Dell 6.2 Server User Manual


 
827 | Behavior andDefaults DellPowerConnectW-SeriesArubaOS6.2 | User Guide
Name Protocol Port(s)
svc-ssh
tcp 22
svc-h323-tcp
tcp 1720
svc-h323-udp
udp 1718 1719
svc-http-proxy1
tcp 3128
svc-http-proxy2
tcp 8080
svc-http-proxy3
tcp 8888
svc-sips
tcp 5061
svc-v6-dhcp
udp 546 547
svc-v6-icmp
icmp 0
any
any 0
Policies
The following are predefined policies.
Predefined Policy Description
ip access-list session allowall
any any any permit
An "allow all" firewall rule that permits all
traffic.
ip access-list session control
user any udp 68 deny
any any svc-icmp permit
any any svc-dns permit
any any svc-papi permit
any any svc-cfgm-tcp permit
any any svc-adp permit
any any svc-tftp permit
any any svc-dhcp permit
any any svc-natt permit
Controls traffic—Apply to untrusted wired
ports in order to allow Dell APs to boot up.
NOTE: In most cases wired ports should be
made "trusted" when attached to an internal
network.
ip access-list session captiveportal
user alias mswitch svc-https dst-nat 8081
user any svc-http dst-nat 8080
user any svc-https dst-nat 8081
user any svc-http-proxy1 dst-nat 8088
user any svc-http-proxy2 dst-nat 8088
user any svc-http-proxy3 dst-nat 8088
Enables Captive Portal authentication.
1. Any HTTPS traffic destined for the
controller will be NATed to port 8081,
where the captive portal server will
answer.
2. All HTTP traffic to any destination will be
NATed to the controller on port 8080,
where an HTTP redirect will be issued.
3. All HTTPS traffic to any destination will be
NATed to the controller on port 8081,
where an HTTP redirect will be issued.
4. All HTTP proxy traffic will be NATed to the
controller on port 8088.
Table 401:
Predefined Policies