Dell PowerConnect W-IAP92 Dell Instant 6.1.3.1-3.0.0.0 User Guide - Page 195

Session Firewall Based Blacklisting, PEF Settings, Firewall ALG Configuration

Page 195 highlights

Session Firewall Based Blacklisting In session firewall based blacklisting, an ACL rule is used to enable the option for automation blacklisting. when the ACL rule is hit, it would send out blacklist information and the client would be blacklisted. To set the blacklist duration, perform the following steps: 1. Select the PEF link and then select Blacklisting tab.  Auth failure blacklist time- Enter the duration since the blacklisting has been triggered when the authentication failure threshold is exceeded.  PEF rule blacklisted time- Enter the duration since the blacklisting has been triggered when a blacklisting rule has been triggered. NOTE: In the Networks tab, click the New link and go to Basic Info > VLAN > Security > Access page to enable Auth failure blacklist Blacklisting. Set a value between 1 to 10 in the max authentication failures of the SSID. To enable session firewall based blacklisting first enable the Blacklisting option of the corresponding ACL rule. Figure 158 Dynamic Blacklisting PEF Settings Firewall ALG Configuration Instant firewall now supports the ALG (Application Layer Gateway) functions such as SIP, Vocera, Alcatel NOE, and Cisco Skinny protocols. To enable or disable the protocols for ALG in Dell Instant perform the following steps: 1. Select PEF from the top right of the Instant UI. 2. Select PEF Settings tab. 3. Select Enabled from the corresponding drop-down list to enable SIP, VOCERA, Alcatel NOE, and Cisco skinny protocols. Figure 159 Enabling ALG Protocols Dell PowerConnect W-Series Instant Access Point 6.1.3.1-3.0.0.0 | User Guide Policy Enforcement Firewall | 195

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

Dell PowerConnect W-Series Instant Access Point 6.1.3.1-3.0.0.0
| User Guide
Policy Enforcement Firewall
|
195
Session Firewall Based Blacklisting
In session firewall based blacklisting, an ACL rule is used to enable the option for automation blacklisting. when
the ACL rule is hit, it would send out blacklist information and the client would be blacklisted.
To set the blacklist duration, perform the following steps:
1.
Select the
PEF
link and then select
Blacklisting
tab.
Auth failure blacklist time
— Enter the duration since the blacklisting has been triggered when the
authentication failure threshold is exceeded.
PEF rule blacklisted time
— Enter the duration since the blacklisting has been triggered when a blacklisting
rule has been triggered.
Figure 158
Dynamic Blacklisting
PEF Settings
Firewall ALG Configuration
Instant firewall now supports the ALG (Application Layer Gateway) functions such as SIP, Vocera, Alcatel NOE,
and Cisco Skinny protocols.
To enable or disable the protocols for ALG in Dell Instant perform the following steps:
1.
Select
PEF
from the top right of the Instant UI.
2.
Select
PEF
Settings
tab.
3.
Select
Enabled
from the corresponding drop-down list to enable SIP, VOCERA, Alcatel NOE, and Cisco
skinny protocols.
Figure 159
Enabling ALG Protocols
NOTE:
In the
Networks
tab, click the
New
link and go to
Basic Info > VLAN > Security > Access
page to enable Auth failure
blacklist Blacklisting. Set a value between 1 to 10 in the
max authentication failures
of the SSID. To enable session firewall based
blacklisting first enable the
Blacklisting
option of the corresponding ACL rule.