public:implementing_govroam
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| public:implementing_govroam [2019/02/22 14:50] – [Q.A. Test of your Govroam implementation] admin | public:implementing_govroam [2025/03/28 14:53] (current) – ↷ Links adapted because of a move operation admin | ||
|---|---|---|---|
| Line 54: | Line 54: | ||
| Recommended viewing - video of James Hooper' | Recommended viewing - video of James Hooper' | ||
| <note warning> | <note warning> | ||
| - | . For slideset, see 'Resources' | + | . For slideset, see [[: |
| ==== Consider Wi-Fi and Network Architecture if offering Visited Service ==== | ==== Consider Wi-Fi and Network Architecture if offering Visited Service ==== | ||
| - | All Govroam services require you to deploy a RADIUS service. Ideally this should be a resilient service and comprise two servers, which may be physical boxes or virtual machines. Selection of the RADIUS server software is covered in the following | + | All Govroam services require you to deploy a RADIUS service. Ideally this should be a resilient service and comprise two servers, which may be physical boxes or virtual machines. Selection of the [[: |
| Consider the technological aspects of the network you wish to offer Govroam over. To provide a reasonably standard experience for users and to try reduce the amount of changes to supplicant and application settings required from site to site, the Tech Spec currently defines a single sets of network parameters based on WPA2 ' | Consider the technological aspects of the network you wish to offer Govroam over. To provide a reasonably standard experience for users and to try reduce the amount of changes to supplicant and application settings required from site to site, the Tech Spec currently defines a single sets of network parameters based on WPA2 ' | ||
| Line 129: | Line 129: | ||
| * [[https:// | * [[https:// | ||
| * [[https:// | * [[https:// | ||
| - | Your ORPS may be [[jisc: | + | Your ORPS may be [[public: |
| ===== Network Architecture ===== | ===== Network Architecture ===== | ||
| Line 228: | Line 228: | ||
| ====== Support Server Section ====== | ====== Support Server Section ====== | ||
| + | <note important> | ||
| ====== Install Your RADIUS Server (ORPS) ====== | ====== Install Your RADIUS Server (ORPS) ====== | ||
| Line 744: | Line 745: | ||
| ====Govroam network==== | ====Govroam network==== | ||
| - | Visited organisations must implement one (or more) dedicated network/ | + | Visited organisations must implement one (or more) dedicated network/ |
| Most participating organisations permit their own users to connect via the organisation' | Most participating organisations permit their own users to connect via the organisation' | ||
| Line 770: | Line 771: | ||
| * WEP must not be implemented on the Govroam Wi-Fi service that connects to the Govroam network service | * WEP must not be implemented on the Govroam Wi-Fi service that connects to the Govroam network service | ||
| * TLS interception proxies/ | * TLS interception proxies/ | ||
| - | Visited organisations may implement IPv4 and IPv6 filtering between the visitor VLAN and other external networks, providing that this permits the forwarding protocols detailed in the [[Firewall Configuration | + | Visited organisations may implement IPv4 and IPv6 filtering between the visitor VLAN and other external networks, providing that this permits the forwarding protocols detailed in the [[: |
| ==== Resources: ==== | ==== Resources: ==== | ||
| Line 1054: | Line 1055: | ||
| * testuser@realm - handled locally and NOT forwarded to NRPS | * testuser@realm - handled locally and NOT forwarded to NRPS | ||
| * invalidtestuser@realm - rejected locally and NOT forwarded to NRPS | * invalidtestuser@realm - rejected locally and NOT forwarded to NRPS | ||
| - | The [[following section]] focusses on invalid User-Name (ie those that do not conform to the Network Access Identifier standard). | + | The following section focusses on invalid User-Name (ie those that do not conform to the Network Access Identifier standard). |
| **Username Handling Conformance Check** - of particular importance in deployments where a single SSID ' | **Username Handling Conformance Check** - of particular importance in deployments where a single SSID ' | ||
| Line 1066: | Line 1067: | ||
| * testuser@anyrealm. (ends with a dot) - authentication should be dropped (User-Name realm MUST NOT end with ' | * testuser@anyrealm. (ends with a dot) - authentication should be dropped (User-Name realm MUST NOT end with ' | ||
| * testuser@myorganisationname..ac.uk (contains double dot) - authentication should be dropped (User-Name realm MUST NOT contain double ' | * testuser@myorganisationname..ac.uk (contains double dot) - authentication should be dropped (User-Name realm MUST NOT contain double ' | ||
| - | **Govroam Information Web Site** - you must have an information web site as detailed in the {{ : | + | **Govroam Information Web Site** - you must have an information web site as detailed in the {{ : |
| - | <note important> | + | |
| - | . | + | |
| * Govroam information page on organisation web site - yes | * Govroam information page on organisation web site - yes | ||
| Line 1114: | Line 1113: | ||
| ====== Mapping App ====== | ====== Mapping App ====== | ||
| + | <note important> | ||
public/implementing_govroam.1550847002.txt.gz · Last modified: 2019/02/22 14:50 by admin
