Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt
Juha Heinanen <[email protected]> Fri, 23 May 2003 11:06:23 +0300
| Newsgroups | gmane.ietf.ppvpn |
|---|---|
| Message-ID | <[email protected]> |
if using radius accounting messages as pe keepalive messages is something that people don't like in the draft then we can easily get rid of the whole pe keepalive business by requiring that each pe must re-authenticate each of its vpn sites every N hours. if i remember correctly, this is how it was in the first version of the draft, but then introduced the pe keepalive concept in order to improve scalability. if a provider has 3,600 vpn sites in its network and N=1, radius server would get on the average one authentication message per second from the pes. that may still be acceptable. but if the number of vpn sites grows to, say, 36,000, then most likely N would need to be made bigger, e.g., 10 or 24. to me even N=24 would be acceptable, since in vpn application getting rid of a pe that no longer contains any sites of a vpn is not usually that urgent matter. if it in some case is an urgent matter, then the network management application could be used to trigger valid pes to immediately re-authenticate the sites of a vpn and thus learn the currently valid pe list. if this sounds better to people, i can edit the draft accordingly. -- juha