Administrator Guide

Table Of Contents
333 | 802.1X Authentication Dell Networking W-Series ArubaOS 6.4.x| User Guide
Parameter Description
Delay between EAP-
Success and WPA2
Unicast Key Exchange
Interval, in milliseconds, between EAP-Success and unicast key exchanges.
Range: 0-2000 ms.
Default: 0 ms (no delay).
Delay between
WPA/WPA2 Unicast
Key and Group Key
Exchange
Interval, in milliseconds, between unicast and multicast key exchange. Time
interval in milliseconds.
Range: 0-2000.
Default: 0 (no delay).
Time interval after
which the PMKSA will
be deleted
The time interval after which the PMKSA (Pairwise Master Key Security
Association) cache is deleted. Time interval in Hours.
Range: 1-2000.
Default: 8.
WPA/WPA2 Key
Message Retry Count
Number of times WPA/WPA2 key messages are retried.
Range: 1-5 retries.
Default: 3 retries.
Multicast Key Rotation Select this checkbox to enable multicast key rotation. This feature is disabled by
default.
Unicast Key Rotation Select this checkbox to enable unicast key rotation. This feature is disabled by
default.
Opportunistic Key
Caching
By default, the 802.1X authentication profile enables a cached pairwise master
key (PMK) which is derived through a client and an associated AP. This key is
used when the client roams to a new AP. This allows clients faster roaming
without a full 802.1x authentication. Uncheck this option to disable this feature.
NOTE: Make sure that the wireless client (the 802.1X supplicant) supports this
feature. If the client does not support this feature, the client will attempt to
renegotiate the key whenever it roams to a new AP. As a result, the key cached on
the controller can be out of sync with the client's key.
Validate PMKID This parameter instructs the controller to check the pairwise master key (PMK)
ID sent by the client. When you enable this option, the client must send a PMKID
in the associate or reassociate frame to indicate that it supports OKC or PMK
caching; otherwise, full 802.1x authentication takes place.
NOTE: This feature is optional, since most clients that support OKC and PMK
caching do not send the PMKID in their association request.
Use Session Key Select the Use Session Key option to use the RADIUS session key as the unicast
WEP key. This option is disabled by default.
Use Static Key Select the Use Static Key option to use a static key as the unicast/multicast WEP
key. This option is disabled by default.
Table 68: 802.1x Authentication Profile Basic WebUI Parameters