Users Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 | User Guide 802.1x Authentication | 291
Authentication Server Retry
Count
Maximum number of authentication requests that are sent to server group.
The allowed range of values for this parameter is 0-3 requests, and the default value is 2
requests.
Framed MTU Sets the framed Maximum Transmission Unit (MTU) attribute sent to the authentication server.
The allowed range of values for this parameter is 500-1500 bytes, and the default value is 1100
bytes.
Number of times ID-Requests
are retried
Maximum number of times ID requests are sent to the client. The allowed range of values for this
parameter is 1-10 retries, and the default value is 3 retries.
Maximum Number of
Reauthentication Attempts
Number of times a user can try to login with wrong credentials after which the user is blacklisted
as a security threat. Set to 0 to disable blacklisting, otherwise enter a value from 0-5 to blacklist
the user after the specified number of failures.
Note: If changed from its default value, this may require a license This option may require a
license (see license descriptions at “License Types” on page 652).
Maximum number of times
Held State can be bypassed
Number of consecutive authentication failures which, when reached, causes the controller to
not respond to authentication requests from a client while the controller is in a held state after
the authentication failure. Before this number is reached, the controller responds to
authentication requests from the client even while the controller is in its held state.
(This parameter is applicable when 802.1x authentication is terminated on the controller, also
known as AAA FastConnect.)
The allowed range of values for this parameter is 0-3 failures, and the default value is 0.
Dynamic WEP Key Message
Retry Count
Set the Number of times WPA/WPA2 Key Messages are retried. The allowed range of values is
1-5 retries, and the default value is 3 retries.
Dynamic WEP Key Size The default dynamic WEP key size is 128 bits, If desired, you can change this parameter to either
40 bits.
Intervalbetween WPA/WPA2
Key Messages
Interval, in milliseconds, between each WPA key exchanges. The allowed range of values is
1000-5000ms, and the default value is 3000 ms.
Delay between EAP-Success
and WPA2 Unicast Key
Exchange
Interval, in milliseconds, between unicast and multicast key exchanges. The allowed range of
values is 0-2000ms, and the default value is 0 ms (no delay).
Time interval after which the
PMKSA will be deleted
The time interval after which the PMKSA (Pairwise Master Key Security Association) cache is
deleted. Time interval in Hours. Range: 1-2000. Default: 8 hrs.
Delay between WPA/WPA2
Unicast Key and Group Key
Exchange
Interval, in milliseconds, between unicast and multicast key exchanges. The allowed range of
values is 0-2000ms, and the default value is 0 ms (no delay).
WPA/WPA2 Key Message
Retry Count
Number of times WPA/WPA2 key messages are retried. The allowed range of values for this
parameter is 1-5 retries, and the default value is 3 retries.
Multicast Key Rotation Select this checkbox to enable multicast key rotation. This feature is disabled by default.
Unicast Key Rotation Select this checkbox to enable unicast key rotation. This feature is disabled by default.
Reauthentication Select the Reauthentication checkbox to force the client to do a 802.1x reauthentication after the
expiration of the default timer for reauthentication. (The default value of the timer is 24 hours.) If
the user fails to reauthenticate with valid credentials, the state of the user is cleared. If
derivation rules are used to classify 802.1x-authenticated users, then the reauthentication timer
per role overrides this setting.
This option is disabled by default.
Table 55 802.1x Authentication Profile Basic WebUI Parameters (Continued)
Parameter Description