Wireless Access

Reply
Highlighted
New Contributor

WLC 7005 active firewall sessions limit

Hello,

 

According to datasheet 7005 controller is limited by 16k active firewall sessions, does it mean it will stop processing traffic for new users or it won't enforce firewall at all above those limit?

 

Is my understanding correct, active firewall session is the same concept as stateful connection in traditional firewall world, so any ICMP/TCP/UDP connection will consume 1 unit of available active sessions pool?

 

Does this limitation apply with APs running in bridge mode?

 

Thank you


Accepted Solutions
Highlighted
Guru Elite

Re: WLC 7005 active firewall sessions limit


@dmitry_skotnikov wrote:

Hello,

 

According to datasheet 7005 controller is limited by 16k active firewall sessions, does it mean it will stop processing traffic for new users or it won't enforce firewall at all above those limit?

Stop Processing Traffic for new Users

Is my understanding correct, active firewall session is the same concept as stateful connection in traditional firewall world, so any ICMP/TCP/UDP connection will consume 1 unit of available active sessions pool?

Yes

Does this limitation apply with APs running in bridge mode?

No.

Thank you


 


*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.5 User Guide
InstantOS 8.5 User Guide
Airheads Knowledgebase
Airheads Video Knowledge Base
Remote Access Point Solution Guide
ArubaOS Consolidated Release Notes
ArubaOS 8 ViA VPN Solution Guide

View solution in original post


All Replies
Highlighted
Guru Elite

Re: WLC 7005 active firewall sessions limit


@dmitry_skotnikov wrote:

Hello,

 

According to datasheet 7005 controller is limited by 16k active firewall sessions, does it mean it will stop processing traffic for new users or it won't enforce firewall at all above those limit?

Stop Processing Traffic for new Users

Is my understanding correct, active firewall session is the same concept as stateful connection in traditional firewall world, so any ICMP/TCP/UDP connection will consume 1 unit of available active sessions pool?

Yes

Does this limitation apply with APs running in bridge mode?

No.

Thank you


 


*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.5 User Guide
InstantOS 8.5 User Guide
Airheads Knowledgebase
Airheads Video Knowledge Base
Remote Access Point Solution Guide
ArubaOS Consolidated Release Notes
ArubaOS 8 ViA VPN Solution Guide

View solution in original post

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: