199| 802.1X Auth entication DellPowerConnect W- Series ArubaOS 6.2 | User Guide
Parameter Description
forthe cached information. The default value is 24 hours.
CA-Certificate Click the CA-Certificate drop-down list and select a certificate for client authentication. The
CAcertificate needs to be loaded in the controller before it wil l appear on this list.
Server-Certificate Click the Server-Certificate drop-down list and select a server certificatethe controller w ill
useto authenticate itself to the client.
TLSGuest Access Select TLS Guest Access to enable guest accessfor EAP-TLS users with valid
certificates.This option isdisabled by default.
TLSGuest Role Clickthe TLS Guest Role drop-down li stand select the default user role for EAP-TLS guest
users.This option may require a l icense This option may require a license.
IgnoreEAPOL-START after
authentication
SelectIgnore EAPOL-START after authentication to ignore EAPOL-START messages after
authentication.Thi s option is disabled by default.
HandleEAPOL-Logoff SelectHandle EAPOL-Logoffto enable handling of EAPOL-LOGOFFmessages. This option is
disabled by default.
IgnoreEAP ID during
negotiation
SelectIgnore EAP ID during negotiation to ignore EAP IDs during negotiation. This option is
disabled by default.
WPA-Fast-Handover Select this option to enable WPA-fast-handover on phonesthat support this feature. WAP
fast-handoveris disabled by default.
Disablerekey and
reauthenticationfor clients
oncal l
Thisfeature disables rekey and reauthentication for V oWLANcl ients. It is disabled by default,
meaning thatrekey and reauthentication is enabled.
NOTE:Thi soption m ayrequi re a license This option may require a license.
Checkcertificate comm on
name against AAAserver
Ifyou use client certificates for user authentication, enabl e this option to verify that the
certificate'scommon nam e existsin the server. This parameter is enabled by default in the
default-capand default-rap VPN profiles, anddisabled by default on all other VPN profil es.
In the CLI
The followingco mmandconfigures settings for an 8 02.1X authentication profiles. Individual parameters aredescribed in the previous table.
(host)(config) #aaa authentication dot1x {<profile>|countermeasures}
ca-cert <certificate>
clear
clone <profile>
eapol-logoff
framed-mtu <mtu>
heldstate-bypass-counter <number>
ignore-eap-id-match
ignore-eapolstart-afterauthentication
machine-authentication blacklist-on-failure|{cache-timeout <hours>}|enable|
{machine-default-role <role>}|{user-default-role <role>}
max-authentication-failures <number>
max-requests <number>
multicast-keyrotation
no ...
opp-key-caching
reauth-max <number>
reauthentication
server {server-retry <number>|server-retry-period <seconds>}
server-cert <certificate>