You configure8 02.1x authentication for IPv6 clients i n the same way as for IPv4 c lient configuration.For more
information about configuring8 02.1x authentication on the controller, see 802.1X Authenticatio n on page 192.
NOTE:Thi s release does not support authentication of management users on IPv6 clients.
Working with Firewall Features
If you installed a Policy Enforcement Firewall Next Generation (PEFNG) license in the controller, you can configure
firewallfunctions for IP v6 client traffic. While these firewall functions are identical to firewall functions for IPv4
clients, you need to explicitly configure them for IPv6 traffic. For more information about firewall policies, see
“GlobalFi rewallParameters” on page317.
NOTE:Voi ce-related and NAT firewall functions are not supportedfor IPv6 traffic.

Authentication

Method Description

MonitorP ing Attack Number ofICMP pi ngsper second,which if exceeded, can indicate a denial of service attack.
Valid range is 1–255 pings per second. Recommended valueis 4.
Default:No default
MonitorTC P SYN Attack
rate
Number ofTCP SYNmessages per second, which if exceeded, can indicate a denial of service
attack.Vali d range is 1–255 messagesper second.Recommended value is 32.
Default:No default
MonitorIP Session Attack Number ofTCP orUDP connection requestsper second, whi ch if exceeded, can indicate a
denial of service attack. Valid range is 1–255 requests per second. Recommended value is32.
Default:No default
DenyInter User Bridging Preventsthe forwarding of Layer-2 traffic between wired or wireless users. You can configure
userrole policiesthat preventLayer-3 traffic between users or networks but this does not block
Layer-2traffic. This option can be used to prevent traffic,such as Appletalk or IPX, from being
forwarded.
Default:Disabled
DenyAll IP Fragm ents Dropsall IPfragments.
NOTE:Do not enable this option unless instructed to do so by a Dellrepresentative.
Default:Disabled
EnforceTCP Handshake
BeforeAllowi ng Data
Preventsdata from passing between two cl ients until the three-way TCP handshake has been
performed. This option should be disabled when you have mobile clients on the network as
enabling this option will cause mobility to fail. You can enable this option if there are no mobile
clientson the network.
Default:Disabled
Prohibit IP Spoofing Enables detectionof IP spoofing (where an intruder sends messages using the IP address ofa
trustedclient). When this option is enabled, IP and MAC addresses are checked for each ARP
request/response.Traffic from a second MAC address using a specific IP addressis denied,
andthe entry is not added to the user table. Possible IP spoofing attacksare logged and an
SNMP trap is sent.
Default:Disabled
Prohibit RST Replay When enabled, closes a TCP connection in both directions if a TCP R ST is received from either

Table39 :

IPv6 FirewallParameters

DellPowerConnect W- Series ArubaOS 6.2 | UserGuide IPv6Support |142