RADIUS AAA High Availability and Efficient Load Distribution for Performance and Scalability
RADIUS High Availability
AppDirector™ parses and distributes RADIUS requests from a single RADIUS client across multiple RADIUS servers. By maintaining RADIUS transaction persistency, AppDirector ensures that each transaction will be completed using the same RADIUS server, while effectively managing loads across servers to ensure high availability and improved responsiveness for end users.
In addition, AppDirector’s bandwidth management capability eliminates the negative impact of traffic bursts. Bandwidth limits can be configured per RADIUS server/client to prevent possible RADIUS server overloads associated with session bursts caused by broadband remote access server (BRAS) failures.
Virtualized RADIUS Architecture, Global Disaster Recovery and RADIUS Service Scalability
AppDirector Global enables the complete virtualization of RADIUS services and distribution of loads across multiple data centers. AppDirector global load balancing affords RADIUS service redundancy along with the ability to flexibly plan and consolidate operations across RADIUS server infrastructure. By optimizing the entire RADIUS resource pool (including global architectures), AppDirector maximizes resource utilization for reduced OPEX. With AppDirector, carriers can economically scale services using the existing RADIUS infrastructure, eliminating the need to overbuild each RADIUS farm to meet peak usage requirements, thus delivering immediate CAPEX savings.
RADIUS UDP “Zero-minute, Zero-touch, Zero-false Positive” DoS/DDoS and IPS Security
RADIUS servers are highly vulnerable to service floods. UDP-based floods are easy to generate as UDP is connection-less and susceptible to spoofing by the thousands of sources approaching the RADIUS server. AppDirector’s behavioral DoS module automatically identifies and blocks RADIUS floods, creating a signature to block spoofed traffic while forwarding all legitimate traffic.
In addition, AppDirector’s IPS module protects RADIUS servers from operating system-level exploits using attack signature matching to block RADIUS attacks. Radware’s Security Update Service provides automatic updates for these signatures to ensure protection from new OS exploits.
To further protect RADIUS server farms from potential threats, AppDirector can ensure selective request forwarding access control from selected source IP addresses.