Administrator Guide

Table Of Contents
Parameter Description
Monitor Ping Attack (per
30 seconds)
Number of ICMP pings per 30 second, which if exceeded, can indicate a denial of
service attack. Valid range is 1-16384 pings per 30 seconds.
Recommended value is 120.
Default: No default
Monitor TCP SYN Attack
rate (per 30 seconds)
Number of TCP SYN messages per 30 second, which if exceeded, can indicate a
denial of service attack. Valid range is 1-16384 pings per 30 seconds.
Recommended value is 960.
Default: No default
Monitor IP Session
Attack (per 30 seconds)
Number of TCP or UDP connection requests per 30 second, which if exceeded,
can indicate a denial of service attack. Valid range is 1-16384 requests per 30
seconds.
Recommended value is 960.
Default: No default
Deny Inter User Bridging Prevents the forwarding of Layer-2 traffic between wired or wireless users. You
can configure user role policies that prevent Layer-3 traffic between users or
networks but this does not block Layer-2 traffic. This option can be used to
prevent traffic, such as Appletalk or IPX, from being forwarded.
Default: Disabled
Deny All IP Fragments Drops all IP fragments.
NOTE: Do not enable this option unless instructed to do so by a Dell
representative.
Default: Disabled
Enforce TCP Handshake
Before Allowing Data
Prevents data from passing between two clients until the three-way TCP
handshake has been performed. This option should be disabled when you have
mobile clients on the network, as enabling this option will cause mobility to fail.
You can enable this option if there are no mobile clients on the network.
Default: Disabled
Prohibit IP Spoofing Enables detection of IP spoofing (where an intruder sends messages using the IP
address of a trusted client). When you enable this option, IP and MAC addresses
are checked for each ARP request/response. Traffic from a second MAC address
using a specific IP address is denied, and the entry is not added to the user table.
Possible IP spoofing attacks are logged and an SNMP trap is sent.
Default: Disabled
Prohibit RST Replay
Attack
When enabled, closes a TCP connection in both directions if a TCP RST is received
from either direction. You should not enable this option unless instructed to do so
by a Dell representative.
Default: Disabled
Table 39: IPv6 Firewall Parameters
Dell Networking W-Series ArubaOS 6.4.x | User Guide IPv6 Support | 218