Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Global Firewall settings

This thread has been viewed 11 times
  • 1.  Global Firewall settings

    Posted May 28, 2014 08:58 AM

    What is the difference between the "Enforce TCP Handshake Before Allowing Data" setting and the "Enforce TCP Sequence numbers" on the global firewall settings page?



  • 2.  RE: Global Firewall settings

    Posted May 28, 2014 09:23 AM

    Enforce TCP Handshake Before Allowing Data

    Prevents data from passing between two clients until the three-way TCP handshake has been performed. This option should be disabled when you have mobile clients on the network as enabling this option will cause mobility to fail. You can enable this option if there are no mobile clients on the network.

    Default: Disabled

     

    Enforce TCP Sequence numbers

    Enforces the TCP sequence numbers for all packets.

    Default:Disabled

     


  • 3.  RE: Global Firewall settings

    Posted May 28, 2014 09:29 AM

    Yes I read the guide and command line reference. The actual exaplanation there for the "Enforce TCP sequence numbers" is -

    "If enabled, prevents data from passing between two clients until the three-way TCP handshake has been performed"

    So what I am asking is what is the operational difference between the two.



  • 4.  RE: Global Firewall settings

    Posted May 28, 2014 10:01 AM

    This is to provide a defense mechanism against syn flood attacks and split handshake attack.

     

    Enforce TCP Sequence numbers
    Enforces the TCP sequence numbers for all packets.

     

    Enforce TCP Handshake Before Allowing Data
    Prevents data from passing between two clients until the three-way TCP handshake has been performed. This option should be disabled when you have mobile clients on the network as enabling this option will cause mobility to fail. You can enable this option if there are no mobile clients on the network.
    Default: Disabled

     

    Why are you trying to enable this option ?

     

    If you are planning to , I suggest you open a TAC case and an Aruba Engineer should assist you with these settings

     



  • 5.  RE: Global Firewall settings

    Posted May 28, 2014 10:14 AM

    In the absence of any proper documentation I'm trying to understand what the settings are for - some customers have asked about IPS configuration and what the Aruba OS can do. I dont have an answer for them as I cant find out what the settings and how they work. Especially when two settings both have the same brief explanation.



  • 6.  RE: Global Firewall settings

    Posted May 28, 2014 10:42 AM

    As an IDS/IPS Aruba has RFProtect module :

     

    http://www.arubanetworks.com/pdf/products/DS_AOS_RFPROTECT.pdf 



  • 7.  RE: Global Firewall settings

    Posted May 29, 2014 08:36 AM

    Unfortunately that is a dead link.



  • 8.  RE: Global Firewall settings

    Posted May 29, 2014 09:47 AM
      |   view attached

    Please find document attached

    Attachment(s)

    pdf
    DS_AOS_RFPROTECT.pdf   404 KB 1 version