FlexAuth Sessions

The following table applies to 802.1X authentication and MAC authentication sessions at the port level.

Name, OID, and syntax

Access

Description

ruckusAuthSessionTable

snSwitch.44.1.7.1

Syntax: SEQUENCE OF RuckusAuthSessionEntry

None

A table providing information about the FlexAuth sessions for each client at the port level in the RUCKUS device. This table contains entries for all the authenticated or failed clients on a given port.

Entries are created when clients are created and entries are cleared when the clients time out or log off.

ruckusAuthSessionEntry

snSwitch.44.1.7.1.1

Syntax: RuckusAuthSessionEntry

None An entry containing information about the FlexAuth session of a specified client on a port.
ruckusAuthSessionMac

snSwitch.44.1.7.1.1.1

Syntax: MacAddress

Read-only

Specifies the MAC address of the client (device or host) represented by this session entry.

ruckusAuthSessionVlan

snSwitch.44.1.7.1.1.2

Syntax: VlanId

Read-only

Specifies the VLAN represented by this session entry to which the client (device or host) belongs.

In case of voice phones, this VLAN is the voice VLAN (tagged). In all other cases, it is most likely an untagged VLAN, unless it is a tagged virtual machine client.

ruckusAuthSessionVlanType

snSwitch.44.1.7.1.1.3

Syntax: INTEGER

{ default(1),

retrict(2),

critical(3),

guest(4),

radius(5) }

Read-only

Describes the type of VLAN associated with the session:

  • default(1) - Default VLANs configured on RUCKUS device.
  • restrict(2) - Restricted VLAN as authentication failed.
  • critical(3) - Critical VLAN as authentication timed out.
  • guest(4) - Guest VLAN as client is not Dot1x capable.
  • radius(5) - RADIUS (auth) server assigned VLAN.
ruckusAuthSessionTaggedVlan

snSwitch.44.1.7.1.1.4

Syntax: VlanId

Read-only Tagged VLAN or voice VLAN sent by the RADIUS server. The port gets added to this VLAN to prepare the device to send tagged packets in case of phones.
ruckusAuthSessionUserName

snSwitch.44.1.7.1.1.5

Syntax: DisplayString

Read-only

Indicates the username associated with the client represented by this session.

In the case of 802.1X sessions, it is the username used by the user to log in to the network. In the case of MAC authentication, it is the MAC address or username assigned by the RADIUS server in the ACCESS-ACCEPT packet during authentication.

ruckusAuthSessionDeviceType

snSwitch.44.1.7.1.1.6

Syntax: INTEGER

{ phone(1),

wlanAP(2),

router(3),

bridge(4),

other(8) }

Read-only Describes the type of the client connected and authenticated on the port.
  • phone(1): description
  • wlanAP(2): description
  • router(3): description
  • bridge(4): description
  • other(8): description
ruckusAuthSessionMethod

snSwitch.44.1.7.1.1.7

Syntax: INTEGER

{ dot1x(1),

macAuth(2) }

Read-only

Specifies the authentication method used for authenticating the client on the session port. It is possible that both 802.1X authentication and MAC authentication are tried, and both either succeeded or failed. The resulting status is generally decided by the last method tried.

ruckusAuthSessionMode

snSwitch.44.1.7.1.1.8

Syntax: RuckusAuthMode

Read-only

Indicates the authentication mode applied for this client on the port.

ruckusAuthSessionStatus

snSwitch.44.1.7.1.1.9

Syntax: INTEGER

{ allowed(1),

blocked(2),

restrict(3),

critical(4),

guest(5),

other(6) }

Read-only

The authentication state of the session can take the following values:

  • allowed(1): Access is granted if client authentication is successful.
  • blocked(2): Access is denied if client authentication fails
  • restrict(3): Restricted access is allowed even if client authentication fails.
  • critical(4): Access is limited to critical operations if client authentication times out.
  • guest(5): Guest role access is allowed if the client is not 802.1X-capable
  • other(6): description

ruckusAuthSessionDot1xStatus

snSwitch.44.1.7.1.1.10

Syntax: Dot1xAuthState

Read-only

Indicates the state of 802.1X authentication, if the client is using 802.1X for authentication.

ruckusAuthSessionAgingType

snSwitch.44.1.7.1.1.11

Syntax: INTEGER

{ software(1),

hardware(2),

enabled(3),

disabled(4) }

Read-only

Indicates the aging status of the client session, which can be one of the following values:

  • software(1): The client MAC address entry is cleared because the entry timed out in hardware for the configured inactivity period and entered the software aging state.
  • hardware(2): The client MAC address has detected inactivity on the port and entered the hardware aging state.
  • enabled(3): Aging is enabled and no inactivity on the port for this client is detected and aging has not started.
  • disabled(4): Aging is disabled for this client and any inactivity period does not clear the session.
ruckusAuthSessionAge

snSwitch.44.1.7.1.1.12

Syntax: Unsigned32

Read-only

When the aging type is either software or hardware, this object indicates the time the session has been in that state. When the configured maximum time is reached, the aging state moves from hardware to software or the session is cleared. The unit is measured in seconds.

ruckusAuthSessionTimeout

snSwitch.44.1.7.1.1.15

Syntax: Unsigned32

Read-only

Specifies the maximum amount of time the session should exit before re-authenticating or terminating the sessions depending on another RADIUS attribute "Termination-Action". The unit is measured in seconds.

ruckusAuthSessionIdleTimeout

snSwitch.44.1.7.1.1.16

Syntax: Unsigned32

Read-only

Specifies the maximum amount of time after which the session is cleared when there is no traffic from the client. A value of "0" means the session never gets terminated due to inactivity. The unit is measured in seconds.

ruckusAuthSessionTime

snSwitch.44.1.7.1.1.17

Syntax: Unsigned32

Read-only

Indcates the session uptime since the session has been up or created. The unit is measured in seconds.

ruckusAuthSessionV4IngressAcl

snSwitch.44.1.7.1.1.18

Syntax: DisplayString

Read-only

Specifies the user access control list (ACL) applied in the ingress direction for the IPv4 traffic for this client on the port.

ruckusAuthSessionV4EgressAcl

snSwitch.44.1.7.1.1.19

Syntax: DisplayString

Read-only

Specifies the user access control list (ACL) applied in the egress direction for the IPv4 traffic for this client on the port.

ruckusAuthSessionV6IngressAcl

snSwitch.44.1.7.1.1.20

Syntax: DisplayString

Read-only

Specifies the user access control list (ACL) applied in the ingress direction for the IPv6 traffic for this client on the port.

ruckusAuthSessionV6EgressAcl

snSwitch.44.1.7.1.1.21

Syntax: DisplayString

Read-only

Specifies the user access control list (ACL) applied in the egress direction for the IPv6 traffic for this client on the port.

ruckusAuthSessionTxOctets

snSwitch.44.1.7.1.1.22

Syntax: Counter64

Read-only

Specifies the number of bytes sent for this session on the port.

ruckusAuthSessionRxOctets

snSwitch.44.1.7.1.1.23

Syntax: Counter64

Read-only

Specifies the number of bytes received for this session on the port.

ruckusAuthSessionTxPkts

snSwitch.44.1.7.1.1.24

Syntax: Counter64

Read-only

Specifies the number of bytes sent for this session on the port.

ruckusAuthSessionRxPkts

snSwitch.44.1.7.1.1.25

Syntax: Counter64

Read-only

Specifies the number of bytes received for this session on the port.

ruckusAuthSessionFailureReason

snSwitch.44.1.7.1.1.26

Syntax: DisplayString

Read-only

Specifies the internal failure reason for this client, such as memory allocation, RADIUS attribute parsing, RADIUS REJECT, and so on.

ruckusAuthSessionFlags

snSwitch.44.1.7.1.1.25

Syntax: BITS

{ staticAuthenticated(0),

taggedSession(1),

dot1xNonCapable(2),

dot1xEnabled(3),

masterMacAuth(4),

v4AclApplied(5),

v6AclApplied(6) }

Read-only

Describes various other parameters of client session by clubbing them together in one object for simplicity.

  • staticAuthenticated(0): Client is authenticated using configured auth-filters on the port, instead of a normal RADIUS server.
  • taggedSession(1): Client VLAN is tagged, which may indicate the client is a phone or tagged virtual machine.
  • dot1xNonCapable(2): Client is not 802.1X-capable.
  • dot1xEnabled(3): When MAC authentication succeeds, 802.1X should be tried depending on the default value (enable), configured value, or RADIUS attribute.
  • masterMacAuth(4): Indicates if this session is a Master session in the case of MAC authentication sessions, because there would be multiple sessions for MAC authentication, but there would be only one session visible
  • v4AclApplied(5): IPv4 ACL is applied for the client.
  • v6AclApplied(6): IPv6 ACL is applied for the client.

staticAuthenticated(0) - client is authenticated using configured auth-filters on the port, instead of normal RADIUS server

taggedSession(1) - client VLAN is tagged which may indicate the client as Phone or tagged virtual machine.

dot1xNonCapable(2) - client is not Dot1x capable.

dot1xEnabled(3) - Dot1x should be tried or not, when MAC-Auth succeeds depending on default value (enable), configured value or RADIUS attribute

masterMacAuth(4) - indicates if this session is Master session in case of MAC-Auth session, as there would be multiple sessions for MAC-Auth, whereas there would be only one session visible.

v4AclApplied(5) - IPv4 ACL is applied for the client.

v6AclApplied(6) - IPv6 ACL is applied for the client.