Reference Guide

Table Of Contents
198 |firewall Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide
Syntax
Parameter Description Range Default
allow-tri-session Allows three-way session when performing destination NAT.
This option should be enabled when the controller is not the
default gateway for wireless clients and the default gateway
is behind the controller. This option is typically used for
captive portal configuration.
—disabled
attack-rate Sets rates which, if exceeded, can indicate a denial of service
attack.
——
broadcast-filter-arp If enabled, all broadcast ARP requests are converted to
unicast and sent directly to the client. You can check the
status of this option using the show ap active and the show
datapath tunnel command. If enabled, the output will display
the letter a in the flags column.
—disabled
bwcontracts-subnet-
broadcast
Applies bw contracts to local subnet broadcast traffic
cp See “firewall cp” on page201
cp-bandwidth-contract See “firewall cp-bandwidth-contract” on page203
deny-inter-user-bridging Prevents the forwarding of Layer-2 traffic between wired or
wireless users. You can configure user role policies that
prevent Layer-3 traffic between users or networks but this
does not block Layer-2 traffic. This option can be used to
prevent traffic, such as Appletalk or IPX, from being
forwarded.
—disabled
deny-inter-user-traffic Denies traffic between untrusted users by disallowing layer2
and layer3 traffic. This parameter does not depend on the
deny-inter-user-bridging parameter being enabled or
disabled.
—disabled
disable-ftp-server Disables the FTP server on the controller. Enabling this option
prevents FTP transfers.
Enabling this option could cause APs to not boot up. You
should not enable this option unless instructed to do so by an
Dell representative.
—disabled
disable-stateful-h323-
processing
Disables stateful H.323 processing. disabled
disable-stateful-sccp-
processing
Disables SCCP processing. disabled
disable-stateful-sip-
processing
Disables monitoring of exchanges between a voice over IP or
voice over WLAN device and a SIP server. This option should
be enabled only when thee is no VoIP or VoWLAN traffic on
the network.
—disabled
disable-stateful-ua-
processing
Disables stateful UA processing. disabled
disable-stateful-vocera-
processing
Disables stateful VOCERA processing. disabled
drop-ip-fragments When enabled, all IP fragments are dropped. You should not
enable this option unless instructed to do so by an Dell
representative.
—disabled