You are here: Home > CLI Commands > Just_CLI_Topics > show aaa state user

show aaa state user

show aaa state user <A.B.C.D>


Display statistics for an authenticated user.





IP address of a user.


The example below shows statics for a user with the IP address The output of this command shows user data, the user’s authentication method. and statistics for assigned roles, timers and flags.


(host) #show aaa state user

Name: MYCOMPANY\tsenter, IP:, MAC: 00:21:5c:85:d0:4a, Role:employee, ACL:51/0, Age: 00:01:46

Authentication: Yes, status: successful, method: 802.1X, protocol: EAP-MD5, server: vortex

Bandwidth = No Limit

Bandwidth = No Limit

Role Derivation: Default

VLAN Derivation: Matched user rule

Idle timeouts: 0, ICMP requests sent: 0, replies received: 0, Valid ARP: 0

Mobility state: Associated, HA: Yes, Proxy ARP: No, Roaming: No Tunnel ID: 0 L3 Mob: 0

Flags: internal=0, trusted_ap=0, delete=0, l3auth=0, l2=1 mba=0

Flags: innerip=0, outerip=0, guest=0, station=0, download=1, nodatapath=0

Auth fails: 0, phy_type: a-HT, reauth: 0, BW Contract: up:0 down:0, user-how: 1

Vlan default: 65, Assigned: 0, Current: 65 vlan-how: 0

Mobility Messages: L2=0, Move=0, Inter=0, Intra=0, ProxyArp=0, Flags=0x0

Tunnel=0, SlotPort=0x1018, Port=0x10e2 (tunnel 130)

Role assigned: n/a, VPN: n/a, Dot1x: Name: employee role-how: 0

Essid: ethersphere-wpa2, Bssid: 00:1a:1e:11:6b:91 AP name/group: AL31/corp1344 Phy-type: a-HT

RadAcct sessionID:n/a

RadAcct Traffic In 0/0 Out 0/0 (0:0/0:0:0:0,0:0/0:0:0:0)

Timers: arp_reply 0, spoof reply 0, reauth 0

Profiles AAA:default-corp1344, dot1x:default, mac: CP: def-role:'logon' sip-role:''

ncfg flags udr 0, mac 0, dot1x 0

Born: 1233772328 (Wed Feb 4 10:32:08 2009)

Command History



ArubaOS 8.0

Command introduced.

Command Information



Command Mode

All platforms

Base operating system.

Enable or Config mode on Mobility Master.