Alcatel-Lucent 7210 SAS E OS System Management Manual page 19

Hide thumbs Also See for 7210 SAS E OS:
Table of Contents

Advertisement

Direct Mode
The first server is used as the primary server. If this server is unreachable, the next server, based on
the server index, of the server pool is used. This continues until either all servers in the pool have
been tried or an answer is received.
If a server is unreachable, it will not be used again by the RADIUS application for the next 30
seconds to allow the server to recover from its unreachable state. After 30 seconds the unreachable
server is available again for the RADIUS application. If in these 30 seconds the RADIUS
application receives a valid response for a previously sent RADIUS packet on that unreachable
server, the server will be available for the RADIUS application again, immediately after reception
of that response.
Round-Robin Mode
The RADIUS application sends the next RADIUS packet to the next server in the server pool. The
same server unreachability behavior is valid as in the Direct mode.
Server Reachability Detection
A server is reachable, when the operational state UP, when a valid response is received within a
timeout period which is configurable by the retry parameter on the RADIUS policy level.
A server is treated as not-reachable, when the operational state down, when the following occurs:
A server that is down can only be used again by the RADIUS algorithm after 30 seconds, unless,
during these 30 seconds a valid RADIUS reply is received for that server. Then, the server is
immediately marked UP again.
The operational state of a server can also be "unknown" if the RADIUS application is not aware of
the state of the RADIUS server (for example, if the server was previously down but no requests
had been sent to the server, thus, it is not certain yet whether the server is actually reachable).
7210 SAS-E OS System Management Guide
A timeout — If a number of consecutive timeouts are encountered for a specific server.
This number is configurable by the retry parameter on RADIUS policy level.
A send failed — If a packet cannot be sent to the RADIUS server because the forwarding
path towards the RADIUS server is broken (for example, the route is not available, the is
interface shutdown, etc.), then, no retry mechanism is invoked and immediately, the next
server in line is used.
Security
Page 19

Advertisement

Table of Contents
loading

Table of Contents