Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt

Juha Heinanen <[email protected]> Fri, 23 May 2003 11:06:23 +0300
Newsgroups gmane.ietf.ppvpn
Message-ID <[email protected]>
if using radius accounting messages as pe keepalive messages is
something that people don't like in the draft then we can easily get rid
of the whole pe keepalive business by requiring that each pe must
re-authenticate each of its vpn sites every N hours.  if i remember
correctly, this is how it was in the first version of the draft, but
then introduced the pe keepalive concept in order to improve
scalability.

if a provider has 3,600 vpn sites in its network and N=1, radius server
would get on the average one authentication message per second from the
pes.  that may still be acceptable.  but if the number of vpn sites
grows to, say, 36,000, then most likely N would need to be made bigger,
e.g., 10 or 24.

to me even N=24 would be acceptable, since in vpn application getting
rid of a pe that no longer contains any sites of a vpn is not usually
that urgent matter.  if it in some case is an urgent matter, then the
network management application could be used to trigger valid pes to
immediately re-authenticate the sites of a vpn and thus learn the
currently valid pe list.

if this sounds better to people, i can edit the draft accordingly.

-- juha