Hi all,
according to the documentation, the radius dead-criteria must be set as
- tries = radius-server retransmit value
- time = radius-server retransmit X radius-server timeout.
However here are the definition of the different parameters :
- time = minimum number of second after a valid radius server answer before setting the server DEAD.
- tries = number of retransmit
- radius-server timeout = time after which the switch send again the answered request
- radius-server retransmit = number of retransmission after timeout.
According to the config in the end of this post, what is the behaviour of the switch regarding the state DEAD or not ?
Switch ------------(request)----------------> Radius t
Switch <-----------(valid answer)--------- Radius time = 0
Switch ------------(request)----------------> Radius
timeout 10s
Switch ------------(request)----------------> Radius
timeout 10s time = 20s somewhere here the time dead-criteria has been met
Switch ------------(request)----------------> Radius here the tries criteria is met and then the server is marked DEAD at the same time
If the switch here gets a valid answer from the Radius (which is considered DEAD), what does happen ? Is the switch back marked UP ? even if the request has just been sent at the same time that the Radius has been marked DEAD ?
I consider to use the probe-on and test to test the reachability but what is the behaviour in the previous case ?
Many thanks in advance
radius server <RADIUS_NAME1>
address ipv4 <RADIUS_IP1> auth-port <AUTH_PORT> acct-port <ACCT_PORT>
retransmit 2 #Specifies how many times the switch retransmits each radius request to the server before giving up.
timeout 10 #Specifies for how many seconds a switch waits for a reply to a radius request before retransmitting the request.
key 7 <KEY>
!
#With retransmit 2 and timeout 10, the switch will give up after 30sec.
aaa group server radius RADIUS-SRV
server name <RADIUS_NAME1>
server name <RADIUS_NAME2>
ip radius source-interface <SOURCE_INT>
ip vrf forwarding <VRF>
deadtime 1 #Specify the number of minutes before a dead server is tested to check wether it has come back up.
!
radius-server dead-criteria time 20 tries 2