Did you enable EAP Termination?
yes enable in profile
Did you install the EAP-GTC supplicant on the device?
yes
Does the device trust the controller's internal certificate?
we have test with trust and without trust but not help
To be honest, EAP-Terminaton, PEAP with LDAP is not really recommended. A legitimate radius server is recommended.
i havenot raduis server in the network
i have asked TAC if the LDAP-AD has any kind of limitation and not recomndadtion but he told me no its easy and no issue while intergration with it .
this is a dot1x profile configuration
(Aruba-VMC) *[mynode] #show aaa authentication dot1x test
802.1X Authentication Profile "test"
------------------------------------
Parameter Value
--------- -----
Max authentication failures 0
Interval between Identity Requests 5 sec
Quiet Period after Failed Authentication 30 sec
Reauthentication Interval 86400 sec
Use Server provided Reauthentication Interval Disabled
Use the termination-action attribute from the Server Disabled
Multicast Key Rotation Time Interval 1800 sec
Unicast Key Rotation Time Interval 900 sec
Authentication Server Retry Interval 5 sec
Authentication Server Retry Count 3
Framed MTU 1100 bytes
Max number of requests sent during an Auth attempt 5
Max Number of Reauthentication Attempts 3
Maximum number of times Held State can be bypassed 0
Dynamic WEP Key Message Retry Count 1
Dynamic WEP Key Size 128 bits
Interval between WPA/WPA2/WPA3 Key Messages 1000 msec
Delay between EAP-Success and WPA2/WPA3 Unicast Key Exchange 0 msec
--More-- (q) quit (u) pageup (/) search (n) repeat Delay between WPA/WPA2/WPA3 Unicast Key and Group Key Exchange 0 msec
Time interval after which the PMKSA will be deleted 8 hr(s)
Delete Keycache upon user deletion Disabled
WPA/WPA2/WPA3 Key Message Retry Count 3
Multicast Key Rotation Disabled
Unicast Key Rotation Disabled
Reauthentication Disabled
Opportunistic Key Caching Enabled
Validate PMKID Enabled
Use Session Key Disabled
Use Static Key Disabled
xSec MTU 1300 bytes
Termination Enabled
Termination EAP-Type eap-peap
Termination Inner EAP-Type eap-gtc
Enforce Suite-B 128 bit or more security level Authentication Disabled
Enforce Suite-B 192 bit security level Authentication Disabled
Token Caching Disabled
Token Caching Period 24 hr(s)
CA-Certificate N/A
Server-Certificate default
TLS Guest Access Disabled
Ignore EAPOL-START after authentication Disabled
--More-- (q) quit (u) pageup (/) search (n) repeat Handle EAPOL-Logoff Disabled
Ignore EAP ID during negotiation. Disabled
WPA-Fast-Handover Disabled
Check certificate common name against AAA server Enabled