CAF – Firewall and IP address recommendations for eduroam

The table below summarizes the IP addresses and ports associated with the Canadian Federation-Level RADIUS servers (FLRs) for eduroam, and monitoring of IdP status for Federated Identity Management (FIM). CANARIE operates additional monitoring and operational tools for CAF services.  Participants are encouraged to use these tools and permit access to CANARIE on the listed ports below.  The list of IPs, protocols and ports below should be made accessible through provisioning of your site firewall rules.

Table 1: CAF Operational Server IP Addresses and Ports

ServiceLocationDNS CNAMEIPv4 AddressIPv6 AddressCAF Participant Site Ports RequiredPorts Accepted by This Host
eduroamKelowna BCprod1-west.eduroam.ca128.189.5.5 icmp ping, UDP & TCP 1812, 1813, 2083, 3799UDP: 1812, 1813
eduroamVancouver BCProd2-west.eduroam.ca142.231.112.1 icmp ping, UDP & TCP 1812, 1813, 2083, 3799UDP: 1812, 1813
eduroamOttawa, ONprod1-east.eduroam.ca205.189.33.1002001:410:102:1::100icmp ping, UDP & TCP 1812, 1813, 2083, 3799UDP: 1812, 1813
eduroamOttawa, ONprod2-east.eduroam.ca205.189.33.1012001:410:102:1::101icmp ping, UDP & TCP 1812, 1813, 2083, 3799UDP: 1812, 1813
eduroamOttawa, ONmonitor.canarie.ca205.189.33.552001:410:102:1::55icmp, ping, UDP & TCP: 1812, 1813, 2083, 3799, TCP: 443UDP: 1812, 1813
eduroamOttawa, ONtools.canarie.ca205.189.33.1112001:410:102:1::111icmp, ping, UDP & TCP: 1812, 1813, 2083, 3799, TCP: 443TCP: 443
FIMOttawa, ONlogger.canarie.ca205.189.33.232001:410:102:1::23icmp, ping, UDP & TCP: 1812, 1813, 2083, 3799, TCP: 443UDP: 514, TCP: 514
FIMToronto, ONcaf-shib2ops.ca128.100.132.106  UDP:ping
TCP: 443