802.1X authentication scalar group types

The 802.1X authentication scalar group provides information that is displayed in the outputs of the following CLI commands:

  • show dot1x
  • show dot1x configuration all
  • show dot1x configuration ethernet port
Note: The following sections present the SNMP MIB objects for 802.1X authentication. These MIB objects are supported on the Brocade ICX devices.

Name, OID, and syntax

Access

Description

brcdDot1xAuthGlobalConfigQuietperiod

brcdIp.1.1.3.38.1.1

Syntax: Unsigned32

Read-write

If the RUCKUS device is unable to authenticate a client, this object shows the amount of time, in seconds, the RUCKUS device waits before it retries to authenticate that client.

The allowed range is from 1 through 4294967294.

Default: 60 seconds

brcdDot1xAuthGlobalConfigTxPeriod

brcdIp.1.1.3.38.1.2

Syntax: Unsigned32

Read-write

When a client does not return an Extensible Authentication Protocol (EAP) response or identity frame, this object shows the amount of time, in seconds, the RUCKUS device waits before retransmitting the EAP-request or identity frame to the client.

The allowed range is from 1 through 4294967294.

Default: 30 seconds

brcdDot1xAuthGlobalConfigSuppTimeOut

brcdIp.1.1.3.38.1.3

Syntax: Unsigned32

Read-write

When a supplicant (client) does not respond to an EAP-request frame, this object shows the amount of time, in seconds, before the RUCKUS device retransmits the frame.

The allowed range is from 1 through 4294967294.

Default: 30 seconds

brcdDot1xAuthGlobalConfigAuthServerTimeOut

brcdIp.1.1.3.38.1.4

Syntax: Unsigned32

Read-write

When the authentication server (RADIUS) does not respond to a message sent from the client, this object shows the amount of time, in seconds, before the RUCKUS device retransmits the message.

The allowed range is from 1 through 4294967294.

Default: 30 seconds

brcdDot1xAuthGlobalConfigMaxReq

brcdIp.1.1.3.38.1.5

Syntax: Unsigned32

Read-write

The number of times the RUCKUS device retransmits an EAP-request or identity request frame if it does not receive an EAP-response or identity response frame from a client.

Default: 2 times

brcdDot1xAuthGlobalConfigReAuthMax

brcdIp.1.1.3.38.1.6

Syntax: Unsigned32

Read-write

The number of reauthentication attempts that are permitted before the port becomes unauthorized.

Default: 2 times

brcdDot1xAuthGlobalConfigReAuthPeriod

brcdIp.1.1.3.38.1.7

Syntax: Unsigned32

Read-write

How often (number of seconds) the device automatically reauthenticates clients when periodic reauthentication is enabled.

The allowed range is from 1 through 4294967294.

Default: 3600 seconds

brcdDot1xAuthGlobalConfigProtocolVersion

brcdIp.1.1.3.38.1.8

Syntax: Unsigned32

Read-only

The EAP protocol version.

brcdDot1xAuthGlobalConfigTotalPortsEnabled

brcdIp.1.1.3.38.1.9

Syntax: Unsigned32

Read-only

The total number of ports that have 802.1x enabled.

brcdDot1xAuthGlobalConfigReauthStatus

brcdIp.1.1.3.38.1.10

Syntax: EnabledStatus

Read-write

Enables or disables reauthentication globally.

Default: disabled

brcdDot1xAuthGlobalConfigMacSessionMaxAge

brcdIp.1.1.3.38.1.11

Syntax: Unsigned32

Read-write

The maximum age of the 802.1x MAC session.

A value from 0 through 65535.

brcdDot1xAuthGlobalConfigNoAgingDeniedSessions

brcdIp.1.1.3.38.1.12

Syntax: EnabledStatus

Read-write

Enables or disables mac-session-no aging for denied sessions.

Default: disabled

brcdDot1xAuthGlobalConfigNoAgingPermittedSessions

brcdIp.1.1.3.38.1.13

Syntax: EnabledStatus

Read-write

Enables or disables mac-session-no aging for permitted sessions.

Default: disabled

brcdDot1xAuthGlobalConfigAuthFailAction

brcdIp.1.1.3.38.1.14

Syntax: Integer

Read-write

Configures the action to take when the authentication fails:

  • blockTraffic(1)
  • restrictedVlan(2)