Bay Networks Radius Bedienungsanleitung Seite 10

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 14
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 9
exchange, and use the Username field for information about the
Mitton Informational [Page 11]
RFC 2882 Extended RADIUS Practices July 2000
desired realm, in it's policy evaluation.
The other implementation performs a similar operations. It uses VSAs
in the Access-Request to distinguish pre-authentication message
types.
8. Accounting Extensions
Traditional Accounting only records session starts and stops which is
pretty boring. Additional session information reporting can be added
easily which gives a better picture of operation in use as they
happen. Some event types are listed below.
8.1. Auditing/Activity
- Call or Modem Starts, Stops
- Tunnel Starts, Stops
- Tunnel Link Starts & Stops
- Admin changes
These events if monitored by a stateful server can be used to gather
information about the usage of the network on a user/session basis.
Information about when a particular user entered the network is more
relevant to network service management than attempting track
backwards from low level IP address flows. Useful information about
port usage across a range of NASes allows service provider to quickly
find problem areas or users.
Information about call failures, successes, and quality are also
deemed important many service providers.
Extending RADIUS accounting is easy, it's surprising that more
implementations have not been made in this area.
9. Conclusions
In real life RADIUS Servers are becoming rather complex software
implementations. They are often brokering authentication and
authorization to other authorities or repositories. Variants of
RADIUS protocol is often used as glue protocol for these type of
solutions.
Some of the solutions are kludges that could be cleaned up by better
underlying services.
What this means to the implementor is that RADIUS as the RFCs
describe it is becoming less relevant. Many additional features
require matching client and server processing message processing.
Mitton Informational [Page 12]
RFC 2882 Extended RADIUS Practices July 2000
Without standardization of these functions we don't have much
interoperability in the field and much effort is spent in reverse
engineering and reaction to unknown areas.
Seitenansicht 9
1 2 ... 5 6 7 8 9 10 11 12 13 14

Kommentare zu diesen Handbüchern

Keine Kommentare