Hi, > It does appear that there are issues cascading RADIATOR servers that are > all using <AuthBy EAPBALANCE> because the RADIUS "State" attribute used to > track the EAP conversations gets mangled as the message progresses through > the chain of servers.
interesting...I dont think that this has been discussed in eduroam (well, certainly not recently) - and if all servers did this then nothing would work in a proxy system > To make things work with the US NTLRS servers they graciously stopped > using EAPBALANCE to load balance between our servers and moved to a > traditional primary/backup model, but obviously I can't ask everyone to do > that :-). ;-) in the UK we did trials with EAPBALANCE and it didnt work well with many of the connecting servers.... we use primary/secondary/tertiary (I'm now wondering if the US found our doc ;-) ) > The RADIATOR folks recommended I try HASHBALANCE instead, but I like the > extra assurance that EAP conversations don't get broken up. yes. the conversation cannot get broken up - both end destinations and middle boxes dont like that - especially since another middle box could choose a different destination alan _______________________________________________ radiator mailing list [email protected] http://www.open.com.au/mailman/listinfo/radiator
