Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt

Juha Heinanen <[email protected]> Thu, 29 May 2003 17:41:52 +0300
Newsgroups gmane.ietf.ppvpn
Message-ID <[email protected]>
Bernard Aboba writes:

 > Having the PE fabricate a User-Name and Password exchange where in fact
 > no such exchange is occurring is not a good idea.

this is how most vpn implementations work today, i.e., the vpn site
information is only configured in the pe.

 > Clearly the PE must be identifying the CE in some manner so that it is
 > confident it is the correct CE, no?  

as i said in above, in most vpn implementations today, the ces doen't 
identify them selfes at all.  in that respect my proposal in a big
improvement, because if the ce is 802.1x capable, it can identify
itself.

 > > the pe needs from radius a list of ip addresses of other pes.  if there
 > > is an existing attribute that can return that, it is fine with me to use
 > > it.
 > 
 > Yes, there is. There is Tunnel-Client-Endpoint and Tunnel-Server Endpoint.
 > If used with a Tunnel-Medium-Type of 1 (IPv4) or 2 (IPv6) these Attributes
 > can contain IP addresses. Have a look at RFC 2868.

i'll take a look at it.  which attribute to use is a minor issue can be
decided later.

-- juha