eduroam (education roaming) is an encrypted, world wide roaming access service developed for the international research and education community. eduroam allows students, faculty, and staff from participating institutions to obtain wireless connectivity when visiting other participating institutions by simply opening their device. This makes connecting to the Internet easy and convenient for conferences, research, or other reasons.

Any member of the UCSB community with a valid UCSBnetID and current affiliation can use eduroam. They can also connect to participating institutions' wireless network service as long as they configure eduroam on their device(s).

Your account must have a current Academic Affiliate, Contractor, Employee, Extension, Pre-hire or Student affiliation type. Your account name must be entered in the form [Your_UCSBnetID]@ucsb.edu. Logins will fail if "@ucsb.edu" is not included. Use your UCSBnetID password. Note: This might not be your actual email address. Do not change it to match your email address.

IMPORTANT: When planning to use eduroam at other participating institutions, we strongly recommend that you configure your device(s) while on the UCSB campus before you leave.

You must leave "@ucsb.edu" after your UCSBnetID. Appending @ucsb.edu is necessary to connect to the eduroam network both on and off campus. Note: This might not be your actual email address. Do not change it to match your email address.

Check the eduroam website for participating institutions in the US.

We strongly recommend that you configure your device for eduroam while on the UCSB campus before you leave. Once you are at a participating campus, all you have to do is turn on your device and it will connect automatically!

For general eduroam questions, contact the UCSB Network Operations Center (NOC) at noc@ucsb.edu while you are still on campus. We will not be able to provide assistance once you are away. The NOC does not provide device configuration and does not provide support for eduroam for visitors from other institutions.

Make sure you use [Your_UCSBnetID@ucsb.edu] for your username when configuring. Note: You must use @ucsb.edu (which might not be your actual email address) for eduroam to connect on and off campus. The IT Help Center at other institutions likely will not be able to help you troubleshoot your connection.

As long as your UCSBnetID remains active and you have a current affiliation, you can continue to connect to eduroam. Valid current affiliation types are Academic Affiliate, Contractor, Employee, Extension, Pre-hire, or Student. Graduates do not have one of these affiliation types unless they have made specific arrangements with a sponsoring academic department for an Academic Affiliate affiliation type.

Please see the eduroam website for news updates, and other relevant information.

Accounts

This section describes basic account information.
 

You can verify your UCSBnetID password on the UCSBnetID Diagnostics page. This is also where you can make sure your account has a valid affiliation which is eligible for wireless service.

Each UCSBnetID account may have one or more "affiliations", which indicate the relationship between the account holder and UCSB. For example, a current student would have a "student" affiliation. The affiliation information is automatically updated as people join and leave the campus.

Affiliations eligible for wireless service include:

  • Academic Affiliate
  • Contractor
  • Employee
  • Extension
  • Pre-hire
  • Student

You can verify your UCSBnetID password and check your current affiliation information on the UCSBnetID Diagnostics page.

The UCSBnetID is an account in the campus Identity system. Most students would recognize it as the account name used to access UMail or GOLD. Faculty use a UCSBnetID to submit grades via eGrades.

Faculty, staff and students can create a UCSBnetID or change the password for their existing UCSBnetID by visiting the Identity Manager page.

Client Configuration

This section addresses various questions regarding client configuration installation, management and support.
 

No special software is required to use the UCSB Wireless Web network, only a standard web browser is needed during the login process.

The eduroam network may require additional software. Some devices will not require any software installation, others will need to run a temporary program during configuration, and others may need to leave a program on the device for continued network access.

Android devices require the Cloudpath client application to complete the automatic setup process, but Cloudpath is not required if you choose to manually configure your Android device. Other operating systems may use Java during the setup process. Windows-based devices may need to download a configuration program if the Java-based configuration program is unable to run.

There are two pieces to remove, the configuration and the Cloudpath application.

  1. Remove the network from your WiF-Fi settings
    1. Go to Settings->Wi-Fi, then tap and hold the wireless network name (e.g. eduroam) and select "Forget network".
  2. Remove the Cloudpath application
    1. Go to Settings->Applications->All and tap on the Cloudpath application, then select "Uninstall."

iPad/iOS
Go to Settings->General->Profile and select the "UCSB Secure" profile, then select "Remove".

MacOS (e.g. MacBook)
Go to System Preferences->Profiles and select the "UCSB Secure" profile, then select the "-" (minus sign) in the lower left corner of the Profiles window to remove the profile.

Students
Students may contact the ITS Student Help Desk for assistance with device configuration.

Faculty and Staff
Faculty and staff should contact their department's IT support staff to inquire if they can assist you. Please note that personally-owned devices (i.e. those not owned by UCSB) are often not supported by departmental IT staff.

Other issues
If you suspect a problem with a wireless access point, your wireless account information or other issues, please contact noc@ucsb.edu for further assistance.

To help automate configuration of groups of settings — like those needed for a wireless network — Apple came up with a system where the necessary information could be placed in a "mobileconfig" file. This file could be loaded on an Apple device and thus greatly simplify the configuration process.

When the built-in Safari browser is presented with a mobileconfig file, the browser will pass the file to the System Preferences management process. The System Preferences management process will do things like prompting the user for approval of the new settings, gather necessary username and password information, etc., and then add the settings to the system. Unfortunately, Apple reportedly does not provide information to developers of other browsers, such as Chrome, which would allow them to also pass mobileconfig files to the System Preferences manager. For this reason we have to use Safari to process Apple's standard mobileconfig files.

Yes. Once properly configured, your Chromebook can be used wherever eduroam is available, including hundreds of educational institutions around the world. Follow these steps to configure your Chromebook:

  1. Open the Chromebook's settings menu by clicking on the clock in the lower-right corner, then select the "gear" icon at the top of the pop-up menu.
  2. Locate the "Network" settings near the top of the "Settings" window, and select "Add connection".
  3. Under "Add connection", select "Add Wi-Fi".
  4. Enter the settings as shown in the image below, using your UCSBnetID and password for the "Identity" and "Password" options. The options shown will change as you proceed with the configuration, so simply start at the top of the example and work all the way through to the bottom. (Note: The "Identity" must consist of your UCSBnetID@ucsb.edu – the @ucsb.edu suffix must be used to successfully log in to the eduroam network.) 
Image
Join Wi-Fi network - Screenshot image
  1. If the connection is successful, the Wi-Fi symbol will appear in the lower-right corner of the screen, showing a relative signal strength for the new eduroam connection.

Technical Details

This section provides specifications and addresses technical questions, which are more detailed than necessary for most users.
 

This is a list of all wireless settings used by the eduroam network. The information is not specific to any particular operating system. Not all settings are available or required in all operating systems. This information is provided for those who want to manually configure their wireless device.

SSID: eduroam
Mode: Infrastructure (not ad-hoc)
IPv4 address and DNS settings: Automatic via DHCP
Security Mode: WPA2-Enterprise
Encryption Type: AES
CA certificate: CA certificate: AAA Certificate Services Root (look for AAACertificateServices)
               Also known as Comodo_AAA_Services_root.pem on Linux systems
Connect to these servers OR "Domain": eduroam.wireless.ucsb.edu
Outer Authentication: PEAP
Outer (or anonymous) identity: anonymous@ucsb.edu
Inner Authentication: MSCHAPv2
Username (or Inner identity): [Your_UCSBnetID]@ucsb.edu
Password: [Your password]

PLEASE NOTE: You must include @ucsb.edu on both the Outer Identity and Inner Identity (Username), otherwise your login request will not be sent to UCSB for processing and your login will fail.

This is a list of all wireless settings used by the UCSB Secure network. The information is not specific to any particular operating system. Not all settings are available or required in all operating systems. This information is provided for those who want to manually configure their wireless device.

SSID: UCSB Secure
Mode: Infrastructure (not ad-hoc)
IPv4 address and DNS settings: Automatic via DHCP
Security Mode: WPA2-Enterprise
Encryption Type: AES
CA certificate: AddTrust External Root (look for addtrustexternalcaroot.crt)
Connect to these servers: ucsb-secure.wireless.ucsb.edu
Outer Authentication: PEAP
Outer (or anonymous) identity: anonymous
Inner Authentication: MSCHAPv2
Username (or Inner identity): [Your UCSBnetID]
Password: [Your password]

Some campus services limit or permit access to wireless clients. Clients of the wireless networks may be assigned IP addresses in the subnets listed below.

  • 169.231.80.0/20 (Campus wireless users)
  • 169.231.96.0/19 (Campus wireless users)
  • 169.231.128.0/20 (Campus wireless users)
  • 169.231.144.0/20 (Campus wireless users)
  • 169.231.160.0/20 (Campus wireless users)
  • 169.231.208.0/20 (Campus wireless users)

WPA2-Enterprise is a set of technical specifications created by a group known as the Wi-Fi Alliance in order to standardize authentication protocols between wireless clients and enterprise wireless access points. In simpler terms, it's an attempt to take what people like about their home wireless access and improve it for large campus and corporate environments ("enterprise" environments).

One of the biggest differences between a home access point and a campus access point is the campus access point must serve many more people. A home access point typically has one password (often known as WPA2-PSK, or Pre-Shared Key) to restrict access to a few people, but this kind of shared password system does not work in a large environment. Instead, the campus access points must be able to authenticate access based on each user's individual password.

One additional improvement is that WPA2-Enterprise can support per-user encryption between the user's device and the access point. A home access point using WPA2-PSK allows each person with the password to see some of the traffic of the other users.

The WPA2-Enterprise specifications include several kinds of authentication processes. UCSB has selected PEAP-MSCHAPv2 because it is commonly available on client devices and has good protection for passwords during the authentication process.

Operating systems known to support WPA2-Enterprise include:

  • Android 2.1 or newer
  • Apple MacOS 10.4 or newer
  • Apple iPad and iPhone
  • Windows XP with Service Pack 3 or later
  • Window Vista or newer (including Windows 10)

Whether a particular operating system will work on the wireless network depends in part upon the capabilities of the wireless network card. Sometimes an update of the wireless card's software (or driver) can help.

Many Linux-based systems support WPA2-Enterprise, though installation of optional software may be required.

Troubleshooting

Even while using the best wireless networks, problems will occur. This is particularly true when there are many people with lots of client devices. The following items should help resolve some of the more common issues.
 

There are several reasons why you might be unable to reach the UCSB Wireless Web login page. Check the following items to avoid the most common problems.

  • Make sure you've selected the UCSB Wireless Web network
    Sometimes people accidentally select the wrong wireless network, so double-check the wireless network name.
  • Visit a regular HTTP web site, not an encrypted HTTPS site
    Web site addresses look like http://www.ucsb.edu and usually start with "http". Some web site addresses start with "https", which means encryption is being used while communicating with the site. These HTTPS addresses can't be captured and redirected to the login page. Solution: Use HTTP by visiting a site like "http://www.ucsb.edu".
  • Use the DNS servers provided by DHCP, do not use custom DNS servers
    Computers use DHCP to get information needed to join a network, including a list of DNS servers. If your device has been configured to use a specific list of DNS servers, remove these servers and accept the servers provided by DHCP. The UCSB Wireless Web network uses DNS servers at 128.111.1.1 and 128.111.1.2.

If you use Windows and join the eduroam or UCSB Secure network for the first time, the connection may fail with a "Windows Security Alert". The message will likely say, "The Credentials provided by the server could not be validated." This is due to Windows not recognizing digital certificates used to help protect the login process. The automatic configuration utility on this site solves this problem by adding the certificate directly on your windows computer.

There are several reasons a device which previously worked on UCSB Secure may no longer work.

  • Your password has changed, but your device's configuration was not updated with the new password.
  • Your account was administratively disabled.
  • You have reached the maximum number of concurrent authenticated devices.

Wireless Coverage

Wireless isn't helpful if it's not available in your area. Issues regarding coverage are discussed below.
 

Wireless service is provided at the locations listed on our Wireless Networking page. Wireless signals are typically available beyond the areas in the coverage list, but these areas may have poor signal strength and unreliable connectivity, and thus are unsupported.

The eduroam network is available wherever UCSB wireless coverage is available. It is also available at other research and educational institutions world-wide. Participating institutions in the United States are available on a map. Information regarding international availability may be found at www.eduroam.org.

Temporary wireless installations are not available since they require equipment and staff resources and do not provide a long-term campus benefit.

Expansion of the campus wireless network has been based solely on funding from departments and other projects or initiatives, such as Collaborate. No central campus funds have been allocated for expanding wireless coverage. Departments seeking expanded coverage may have their information technology support staff contact noc@ucsb.edu to request a quote. When requesting a quote, please include specific room numbers to be covered.