Reference Guide

Table Of Contents
Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide ipv6 firewall | 296
Syntax
Usage Guidelines
Parameter Description Range Default
attack-rate Sets rates which, if exceeded, can indicate a denial of service attack.
ping Number of ICMP pings per second, which if exceeded, can indicate a
denial of service attack. Recommended value is 4
1-255
session Number of TCP or UDP connection requests per second, which if
exceeded, can indicate a denial of service attack. Recommended
value is 32.
1-255
tcp-syn Number of TCP SYN messages per second, which if exceeded, can
indicate a denial of service attack. Recommended value is 32.
1-255
deny-inter-user-
bridging
Prevents the forwarding of Layer-2 traffic between wired or wireless
users. You can configure user role policies that prevent Layer-3 traffic
between users or networks but this does not block Layer-2 traffic. This
option can be used to prevent Appletalk or IPX traffic from being
forwarded.
disabled
drop-ip-frag
ments
When enabled, all IP fragments are dropped. You should not enable
this option unless instructed to do so by an Dell representative.
disabled
enable This command enables firewall functions for IPv6 packet forwarding. If
IPv6 firewall is not enabled the IPv6 packets are forwarded without
session management.
disabled
enable-per-pac
ket-logging
Enables logging of every packet if logging is enabled for the
corresponding session rule. Normally, one event is logged per session.
If you enable this option, each packet in the session is logged. You
should not enable this option unless instructed to do so by an Dell
representative, as doing so may create unnecessary overhead on the
controller.
disabled
enforce-tcp-
handshake
Prevents data from passing between two clients until the three-way
TCP handshake has been performed. This option should be disabled
when you have mobile clients on the network as enabling this option
will cause mobility to fail. You can enable this option if there are no
mobile clients on the network.
disabled
prohibit-ip-
spoofing
Detects IP spoofing (where an intruder sends messages using the IP
address of a trusted client). When this option is enabled, IP and MAC
addresses are checked; possible IP spoofing attacks are logged and
an SNMP trap is sent.
disabled
prohibit-rst-re
play
Closes a TCP connection in both directions if a TCP RST is received
from either direction. You should not enable this option unless
instructed to do so by an Dell representative.
disabled
session-idle-
timeout
Time, in seconds, that a non-TCP session can be idle before it is
removed from the session table. You should not modify this option
unless instructed to do so by an Dell representative.
16-259 15 seconds
session-mirror-
destination
Destination to which mirrored session packets are sent. The
destination can be either an IPv4 address or a controller port. You
configure IPv6 flows to be mirrored with the mirror option of the ipv6
access-list session command. Use this option only for troubleshooting
or debugging.
——
ip-address
<
ipaddr>
Send mirrored session packets to the specified IP address
port <slot>/
<port>
Send mirrored session packets to the specified controller port.