Tony,

Nickolas Christopher is our F5 specialist. Below is his answer to your question 
(he doesn't subscribe to the list so I pass it on his behalf):

" The problem was with the TCP profile on the F5.  The client-side TCP settings 
were configured using a template based on bandwidth savings.  That template had 
Nagle's algorithm enabled.  
http://searchnetworking.techtarget.com/definition/Nagles-algorithm

Nagle's algorithm tries to reduce congestion by bundling very small packets 
together.  That was the cause of poor response from ldapr.  The ldap servers 
were responding fast, but the F5 was holding packets in efforts to save 
bandwidth.

Turning off Nagle's algorithm solved the performance issues we experienced.

Nick"



Yu Wang
____________________________
Network Architect
Information Technology Services
The Florida State University
850-645-6810
[email protected]


-----Original Message-----
From: The EDUCAUSE Wireless Issues Constituent Group Listserv 
[mailto:[email protected]] On Behalf Of Tony Juarez
Sent: Tuesday, September 02, 2014 4:07 PM
To: [email protected]
Subject: Re: [WIRELESS-LAN] Authentication failures at peak times (Cisco)

Yu,

What type of change did you make to the F5¹s we are seeing a similar
issues with are Cisco wireless and F5 and LDAP authentications

Tony Juarez, CCNP Wireless
Network Engineer II
IT Services

773-702-5592 (Office)
773-230-7923 (Cell)





On 8/27/14, 2:15 PM, "Wang, Yu" <[email protected]> wrote:

>Where are all your user accounts hosted? What kind of user database that
>serves the wireless system? Do you have a rough number of how many
>concurrent users at peak time?
>
>We had peak time wireless authentication failure issues in the past
>Spring semester. We did performance tests in the summer and found out it
>was the backend (F5 + LDAP). We did improvements in the summer and we
>have not seen the issue in the first three days of Fall semester.
>Yesterday's wireless usage set a new record with over 32k unique users
>and over 15k concurrent users.
>
>We use Aruba wireless with 802.1X, WPA2-Ent, PEAP, MSCHAPv2 + freeradius
>+ F5 + ldap. It's different than yours but from the error you mentioned,
>it's likely the backend was congested.
>
>
>
>Yu Wang
>____________________________
>Network Architect
>Information Technology Services
>The Florida State University
>850-645-6810
>[email protected]
>
>
>-----Original Message-----
>From: The EDUCAUSE Wireless Issues Constituent Group Listserv
>[mailto:[email protected]] On Behalf Of Eric T. Barnett
>Sent: Wednesday, August 27, 2014 2:12 PM
>To: [email protected]
>Subject: [WIRELESS-LAN] Authentication failures at peak times (Cisco)
>
>We've got a relatively small deployment compared to many on this list,
>but we've run into a problem we just can't put our finger on. We're using
>5508s and ISE as a RADIUS server and we're having HUGE latencies on
>WPA2-Enterprise PEAP authentication. There's times when almost no one can
>authenticate. What's really weird is that the controllers show "AAA
>Authentication Error" when this happens even though the username and
>password is correct. None of the devices seem distressed and there's no
>network problems we can see. Anyone ever seen this before or have any
>ideas how to troubleshoot? TAC so far has been not incredibly useful but
>they have only been on the case for a day or so now. I can hear my users
>sharpening the pitchforks...
>
>Thanks,
>
>Eric Barnett
>Wireless Administrator
>Information and Technology Services
>Arkansas State University
>870 680 4243
>
>**********
>Participation and subscription information for this EDUCAUSE Constituent
>Group discussion list can be found at http://www.educause.edu/groups/.
>
>**********
>Participation and subscription information for this EDUCAUSE Constituent
>Group discussion list can be found at http://www.educause.edu/groups/.

**********
Participation and subscription information for this EDUCAUSE Constituent Group 
discussion list can be found at http://www.educause.edu/groups/.

**********
Participation and subscription information for this EDUCAUSE Constituent Group 
discussion list can be found at http://www.educause.edu/groups/.

Reply via email to