FlexAuth Dot1X configuration

The following table applies to Dot1X authentication only.

Name, OID, and syntax

Access

Description

ruckusDot1xQuietPeriod

snSwitch.44.1.2.1

Syntax: Unsigned32 (0..4294967295)

Read-only

When the RUCKUS device is unable to authenticate the client, the amount of time the RUCKUS device waits before trying again.

The default value is 60 seconds.

ruckusDot1xTxPeriod

snSwitch.44.1.2.2

Syntax: Unsigned32 (1..4294967295)

Read-only

When a client does not send back an Extensible Authentication Protocol (EAP)-response or identity frame, the amount of time the RUCKUS device waits before retransmitting the EAP-request or identity frame to the client.

The default value is 30 seconds.

ruckusDot1xSuppTimeout

snSwitch.44.1.2.3

Syntax: Unsigned32 (1..4294967295)

Read-only

When a supplicant or client does not respond to an EAP-request frame, the amount of time before the RUCKUS device retransmits the frame.

The default value is 30 seconds.

ruckusDot1xMaxReq

snSwitch.44.1.2.4

Syntax: Unsigned32 (1..10)

Read-only

The number of times the RUCKUS device retransmits an EAP-request or identity request frame if it does not receive an EAP-response or identity response frame from the client.

The default value is 2.

ruckusDot1xMaxReauthReq

snSwitch.44.1.2.5

Syntax: Unsigned32 (1..10)
Read-only

The number of re-authentication attempts that are permitted before the port becomes unauthorized.

The default value is 2.

ruckusDot1xGuestVlan

snSwitch.44.1.2.6

Syntax: VlanId

Read-only

This VLAN is used to place the clients when the supplicant or client times out because it is not capable of the IEEE 802.1X authentication protocol.

A value of zero for this object indicates no guest VLAN configured for the interface.

ruckusDot1xMacAuthOverride

snSwitch.44.1.2.7

Syntax: EnabledStatus

Read-only

Specifies if MAC authentication should be tried next when a client fails authentication with the IEEE 802.1X authentication method.

This may be required when devices are IEEE 802.1X-capable, but the authentication server is not configured with user profiles. Instead, it is configured with device profiles, so MAC authentication can succeed.

The default value is disabled.