Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 Sep 1999 12:07:29 -0700 (PDT)
From:      "Rodney W. Grimes" <freebsd@gndrsh.dnsmgr.net>
To:        tlambert@primenet.com (Terry Lambert)
Cc:        ben@scientia.demon.co.uk, chat@FreeBSD.ORG
Subject:   Re: Filtering port 25 (was Re: On hub.freebsd.org refusing to   talk to dialups)
Message-ID:  <199909291907.MAA20055@gndrsh.dnsmgr.net>
In-Reply-To: <199909291738.KAA16940@usr06.primenet.com> from Terry Lambert at "Sep 29, 1999 05:38:51 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
> > > FWIW, most ISPs buy POPs (Points of Presense) from a big provider,
> > > and do not control the IP address assignment (even for static IP
> > > addresses) nor do they control the account name assignments, which
> > > must apriori not conflict with existing RADIUS records from the
> > > middle tier provider.
> > 
> > Technical correction, they do control the account name assignments,
> > which is done through domainized versions of RADIUS by apending
> > a @domain that is used by a local to the POP radius proxy to forward
> > the request to the correct client of the big provider.  Radiator
> > and Merit Radius both have this feature and are used extensivly
> > by the wholesale dialup providers.
> 
> The technical name of this suffix is called the RADIUS "realm".

Rights, thanks, but I don't use that name for it, it confuses all the other
folks around here into thinking that I am talking about our Kerberous
stuff :-) ;-).

> Not everyone uses this, as they require license fees.

Allmost everyone in the wholesale dialup business uses this.  A Radiator
licence at $1000 is pennies when your dealing with things at this scale.
The ISP end of it does not take a modified radius server if the Radiator
configuration is set to strip the realm during proxy.

> 
> > We have contracts with some of these wholesale providers and we
> > totally control the account name portion.  We don't even need to call
> > them when we add/delete accounts.  
> 
> I assume you are talking accounts using dynamic IP assignment?

Mostly, but not totatly, we can do static IP as well.  We can even
inject routes to get fancier customers with IP space using these
setups.  It's a lot more complicated and we only have 1 wholesaler
that is currently willing to do this, but it works just fine.

-- 
Rod Grimes - KD7CAX - (RWG25)                    rgrimes@gndrsh.dnsmgr.net


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-chat" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199909291907.MAA20055>