As national operators of eduroam, we designed the eduroam service in Canada to be resilient by hosting four Federation-Level RADIUS servers (FLRs) across Canada (two in the West and two in the East).

This document outlines the steps required to configure a Ruckus Cloudpath RADIUS server at an eduroam identity provider (IdP) site, accepting traffic from all four FLRs IP addresses in Canada. : https://www.canarie.ca/document/caf-firewall-and-ip-address-recommendations-for-eduroam/

Outbound RADIUS traffic from an eduroam Service Provider (SP) site to authenticate eduroam users who are roaming off-campus may be sent to any of the four FLRs, so when eduroam IdP sites configure all four FLRs on their server(s?), Radius traffic should flow unimpeded to authenticate their users while roaming abroad.

A limitation in the Cloudpath provisioning UI for eduroam (allowing just two FLRs IPs to be configured), could cause RADIUS request timeouts/failure, which would result in the inability to authenticate users and grant them access to eduroam.

The following steps provide a workaround to add additional FLRs IPs by opening all possible RADIUS pathways to maximize connectivity to the eduroam service for users whenever and wherever they are roaming  in Canada.

1.    Connectivity Issue Overview

Currently, only two FLRs IP addresses can be configured when onboarding an institution using Ruckus Cloudpath. This limitation opens the potential for RADIUS requests to be missed when directed to unconfigured IPs, leading to authentication failures.

The diagram below shows how RADIUS traffic could be missed when only two FLRs are configured:

2. Configuration Steps

Follow the steps below to update the Cloudpath configuration:

  1. Log in to your Cloudpath instance.

3. Final Notes

Completing this configuration will ensure that your institution’s RADIUS server can communicate with all four FLRs, virtually eliminating request timeouts and improving eduroam service availability and reliability for users while roaming at other eduroam sites across Canada.