rebel2234
07-31-2009, 09:52 AM
We just recently switched from RIP to OSPF and have all of our boxes on a backbone area of 0.0.0.0 default route is learned via OSPF with "default-information originate always" on our edge box. Our routing table is full and all boxes are pingable from other boxes. The problem I am seeing has to do with Radius ACL an OSPF. When we activate changes on an AP none of our customers are getting authenticated.
I think what is happening is radius acl is trying to reach our radius box with a ICMP packet BEFORE OSPF has time to rebuild its routes therefore causing an unreachable status to our radius servers and then acl dosent try to auth to our radius server after that. What I had to do to fix it is put a static route in our ap pointing to our radius server. Maybe there should be a delay on radius acl to try to auth against a radius server so that some of the dynamic routing protocols have time to learn their routes.
The box I am trying this on is a is 1.3.23b.v.world x86-WRAP. I know I will probably get the "upgrade to the new version and try it" routine but I will have to re-up the license for this box and I am away and not able to fix the problem if something goes south. I just wanted to bring this to Valemount's attention incase this is a problem across all releases. Our routing table consists of 56 entrys at this point.
I think what is happening is radius acl is trying to reach our radius box with a ICMP packet BEFORE OSPF has time to rebuild its routes therefore causing an unreachable status to our radius servers and then acl dosent try to auth to our radius server after that. What I had to do to fix it is put a static route in our ap pointing to our radius server. Maybe there should be a delay on radius acl to try to auth against a radius server so that some of the dynamic routing protocols have time to learn their routes.
The box I am trying this on is a is 1.3.23b.v.world x86-WRAP. I know I will probably get the "upgrade to the new version and try it" routine but I will have to re-up the license for this box and I am away and not able to fix the problem if something goes south. I just wanted to bring this to Valemount's attention incase this is a problem across all releases. Our routing table consists of 56 entrys at this point.