311| Roles and Policies DellPowerConnect W- Series ArubaOS 6.2 | User Guide
Parameter Description
configureuser role pol icies thatprevent Layer-3 traffic between usersor networks
butthis does not block Layer-2 traffic. This option can be used to prevent traffic, such
asAppletalk or IPX, from being forwarded.
Default:Disabled
DenyInter User Traffic Deniestraffic between untrusted users by disallowing layer2 and layer3 traffic. This
parameterdoes not depend on the deny-inter-user-bridging parameter being enabled
ordi sabled.
Default:Disabled
DenyAll IP Fragm ents Dropsal l IP fragments.
NOTE:Do not enable this option unless instructed to do so by a Dell representative.
Default:Disabled
EnforceTCP Handshake Before
Allowing Data
Preventsdata from passing between two clients until the three-way TCP handshake
hasbeen performed. Thi soption should be di sabled when you havem obile clients on
thenetwork as enabling this option wil l cause mobility to fail. You can enable this
optioni fthere are no mobi le clients on the network.
Default:Disabled
Prohibit IP Spoofing Enablesdetection of IP spoofing (where an intruder sends messages using the IP
addressof a trusted client). When this option is enabled, source and destination IP
andMAC addresses are checked for each ARP request/response. Trafficfrom a
secondMAC address using a specific IP address is denied, and the entry is not
addedto the user table. Possible IP spoofing attacks are logged and an SNMP trap is
sent.
Default:Enabled
Prohibit RST Replay Attack Whenenabl ed, closes a TCP connection in both directions if a TCP RST is received
fromei therdi rection. You should not enable this option unlessi nstructedto do so by
a Dell representative.
Default:Disabled
LogICMP Errors Enablesl ogging of received ICMP errors. You should not enable this option unless
instructedto do so by a Dell representative.
Default:Disabled
StatefulSIP Processing Disablesmoni toring ofexchanges between a voice over IP or voice over WLAN
deviceand a S IPserver. Thi soption should be enabl ed only when there is no VoIP or
VoWLANtraffic on the network.
Default:Disabled (stateful SIP processing is enabled)
Allow Tri-session with DNAT Allows three-waysession when performing destination NAT. This option should be
enabled when the controller is
not
thedefault gateway for wirel ess clients and the
defaultgateway is behi nd the controller. This option is typicall y used forcaptive
portalconfiguration.
Default:Disabled.
AmsduConfiguration Enableshandling AMSDU traffic from clients.
Default:Disabled
SessionMi rror Destination Destination(IP address or port) to which mirrored session packets are sent.Thi s
optioni s used only for troubleshooting or debugging.
Packetscan be mirrored i n multiple ACLs, so only a single copy is mirrored if there is
am atchw ithin more than one ACL.
Youcan configure the follow ing: