Re: Ordered delivery of EAP messages
From: Bernard Aboba (bernard_abobahotmail.com)
Date: Tue, 6 Mar 2007 10:24:46 -0800 (PST)
RADIUS could conceivably reorder packets even where there is no EAP retransmission.

This would seem to be most likely in trans-continental roaming scenarios where the RTTs could be quite large, and the RADIUS RTO is set low (e.g. a second or less) without backoff.

Trans-continential roaming test have shown very high failure rates for EAP conversations with lots of roundtrips, so I wouldn't be surprised if this issue was showing up in real networks.

One way to make this less likely would be for the NAS to detect FRTO via Event-Timestamp & Identifier change, and then wait until sending a new Access-Request, to allow the retransmitted Access-Request to drain from the network.


Alper said:

The problem scenario requires EAP-layer retransmission, correct?
Authentication server does not perform such retransmission. So, I don't see
equivalence between the two legs of the EAP transport.


Results generated by Tiger Technologies using MHonArc.