Users Guide

Table Of Contents
Predefined Policy Description
ip access-list session dns-acl
any any svc-dns permit
Permits all DNS
traffic.
ip access-list session logon-control
user any udp 68 deny
any any svc-icmp permit
any any svc-dns permit
any any svc-dhcp permit
any any svc-natt permit
The default pre-
authentication
role that should
be used by all
wireless clients.
Prohibits the
client from acting
as a DHCP server.
Permits all ICMP,
DNS, and DHCP.
Also permits
IPsec NAT-T (UDP
4500). Remove
NAT-T if not
needed.
ip access-list session srcnat
user any any src-nat
This policy can be
used to source-
NAT all traffic.
Because no NAT
pool is specified,
traffic that
matches this
policy will be
source NATed to
the IP address of
the controller.
ip access-list session skinny-acl
any any svc-sccp permit queue high
Use for Cisco
Skinny VoIP
devices to
automatically
permit and
prioritize VoIP
traffic.
ip access-list session tftp-acl
any any svc-tftp permit
Permits all TFTP
traffic.
ip access-list session guest This policy is not
used.
ip access-list session dhcp-acl
any any svc-dhcp permit
Permits all DHCP
traffic. If DHCP is
not allowed,
clients will not be
able to request or
renew IP
addresses.
Dell Networking W-Series ArubaOS 6.4.x | User Guide Behavior and Defaults | 1137