Reference Guide

Table Of Contents
Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide show firewall | 791
show firewall
show firewall
Description
Display a list of global firewall policies.
Syntax
No parameters
Example
This example below shows all firewall policies currently configured on the controller.
The output of this command includes the following information:
Parameter Description
Enforce TCP handshake
before allowing data
If enabled, this feature prevents data from passing between two clients until the three-way
TCP handshake has been performed. This option should be disabled when you have mobile
clients on the network as enabling this option will cause mobility to fail. You can enable this
option if there are no mobile clients on the network.
Prohibit RST replay
attack
If enabled, this setting closes a TCP connection in both directions if a TCP RST is received
from either direction.
(host) #show firewall
Global firewall policies
------------------------
Policy Action Rate Slot/Port
------ ------ ---- ---------
Enforce TCP handshake before allowing data Enabled
Prohibit RST replay attack Enabled
Deny all IP fragments Enabled
Prohibit IP Spoofing Enabled
Monitor ping attack Enabled 20/sec
Monitor TCP SYN attack Disabled
Monitor IP sessions attack Disabled
Deny inter user bridging Disabled
Log all received ICMP errors Disabled
Per-packet logging Disabled
Session mirror destination Disabled
Stateful SIP Processing Enabled
Allow tri-session with DNAT Enabled
Disable FTP server No
GRE call id processing Disabled
Session Idle Timeout Disabled
Broadcast-filter ARP Disabled
WMM content enforcement Disabled
Session VOIP Timeout Disabled
Stateful H.323 Processing Enabled
Stateful SCCP Processing Enabled
Only allow local subnets in user table Enabled
Monitor/police CP attacks Enabled 255/sec
Rate limit CP untrusted ucast traffic Enabled 10 Mbps
Rate limit CP untrusted mcast traffic Enabled 2 Mbps
Rate limit CP trusted ucast traffic Enabled 80 Mbps
Rate limit CP trusted mcast traffic Enabled 2 Mbps
Rate limit CP route traffic Enabled 1 Mbps
Rate limit CP session mirror traffic Enabled 1 Mbps
Rate limit CP auth process traffic Enabled 1 Mbps
Deny inter user traffic Disabled
Session mirror IPSEC Disabled