Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt
Juha Heinanen <[email protected]> Thu, 29 May 2003 17:41:52 +0300
| Newsgroups | gmane.ietf.ppvpn |
|---|---|
| Message-ID | <[email protected]> |
Bernard Aboba writes: > Having the PE fabricate a User-Name and Password exchange where in fact > no such exchange is occurring is not a good idea. this is how most vpn implementations work today, i.e., the vpn site information is only configured in the pe. > Clearly the PE must be identifying the CE in some manner so that it is > confident it is the correct CE, no? as i said in above, in most vpn implementations today, the ces doen't identify them selfes at all. in that respect my proposal in a big improvement, because if the ce is 802.1x capable, it can identify itself. > > the pe needs from radius a list of ip addresses of other pes. if there > > is an existing attribute that can return that, it is fine with me to use > > it. > > Yes, there is. There is Tunnel-Client-Endpoint and Tunnel-Server Endpoint. > If used with a Tunnel-Medium-Type of 1 (IPv4) or 2 (IPv6) these Attributes > can contain IP addresses. Have a look at RFC 2868. i'll take a look at it. which attribute to use is a minor issue can be decided later. -- juha