Dell W-Series 277 Instant 6.5.1.0-4.3.1.0 User Guide - Page 186
Configuring Firewall Settings to Disable Auto Topology Rules, Security, Firewall Settings, Firewall
View all Dell W-Series 277 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 186 highlights
To view the attack statistics (Instant AP)# show attack stats attack counters Counter ------arp packet counter drop bad arp packet counter dhcp response packet counter fixed bad dhcp packet counter send arp attack alert counter send dhcp attack alert counter arp poison check counter garp send check counter Value ------0 0 0 0 0 0 0 0 Configuring Firewall Settings to Disable Auto Topology Rules By default, the auto topology rules in a W-IAP are enabled. You can disable the rules by configuring firewall settings in the W-IAP. In order to deny auto topology communication outside the W-IAP subnet, the inbound firewall settings must be enabled. When the inbound firewall settings are enabled: l Access Control Entities (ACEs) must be configured to block auto topology messages, as there is no default rule at the top of predefined ACLs. l ACEs must be configured to override the guest VLAN auto-expanded ACEs. In other words, the user defined ACEs take higher precedence over guest VLAN ACEs. For more information on inbound firewall settings, see Managing Inbound Traffic. The priority of a particular ACE is determined based on the order in which it is programmed. Ensure that you do not accidentally override the guest VLAN ACEs. You can change the status of auto topology rules by using the Instant UI or the CLI: In the Instant UI 1. Click the Security located directly above the Search bar in the Instant main window. 2. Go to the Firewall Settings tab. 3. In Firewall section, select Disabled from the Auto topology rules drop-down list. 4. Click OK. In the CLI (Instant AP)(config)# firewall (Instant AP)(firewall)# disable-auto-topology-rules (Instant AP)(firewall)# end (Instant AP)# commit apply To view the configuration status: Firewall -------- Type Value ---- ----- Auto topology rules disable Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide Roles and Policies | 186