
indicate a denial of service attack. Recommended value is 4
1-255
—
session
Number of TCP or UDP connection requests per second, which
if exceeded, can indicate a denial of service attack.
Recommended value is 32.
1-255
—
tcp-syn
Number of TCP SYN messages per second, which if exceeded,
can indicate a denial of service attack. Recommended value is
32.
1-255
—
deny-inter-user-
bridging
Prevents the forwarding of Layer-2 traffic between wired or
wireless users. You can configure user role policies that
prevent Layer-3 traffic between users or networks but this does
not block Layer-2 traffic. This option can be used to prevent
Appletalk or IPX traffic from being forwarded.
—
disabled
drop-ip-frag
ments
When enabled, all IP fragments are dropped. You should not
enable this option unless instructed to do so by an Dell
representative.
—
disabled
enable-per-pac
ket-logging
Enables logging of every packet if logging is enabled for the
corresponding session rule. Normally, one event is logged per
session. If you enable this option, each packet in the session is
logged. You should not enable this option unless instructed to
do so by an Dell representative, as doing so may create
unnecessary overhead on the controller.
—
disabled
enforce-tcp-
handshake
Prevents data from passing between two clients until the three-
way TCP handshake has been performed. This option should
be disabled when you have mobile clients on the network as
enabling this option will cause mobility to fail. You can enable
this option if there are no mobile clients on the network.
—
disabled
Dell PowerConnect W-Series ArubaOS 6.2 |
Reference Guide
ipv6 firewall | 343
Summary of Contents for PowerConnect W-7200 Series
Page 1: ...Dell PowerConnect W Series ArubaOS 6 2 Command Line Interface Reference Guide ...
Page 38: ...38 aaa authentication server windows DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 319: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide interface loopback 319 ...
Page 346: ...346 ipv6 mld DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 387: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide ip radius 387 ...
Page 995: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide show firewall 995 ...
Page 1529: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide wms client 1529 ...
Page 1536: ...0510956 01 March 2013 1536 ...