Configuring a S erver-Derived Role

If the client is authenticated throughan authenticatio nserver, the user role for the client can be basedo no neor
more attributes returnedby the server during authentication. You configurethe user role to be derived by specifying
condition rules; whena condition is met, the specified user role is assigned to t he client.Yo u can specify more than
one condition rule; the orderof rules is i mportant as the first matching condition is applied. You can also define
serverrules based on client attributes such as E SSID, BSSID, or MAC address, even though these attributes are not
returnedby the server.
For information about configuring a server-derivedrole, see "Configuring Server-Derivation Rules"o n page1 82.

Configuring a V SA-Derived Role

Many NetworkA ddressServer (NAS) vendors, includingDell, use VSAs to provide features not supported in standard
RADIUS attributes. For Dell systems, V SAs can be employed to provide the user role and VLAN for RA DIUS-
authenticated clients, howeverthe VSAs must be present ony ourR ADIUS server.This involves defining thevendor
(Dell)and/or the vendor-specific code (14823), vendor-assigned attribute number, attribute format (suchas st ringor
integer),and att ribute valuein the RADIUS dictionary file. VSAs supported on Dell controllersconform to the
format recommendedin RFC 2865, “Remote Authenticati on Dial In User Service (RADI US)”.
Dictionary files that contain D ellV SAs are available on the Dell support website for various RADI US servers.Log
into the Dell support website to download a dictionary file from the Tools folder.
Understanding Glo bal Firewall Parameters
Table8 4 describes optional firewallparameters you can set on theco ntrollerfor IPv4 traffic. To set these options in
the WebUI, navigate to the Configuration > Advanced Services > Stateful Firewall > Global Setting page and
select or entervalues in the IPv4 column.To set these options in the CLI, use the firewall configuration
commands.
See IPv6 Support on page 128 for information about configuring firewall parameters for IPv6 traffic.
Parameter Description
MonitorP ing Attack Number ofICMP pi ngsper second,which i fexceeded, can i ndicate a denial of
serviceattack. Vali d range is 1-255 pings per second. Recommended value is4.
Default:No default
MonitorTC P SYN Attackrate Number ofTCP SYNmessages per second, which i fexceeded, can i ndicate a denial
ofservice attack. Vali d range is 1-255 messagesper second.Recommended valueis
32.
Default:No default
MonitorIP Session Attack Number ofTCP orUDP connection requests per second, which if exceeded, can
indicate a denial of service attack.Val id range is 1-255requests per second.
Recommended value is 32.
Default:No default
Monitor/Police CP Attack rate (per
sec)
Rateof misbehaving user’s inbound traffic, whi ch if exceeded, can indicate a denial
orservice attack.
Recommended value is 100 frames per second.
DenyInter User Bridging Preventsthe forwarding of Layer-2 traffic between wired or wireless users. You can

Table84 :

IPv4 FirewallParameters
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide Rolesand Policies | 310