JANET Roaming Service / eduroam
Newcastle University is a member of the JANET Roaming Service (JRS) which is part of the international roaming service eduroam.
JRS provides the infrastructure that allows Newcastle users to login at any participating institution using their Newcastle login name and password. JRS also allows users from any participating institution to login at Newcastle using their local login name and password.
JRS defines three different tiers of service which participating sites may adopt, Newcastle University implements the JANET Roaming Service Tier 2 which is the most commonly used. The service is wireless only using the SSID eduroam, 802.1x for access control with PEAP and MSCHAPv2 for encryption. This implementation provides the simplest solution for users.
Newcastle Users
Staff and students at Newcastle are able to try the eduroam service, this will allow users to test their configuration before leaving for another eduroam enabled institution. On campus staff and students should use the wireless service (newcastle-university).
While visiting other participating institutions users can connect to the local eduroam network to get an internet connection. You should configure your laptop as described in the following sections, depending on your operating system.
Windows XP
Windows Vista
Windows 7
Mac OS X (10.5 Leopard)
Linux
iPhone OS 3.0
Generic Settings
You must abide by the rules of use for the institution you are connected to and you should check the JRS web site at the institution before you arrive. Here is a list of participating institutions in the UK.
All users must comply with the JANET Roaming Policy
Visiting Users
Visitors must follow the local Rules of use, this includes using security software and secure protocols to avoid computer viruses.
You should connect to the wireless network using the SSID eduroam and an 802.1x supplicant. You will be assigned an IP address automatically from our DHCP servers and once authenticated allowed onto a visitor vlan. All traffic off campus goes through a transparent proxy where NAT is used to give you a public IP address. Network protocols are limited to the ports required by the JANET Roaming Service.
Users experiencing any technical problems with the Roaming service or with remote access facilities provided by their Home Organisation, should consult their Home Organisation IT Support.
All users must comply with the JANET Roaming Policy
Locations
eduroam is available on all campus access points, see the locations map
Network Ports
The following ports are open for eduroam users:
- IMSP: TCP/406 egress and established.
- IMAP4: TCP/143 egress and established.
- IMAP3: TCP/220 egress and established.
- IMAPS: TCP/993 egress and established.
- POP: TCP/110 egress and established.
- POP3S: TCP/995 egress and established.
- SMTPS: TCP/465 egress and established.
- Message submission: TCP/587 egress and established.
Web
- HTTP: TCP/80 egress and established.
- HTTPS: TCP/443 egress and established.
VPN
- Standard IPSec VPN: IP protocols 50 (ESP) and 51 (AH) both egress and ingress; TCP/500 (IKE) egress only.
- IPSec NAT traversal: UDP/4500 egress and established.
- Cisco IPSec NAT traversal: TCP/10000 egress and established.
- PPTP: IP protocol 47 (GRE) egress and established; TCP/1723 egress and established.
- OpenVPN: TCP/5000 egress and established.
- IPv6 Tunnel Broker NAT traversal: UDP/3653 and TCP/3653 egress and established.
Remote Desktop
- RDP: TCP/3389 egress and established.
- VNC: TCP/5900 egress and established.
- Citrix: TCP/1494 egress and established.
Directory Services
- LDAP: TCP/389 egress and established.
- LDAPS: TCP/636 egress and established.
Secure Shell
- SSH: TCP/22 egress and established.
File transfer
- Passive (S)FTP: TCP/21 egress and established.
