Deployment Guide

Table Of Contents
AAA Policy supports the ability to load balance RADIUS requests across target servers in a load-
balancing pool. (A minimum of two servers is required.) Each client authentication session
begins and ends on a single RADIUS server. The Extreme Campus Controller validates that each
server can be reached and logs an alert when a server in the pool is unreachable. The server pool
is readjusted based on the status of each server in the pool.
Note
Configure one server for both Accounting and Authentication purposes.
When this setting is set to Failover, a RADIUS request is sent to one server at a time:
The RADIUS request is sent to the Primary server (based on the RADIUS server order in the
AAA policy).
When the Primary server is not accessible, the request is sent to the second server (the
Failover server).
When the Primary server is accessible, the request is automatically sent to the Primary server
instead of the Failover server.
Note
The RADIUS Status message (RFC 5997) indicates if the RADIUS server is
accessible.
When this setting is set to Load Balance, a RADIUS request is sent in round robin fashion:
When a RADIUS server is not accessible, Extreme Campus Controller stops sending requests
to that server.
When a server is accessible, the server is added to the pool of servers.
Note
The RADIUS Status message (RFC 5997) indicates if the RADIUS server is
accessible.
Include Framed IP
Select this option to include the FRAMED-IP attribute value pair in the RADIUS ACCESS-REQ
message. You can include the user IP address in the RADIUS ACCESS-REQ through the
FRAMED-IP attribute. This can extend user access reporting capabilities. Framed IP is supported
by External Captive Portal only. Centralized Web Authentication does not support Framed IP.
Report NAS Location
Sends Network Access Server (NAS) Location per the RFC5580 Out of Band agreement. After a
NAS Location change, the new NAS Location is reported in the next RADIUS Request or RADIUS
Accounting message.
Note
Mid-session requests and the Initial Server Request for Location as described in
RFC5580 are not supported.
Deploying Centralized Web Authentication Configure AAA Policy — ExtremeControl
Extreme Campus Controller Deployment Guide for version 5.46.03 139