Wireless Access

 View Only
last person joined: 7 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Documentation to set up Eduroam

This thread has been viewed 90 times
  • 1.  Documentation to set up Eduroam

    Posted Jun 23, 2021 11:30 AM
    I have been looking into eduroam and signed up for a 90 day demo.   The documentation is confusing to me.   Does anybody have  some documentation on the way to set it up?

    ------------------------------
    Gary French
    Network Admin - Wireless
    ACU
    ------------------------------


  • 2.  RE: Documentation to set up Eduroam

    Posted Jun 23, 2021 11:44 AM
    Which bits are confusing you ?

    I set up clearpass for eduroam, but front ended it with a free radius server

    the clearpass config then just becomes two cppm services

    if user realm = your institution then process locally
    else
    proxy auth to free radius server

    any fancy stuff related to eduroam can the be configured in Freeradius e.g. CUI

    I actually talked to them using RADSEC from the FR box.


    happy to help though if you want to talk to the NRPS systems directly from clearpass

    Rgds
    Alex




  • 3.  RE: Documentation to set up Eduroam

    Posted Jun 23, 2021 04:27 PM
    Thanks Alex,  I think I have the ClearPass portion of  down okay.  I just went through the wizard.

    The controller bit...is what does not make sense .   It looks like their document is bit out dated.   Gonna see if support can help me out..

    ------------------------------
    Gary French
    ------------------------------



  • 4.  RE: Documentation to set up Eduroam

    Posted Jun 23, 2021 04:47 PM
    :-)
    oh theres a wizard now ?

    o.k fair enough
    A




  • 5.  RE: Documentation to set up Eduroam

    MVP EXPERT
    Posted Jun 25, 2021 05:20 AM
    Hey Gary, in theory you can just create a new SSID/AAA Profile/VAP on the Controller for Eduroam. The Controller will simply send the RADIUS Auth on to CPPM. It is CPPM which will then proxy the request on the Federation Auth Servers and so on. Don't forget also to create a 'Reject' Service on CPPM to drop any non-edurom accountns such as @gmail.com @yahoo.com etc ​

    ------------------------------
    Craig Syme
    ------------------------------



  • 6.  RE: Documentation to set up Eduroam

    Posted Jun 25, 2021 11:09 AM
    Craig,

    Thanks for the  tip...I hadn't thought of rejecting gmail and Yahoo addresses.

    ------------------------------
    Gary French
    ------------------------------



  • 7.  RE: Documentation to set up Eduroam

    MVP
    Posted Jun 28, 2021 07:03 AM
    What domains are in your reject list? Ye cannot block anything not containing ".edu"  because that would block International users.

    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 8.  RE: Documentation to set up Eduroam

    Posted Jun 28, 2021 08:36 AM
    All I did was to check for local domain to handle eap locally and then proxy other auths up to the NRPS eduroam devices. They’re going t reject any non proxy able domains
    A




  • 9.  RE: Documentation to set up Eduroam

    Posted Aug 02, 2021 10:32 AM
    Can you tell me where to find the ClearPass/eduroam wizard?

    ------------------------------
    Cathy Fasano
    ------------------------------



  • 10.  RE: Documentation to set up Eduroam

    MVP
    Posted Aug 02, 2021 10:37 AM
    They are the same place as all the other Wizards.

    Configuration -> Service Templates & Wizards -> EDUROAM Service

    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 11.  RE: Documentation to set up Eduroam

    MVP EXPERT
    Posted Aug 02, 2021 10:39 AM
    Here you go :

    https://www.arubanetworks.com/techdocs/ClearPass/6.10/PolicyManager/Content/CPPM_UserGuide/Services/ServiceTemplates_Eduroam.htm

    ------------------------------
    Craig Syme
    ------------------------------



  • 12.  RE: Documentation to set up Eduroam

    MVP
    Posted Aug 02, 2021 10:43 AM
    Not everyone is running 6.10.x.  For instance we are using 6.9.x.

    My instructions work for all versions of CPPM 6.x.x that have that wizard.

    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 13.  RE: Documentation to set up Eduroam

    Posted Aug 03, 2021 03:04 PM
    Thanks for the heads up wrt versions. We're running 6.6.10.x and don't have any wizards/templates at all.

    ------------------------------
    Cathy Fasano
    ------------------------------



  • 14.  RE: Documentation to set up Eduroam

    MVP
    Posted Aug 04, 2021 08:15 AM
    That is weird.

    In my experience, as one of the first Aruba ClearPass customers they have had wizards dating bact to when Aruba bought the Avenda eTIPS product. Looks like it is time to spin up 6.10.x in the Lab.

    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 15.  RE: Documentation to set up Eduroam

    Posted Aug 04, 2021 08:28 AM
    Fairly sure I’ve got wizards in my 6.10.1,
    I’ll check but will be a few days
    A

    Sent from my iPhone




  • 16.  RE: Documentation to set up Eduroam

    Posted Aug 04, 2021 10:27 AM
    I think you guys did the same dyslexic thing I did when I first looked at that. I'm running 6.6 not 6.10 -- it's because I'm running 6.6.10.106403 so my brain parsed that incorrectly.

    Which brings up the obvious question -- what are the requirements for upgrading from 6.6 to something with templates?


    ------------------------------
    Cathy Fasano
    ------------------------------



  • 17.  RE: Documentation to set up Eduroam

    MVP
    Posted Aug 04, 2021 10:37 AM
    I know for a fact 6.6.x has templates. We have ClearPass since version 5.0.

    ClearPass 6.6.x was end of support on April 6, 2019. You usually need a valid support contract to get upgrades, I believe. Since ClearPass operation is critical to our network access, we keep a valid support contract on it.

    Reach out to your Aruba account team for your official options.

    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 18.  RE: Documentation to set up Eduroam

    Posted Aug 04, 2021 11:18 AM
    I found the templates when I actually paid attention to the whole window under Configuration >> Start Here. This version is old enough that there is no "Service Templates & Wizards" menu choice. There is no obvious "EDUROAM Service" in the list of templates, either.

    I'm brand new in my job, and brand new to aruba. Three years ago the institution's "aruba partner" did a "set up eduroam" project, where they produced a working eduroam SP but a non-functional IdP. I'm trying to figure out wth they did and how to fix it.

    My one conversation with the "aruba partner" was him wanting to set up a project where we would pay for something that they specify. I don't have enough understanding of either aruba or eduroam to make sure that the project specification would result in a working eduroam setup, and since they've already fscked the process once I'm really leery.

    I know that my institution is paying plenty, and our "partner" has as THEIR first priority getting us to replace all of our APs with newer models. We absolutely cannot afford that, and besides if I tell my dean that we have to replace 443 of our 444 perfectly functional APs, then the answer is going to be "well if we have to replace everything then the replacements certainly aren't going to be aruba APs!" (They seem to be under working under the delusion that if they hold our technology hostage we'll pay up. Don't seem to understand that the current financial position of higher ed means that just ends up with a dead hostage...)

    ------------------------------
    Cathy Fasano
    ------------------------------



  • 19.  RE: Documentation to set up Eduroam

    MVP
    Posted Aug 04, 2021 11:26 AM
    This user manual page says there is one unless you are using High Capacity Guest mode (not very common).





    EDUROAM Service
    Arubanetworks remove preview
    EDUROAM Service
    Open topic with navigation This template is designed for the following scenarios:  Local campus users connecting to eduroam from the local wireless network.  Roaming users from an eduroam campus connecting to their campus network.  Roaming users connecting from local campus or other campuses that are part of the eduroam federation.
    View this on Arubanetworks >


    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 20.  RE: Documentation to set up Eduroam

    Posted Aug 04, 2021 12:44 PM
      |   view attached
    Well I have no idea why I didn't see the template the first six times I looked! *facepalm*

    Given that I'm coming into the middle of this and I have a partially-working setup, how should I proceed? Should I rename and disable my current Eduroam-Local, Eduroam-Inbound, Eduroam-Outbound services, and then run the wizard?

    I've been using this document Microsoft Word - gn3-na3-ufs139-aruba_controller_final.docx (geant.org) and following Chapter 3.1 and looking at what is done already with my working SP. Steps 1, 2 & 3 are done, so there are the national proxies authentication sources created, network devices added, device groups (eduroam proxies & Local controllers) Should I move any of that out of the way before I start the template?

    And another question about what I'm seeing in my install... The docs show a correct Services ordering, and my setup is opposite -- it shows the eduroam services before the services in [ ] (those are default services right?) Will the template do the right thing?

    ------------------------------
    Cathy Fasano
    ------------------------------



  • 21.  RE: Documentation to set up Eduroam

    MVP
    Posted Aug 04, 2021 12:55 PM
    I do not know where you are located.

    I am in the United States and just starting down this eduroam journey after using ClearPass for years.

    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------