Users Guide

Table Of Contents
Creating an ACL White List
The ACL White List consists of rules that explicitly permit or deny session traffic from being forwarded to or
blocked from the controller. The white list protects the controller during traffic session processing by
prohibiting traffic from being automatically forwarded to the controller if it was not specifically denied in a
blacklist. The maximum number of entries allowed in the ACL White List is 64. To create an ACL white list, you
must first define a white list bandwidth contract, and then assign it to an ACL.
Creating a Bandwidth Contract in the WebUI
1. Navigate to the Configuration > Advanced Services > Stateful Firewall > White List BW Contracts
page.
2. Click Add to create a new contract.
3. In the White list contract name field, enter the name of a bandwidth contract.
4. The Bandwidth Rate field allows you to define a bandwidth rate in either kbps or Mbps. Enter a rate value
the Bandwidth rate field, then click the drop-down list and select either kbps or Mbps.
5. Click Done.
Configuring the ACL White List in the WebUI
1. Navigate to the Configuration > Stateful Firewall> ACL White Listpage.
2. To add an entry, click the Addbutton at the bottom of the page. The Add New Protocolsection displays.
3. Click the Action drop-down list and select Permit or Deny. Permit allows session traffic to be forwarded
to the controller while Deny blocks session traffic.
4. Click the IP Version drop-down list and select theIPv4 or IPv6 filter. You need to select one of three
following choices from the Source drop-down list:
n For a specific IPv4 or IPv6 filter, select IP/Mask. Enter the IP address and mask of the IPv4 or IPv6 filter
in the corresponding fields.
n For a IPv4 or IPv6 host, select Any and enter the source address.
5. In the IP Protocol Number or IP Protocol field, enter the number for a protocol or select the protocol
from the drop-down list used by session traffic.
6. In the Starting Ports field, enter a starting port. This is the first port, in the port range, on which permitted
or denied session traffic is running. Port range: 1–65535.
7. In the End Ports field, enter an ending port. This is the last port, in the port range, on which permitted or
denied session traffic is running. Port range: 1–65535.
8. (Optional) Click the White list Bandwidth Contract drop-down list and specify the name of a bandwidth
contract to apply to the session traffic. For further information on creating Bandwidth Contracts, see User
Roles on page 445
9. Click Done. The ACL displays on the white list section.
10.To delete an entry, click Delete next to the entry you want to delete.
11.Click Apply to save changes.
Creating a Bandwidth Contract in the CLI
(host)(config) #cp-bandwidth-contract
Configuring the ACL White List in the CLI
Use the following CLI command to create ACL White Lists.
(host) (config)firewall cp
Dell Networking W-Series ArubaOS 6.4.x | User Guide Roles and Policies | 444