140 likes | 286 Views
Cross-Campus WLAN Roaming Environment in Taiwan. Che-Nan Yang The National Center for High-performance Computing. Project Participant. Executive Department National Center for High-performance Computing technical staffs : Kevin Tang, Allen Huang. Advisory Board
E N D
Cross-Campus WLAN Roaming Environment in Taiwan Che-Nan Yang The National Center for High-performance Computing
Project Participant • Executive Department • National Center for High-performance Computing • technical staffs:Kevin Tang, Allen Huang • Advisory Board • National Science and Technology Program for Telecommunications • Project Leader • National Center for High-performance Computing • Director Chiunn-Shyong Yeh • National Taiwan University • Dr. Zsehong Tsai Professor
Roaming Platform Participants • National Taiwan University • National Cheng-chi University • National Chiao-Tung University • National Tsing-Hua University • National Central University • National Cheng-Kung University • National Chi-Nan University • National Chung-Hsing University • National Dong Hwa University • National Taipei University • National Yang-Ming University • National Taiwan Normal University • National Chung-Cheng University • National Taiwan Ocean University • National United University • National Hsinchu University of Education • National University of Tainan • National University of Kaohsiung • National Ilan University • National Taitung University • National Taiwan University of Science and Technology • National Yunlin University of Science and Technology • National Kaohsiung First University of Science and Technology • Northern Taiwan Institute of Science and Technology • Taipei Medical University Tamkang University Feng Chia University I-Shou University Soochou University Wufeng Institute of Technology Vanung University Huafan University Kaohsiung Medical University Ming Chuan University Providence University Da-Yeh University Shih Hsin University Yuan Ze University Chung Hua University Chinese Culture University Hsiuping Institute of Technology Ling Tung University Lunghwa University of Science and Technology Takming College Jin Wen Institute of Technology Fooyin University Tatung University Mingdao University St. John’s University Yuanpei Institute of Science and Technology Can roaming between 110+ universities in Taiwan. And over 900,000 user accounts are being served.
Project Brief • Objectives • Provide the WLAN roaming environment in campus. • Promote WLAN applications. • Cross-Campus WLAN Roaming Security Enhancement • Tasks • Construct the roaming platform and the operation and maintenance manual. • Build the Web-based and 802.1x Authentication environments to test the roaming platform. • Promote and provide the technical support to build the WLAN roaming environment. • Evaluate campuses’ WLAN environment and support them to join the WLAN roaming platform. • Construct the web site to provide WLAN cross-campus roaming information and service consultation. • International WLAN Roaming Cooperation
Services • Current Services • Mobile users can use their own accounts and passwords to pass through the authentication mechanism in other campuses through the WLAN Roaming Center. • Future Services • Establish a standard cross-campus authentication architecture • Tele-courses • VoIP/Viedo Phone Applications
Status of Taiwan’s Campus WLAN(2007,Q3) Total:163 Univ. and Colleges Non Roaming 29% In Roaming 71% No plan for Campus WLAN 2% Will complete Campus WLAN in 2 years: 3% Campus WLAN ready: 95%
RADIUS Server (in campus) Roaming Center (NCHC) Roaming Server (Linux Red Hat/Fedora) Firewall OpenVPND RADIUS Server with Proxy ( FreeRadius, SNMP enabled ) Roaming Server – Software Architecture • The “FreeRADIUS” implements the RADIUS protocol and uses the RADIUS-Proxy to communication with Roaming Center. • The “Firewall” controls the access right to Roaming Server. • The “OpenVPND” builds the secure tunnel between Roaming Server and Roaming Center. • Roaming Center uses the “SNMP” to monitor the status of Roaming Server. VPN TUNNEL
Current Authentication in Taiwan’s Campus WLAN • Web-based UAM (Universal Access Method)- 92% • PRO • Easy implementation/ Easy installation • Supporting multiple OS. UNIX、LDAP、SQL Server …etc • CON • Phishing is possible. • 802.1x EAP (Extensible Authentication Protocol)- 5% • PRO • Standardized Authentication with many option • Better security level • If EAP-TTLS is used, multiple account authentication systems can be supported • CON • Access Point and client need to support 802.1x • Higher installation cost • Others- 3% • MAC address • Open
Major Applications in Taiwan’s Campus WLAN • The most popular use of WLAN in campus includes: • Internet Access • Download class material • E-Mail • E-learning • Administration (parking control, etc) • Library • MSN,Yahoo Messenger, ICQ… • VoIP • Web TV
International WLAN Roaming • collaboration with the eduroam project for international WLAN roaming services. • Authentication mechanism : 802.1x EAP-TTLS • Eduroam project website : http://www.eduroam.org/ Eduroam Europe Eduroam Asia-pacific
400+ hotspots 100+ hotspots International WLAN Roaming Map Taiwan Cross-Campus WLAN Roaming eduroam International Roaming
Current and Future Works • WLAN/WMAN Security Enhancement • To continuously assess and enhance the security level of campuses and project-sponsored WLAN hot spots • Web site to provide roaming information, security announcement and consultation • 802.1x Promotion and Migration • To migrate from Web-based Access to 802.1x EAP • To integrate EAP-TTLS or EAP-SIM authentication in the WLAN roaming platform • To extend the roaming services from campus to island-wide • To support VoIP * Balanced among security, ubiquity, and cost!
Relative Sites • National Science and Technology Program for Telecommunications http://www.ntpo.org.tw/eng/ • National Center for High-performance Computing http://www.nchc.org.tw/english/index.php • WLAN Cross-Campus Roaming Project Web Site http://wlanrc.nchc.org.twhttp://wlanrc.nchc.org.tw/web_eng/index1-1.html (English version)