[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Comments on "practical deployments"



Bernard Aboba wrote:
> It will be interesting to see how well it works.  I have previously been
> involved in a number of
> inter-domain roaming trials.  When the RADIUS traffic was routed through
> an exchange point,
> the results were not very promising.  With packet loss rates of 1-5%,

  I'll track the tests, and see if we can do some measurements under load.

  For existing (non-EAP) proxies, I don't recall seeing loss rates that
high.  I'll go check, but I think latencies and loss have decreased,
while bandwidth has increased in the net.  Plus, most RADIUS
interconnects are now done over Ipsec, which helps with the underlying
reliability.

> RADIUS retransmissions
> were pretty common and this would often lead to EAP retransmissions. 
> The overall
> authentication times could get pretty long and sometimes authentication
> wouldn't complete
> at all.  Most of the carriers we worked with ended up deploying web
> portals instead :(

  WiMAX is standardizing on EAP for authentication.  Discussions are
underway to design a standard interconnect architecture.  So this
appears to be less of a problem now.

  Alan DeKok.

--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>