PredefinedPolicy Description
NOTE:In order for captive portal to work
properly, DNS must also be permitted. This is
normally done in the "logon-control" firewall
rule.
ip access-list session cplogout user alias mswitch
svc-https dst-nat 8081
Usedto enable the captive portal "logout"
window. If the userattempts to connect to the
controller on thestandard HTTPS port (443) the
client will be NATed to port 8081,where the
captiveportal server will answer. If this rule is
notpresent, a wirel esscli entm aybe abl e to
accessthe controller's admi nistrative
interface.
ip access-list session vpnlogon
any any svc-ike permit
any any svc-esp permit
any any svc-l2tp permit
any any svc-pptp permit
any any svc-gre permit
Thispol icy permits VPN sessions to be
establishedto any destination. IPsec (IKE,
ESP, and L2TP)and P PTP (PPTP and GRE) are
supported.
ip access-list session ap-acl
any any udp 5000
any any udp 5555
any any svc-gre permit
any any svc-syslog permit
any user svc-snmp permit
user any svc-snmp-trap permit
user any svc-ntp permit
Thisi s a policy for internal use and should not
bem odified. It permits APsto boot up and
communicate with the controller.
ip access-list session validuser
any any any permit
Thisfirew all rule controls which userswil l be
addedto the user-table of the controller
throughuntrusted interfaces. Only IP
addressespermitted by this ACL wil l be
admittedto the system for further processing.
Ifa client device attempts to use an IP address
thatis denied by this rul e, the client device
will be ignored by the controller and given no
networkaccess. You can use this rule to
restrictforeign IP addresses from being added
tothe user-table.
Thispol icy should not be applied to any user
role, it isan internal system policy.
ip access-list session vocera-acl
any any svc-vocera permit queue high
Usefor Vocera VoIP devices to automatically
permit and prioritize Vocera traffic.
ip access-list session icmp-acl
any any svc-icmp permit
Permits all ICMP traffic.
ip access-list session sip-acl
any any svc-sip-udp permit queue high
any any svc-sip-tcp permit queue high
Usefor SIP VoIP devices to automatically
permit and prioritize all SIP control and data
traffic.
ip access-list session https-acl Permits all HTTPS traffic.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide Behaviorand Defaults | 828