FlexAuth Port Auth-Filter Configuration

The following table applies to IEEE 802.1X authentication and MAC authentication at the port level only.

Name, OID, and syntax

Access

Description

ruckusAuthPortFilterTable

snSwitch.44.1.6.1

Syntax: SEQUENCE OF RuckusAuthPortFilterEntry

None

This table allows configuration of FlexAuth auth-filters which are applied to statically authenticate the clients without the need for a RADIUS server authenticator. This helps to permit or deny predefined clients and save time in authentication. An entry exists in this table for every auth-filter bound on the port.

ruckusAuthPortFilterEntry

snSwitch.44.1.6.1.1

Syntax: RuckusAuthPortFilterEntry

None An entry of FlexAuth port auth-filter configuration.
ruckusAuthPortFilterId

snSwitch.44.1.6.1.1.1

Syntax: Integer

None An index into the auth-filter table.
ruckusAuthPortFilterMac

snSwitch.44.1.6.1.1.2

Syntax: MacAddress

Read-only

Specifies the MAC address of the filter to match the clients authenticating through static authentication.

ruckusAuthPortFilterMask

snSwitch.44.1.6.1.1.3

Syntax: MacAddress

Read-only

Specifies the mask of the filter for matching the incoming clients through static authentication.

The mask is applied on the MAC address provided in the filter and the client MAC address before the matching decision is made.

ruckusAuthPortFilterVlan

snSwitch.44.1.6.1.1.4

Syntax: VlanId

Read-only

Specifies the VLAN which should be used to place the authenticating client after the matching is done. This VLAN applies only when the action is permitted. Denied clients are always blocked.

ruckusAuthPortFilterAction

snSwitch.44.1.6.1.1.5

Syntax: INTEGER { permit(1),

deny(2) }

Read-only

Specifies the action to be performed when this filter is applied on the authenticating client and matching occurs.

  • permit(1) - allow the client in specified VLAN
  • deny(2) - block the client.