[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Question on Status-Server document and CoA port
- To: "Alan DeKok" <aland@deployingradius.com>
- Subject: Re: Question on Status-Server document and CoA port
- From: "Greg Weber" <gdweber@gmail.com>
- Date: Mon, 24 Nov 2008 22:22:16 -0500
- Cc: "radext mailing list" <radiusext@ops.ietf.org>
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:cc:in-reply-to:mime-version :content-type:content-transfer-encoding:content-disposition :references; b=LM4xhidvbn5IKZWH+gSj54MHOxtXC1Do/+T6oibj4X7fXNI3FHbwTyKrlm5NxZg/0u 63yVPGRuiU1jHx+eeWkCC+iIYX+AYBk/7U64L05Sl6unk43tSSqD5DCPl9GaHTKC0N6c QjLMFaWvXi1487PG5JHWZ7Xwp//SqFRz/7TEQ=
- In-reply-to: <49245A80.9000607@deployingradius.com>
- References: <49245A80.9000607@deployingradius.com>
On Wed, Nov 19, 2008 at 1:27 PM, Alan DeKok <aland@deployingradius.com> wrote:
> One issue with the current draft was brought up in the WG meeting
> yesterday. The draft proposes that when RADIUS servers start, they send
> Status-Server packets to any NASes that have a CoA port defined. This
> procedure can be used by the NAS to determine that the server is up,
> potentially increasing network stability.
>
> This behavior, however, is not part of the traditional implementations
> of Status-Server. It was suggested at the least IETF by Glen, and added
> to the document after that.
>
> If the server has many NASes configured, it may send tens, or possibly
> hundreds of packets on startup. It would seem reasonable to add a
> suggestion to use jitter, though the current draft doesn't suggest that.
>
> Should the document be updated to suggest jitter, or should the text
> relating to CoA be deleted entirely?
I would suggest to remove this text unless you want to pursue it
on the Experimental track. At least, I would think any watchdog
traffic should be on the same port/addr path as the signaling traffic
that it's trying to protect, in order to avoid firewall changes in the POP.
You are trying to see if the NAS can initiate authentication/accounting,
right, not if the DAS is operating? It just seems like you are trying
to recreate the Status-Client behavior by using Status-Server on the
CoA port.
Greg
>
> Alan DeKok.
>
> --
> to unsubscribe send a message to radiusext-request@ops.ietf.org with
> the word 'unsubscribe' in a single line as the message text body.
> archive: <http://psg.com/lists/radiusext/>
>
--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>