Re: redundant load balancing and mschap

2012-08-25 Thread Phil Mayers
On 08/24/2012 11:53 PM, McNutt, Justin M. wrote: The underlying problem is that I have four production RADIUS servers that all seem to choose the same domain controller, which is not only a lot of load, but it's a bad idea in terms of fault tolerance. I agree about the fault tolerance. In my ex

RE: redundant load balancing and mschap

2012-08-24 Thread McNutt, Justin M.
cnuttj=missouri@lists.freeradius.org [mailto:freeradius-users-bounces+mcnuttj=missouri@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Friday, August 24, 2012 4:23 PM To: freeradius-users@lists.freeradius.org Subject: Re: redundant load balancing and mschap On 08/24/2012 08:11 PM, McNutt,

RE: redundant load balancing and mschap

2012-08-24 Thread McNutt, Justin M.
something about it here. --J -Original Message- From: freeradius-users-bounces+mcnuttj=missouri@lists.freeradius.org [mailto:freeradius-users-bounces+mcnuttj=missouri@lists.freeradius.org] On Behalf Of Phil Mayers Sent: Friday, August 24, 2012 4:23 PM To: freeradius-users@lis

RE: redundant load balancing and mschap

2012-08-24 Thread McNutt, Justin M.
lto:freeradius-users-bounces+mcnuttj=missouri@lists.freeradius.org] On Behalf Of alan buxey Sent: Friday, August 24, 2012 3:59 PM To: FreeRadius users mailing list Subject: Re: redundant load balancing and mschap Hi, >Authentication *works*, but all authentications go to the same DC

Re: redundant load balancing and mschap

2012-08-24 Thread Phil Mayers
On 08/24/2012 08:11 PM, McNutt, Justin M. wrote: Grrr... This is probably a Samba issue - a known one? - but I can't seem to get AD authentications to hit multiple DCs. Everything goes to the one This is indeed a Samba issue, and unfortunately a hard one to fix. ntlm_auth doesn't talk over th

Re: redundant load balancing and mschap

2012-08-24 Thread alan buxey
Hi, >Authentication *works*, but all authentications go to the same DC (the one >specified in "mschap2").  Running "radiusd -X" shows that all mschap1/2/3 >instances are being called, and no authentication *attempts* are being >sent to the other two domain controllers.  (1 and 3 ar

Re: redundant load balancing and mschap

2012-08-24 Thread Alan DeKok
McNutt, Justin M. wrote: > Grrr... > > This is probably a Samba issue - a known one? - but I can't seem to get > AD authentications to hit multiple DCs. Everything goes to the one > listed in /etc/samba/smb.conf (which may be a coincidence). That's how the NT protocols work, IIRC. You need