<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.emfcamp.org/2022/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Russ</id>
	<title>Electromagnetic Field 2022 - User contributions [en-gb]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.emfcamp.org/2022/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Russ"/>
	<link rel="alternate" type="text/html" href="https://wiki.emfcamp.org/2022/wiki/Special:Contributions/Russ"/>
	<updated>2026-04-23T01:11:53Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.6</generator>
	<entry>
		<id>https://wiki.emfcamp.org/2022/w/index.php?title=Phones&amp;diff=1792</id>
		<title>Phones</title>
		<link rel="alternate" type="text/html" href="https://wiki.emfcamp.org/2022/w/index.php?title=Phones&amp;diff=1792"/>
		<updated>2022-06-04T12:25:40Z</updated>

		<summary type="html">&lt;p&gt;Russ: /* Telet/EMF Cells */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=DECT=&lt;br /&gt;
&lt;br /&gt;
The Phone Operation Center (powered by [https://www.eventphone.de/ Eventphone]) will be present at the EMF Camp this year providing site-wide DECT telephone access. &lt;br /&gt;
&lt;br /&gt;
You can bring your own DECT telephone and join the network, enabling you to call other EMF participants and interactive services for free.&lt;br /&gt;
&lt;br /&gt;
== Compatibility ==&lt;br /&gt;
&lt;br /&gt;
Use the [https://eventphone.de/doku/dect_phone_compatibility_list DECT Phone Compatibility List] to find out if your phone is compatible.&lt;br /&gt;
&lt;br /&gt;
== Registration ==&lt;br /&gt;
&lt;br /&gt;
To secure your personal extension in advance please [https://guru3.eventphone.de/register.jsf?environment=production register for an account]. Once logged in you can [https://guru3.eventphone.de/extension.swf/new create a new extension] - remember to set the type to &amp;quot;DECT&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once you're in range of the network you can instruct your phone to join.&lt;br /&gt;
&lt;br /&gt;
1. Find the &amp;quot;Register&amp;quot; option in your phone's menus. This varies between models, and you may need to do it more than once.&lt;br /&gt;
&lt;br /&gt;
2. If you're prompted for a pin try 0000&lt;br /&gt;
&lt;br /&gt;
3. Once your phone has registered, click the key icon within Guru3 and call the number shown to claim your personal extension&lt;br /&gt;
&lt;br /&gt;
4. You're now connected to the network and call other users.&lt;br /&gt;
&lt;br /&gt;
=POTS (Plain old telephone service)=&lt;br /&gt;
&lt;br /&gt;
There will be a site-wide POTS network allowing you to connect a traditional analog phone to a phone line, with support for modems and fax machines.&lt;br /&gt;
&lt;br /&gt;
For more information see [[Village:CuTEL_HQ|CuTEL_HQ]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Info Pages]]&lt;br /&gt;
&lt;br /&gt;
=External Calls=&lt;br /&gt;
==Outbound==&lt;br /&gt;
&lt;br /&gt;
NO outbound dialing from SIP extensions!&lt;br /&gt;
&lt;br /&gt;
You can dial most PSTN number you like from the fixed phones at the venue and also from the DECT phones.&lt;br /&gt;
Outbound calls are limited to a maximum duration of 10 minutes. The call will be disconnected, reaching the limit. A warning beep will be played 30 seconds before.&lt;br /&gt;
There is no need for a special prefix, just dial the number in national or international format.&lt;br /&gt;
UK numbers don't need a country code. International numbers should start with double zero not plus.&lt;br /&gt;
&lt;br /&gt;
==Inbound==&lt;br /&gt;
You can receive calls on the camp network from the outside world, callers can dial;&lt;br /&gt;
&lt;br /&gt;
    +44 330 053 2800 (UK)&lt;br /&gt;
    +1 313 631 2600 (US)&lt;br /&gt;
&lt;br /&gt;
And then enter your extension number followed by #&lt;br /&gt;
&lt;br /&gt;
===== Alternative way with DID (direct inward dialling) =====&lt;br /&gt;
Using this way you might call all extensions directly.&lt;br /&gt;
&lt;br /&gt;
CAUTION: This might not work with every network operator. The number length might cause issues.&lt;br /&gt;
&lt;br /&gt;
     +49 221 5961909 [YOUR EXTENSION] (DE)&lt;br /&gt;
&lt;br /&gt;
=Cellular=&lt;br /&gt;
The main 4 UK networks have patchy coverage on site, at the moment Vodafone seems to be marginally better.&lt;br /&gt;
&lt;br /&gt;
==Telet/EMF Cells==&lt;br /&gt;
&lt;br /&gt;
We have 2 GSM/LTE (2G/4G) cells on site provided by [https://teletresearch.com/ Telet Research], these provide our own low power mobile network. &lt;br /&gt;
'''This service is very experimental!&lt;br /&gt;
'''&lt;br /&gt;
You can access the network with your regular SIM card and mobile number, your phone should automatically roam onto this network if it doesn't see your regular providers signal. Your calls will still work as normal on your existing number.&lt;br /&gt;
&lt;br /&gt;
The cells offer 4G/LTE Data but Voice is only on 2G/GSM, so if you try to make a call there may be some delay while the phone drops down to 2G to complete the call.&lt;br /&gt;
There is only 3MHz of LTE spectrum allocated which equates to around 6-7mbps for everyone so please don't run speed tests just to see what you get, its not fast!&lt;br /&gt;
The network code for this is 235 88 and should appear on your phone as Telet/EMF, you may also see the network name Wavemobile.&lt;br /&gt;
&lt;br /&gt;
===Roaming Messages===&lt;br /&gt;
You may get a text message from your operator that says you are roaming in Jersey, this is due to the way the Telet cells run, they relay the signalling traffic through Jersey Telecom in order to provide access for existing sims.&lt;br /&gt;
Please do not worry about roaming charges no calls or data go back to your operator they are passed out to the public networks via Telet and no billing records are sent to the home carrier.&lt;br /&gt;
&lt;br /&gt;
===Cell Locations===&lt;br /&gt;
One cell is located in HQ and the other is a DK at the north end of the site, there isn't much particularly interesting to look at, they're just a box with antenna ports, a PoE network connection and a GSM antenna (for synchronisation)&lt;br /&gt;
&lt;br /&gt;
===Calls to the camp network===&lt;br /&gt;
When on the Telet/EMF cellular network you can call directly to the camp network by prefixing the number with 363 (EMF) so to call the info desk you would dial 3631001, your regular mobile number will be sent as caller ID.&lt;br /&gt;
&lt;br /&gt;
===Questions===&lt;br /&gt;
Any questions about this service can be directed to the POC via the Infodesk.&lt;br /&gt;
&lt;br /&gt;
==WiFi Calling==&lt;br /&gt;
We have done some work on the WiFi network to enable access for WiFi calling to UK providers, previously this hasn't worked as the IP range we use appears to the carrier as being in Germany and most then block WiFi Calling, However we have solved this, wifi calling should just work normally the same way as it does at home from any of the camp wifi networks.&lt;br /&gt;
&lt;br /&gt;
Again please direct questions about WiFiCalling to the POC via the Infodesk.&lt;/div&gt;</summary>
		<author><name>Russ</name></author>
	</entry>
	<entry>
		<id>https://wiki.emfcamp.org/2022/w/index.php?title=Network&amp;diff=1662</id>
		<title>Network</title>
		<link rel="alternate" type="text/html" href="https://wiki.emfcamp.org/2022/w/index.php?title=Network&amp;diff=1662"/>
		<updated>2022-06-01T20:59:28Z</updated>

		<summary type="html">&lt;p&gt;Russ: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right;&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
[[Team:NOC]] has tried to build and support the fastest network for you: a network comparable to a medium sized ISP, built up in just a couple of days. It might not be perfect all the time. We will be providing blanket wireless coverage and wired network access to both venues and camping tents.&lt;br /&gt;
&lt;br /&gt;
=== Key points ===&lt;br /&gt;
&lt;br /&gt;
* To use the camp WiFi on most modern devices, connect to the '''emfcamp''' network with a username of '''emf''' and a password of '''emf'''.&lt;br /&gt;
* If you're using a modern Android phone (Android 10 or above), the '''emfcamp-insecure22''' network is easier to configure, and it will be encrypted (despite the name).&lt;br /&gt;
* Don't set up your own wireless access point. This is a serious problem in such a dense event and [[Network/Rogue Access Points|here's why]].&lt;br /&gt;
&lt;br /&gt;
== Wireless ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;dl&amp;gt;&lt;br /&gt;
  &amp;lt;dt&amp;gt;Network Name (SSID)&amp;lt;/dt&amp;gt;&lt;br /&gt;
  &amp;lt;dd&amp;gt;emfcamp&amp;lt;/dd&amp;gt;&lt;br /&gt;
  &amp;lt;dt&amp;gt;Username&amp;lt;/dt&amp;gt;&lt;br /&gt;
  &amp;lt;dd&amp;gt;emf&amp;lt;/dd&amp;gt;&lt;br /&gt;
  &amp;lt;dt&amp;gt;Password&amp;lt;/dt&amp;gt;&lt;br /&gt;
  &amp;lt;dd&amp;gt;emf&amp;lt;/dd&amp;gt;&lt;br /&gt;
&amp;lt;/dl&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The whole field has been covered with many wireless access points to ensure the best possible coverage and to allow you to roam seamlessly without interruption. Please note that your device will be reachable by anyone on the internet, please take suitable precautions such as turning on a firewall, and making sure your software is up to date.&lt;br /&gt;
&lt;br /&gt;
You should not bring your own wireless access point, its unlikely to provide better service than the camp ones, and it makes the network worse for everyone else. Any rogue access points will be hunted down and disconnected from the network - see [[Network/Rogue_Access_Points]] if you want to know why. If you have a project that needs to provide its own AP for some reason please contact the NOC and we will find an alternative solution.&lt;br /&gt;
&lt;br /&gt;
Here is the complete list of wireless networks (SSIDs) available:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! emfcamp&lt;br /&gt;
| This is 2.4GHz + 5GHz and should you should use this one in preference, if you can see it. This is the most secure, WPA2-Enterprise. However, it's a pain to configure on Android devices.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap&amp;quot; | emfcamp-insecure22&lt;br /&gt;
| '''Warning: insecure on some devices''' This is both 5GHz and 2.4GHz, and can be used for older devices that don't support WPA2-Enterprise. If your device supports [https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encryption Opportunistic Wireless Encryption], such as Android 10 or above, this is encrypted, although not quite as secure as the '''emfcamp''' SSID. Otherwise, it's unencrypted, and people will likely intercept your traffic. Inbound connections from the rest of the campsite are possible, inbound connections from the Internet are blocked.&lt;br /&gt;
|-&lt;br /&gt;
! spacenet&lt;br /&gt;
| This is 2.4GHz + 5GHz and WPA2-Enterprise, you can connect with a valid account if your hackerspace offers.&lt;br /&gt;
|-&lt;br /&gt;
! eduroam&lt;br /&gt;
| This is 2.4GHz + 5GHz and WPA2-Enterprise, you can connect with a valid account if your university/college/school is offering eduroam. More information can be found at [https://www.eduroam.org/ eduroam.org].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When connecting to any of the WPA2-Enterprise password, which require a username and password, you can use the following (case-sensitive):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Username&lt;br /&gt;
! Password&lt;br /&gt;
! Result&lt;br /&gt;
|-&lt;br /&gt;
| emf&lt;br /&gt;
| emf&lt;br /&gt;
| Filtered connection with public IP address. Inbound connections from the rest of the campsite are possible, inbound connections from the Internet are blocked.&lt;br /&gt;
|-&lt;br /&gt;
| allowany&lt;br /&gt;
| allowany&lt;br /&gt;
| Unfiltered connection with public IP address&lt;br /&gt;
|-&lt;br /&gt;
| outboundonly&lt;br /&gt;
| outboundonly&lt;br /&gt;
| Filtered connection with public IP address. Inbound connections from the Internet or camp-site are not possible.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Use of the 5GHz SSIDs is recommended if your device supports them. 802.11b is disabled as it slows everyone else down.&lt;br /&gt;
&lt;br /&gt;
Even if you are using an encrypted network, you should still [[#Encryption|encrypt any sensitive traffic]] sent over the air end-to-end to prevent snooping. Although some SSIDs offer encryption, it is only over-the-air.&lt;br /&gt;
&lt;br /&gt;
We have airtime fairness configured on our wireless controllers, so if you wish to use a lot of bandwidth (e.g. stream videos or download large files), please use a [[#Wired|wired connection]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Client Settings ====&lt;br /&gt;
Also see [[Network/802.1X client settings]] for a list of OS-specific client settings.&lt;br /&gt;
&lt;br /&gt;
 SSID: emfcamp&lt;br /&gt;
 &lt;br /&gt;
 EAP-TTLS:&lt;br /&gt;
 &lt;br /&gt;
 Phase 1: EAP-TTLS&lt;br /&gt;
 Phase 2: PAP&lt;br /&gt;
 &lt;br /&gt;
 PEAP:&lt;br /&gt;
 &lt;br /&gt;
 Phase 1: PEAP&lt;br /&gt;
 Phase 2: MSCHAPv2 or EAP-MSCHAPv2 or PAP&lt;br /&gt;
 &lt;br /&gt;
 CN = radius.emf.camp&lt;br /&gt;
 CA = ISRG Root X1&lt;br /&gt;
&lt;br /&gt;
 SHA256 Fingerprint = B8:3B:F9:39:C4:F2:BF:D0:87:D7:93:5C:A0:DD:18:F3:31:7B:DD:B1:EC:88:3B:22:E0:B2:39:CB:7C:F8:FD:43&lt;br /&gt;
&lt;br /&gt;
Make sure '''you check the certificate''' in order to know you are connecting to the correct network (you should check on both the CN and the CA). Check [[Network/RADIUS_certificate|here]] for the complete certificate.&lt;br /&gt;
&lt;br /&gt;
[[File:Ubuntu network settings.png|thumb|Ubuntu network settings]]&lt;br /&gt;
On Ubuntu/Debian based distros the certificate file can be found in /etc/ssl/certs/ISRG_Root_X1.pem&lt;br /&gt;
&lt;br /&gt;
'''Android'''&lt;br /&gt;
&lt;br /&gt;
This app will help you get set up: https://play.google.com/store/apps/details?id=nl.eventinfra.wifisetup. Or follow [[Network/802.1X_client_settings#Manually|these instructions]] to do it manually.&lt;br /&gt;
&lt;br /&gt;
== Wired Ethernet ==&lt;br /&gt;
&lt;br /&gt;
All camping areas are within 60m of a datenklo (or data toilet), where you can connect to the network. If you intend to do so please bring 60-70m of CAT5 cable as we are unable to provide any.&lt;br /&gt;
&lt;br /&gt;
Lay your own cable neatly from your tent back to the nearest Datenklo, and leave 6m of slack coiled on the floor in front of it. And please lay it so that it can be clearly seen that it needs to be plugged in - or you risk having your cable overlooked. At regular intervals a member of the NOC team will connect it up and enable the port.&lt;br /&gt;
&lt;br /&gt;
If you wish to be removed from a Datenklo again on Sunday or Monday, leave your entire cable coiled outside the DK and we will disconnect it. If you need to leave before then, contact the [[Team:InfoDesk|helpdesk]] directly.&lt;br /&gt;
&lt;br /&gt;
All of our edge ports are at least 100 Mbps or 1 Gbps, auto-negotiate, auto-MDX. We are unlikely to have PoE ports for general use.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Note that most of our ports will not support 10 Mbps - if you need it for old equipment or embedded things, please bring your own switch to convert. !--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Static IPs ==&lt;br /&gt;
&lt;br /&gt;
If you need a static IP on the wired network, contact the NOC.&lt;br /&gt;
&lt;br /&gt;
== IPv6 ==&lt;br /&gt;
&lt;br /&gt;
Naturally, IPv6 is available throughout the network and should &amp;quot;just work&amp;quot; for you. [[Team:NOC]] does not recommend disabling IPv6 if you have problems, instead try to understand the problem you are experiencing and get educated in the new world order. Contact the [[Team:InfoDesk|NOC helpdesk]] if you need help.&lt;br /&gt;
&lt;br /&gt;
== Services ==&lt;br /&gt;
&lt;br /&gt;
* DNS: 78.158.87.11 and 78.158.87.12&lt;br /&gt;
* NTP: 78.158.87.11 and 78.158.87.12 (ntp1.emf.camp and ntp2.emf.camp)&lt;br /&gt;
* Nearest Debian mirror: http://debian.mirror.uk.sargasso.net&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security ==&lt;br /&gt;
&lt;br /&gt;
=== Encryption ===&lt;br /&gt;
&lt;br /&gt;
Please treat the network as wide open and full of attackers. Although [[Team:NOC]] themselves will not monitor the network, always assume that Alice flirting with Bob will be spied upon by The Third Party.&lt;br /&gt;
&lt;br /&gt;
Any sensitive information including passwords must therefore be encrypted. Please make sure you don't use any software or web applications that send sensitive data or passwords in the clear.&lt;br /&gt;
&lt;br /&gt;
The following mechanisms should be safe:&lt;br /&gt;
* Anything that goes through a VPN&lt;br /&gt;
* Any website that uses HTTPS&lt;br /&gt;
* Any application that uses SSL&lt;br /&gt;
** In the case of email, you need to have SSL enabled for both receiving mail (POP, IMAP) and sending it (SMTP)&lt;br /&gt;
* ssh and scp&lt;br /&gt;
* Where possible, use One-time passwords. Real tokens work best, many of those should be compatible with open source radius servers. [http://perlmonks.org/?node=967433 Here] is a simple Perl radius server implementation for [http://tools.ietf.org/html/rfc6238 RFC6238] tokens that works with ssh and other stuff on linux.&lt;br /&gt;
&lt;br /&gt;
The following are almost always unsafe:&lt;br /&gt;
&lt;br /&gt;
* FTP with login/password (are almost always sent in the clear)&lt;br /&gt;
* Telnet with login/password&lt;br /&gt;
* Email if you don't use SSL&lt;br /&gt;
* Webmail that doesn't use HTTPS&lt;br /&gt;
** Someone could trigger a password reminder and then intercept your email&lt;br /&gt;
* Websites that use HTTP (not HTTPS) where you need to fill in a password in the page itself&lt;br /&gt;
&lt;br /&gt;
Possibly unsafe, make sure that you understand what you're doing:&lt;br /&gt;
&lt;br /&gt;
* Websites where you need to fill in a password and your ''browser'' (not the website!) tells you it's going to be sent securely&lt;br /&gt;
* Websites that require an account but remember you're logged in&lt;br /&gt;
** The password ''may'' be protected but not the content or cookies that automatically log you in&lt;br /&gt;
* Any time your browser or other application brings up ''anything'' to do with a certificate&lt;br /&gt;
* Anything not protected with SSL: someone could be faking DNS answers to impersonate certain sites&lt;br /&gt;
&lt;br /&gt;
Remember: if you're being stupid someone may feel the need to teach you a security lesson in a not so subtle way! (No, that doesn't mean it's ok to hack people just to see if their security is in order.)&lt;br /&gt;
&lt;br /&gt;
=== Firewall ===&lt;br /&gt;
&lt;br /&gt;
On the wired network there is no network firewall and on the WiFi network there is limited firewalling in place. We operate an unfiltered network that is wide open to the Internet. There is no NAT, and everybody has a public IP address. This is our definition of &amp;quot;network neutrality&amp;quot; - a network that doesn't do anything whatsoever to your IP connection.&lt;br /&gt;
&lt;br /&gt;
If you are used to feeling secure just because you've been sitting behind a NAT router, think again. You are now wide open to the whole Internet. Ensure your personal firewall is enabled and set to &amp;quot;Public Network&amp;quot; and that you have applied all security updates to your OS and applications.&lt;br /&gt;
&lt;br /&gt;
By default the WiFi network allows inbound connections from the rest of the campsite, but inbound connections from the Internet are blocked. If you want to ensure no inbound connections are possible towards your WiFi device, use the &amp;quot;outboundonly&amp;quot;-login. &lt;br /&gt;
&lt;br /&gt;
In case you want to enable inbound connections towards your WiFi-device, use the &amp;quot;allowany&amp;quot;-login.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== Can I bring a server? ===&lt;br /&gt;
&lt;br /&gt;
Sure. You can host a server anywhere on the network, and the long DHCP lease time will effectively give you a static IP address.&lt;br /&gt;
&lt;br /&gt;
If you would like to house your server in our data centre (NOC-DC), please contact us before the event by e-mail to noc@. 1 Gbps copper ports are standard; if you require a 10 Gbps port, you'll need to supply a DAC or SFPs (our end Arista-coded) with fibre.&lt;br /&gt;
&lt;br /&gt;
=== Is there a server I can use to host data on site? ===&lt;br /&gt;
&lt;br /&gt;
Due to lack of demand at the last event, this will not be provided this time.&lt;br /&gt;
&lt;br /&gt;
=== Can I use the 2.4GHz band for non-wifi projects? ===&lt;br /&gt;
&lt;br /&gt;
The following channels are available for adhoc/mesh/other wireless stuff:&lt;br /&gt;
&lt;br /&gt;
* 2.4GHz: Channel 1 &lt;br /&gt;
* 5GHz: Channel 136, 140&lt;br /&gt;
&lt;br /&gt;
We cannot force you to use these channels, but we are trying to build a functional wireless network for the other attendees too. So please, don't do any experiments on other channels.&lt;br /&gt;
&lt;br /&gt;
=== Can I bring an access point? ===&lt;br /&gt;
&lt;br /&gt;
No, this is strictly prohibited! We need all available channels to provide good quality coverage for the rest of the attendees. Please do not be selfish here as you will degrade performance for everyone else, and we WILL track you down.&lt;br /&gt;
&lt;br /&gt;
If you think you can ignore this rule because one little access point can't hurt anyone, think again. This page has the calculations on just how huge a problem it is for an event of our size: [[Network/Rogue Access Points]].&lt;br /&gt;
&lt;br /&gt;
If you are operating a village (using an EMF-supplied tent) that has poor coverage, we may be able to arrange to put an extra access point in it during the event to improve coverage. Stop by the NOC and ask.&lt;br /&gt;
&lt;br /&gt;
=== Can I bring a switch? ===&lt;br /&gt;
&lt;br /&gt;
Yes, but for stability purposes all edge ports are limited to 10 MAC addresses at a time. If you want to connect a switch with more stations, you need to stop by the NOC and ask us to raise the port-security on your port. If you do this, you need to convince us that you know what you're doing and promise not to do anything that may harm the network - in particular, you must not connect the switch to our network by more than 1 cable (not even to a different DK). Make sure that you disable STP and other protocols on your switch which try to be intelligent.&lt;br /&gt;
&lt;br /&gt;
=== My port goes up and down every couple of minutes ===&lt;br /&gt;
&lt;br /&gt;
You have probably tripped port security. Most likely scenario is that you have connected more than 10 stations without consulting us (see answer to previous question). To reduce support calls, the port will automatically be re-enabled after a few minutes. But if you haven't fixed the problem, it will immediately be shut down again.&lt;br /&gt;
&lt;br /&gt;
== Supporters ==&lt;br /&gt;
&lt;br /&gt;
We'd like to extend our immense gratitude to the following people and organisations who have been instrumental in making the EMF network and uplink happen through their donations and sponsorship:&lt;br /&gt;
&lt;br /&gt;
* [https://ethernet.business.sky.com Sky For Business]&lt;br /&gt;
* [http://www.sargasso.co.uk/from/emfcamp Sargasso Networks]&lt;br /&gt;
* [https://eventinfra.org EventInfra]&lt;br /&gt;
* [https://www.lonap.net LONAP]&lt;br /&gt;
* [https://www.comtec.com Comtec Enterprises]&lt;br /&gt;
* [https://www.mythic-beasts.com/ Mythic Beasts]&lt;br /&gt;
* [https://www.i3d.net/ i3D.net]&lt;/div&gt;</summary>
		<author><name>Russ</name></author>
	</entry>
	<entry>
		<id>https://wiki.emfcamp.org/2022/w/index.php?title=Network&amp;diff=1661</id>
		<title>Network</title>
		<link rel="alternate" type="text/html" href="https://wiki.emfcamp.org/2022/w/index.php?title=Network&amp;diff=1661"/>
		<updated>2022-06-01T20:56:52Z</updated>

		<summary type="html">&lt;p&gt;Russ: Update for OWE and other bits&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;float:right;&amp;quot;&amp;gt;__TOC__&amp;lt;/div&amp;gt;&lt;br /&gt;
[[Team:NOC]] has tried to build and support the fastest network for you: a network comparable to a medium sized ISP, built up in just a couple of days. It might not be perfect all the time. We will be providing blanket wireless coverage and wired network access to both venues and camping tents.&lt;br /&gt;
&lt;br /&gt;
=== Key points ===&lt;br /&gt;
&lt;br /&gt;
* To use the camp WiFi on most modern devices, connect to the '''emfcamp''' network with a username of '''emf''' and a password of '''emf'''.&lt;br /&gt;
* If you're using a modern Android phone (Android 10 or above), the '''emfcamp-insecure22''' network is easier to configure, and it will be encrypted (despite the name).&lt;br /&gt;
* Don't set up your own wireless access point. This is a serious problem in such a dense event and [[Network/Rogue Access Points|here's why]].&lt;br /&gt;
&lt;br /&gt;
== Wireless ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;dl&amp;gt;&lt;br /&gt;
  &amp;lt;dt&amp;gt;Network Name (SSID)&amp;lt;/dt&amp;gt;&lt;br /&gt;
  &amp;lt;dd&amp;gt;emfcamp&amp;lt;/dd&amp;gt;&lt;br /&gt;
  &amp;lt;dt&amp;gt;Username&amp;lt;/dt&amp;gt;&lt;br /&gt;
  &amp;lt;dd&amp;gt;emf&amp;lt;/dd&amp;gt;&lt;br /&gt;
  &amp;lt;dt&amp;gt;Password&amp;lt;/dt&amp;gt;&lt;br /&gt;
  &amp;lt;dd&amp;gt;emf&amp;lt;/dd&amp;gt;&lt;br /&gt;
&amp;lt;/dl&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The whole field has been covered with many wireless access points to ensure the best possible coverage and to allow you to roam seamlessly without interruption. Please note that your device will be reachable by anyone on the internet, please take suitable precautions such as turning on a firewall, and making sure your software is up to date.&lt;br /&gt;
&lt;br /&gt;
You should not bring your own wireless access point, its unlikely to provide better service than the camp ones, and it makes the network worse for everyone else. Any rogue access points will be hunted down and disconnected from the network - see [[Network/Rogue_Access_Points]] if you want to know why. If you have a project that needs to provide its own AP for some reason please contact the NOC and we will find an alternative solution.&lt;br /&gt;
&lt;br /&gt;
Here is the complete list of wireless networks (SSIDs) available:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! emfcamp&lt;br /&gt;
| This is 2.4GHz + 5GHz and should you should use this one in preference, if you can see it. This is the most secure, WPA2-Enterprise. However, it's a pain to configure on Android devices.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap&amp;quot; | emfcamp-insecure22&lt;br /&gt;
| '''Warning: insecure on some devices''' This is both 5GHz and 2.4GHz, and can be used for older devices that don't support WPA2-Enterprise. If your device supports [https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encryption Opportunistic Wireless Encryption], such as Android 10 or above, this is encrypted. Otherwise, it's unencrypted, and people will likely intercept your traffic. Inbound connections from the rest of the campsite are possible, inbound connections from the Internet are blocked.&lt;br /&gt;
|-&lt;br /&gt;
! spacenet&lt;br /&gt;
| This is 2.4GHz + 5GHz and WPA2-Enterprise, you can connect with a valid account if your hackerspace offers.&lt;br /&gt;
|-&lt;br /&gt;
! eduroam&lt;br /&gt;
| This is 2.4GHz + 5GHz and WPA2-Enterprise, you can connect with a valid account if your university/college/school is offering eduroam. More information can be found at [https://www.eduroam.org/ eduroam.org].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
When connecting to any of the WPA2-Enterprise password, which require a username and password, you can use the following (case-sensitive):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Username&lt;br /&gt;
! Password&lt;br /&gt;
! Result&lt;br /&gt;
|-&lt;br /&gt;
| emf&lt;br /&gt;
| emf&lt;br /&gt;
| Filtered connection with public IP address. Inbound connections from the rest of the campsite are possible, inbound connections from the Internet are blocked.&lt;br /&gt;
|-&lt;br /&gt;
| allowany&lt;br /&gt;
| allowany&lt;br /&gt;
| Unfiltered connection with public IP address&lt;br /&gt;
|-&lt;br /&gt;
| outboundonly&lt;br /&gt;
| outboundonly&lt;br /&gt;
| Filtered connection with public IP address. Inbound connections from the Internet or camp-site are not possible.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Use of the 5GHz SSIDs is recommended if your device supports them. 802.11b is disabled as it slows everyone else down.&lt;br /&gt;
&lt;br /&gt;
Even if you are using an encrypted network, you should still [[#Encryption|encrypt any sensitive traffic]] sent over the air end-to-end to prevent snooping. Although some SSIDs offer encryption, it is only over-the-air.&lt;br /&gt;
&lt;br /&gt;
We have airtime fairness configured on our wireless controllers, so if you wish to use a lot of bandwidth (e.g. stream videos or download large files), please use a [[#Wired|wired connection]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Client Settings ====&lt;br /&gt;
Also see [[Network/802.1X client settings]] for a list of OS-specific client settings.&lt;br /&gt;
&lt;br /&gt;
 SSID: emfcamp&lt;br /&gt;
 &lt;br /&gt;
 EAP-TTLS:&lt;br /&gt;
 &lt;br /&gt;
 Phase 1: EAP-TTLS&lt;br /&gt;
 Phase 2: PAP&lt;br /&gt;
 &lt;br /&gt;
 PEAP:&lt;br /&gt;
 &lt;br /&gt;
 Phase 1: PEAP&lt;br /&gt;
 Phase 2: MSCHAPv2 or EAP-MSCHAPv2 or PAP&lt;br /&gt;
 &lt;br /&gt;
 CN = radius.emf.camp&lt;br /&gt;
 CA = ISRG Root X1&lt;br /&gt;
&lt;br /&gt;
 SHA256 Fingerprint = B8:3B:F9:39:C4:F2:BF:D0:87:D7:93:5C:A0:DD:18:F3:31:7B:DD:B1:EC:88:3B:22:E0:B2:39:CB:7C:F8:FD:43&lt;br /&gt;
&lt;br /&gt;
Make sure '''you check the certificate''' in order to know you are connecting to the correct network (you should check on both the CN and the CA). Check [[Network/RADIUS_certificate|here]] for the complete certificate.&lt;br /&gt;
&lt;br /&gt;
[[File:Ubuntu network settings.png|thumb|Ubuntu network settings]]&lt;br /&gt;
On Ubuntu/Debian based distros the certificate file can be found in /etc/ssl/certs/ISRG_Root_X1.pem&lt;br /&gt;
&lt;br /&gt;
'''Android'''&lt;br /&gt;
&lt;br /&gt;
This app will help you get set up: https://play.google.com/store/apps/details?id=nl.eventinfra.wifisetup. Or follow [[Network/802.1X_client_settings#Manually|these instructions]] to do it manually.&lt;br /&gt;
&lt;br /&gt;
== Wired Ethernet ==&lt;br /&gt;
&lt;br /&gt;
All camping areas are within 60m of a datenklo (or data toilet), where you can connect to the network. If you intend to do so please bring 60-70m of CAT5 cable as we are unable to provide any.&lt;br /&gt;
&lt;br /&gt;
Lay your own cable neatly from your tent back to the nearest Datenklo, and leave 6m of slack coiled on the floor in front of it. And please lay it so that it can be clearly seen that it needs to be plugged in - or you risk having your cable overlooked. At regular intervals a member of the NOC team will connect it up and enable the port.&lt;br /&gt;
&lt;br /&gt;
If you wish to be removed from a Datenklo again on Sunday or Monday, leave your entire cable coiled outside the DK and we will disconnect it. If you need to leave before then, contact the [[Team:InfoDesk|helpdesk]] directly.&lt;br /&gt;
&lt;br /&gt;
All of our edge ports are at least 100 Mbps or 1 Gbps, auto-negotiate, auto-MDX. We are unlikely to have PoE ports for general use.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Note that most of our ports will not support 10 Mbps - if you need it for old equipment or embedded things, please bring your own switch to convert. !--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Static IPs ==&lt;br /&gt;
&lt;br /&gt;
If you need a static IP on the wired network, contact the NOC.&lt;br /&gt;
&lt;br /&gt;
== IPv6 ==&lt;br /&gt;
&lt;br /&gt;
Naturally, IPv6 is available throughout the network and should &amp;quot;just work&amp;quot; for you. [[Team:NOC]] does not recommend disabling IPv6 if you have problems, instead try to understand the problem you are experiencing and get educated in the new world order. Contact the [[Team:InfoDesk|NOC helpdesk]] if you need help.&lt;br /&gt;
&lt;br /&gt;
== Services ==&lt;br /&gt;
&lt;br /&gt;
* DNS: 78.158.87.11 and 78.158.87.12&lt;br /&gt;
* NTP: 78.158.87.11 and 78.158.87.12 (ntp1.emf.camp and ntp2.emf.camp)&lt;br /&gt;
* Nearest Debian mirror: http://debian.mirror.uk.sargasso.net&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Security ==&lt;br /&gt;
&lt;br /&gt;
=== Encryption ===&lt;br /&gt;
&lt;br /&gt;
Please treat the network as wide open and full of attackers. Although [[Team:NOC]] themselves will not monitor the network, always assume that Alice flirting with Bob will be spied upon by The Third Party.&lt;br /&gt;
&lt;br /&gt;
Any sensitive information including passwords must therefore be encrypted. Please make sure you don't use any software or web applications that send sensitive data or passwords in the clear.&lt;br /&gt;
&lt;br /&gt;
The following mechanisms should be safe:&lt;br /&gt;
* Anything that goes through a VPN&lt;br /&gt;
* Any website that uses HTTPS&lt;br /&gt;
* Any application that uses SSL&lt;br /&gt;
** In the case of email, you need to have SSL enabled for both receiving mail (POP, IMAP) and sending it (SMTP)&lt;br /&gt;
* ssh and scp&lt;br /&gt;
* Where possible, use One-time passwords. Real tokens work best, many of those should be compatible with open source radius servers. [http://perlmonks.org/?node=967433 Here] is a simple Perl radius server implementation for [http://tools.ietf.org/html/rfc6238 RFC6238] tokens that works with ssh and other stuff on linux.&lt;br /&gt;
&lt;br /&gt;
The following are almost always unsafe:&lt;br /&gt;
&lt;br /&gt;
* FTP with login/password (are almost always sent in the clear)&lt;br /&gt;
* Telnet with login/password&lt;br /&gt;
* Email if you don't use SSL&lt;br /&gt;
* Webmail that doesn't use HTTPS&lt;br /&gt;
** Someone could trigger a password reminder and then intercept your email&lt;br /&gt;
* Websites that use HTTP (not HTTPS) where you need to fill in a password in the page itself&lt;br /&gt;
&lt;br /&gt;
Possibly unsafe, make sure that you understand what you're doing:&lt;br /&gt;
&lt;br /&gt;
* Websites where you need to fill in a password and your ''browser'' (not the website!) tells you it's going to be sent securely&lt;br /&gt;
* Websites that require an account but remember you're logged in&lt;br /&gt;
** The password ''may'' be protected but not the content or cookies that automatically log you in&lt;br /&gt;
* Any time your browser or other application brings up ''anything'' to do with a certificate&lt;br /&gt;
* Anything not protected with SSL: someone could be faking DNS answers to impersonate certain sites&lt;br /&gt;
&lt;br /&gt;
Remember: if you're being stupid someone may feel the need to teach you a security lesson in a not so subtle way! (No, that doesn't mean it's ok to hack people just to see if their security is in order.)&lt;br /&gt;
&lt;br /&gt;
=== Firewall ===&lt;br /&gt;
&lt;br /&gt;
On the wired network there is no network firewall and on the WiFi network there is limited firewalling in place. We operate an unfiltered network that is wide open to the Internet. There is no NAT, and everybody has a public IP address. This is our definition of &amp;quot;network neutrality&amp;quot; - a network that doesn't do anything whatsoever to your IP connection.&lt;br /&gt;
&lt;br /&gt;
If you are used to feeling secure just because you've been sitting behind a NAT router, think again. You are now wide open to the whole Internet. Ensure your personal firewall is enabled and set to &amp;quot;Public Network&amp;quot; and that you have applied all security updates to your OS and applications.&lt;br /&gt;
&lt;br /&gt;
By default the WiFi network allows inbound connections from the rest of the campsite, but inbound connections from the Internet are blocked. If you want to ensure no inbound connections are possible towards your WiFi device, use the &amp;quot;outboundonly&amp;quot;-login. &lt;br /&gt;
&lt;br /&gt;
In case you want to enable inbound connections towards your WiFi-device, use the &amp;quot;allowany&amp;quot;-login.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== Can I bring a server? ===&lt;br /&gt;
&lt;br /&gt;
Sure. You can host a server anywhere on the network, and the long DHCP lease time will effectively give you a static IP address.&lt;br /&gt;
&lt;br /&gt;
If you would like to house your server in our data centre (NOC-DC), please contact us before the event by e-mail to noc@. 1 Gbps copper ports are standard; if you require a 10 Gbps port, you'll need to supply a DAC or SFPs (our end Arista-coded) with fibre.&lt;br /&gt;
&lt;br /&gt;
=== Is there a server I can use to host data on site? ===&lt;br /&gt;
&lt;br /&gt;
Due to lack of demand at the last event, this will not be provided this time.&lt;br /&gt;
&lt;br /&gt;
=== Can I use the 2.4GHz band for non-wifi projects? ===&lt;br /&gt;
&lt;br /&gt;
The following channels are available for adhoc/mesh/other wireless stuff:&lt;br /&gt;
&lt;br /&gt;
* 2.4GHz: Channel 1 &lt;br /&gt;
* 5GHz: Channel 136, 140&lt;br /&gt;
&lt;br /&gt;
We cannot force you to use these channels, but we are trying to build a functional wireless network for the other attendees too. So please, don't do any experiments on other channels.&lt;br /&gt;
&lt;br /&gt;
=== Can I bring an access point? ===&lt;br /&gt;
&lt;br /&gt;
No, this is strictly prohibited! We need all available channels to provide good quality coverage for the rest of the attendees. Please do not be selfish here as you will degrade performance for everyone else, and we WILL track you down.&lt;br /&gt;
&lt;br /&gt;
If you think you can ignore this rule because one little access point can't hurt anyone, think again. This page has the calculations on just how huge a problem it is for an event of our size: [[Network/Rogue Access Points]].&lt;br /&gt;
&lt;br /&gt;
If you are operating a village (using an EMF-supplied tent) that has poor coverage, we may be able to arrange to put an extra access point in it during the event to improve coverage. Stop by the NOC and ask.&lt;br /&gt;
&lt;br /&gt;
=== Can I bring a switch? ===&lt;br /&gt;
&lt;br /&gt;
Yes, but for stability purposes all edge ports are limited to 10 MAC addresses at a time. If you want to connect a switch with more stations, you need to stop by the NOC and ask us to raise the port-security on your port. If you do this, you need to convince us that you know what you're doing and promise not to do anything that may harm the network - in particular, you must not connect the switch to our network by more than 1 cable (not even to a different DK). Make sure that you disable STP and other protocols on your switch which try to be intelligent.&lt;br /&gt;
&lt;br /&gt;
=== My port goes up and down every couple of minutes ===&lt;br /&gt;
&lt;br /&gt;
You have probably tripped port security. Most likely scenario is that you have connected more than 10 stations without consulting us (see answer to previous question). To reduce support calls, the port will automatically be re-enabled after a few minutes. But if you haven't fixed the problem, it will immediately be shut down again.&lt;br /&gt;
&lt;br /&gt;
== Supporters ==&lt;br /&gt;
&lt;br /&gt;
We'd like to extend our immense gratitude to the following people and organisations who have been instrumental in making the EMF network and uplink happen through their donations and sponsorship:&lt;br /&gt;
&lt;br /&gt;
* [https://ethernet.business.sky.com Sky For Business]&lt;br /&gt;
* [http://www.sargasso.co.uk/from/emfcamp Sargasso Networks]&lt;br /&gt;
* [https://eventinfra.org EventInfra]&lt;br /&gt;
* [https://www.lonap.net LONAP]&lt;br /&gt;
* [https://www.comtec.com Comtec Enterprises]&lt;br /&gt;
* [https://www.mythic-beasts.com/ Mythic Beasts]&lt;br /&gt;
* [https://www.i3d.net/ i3D.net]&lt;/div&gt;</summary>
		<author><name>Russ</name></author>
	</entry>
</feed>