Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Server Fail Through

This thread has been viewed 4 times
  • 1.  Server Fail Through

    MVP EXPERT
    Posted Jan 13, 2013 07:49 AM

    I have a question regarding server fail through when using a server group. I understand that server fail through is only enabled when termination is happening on the controller. Say for instance however you do not have termination on the controller enabled but server fail through is enabled on the server group. Within the sever group is a RADIUS server (1st) and InternalDB (2nd). If I have a guest user authenticating against the InternalDB in this group


    Am I correct in thinking that the server fail through will be ignored in this instance since termination is not configured and will both auth servers be ignored Or will the request be sent to the RADIUS and thats it.?



  • 2.  RE: Server Fail Through
    Best Answer

    Posted Jan 14, 2013 01:36 PM

    You can use fail through on a server group whether you are terminating on the controller or not; it works either way.    It is typically not enabled when the two servers are from the same directory source; for example two RADIUS servers point to the same AD.  But if you have two differing sources of users, then fail through can be enabled regardless of the termination setting.

     

    In your example, the authentication attempt will be tried against the RADIUS server (1).....that request will fail as that user doesn't exist (assuming they don't exist)....it will then try the Internal DB.



  • 3.  RE: Server Fail Through

    MVP EXPERT
    Posted Jan 14, 2013 06:08 PM

    Brilliant that's what I thought, I read someone that fail through only works with 802.1x but guess that was wrong...



  • 4.  RE: Server Fail Through

    EMPLOYEE
    Posted Jan 16, 2013 12:29 PM

    In this scenario, for every guest connection attempt, your radius server will receive a transaction and send a deny. Depending on how many people can see this SSID it might put a drastic load on your radius server. 

     

    I know if we did this, the security group would be screaming at us. We have 50/50 employees/guests on our WLAN. This would double our RADIUS farm load.

     

    Just a thought.