Users Guide

Table Of Contents
389| Roles and Policies Dell Networking W-Series ArubaOS 6.5.x| User Guide
Parameter Description
Monitor/Police CP Attack rate
(per 30 seconds)
Rate of misbehaving user’s traffic, which if exceeded, can indicate a
denial or service attack.
Recommended value is 3000 frames per 30 seconds.
Default: No default
Monitor/Police Gratuitous ARP
Attack rate (per 30 seconds)
Number of Gratuitous ARP packets per 30 seconds, which if exceeded,
can indicate denial of service attack. Valid range is 1-16384 packets per
30 seconds.
Recommended value is 50 packets.
Default: 50 packets
NOTE: Blacklisting of wired clients is not supported.
Deny Inter User Bridging Prevents the forwarding of Layer-2 traffic between wired or wireless
users. You can configure user role policies that prevent Layer-3 traffic
between users or networks but this does not block Layer-2 traffic. This
option can be used to prevent traffic, such as Appletalk or IPX, from
being forwarded.
Default: Disabled
Deny Inter User Traffic Denies traffic between untrusted users by disallowing layer-2 and
layer-3 traffic. This parameter does not depend on the deny-inter-user-
bridging parameter being enabled or disabled.
Default: Disabled
Deny Source Routing
Permits the firewall to reject and log packets with the specified IP
options loose source routing, strict source routing, and record route.
Note that network packets where the IPv6 source or destination
address of the network packet is defined as an “link-local address
(fe80::/64) are permitted.
Default: Disabled
Deny All IP Fragments Drops all IP fragments.
NOTE: Do not enable this option unless instructed to do so by a Dell
representative.
Default: Disabled
Enforce TCP Handshake
Before Allowing Data
Prevents data from passing between two clients until the three-way TCP
handshake has been performed. This option should be disabled when
you have mobile clients on the network as enabling this option will
cause mobility to fail. You can enable this option if there are no mobile
clients on the network.
Default: Disabled