RE: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Jason Cook
Thanks Brook, looks interesting will check it out in more detail. -- Jason Cook Technology Services The University of Adelaide, AUSTRALIA 5005 Ph    : +61 8 8313 4800 -Original Message- From: Brook Schofield [mailto:schofi...@terena.org] Sent: Tuesday, 13 November 2012 7:07 PM To: The

RE: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Jason Cook
All our data is taken from radius records (because WCS/NCS/Prime/[insert future name here] doesn't give us the reporting we want and probably never will), this gives us UID, MAC address's, IP address, time stamps, role (student/staff/visitor) which are imported into a home built database for qu

RE: [WIRELESS-LAN] Eduroam technical questions

2012-11-13 Thread Lee H Badman
Ah. You clever fella. Thanks for turning on the light. Lee H. Badman Network Architect/Wireless TME ITS, Syracuse University 315.443.3003 From: The EDUCAUSE Wireless Issues Constituent Group Listserv [WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] on behalf of Hanset, Phili

Re: [WIRELESS-LAN] Eduroam technical questions

2012-11-13 Thread Hanset, Philippe C
Robert, You are, of course, allowed to deactivate users that are reported for abuse. This is your institution's network! Philippe On Nov 13, 2012, at 10:12 AM, "Colantuoni, Robert" mailto:r...@buffalo.edu>> wrote: OK – one more question – We currently handling security reports regarding abu

RE: [WIRELESS-LAN] Report from Educause (the session was not streamed)

2012-11-13 Thread Brandon Abell
This free Mac app works pretty well without GPS and may be worth a try. Maybe not as good as the GPS-assisted solutions, but has worked well for my personal use: http://www.netspotapp.com/ Basically you just import an image from a satellite map or a scale drawing and then click two points on

Re: [WIRELESS-LAN] Report from Educause (the session was not streamed)

2012-11-13 Thread Mike King
Here's a screen shot from one I did previous to our outdoor deployment http://www.mpking.com/file/CampusSurvey.png (Only one I can find right now) On Tue, Nov 13, 2012 at 1:43 PM, Mike King wrote: > Ekahau has GPS assisted survey > http://www.ekahau.com/products/ekahau-site-survey/overview.html

Re: [WIRELESS-LAN] Report from Educause (the session was not streamed)

2012-11-13 Thread Mike King
Ekahau has GPS assisted survey http://www.ekahau.com/products/ekahau-site-survey/overview.html I've used it to map our outdoor Wifi deployment. You need a GPS, and you need to be a bit careful on how you collect your results. Driving 30MPH inside a car did not necessarily equate to walking aroun

Re: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Fligor, Debbie
On Nov 12, 2012, at 20:55, Jeff Kell wrote: > On 11/12/2012 9:41 PM, Lee H Badman wrote: >> Also... Does anyone get a bit turned off about having yet another SSID in >> the air, or debranding your own in favor of pushing Eduroam as your SSID? >> Again, just wondering. Let's task Phillipe with f

RE: [WIRELESS-LAN] Cisco ISE?

2012-11-13 Thread Eric T. Barnett
I'm curious. We're using ISE for WPA2/PEAP as well, but our GoDaddy cert keeps giving cert errors on pretty much anything. What cert are you using? Or is this normal? Thanks, Eric From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behal

Re: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Johnson, Neil M
James, That's a cool graph. What tool(s) did you use to create it? Thanks. -Neil -- Neil Johnson Network Engineer The University of Iowa Phone: 319 384-0938 Fax: 319 335-2951 Mobile: 319 540-2081 E-Mail: neil-john...@uiowa.edu On 11/13/12 5:26 AM, "James JJ Hooper" wrote: >> -Origi

Re: [WIRELESS-LAN] Eduroam technical questions

2012-11-13 Thread Hanset, Philippe C
Lee, Your campus only terminates EAP sessions for YOUR users. For visitors, you take the initial TLS negotiation (with the outer tunnel identity e.g. lhbad...@syr.edu, or anonym...@syr.edu, or @syr.edu ) and you pass it to the t

RE: [WIRELESS-LAN] Eduroam technical questions

2012-11-13 Thread Lee H Badman
Thanks, Phillipe- I'm talking more from supplicant config side. So we use Xpressconnect to configure our supplicants to only use MS-CHAPv2 /PEAP while disabling the other EAP types, and in RADIUS only have this single EAP type enabled. So if our Eduraom SSID required this EAP type, and someon

RE: [WIRELESS-LAN] Eduroam technical questions

2012-11-13 Thread Colantuoni, Robert
OK - one more question - We currently handling security reports regarding abuse on our wireless network by looking up the IP/User and then pushing the user account into a "deact" group and filtering for that on the radius server. This cuts off the users network access without affecting their ab

Re: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Hanset, Philippe C
For sanity, we will only pass to you *.northwestern.edu or other domains that you own and would like to be resolved e.g northwestern-1.edu On Nov 13, 2012, at 9:24 AM, Julian Y Koh wrote: > On Nov 12, 2012, at 18:34 , "Hanset, Philippe C" wrote: >> >> To answer the sub-domain question: we pas

Re: [WIRELESS-LAN] Eduroam technical questions

2012-11-13 Thread Hanset, Philippe C
Lee, eduroam is EAP agnostic. All that the roaming does is pass the initial SSL/TLS tunnel to the home institution. Then in the tunnel, exchanges occur between your device and your home institution So, as long as your institution does a tunneled EAP, your are done. The visited institution has n

Eduroam technical questions

2012-11-13 Thread Lee H Badman
I have read through the most recent docs, not quite grasping: - If we use MS-CHAPv2 w PEAP on our campus, and that's all we want to use, does that exclude us from Eduroam? - If not, what happens when I roam to another campus that uses TLS, or visa versa? The goal is autoconnection, with no

Re: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Julian Y Koh
On Nov 12, 2012, at 18:34 , "Hanset, Philippe C" wrote: > > To answer the sub-domain question: we pass to your University everything in > the form @*.university.edu > So you decide what to do. But that's still not recommended as per the eduroam best practices? Is there a requirement that the u

RE: Report from Educause (the session was not streamed)

2012-11-13 Thread Osborne, Bruce W
Philippe, So, in the US, power line AC is 60Hz and 802.11AC is 5Hz. What propagation range can we expect at sub-audio frequencies? Will this affect transmission of high fidelity sound on 802.11AC? Humorous typo :) I believe Aruba at one time had a solution (possibly unsupported) for outdoor

RE: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread James JJ Hooper
> -Original Message- > From: The EDUCAUSE Wireless Issues Constituent Group Listserv > [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Hanset, > Philippe C > Sent: 13 November 2012 00:35 > To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU > Subject: Re: [WIRELESS-LAN] eduroam question(s) > >

RE: [WIRELESS-LAN] eduroam question(s)

2012-11-13 Thread Lee H Badman
On the metrics, is there any way of showing how many of the Eduroam clients are bona ride visitors versus your own clients on the Eduroam SSID? That's the real delta I'm curious about in general- how many true visitors using it. Thanks, Lee Lee H. Badman Network Architect/Wireless TME ITS,