Reference Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 Command Line Interface | Reference Guide aaa authentication dot1x | 15
Syntax
Parameter Description Range Default
<profile> Name that identifies an instance of the profile. The name must be 1-63
characters.
“default”
clear Clear the Cached PMK, Role and VLAN entries. This command is
available in enable mode only.
——
countermeasures Scans for message integrity code (MIC) failures in traffic received
from clients. If there are more than 2 MIC failures within 60 seconds,
the AP is shut down for 60 seconds. This option is intended to slow
down an attacker who is making a large number of forgery attempts
in a short time.
disabled
ca-cert
<certificate>
CA certificate for client authentication. The CA certificate needs to be
loaded in the controller.
——
clone <profile> Name of an existing 802.1x profile from which parameter values are
copied.
——
eapol-logoff Enables handling of EAPOL-LOGOFF messages. disabled
framed-mtu <MTU> Sets the framed MTU attribute sent to the authentication server. 500-1500 1100
heldstate-
bypass-counter
<number>
(This parameter is applicable when 802.1x authentication is
terminated on the controller, also known as AAA FastConnect.)
Number of consecutive authentication failures which, when reached,
causes the controller to not respond to authentication requests from
a client while the controller is in a held state after the authentication
failure. Until this number is reached, the controller responds to
authentication requests from the client even while the controller is in
its held state.
0-3 0
ignore-eap-id-
match
Ignore EAP ID during negotiation. disabled
ignore-eapol
start-
afterauthenticat
ion
Ignores EAPOL-START messages after authentication. disabled
machine-
authentication
(For Windows environments only) These parameters set machine
authentication:
NOTE: This parameter requires the PEFNG license.
blacklist-on-
failure
Blacklists the client if machine authentication fails. disabled
cache-timeout
<hours>
The timeout, in hours, for machine authentication. 1-1000 24 hours (1
day)
enable Select this option to enforce machine authentication before user
authentication. If selected, either the machine-default-role or the
user-default-role is assigned to the user, depending on which
authentication is successful.
disabled
machine-
default-role
<role>
Default role assigned to the user after completing only machine
authentication.
guest
user-default-
role <role>
Default role assigned to the user after 802.1x authentication. guest