FlexAuth Global Configuration

The following table presents management information for configuration or querying of Flexible Authentication (consisting of IEEE 802.1X authentication, MAC authentication, and Web authentication). The management information is grouped into the following MIBs:

  • Global-level Auth configuration
  • Global-level Dot1x configuration
  • Global-level Mac authentication configuration
  • Global-level Web authentication configuration
  • Port-level Auth configuration
  • Auth session information
  • Auth session statistics information

The following table applies to Dot1x and MAC authentication also.

Name, OID, and syntax

Access

Description

ruckusAuthDefaultVlan

snSwitch.44.1.1.1

Syntax: VlanId

Read-only

The default VLAN is used to place all the FlexAuth-enabled ports, so this VLAN acts as a VLAN for the clients to belong to when the authentication server does not assign any VLANs.

A value of zero for this object indicates no default VLAN configured for this RUCKUS device.

ruckusAuthVoiceVlan

snSwitch.44.1.1.2

Syntax: VlanId

Read-only

The voice VLAN is used to advertise through LLDP or CDP on the ports, when connected devices are detected as phones and the authentication server does not assign any voice VLAN.

A value of zero for this object indicates no voice VLAN configured for this RUCKUS device.

ruckusAuthCriticalVlan

snSwitch.44.1.1.3

Syntax: VlanId

Read-only

This VLAN is used to place the clients, when the authentication server times out and the timeout action is configured as "critical", so the clients have limited access.

A value of zero for this object indicates no critical VLAN is configured for this RUCKUS device.

ruckusAuthRestrictVlan

snSwitch.44.1.1.4

Syntax: VlanId

Read-only

This VLAN is used to place the clients when the clients fail the authentication and the failure action is configured as "restrict" so that the clients have limited access.

A value of zero for this object indicates no restrict VLAN configured for this RUCKUS device.

ruckusAuthEnable

snSwitch.44.1.1.5

Syntax: BITS {dot1x(0), macAuth(1)}
Read-only

Specifies the authentication methods are enabled globally. Unless the method is enabled globally, the same cannot be enabled at the port level.

A bit field of "1" indicates enabled, otherwise disabled.

ruckusAuthMode

snSwitch.44.1.1.6

Syntax: RuckusAuthMode

Read-only

Specifies the authentication mode for all the FlexAuth-enabled ports.

The default mode is singleUntagged.

ruckusAuthMethods

snSwitch.44.1.1.7

Syntax: RuckusAuthOrder

Read-only

Specifies which authentication methods to be attempted in a series of methods for all FlexAuth-enabled ports.

The default method is dot1xMauth.

ruckusAuthMaxSessions

snSwitch.44.1.1.8

Syntax: Unsigned32 (1..1024)

Read-only

Specifies the maximum number of authenticated clients allowed on a port. This does not include the clients allowed due to authentication failure and timeout policies.

The default value is 2.

ruckusAuthFailAction

snSwitch.44.1.1.9

Syntax: RuckusAuthFailAction

Read-only

Specifies the action to be taken when the clients fail the authentication.

The default action is blockTraffic.

ruckusAuthTimeoutAction

snSwitch.44.1.1.10

Syntax: RuckusAuthTimeoutAction

Read-only

Specifies the action to be taken when the authentication server times out.

The default action is "other".

ruckusAuthReauthEnable

snSwitch.44.1.1.11

Syntax: EnabledStatus

Read-only

The reauthentication control for all the FlexAuth-enabled ports.

Setting this object to "enabled" causes every FlexAuth-enabled port to re-authenticate the devices connecting to the port after every period of time specified by the "ruckusAuthReauthPeriod" object.

Setting this object to "disabled" disables the reauthentication.

ruckusAuthReauthPeriod

snSwitch.44.1.1.12

Syntax: Unsigned32 (1..4294967295)

Read-only

Specifies how often to re-authenticates clients when periodic re-authentication is enabled.

The default value is 3600 seconds.

ruckusAuthReauthTimeout

snSwitch.44.1.1.13

Syntax: Unsigned32 (1..4294967295)

Read-only

Specifies how often to re-authenticates clients when the clients were allowed due to authentication server timeout.

Value of "0"disables the re-authentication.

The default value is 300 seconds.

ruckusAuthIdleTimeout

snSwitch.44.1.1.14

Syntax: Unsigned32 (1..65535)

Read-only

Specifies the time to keep the sessions in the RUCKUS device after the inactivity detection time expired in the hardware. If the clients start the traffic in this time, they need not authenticate again. Otherwise, they would have to authentication once the session gets deleted.

This can be set from the authentication server for each client and a value of "0" can disable the aging.

The default value is 120 seconds.

ruckusAuthDeniedTimeout

snSwitch.44.1.1.15

Syntax: Unsigned32 (1..65535)

Read-only

Specifies the time to keep the denied sessions in the RUCKUS device for the clients that are blocked because they failed authentication. The device authenticates when the clients start the traffic again.

The default value is 70 seconds.

ruckusAuthAging

snSwitch.44.1.1.16

Syntax: RuckusAuthAging

Read-only

Specifies if denied and permitted sessions are enabled or disabled for aging. Aging is enabled by default.

ruckusAuthDefaultV4IngressAcl

snSwitch.44.1.1.17

Syntax: DisplayString

Read-only Specifies the default user Access Control List (ACL) applied in the ingress direction for the IPv4 traffic sessions when ACLs are not dynamically assigned through RADIUS.
ruckusAuthDefaultV4EgressAcl

snSwitch.44.1.1.18

Syntax: DisplayString

Read-only Specifies the default user Access Control List (ACL) applied in the egress direction for the IPv4 traffic sessions when ACLs are not dynamically assigned through RADIUS.
ruckusAuthDefaultV6IngressAcl

snSwitch.44.1.1.19

Syntax: DisplayString

Read-only Specifies the default user Access Control List (ACL) applied in the ingress direction for the IPv6 traffic sessions when ACLs are not dynamically assigned through RADIUS.
ruckusAuthDefaultV6EgressAcl

snSwitch.44.1.1.20

Syntax: DisplayString

Read-only Specifies the default user Access Control List (ACL) applied in the egress direction for the IPv6 traffic sessions when ACL are not dynamically assigned through RADIUS.