Microsoft IAS and Loadbalancing with Cisco CSS

From: Eric J. (bt_hirosaito_at_gmx.de)
Date: 03/21/05


Date: 21 Mar 2005 02:17:40 -0800

Hi,

does anyone of you have any experiences with using a cisco CSS and IAS
?
Cause we got many problems with that:

The switch sends the radius request to the loadbalancer which
translates the ip and forwards it to the server.
But only the first return packet comes from the virtual loadbalancer
ip. all other packets arenīt translated and still have the real ip of
the server.
So the switch always says: RADIUS: Response for non-existent request
ident

cause the switch asks the .55 (virtualIP) and the .35(realIP) answers

here the switch-log. maybe anyone has a clue.

RADIUS: EAP-login: length of radius packet = 177 code = 1
RADIUS: Initial Transmit FastEthernet0/2 id 155 10.10.10.55:1812,
Access-Request, len 177

RADIUS: Received from id 155 10.10.10.55:10609, Access-Challenge, len
76

 RADIUS: EAP-login: length of eap packet = 6
  RADIUS: EAP-login: got challenge from radius

RADIUS: ustruct sharecount=1
RADIUS: EAP-login: length of radius packet = 245 code = 1
RADIUS: Initial Transmit FastEthernet0/2 id 156 10.10.10.55:1812,
Access-Request, len 245

RADIUS: Received from id 156 10.10.10.35:1812, Access-Challenge, len
1576

RADIUS: Response for non-existent request ident
RADIUS: Retransmit id 156
RADIUS: Received from id 156 10.10.10.35:1812, Access-Challenge, len
1576

RADIUS: Response for non-existent request ident

Thanks
Eric



Relevant Pages

  • Re: Nortel Passport 8006 - Microsoft IAS
    ... I'm in interested in your setup with the Nortel Baystack 450, ... authenticate the user's pc that connects to the switch or the logon to the ... how do the Radius ... authenticate the pc, by MAC or certificate? ...
    (microsoft.public.internet.radius)
  • 802.1x port authentication problem
    ... here using 802.1x authentication with RADIUS. ... Our wired network switches support this, and the backend auth will be Win2k3 ... place *after* the user has logged on, and the switch port is not unblocked ... This should ensure that the authentication phase takes place earlier, ...
    (microsoft.public.win2000.security)
  • RE: Wanted: Small switch, 802.1x & Network Policy Server compatible
    ... NPS adheres to the RADIUS RFC's. ... Whatever switch you buy, it must be RADIUS-compliant and must support both ... as my Linksys Switch is not capable of Windows Server 2008 Radius ...
    (microsoft.public.internet.radius)
  • radius authenticaion then ad
    ... I've got a test bench setup with an Entarasys E1 switch ... using the policy manager, an AD server 2003, IAS, xp ... authenticate to the radius server which then passes ...
    (microsoft.public.internet.radius)
  • Re: Want to add your own hole geometry to Hole Wizard?
    ... by experimentation. ... The /d switch was posted here years ago, ... item called "Check Radius of Curvature". ... all SW gives is the arc length. ...
    (comp.cad.solidworks)