ArubaOS 8.6.0.0Help Center
Working with Firewall Features
If you installed a许可证Mobility Master,您可以配置functions for IPv6 client traffic. While thesefunctions are identical toIPv4客户端的功能,您需要明确将其配置为IPv6流量。有关有关的更多信息policies, seeUnderstanding Global Firewall Parameters.
|
Voice-related andfunctions are not supported for IPv6 traffic. |
Table 1:IPv6防火墙参数
Parameter |
Description |
监视PING攻击(每30秒) |
Number of每30秒的ping(如果超过)可以表明attack. Valid range is 1-16384 pings per 30 seconds. Recommended value is 120. Default: No default |
Monitor TCP SYN Attack rate (per 30 seconds) |
Number ofSYN messages per 30 second, which if exceeded, can indicate aattack. Valid range is 1-16384 pings per 30 seconds. 推荐值为960。 Default: No default |
Monitor IP Session Attack (per 30 seconds) |
Number of或者connection requests per 30 second, which if exceeded, can indicate aattack. Valid range is 1-16384 requests per 30 seconds. 推荐值为960。 Default: No default |
Deny Inter User Bridging |
防止有线或无线用户之间的2层流量转发。您可以配置用户角色策略,以防止用户或网络之间的3层流量,但这不会阻止2层流量。此选项可用于防止转发流量,例如appletalk或ipx。 Default: Disabled |
Deny All IP Fragments |
Drops all IP fragments. 笔记:Do not enable this option unless instructed to do so by a
nArubarepresentative. Default: Disabled |
在允许数据之前强制执行TCP握手 |
Prevents data from passing between two clients until the three-wayhandshake has been performed. This option should be disabled when you have mobile clients on the network, as enabling this option will cause mobility to fail. You can enable this option if there are no mobile clients on the network. Default: Disabled |
Prohibit IP Spoofing |
Enables detection of IP spoofing (where an intruder sends messages using the IP address of a trusted client). When you enable this option, IP and检查每个地址request or response. Traffic from a second使用特定的IP地址的地址被拒绝,并且该条目未添加到用户表中。可能记录了可能的IP欺骗攻击trap is sent. Default: Disabled |
Prohibit RST Replay Attack |
When enabled, closes aconnection in both directions if aRST is received from either direction. You should not enable this option unless instructed to do so by a
nArubarepresentative. Default: Disabled |
会话镜目的地 |
目的地(IPv4地址或managed deviceport) to which mirrored session packets are sent. You can configure IPv6 flows to be mirrored with the sessionmirror option. This option is used only for troubleshooting or debugging. Default: N/A |
Session Idle Timeout |
Set the time, in seconds, that a non-会话可以在将其从会话表中删除之前闲置。在16–259秒内指定一个值。除非指示这样做,否则您不应设置此选项
nArubarepresentative. 默认:30秒 |
Per-packet Logging |
Enables logging of every packet if logging is enabled for the corresponding session rule. Normally, one event is logged per session. If you enable this option, each packet in the session is logged. You should not enable this option unless instructed to do so by a
nAruba代表,这样做可能会在managed device. Default: Disabled (per-session logging is performed) |
IPv6Enable |
全球启用IPv6。 |
下面的过程介绍如何配置the功能。
1.In theMobility Masternode hierarchy, navigate to the配置>服务>防火墙tab.
2.扩展Global Settingaccordion.
3.Under theIPv6column, enter the following:
Enter a value forMonitor ping attack (per 30 sec).
Enter a value forMonitor IP sessions attack(per 30 sec).
Enter a value forMonitor TCP SYN attack rate (per 30 sec).
4.ClickSubmit.
5.Click等待更改.
6。In the等待更改window, select the check box and clickDeploy changes.
以下commands configurefunctions.
(主机)[myNode](config)#ipv6燃烧所有攻击率PING 15
(host) [mynode] (config)#ipv6 firewall attack-rate session 25
(host) [mynode] (config)#ipv6 firewall session-idle-timeout 60