preventing multiple authentication attempts for up to 2 minutes.

Matthew Newton mcn4 at leicester.ac.uk
Fri Mar 18 14:22:09 CET 2016


On Fri, Mar 18, 2016 at 09:14:43AM -0400, Jim Whitescarver wrote:
> When I run radtest and a duplicate request comes in I get
> 
> (0) Ignoring duplicate packet from client localhost port 32940 - ID: 2 due
> to unfinished request in component authenticate module python

OK, that makes sense. First still in progress when the duplicate
comes in.

> in the log.  However, in an actual login attempt from a 3rd party system
> configured to use this radius instance I often see a second authentication
> attempt almost immediately started while the first is still in progress.
> 
> How can I prevent this?

Update timers on the remote system to not retry so quickly?

If there has been no reply to the client, then any other requests
sent are down to the remote client, not FreeRADIUS.

Matthew


-- 
Matthew Newton, Ph.D. <mcn4 at le.ac.uk>

Systems Specialist, Infrastructure Services,
I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

For IT help contact helpdesk extn. 2253, <ithelp at le.ac.uk>


More information about the Freeradius-Users mailing list