Reference Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 CLI | Reference Guide firewall | 237
Syntax
Parameter Description Range Default
allow-tri-session Allows three-way session when performing destination NAT.
This option should be enabled when the controller is not the
default gateway for wireless clients and the default gateway
is behind the controller. This option is typically used for
captive portal configuration.
disabled
amsdu Aggregated Medium Access Control Service Data Units
(AMSDU) packets are dropped if this option is enabled.
disabled
attack-rate Sets rates which, if exceeded, can indicate a denial of service
attack.
——
broadcast-filter-arp If enabled, all broadcast ARP requests are converted to
unicast and sent directly to the client. You can check the
status of this option using the show ap active and the show
datapath tunnel command. If enabled, the output will display
the letter a in the flags column.
disabled
bwcontracts-subnet-
broadcast
Applies bw contracts to local subnet broadcast traffic.
clear-sessions-role-
update
This clears the datapath sessions when roles are updated.
cp See “firewall cp” on page 240
cp-bandwidth-contract See “firewall cp-bandwidth-contract” on page 242
deny-inter-user-bridging Prevents the forwarding of Layer2 traffic between wired or
wireless users. You can configure user role policies that
prevent Layer3 traffic between users or networks but this
does not block Layer2 traffic. This option can be used to
prevent traffic, such as Appletalk or IPX from being
forwarded. If enabled, traffic (all non-IP traffic) to untrusted
port or tunnel is also blocked.
disabled
deny-inter-user-traffic Denies downstream traffic between users in a wireless
network (untrusted users) by disallowing layer2 and layer3
traffic. This parameter does not depend on the deny-inter-
user-bridging parameter being enabled or disabled.
disabled
disable-ftp-server Disables the FTP server on the controller. Enabling this option
prevents FTP transfers.
Enabling this option could cause APs to not boot up. You
should not enable this option unless instructed to do so by an
Dell representative.
disabled
disable-stateful-h323-
processing
Disables stateful H.323 processing. disabled
disable-stateful-sccp-
processing
Disables SCCP processing. disabled
disable-stateful-sip-
processing
Disables monitoring of exchanges between a voice over IP or
voice over WLAN device and a SIP server. This option should
be enabled only when thee is no VoIP or VoWLAN traffic on
the network.
disabled
disable-stateful-ua-
processing
Disables stateful UA processing. disabled
disable-stateful-vocera-
processing
Disables stateful VOCERA processing. disabled