FlexAuth Port Configuration

The following table applies to 802.1X authentication and MAC authentication at the port level.

Name, OID, and syntax

Access

Description

ruckusAuthPortTable

snSwitch.44.1.5.1

Syntax: SEQUENCE OF RuckusAuthPortEntry

None

A table that allows configuration of FlexAuth including 802.1X authentication for a specified port. Most objects at the port level override the similarily configured objects at the global level.

An entry exists in this table for each configured with FlexAuth.

ruckusAuthPortEntry

snSwitch.44.1.5.1.1

Syntax: RuckusAuthPortEntry

None An entry of FlexAuth port configuration.
ruckusAuthPortEnable

snSwitch.44.1.4.5.1.1.1

Syntax: BITS { dot1x(0),

macAuth(1) }

Read-only

Specifies authentication methods that are enabled on this port. Unless the method is enabled globally, the same cannot be enabled at the port level. A bit field of "1" indicates enabled, otherwise disabled.

ruckusAuthPortDot1xControl

snSwitch.44.1.4.5.1.1.2

Syntax: INTEGER

{ forceUnauthorized(1),

controlauto(2),

forceAuthorized(3),

other(4) }

Read-only

Specifies the 802.1X operating mode for this port, when 802.1X authentication is enabled.

  • force-unauthorized(1): The controlled port is placed unconditionally in the unauthorized state.
  • control-auto(2): The controlled port is unauthorized until authentication takes place between the client and server.
  • force-authorized(3): The controlled port is placed unconditionally in the authorized state.
  • other(4): Not initialized.

    The default value is force-unauthorized(1).

ruckusAuthPortDefaultVlan

snSwitch.44.1.4.5.1.1.3

Syntax: VlanId

Read-only

This default VLAN is used to place the port. This VLAN acts as a VLAN for the clients to belong to when the authentication server does not assign any VLANs.

A value of zero for this object indicates no default VLAN is configured for this port on this RUCKUS device and therefore, the global default VLAN is used.

ruckusAuthPortVoiceVlan

snSwitch.44.1.4.5.1.1.4

Syntax: VlanId

Read-only

This voice VLAN is used to advertise through LLDP or CDP on this port when connected devices are detected as phones and the authentication server does not assign any voice VLAN.

A value of zero for this object indicates no voice VLAN is configured for this port on this RUCKUS device and therefore, the global voice VLAN is used.

ruckusAuthPortCriticalVlan

snSwitch.44.1.4.5.1.1.5

Syntax: VlanId

Read-only

This VLAN is used to place the clients of this port when the authentication server times out and the port auth-timeout-action is configured as "critical" and therefore, the clients have limited access.

A value of zero for this object indicates no critical VLAN is configured for this port on this RUCKUS device and therefore, the global critical VLAN is used.

ruckusAuthPortRestrictVlan

snSwitch.44.1.4.5.1.1.6

Syntax: VlanId

Read-only This VLAN is used to place the clients of this port, when the clients fail the authentication and the auth-failure-action is configured as 'restrict'. Therefore, the clients have limited access.

A value of zero for this object indicates no restrict VLAN is configured for this port on this RUCKUS device and therefore, the global restrict VLAN is used.

ruckusAuthPortMode

snSwitch.44.1.4.5.1.1.7

Syntax: RuckusAuthMode

Read-only

Specifies the authentication mode for this port. This overrides the globally configured value.

The default value is singleUntagged.

ruckusAuthPortMethods

snSwitch.44.1.4.5.1.1.8

Syntax: RuckusAuthOrder

Read-only

Specifies authentication methods to be attempted in series of methods for this port. This overrides the globally configured value.

The default value is dot1xMauth.

ruckusAuthPortMaxSessions

snSwitch.44.1.4.5.1.1.9

Syntax: Unsigned32 (1..1024)

Read-only

Specifies the maximum number of authenticated clients allowed on this port. This does not include the clients allowed due to authentication failure and timeout policies.

The default value is 2.

ruckusAuthPortFailAction

snSwitch.44.1.4.5.1.1.10

Syntax: RuckusAuthFailAction

Read-only

Specifies the action to be taken on this port. This overrides the globally set value.

The default value is blockTraffic.

ruckusAuthPortTimeoutAction

snSwitch.44.1.4.5.1.1.11

Syntax: RuckusAuthTimeoutAction

Read-only

Specifies the action to be taken on this port, when the authentication server times out for various reasons like server busy, network access, etc. This overrides the globally set value.

The default value is other.

ruckusAuthPortReauthTimeout

snSwitch.44.1.4.5.1.1.12

Syntax: Unsigned32 (1..4294967295)

Read-only

This value specifies how often to re-authenticates clients of this port when the clients were allowed due to authentication server timeout. Value of 0 disables the re-authentication.

The default value is 300 seconds.

ruckusAuthPortAging

snSwitch.44.1.4.5.1.1.13

Syntax: RuckusAuthAging

Read-only

This value specifies if denied and permitted sessions are enabled or disabled for aging on this port. This overrides the global value.

ruckusAuthPortAllowTagged

snSwitch.44.1.4.5.1.1.14

Syntax: EnabledStatus

Read-only

This value specifies if denied and permitted sessions are enabled or disabled for aging on this port. A bit

field of '1' indicates enabled, otherwise disabled.

The default value is disabled.

ruckusAuthPortSourceGuard

snSwitch.44.1.4.5.1.1.15

Syntax: EnabledStatus

Read-only

Source guard enabling ensures that the client IP address needs to be learned and allow the packets matching that IP address only. This is implied when user ACLs are applied on the port.

The default value is disabled.

ruckusAuthPortDosAttacks

snSwitch.44.1.4.5.1.1.16

Syntax: EnabledStatus

Read-only

Specifies to prevent or allow Denial of Service (DoS) attacks on this port. Sending packets from different clients (MAC addresses) continuously causes DOS, because the clients are not allowed without authentication and may cause exhaustion of system resources.

The default value is disabled.

ruckusAuthPortDosAttackLimit

snSwitch.44.1.4.5.1.1.17

Syntax: Unsigned32 (1..65535)

Read-only

Specifies the maximum number of clients to be allowed at any time without authentication. IIf the number of clients pending authentication exceed the configured limit (as specified by this object), the port shuts down to prevent DoS attacks.

The default value is 512.