Users Guide

Table Of Contents
Configuring a VSA-Derived Role
Many Network Address Server (NAS) vendors, including Dell, use VSAs to provide features not supported in
standard RADIUS attributes. For Dell systems, VSAs can be employed to provide the user role and VLAN for
RADIUS-authenticated clients, however the VSAs must be present on your RADIUS server. This involves
defining the vendor (Dell) and/or the vendor-specific code (14823), vendor-assigned attribute number,
attribute format (such as string or integer), and attribute value in the RADIUS dictionary file. VSAs supported
on controllers conform to the format recommended in RFC 2865, Remote Authentication Dial In User Service
(RADIUS)”.
For more information on Dell VSAs, see
RADIUS Server VSAs on page 180. Dictionary files that contain Dell
VSAs are available on the Dell support website for various RADIUS servers. Log into the Dell support website to
download a dictionary file from the Tools folder.
Understanding Global Firewall Parameters
Table 82 describes optional firewall parameters you can set on the controller for IPv4 traffic. To set these
options in the WebUI, navigate to the Configuration > Advanced Services > Stateful Firewall > Global
Setting page and select or enter values in the IPv4 column. To set these options in the CLI, use the firewall
configuration commands.
See IPv6 Support on page 125 for information about configuring firewall parameters for IPv6 traffic.
Parameter Description
Monitor Ping Attack (per 30
seconds)
Number of ICMP pings per 30 second, which if exceeded, can indicate a
denial of service attack. Valid range is 1-16384 pings per 30 seconds.
Recommended value is 120 seconds.
Default: No default
Monitor TCP SYN Attack rate
(per 30 seconds)
Number of TCP SYN messages per 30 second, which if exceeded, can
indicate a denial of service attack. Valid range is 1-16384 pings per 30
seconds.
Recommended value is 960 seconds.
Default: No default
Monitor IP Session Attack (per
30 seconds)
Number of TCP or UDP connection requests per 30 second, which if
exceeded, can indicate a denial of service attack. Valid range is 1-16384
requests per 30 seconds.
Recommended value is 960 seconds.
Default: No default
Monitor/Police ARP Attack (non
Gratuitous ARP) rate (per 30
seconds)
Number of ARP packets (other than Gratuitous ARP packets) per 30
seconds, which if exceeded, can indicate a denial of service attack. Valid
range is 1-16384 packets per 30 seconds.
Recommended value is 960 packets.
Default: No default
NOTE: Blacklisting of wired clients is not supported.
Table 82: IPv4 Firewall Parameters
Dell Networking W-Series ArubaOS 6.5.x | User Guide Roles and Policies | 388