<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bcast/Mcast ICMP not allowed when configured as best practices in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70597#M6386</link>
    <description>&lt;P&gt;Hello Robert,&lt;/P&gt; &lt;P&gt;I’ll&amp;nbsp;test it.&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2020 17:07:50 GMT</pubDate>
    <dc:creator>Aviv_Kedem</dc:creator>
    <dc:date>2020-02-03T17:07:50Z</dc:date>
    <item>
      <title>Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70591#M6380</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt; &lt;P&gt;AP7532 versions: 5.9.1.4 - 5.9.3.3&lt;/P&gt; &lt;P&gt;Receiving many logs:&lt;EM&gt;&amp;nbsp;%DATAPLANE-4-DOSATTACK: BAD_PACKET: &amp;nbsp;Bcast/Mcast ICMP not allowed&lt;/EM&gt;&lt;/P&gt; &lt;P&gt;But I had disabled it in&amp;nbsp;the firewall policy (from best practices) :&lt;/P&gt; &lt;P&gt;&lt;EM&gt;show running-config firewall-policy default include-factory | include broadcast-multicast-icmp&lt;/EM&gt;&lt;/P&gt; &lt;P&gt;&lt;EM&gt;no ip dos broadcast-multicast-icmp&lt;/EM&gt;&lt;/P&gt; &lt;P&gt;Why the messages are still appears ?&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt; &lt;P&gt;Aviv&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2020 17:47:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70591#M6380</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2020-02-02T17:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70592#M6381</link>
      <description>&lt;P&gt;Hi Aviv,&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; Please check that&lt;/P&gt; &lt;P&gt;1. AP/profile using mentioned firewall-policy&lt;/P&gt; &lt;P&gt;2. Firewall is enabled&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Regards,&lt;/P&gt; &lt;P&gt;&amp;nbsp; Misha&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2020 18:14:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70592#M6381</guid>
      <dc:creator>vanelm</dc:creator>
      <dc:date>2020-02-02T18:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70593#M6382</link>
      <description>&lt;P&gt;Hello Misha,&lt;/P&gt; &lt;P&gt;show running-config firewall-policy default include-factory from AP:&lt;/P&gt; &lt;BLOCKQUOTE&gt; &lt;P&gt;&amp;nbsp;no ip dos smurf&lt;BR /&gt; &amp;nbsp;no ip dos twinge&lt;BR /&gt; &amp;nbsp;no ip dos invalid-protocol&lt;BR /&gt; &amp;nbsp;no ip dos router-advt&lt;BR /&gt; &amp;nbsp;no ip dos router-solicit&lt;BR /&gt; &amp;nbsp;no ip dos option-route&lt;BR /&gt; &amp;nbsp;no ip dos ascend&lt;BR /&gt; &amp;nbsp;no ip dos chargen&lt;BR /&gt; &amp;nbsp;no ip dos fraggle&lt;BR /&gt; &amp;nbsp;no ip dos snork&lt;BR /&gt; &amp;nbsp;no ip dos ftp-bounce&lt;BR /&gt; &amp;nbsp;no ip dos tcp-intercept&lt;BR /&gt; &amp;nbsp;no ip dos broadcast-multicast-icmp&lt;BR /&gt; &amp;nbsp;no ip dos land&lt;BR /&gt; &amp;nbsp;no ip dos tcp-xmas-scan&lt;BR /&gt; &amp;nbsp;no ip dos tcp-null-scan&lt;BR /&gt; &amp;nbsp;no ip dos winnuke&lt;BR /&gt; &amp;nbsp;no ip dos tcp-fin-scan&lt;BR /&gt; &amp;nbsp;no ip dos udp-short-hdr&lt;BR /&gt; &amp;nbsp;no ip dos tcp-post-syn&lt;BR /&gt; &amp;nbsp;no ip dos tcphdrfrag&lt;BR /&gt; &amp;nbsp;no ip dos ip-ttl-zero&lt;BR /&gt; &amp;nbsp;no ip dos ipspoof&lt;BR /&gt; &amp;nbsp;no ip dos tcp-bad-sequence&lt;BR /&gt; &amp;nbsp;no ip dos tcp-sequence-past-window&lt;BR /&gt; &amp;nbsp;ip tcp validate-rst-seq-number&lt;BR /&gt; &amp;nbsp;ip tcp validate-rst-ack-number&lt;BR /&gt; &amp;nbsp;ip tcp validate-icmp-unreachable&lt;BR /&gt; &amp;nbsp;ip tcp recreate-flow-on-out-of-state-syn&lt;BR /&gt; &amp;nbsp;ip tcp optimize-unnecessary-resends&lt;BR /&gt; &amp;nbsp;ip dos tcp-max-incomplete high 500&lt;BR /&gt; &amp;nbsp;ip dos tcp-max-incomplete low 200&lt;BR /&gt; &amp;nbsp;no ip-mac conflict&lt;BR /&gt; &amp;nbsp;no ip-mac routing conflict&lt;BR /&gt; &amp;nbsp;flow timeout icmp 30&lt;BR /&gt; &amp;nbsp;flow timeout udp 30&lt;BR /&gt; &amp;nbsp;flow timeout tcp setup 10&lt;BR /&gt; &amp;nbsp;flow timeout tcp established 5400&lt;BR /&gt; &amp;nbsp;flow timeout tcp close-wait 10&lt;BR /&gt; &amp;nbsp;flow timeout tcp reset 10&lt;BR /&gt; &amp;nbsp;flow timeout tcp stateless-general 90&lt;BR /&gt; &amp;nbsp;flow timeout tcp stateless-fin-or-reset 10&lt;BR /&gt; &amp;nbsp;flow timeout other 30&lt;BR /&gt; &amp;nbsp;dhcp-offer-convert&lt;BR /&gt; &amp;nbsp;proxy-arp&lt;BR /&gt; &amp;nbsp;firewall enable&lt;BR /&gt; &amp;nbsp;ipv6 firewall enable&lt;BR /&gt; &amp;nbsp;no ipv6 rewrite-flow-label&lt;BR /&gt; &amp;nbsp;no ipv6 strict-ext-hdr-check&amp;nbsp;&lt;BR /&gt; &amp;nbsp;no ipv6 unknown-options&amp;nbsp;&lt;BR /&gt; &amp;nbsp;no ipv6 duplicate-options&amp;nbsp;&lt;BR /&gt; &amp;nbsp;no ipv6 option end-point-identification&lt;BR /&gt; &amp;nbsp;no ipv6 option router-alert&lt;BR /&gt; &amp;nbsp;no ipv6 option network-service-access-point&lt;BR /&gt; &amp;nbsp;no ipv6 option strict-hao-opt-check&lt;BR /&gt; &amp;nbsp;no ipv6 option strict-padding&lt;BR /&gt; &amp;nbsp;no ipv6 routing-type one&lt;BR /&gt; &amp;nbsp;no ipv6 routing-type two&lt;BR /&gt; &amp;nbsp;ipv6 dos multicast-icmpv6 log-and-drop log-level warnings&amp;nbsp;&lt;BR /&gt; &amp;nbsp;ipv6 dos hop-limit-zero log-and-drop log-level warnings&amp;nbsp;&lt;BR /&gt; &amp;nbsp;ipv6 dos tcp-intercept-mobility log-and-drop log-level warnings&amp;nbsp;&lt;BR /&gt; &amp;nbsp;acl-logging&lt;BR /&gt; &amp;nbsp;no stateful-packet-inspection-l2&lt;BR /&gt; &amp;nbsp;flow dhcp stateful&lt;BR /&gt; &amp;nbsp;alg ftp&lt;BR /&gt; &amp;nbsp;alg tftp&lt;BR /&gt; &amp;nbsp;no alg sip&lt;BR /&gt; &amp;nbsp;alg dns&lt;BR /&gt; &amp;nbsp;no alg facetime&lt;BR /&gt; &amp;nbsp;no alg sccp&lt;BR /&gt; &amp;nbsp;alg pptp&lt;BR /&gt; &amp;nbsp;no logging icmp-all&lt;BR /&gt; &amp;nbsp;no logging icmp-packet-drop&lt;BR /&gt; &amp;nbsp;no logging malformed-packet-drop&lt;BR /&gt; &amp;nbsp;no logging verbose&lt;BR /&gt; &amp;nbsp;ip tcp adjust-mss 1400&lt;BR /&gt; &amp;nbsp;clamp tcp-mss&lt;BR /&gt; &amp;nbsp;virtual-defragmentation&lt;BR /&gt; &amp;nbsp;no virtual-defragmentation minimum-first-fragment-length&lt;BR /&gt; &amp;nbsp;virtual-defragmentation maximum-fragments-per-datagram 140&lt;BR /&gt; &amp;nbsp;virtual-defragmentation maximum-defragmentation-per-host 8&lt;BR /&gt; &amp;nbsp;virtual-defragmentation timeout 1&lt;BR /&gt; &amp;nbsp;dns-snoop entry-timeout 1800&lt;BR /&gt; &amp;nbsp;no 802.2-encapsulation&lt;BR /&gt; &amp;nbsp;no vlan-stacking&lt;BR /&gt; &amp;nbsp;dns-snoop drop-on-parserror&lt;BR /&gt; &amp;nbsp;proxy-nd&lt;BR /&gt; &amp;nbsp;no ipv6-mac conflict&lt;BR /&gt; &amp;nbsp;no ipv6-mac routing conflict&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;/BLOCKQUOTE&gt; &lt;P&gt;Regards,&lt;/P&gt; &lt;P&gt;Aviv&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2020 18:48:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70593#M6382</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2020-02-02T18:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70594#M6383</link>
      <description>&lt;P&gt;Please apply the best practice for the firewall and make sure you behave it applied to the AP profile.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&lt;A href="https://gtacknowledge.extremenetworks.com/pkb_mobile#/articles/en_US/How_To/What-is-the-best-practice-firewall-settings-to-be-configured-on-WM3000-series" target="_blank" rel="nofollow noreferrer noopener"&gt;FireWall Best Practice&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2020 23:05:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70594#M6383</guid>
      <dc:creator>RobertZ</dc:creator>
      <dc:date>2020-02-02T23:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70595#M6384</link>
      <description>&lt;P&gt;Hello Robert,&lt;/P&gt; &lt;P&gt;It already was configured.&lt;/P&gt; &lt;P&gt;I think there is some bug.&lt;/P&gt; &lt;P&gt;&amp;nbsp;These logs are appears even if the feature is disabled.&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt; &lt;P&gt;Aviv&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2020 23:20:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70595#M6384</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2020-02-02T23:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70596#M6385</link>
      <description>&lt;P&gt;I don't recall if this was a bug in firmware 5.9.1 or 5.9.3. Since you are on very old firmware it will be beneficial for you to upgrade to current firmware version 5.9.7 and retest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 00:07:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70596#M6385</guid>
      <dc:creator>RobertZ</dc:creator>
      <dc:date>2020-02-03T00:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Bcast/Mcast ICMP not allowed when configured as best practices</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70597#M6386</link>
      <description>&lt;P&gt;Hello Robert,&lt;/P&gt; &lt;P&gt;I’ll&amp;nbsp;test it.&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 17:07:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/bcast-mcast-icmp-not-allowed-when-configured-as-best-practices/m-p/70597#M6386</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2020-02-03T17:07:50Z</dc:date>
    </item>
  </channel>
</rss>

