[RADIATOR] Top level radius servers problems

Alan Buxey A.L.M.Buxey at lboro.ac.uk
Wed May 25 05:59:31 CDT 2011


Hi,

> We add to all our peers handler configurations a “NoReplyHook”
> (Paul Dekkers from Surfnet is also helping us on this problem)

okay - thats pretty much similar to what I have and recommend too  :-)

one question though - what is our FarmSize set to? how many threads
are you running - and are you in some higher debug mode? 

Try FarmSize 8 for example, to give some extra worker threads
for when some are tied up with non responding home names - (obviously
with a caveat of knowing the methods you use and whether having a Farm
would be an issue - as per the RADIATOR docs)

> Do you have a configuration already to limit this type of brute-force 
> attacks?

that depends entirely on the end sites NAS kit - if will be different
for each vendor. I'd expect to tell a site to look at their docs
and configure their chosen equipment (or get their support people to) - 
we cannot be experts or advisors for every single bit of NAS kit out there
:-(

alan


More information about the radiator mailing list