Configure RADIUS load balancing with persistence
Enabling the Load Balancing or Content Switching Feature
-
For instructions on enabling the load balancing feature, see Enabling Load Balancing.
-
For instructions on enabling the content switching feature, see Enabling Content Switching
Configuring Virtual Servers
-
RADIUS authentication virtual server. This virtual server and its associated service handles authentication traffic to your RADIUS server. Authentication traffic consists of connections associated with users logging onto your protected application or virtual private network (VPN).
-
RADIUS accounting virtual server. This virtual server and its associated service handles accounting connections to your RADIUS server. Accounting traffic consists of connections that track an authenticated user’s activities on your protected application or VPN.
To configure a load balancing virtual server by using the command line interface
add lb vserver <name> RADIUS <IP address> <port> -lbmethod TOKEN -rule <rule>
show lb vserver <name>
add lb virtual server command with the set lb vserver command, which takes the same arguments.
To configure a content switching virtual server by using the command line interface
add cs vserver <name> RADIUS <IP address> <port> -lbmethod TOKEN -rule <rule>
show cs vserver <name>
add cs vserver command with the set cs vserver command, which takes the same arguments.
add lb vserver radius_auth_vs1 RADIUS 192.168.46.33 1812 -lbmethod TOKEN -rule CLIENT.UDP.RADIUS.USERNAME
add lb vserver radius_acct_vs1 RADIUS 192.168.46.34 1813 -lbmethod TOKEN -rule CLIENT.UDP.RADIUS.USERNAME
set lb vserver radius_auth_vs1 RADIUS 192.168.46.33 1812 -lbmethod TOKEN -rule CLIENT.UDP.RADIUS.USERNAME
set lb vserver radius_auth_vs1 RADIUS 192.168.46.34 1813 -lbmethod TOKEN -rule CLIENT.UDP.RADIUS.USERNAME
To configure a load balancing or content switching virtual server by using the configuration utility
Configuring Services
Binding Virtual Servers to Services
Configuring a Persistency Group for Radius
Configuring RADIUS Shared Secret
RADIUS shared secret key validation scenarios
-
RADIUS shared secret key is configured for both the radius client and the radius server: The NetScaler appliance uses the RADIUS secret key for both the client side and the server side. If the verification succeeds, the appliance allows the RADIUS message to go through. Otherwise, it drops the RADIUS message.
-
RADIUS shared secret key is not configured for either the radius client or the radius server: The NetScaler appliance drops the RADIUS message, because shared-secret-key validation cannot be performed on a node that has no radkey configured.
-
RADIUS shared secret key is not configured for both the RADIUS client and the RADIUS server: The NetScaler appliance bypasses the RADIUS secret key validation and allows the RADIUS messages to go through.
add radiusNode <clientPrefix/Subnet> -radKey <Shared_secret_key>
Arguments
IPaddress
Radkey
add lb vserver radius_auth_vs1 RADIUS 192.168.46.33 1812 -lbmethod TOKEN -rule CLIENT.UDP.RADIUS.USERNAME
add lb vserver radius_acct_vs1 RADIUS 192.168.46.34 1813 -lbmethod TOKEN -rule CLIENT.UDP.RADIUS.USERNAME
add service radius_auth_service1 192.168.41.68 RADIUS 1812
add service radius_acct_service1 192.168.41.70 RADIUS 1813
bind lb vserver radius_auth_vs1 radius_auth_service1
bind lb vserver radius_acct_vs1 radius_acct_service[1-3]
add radiusNode 192.168.41.0/24 -radKey serverkey123
add radiusNode 203.0.113.0/24 -radkey clientkey123