[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Comments on draft-adrangi-radius-extension-for-pwlan-00.txt



Hi Jari,
Thanks for the dialogue - please see my commens inline.
BR,
Farid

> I guess part of my confusion comes from the fact that I don't 
> know if IP Address Type Options = Public and Private in an 
> Access-Accept means
> 

[FA] I think there is a misunderstanding here - "public and private" 
will be used only in the AccessRequest message to indicate that an
Access Network is capable of doing both options.
And I think the text is very specific about this fact. [FA]

>     (1) The home server does not care
>     (2) The home server wants both types of addresses to be assigned.
> 
> Option 1 sounds logical to me.
> 
> >>3) I get a bit worried that lack of enforcement is going to cause 
> >>problems. Is it a general approach for AAA attributes from the home 
> >>server to be hints?
> > 
> > [FA] I would not consider this as a hint, rather a explicit 
> request. 
> > Because, this enforcement attribute is in response to the 
> > advertisement in the access-request. Please note that the 
> enforcement 
> > attribute should not be sent if the advertisement attribute is not 
> > present. [FA]
> 
> It does indeed help if you only send the enforcement 
> attribute after seeing an advertisement in access-request. 
> Then we at least know the NAS supports this function, and we 
> know what address types are available. Also, you wrote earlier:
> 
[FA] That's the intent. [FA]

> > The other is how the Access Network is going to enforce the 
> specified 
> > address type option (private or public address) when the 
> client  does 
> > a DHCP request - which IMO, this is outside the scope of 
> the document 
> > and  perhaps we should be more explicit about it.
> 
> So I guess what you mean is that you *will* enforce the 
> address type. The only missing things are how the NAS will 
> tell the DHCP server about this, and whether the client and 
> the DHCP server need some protocol enhancements to get this 
> done. And you consider these issues to be out of scope for 
> this draft, which sounds reasonable.
> 
> Is my understanding correct?
> 

[FA] Yes, correct. [FA]

> --Jari
> 
> 

--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>