Users Guide

Table Of Contents
Parameter Description
Prohibit IP Spoofing Enables detection of IP spoofing (where an intruder sends messages
using the IP address of a trusted client). When this option is enabled,
source and destination IP and MAC addresses are checked for each
ARP request/response. Traffic from a second MAC address using a
specific IP address is denied, and the entry is not added to the user
table. Possible IP spoofing attacks are logged and an SNMP trap is sent.
Default: Enabled
Prohibit RST Replay Attack When enabled, closes a TCP connection in both directions if a TCP RST
is received from either direction. You should not enable this option
unless instructed to do so by a Dell representative.
Default: Disabled
Log ICMP Errors Enables logging of received ICMP errors. You should not enable this
option unless instructed to do so by a Dell representative.
Default: Disabled
Stateful SIP Processing Disables monitoring of exchanges between a voice over IP or voice over
WLAN device and a SIP server. This option should be enabled only when
there is no VoIP or VoWLAN traffic on the network.
Default: Disabled (stateful SIP processing is enabled)
Allow Tri-session with DNAT Allows three-way session when performing destination NAT. This option
should be enabled when the controller is not the default gateway for
wireless clients and the default gateway is behind the controller. This
option is typically used for captive portal configuration.
Default: Disabled.
Amsdu Configuration
Enables handling AMSDU traffic from clients.
Default: Disabled
Session Mirror Destination Destination (IP address or port) to which mirrored session packets are
sent. This option is used only for troubleshooting or debugging.
Packets can be mirrored in multiple ACLs, so only a single copy is
mirrored if there is a match within more than one ACL.
You can configure the following:
l Ethertype to be mirrored with the Ethertype ACL mirror option.
l IP flows to be mirrored with the session ACL mirror option.
l MAC flows to be mirrored with the MAC ACL mirror option.
l If you configure both an IP address and a port to receive mirrored
packets, the IP address takes precedence.
Default: N/A
Session Idle Timeout (sec) Set the time, in seconds, that a non-TCP session can be idle before it is
removed from the session table. Specify a value in the range 16-259
seconds. You should not set this option unless instructed to do so by a
Dell representative.
Dell Networking W-Series ArubaOS 6.5.x | User Guide Roles and Policies | 390