Forum Discussion
flomkrl_29950
Nimbostratus
Nov 27, 2008RADIUS Load Balancing
Hello,
I have to use 2 radius server in failover authentification.
1 - The Firsty idea is to create Virtual server for radius with a monitor which just check that radius answer although it is a radius-reject (for security purpose we do not want to use a user password to test, we will test with a wrong username)
Does anyone know all the command line of /usr/bin/monitors/builtins/RADIUSACCT_monitor /usr/bin/monitors/builtins/RADIUS_monitor
the idea is to create a monitor script which use RADIUS?_monitor and send Ok if there is answer and send NOK with no answer, that's all.
2 - The second idea is to modify the authentication irule for disabling the active node if there is an authentification error (not a reject).
If auth failed
=>check node up, if node up make it down
=>check node down, if node up make it up
I prefere the 1st idea,
Thanks for your help,
Flo,
4 Replies
- flomkrl_29950
Nimbostratus
Finaly i use 1st idea : - scott_sams_8256
Nimbostratus
where does this go? i trying to use the radius_monitor external program. the radius sees the valid auth but denies cause it sees user as guest. where or how do i enter in user id and password for this? - hoolio
Cirrostratus
The code flomkrl posted is used in an external monitor. USERNAME="TEST" is where he is setting the login name. - amolari
Cirrostratus
i have filled an RFE, maybe of interest for you
RFE 445480 - Radius Monitor should mark member up even with Access-Reject
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects