Chairman – ICT Directors forum RENU, Uganda

Slides:



Advertisements
Similar presentations
RadSec – A better RADIUS protocol
Advertisements

Connect. Communicate. Collaborate eduroam: towards a managed European service Miroslav Milinović, Srce, Zagreb, Croatia eduroam SA, GÉANT2 Wi-Fi Workshop,
Licia Florio EUNIS05, Manchester 1 Eduroam EUNIS Conference, June Licia Florio.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Southampton Open Wireless Network The Topology Talk.
TF Mobility Group 22nd September A comparison of each national solution was made against Del C – “requirements”, the following solutions were assessed.
Copyright JNT Association 2006 The JANET Roaming Service.
Eduroam – Roam In a Day Louis Twomey, HEAnet Limited HEAnet Conference th November, 2006.
Connect communicate collaborate RADIUS and WLAN Infrastructure Monitoring Jovana Palibrk, AMRES NA3 T2, Sofia,
High-quality Internet for higher education and research Federated network access with Klaas Wierenga SURFnet Ljubljana, April.
EduShib VA What is EduShib VA? EduShib VA (Virtual Appliance) is a image based implementation tool for eduroam and Shibboleth.
Using RADIUS Within the Framework of the School Environment Charles Bolen Systems Engineer December 6, 2011.
Lecture 12: WLAN Roaming Communities EDUROAM TM. eduroam TM eduroam (education roaming) is the secure, world-wide roaming access service developed for.
Wireless Ad Hoc VoIP Thesis by: Patrick Stuedi & Gustavo Alonso Presentation by: Anil Kumar Marukala & Syed Khaja Najmuddin Ahmed.
Clinic Security and Policy Enforcement in Windows Server 2008.
Wireless ambitions Frans Panken I2 Spring meeting 24 april 2012.
1 Week #7 Network Access Protection Overview of Network Access Protection How NAP Works Configuring NAP Monitoring and Troubleshooting NAP.
Eduroam Louis Twomey HEAnet Library Services Day 20 th November 2014.
Version 4.0. Objectives Describe how networks impact our daily lives. Describe the role of data networking in the human network. Identify the key components.
Education roaming Secure Wireless Service for Research and Education.
Implementing Network Access Protection
High-quality Internet for higher education and research Paul Dekkers April 4th, Turkey.
Michal Procházka, Jan Oppolzer CESNET.
A Practical Guide for Joining EduRoam EuroCAMP Torino A Practical Guide for Joining EduRoam 4 March 2005 Version 1.6.
Module 8: Configuring Network Access Protection
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
Ian Bailey Director Application Architecture Office of CIO, Province of BC A User Centric and Claims Based Architecture for British Columbia.
Configuring Network Access Protection
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Workshop roaming services: eduroam / govroam
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Federated Wireless Network Authentication Kevin Miller Duke University Internet2 Joint Techs Salt Lake City February, 2005.
Simon Prasad. Introduction  Smartphone and other mobile devices have made it so easy to stay connected.  But this easy availability may lead to personal.
Project Moonshot Daniel Kouřil EGI Technical Forum
THE CAMPUS IDENTITY SYSTEM Lucy Lynch, NSRC. Learning Objectives Discovering the key role campus networks play in trusted identities for R&E Authoritative.
Federated Access to Storage EGI CF 2012 Luke Howard, Daniel Kouril, Michal Prochazka.
WACREN EduID Fostering Identity Federations in West and Central Africa 3rd Sci-GaIA Workshop Dar es Salaam, Tanzania – 5 th September Omo Oaiya.
Global Virtual Research Organizations
Basharat Institute of Higher Education
10 Years of eduroam (from an idea to a product)
Module 9: Configuring Network Access
Large-scale (Campus) Lan design (Part II)
Wireless Protocols WEP, WPA & WPA2.
Internet and Intranet.
University of Stuttgart University of Murcia
Innovative Solutions from Internet2
Implementing Network Access Protection
Securing the Network Perimeter with ISA 2004
Module 8: Securing Network Traffic by Using IPSec and Certificates
2TCloud - Veeam Cloud Connect
Wireless Technology.
Internet and Intranet.
Tailor slide to customer industry/pain points
Company Overview & Strategy
INTRODUCTION TO COMPUTER NETWORKS
20409A 7: Installing and Configuring System Center 2012 R2 Virtual Machine Manager Module 7 Installing and Configuring System Center 2012 R2 Virtual.
SECURING WIRELESS LANS WITH CERTIFICATE SERVICES
Converged Service A Dartmouth Perspective
Protecting Network Assets
Internet and Intranet.
SurfCFCC Secure Wireless Access For Students, Faculty, and Staff.
HIMSS National Conference New Orleans Convention Center
Chapter 3 VLANs Chaffee County Academy
Federations: Introduction Justin Knight, Jisc
Module 8: Securing Network Traffic by Using IPSec and Certificates
Mark Spencer - James Dickerson
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Internet and Intranet.
Eduroam and Ipv6 Deployment Progress in Uva Wellassa University
Presentation transcript:

Chairman – ICT Directors forum RENU, Uganda Deploying Educational Roaming (eduroam) in ICER Mali: Challenges and Lessons Learned Sidy Soumare - IT Site leader, Malian International Centre for Excellence in research,NIAID/NIH Lloyd Ssentongo- IT Site Leader , Ugandan International Center for Excellence in Research, NIAID/NIH Chairman – ICT Directors forum RENU, Uganda

What’s Eduroam ? Eduroam stand for education roaming. It’is the secure, world-wide roaming access service developed for the international research and education community.  eduroam allows students, researchers and staff from participating institutions to obtain Internet connectivity across campus and when visiting other participating institutions by simply opening their laptop.

What’s the importance of Eduroam ? Eduroam facilitates travelers from academic institutions by allowing them to gain network access with minimal configuration and no need for the visited institution to grant them the access explicitly. This benefits visiting faculty, academics traveling for conferences and collaborative work, study abroad students, visitors and even regional academic exchange. By joining Eduroam you extend the network to visitors at your institution without adding any additional maintenance responsibilities to your IT staff.  Moreover, by extending the network, you help to guarantee access to your own students and faculty while they are abroad.

Eduroam - Technical overview

As described in the introduction the eduroam project is "A worldwide federation of RADIUS servers facilitating network access for roaming academic affiliates using IEEE 802.1x as the vehicle. Eduroam's use of 802.1x in concert with RADIUS means the network is built around well understood, established, and easy to manage standards which are often already deployed within the network infrastructure of educational institutions."

Eduroam offers two distinct services: Identity Provider (“IDP”) and Service Provider (“SP”). IDP: When an institution is connected to eduroam as an IDP, its students, faculty, and staff can use their personal credentials from their institution to join eduroam anywhere around the world. SP: When an organization is connected to eduroam as an SP, students, faculty, and staff from around the world can join the eduroam network as visitors of that organization.

Eduroam SSID broadcast: With todays WIFI services, creating a new SSID is straightforward. Most of the institutions, have already several SSIDs in production. In the case of WiFi, less is better when it comes to the number of SSIDs. The recommendation is being 5 per AP. With eduroam, an institution can verify the legitimacy of a visitor without direct access to the user's credentials (SSL/TLS tunnel goes between user's device and user's home RADIUS server)

Eduroam SSID broadcast: With eduroam, a user can verify the legitimacy of an infrastructure (When verifying the SSL/TLS certificate during the EAP exchange, the user also makes sure that the infrastructure is a valid member of the federation). With eduroam, the wireless traffic is encrypted between the user's device and the institution's infrastructure.

Access role: Access roles can be created based on the outer-identity of the 802.1X authentication request. A user with an outer identity that matches the realm (i.e. domain) of the organization can be assigned to VLANs with access to sensitive resources, while all other users’ with realms that do not match the organization will be assigned to VLANs with less privileged access. Raduis servers: Radiator and FreeRADIUS are the two RADIUS servers generally used. The configuration are slightly different while implementing Raduis for SP or Raduis for SP+IDP.

Challenges during the implementation of Eduroam in Mali

The country: Mali, officially the Republic of Mali, is a landlocked country in West Africa. Mali is the eighth-largest country in Africa, with an area of just over 1,240,000 square kilometers. The population of Mali is 16 million. Its capital is Bamako and the Official language is French.

Eduroam implementation in Mali - Context The establishment of the Mali Research and Education Network (MaliREN) is underway and this institution would like to include in its services access to the "Eduroam” infrastructure. In order to ensure this, MaliREN has delegated to ICER Mali (the International Center of Excellence in Research), one of its member institutions, the deployment and maintenance of its Radius server for "Eduroam” access management.

Eduroam implementation in Mali – Architecture Straightforward…

ICER Mali: ICER Mali is a bio-medical research center ICER Mali: ICER Mali is a bio-medical research center. It has running it’s own data center in the campus of medical school since 10+ years ICER Mali infrastructure: 2 X HP Proliant ML350p Gen8 + VMware vSphere 5 Enterprise 2 X DS2246 nodes (NetApp storage) 2 X Cisco 2960 command line switches for NFS traffic Radius server: FreeRadius ! CentOS Linux 7 (Core)-Kernel 3.10.0-327.36.1.e17.x86_64 vSphere VM Version 8 CPU: 1vCPU / Memory: 2048MB / vDisk: 16GB

Challenges during the implementation of eduroam The country have no National level Radius proxy server. |||| National level RADIUS proxy server in a different country at WACREN Headquarter. Country code Top Domain issues. Icermali.org instead of the preferred icermali.ml It took some time to get exemptions at the ETLR The network infrastructure for MaliREN was not ready

Acknowledgements Michael Tartakovsky, CIO NIAID/NIH, Director OCICB Christopher J Whalen, IBRSP/OCICB/NIAID/NIH Economou Matthew , IBRSP/OCICB/NIAID/NIH Brian k Moyer, IBRSP/OCICB/NIAID/NIH Omo Oaiya – CTO WACREN Davy Abeye - WACREN