<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Rant: F5 LTM and GTM Doesn&#8217;t Do External AAA Authorization</title>
	<atom:link href="http://etherealmind.com/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/feed/" rel="self" type="application/rss+xml" />
	<link>http://etherealmind.com/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/</link>
	<description>Network design, architecture, thinking, working. Tech.</description>
	<lastBuildDate>Wed, 23 May 2012 00:26:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Greg Ferro</title>
		<link>http://etherealmind.com/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/#comment-156</link>
		<dc:creator>Greg Ferro</dc:creator>
		<pubDate>Thu, 28 Feb 2008 22:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/2008/02/27/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/#comment-156</guid>
		<description>Thanks for your response. I have two points.

I disagree with you on point 1, my data center is filled with products that do support authorization usually RADIUS or TACACS, but sometimes LDAP. In fact, I can&#039;t think of any other product that does not have external authorization. But then, I believe myself to be a professional and I make security conscious choices.

I can see why RADIUS would lose in the development cycle and your point appears valid in this context. Let me make this point, if F5 can&#039;t get the basic functions in place, how are they going to deliver the main functions ?

To put it differently, listening to customers when they SAY what they want, and failing to address fundamentals (or what they actually need) can lead to poor choices. Everyone says they want junk food, even when they know its the wrong choice.

Addiitonally, I have been asking for Radius authentication for  years, and I am not alone. Check the forums for the &#039;me too&#039; on my post. Which customers have you been listening to ?

Develop all the fancy features you like, but lets not forget fundamentals here. F5 has abrogated a primary security responsibility and it should be addressed.</description>
		<content:encoded><![CDATA[<p>Thanks for your response. I have two points.</p>
<p>I disagree with you on point 1, my data center is filled with products that do support authorization usually RADIUS or TACACS, but sometimes LDAP. In fact, I can&#8217;t think of any other product that does not have external authorization. But then, I believe myself to be a professional and I make security conscious choices.</p>
<p>I can see why RADIUS would lose in the development cycle and your point appears valid in this context. Let me make this point, if F5 can&#8217;t get the basic functions in place, how are they going to deliver the main functions ?</p>
<p>To put it differently, listening to customers when they SAY what they want, and failing to address fundamentals (or what they actually need) can lead to poor choices. Everyone says they want junk food, even when they know its the wrong choice.</p>
<p>Addiitonally, I have been asking for Radius authentication for  years, and I am not alone. Check the forums for the &#8216;me too&#8217; on my post. Which customers have you been listening to ?</p>
<p>Develop all the fancy features you like, but lets not forget fundamentals here. F5 has abrogated a primary security responsibility and it should be addressed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don MacVittie</title>
		<link>http://etherealmind.com/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/#comment-158</link>
		<dc:creator>Don MacVittie</dc:creator>
		<pubDate>Thu, 28 Feb 2008 21:52:55 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/2008/02/27/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/#comment-158</guid>
		<description>Good Faith Disclosure: I am an F5 employee, one of the ones &quot;...concentrating on nifty features...&quot; ;-)

I&#039;ll give you that it&#039;s inconvenient not to have Radius do it for you (and prior to my employment at F5 have ranted about this in data center devices and appliances in general - and storage in particular), but there are two simple facts:

(1) The data center is sadly filled with devices and appliances that still don&#039;t support Radius, F5 is hardly unique in that sense.

(2) F5 does a very good job of listening to customers - that is one of the reasons I came to the company.

When customers are asked where development time should be spent, Radius always loses. It always loses because for most organizations it is a minor imposition and they can get bigger bang for their buck if we implement things like Powershell and Control Point. We give the customers what they want - asking them would be a waste of time if we didn&#039;t listen.

That doesn&#039;t make it less inconvenient - particularly on initial setup - but for most customers that inconvenience is a minimal part of overall configuration cost and effort. For those it isn&#039;t, they get basic Radius configured, as Christian mentions.

Remember that this is not core functionality for these products - a differentiator definitely, but not generally a buy/no buy decision point.

Don.</description>
		<content:encoded><![CDATA[<p>Good Faith Disclosure: I am an F5 employee, one of the ones &#8220;&#8230;concentrating on nifty features&#8230;&#8221; <img src='http://etherealmind.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>I&#8217;ll give you that it&#8217;s inconvenient not to have Radius do it for you (and prior to my employment at F5 have ranted about this in data center devices and appliances in general &#8211; and storage in particular), but there are two simple facts:</p>
<p>(1) The data center is sadly filled with devices and appliances that still don&#8217;t support Radius, F5 is hardly unique in that sense.</p>
<p>(2) F5 does a very good job of listening to customers &#8211; that is one of the reasons I came to the company.</p>
<p>When customers are asked where development time should be spent, Radius always loses. It always loses because for most organizations it is a minor imposition and they can get bigger bang for their buck if we implement things like Powershell and Control Point. We give the customers what they want &#8211; asking them would be a waste of time if we didn&#8217;t listen.</p>
<p>That doesn&#8217;t make it less inconvenient &#8211; particularly on initial setup &#8211; but for most customers that inconvenience is a minimal part of overall configuration cost and effort. For those it isn&#8217;t, they get basic Radius configured, as Christian mentions.</p>
<p>Remember that this is not core functionality for these products &#8211; a differentiator definitely, but not generally a buy/no buy decision point.</p>
<p>Don.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian</title>
		<link>http://etherealmind.com/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/#comment-157</link>
		<dc:creator>Christian</dc:creator>
		<pubDate>Thu, 28 Feb 2008 01:52:17 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/2008/02/27/f5-ltm-gtm-radius-tacacs-no-aaa-authorization/#comment-157</guid>
		<description>I&#039;ve recently ran into the same problem.. very annoying

BUT -  I have gotten basic Radius working fine

also - F5 is a few years ahead of ace, i use ace&#039;s too for virtualized customer infrastructures

The ACE is no competition for the F5 IMO, but i would really like to see F5 implement TACACS very soon</description>
		<content:encoded><![CDATA[<p>I&#8217;ve recently ran into the same problem.. very annoying</p>
<p>BUT &#8211;  I have gotten basic Radius working fine</p>
<p>also &#8211; F5 is a few years ahead of ace, i use ace&#8217;s too for virtualized customer infrastructures</p>
<p>The ACE is no competition for the F5 IMO, but i would really like to see F5 implement TACACS very soon</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Served from: etherealmind.com @ 2012-05-23 07:27:18 by W3 Total Cache -->
