Массовая авторизация и radreqlimit

Radius related questions
Post Reply
brodayga
Posts: 62
Joined: 23 Oct 2014, 06:13

Массовая авторизация и radreqlimit

Post by brodayga » 09 Nov 2017, 12:09

Проблема с тем что при массовой авторизации (после перезагрузки например) происходит какойто ступор, но при этом через какое-то время(иногда через минуту, иногда через пол часа) может моментально авторизовать всех

Code: Select all

radius(1, 192.168.55.2):
state: active
  fail count: 0
  request count: 50
  queue length: 2840
  auth sent: 9355
  auth lost(total/5m/1m): 4492/541/97
  auth avg query time(5m/1m): 0/0 ms
 
через 30 сек

Code: Select all

radius(1, 192.168.55.2):
  state: active
  fail count: 0
  request count: 50
  queue length: 2836
  auth sent: 9405
  auth lost(total/5m/1m): 4544/524/98
  auth avg query time(5m/1m): 0/0 ms
 
При этом видно что время запросов среднее 0 , как я понимаю значит что все запросы теряются, но при этом если смотреть tcpdump радиус отвечает моментально
Спойлер
14:51:34.237355 IP 192.168.55.4.35274 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:34.237467 IP 192.168.55.4.43921 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:34.237582 IP 192.168.55.4.49290 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:34.240386 IP 192.168.55.2.1812 > 192.168.55.4.49290: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:34.241054 IP 192.168.55.2.1812 > 192.168.55.4.43921: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:34.241307 IP 192.168.55.2.1812 > 192.168.55.4.35274: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:34.327338 IP 192.168.55.4.45302 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:34.331028 IP 192.168.55.4.41401 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 123
14:51:34.331351 IP 192.168.55.2.1812 > 192.168.55.4.45302: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:34.333792 IP 192.168.55.2.1812 > 192.168.55.4.41401: RADIUS, Access Accept (2), id: 0x01 length: 37
14:51:34.455568 IP 192.168.55.4.47378 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:34.455758 IP 192.168.55.4.47058 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:34.458763 IP 192.168.55.2.1812 > 192.168.55.4.47058: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:34.458982 IP 192.168.55.2.1812 > 192.168.55.4.47378: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:35.550846 IP 192.168.55.4.33677 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:35.553966 IP 192.168.55.2.1812 > 192.168.55.4.33677: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:36.820320 IP 192.168.55.4.40998 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 120
14:51:36.823517 IP 192.168.55.2.1812 > 192.168.55.4.40998: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:37.037387 IP 192.168.55.4.49338 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:37.037410 IP 192.168.55.4.52571 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:37.038662 IP 192.168.55.4.46203 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:37.040079 IP 192.168.55.4.57684 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:37.040195 IP 192.168.55.2.1812 > 192.168.55.4.52571: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:37.040553 IP 192.168.55.2.1812 > 192.168.55.4.49338: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:37.040974 IP 192.168.55.2.1812 > 192.168.55.4.46203: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:37.042403 IP 192.168.55.2.1812 > 192.168.55.4.57684: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:37.113835 IP 192.168.55.4.41866 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 120
14:51:37.116303 IP 192.168.55.2.1812 > 192.168.55.4.41866: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:37.179430 IP 192.168.55.4.43462 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:37.182978 IP 192.168.55.2.1812 > 192.168.55.4.43462: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:37.273601 IP 192.168.55.4.42513 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:37.273795 IP 192.168.55.4.56158 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:37.275163 IP 192.168.55.2.1812 > 192.168.55.4.56158: RADIUS, Access Reject (3), id: 0x01 length: 23
14:51:37.277431 IP 192.168.55.2.1812 > 192.168.55.4.42513: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:37.380881 IP 192.168.55.4.52520 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 120
14:51:37.383898 IP 192.168.55.2.1812 > 192.168.55.4.52520: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:37.437572 IP 192.168.55.4.58629 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:37.440487 IP 192.168.55.2.1812 > 192.168.55.4.58629: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:37.522017 IP 192.168.55.4.49668 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:37.525073 IP 192.168.55.2.1812 > 192.168.55.4.49668: RADIUS, Access Accept (2), id: 0x01 length: 46
14:51:37.541408 IP 192.168.55.4.53648 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 121
14:51:37.544793 IP 192.168.55.2.1812 > 192.168.55.4.53648: RADIUS, Access Accept (2), id: 0x01 length: 46
14:51:37.636611 IP 192.168.55.4.34503 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:37.639543 IP 192.168.55.2.1812 > 192.168.55.4.34503: RADIUS, Access Accept (2), id: 0x01 length: 46
14:51:37.673187 IP 192.168.55.4.32878 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 123
14:51:37.676458 IP 192.168.55.2.1812 > 192.168.55.4.32878: RADIUS, Access Accept (2), id: 0x01 length: 39
14:51:37.823515 IP 192.168.55.4.50993 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 123
14:51:37.827048 IP 192.168.55.2.1812 > 192.168.55.4.50993: RADIUS, Access Accept (2), id: 0x01 length: 38
14:51:38.186891 IP 192.168.55.4.59239 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 120
14:51:38.190660 IP 192.168.55.2.1812 > 192.168.55.4.59239: RADIUS, Access Accept (2), id: 0x01 length: 46
14:51:38.409908 IP 192.168.55.4.39612 > 192.168.55.2.1812: RADIUS, Access Request (1), id: 0x01 length: 122
14:51:38.411621 IP 192.168.55.2.1812 > 192.168.55.4.39612: RADIUS, Access Reject (3), id: 0x01 length: 23
в логах аксела
Спойлер
.....
[2017-11-09 14:53:22]: debug: ipoe6566: radius(1): req_exit 49
[2017-11-09 14:53:22]: debug: ipoe6566: radius(1): wakeup 0x2c58b18
[2017-11-09 14:53:22]: warn: ipoe6566: radius: server(1) not responding
[2017-11-09 14:53:22]: warn: ipoe6566: radius: no available servers
[2017-11-09 14:53:22]: warn: ipoe6566: authentication failed
[2017-11-09 14:53:22]: debug: ipoe6566: terminate
[2017-11-09 14:53:22]: info: ipoe6566: ipoe: session finished
[2017-11-09 14:26:10]: info: ipoe6567: create interface ipoe6567 parent eth2
[2017-11-09 14:26:10]: debug: ipoe6567: radius(1): queue 0x7f1fd4725bc8
[2017-11-09 14:53:05]: debug: ipoe6567: radius(1): wakeup 0x7f1fd4725bc8 -1
[2017-11-09 14:53:05]: info: ipoe6567: send [RADIUS(1) Access-Request id=1 <User-Name "10.213.8.60"> <NAS-Identifier "accelipup"> <NAS-IP-Address 192.168.55
.4> <NAS-Port 9772> <NAS-Port-Id "ipoe6567"> <NAS-Port-Type Ethernet> <Calling-Station-Id "4c:5e:0c:14:1a:91"> <Called-Station-Id "eth2"> <Framed-IP-Address
10.213.8.60> <User-Password>]
[2017-11-09 14:53:23]: debug: ipoe6567: radius(1): req_exit 49
[2017-11-09 14:53:23]: debug: ipoe6567: radius(1): wakeup 0x7f1fd07b5c48
[2017-11-09 14:53:23]: warn: ipoe6567: radius: server(1) not responding
[2017-11-09 14:53:23]: warn: ipoe6567: radius: no available servers
[2017-11-09 14:53:23]: warn: ipoe6567: authentication failed
[2017-11-09 14:53:24]: debug: ipoe6567: terminate
[2017-11-09 14:53:24]: info: ipoe6567: ipoe: session finished
[2017-11-09 14:26:10]: info: ipoe6568: create interface ipoe6568 parent eth2
[2017-11-09 14:26:10]: debug: ipoe6568: radius(1): queue 0x27aae18
[2017-11-09 14:53:06]: debug: ipoe6568: radius(1): wakeup 0x27aae18 -1
[2017-11-09 14:53:06]: info: ipoe6568: send [RADIUS(1) Access-Request id=1 <User-Name "10.38.0.20"> <NAS-Identifier "accelipup"> <NAS-IP-Address 192.168.55.
4> <NAS-Port 9773> <NAS-Port-Id "ipoe6568"> <NAS-Port-Type Ethernet> <Calling-Station-Id "4c:5e:0c:14:1a:91"> <Called-Station-Id "eth2"> <Framed-IP-Address 1
0.38.0.20> <User-Password>]
[2017-11-09 14:53:24]: debug: ipoe6568: radius(1): req_exit 49
[2017-11-09 14:53:24]: debug: ipoe6568: radius(1): wakeup 0x7f1fd4a2e198
[2017-11-09 14:53:24]: warn: ipoe6568: radius: server(1) not responding
[2017-11-09 14:53:24]: warn: ipoe6568: radius: no available servers
[2017-11-09 14:53:24]: warn: ipoe6568: authentication failed
[2017-11-09 14:53:24]: debug: ipoe6568: terminate
[2017-11-09 14:53:24]: info: ipoe6568: ipoe: session finished

настройки радиус

Code: Select all

[radius]
nas-identifier=accelipup
nas-ip-address=192.168.55.4
gw-ip-address=192.168.55.4
server=192.168.55.2,*******,auth-port=1812,acct-port=0,req-limit=50,fail-timeout=0
server=192.168.55.2,*******,auth-port=0,acct-port=1813,fail-timeout=0
dae-server=192.168.55.4:3799,********
verbose=1
timeout=1
max-try=1
acct-timeout=500
Ещё интересный момент что при этом аккаунтинг указанный отдельным сервером тоже перестаёт работать хотя не указана очередь , и судя по tcpdump тоже все прилетает моментально
Спойлер
radius(2, 192.168.55.2):
state: active
fail count: 0
request count: 0
queue length: 0
acct sent: 4800
acct lost(total/5m/1m): 87/1/0
acct avg query time(5m/1m): 10437/0 ms
interim sent: 94116
interim lost(total/5m/1m): 46984/4492/1912
interim avg query time(5m/1m): 0/0 ms

через 15 минут, хотя за минуту до этого всё было также плохо
Спойлер
ipoe:
starting: 0
active: 6633
delayed: 0
radius(1, 192.168.55.2):
state: active
fail count: 0
request count: 0
queue length: 0
auth sent: 13573
auth lost(total/5m/1m): 6504/1027/0
auth avg query time(5m/1m): 226/3 ms
radius(2, 192.168.55.2):
state: active
fail count: 0
request count: 0
queue length: 0
acct sent: 6837
acct lost(total/5m/1m): 90/3/0
acct avg query time(5m/1m): 216/4 ms
interim sent: 101209
interim lost(total/5m/1m): 48571/803/0
interim avg query time(5m/1m): 59/0 ms

Упустил, одно ядро при этом уходит в полку и возвращается после авторизации всех абонов

brodayga
Posts: 62
Joined: 23 Oct 2014, 06:13

Re: Массовая авторизация и radreqlimit

Post by brodayga » 09 Nov 2017, 13:33

Вроде похожа проблема в ветке viewtopic.php?f=11&t=762 .Но пишут что совсем зависает, но может просто не дождались пока отвиснет.

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest