An eduroam wireless network is a wireless network. This sounds trivial, but it is important to keep in mind that
This section provides general advice regarding wireless LAN deployment. It is not meant as a replacement for further literature; there are many books and online publications regarding good wireless LAN planning, and you are encouraged to familiarise yourself with this topic.
(Editor's note: place all your helpful advice HERE! :-) )
Since an eduroam hotspot always uses the RADIUS protocol to connect to a RADIUS authentication server, your network setup must allow this RADIUS communication. This includes opening firewalls for traffic from the WLAN equipment (AP/Controller) to UDP port 1812 (do not confuse this with TCP!). The RADIUS protocol can easily create UDP fragments, and will not function fully without UDP fragmentation support. Be sure to check your equipment whether forwarding of UDP fragments is supported and allowed.
All of the solutions presented below support the basic requirements for an eduroam SP: support for IEEE 802.1X authentications, WPA2/AES support. When deploying eduroam, deployers often want to make use of additional features such as multi-SSID support, dynamic VLAN assignment and others. Every section contains a table with a short overview of their support of such additional useful features.
Feature | supported? |
---|---|
multi-SSID | yes |
VLANs | yes |
dynamic VLAN assignment | partial; not with IPv6 |
Feature | supported? |
---|---|
multi-SSID | yes |
VLANs | yes |
dynamic VLAN assignment | yes |
Feature | supported? |
---|---|
multi-SSID | yes |
VLANs | yes |
dynamic VLAN assignment | yes |
Feature | supported? |
---|---|
multi-SSID | yes |
VLANs | yes |
dynamic VLAN assignment | yes |
Feature | supported? |
---|---|
multi-SSID | no |
VLANs | no |
dynamic VLAN assignment | no |