Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Julian Y Koh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue Nov 01 2011 13:25:20 Central Time, Lee H Badman wrote: > > For those of you with large (10,000 + users) RADIUS deployments, what servers > are you using and what are your points of pain and/or appreciation? We're currently using Steel Belted

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Hanset, Philippe C
Lee, I will speak as UTK and eduroam-US. We see a lot of satisfaction with the following three RADIUS flavors: -RADIATOR (supported, very affordable, and PERL based...easy to customize, keeps up with innovations: RadSec, CUI,...) -FreeRADIUS (open Source, FREE, C based, support community, keeps

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Hanset, Philippe C
Lee, If you want to see some configuration examples for six RADIUS flavors go there: https://www.eduroamus.org/radius_configuration This will not give you examples of how to do PEAP, but you will have a good idea of how the various flavors are configured for proxying. Philippe On Nov 1, 2011, a

RE: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Hector J Rios
ana State University From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Lee H Badman Sent: Tuesday, November 01, 2011 1:25 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: [WIRELESS-LAN] RADIUS Server preference for 10K+

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Arran Cudbard-Bell
t; Sent: Tuesday, November 01, 2011 1:25 PM > To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU > Subject: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments? > > We’re feeling some frustration with our current RADIUS solution (ACS 5, > virtual appliances) that are frequently att

RE: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Reynolds, Walter
AUSE.EDU > Subject: Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client > Environments? > > +1 for FreeRADIUS ;) > > -Arran > > On 1 Nov 2011, at 20:19, Hector J Rios wrote: > > > > We've been running FreeRADIUS on freeBSD since 2008 and

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread kalbach
Freeradius We support TTLS/PAP with a MIT Kerberos backend. Typical day we do 330K authentications in a day, with about 18K unique users. Like U of M, most are smart phones. We have 2 servers handling this. John Kalbach Information Technology Services kalb...@psu.edu

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-01 Thread Jeffrey Sessler
Lee, We're using the Avaya's Identity Engines Ignition product. It's a virtual appliance, we run a pair in HA mode, and it's servicing requests for 10K+ users. We had been using Ignition back when idEngines was around, followed it to Nortel, and then to Avaya. We were particularly interested in

RE: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-02 Thread Lee H Badman
ember 01, 2011 2:30 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments? -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue Nov 01 2011 13:25:20 Central Time, Lee H Badman wrote: > > For those of you with large (10,

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-02 Thread Julian Y Koh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed Nov 02 2011 08:09:21 Central Time, Lee H Badman wrote: > > Out of curiosity, can you describe what Juniper's replacement for SBR is > missing? Biggest thing was IP pools, since we assign IP addresses to our traditional VPN clients via RADIUS

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-02 Thread Jeroen van Ingen
Hi Lee, > For those of you with large (10,000 + users) RADIUS deployments, what > servers are you using and what are your points of pain and/or > appreciation? We're using Radiator. No real points of pain; what we appreciate are the features to manipulate requests and support all kinds of authent

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-02 Thread Jason Cook
We Freeradius on RH5.X supporting PEAP/MSCHAP with AD for dot1x and LDAP for VPN. We have two production wireless that see about 8000-9000 users per day 15000 over the month. no real pain points except some issues to resolve when RH gets upgraded. file permissions/SE Linux caused the most i

Re: [WIRELESS-LAN] RADIUS Server preference for 10K+ Client Environments?

2011-11-03 Thread Jason Murray
We use FreeRadius 2.1.x servers running on pair HP DL360-G7s with Linux. We have around 8k simultaneous users online at any one time. Authentication type is 802.1x MS-CHAPv2/PEAP which is proxied though the FreeRadius servers to a cluster of MS AD servers, where our single-sign-on system terminate