Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 60

Save., Advanced Authentication, Profiles > AAA, Authentication Timers, RADIUS Client

Page 60 highlights

Table 10 Profiles > AAA > Advanced Authentication Profile Settings Field Default Description Authentication Timers User Idle Timeout 300 seconds Maximum period, in seconds, after which a client is considered idle if there is no user traffic from the client. The timeout period is reset if there is a user traffic. After this timeout period has elapsed, the controller sends probe packets to the client; if the client responds to the probe, it is considered active and the User Idle Timeout is reset (an active client that is not initiating new sessions is not removed). If the client does not respond to the probe, it is removed from the system. Range: 30 to 15300 seconds Fast Aging of Multiple No Instances of User When this feature is enabled, the controller actively sends probe packets to all users with the same MAC address but different IP addresses. The users that fail to respond are purged from the system. This command enables quick detection of multiple instances of the same MAC address in the user table and removal of an "old" IP address. This can occur when a client (or an AP connected to an untrusted port on the controller) changes its IP address. Dead Time for down 10 minutes Authentication Server (0- 60 min) Maximum period, in minutes, that the controller considers an unresponsive authentication server to be "out of service". This timer is only applicable if there are two or more authentication servers configured on the controller. If there is only one authentication server configured, the server is never considered out of service and all requests are sent to the server. If one or more backup servers are configured and a server is unresponsive, it is marked as out of service for the dead time; subsequent requests are sent to the next server on the priority list for the duration of the dead time. If the server is responsive after the dead time has elapsed, it can take over servicing requests from a lowerpriority server; if the server continues to be unresponsive, it is marked as down for the dead time. Range: 0-50 Unauthenticated User Lifetime (0-255 min) 5 minutes Maximum time, in minutes, unauthenticated clients are allowed to remain logged on. Range: 0-255 RADIUS Client RFC 3576 Server UDP 3799 Port (1-65535) Configures the UDP port to receive requests from a RADIUS server that can send user disconnect and change-of-authorization messages, as described in RFC 3576, "Dynamic Authorization Extensions to Remote Dial In User Service (RADIUS)". NOTE: This parameter can only be used on the master controller. DNS Query Interval DNS Query Interval (1- 15 1440 min) If you define a RADIUS server using the FQDN of the server rather than its IP address, the controller will periodically generate a DNS request and cache the IP address returned in the DNS response. By default, DNS requests are sent every 15 minutes 3. Select Add or Save. The added or edited Advanced Authentication profile appears on the Profiles > AAA page. 60 | Dell PowerConnect W Configuration Reference Dell PowerConnect W AirWave 7.2 | Configuration Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

60
|
Dell PowerConnect W Configuration Reference
Dell PowerConnect W AirWave 7.2
| Configuration Guide
3.
Select
Add
or
Save.
The added or edited
Advanced Authentication
profile appears on the
Profiles > AAA
page.
Authentication Timers
User Idle Timeout
300 seconds
Maximum period, in seconds, after which a client is considered idle if there is no
user traffic from the client.
The timeout period is reset if there is a user traffic. After this timeout period has
elapsed, the controller sends probe packets to the client; if the client responds to the
probe, it is considered active and the User Idle Timeout is reset (an active client that
is not initiating new sessions is not removed). If the client does not respond to the
probe, it is removed from the system.
Range: 30 to 15300 seconds
Fast Aging of Multiple
Instances of User
No
When this feature is enabled, the controller actively sends probe packets to all users
with the same MAC address but different IP addresses. The users that fail to respond
are purged from the system. This command enables quick detection of multiple
instances of the same MAC address in the user table and removal of an “old” IP
address. This can occur when a client (or an AP connected to an untrusted port on
the controller) changes its IP address.
Dead Time for down
Authentication Server (0-
60 min)
10 minutes
Maximum period, in minutes, that the controller considers an unresponsive
authentication server to be “out of service”.
This timer is only applicable if there are two or more authentication servers
configured on the controller. If there is only one authentication server configured,
the server is never considered out of service and all requests are sent to the server.
If one or more backup servers are configured and a server is unresponsive, it is
marked as out of service for the dead time; subsequent requests are sent to the next
server on the priority list for the duration of the dead time. If the server is responsive
after the dead time has elapsed, it can take over servicing requests from a lower-
priority server; if the server continues to be unresponsive, it is marked as down for
the dead time.
Range: 0–50
Unauthenticated User
Lifetime (0-255 min)
5 minutes
Maximum time, in minutes, unauthenticated clients are allowed to remain
logged on.
Range: 0–255
RADIUS Client
RFC 3576 Server UDP
Port (1-65535)
3799
Configures the UDP port to receive requests from a RADIUS server that can send
user disconnect and change-of-authorization messages, as described in RFC 3576,
“Dynamic Authorization Extensions to Remote Dial In User Service (RADIUS)”.
NOTE:
This parameter can only be used on the master controller.
DNS Query Interval
DNS Query Interval (1-
1440 min)
15
If you define a RADIUS server using the FQDN of the server rather than its IP
address, the controller will periodically generate a DNS request and cache the IP
address returned in the DNS response. By default, DNS requests are sent every 15
minutes
Table 10
Profiles > AAA > Advanced Authentication Profile Settings
Field
Default
Description