eduroam in a box eduroam in a box take 3 take 3
play

Eduroam in a box Eduroam in a box (take 3) (take 3) Rok Pape, - PowerPoint PPT Presentation

Eduroam in a box Eduroam in a box (take 3) (take 3) Rok Pape, ARNES, Barcelona, 06.09.2005 ARNES EduRoam 1/2 ARNES EduRoam 1/2 WPA/WPA2 Wireless network WPA Enterprise ( + WPA2 where available) Dynamic VLANs Support for


  1. Eduroam in a box Eduroam in a box (take 3) (take 3) Rok Papež, ARNES, Barcelona, 06.09.2005

  2. ARNES EduRoam 1/2 ARNES EduRoam 1/2 ● WPA/WPA2 Wireless network – WPA Enterprise ( + WPA2 where available) – Dynamic VLANs – Support for legacy networks (multiple SSID) ● RADIUS tree hierarhy – Non-automatic auth (forced EAP-TTLS + PAP) – Send real user-name with Access-Accept – Monitor users (full log + IP, close stale connections) – FreeRADIUS problems (threads, libs, Alan DeKok)

  3. ARNES EduRoam 2/2 ARNES EduRoam 2/2 ● OpenLDAP – Very unintuitive software – Reliability vs. Performance (bdb/hdb vs. Lmdb) – Phpldapadmin = administrator tool – siEduPerson schema – Bad documentation about schemas ● Specification updates ● L2 security is complex (Catalyst 3750, L2/L3 fw)

  4. EduRoam administrators EduRoam administrators ● 50% use trial and error learning – Low understanding of Wireless security – Low understanding of Ethernet security – Radius servers are missconfigured – Extensive, manual one-time network inspections – Why use LDAP and not MySQL/text files ? ● Time consuming EduRoam deployment ● With time - small AAI missconfigurations

  5. EduRoam in a box – why ? EduRoam in a box – why ? ● Speed up deployment ● For less technicaly experianced ● Deployment of a proven solution ● Less errors ● Automated configuration with easier deployment ● Easier reporting of data – Statistics – AP database

  6. ARNES Eduroams ARNES Eduroams ● Big EduRoam ● Small EduRoam – WPA(2) Enterprise – WPA(2) Enterprise – FreeRADIUS – FreeRADIUS – OpenLDAP – OpenLDAP – ISC DHCPd – ISC DHCPd – MySQL (accounting) – MySQL (accounting) – EduRoam monitor – EduRoam monitor – L2/L3 security via – L2/L3 security via switch Linux firewall

  7. Eduroam in a box „Home“ Eduroam in a box „Home“

  8. Eduroam in a box „Network“ 1/2 Eduroam in a box „Network“ 1/2

  9. Eduroam in a box „Network“ 2/2 Eduroam in a box „Network“ 2/2

  10. Eduroam in a box „Crypto“ 1/2 Eduroam in a box „Crypto“ 1/2

  11. Eduroam in a box „Crypto“ 2/2 Eduroam in a box „Crypto“ 2/2

  12. Eduroam in a box „Accounting“ Eduroam in a box „Accounting“

  13. Eduroam in a box „Access Points“ Eduroam in a box „Access Points“

  14. Eduroam in a box „AAI“ 1/3 Eduroam in a box „AAI“ 1/3

  15. Eduroam in a box „AAI“ 2/3 Eduroam in a box „AAI“ 2/3

  16. Eduroam in a box „AAI“ 3/3 Eduroam in a box „AAI“ 3/3

  17. Eduroam in a box - Summary Eduroam in a box - Summary ● Skeleton/base is done ● Rough around the edges ● Still work to do ● Field deployments ● Support for other equipment – „Big EduRoam“ - Catalyst 3750 – Other Access Points

Recommend


More recommend