| Re: Ordered delivery of EAP messages | <– Date –> <– Thread –> |
|
From: Bernard Aboba (bernard_aboba |
|
| Date: Tue, 6 Mar 2007 20:54:45 -0800 (PST) | |
RFC 2865 says:
The RADIUS server can detect a duplicate request if it has the same client source IP address and source UDP port and Identifier within a short span of time.
This, to me, implies duplicate detection on the server side does not rely on
orderly delivery. Keeping the history for "a short span of time" allows
duplicate detection irrespective of the order the requests come in.
That advice seems sensible; if implemented, I think it would address the FRTO scenarios we have been discussing, wouldn't it? Given client backoff, it seems highly unlikely that an Access-Request would be reordered outside of a "short span of time" (e.g. say, 1 minute).
As for the responses... Assuming the RADIUS client transmitted a request
twice (first one timed out), if it receives one of the responses, would it
still accept the second (duplicate) response if it arrives as well? Wouldn't
the RADIUS client just drop the second response because there is no
outstanding request to match anymore?
Yes, I think that the RADIUS client will drop a duplicate response. The problem occurs more on the RADIUS server side, where the server could potentially send an Access-Reject if it wasn't doing duplicate detection as referred to above, and as a result the EAP method got mixed up.
- Re: Ordered delivery of EAP messages, (continued)
- Re: Ordered delivery of EAP messages Peter Deacon, March 6 2007
- Re: Ordered delivery of EAP messages Bernard Aboba, March 6 2007
- Re: Ordered delivery of EAP messages Peter Deacon, March 6 2007
- Re: Ordered delivery of EAP messages Alper Yegin, March 6 2007
- Re: Ordered delivery of EAP messages Bernard Aboba, March 6 2007
- Re: Ordered delivery of EAP messages Avi Lior, March 7 2007
- Re: Ordered delivery of EAP messages Yoshihiro Ohba, March 7 2007
- Re: Ordered delivery of EAP messages Avi Lior, March 7 2007
- Re: Ordered delivery of EAP messages Peter Deacon, March 7 2007
Results generated by Tiger Technologies using MHonArc.