FlexAuth REST Configuration

Configures, updates and deletes FlexAuth REST configuration. The URI to configure FlexAuth commands is:

https://<mgmt-ip>/restconf/data/authentication/config

The following are the list of supported CLIs for FlexAuth module:
  • Authentication (mode)
  • auth-default-vlan <id>

  • auth-order mac-auth dot1x

  • auth-fail-action restricted-vlan <vlan-id>

  • auth-timeout-action critical-vlan <id>

  • auth-timeout-action success

  • auth-timeout-action failure

  • dot1x enable

  • dot1x enable ether <1/1/1>

  • dot1x guest-vlan <guest-vlan >

  • dot1x port-control auto ethernet <1/1/1>

  • dot1x port-control force-authorized ethernet <1/1/1>

  • dot1x port-control force-unauthorized ethernet <1/1/1>

  • mac-authentication enable

  • mac-authentication enable ethernet <1/1/1>

  • mac-authentication dot1x-override

  • mac-authentication dot1x-disable

  • max-sessions <max-session>

  • re-authentication

  • restricted-vlan <vlan-id>

  • critical-vlan <vlan-id>

  • voice-vlan <vlan-id>

Supported HTTP Operations

GET request

curl -X GET https://<host>/restconf/data/authentication/config -u test:test1234 --insecure

curl -X GET https://<host>/restconf/data/authentication/config/dot1x -u test:test1234 --insecure

curl -X GET https://<host>/restconf/data/authentication/config/mac-authentication  -u test:test1234 --insecure

POST or PATCH request

curl -X PATCH -H "Content-Type: application/json" -d @input.json https://<host>/restconf/data/authentication/config -u super:sp-admin --insecure
file: input.json

{
    "config": {
        "max-sessions": 15,
        "re-authentication": true,
        "auth-default-vlan": 110,
        "restricted-vlan": 112,
        "critical-vlan":  113,
        "voice-vlan": 114
    }
} 

POST or PATCH request

curl -X POST  -H "Content-Type: application/json" -d @dot1x.json https://<host>/restconf/data/authentication/config -u test:test1234 --insecure

curl -X POST  -H "Content-Type: application/json" -d @mauth.json https://<host>/restconf/data/authentication/config -u test:test1234 --insecure
dot1x.json

{
    "dot1x": {
            "port-control": {
                "force-unauthorized": "ethernet 1/1/3"
            },
            "guest-vlan": "107",
            "ethernet": "ethernet 1/1/3",
            "enable": true
    }
}

mauth.json

{
     "mac-authentication": {
        "dot1x-override": true,
        "dot1x-disable": true,
        "ethernet": "ethernet 1/1/13",
        "enable":true
      }
}

curl -X PATCH  -H "Content-Type: application/json" -d @dot1x.json https://<host>/restconf/data/authentication/config/dot1x -u test:test1234 --insecure

cat dot1x.json                                                                                                            {
{
    "dot1x": {
        "guest-vlan": "107",
        "ethernet": "ethernet 1/1/3",
        "enable": true
    }
}

curl -X PATCH  -H "Content-Type: application/json" -d @port-control.json https://<host>/restconf/data/authentication/config/dot1x/port-control -u test:test1234 --insecure
cat port-control.json
{
    "port-control": {
        "force-authorized": "ethernet 1/1/3"
    }
}

curl -X PATCH  -H "Content-Type: application/json" -d @auth_order.json https://<host>/restconf/data/authentication/config -u test:test1234 --insecure
auth_order.json

{    
    "config": {
     "auth-order": {
        "mac-auth": "dot1x"
      }
    }
}
curl -X PATCH  -H "Content-Type: application/json" -d @fail_action.json https://<host>/restconf/data/authentication/config -u test:test1234 --insecure
fail_action.json

{
    "config": {
        "fail-action": {
            "fail-action": "restricted-vlan"
        }
    }
}
curl -X PATCH  -H "Content-Type: application/json" -d @time_out.json https://<host>/restconf/data/authentication/config -u test:test1234 --insecure
{
time_out.json
    "config": {
        "timeout-action":{
            "success": true
        }
    }
}

The following URI deletes all the configuration:

curl -X DELETE https://<host>/restconf/data/authentication/config -u test:test1234 --insecure   

The following URI deletes the MAC authentication container details:

curl -X DELETE https://<host>/restconf/data/authentication/config/mac-authentication -u test:test1234 --insecure       

The following URI deletes the port-control container in dot1x configuration:

curl -X DELETE https://<host>/restconf/data/authentication/config/dot1x/port-control -u test:test1234 --insecure   

The following URI deletes the entire dot1x container configuration:

curl -X DELETE https://<host>/restconf/data/authentication/config/dot1x -u test:test1234 --insecure    

The following URI deletes the auth-order container configuration:

curl -X DELETE https://<host>/restconf/data/authentication/config/auth-order -u test:test1234 --insecure      

The following URI deletes the auth-fail-action container configuration:

curl -X DELETE https://<host>/restconf/data/authentication/config/fail-action -u test:test1234 --insecure