CTS 126: Using Eduroam in Higher Education




Clear To Send: Wireless Network Engineering show

Summary: We took Anders Nilsson away from a party during Cisco Live and asked him to talk about Eduroam.<br> Eduroam<br> Anders Nilsson joins us on the show to discuss the basics of eduroam, how it works, and why higher education institutions decide to deploy the eduroam SSID on their campus. Anders is from Sweden and you may know him through the Wi-Fi Moose.<br> https://twitter.com/HerrNilsson2/status/1007630629272457216<br> Anders does work for the Swedish education network and is technically responsible for eduroam in Sweden. That makes him today’s subject matter expert for this topic.<br> If you’re from a higher education institute you may be familiar with eduroam already. Or maybe you’re thinking about deploying eduroam or you don’t fully understand how it works. Anders provides a thorough introduction to eduroam which was started around 2003 in the Netherlands.<br> The goal was to provide a better way for guest students at a visiting university to access Wi-Fi. In it’s early days, eduroam was implemented as an Open SSID with an access list that allowed VPN only. They quickly realized this method wouldn’t scale very well and went for the 802.1X solution instead.<br> eduroam is WPA2 Enterprise based with a federation of RADIUS servers. This means an institution will peer its RADIUS server(s) to the eduroam federation RADIUS servers. When a visiting user wants to join the eduroam SSID but authenticate back to the home RADIUS servers, the local institution will forward the authentication requests up the eduroam chain.<br> This allows for a seamless, convenient connection for the global academic community by using a single SSID, eduroam, at any participating institution. In the old days, a visiting user had to get ahold of the local IT department in order to gain access or use a visitor SSID.<br> Since eduroam is implemented using WPA2 Enterprise, it is strongly suggested to start with using EAP-TLS. Although, other EAP methods are allowed to be used, the table below features the common EAP types deployed with eduroam.<br> <br> <br> <br> <br> EAP-Type<br> <br> <br> Native Supplicant Support<br> <br> <br> Pros<br> <br> <br> Cons<br> <br> <br> <br> <br> EAP-TLS<br> <br> <br> Windows (XP, Vista, 7), Mac OS X, Linux, iOS (iPhone, iPod Touch, iPad), Android (v1.6+)<br> <br> <br> • Validates client as well as infrastructure<br> • Reduced risk of being Phished<br> • Blocking user access is via certificate revocation<br> <br> <br> • PKI infrastructure is required<br> • Users must configure supplicant to use certificate<a href="https://www.eduroam.us/node/80#certificate_supplicant_configuration">*</a><br> • Identity may be exposed in TLS exchange depending on contents of certificate<br> <br> <br> <br> <br> EAP-TTLS<br> <br> <br> Windows (8, 10), Mac OS X, Linux, iOS (iPhone, iPod Touch, iPad), Android (v1.6+)<br> <br> <br> <br> • No native supplicant support on Microsoft Windows XP or 7<br> • Potential for Man-in-the-Middle attacks<a href="https://www.eduroam.us/node/80#mitm-mitigation">*</a><br> <br> <br> <br> <br> EAP-PEAP<br> <br> <br> Windows (XP, Vista, 7), Mac OS X, Linux, iOS (iPhone, iPod Touch, iPad), Android (v1.6+)<br> <br> <br> • Works on many platforms<br> <br> <br> • Potential for Man-in-the-Middle attacks<a href="https://www.eduroam.us/node/80#mitm-mitigation">*</a><br> • Identity may be exposed during Phase-1 of exchange<br> <br> <br> <br> <br> Links and Resources<br> Follow Anders on Twitter – <a href="https://twitter.com/HerrNilsson2" target="_blank" rel="nofollow noopener">@HerrNilsson2</a><br> Learn more about <a href="https://www.eduroam.org" target="_blank" rel="nofollow noopener">eduroam</a><br> Read the eduroam <a href="https://www.incommon.org/eduroam/faq.html" target="_blank" rel="nofollow noopener">FAQ</a><br>