20 | aaa authentication dot1x
Dell PowerConnect W-Series ArubaOS 6.2 | Reference Guide
Parameter
Description
Range
Default
countermeasures
Scans for message integrity code (MIC) failures in
traffic received from clients. If there are more than 2
MIC failures within 60 seconds, the AP is shut down
for 60 seconds. This option is intended to slow down
an attacker who is making a large number of forgery
attempts in a short time.
—
disabled
ca-cert <certificate>
CA certificate for client authentication. The CA
certificate needs to be loaded in the controller.
—
—
cert-cn-lookup
If you use client certificates for user authentication,
enable this option to verify that the certificate's
common name exists in the server. This parameter is
disabled by default.
—
—
eapol-logoff
Enables handling of EAPOL-LOGOFF messages.
—
disabled
enforce-suite-b-128
Configure Suite-B 128 bit or more security level
authentication enforcement
disabled
enforce-suite-b-192
Configure Suite-B 192 bit or more security level
authentication enforcement
disabled
framed-mtu <MTU>
Sets the framed MTU attribute sent to the
authentication server.
500-
1500
1100
heldstate-bypass-counter
<number>
(This parameter is applicable when 802.1X
authentication is terminated on the controller, also
known as AAA FastConnect.) Number of consecutive
authentication failures which, when reached,
causes the controller to not respond to
authentication requests from a client while the
controller is in a held state after the authentication
failure. Until this number is reached, the controller
responds to authentication requests from the client
even while the controller is in its held state.
0-3
0
ignore-eap-id-
match
Ignore EAP ID during negotiation.
—
disabled
ignore-eapol
start-afterauthentication
Ignores EAPOL-START messages after
authentication.
—
disabled
machine-authentication
(For Windows environments only) These parameters
set machine authentication:
NOTE: This parameter requires the PEFNG license.
blacklist-on-failure
Blacklists the client if machine authentication fails.
—
disabled
cache-timeout <hours>
The timeout, in hours, for machine authentication.
1-1000
24 hours
(1 day)
enable
Select this option to enforce machine authentication
before user authentication. If selected, either the
machine-default-role or the user-default-role is
assigned to the user, depending on which
authentication is successful.
—
disabled
Summary of Contents for PowerConnect W-7200 Series
Page 1: ...Dell PowerConnect W Series ArubaOS 6 2 Command Line Interface Reference Guide ...
Page 38: ...38 aaa authentication server windows DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 319: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide interface loopback 319 ...
Page 346: ...346 ipv6 mld DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 387: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide ip radius 387 ...
Page 995: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide show firewall 995 ...
Page 1529: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide wms client 1529 ...
Page 1536: ...0510956 01 March 2013 1536 ...