Realm: royalfree.nhs.uk Full
royalfree.nhs.uk/royalfree-nhs-uk-0/NRPS: roaming0.govroam.uk
(212.219.190.139) -
Unknown Client
/
Port 1812 Drop
/
Bad Client Shared Secret
/
Dropping Auth Requests
/
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming0.govroam.uk/
Ping
- Output
- PING OK - Packet loss = 0%, RTA = 10.66 ms
- Last State Change
- Tue Sep 8 12:52:36 2026
- Last Check
- Wed Sep 9 06:22:26 2026
- Next Check
- Wed Sep 9 06:32:26 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming0.govroam.uk/
RADIUS Port
- Output
- OK: Port 1812 is probably open, unless there's a DROP firewall
- Last State Change
- Tue Sep 8 12:51:37 2026
- Last Check
- Wed Sep 9 06:21:36 2026
- Next Check
- Wed Sep 9 06:31:36 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming0.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:49:52 2026
- Last Check
- Wed Sep 9 06:19:50 2026
- Next Check
- Wed Sep 9 06:29:50 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming0.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:51:01 2026
- Last Check
- Wed Sep 9 06:18:57 2026
- Next Check
- Wed Sep 9 06:28:57 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming0.govroam.uk/
Zombie
- Output
- CRITICAL: Marked as down within the last day
- Last State Change
- Tue Sep 8 14:38:48 2026
- Last Check
- Wed Sep 9 06:18:47 2026
- Next Check
- Wed Sep 9 06:28:47 2026
- Meaning:
- Over the last day, the ORPS has been marked as 'down' by the NRPS. A server is marked as 'down' (or a Zombie) if it doesn't respond to an authentication query within 30s. If the ORPS is serving a Federation then the chances are that one of the Federation members isn't responding to a proxied query. If the ORPS isn't serving a Federation then it's a problem with the local configuration.
- Solution:
- An independently connected site needs to fix the configuration to ensure that the ORPS is sending a response to ALL auth requests. A Federation Operator nedds to check their logs to determine which members aren't sending responses and help them correct their configuration.
royalfree.nhs.uk/royalfree-nhs-uk-0/NRPS: roaming1.govroam.uk
(212.219.209.43) -
Unknown Client
/
Port 1812 Drop
/
Bad Client Shared Secret
/
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming1.govroam.uk/
Ping
- Output
- PING OK - Packet loss = 0%, RTA = 10.39 ms
- Last State Change
- Tue Sep 8 12:50:20 2026
- Last Check
- Wed Sep 9 06:20:10 2026
- Next Check
- Wed Sep 9 06:30:10 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming1.govroam.uk/
RADIUS Port
- Output
- OK: Port 1812 is probably open, unless there's a DROP firewall
- Last State Change
- Tue Sep 8 12:50:49 2026
- Last Check
- Wed Sep 9 06:20:48 2026
- Next Check
- Wed Sep 9 06:30:48 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming1.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:50:07 2026
- Last Check
- Wed Sep 9 06:20:05 2026
- Next Check
- Wed Sep 9 06:30:05 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming1.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:53:36 2026
- Last Check
- Wed Sep 9 06:21:32 2026
- Next Check
- Wed Sep 9 06:31:32 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming1.govroam.uk/
Zombie
- Output
- UNKNOWN: No Data. No data but not marked as down within the last week
- Last State Change
- Tue Sep 8 12:50:39 2026
- Last Check
- Wed Sep 9 06:18:37 2026
- Next Check
- Wed Sep 9 06:28:37 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/NRPS: roaming2.govroam.uk
(212.219.247.59) -
Unknown Client
/
Port 1812 Drop
/
Bad Client Shared Secret
/
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming2.govroam.uk/
Ping
- Output
- PING OK - Packet loss = 0%, RTA = 15.35 ms
- Last State Change
- Tue Sep 8 12:50:36 2026
- Last Check
- Wed Sep 9 06:20:27 2026
- Next Check
- Wed Sep 9 06:30:27 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming2.govroam.uk/
RADIUS Port
- Output
- OK: Port 1812 is probably open, unless there's a DROP firewall
- Last State Change
- Tue Sep 8 12:50:37 2026
- Last Check
- Wed Sep 9 06:20:36 2026
- Next Check
- Wed Sep 9 06:30:36 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming2.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:53:25 2026
- Last Check
- Wed Sep 9 06:13:23 2026
- Next Check
- Wed Sep 9 06:23:23 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming2.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:53:41 2026
- Last Check
- Wed Sep 9 06:21:37 2026
- Next Check
- Wed Sep 9 06:31:37 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming2.govroam.uk/
Zombie
- Output
- UNKNOWN: No Data. No data but not marked as down within the last week
- Last State Change
- Tue Sep 8 12:51:55 2026
- Last Check
- Wed Sep 9 06:19:53 2026
- Next Check
- Wed Sep 9 06:29:53 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/NRPS: roaming3.govroam.uk
(195.194.21.203) -
Unknown Client
/
Port 1812 Drop
/
Bad Client Shared Secret
/
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming3.govroam.uk/
Ping
- Output
- PING OK - Packet loss = 0%, RTA = 15.31 ms
- Last State Change
- Tue Sep 8 12:50:58 2026
- Last Check
- Wed Sep 9 06:20:48 2026
- Next Check
- Wed Sep 9 06:30:48 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming3.govroam.uk/
RADIUS Port
- Output
- OK: Port 1812 is probably open, unless there's a DROP firewall
- Last State Change
- Tue Sep 8 12:50:50 2026
- Last Check
- Wed Sep 9 06:20:48 2026
- Next Check
- Wed Sep 9 06:30:48 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming3.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:52:01 2026
- Last Check
- Wed Sep 9 06:22:01 2026
- Next Check
- Wed Sep 9 06:32:00 2026
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming3.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:49:51 2026
- Last Check
- Wed Sep 9 06:17:47 2026
- Next Check
- Wed Sep 9 06:27:47 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-0/roaming3.govroam.uk/
Zombie
- Output
- UNKNOWN: No Data. No data but not marked as down within the last week
- Last State Change
- Tue Sep 8 12:51:35 2026
- Last Check
- Wed Sep 9 06:19:33 2026
- Next Check
- Wed Sep 9 06:29:33 2026
royalfree.nhs.uk/royalfree-nhs-uk-1/NRPS: roaming0.govroam.uk
(212.219.190.139) -
Dropping Auth Requests
/
IPS firewall
/
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming0.govroam.uk/
Ping
- Output
- PING CRITICAL - Packet loss = 100%
- Last State Change
- Tue Sep 8 12:53:50 2026
- Last Check
- Wed Sep 9 06:20:49 2026
- Next Check
- Wed Sep 9 06:30:49 2026
- Meaning:
- A failed Ping test means that ICMP packets are either not getting to the server, or the responses aren't getting back.
- Solution:
- Check your firewall logs to see if the packets are arriving. If not, check your routing. If they are, then check to see if they're being DROPed or REJECTed. If you're confident that a response is being sent then please let Jisc know at govroam@jisc.ac.uk
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming0.govroam.uk/
RADIUS Port
- Output
- CRITICAL: No response. Host down or firewall dropping new connections
- Last State Change
- Tue Sep 8 12:54:05 2026
- Last Check
- Wed Sep 9 06:22:00 2026
- Next Check
- Wed Sep 9 06:32:00 2026
- Meaning:
- A simple port scan of port 1812/udp was attempted and there was no response from the port. This implies that either the port is not open i.e. there isn't a daemon running on it, or that there is a firewall configured to not to respond to such scans. Dropping such packets isn't a problem as long as the server is able to respond to RADIUS auth requests.
- Solution:
- Check the state of the RADIUS daemon and ensure that it's up and running on port 1812/udp. If it is, then check your firewall(s) to see if they're configured to drop incoming connections.
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming0.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:51:04 2026
- Last Check
- Wed Sep 9 06:21:02 2026
- Next Check
- Wed Sep 9 06:31:02 2026
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming0.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:51:31 2026
- Last Check
- Wed Sep 9 06:19:28 2026
- Next Check
- Wed Sep 9 06:29:28 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming0.govroam.uk/
Zombie
- Output
- CRITICAL: Marked as down within the last day
- Last State Change
- Tue Sep 8 12:53:51 2026
- Last Check
- Wed Sep 9 06:21:50 2026
- Next Check
- Wed Sep 9 06:31:50 2026
- Meaning:
- Over the last day, the ORPS has been marked as 'down' by the NRPS. A server is marked as 'down' (or a Zombie) if it doesn't respond to an authentication query within 30s. If the ORPS is serving a Federation then the chances are that one of the Federation members isn't responding to a proxied query. If the ORPS isn't serving a Federation then it's a problem with the local configuration.
- Solution:
- An independently connected site needs to fix the configuration to ensure that the ORPS is sending a response to ALL auth requests. A Federation Operator nedds to check their logs to determine which members aren't sending responses and help them correct their configuration.
royalfree.nhs.uk/royalfree-nhs-uk-1/NRPS: roaming1.govroam.uk
(212.219.209.43) -
Dropping Auth Requests
/
IPS firewall
/
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming1.govroam.uk/
Ping
- Output
- PING CRITICAL - Packet loss = 100%
- Last State Change
- Tue Sep 8 12:53:40 2026
- Last Check
- Wed Sep 9 06:20:39 2026
- Next Check
- Wed Sep 9 06:30:38 2026
- Meaning:
- A failed Ping test means that ICMP packets are either not getting to the server, or the responses aren't getting back.
- Solution:
- Check your firewall logs to see if the packets are arriving. If not, check your routing. If they are, then check to see if they're being DROPed or REJECTed. If you're confident that a response is being sent then please let Jisc know at govroam@jisc.ac.uk
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming1.govroam.uk/
RADIUS Port
- Output
- CRITICAL: No response. Host down or firewall dropping new connections
- Last State Change
- Tue Sep 8 12:50:52 2026
- Last Check
- Wed Sep 9 06:18:48 2026
- Next Check
- Wed Sep 9 06:28:48 2026
- Meaning:
- A simple port scan of port 1812/udp was attempted and there was no response from the port. This implies that either the port is not open i.e. there isn't a daemon running on it, or that there is a firewall configured to not to respond to such scans. Dropping such packets isn't a problem as long as the server is able to respond to RADIUS auth requests.
- Solution:
- Check the state of the RADIUS daemon and ensure that it's up and running on port 1812/udp. If it is, then check your firewall(s) to see if they're configured to drop incoming connections.
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming1.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:50:43 2026
- Last Check
- Wed Sep 9 06:20:41 2026
- Next Check
- Wed Sep 9 06:30:41 2026
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming1.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:54:58 2026
- Last Check
- Wed Sep 9 06:22:54 2026
- Next Check
- Wed Sep 9 06:32:54 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming1.govroam.uk/
Zombie
- Output
- CRITICAL: Marked as down within the last day
- Last State Change
- Tue Sep 8 12:53:34 2026
- Last Check
- Wed Sep 9 06:21:32 2026
- Next Check
- Wed Sep 9 06:31:32 2026
- Meaning:
- Over the last day, the ORPS has been marked as 'down' by the NRPS. A server is marked as 'down' (or a Zombie) if it doesn't respond to an authentication query within 30s. If the ORPS is serving a Federation then the chances are that one of the Federation members isn't responding to a proxied query. If the ORPS isn't serving a Federation then it's a problem with the local configuration.
- Solution:
- An independently connected site needs to fix the configuration to ensure that the ORPS is sending a response to ALL auth requests. A Federation Operator nedds to check their logs to determine which members aren't sending responses and help them correct their configuration.
royalfree.nhs.uk/royalfree-nhs-uk-1/NRPS: roaming2.govroam.uk
(212.219.247.59) -
Dropping Auth Requests
/
IPS firewall
/
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming2.govroam.uk/
Ping
- Output
- PING CRITICAL - Packet loss = 100%
- Last State Change
- Tue Sep 8 12:51:36 2026
- Last Check
- Wed Sep 9 06:18:35 2026
- Next Check
- Wed Sep 9 06:28:35 2026
- Meaning:
- A failed Ping test means that ICMP packets are either not getting to the server, or the responses aren't getting back.
- Solution:
- Check your firewall logs to see if the packets are arriving. If not, check your routing. If they are, then check to see if they're being DROPed or REJECTed. If you're confident that a response is being sent then please let Jisc know at govroam@jisc.ac.uk
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming2.govroam.uk/
RADIUS Port
- Output
- CRITICAL: No response. Host down or firewall dropping new connections
- Last State Change
- Tue Sep 8 12:53:34 2026
- Last Check
- Wed Sep 9 06:21:29 2026
- Next Check
- Wed Sep 9 06:31:29 2026
- Meaning:
- A simple port scan of port 1812/udp was attempted and there was no response from the port. This implies that either the port is not open i.e. there isn't a daemon running on it, or that there is a firewall configured to not to respond to such scans. Dropping such packets isn't a problem as long as the server is able to respond to RADIUS auth requests.
- Solution:
- Check the state of the RADIUS daemon and ensure that it's up and running on port 1812/udp. If it is, then check your firewall(s) to see if they're configured to drop incoming connections.
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming2.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:51:01 2026
- Last Check
- Wed Sep 9 06:21:00 2026
- Next Check
- Wed Sep 9 06:31:00 2026
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming2.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:50:29 2026
- Last Check
- Wed Sep 9 06:18:25 2026
- Next Check
- Wed Sep 9 06:28:25 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming2.govroam.uk/
Zombie
- Output
- CRITICAL: Marked as down within the last day
- Last State Change
- Tue Sep 8 12:51:11 2026
- Last Check
- Wed Sep 9 06:19:09 2026
- Next Check
- Wed Sep 9 06:29:09 2026
- Meaning:
- Over the last day, the ORPS has been marked as 'down' by the NRPS. A server is marked as 'down' (or a Zombie) if it doesn't respond to an authentication query within 30s. If the ORPS is serving a Federation then the chances are that one of the Federation members isn't responding to a proxied query. If the ORPS isn't serving a Federation then it's a problem with the local configuration.
- Solution:
- An independently connected site needs to fix the configuration to ensure that the ORPS is sending a response to ALL auth requests. A Federation Operator nedds to check their logs to determine which members aren't sending responses and help them correct their configuration.
royalfree.nhs.uk/royalfree-nhs-uk-1/NRPS: roaming3.govroam.uk
(195.194.21.203) -
Dropping Auth Requests
/
IPS firewall
/
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming3.govroam.uk/
Ping
- Output
- (Service Check Timed Out)
- Last State Change
- Tue Sep 8 12:51:31 2026
- Last Check
- Wed Sep 9 06:18:30 2026
- Next Check
- Wed Sep 9 06:28:29 2026
- Meaning:
- A failed Ping test means that ICMP packets are either not getting to the server, or the responses aren't getting back.
- Solution:
- Check your firewall logs to see if the packets are arriving. If not, check your routing. If they are, then check to see if they're being DROPed or REJECTed. If you're confident that a response is being sent then please let Jisc know at govroam@jisc.ac.uk
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming3.govroam.uk/
RADIUS Port
- Output
- CRITICAL: No response. Host down or firewall dropping new connections
- Last State Change
- Tue Sep 8 12:54:24 2026
- Last Check
- Wed Sep 9 06:22:19 2026
- Next Check
- Wed Sep 9 06:32:19 2026
- Meaning:
- A simple port scan of port 1812/udp was attempted and there was no response from the port. This implies that either the port is not open i.e. there isn't a daemon running on it, or that there is a firewall configured to not to respond to such scans. Dropping such packets isn't a problem as long as the server is able to respond to RADIUS auth requests.
- Solution:
- Check the state of the RADIUS daemon and ensure that it's up and running on port 1812/udp. If it is, then check your firewall(s) to see if they're configured to drop incoming connections.
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming3.govroam.uk/
Server Shared Secret
- Output
- OK: Good shared secret over last day
- Last State Change
- Tue Sep 8 12:54:40 2026
- Last Check
- Wed Sep 9 06:14:39 2026
- Next Check
- Wed Sep 9 06:24:39 2026
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming3.govroam.uk/
Simple Authentication
- Output
- WARNING: Timeout. No response from RADIUS server
- Last State Change
- Tue Sep 8 12:51:16 2026
- Last Check
- Wed Sep 9 06:19:13 2026
- Next Check
- Wed Sep 9 06:29:13 2026
- Meaning:
- An authentication attempt has been made using generic credentials and no response was received. It's expected that a RADIUS server would respond to non-existent credentials with an Access-Reject and if it didn't then there might be a problem. It's not part of the Tech Spec that all requests should be responded to but it's desirable. It would help us keep better track of your system state. However, be aware that all proxied/EAP requests MUST be responded to.
- Solution:
- Check your RADIUS logs to see what's happening to these requests. The username is 'jisctest' so should stand out. If you can, please ensure that your RADIUS server responds to the requests (with an Access-Reject). Alternatively, enable Status-Server (FreeRADIUS, RADIATOR and radsecproxy support it).
royalfree.nhs.uk/royalfree-nhs-uk-1/roaming3.govroam.uk/
Zombie
- Output
- CRITICAL: Marked as down within the last day
- Last State Change
- Tue Sep 8 12:53:30 2026
- Last Check
- Wed Sep 9 06:21:29 2026
- Next Check
- Wed Sep 9 06:31:29 2026
- Meaning:
- Over the last day, the ORPS has been marked as 'down' by the NRPS. A server is marked as 'down' (or a Zombie) if it doesn't respond to an authentication query within 30s. If the ORPS is serving a Federation then the chances are that one of the Federation members isn't responding to a proxied query. If the ORPS isn't serving a Federation then it's a problem with the local configuration.
- Solution:
- An independently connected site needs to fix the configuration to ensure that the ORPS is sending a response to ALL auth requests. A Federation Operator nedds to check their logs to determine which members aren't sending responses and help them correct their configuration.
Called Station ID Check
- Output
- WARNING: 100% Lower case characters in MAC (last: 2026-09-09 06:01:43)
- Last State Change
- Tue Sep 1 06:12:35 2026
- Last Check
- Wed Sep 9 06:22:34 2026
- Next Check
- Wed Sep 9 06:37:32 2026
- Meaning:
-
The Called-Station-ID contains the MAC address of the device the client
connects to as well as, potentially, the SSID of the wireless network it
connected to. The format of the MAC address is specified in RFC
3580 as
'XX-XX-XX-XX-XX-XX:SSID' with '-' being the only valid separator and all
upper case. The SSID should be appended.
Having the Called-Station-ID included in proxied requests makes it possible to ensure that the SSID being broadcast matches the service requirements. - Solution:
- Configure your wireless system to provide the CSI in the RFC3580 format.
Calling Station ID Check
- Output
- WARNING: 100% MAC format wrong, contains lower case (last: 2026-09-09 06:01:43)
- Last State Change
- Tue Sep 1 06:11:56 2026
- Last Check
- Wed Sep 9 06:21:52 2026
- Next Check
- Wed Sep 9 06:36:52 2026
- Meaning:
- Calling Station ID identifies the device making the connection and RFC 3580 states that the format should be XX-XX-XX-XX-XX-XX (i.e. '-' separated and upper case).
- Solution:
- Configure your wireless system to use upper case and '-' separated pairs.
Operator Check
- Output
- WARNING: 100% Missing Operator-Name (last: 2026-09-09 06:01:43)
- Last State Change
- Tue Sep 1 18:19:03 2026
- Last Check
- Wed Sep 9 06:19:02 2026
- Next Check
- Wed Sep 9 06:34:01 2026
- Meaning:
- Operator-Name is missing from RADIUS requests. Operator-Name identifies the site sending the requests and is used by home sites in audit trails and in cases of mis-use.
- Solution:
- Where possible (FreeRADIUS, radsecproxy, RADIATOR) Operator-Name should be configured to send the site identifier (in the format 1realm.name e.g. 1holby.nhs.uk).
Realm Syntax Check
- Output
- WARNING: 1.5% 3GPP realm (last: 2026-09-08 20:15:14)
- Last State Change
- Tue Sep 8 18:23:40 2026
- Last Check
- Wed Sep 9 06:08:36 2026
- Next Check
- Wed Sep 9 06:23:36 2026
- Meaning:
- Users and devices often put in their email addresses or preconfigured setting such as '@gmail.com' or '3gppnetwork.org' which are never going to be Govroam realms.
- Solution:
- Filter out the common realms which are never going to be Govroam sites.
VLAN Check
- Output
- CRITICAL: 69% Tunnel-Type attr present (last: 2026-09-09 06:01:43). 69% Tunnel-Medium-Type attr present (last: 2026-09-09 06:01:43). 69% Tunnel-Private-Group-ID (last: 2026-09-09 06:01:43)
- Last State Change
- Tue Sep 8 14:04:47 2026
- Last Check
- Wed Sep 9 06:19:44 2026
- Next Check
- Wed Sep 9 06:34:44 2026
- Meaning:
- Various attributes such as Tunnel-Type, Tunnel-Medium-Type and Tunnel-Private-Group-ID being sent out in responses. The 'Tunnel' attributes are commonly used to instruct wireless controllers which VLAN to place a client in. Thus if these attributes aren't filtered out then one site might be sending these attributes to another site. At best users won't be connected, at worst they'll be placed on an inappropriate VLAN.
- Solution:
- Apply filters on the RADIUS servers to restrict the attributes to just the set as specified in the Tech Spec. Both outgoing AND incoming packets need the filters applied to them for everyone's protection