FlexAuth MAC Authentication Configuration

The following table applies to MAC authentication only.

Name, OID, and syntax

Access

Description

ruckusMacAuthPasswordFormat

snSwitch.44.1.3.1

Syntax: INTEGER { dashFormat(1),

colonFormat(2),

dotFormat(3),

normalFormat(4) }

Read-only

Specifies the format to be used for the MAC address, which is used as credential in MAC authentication.

Because MAC addresses are represented in different formats, all such formats are supported as given

in the following options:

(Use bullets for each of these options)

* dashFormat(1): Username or password is formatted as xx-xx-xx-xx-xx-xx.

* colonFormat(2): Username or password is formatted as xx:xx:xx:xx:xxxx.

* dotFormat(3): Username or password is formatted as xxxx.xxxx.xxxx.

* normalFormat(4): Username or password is formatted as xxxxxxxxxxxx.

The default value is normalFormat(4).

ruckusMacAuthPasswordOverride

snSwitch.44.1.3.2

Syntax: DisplayString

Read-only

Specifies the password to be used for all MAC authentication clients.

Normally, the length string is zero, which means the client MAC address is used as the password.

ruckusMacAuthDot1xOverride

snSwitch.44.1.3.3

Syntax: EnabledStatus

Read-only

Specifies if 802.1X authentication should be tried next when a client fails authentication with MAC-Authentication method.

This may be required when devices are Dot1x capable, authentication order is MAC-Auth followed by Dot1x, and authentication server is not configured with device profiles, instead it is configured with user profiles for the Dot1x to succeed.

The default value is disabled.

ruckusMacAuthDot1xEnable

snSwitch.44.1.3.4

Syntax: EnabledStatus

Read-only

Specifies if 802.1X authentication should be tried next when a client succeeds authentication with the MAC authentication method.

This may be required when devices are not IEEE 802.1X-capable, the authentication order is MAC authentication followed by IEEE 802.1X authentication, and the authentication server is not configured with user profiles. Instead, it is configured with device profiles, so MAC authentication can succeed.

The default value is enabled.