Users Guide

Table Of Contents
Configuring Mixed Authentication Modes
Use l2-auth-fail-through command to perform mixed authentication which includes both MAC and 802.1X
authentication. When MAC authentication fails, enable the l2-auth-fail-through command to perform
802.1X authentication.
By default the l2-auth-fail-through command is disabled.
Authentication 1 2 3 4 5 6
MAC
authentication
Success Success Success Fail Fail Fail
802.1X
authentication
Success Fail Success Fail
Association dynamic-
wep
No
Associatio
n
static-
wep
dynamic-
wep
No
Associatio
n
static-
wep
Role Assignment 802.1X MAC 802.1X logon
Table 68: Mixed Authentication Modes
Table 68 describes the different authentication possibilities
In the CLI
(host)(config) #aaa profile test
l2-auth-fail-through
Performing Advanced Configuration Options for 802.1X
This section describes advanced configuration options for 802.1X authentication.
Configuring Reauthentication with Unicast Key Rotation
When enabled, unicast and multicast keys are updated after each reauthorization. It is a best practice to
configure the time intervals for reauthentication, multicast key rotation, and unicast key rotation to be at least
15 minutes. Ensure that these intervals are mutually prime, and the factor of the unicast key rotation interval
and the multicast key rotation interval is less than the reauthentication interval.
Unicast key rotation depends upon both the AP/controller and wireless client behavior. It is known that some wireless
NICs have issues with unicast key rotation.
The following is an example of the parameters you can configure for reauthentication with unicast and
multicast key rotation:
l Reauthentication: Enabled
l Reauthentication Time Interval: 6011 Seconds
l Multicast Key Rotation: Enabled
l Multicast Key Rotation Time Interval: 1867 Seconds
l Unicast Key Rotation: Enabled
Dell Networking W-Series ArubaOS 6.5.x | User Guide 802.1X Authentication | 283