Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide 802.1x Authentication | 259
7. Click Apply.
Using the CLI
The following command configures settings for an 802.1x authentication profiles. Individual parameters are
described in Table 52, above.
aaa authentication dot1x {<profile>|countermeasures}
ca-cert <certificate>
clear
clone <profile>
eapol-logoff
framed-mtu <mtu>
heldstate-bypass-counter <number>
ignore-eap-id-match
ignore-eapolstart-afterauthentication
machine-authentication blacklist-on-failure|{cache-timeout <hours>}|enable|
{machine-default-role <role>}|{user-default-role <role>}
max-authentication-failures <number>
max-requests <number>
multicast-keyrotation
no ...
opp-key-caching
reauth-max <number>
reauthentication
server {server-retry <number>|server-retry-period <seconds>}
server-cert <certificate>
termination {eap-type <type>}|enable|enable-token-caching|{inner-eap-type (eapgtc|
eap-mschapv2)}|{token-caching-period <hours>}
timer {idrequest_period <seconds>}|{mkey-rotation-period <seconds>}|{quiet-period
<seconds>}|{reauth-period <seconds>}|{ukey-rotation-period <seconds>}|{wpagroupkey-
delay <seconds>}|{wpa-key-period <milliseconds>}
tls-guest-access
tls-guest-role <role>
unicast-keyrotation
use-session-key
TLS Guest Access Select TLS Guest Access to enable guest access for EAP-TLS users with valid
certificates. This option is disabled by default.
TLS Guest Role Click the TLS Guest Role drop-down list and select the default user role for EAP-TLS guest users.
NOTE: This option may require a license (see Chapter 27 on page527)..
Ignore EAPOL-START after
authentication
Select Ignore EAPOL-START after authentication to ignore EAPOL-START messages after
authentication. This option is disabled by default.
Handle EAPOL-Logoff Select Handle EAPOL-Logoff to enable handling of EAPOL-LOGOFF messages. This option is
disabled by default.
Ignore EAP ID during
negotiation
Select Ignore EAP ID during negotiation to ignore EAP IDs during negotiation. This option is
disabled by default.
WPA-Fast-Handover Select this option to enable WPA-fast-handover on phones that support this feature. WAP fast-
handover is disabled by default.
Disable rekey and
reauthentication for clients
on call
This feature disables rekey and reauthentication for VoWLAN clients. It is disabled by default,
meaning that rekey and reauthentication is enabled.
NOTE: This option may require a license (see Chapter 27 on page527).
Table 52 802.1x Authentication Profile Basic WebUI Parameters (Continued)
Parameter Description