Users Guide

Table Of Contents
Dell PowerConnect W-Series ArubaOS 6.1 | User Guide 802.1x Authentication | 293
7. Click Apply.
Using the CLI
The following command configures settings for an 802.1x authentication profiles. Individual parameters are
described in Table 55, above.
aaa authentication dot1x {<profile>|countermeasures}
ca-cert <certificate>
clear
clone <profile>
eapol-logoff
framed-mtu <mtu>
heldstate-bypass-counter <number>
ignore-eap-id-match
ignore-eapolstart-afterauthentication
machine-authentication blacklist-on-failure|{cache-timeout <hours>}|enable|
{machine-default-role <role>}|{user-default-role <role>}
max-authentication-failures <number>
max-requests <number>
multicast-keyrotation
no ...
opp-key-caching
reauth-max <number>
reauthentication
server {server-retry <number>|server-retry-period <seconds>}
server-cert <certificate>
termination {eap-type <type>}|enable|enable-token-caching|{inner-eap-type (eapgtc|
eap-mschapv2)}|{token-caching-period <hours>}
timer {idrequest_period <seconds>}|{mkey-rotation-period <seconds>}|{quiet-period
<seconds>}|{reauth-period <seconds>}|{ukey-rotation-period <seconds>}|{wpagroupkey-
TLS Guest Access Select TLS Guest Access to enable guest access for EAP-TLS users with valid
certificates. This option is disabled by default.
TLS Guest Role Click the TLS Guest Role drop-down list and select the default user role for EAP-TLS guest users.
Note: This option may require a license This option may require a license (see license
descriptions at “License Types” on page 652).
Ignore EAPOL-START after
authentication
Select Ignore EAPOL-START after authentication to ignore EAPOL-START messages after
authentication. This option is disabled by default.
Handle EAPOL-Logoff Select Handle EAPOL-Logoff to enable handling of EAPOL-LOGOFF messages. This option is
disabled by default.
Ignore EAP ID during
negotiation
Select Ignore EAP ID during negotiation to ignore EAP IDs during negotiation. This option is
disabled by default.
WPA-Fast-Handover Select this option to enable WPA-fast-handover on phones that support this feature. WAP fast-
handover is disabled by default.
Disable rekey and
reauthentication for clients
on call
This feature disables rekey and reauthentication for VoWLAN clients. It is disabled by default,
meaning that rekey and reauthentication is enabled.
Note: This option may require a license This option may require a license (see license
descriptions at “License Types” on page 652).
Check certificate common
name against AAA server
If you use client certificates for user authentication, enable this option to verify that the
certificate's common name exists in the server. This parameter is enabled by default in the
default-cap and default-rap VPN profiles, and disabled by default on all other VPN profiles.
Table 55 802.1x Authentication Profile Basic WebUI Parameters (Continued)
Parameter Description