Alteon Application Switch Operating System Application Guide
Load Balancing Special Services
304
Document
ID:
RDWR-ALOS-V2900_AG1302
WAP SLB with RADIUS Snooping
RADIUS snooping is similar to the static session entry method in the way that a static session entry
is added to, or removed from, Alteon for the WAP traffic for a user. It is different from the static
session entry method in the way that RADIUS accounting packets are snooped by Alteon instead of
by the RADIUS server using TPCP.
RADIUS snooping enables Alteon to examine RADIUS accounting packets for client information. This
information is needed to add to or delete static session entries in the Alteon session table so that it
can perform the required persistency for load balancing. A static session entry does not age out.
Such an entry, added using RADIUS snooping, is only deleted using RADIUS snooping. Alteon load
balances both the RADIUS and WAP gateway traffic using the same virtual server IP address.
How WAP SLB Works with RADIUS Snooping
Before the Remote Access Service (RAS) allows the WAP traffic for a user to pass in and out of the
gateway, it sends a RADIUS Accounting Start message to one of the RADIUS servers. Alteon then
snoops on the packet to extract the required information. It needs to know the type of the RADIUS
Accounting message, the client IP address, the caller ID, and the user's name. If it finds this
information, Alteon adds a session entry to its session table. If any of this information is missing,
Alteon does not take any action to handle the session entry.
When the client ends the WAP connection, the RAS sends an RADIUS Accounting Stop packet. If
Alteon finds the needed information in a RADIUS Accounting Stop packet, it removes the
corresponding session entry from its table.
The following steps occur when using RADIUS snooping:
1. The user is authenticated on dialing.
2. The RAS establishes a session with the client and sends a RADIUS Accounting Start message
with the client IP address to the RADIUS server.
3. Alteon snoops on the RADIUS accounting packet and adds a session entry if it finds enough
information in the packet.
4. Alteon load balances the WAP traffic to a specific WAP gateway.
5. When the client terminates the session, the RAS sends an Accounting Stop message to the
RADIUS server, and the session entry is deleted from Alteon.
Review the following guidelines before configuring RADIUS snooping:
•
The same virtual server IP address must be used when load balancing both the RADIUS
accounting traffic and WAP traffic.
•
All the RADIUS servers must use the same UDP port for RADIUS accounting services.
•
Before a session entry is recorded on Alteon, WAP packets for a user can go to any of the real
WAP gateways.
•
If a session entry for a client cannot be added because of resource constraints, the subsequent
WAP packets for that client will not be load balanced correctly. The client will need to drop the
connection and then reconnect to the wireless service.
•
The persistence of a session cannot be maintained if the number of healthy real WAP gateways
changes during the session. For example, if a new WAP server comes into service or some of the
existing WAP servers are down, the number of healthy WAP gateway changes and, in this case,
the persistence for a user cannot be maintained.
•
Persistence cannot be maintained if the user moves from one ISP to another, or if the base of
the user's session changes (that is, from CALLING_STATION_ID to USER_NAME, or vice versa).
For example, if a user moves out of a roaming area, it is possible that the user’s
CALLING_STATION_ID is not available in the RADIUS accounting packets. In such a case, Alteon
uses USER_NAME to choose a WAP server instead of CALLING_STATION_ID. As a result,
persistence cannot be maintained.
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...