Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

RADIUS Load Balancing for 802.1x

This thread has been viewed 7 times
  • 1.  RADIUS Load Balancing for 802.1x

    MVP
    Posted Mar 04, 2020 05:14 AM

    This question involves Aruba 2540 switches (and 5400 modules).

     

    We use 802.1x on our access network and have 2 radius servers configured on the switches.

     

    When I look at the statistics however I see that only one of the two radius servers is being queried while the other gets maybe 0.1% of the traffic

     

    I have tried to find some type of load balancing configuration directive without success, so what am I missing here?

     

    The 2540s are currently running 16.02 or 16.05 firmwares (ArubaOS-switch), we do plan to upgrade them all to 16.10 in the not-too-distant-future.



  • 2.  RE: RADIUS Load Balancing for 802.1x
    Best Answer

    Posted Mar 04, 2020 05:59 AM

    Hi,

     

    there is no loadbalancing on AOS-S.

     

    First entry in your Config will be used.

    After this first server is "dead" (after a time you able to set in your config)

    second will be used.

     

    If you want to loadbalance, yo have to play arround with the order of the RADIUS Server entries in your switches.

     

    Or you need a real loadbalancer...but thats much effort.

     

    Regards



  • 3.  RE: RADIUS Load Balancing for 802.1x

    MVP
    Posted Mar 04, 2020 01:22 PM

    Thanks for the replies!

     

    Does this also apply to ArubaOS on the wireless controller?

    There there is a profile to mark you want load balancing but according to the actual logs of our servers the majority of traffic is still going to the first server.

     

    (7030 controller, ArubaOS 8.6.0.1)



  • 4.  RE: RADIUS Load Balancing for 802.1x



  • 5.  RE: RADIUS Load Balancing for 802.1x

    Posted Mar 04, 2020 08:22 AM
    The switch doesn’t have load balance capabilities , you will need a load balancer .

    Sent from Mail for Windows 10