297| Roles and Policies DellPowerConnect W- Series ArubaOS 6.2 | User Guide
NOTE:You can appl yIPv4 and IPv6 firewall poli cies tothe same user role. S ee IPv6S upporton page 128 for
information aboutconfiguri ng IPv6firewal l policies.
Working W ith Access Con trol Lists(AC Ls)
Access control lists (ACLs) are a common way of restricti ngc ertain types of traffic on a physical port. ArubaOS
provides the followingt ypes of ACLs:
lStandardACLs permit or deny traffic based on the source IP address of the packet. Standard ACLS can be either
namedor numbered, with valid numbers in the rangeof 1-99 and 13 00-1399. Standard ACLs use a bitwise mask
to specify the portion of the source IP address to be matched.
lExtended ACLs permit or deny traffic based on source or destination I P address, source or destination port
number,or IP protocol. Extended ACLs can be named or numbered, with valid numbers in the range1 00-199
and2000-2699.
lMAC ACLs are usedt o filtert rafficon a specific source MAC address or range of MAC addresses.Optionally,
you can mirror packets to a datapath or remote destinatio n for troubleshootingand debugging purposes. MAC
ACLs can be either named or numbered,wi th valid numbersin t he rangeof 7 00-799 and 1200-129 9.
lEthertype ACLs are used to filter based on the Ethertype fieldin the frame header. Optionally,y ouc anmirror
packets to a datapath or remote destination for troubleshooting and debugging purposes.E thertype ACLs can be
either namedo r numbered,with valid numbers in the range of 200-299 .TheseA CLs can be used to permit IP
while blockingo thernon-IP protocols, such as I PX or AppleTalk.
lService ACLs provide ageneric way to restrict how protoco lsand services from specific hosts and subnets to the
controllerare used. Rules with this ACL are applied to all traffic on the controller regardlesso f the ingress port or
VLAN.
ArubaOSprovides both standard and extended ACLs for compatibility wi th router software from popularvendors,
however firewallpolicies provide equivalent and greater function than standardand extended ACLs and should be
used instead.
You canapply MAC and Ethertype ACLs to a user role, however these ACLs only applyto non-IP traffic

from

the
user.
Support fo r Desktop Virtualizatio n Protocols
ArubaOSsupports desktop vi rtualization protocols by providing preconfiguredA CLs for Citrix and VMware clients.
You can applythese AC Ls to the user-rolewhen using the Virtual Desktop Infrastructure (VDI) clients. This ensures
that any enterpriseapplication that uses the VDI client performs optimally with appropriateQoS.
NOTE:Disable the voice aware ARM w hen applying the ACLsfor the VDI clients as the virtual desktopsessions may prevent the ARM
scanning.
Creating a Firewall Policy
This section describes how to configure the rules that constitute a firewall policy. A firewall policy can then be
appliedt o a user role (until the policy is applied to a user role, it does not have any effect).
Table8 0 describes requiredand opti onalparameters for a rule.