143| IPv6 Suppor t DellPowerConnect W- Series ArubaOS 6.2 | User Guide

Authentication

Method Description

Attack direction. You should not enable this option unlessi nstructedto do so by a Dell representative.
Default:Disabled
SessionMi rror
Destination
Destination(IPv4 address or controller port) tow hich mirrored session packetsare sent. You
canconfigure IPv6 flows to be mirrored wi ththe session ACL “mirror” option. This option is
usedonly for troubleshooting or debugging.
Default:N/A
SessionIdle Ti meout Setthe time, i n seconds, thata non-TCP session can be idl e beforei ti srem ovedfrom the
sessiontable. Speci fya value in the range 16–259 seconds. You should not setthis option unless
instructedto do so by a Dell representative.
Default:30 seconds
Per-packetLogging Enablesl ogging of everypacket if logging is enabled for the corresponding session rule.
Normally, one event is logged per session. Ifyou enable this option, each packet in the session
isl ogged. You should not enable this option unlessi nstructedto do so by a Dell representative,
asdoing so may create unnecessary overhead on the controller.
Default:Disabled (per-session logging is performed)
Ipv6Enable
The followingexamples configure attack rates and the sessio n timeout for IPv6 traffic.
To configuret hefirewall function via the WebUI:
1. N avigate to the Configuration > Advanced Services > Stateful Firewall > Global Setting page.
2. U nderthe IPv6 column,enter the following:
lFor Monitor Ping Attack, enter 15
lFor Monitor IP Session Att ack,enter 25
lFor Session Idle Timeout, enter 60
3. Click A pply.
To configurefirewall functions using the command line interface,i ssue thefollowing commands in config mode:
ipv6 firewall attack-rate ping 15
ipv6 firewall attack-rate session 25
ipv6 firewall session-idle-timeout 60
Understand ing Firewall Policie s
A userrole, which determines a client’snetwork privileges, is defined by oneor more firewall policies. A firewall
policy consists of one or more rules that define the source, destination, and service t ype for specific traffic and
whetheryo uwant t heco ntrollerto permit or deny traffic that matches the rule.
You canco nfigurefirewall policies for IPv4 traffic orfor IPv6 traffic and apply IPv4 and IPv6 firewall policies to the
same userrole. For example, if you have employees that are using both IPv4 and IPv6 clients you can configure both
IPv4 and IPv6 firewall policies and apply them both to the “employee” user role.
The procedureto configurean I Pv6 firewall policy rule is similar to configuring a firewall policy rule for IPv4 traffic,
but with some differences. Table1 8 describes requiredand opti onalparameters for an IP v6 firewall policy rule.