thank you for all your info.
i have a question in aruba switch can this config to config in range? try to combine all this AAA into port range not every port. help
aaa server-group radius "ClearPass" host 10.4.1.100
aaa server-group radius "ClearPass" host 10.19.2.100
aaa accounting update periodic 10
aaa accounting commands stop-only tacacs
aaa accounting exec start-stop tacacs
aaa accounting network start-stop radius server-group "ClearPass"
aaa accounting system stop-only tacacs
aaa authorization commands tacacs
aaa authorization user-role enable download
aaa authentication login privilege-mode
aaa authentication console login tacacs
aaa authentication console enable tacacs
aaa authentication telnet login tacacs
aaa authentication telnet enable tacacs
aaa authentication web login radius local
aaa authentication web enable radius local
aaa authentication ssh login tacacs
aaa authentication ssh enable tacacs
aaa authentication port-access eap-radius server-group "ClearPass"
aaa authentication mac-based chap-radius server-group "ClearPass"
aaa port-access authenticator 1 tx-period 10
aaa port-access authenticator 1 supplicant-timeout 10
aaa port-access authenticator 2 tx-period 10
aaa port-access authenticator 2 supplicant-timeout 10
aaa port-access authenticator 3 tx-period 10
aaa port-access authenticator 3 supplicant-timeout 10
aaa port-access authenticator 4 tx-period 10
aaa port-access authenticator 4 supplicant-timeout 10
aaa port-access authenticator 5 tx-period 10
aaa port-access authenticator 5 supplicant-timeout 10
aaa port-access authenticator 6 tx-period 10
aaa port-access authenticator 6 supplicant-timeout 10
aaa port-access authenticator 7 tx-period 10
aaa port-access authenticator 7 supplicant-timeout 10
aaa port-access authenticator 8 tx-period 10
aaa port-access authenticator 8 supplicant-timeout 10
aaa port-access authenticator 9 tx-period 10
aaa port-access authenticator 9 supplicant-timeout 10
aaa port-access authenticator 10 tx-period 10
aaa port-access authenticator 10 supplicant-timeout 10
aaa port-access authenticator 11 tx-period 10
aaa port-access authenticator 11 supplicant-timeout 10
aaa port-access authenticator 12 tx-period 10
aaa port-access authenticator 12 supplicant-timeout 10
aaa port-access authenticator 13 tx-period 10
aaa port-access authenticator 13 supplicant-timeout 10
aaa port-access authenticator 14 tx-period 10
aaa port-access authenticator 14 supplicant-timeout 10
aaa port-access authenticator 15 tx-period 10
aaa port-access authenticator 15 supplicant-timeout 10
aaa port-access authenticator 16 tx-period 10
aaa port-access authenticator 16 supplicant-timeout 10
aaa port-access authenticator 17 tx-period 10
aaa port-access authenticator 17 supplicant-timeout 10
aaa port-access authenticator 18 tx-period 10
aaa port-access authenticator 18 supplicant-timeout 10
aaa port-access authenticator 19 tx-period 10
aaa port-access authenticator 19 supplicant-timeout 10
aaa port-access authenticator 20 tx-period 10
aaa port-access authenticator 20 supplicant-timeout 10
aaa port-access authenticator 21 tx-period 10
aaa port-access authenticator 21 supplicant-timeout 10
aaa port-access authenticator 22 tx-period 10
aaa port-access authenticator 22 supplicant-timeout 10
aaa port-access authenticator 23 tx-period 10
aaa port-access authenticator 23 supplicant-timeout 10
aaa port-access authenticator 24 tx-period 10
aaa port-access authenticator 24 supplicant-timeout 10
aaa port-access authenticator 25 tx-period 10
aaa port-access authenticator 25 supplicant-timeout 10
aaa port-access authenticator 26 tx-period 10
aaa port-access authenticator 26 supplicant-timeout 10
aaa port-access authenticator 28 tx-period 10
aaa port-access authenticator 28 supplicant-timeout 10
aaa port-access authenticator 30 tx-period 10
aaa port-access authenticator 30 supplicant-timeout 10
aaa port-access authenticator 31 tx-period 10
aaa port-access authenticator 31 supplicant-timeout 10
aaa port-access authenticator 32 tx-period 10
aaa port-access authenticator 32 supplicant-timeout 10
aaa port-access authenticator 33 tx-period 10
aaa port-access authenticator 33 supplicant-timeout 10
aaa port-access authenticator 34 tx-period 10
aaa port-access authenticator 34 supplicant-timeout 10
aaa port-access authenticator 35 tx-period 10
aaa port-access authenticator 35 supplicant-timeout 10
aaa port-access authenticator 36 tx-period 10
aaa port-access authenticator 36 supplicant-timeout 10
aaa port-access authenticator 37 tx-period 10
aaa port-access authenticator 37 supplicant-timeout 10
aaa port-access authenticator 38 tx-period 10
aaa port-access authenticator 38 supplicant-timeout 10
aaa port-access authenticator 39 tx-period 10
aaa port-access authenticator 39 supplicant-timeout 10
aaa port-access authenticator 40 tx-period 10
aaa port-access authenticator 40 supplicant-timeout 10
aaa port-access authenticator 41 tx-period 10
aaa port-access authenticator 41 supplicant-timeout 10
aaa port-access authenticator 42 tx-period 10
aaa port-access authenticator 42 supplicant-timeout 10
aaa port-access authenticator 43 tx-period 10
aaa port-access authenticator 43 supplicant-timeout 10
aaa port-access authenticator 44 tx-period 10
aaa port-access authenticator 44 supplicant-timeout 10
aaa port-access authenticator active
aaa port-access mac-based 1-26,28,30-44
aaa port-access mac-based 1 addr-limit 2
aaa port-access mac-based 2 addr-limit 2
aaa port-access mac-based 3 addr-limit 2
aaa port-access mac-based 4 addr-limit 2
aaa port-access mac-based 5 addr-limit 2
aaa port-access mac-based 6 addr-limit 2
aaa port-access mac-based 7 addr-limit 2
aaa port-access mac-based 8 addr-limit 2
aaa port-access mac-based 9 addr-limit 2
aaa port-access mac-based 10 addr-limit 2
aaa port-access mac-based 11 addr-limit 2
aaa port-access mac-based 12 addr-limit 2
aaa port-access mac-based 13 addr-limit 2
aaa port-access mac-based 14 addr-limit 2
aaa port-access mac-based 15 addr-limit 2
aaa port-access mac-based 16 addr-limit 2
aaa port-access mac-based 17 addr-limit 2
aaa port-access mac-based 18 addr-limit 2
aaa port-access mac-based 19 addr-limit 2
aaa port-access mac-based 20 addr-limit 2
aaa port-access mac-based 21 addr-limit 2
aaa port-access mac-based 22 addr-limit 2
aaa port-access mac-based 23 addr-limit 2
aaa port-access mac-based 24 addr-limit 2
aaa port-access mac-based 25 addr-limit 2
aaa port-access mac-based 26 addr-limit 2
aaa port-access mac-based 28 addr-limit 2
aaa port-access mac-based 30 addr-limit 2
aaa port-access mac-based 31 addr-limit 2
aaa port-access mac-based 32 addr-limit 2
aaa port-access mac-based 33 addr-limit 2
aaa port-access mac-based 34 addr-limit 2
aaa port-access mac-based 35 addr-limit 2
aaa port-access mac-based 36 addr-limit 2
aaa port-access mac-based 37 addr-limit 2
aaa port-access mac-based 38 addr-limit 2
aaa port-access mac-based 39 addr-limit 2
aaa port-access mac-based 40 addr-limit 2
aaa port-access mac-based 41 addr-limit 2
aaa port-access mac-based 42 addr-limit 2
aaa port-access mac-based 43 addr-limit 2
aaa port-access mac-based 44 addr-limit 2
Original Message:
Sent: Oct 28, 2019 10:22 AM
From: Renier De Witte
Subject: Remove All AAA Config From a Port
Dear all,
whats the best practice to remove all AAA config from a profile.
the NO command for the authenticon ( mac/authenticator works) pure functional works but i can remove the following settings
- aaa port-access authenticator tx-period 10
aaa port-access authenticator supplicant-timeout 10
aaa port-access authenticator client-limit 10
aaa port-access mac-based addr-limit 10
Thanks
#2930F