Reference Guide

Table Of Contents
Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide firewall | 199
enable-per-packet-logging Enables logging of every packet if logging is enabled for the
corresponding session rule. Normally, one event is logged per
session. If you enable this option, each packet in the session
is logged. You should not enable this option unless instructed
to do so by an Dell representative, as doing so may create
unnecessary overhead on the controller.
—disabled
enforce-tcp-handshake Prevents data from passing between two clients until the
three-way TCP handshake has been performed. This option
should be disabled when you have mobile clients on the
network as enabling this option will cause mobility to fail. You
can enable this option if there are no mobile clients on the
network.
—disabled
gre-call-id-processing Creates a unique state for each PPTP tunnel. You should not
enable this option unless instructed to do so by an Dell
representative.
—disabled
local-valid-users Adds only IP addresses, which belong to a local subnet, to the
user-table.
—disabled
log-icmp-error Logs received ICMP errors. You should not enable this option
unless instructed to do so by an Dell representative.
—disabled
prohibit-arp-spoofing Detects and prohibits arp spoofing. When this option is
enabled, possible arp spoofing attacks are logged and an
SNMP trap is sent.
—disabled
prohibit-ip-spoofing Detects IP spoofing (where an intruder sends messages using
the IP address of a trusted client). When this option is
enabled, IP and MAC addresses are checked; possible IP
spoofing attacks are logged and an SNMP trap is sent.
—disabled
prohibit-rst-replay Closes a TCP connection in both directions if a TCP RST is
received from either direction. You should not enable this
option unless instructed to do so by an Dell representative.
—disabled
session-idle-timeout Time, in seconds, that a non-TCP session can be idle before it
is removed from the session table. You should not modify this
option unless instructed to do so by an Dell representative.
16-259 15 seconds
session-mirror-
destination
Destination to which mirrored packets are sent. This option is
used only for troubleshooting or debugging.
Packets can be mirrored in multiple ACLs, so only a single
copy is mirrored if there is a match within more than one ACL.
You can configure the following:
Ethertype to be mirrored with the Ethertype ACL mirror option.
See “ip access-list eth” on page255.
IP flows to be mirrored with the session ACL mirror option.
See “ip access-list session” on page262.
MAC flows to be mirrored with the MAC ACL mirror option.
See “ip access-list mac” on page260.
If you configure both an IP address and a port to receive
mirrored packets, the IP address takes precedence.
——
session-mirror-ipsec Configures session mirroring of all frames that are processed
by IPsec. Frames are sent to IP address specified by the
session-mirror-destination option.This option is used only for
troubleshooting or debugging.
—disabled
session-voip-timeout Idle session timeout, in seconds, for sessions that are marked
as voice sessions. If no voice packet exchange occurs over a
voice session for the specified time, the voice session is
removed.
16-300 300
seconds
Parameter Description Range Default