"eric " <[EMAIL PROTECTED]> wrote:
> However, apparently some implementations may actually forward proxy
> states along the path...

  If the request is being forwarded, any Proxy-State in the original
request must be in the forwarded copy, too.

> why? I don't know...other than broken radius servers:
>
>      If a Proxy-State Attribute is added to a packet when forwarding
>       the packet, the Proxy-State Attribute MUST be added after any
>       existing Proxy-State attributes.

  Which FreeRADIUS does.  I don't think Merit does it, though.

  And for some reason, the people at Merit got their name on the
RFC's, despite having probably the worst RADIUS server implementation
I've seen *anywhere*.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to