Answer the question
In order to leave comments, you need to log in
Best practice FreeRadius cluster?
Hello. Given:
Backend: Pair of servers with Ldap user base;
Frontend: One server with freeradius;
Everything works on Debian8
Raise an identical freeradius server on a third-party site for fault tolerance and assemble a cluster from two.
The question is, what is the best way to do this? personally, I'm thinking:
haproxy (but here the question is will it proxy tls transparently or will it need SA from Radius?)
or vrrp between two nodes (but what if I have freeradius working via udp, won't this cause a problem with load-balancing?)
Mb anyone have better ideas and good experience please share it. Thanks in advance .
Answer the question
In order to leave comments, you need to log in
haproxy, vrrp, ... what is all this for?
radius it is from the same era where dns and smtp come from
when fault tolerance is achieved simply by specifying several servers on the client, just
make the second radius and set up rsync for the users file, sql-base replication, or whatever you have in the backend
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question