QUT has setup an eduroam pilot site which is now operational. The eduroam site is located at Margaret Street from a single access point. There where several technical delays in setting up the pilot but these have all been resolved. Difficulties included

  • Access point configuration
  • Radius server configuration in particular OS and Library version mismatches
  • Host based and network Firewalls
  • Time settings on the access point causing certificates to be expired

The pilot Radius server has been linked into the Australian and World Radius hierarchy and has been successfully tested from end-to-end.

QUT, other QUESTnet Universities and AARNet participated in a virtual conference discussing issues related to the delivery of eduroam across the sector. The most significant issue raised was around inability to recover Internet traffic costs, particularly where universities are in close proximity. As a result of this discussion the QUESTnet Universities have decided to allow access only to 'FREE' traffic sites by default and rely on clients being able to create a VPN session back to their own institute. From there charging should occur through the home universities Internet changing systems. This is yet to be tested as a solution.

Issues

For QUT to move from pilot to production will require additional resources with a rollout performed in several phases. The first phase will most likely target Hot spots where visitors are likely to frequent such as lecture theaters, conference rooms and caf?s for example. During phase one each access point to participate in eduroam will need to be configured manually. Automatic configuration of access points will only be available after an upgrade to the QUT CISCO wireless infrastructure, planned for Q1 or Q2 2006. Phase 2 will complete the deployment by providing eduroam to all current and future access points. This will only occur when automatic access point configuration is available. Other activities included in a production rollout are;

  • Development of a QUT eduroam website
  • Development of 802.1x client software deployment package
  • Configuration options and testing of non-Windows based systems and other devices such as PDA's.
  • Setup and configuration of a production capable Radius server
  • Rollout eduroam SSID configuration to Access points
  • Education of Help desk staff
  • Publicity campaign
A complete list of production rollout activities is being developed into AMP project proposal that will include an estimate of resources and will be presented to various committees (TIDG, Management Team, PPO) for consideration.




 
© QRNO 2004