sometimes you need a smaller size < 1000 bytes for radius fragmentation (because of udp fragmentation)

##############
aruba cx switches
##############
>> on aruba cx switch you can make the following setting:
aaa authentication port-access dot1x authenticator
eap-tls-fragement towards-server 900
enable

##############
aruba os / former procurve switches
##############
syntax:
aaa port-access authenticator eap-tls-fragment towards-server <max-fragment-size>
- see also: https://arubanetworking.hpe.com/techdocs/AOS-S/16.11/ASG/WC/content/common%20files/cnf-eap-tls-fra-siz.htm?Highlight=eap%20fragment


##############
Aruba Central / Cloud / Wifi
##############

to make the setting on aruba cloud managed access point:
> go to device -> Security
>> under section "Authentication Servers" choose: EAP Fragmentation MTU 900

** if you have fragmenation problems set the MTU < 1024 bytes, or always use 900 bytes ;-)

computer2know :: thank you for your visit :: have a nice day :: © 2025