Skip to main content
Use this page to plan capacity, onboarding, and operational expectations for Altostrat Radius. The limits below are default account limits. Where a row is marked adjustable, contact Altostrat before you design around the higher value.
This page covers feature coverage, availability, retention, and operational limits.

Feature Coverage

CapabilitySupportNotes
RadSec TLSSupportedUse RadSec for encrypted RADIUS transport and NAS identity.
EAP-PEAPSupportedUsed for Wi-Fi and 802.1X environments where the NAS and client stack support it.
EAP-TTLSSupportedUsed for tunneled EAP deployments.
PAP, CHAP, MS-CHAP, and MS-CHAPv2SupportedCommon for broadband, VPN, PPP, and access-network devices.
External identity providers for EAPSupportedExamples include Microsoft Azure, Google Workspace, and Okta.
Custom attributesSupportedAttribute names, operators, and value types must pass validation.
Webhook eventsSupportedUse events for external automation and operational workflows.
Full-text searchSupportedSearch is designed for operational lookup across RADIUS data.
Authentication logsSupportedRetained for 12 months.
Accounting data storageSupportedRetained for 12 months.
Accounting triggersSupportedUse triggers for usage-based actions, such as taking action after a monthly usage threshold.
Management interfaceWeb basedOperators manage users, groups, NAS devices, realms, logs, and settings through the web UI.
REST API integrationSupportedUse the API for provisioning and external systems integration.
Altostrat Workflows integrationSupportedUse workflows to automate follow-up actions from RADIUS events.

Security And Data Protection

ControlCoverage
Encryption in transitSupported.
Encryption at restSupported.
Point-in-time recoveryPer-second recovery granularity for 15 days.
DDoS protectionSupported.

Availability Targets

TargetValueNotes
RADIUS availability guarantee99.999%SLA-backed.
Data durability99.999999999%11 nines, SLA-backed.
Service IP availability99.99% per IPSLA-backed.
Authentication timeAt most 80 msTarget authentication processing time.
Service IP addresses2Exposed for service reachability.
Availability Zones per region3Each always-on region uses multiple AZs.
AZ failoverYesDesigned to fail over within milliseconds.
Always-on regions3Virginia, Sydney, and Cape Town.
Regional failoverYesDesigned to fail over within minutes.

Performance Limits

LimitDefaultAdjustable
Maximum concurrent authentication attempts per NAS device1,000 per secondNo
Maximum concurrent authentication attempts per workspace12,000 per secondNo
Minimum accounting data frequency300 secondsNo
Management API rate limit600 requests per minuteYes
The minimum accounting data frequency means NAS devices should not send interim accounting updates more frequently than every 300 seconds unless Altostrat has explicitly advised otherwise.

Migration Limits

Migration limits apply individually to customer records, RADIUS accounts, attribute groups, and NAS devices.
LimitDefaultAdjustable
CSV import size500 MBNo
For large migrations, use chunked imports and validate a smaller sample before importing the full file. See Folders and Users for the user onboarding workflow and Architecture and Scale for how large imports are processed.

Customer Record Limits

LimitDefaultAdjustable
Customer records500,000Yes
Metadata pairs per customer record20No
Tags per customer record10No
RADIUS accounts per customer record25,000Yes

RADIUS Account Limits

LimitDefaultAdjustable
RADIUS accounts1,000,000Yes
Attribute groups per RADIUS account5No
Check attributes per RADIUS account5No
Reply attributes per RADIUS account10No
Metadata pairs per RADIUS account20No
Tags per RADIUS account10No

NAS Device Limits

LimitDefaultAdjustable
NAS devices25,000Yes
Metadata pairs per NAS device20No

Attribute Group Limits

LimitDefaultAdjustable
Attribute groups15,000Yes
Check attributes per group15No
Reply attributes per group25No
RADIUS accounts in an attribute group1,000,000Yes
Metadata pairs per attribute group20No
Tags per attribute group10No

Design Guidance

  • Use groups for reusable policy so account-level attributes stay small and easy to reason about.
  • Keep metadata focused on operational lookup fields; avoid storing secrets in metadata.
  • Use tags for coarse filtering, ownership, and lifecycle state rather than high-cardinality data.
  • Keep accounting interim updates at or above the supported minimum interval when usage, sessions, quotas, and triggers depend on accounting.
  • Ask Altostrat about adjustable limits before a migration, reseller model, or large customer deployment depends on higher ceilings.