Similar documents
Deploying iphone and ipad Virtual Private Networks

IdentiFi and Eduroam Roaming Wireless Service Integration CONFIGURATION GUIDE

What is the Barracuda SSL VPN Server Agent?

WLAN Information Security Best Practice Document

Enabling Multiple Wireless Networks on RV320 VPN Router, WAP321 Wireless-N Access Point, and Sx300 Series Switches

Belnet Networking Conference 2013

NXC5500/2500. Application Note. Captive Portal with QR Code. Version 4.20 Edition 2, 02/2015. Copyright 2015 ZyXEL Communications Corporation

ADDENDUM 12 TO APPENDIX 8 TO SCHEDULE 3.3

Lab Configuring LEAP/EAP using Local RADIUS Authentication

Secure WiFi Access in Schools and Educational Institutions. WPA2 / 802.1X and Captive Portal based Access Security

Clientless SSL VPN Users

WiNG5 CAPTIVE PORTAL DESIGN GUIDE

CASPUR WI-FI OPEN SOURCE. GARR Conference Authors: A.Ferraresi, M.Goretti, D.Guerri, M.Latini (CASPUR) Speaker: Davide Guerri (CASPUR)

Step-by-step Guide for Configuring Cisco ACS server as the Radius with an External Windows Database

Configuring the Cisco ISA500 for Active Directory/LDAP and RADIUS Authentication

Eduroam wireless network Windows Vista

Cisco Secure Access Control Server 4.2 for Windows

Cisco Secure ACS. By Igor Koudashev, Systems Engineer, Cisco Systems Australia 2006 Cisco Systems, Inc. All rights reserved.

Configuring User Identification via Active Directory

Wireless Network Configuration Guide

ClickShare Network Integration

A practical guide to Eduroam

Virtual Private Network (VPN)

Eduroam wireless network Apple Mac OSX 10.4

DIGIPASS Authentication for Cisco ASA 5500 Series

ZyWALL OTP Co works with Active Directory Not Only Enhances Password Security but Also Simplifies Account Management

Configuring Global Protect SSL VPN with a user-defined port

Design and Implementation Guide. Apple iphone Compatibility

INTEGRATION GUIDE. DIGIPASS Authentication for F5 FirePass

Campus VPN. Version 1.0 September 22, 2008

Massey University Wireless Network - Client

Eduroam wireless network Apple Mac OSX 10.5

Cisco Virtual Office Express

Implementing and Administering Security in a Microsoft Windows Server 2003 Network

Edith Cowan University Information Technology Services Centre

NETASQ ACTIVE DIRECTORY INTEGRATION

KFUPM Enterprise Network. Sadiq M. Sait

Using Windows NPS as RADIUS in eduroam

Abstract. Avaya Solution & Interoperability Test Lab

Eduroam wireless network - Windows 7

Centrify Cloud Connector Deployment Guide

Security. TestOut Modules

DIGIPASS Authentication for GajShield GS Series

AAA & Captive Portal Cloud Service TM and Virtual Appliance

RWL Tech Note Wireless 802.1x Authentication with Windows NPS

Chapter 3 Authenticating Users

External Authentication with Netscreen 25 Remote VPN Authenticating Users Using SecurAccess Server by SecurEnvoy

Deploying iphone and ipad Apple Configurator

Mikrotik Router OS - Setup and Configuration Guide for Aradial Radius Server

2.1.1 This policy and any future changes requires ratification by CAUDIT.

Entrust IdentityGuard Comprehensive

Network Startup Resource Center

Access Your Cisco Smart Storage Remotely Via WebDAV

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

Aradial Enforcer / AAA Features & capabilities

How To Set Up An Ipa 1X For Aaa On A Ipa 2.1X On A Network With Aaa (Ipa) On A Computer Or Ipa (Ipo) On An Ipo 2.0.1

Aerohive Private PSK. solution brief

vwlan External RADIUS 802.1x Authentication

Accessing the Media General SSL VPN

INTEGRATION GUIDE. DIGIPASS Authentication for Citrix NetScaler (with AGEE)

Connecting to the University Wireless Network

User-ID Best Practices

Application Note. Onsight Device Certificate Management

External Authentication with Cisco VPN 3000 Concentrator Authenticating Users Using SecurAccess Server by SecurEnvoy

Using different Security Policies on Group Level for AD within one Portal. SSL-VPN Security on Group Level. Introduction

Deployment Guide: Cisco Guest Access Using the Cisco Wireless LAN Controller

Hosted Microsoft Exchange Client Setup & Guide Book

Wi- Fi settings for Windows XP

Phone: Fax: Box: 230

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

Training module 2 Installing VMware View

Case Study - Configuration between NXC2500 and LDAP Server

Network Security 1 Module 4 Trust and Identity Technology

Configuring Single Sign-on for WebVPN

Cisco Mobility Express Bundle. S&L Webinar

Virtuelle WLAN Controller Alcatel Lucent Wireless LAN Instant AP

VLANs. Application Note

Wireless VPN White Paper. WIALAN Technologies, Inc.

Authentication. Authentication in FortiOS. Single Sign-On (SSO)

VPN Overview. The path for wireless VPN users

How to configure MAC authentication on a ProCurve switch

Workspot Configuration Guide for the Cisco Adaptive Security Appliance

ipad or iphone with Junos Pulse and Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

Configuration of Cisco Autonomous Access Point with 802.1x Authentication for Avaya 3631 Wireless Telephone

User Identification (User-ID) Tips and Best Practices

Release Notes. Release Purpose... 1 Platform Compatibility... 1 Upgrading Information... 1 Browser Support... 1 Known Issues... 2 Resolved Issues...

Connecting to Delta College Exchange services off-campus

DIGIPASS Authentication for Citrix Access Gateway VPN Connections

Product Summary RADIUS Servers

Designing a Windows Server 2008 Network Infrastructure

Microsoft Lync Certification Configuration Guide for WiNG 5.5

DV230 Web Based Configuration Troubleshooting Guide

External Authentication with Cisco ASA Authenticating Users Using SecurAccess Server by SecurEnvoy

Transcription:

Implementation of federated authentication Case study Cesar Pacheco Politecnico di Torino Politecnico di Torino 2-3-4 March 2005 EuroCAMP

Working The members come from Departments of Politecnico, ISPs, Research Institute and ICT companies Ce.S.I.T. (ICT Project and mangement resources) coordinator Marcello Maggiora, Cesar Pacheco, Antonio Lantieri DAUIN (Control and Computer Engineering) Antonio Lioy DELEN (Electronics) TLC - Fabio Neri GESD (Student Support Services) Enrico Venuto ISMB (Istituto Superiore Mario Boella Research Institute) Daniele Mazzocchi, Daniele Brevi Telecom Italia Marco Boasso Hewlett-Packard external support Cisco Systems external support

Overview Politecnico di Torino Campus project Politecnico User databases Authentication methods WLAN Network Infrastructure Cisco ACS Implementation Proxy Radius Infrastructure Proxy Radius configuration for Eduroam and Telecom Italia roaming

Politecnico di Torino Campus 725 teachers, 600 technical and administrative employees 27,000 students 1000 courses for 70,000 hours/year of classes 17 campuses in Piemonte 10,000 fixed network points

Politecnico di Torino Campuses Torino: 10 Alessandria Aosta Biella Chivasso Ivrea Vercelli Mondovì 17

project The WiFi Project at Politecnico di Torino started in 2003 as an initiative to implement a scalable WLAN network for the geographically dispersed campus of Politecnico di Torino. Features: Centralized management of the covered radio areas Centralized authentication Centralized access control.

Politecnico User databases Politecnico Student Database HP Enterprise Directory Server (X.500) 40,000 users user@studenti.polito.it Personal and Teacher Database Stalker Communigate Pro V 4.18 (LDAP Directory) 3,000 users user@polito.it

Authentication methods SECURITY Auth. Models Status Autent. Mutual Security level (air) Username Prot. Password Prot. Data Prot. Suggested activities Open HTTPS SSL3 Enabled All areas Client Password Server Certificate Not at network level Internet Browsing Secure Apps Tunnel VPN Enabled All areas Client Password Like wired polito Users 802.1x WPA-TKIP Field test Client Password Server Certificate Low in MS-PEAP Like wired polito Users 802.1x EAP/TLS- WPA Lab. test Client Certificate Server Certificate Low - Like wired polito Users

STAT UTIL DUPLEX SPEED LINE PWR SYSTEM RPS 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 CATALYST 3550IN LINEPOWER 1 2 WLAN Network Infrastructure Athen Backbone Access Point 802.11 a/b/g POE Switch WLAN Open WLAN 802.1x SSID1 SSID2 Informative Portal Captive Portal DHCP Server Firewall ACS Radius Server Radio Management VPN Concentrator Internet

Cisco ACS Implementation For students database ODBC connection to X.500 Supports MS-CHAP authentication methods like PEAP-EAP-MSCHAP Limitations for digital certificates comparison For teachers and employees Bind LDAP v3 to LDAP Directory SAN or binary comparison for digital certificates Limitations for MS-CHAP authentication methods like PEAP-EAP-MSCHAP

Proxy Radius Infrastructure Proxy radius Athen Backbone Proxy radius Telecom Italia Garr Internet Central Proxy Radius (handler for polito.it) Bind LDAP v3 Students Radius ODBC Edu-Roam LDAP Directory X.500 Oracle

Proxy Radius Configuration Radius Servers shared secret (-Garr) Proxy Distribution Table polito.it domains local proxy wifiarea.it Telecom Italia other domains Garr -Eduroam

Questions Time http://wifi wifi.polito..polito.it Politecnico di Torino 2-3-4 March 2005 EuroCAMP