Technical Note: Using VIP (Virtual IP) Does Not Work for RADIUS
Description
Scope
Version: 8, 9
Solution
Controller rejecting authentication response from the appliance in L2 High Availability configuration. Controller's AAA Server configuration contains Network Sentry's VIP (Virtual IP).
The appliance responds to RADIUS requests using the physical eth0 IP address (regardless of High Availability configuration). The controller will not accept a response from an IP address that is not defined in the AAA Server configuration.
Scope
Version: 8, 9
Solution
The following must be configured on the controller:
- 2 AAA Server configurations: one for the Primary Control Server IP and one for the Secondary Control Server IP.
- Fail over to Secondary when Primary does not respond (Round Robin cannot be used).
Refer to the appropriate integration guide for more details regarding configuration.
