Users Guide

Table Of Contents
256 | 802.1x Authentication Dell PowerConnect ArubaOS 5.0 | User Guide
Machine Authentication:
Default Machine Role
Select the default role to be assigned to the user after completing only machine authentication.
Default: guest
Machine Authentication:
Default User Role
Select the default role to be assigned to the user after completing 802.1x authentication.
Default: guest
Reauthentication Select this option to force the client to do a 802.1x re-authentication after the expiration of the
default timer for re-authentication. The default value of the timer (Reauthentication Interval) is 24
hours. If the user fails to re-authenticate with valid credentials, the state of the user is cleared.
If derivation rules are used to classify 802.1x-authenticated users, then the Re-authentication
timer per role overrides this setting.
Default: disabled
Termination Select this option to terminate 802.1x authentication on the controller.
Default: disabled
Termination EAP-Type The EAP method, either EAP-PEAP or EAP-TLS.
Default: eap-peap
Termination Inner EAP-Type Select one of the following:
z EAP-Generic Token Card (GTC): Described in RFC 2284, this EAP method permits the transfer
of unencrypted usernames and passwords from client to server. The main uses for EAP-GTC
are one-time token cards such as SecureID and the use of LDAP or RADIUS as the user
authentication server. You can also enable caching of user credentials on the controller as a
backup to an external authentication server.
z EAP-Microsoft Challenge Authentication Protocol version 2 (MS-CHAPv2): Described in RFC
2759, this EAP method is widely supported by Microsoft clients.
Default: eap-mschapv2
Advanced 802.1x Authentication Profile settings
Max authentication failures Number of times a user can try to login with wrong credentials
after which the user is blacklisted as a security threat. Set to 0
to disable blacklisting, otherwise enter a non-zero integer to
blacklist the user after the specified number of failures. The range of allowed values is 0-5
failures, and the default value is 0 failures.
NOTE: This option may require a license (see Chapter 27 on page527).
Enforce Machine
Authentication
Select the Enforce Machine Authentication option to require
machine authentication. This option is also available on the Basic settings tab.
NOTE: This option may require a license (see Chapter 27 on page527).
Machine Authentication:
Default Machine Role
Default role assigned to the user after completing only machine authentication. The default role
for this setting is the “guest” role.
Machine Authentication
Cache Timeout
The timeout, in hours, for machine authentication. The allowed range of values is 1-1000 hours,
and the default value is 24 hours.
Blacklist on Machine
Authentication Failure
Select the Blacklist on Machine Authentication Failure checkbox to blacklist a client if machine
authentication fails. This setting is disabled by default
Machine Authentication:
Default User Role
Default role assigned to the user after 802.1x authentication. The default role for this setting is the
“guest” role.
Interval between Identity
Requests
Interval, in seconds, between identity request retries. The allowed range of values is 1-65535
seconds, and the default value is 30 seconds.
Quiet Period after Failed
Authentication
The enforced quiet period interval, in seconds, following failed authentication. The allowed
range of values is 1-65535 seconds, and the default value is 30 seconds.
Reauthentication Interval Interval, in seconds, between reauthentication attempts. The allowed range of values for this
parameter is 60-864000 seconds, and the default value is 86400 seconds (1day).
Table 52 802.1x Authentication Profile Basic WebUI Parameters (Continued)
Parameter Description