Govroam

The Roaming solution for the public sector

User Tools

Site Tools


public:faq

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
public:faq [2021/04/07 10:04] adminpublic:faq [2024/08/02 10:02] (current) – [Q: We're a public sector organisation and would like to join Govroam, what are the next steps?] admin
Line 9: Line 9:
 The [[ https://utilities.govroam.uk/boardingforms/boarding/full |full boarding form]] needs filling out completely. It asks for contact information, information about your RADIUS servers and various other pieces of information. If you're joining as a Federation, please fill in the {{ :public:federationregistry.xls |Registry}} document too and send it to <govroam@jisc.ac.uk>. The [[ https://utilities.govroam.uk/boardingforms/boarding/full |full boarding form]] needs filling out completely. It asks for contact information, information about your RADIUS servers and various other pieces of information. If you're joining as a Federation, please fill in the {{ :public:federationregistry.xls |Registry}} document too and send it to <govroam@jisc.ac.uk>.
  
-Once we have properly completed forms then we'll sort out the appropriate payments, send you an [[public:unpacking_.tar.gpg.zip_file|encrypted file with the shared secrets]] for RADIUS servers, access to the CAT, the Govroam App, subscribe you to the support mailing lists and add your support details to our Support Matrix.+Once we have properly completed forms then we'll sort out the appropriate payments, send you an [[public:unpacking_.tar.gpg.zip_file|encrypted file with the shared secrets]] for RADIUS servers, the Govroam App, subscribe you to the support mailing lists and add your support details to our Support Matrix.
  
 ===Q: We're a public sector organisation and would like to join Govroam as a Visited Only site, what are the next steps?=== ===Q: We're a public sector organisation and would like to join Govroam as a Visited Only site, what are the next steps?===
Line 63: Line 63:
  
 Our technical requirements in detail: Our technical requirements in detail:
-{{ :public:20171212_govroam_tech_spec_v2.docx |Tech Spec V2}}+{{ :public:2021_techspec_v3.pdf |Tech Spec V3}}
  
 ====Technical==== ====Technical====
Line 105: Line 105:
 If you already have a RADIUS server then you may be able to configure it to act as an ORPS at no extra cost. If the software doesn't allow it, or you want to separate your services then the ORPS you add will only be handling the authentication requests destined/source to/from offsite, which will by about 1% of your total authentication requests. If you already have a RADIUS server then you may be able to configure it to act as an ORPS at no extra cost. If the software doesn't allow it, or you want to separate your services then the ORPS you add will only be handling the authentication requests destined/source to/from offsite, which will by about 1% of your total authentication requests.
  
-As for the software - any modern RADIUS server can handle Govroam. There are no odd requirements. Having said that through, there should be a preference for servers which can handle Server Status (for resilience), CUI (Chargeable User Identity for audit), Operator-Name (for logging) and RADSEC (for the future).+As for the software - any modern RADIUS server can handle Govroam. There are no odd requirements. Having said that though, there should be a preference for servers which can handle Server Status (for resilience), CUI (Chargeable User Identity for audit), Operator-Name (for logging) and RADSEC (for the future).
  
 If you value the service then resilience should be considered. At least two RADIUS servers at each level are recommended and three is quite common. Many RADIUS servers (and wireless controllers) offer load balancing options so hardware load balancers shouldn't be needed. The servers themselves are generally stateless and require no intercommunication.  If you value the service then resilience should be considered. At least two RADIUS servers at each level are recommended and three is quite common. Many RADIUS servers (and wireless controllers) offer load balancing options so hardware load balancers shouldn't be needed. The servers themselves are generally stateless and require no intercommunication. 
Line 176: Line 176:
 A: Follow these instructions: [[Unpacking .tar.gpg.zip file]] A: Follow these instructions: [[Unpacking .tar.gpg.zip file]]
  
 +===Q: Firewall is seeing fragmented packets from RADIUS servers?===
 +
 +A: If the RADIUS packets exceed the MTU size then they'll be fragmented. This normally happens only with EAP-TLS (client certificate based authentication). We have some suggestions on [[How to deal with fragmentation of EAP packets|how to deal with packet fragmentation]].
  
public/faq.1617789868.txt.gz · Last modified: 2021/04/07 10:04 by admin