HA scenario = failure

Alan DeKok aland at deployingradius.com
Mon Feb 9 17:15:50 CET 2015


On Feb 9, 2015, at 11:09 AM, Rob Walker <rob3rt.walk3r at gmail.com> wrote:
> I'm a freerad newb, trying to get my HP Procurve 2910al working with 2
> freerad servers (setup identically) and windows/linux endpoints. I've
> tested this setup successfully against each individual freerad server ok.
> As soon as I test stopping one of the free radius server hosts so that the
> 2910al is forced to try the other freerad server (testing a HA scenario) -
> authentication fails.

  That’s bad.

> I can only guess that it's something the switch is mishandling?

  Yes.

> If someone
> could advise on the below outputs it would be appreciated, it seems the
> packet length is much less when it doesn't work?

  The packet length doesn’t matter.  What matters is the the switch sends a packet to the server.  That’s good.  The server responds.  That’s good.  The switch never sends another packet.  That’s bad.

  Alan DeKok.




More information about the Freeradius-Users mailing list