Pitt Digital — Help Desk Staff Reference
Pitt and UPMC Network Access Guide
Wireless access via Eduroam, VPN, and wired VLAN extension between Pitt and UPMC
Article ID: PITT-KB-NET-622 | Category: Network Services > PittNet | Audience: Help Desk Staff | Owner: Pitt Digital Network Operations
1. Quick Reference — Which Access Method Should I Use?
Use the table below to quickly direct callers to the correct solution. Most wireless access needs are now solved by Eduroam without any ticket required.
Choose the right access method based on the caller's situation
| Caller's Situation |
Best Solution |
Ticket Required? |
See Section |
| Pitt user needs internet access at a UPMC Pittsburgh hospital |
Eduroam Wi-Fi |
No — self-service |
Section 3 |
| UPMC user needs internet access at a Pitt campus location |
Eduroam Wi-Fi |
No — self-service |
Section 3c |
| Pitt user needs to access Pitt-firewalled resources (journals, databases, dept. servers) while at UPMC |
Eduroam + PittNet VPN (GlobalProtect) |
No — self-service install |
Section 3d |
| Pitt user at UPMC does not have Eduroam access (non-Pittsburgh UPMC location, or UPMC device without Eduroam) |
UPMC GIA Wi-Fi + PittNet VPN |
No — use UPMC guest Wi-Fi |
Section 3e |
| Device needs to function as part of the Pitt network at a physical UPMC location (enterprise systems, IP assignment, VLAN membership) |
Physical VLAN Extension (wired) |
Yes — both Pitt and UPMC tickets needed |
Section 7a |
| Device needs to function as part of the UPMC network at a physical Pitt location (enterprise systems, IP assignment, VLAN membership) |
Physical VLAN Extension (wired) |
Yes — both Pitt and UPMC tickets needed |
Section 7b |
2. Service Overview
The University of Pittsburgh and UPMC collaborate extensively in research, patient care, operations, and technology. Pitt Digital and UPMC jointly maintain multiple mechanisms to enable network connectivity between the two organizations. Currently there are three distinct access methods, each suited to different use cases:
| Access Method |
What It Provides |
Connection Type |
Requires Ticket? |
| Eduroam Wi-Fi |
Internet access at Pitt and UPMC locations using home institution credentials. No guest accounts needed. |
Wireless — available at 5 UPMC hospitals and all Pitt campuses |
No |
| PittNet VPN (GlobalProtect) |
Encrypted tunnel to access Pitt-firewalled resources (databases, departmental servers, research systems) from any network including UPMC Wi-Fi. |
Software client — works over any internet connection except over UPMC networks. Only the UPMC guest network will allow you to login to PITTNET Portal |
No — software install only. See your RC Admin for access to secured resources via Global Protect VPN. |
| Physical VLAN Extension |
Extends a Pitt or UPMC network segment to a physical port in the other organization's building. Devices receive IP addresses from the originating organization's network. |
Wired — physical data ports only. Wireless VLAN extension is not available. |
Yes — coordinated between both organizations |
ℹ Important Distinction for Help Desk Staff: Many callers who previously needed a physical VLAN extension ticket simply need internet access at the other organization's location. Eduroam resolves this without any ticket. Only escalate to the VLAN extension process when a device must receive a Pitt- or UPMC-assigned IP address, or when an enterprise system requires layer-2 network membership at the physical level.
3. Wireless Access at UPMC Facilities (Eduroam)
✓ Current Status: Eduroam is Live at UPMC
As of November 2020, Pitt Digital and UPMC jointly deployed Eduroam at five UPMC Pittsburgh hospitals. Pitt students, faculty, and staff can connect to the internet at these locations using their Pitt credentials — no guest approval or ticket is needed. Likewise, UPMC associates can connect to the internet at all Pitt campus locations using their UPMC credentials.
Eduroam was developed for the international research and education community and is available in over 100 territories worldwide. This deployment enables Pitt and UPMC collaborators to connect at thousands of additional institutions globally using a single set of credentials.
3a. UPMC Locations with Eduroam
Eduroam is currently available at the following UPMC Pittsburgh facilities:
| UPMC Facility |
Neighborhood / Area |
Eduroam SSID |
| UPMC Presbyterian |
Oakland |
eduroam |
| UPMC Montefiore |
Oakland (connected walkway to Presbyterian) |
eduroam |
| UPMC Children's Hospital of Pittsburgh |
Lawrenceville (North Oakland) |
eduroam |
| UPMC Shadyside |
Shadyside |
eduroam |
| UPMC Mercy |
Uptown |
eduroam |
⚠ Other UPMC Locations: Eduroam coverage is specific to the five Pittsburgh-area facilities listed above. UPMC facilities outside of the Oakland, Shadyside, Lawrenceville, and Uptown corridors are not confirmed as Eduroam participants. For callers at other UPMC sites, direct them to the UPMC GIA (Guest Internet Access) Wi-Fi option and the PittNet VPN. See Section 3e.
3b. How to Connect — Pitt Users at UPMC
Pitt students, faculty, and staff can connect to Eduroam at UPMC locations using their standard University Computing Account credentials:
- On your device, open the Wi-Fi network list.
- Select the network named eduroam.
- When prompted for credentials, enter your Pitt email address (username@pitt.edu) and your University Computing Account password.
- If prompted to trust or install a certificate, accept it to complete the connection.
Note: Eduroam provides internet access only. To access Pitt resources that are protected by University firewalls (such as digital research journals, departmental databases, or departmental printers), you must also connect to the PittNet VPN. See Section 3d below.
⚠ Password Change Reminder: If a caller has recently changed their University Computing Account password, they must forget the Eduroam network on their device and reconnect, entering the new password. Devices will not automatically re-authenticate with new credentials.
3c. How to Connect — UPMC Users at Pitt
UPMC associates visiting any University of Pittsburgh campus location can connect to Eduroam using their UPMC credentials:
- On your device, open the Wi-Fi network list.
- Select the network named eduroam.
- When prompted, enter your UPMC email address and password (home institution credentials).
Note: Eduroam at Pitt is not available in residence halls. For UPMC visitors to Pitt academic and administrative buildings, Eduroam is available at most campus locations. Pitt Guest Wi-Fi is also available campus-wide but is not available at UPMC facilities. For Eduroam support issues, UPMC users should contact the UPMC Help Desk at 412-647-HELP (4357) — Pitt's Help Desk cannot support UPMC account credentials.
3d. Using PittNet VPN Over Eduroam or UPMC Wi-Fi
Eduroam provides internet access only. To access University resources protected by Pitt's firewalls (research databases, departmental servers, printers, remote desktop), users must also run the PittNet VPN (GlobalProtect) client:
| Step |
Action |
| 1 |
Connect to eduroam at the UPMC location (or to UPMC GIA if Eduroam is not available). |
| 2 |
Open the GlobalProtect VPN client on your device. If not installed, download it from the Software Download Service at software.pitt.edu. Search for "GlobalProtect" and select the appropriate version. |
| 3 |
In the portal address field, enter: portal-palo.pitt.edu |
| 4 |
Enter your Pitt University Computing Account username and password, then click Connect. |
| 5 |
Complete Duo multifactor authentication (enter "push" for the default push notification, or enter a passcode). |
| 6 |
Once connected, you can access all Pitt-firewalled resources as if you were on campus. The GlobalProtect icon will show green/connected in the system tray or menu bar. |
ℹ Note for UPMC Workstations: Some UPMC-managed workstations may experience issues connecting to the Pitt VPN due to UPMC's network security policies. In these cases, the recommendation is to use a personal or Pitt-managed device for VPN connectivity. If a caller is experiencing this issue on a UPMC workstation, note it in the TDX ticket and route to Pitt Digital Network Engineering for assessment.
3e. UPMC Guest Internet Access (GIA) — Fallback for Non-Eduroam UPMC Locations
At UPMC facilities where Eduroam is not available (non-Pittsburgh locations or other facilities not listed in Section 3a), Pitt users can connect to UPMC's public GIA (Guest Internet Access) Wi-Fi network for basic internet access:
- Open your device's Wi-Fi settings at the UPMC location.
- Connect to the network named GIA (Guest Internet Access).
- Accept the UPMC network usage terms if prompted.
- Once connected to GIA, launch GlobalProtect and connect to portal-palo.pitt.edu to access Pitt-firewalled resources (see Section 3d above).
GIA provides basic internet access only. It does not authenticate with Pitt systems. Always use GlobalProtect VPN on top of GIA to securely access Pitt resources.
📋 Help Desk Quick Summary — Wireless Calls
- Pitt user at UPMC Presbyterian, Montefiore, Children's, Shadyside, or Mercy: Use Eduroam with Pitt credentials. No ticket needed.
- Pitt user needs to access Pitt-firewalled resources while at UPMC: Eduroam + GlobalProtect VPN (portal-palo.pitt.edu). No ticket needed.
- UPMC user at any Pitt campus building: Use Eduroam with UPMC credentials. Support the account with UPMC Help Desk (412-647-HELP).
- Pitt user at UPMC location without Eduroam: Connect to UPMC GIA Wi-Fi, then run GlobalProtect VPN. No ticket needed.
- Device needs to be on the Pitt or UPMC network at the physical/IP level: Physical VLAN extension — tickets required. See Sections 5–8.
4. Help Desk Role and Responsibilities
When a caller contacts the Help Desk regarding Pitt–UPMC network connectivity, Help Desk staff should first assess whether the caller's need is met by Eduroam or VPN (Sections 3a–3e above). Only proceed to the physical VLAN extension process below when the caller's situation requires enterprise-level network integration at the physical layer.
| Step |
Responsibility |
Detail |
| 1 |
Triage the Access Need |
Use the decision table in Section 1 to determine whether Eduroam, VPN, or a physical VLAN extension is needed. Resolve wireless/VPN issues without ticketing where possible. |
| 2 |
Qualify the VLAN Request |
If a physical VLAN extension is confirmed necessary, gather all required information before opening any tickets. See Step 1 checklist in Section 5. |
| 3 |
Determine Request Type |
Identify whether this is Pitt→UPMC or UPMC→Pitt. See Section 6. |
| 4 |
Create and Route the Pitt TDX Ticket |
Open the ticket, populate with all gathered information, and route to the correct Pitt Digital team. See Section 7. |
| 5 |
Advise Caller on UPMC Ticket |
Instruct the caller how to open the corresponding UPMC ticket, including the routing group and the Pitt TDX ticket number to reference. |
| 6 |
Cross-Reference Both Ticket Numbers |
Ensure the Pitt TDX ticket number is in the UPMC ticket and vice versa. Both systems must reference each other for technical teams to coordinate. |
5. Step 1 — Pre-Qualification Checklist (Physical VLAN Extension)
Gather the following information from the caller before opening any tickets. This information is required for both the Pitt TDX ticket and the UPMC ticket.
A. Caller Identity and Departmental Information
| # |
Question to Ask the Caller |
Staff Notes |
| 1 |
Are you a Pitt employee, a UPMC employee, or dual-employed by both? |
Determines which process and ticket routing applies. If dual-employed, ask Q2. |
| 2 |
(If dual-employed) Are you making this request as a Pitt employee or as a UPMC employee? |
Follow the process for the organization they are representing for this specific request. |
| 3 |
What department are you in? |
Required in both Pitt and UPMC tickets. |
| 4 |
Name of your departmental administrator |
Required for both Pitt and UPMC employees. |
| 5 |
Name of your departmental IT contact |
Required for both Pitt and UPMC employees. |
| 6 |
(Pitt employees) Name of your RC (Responsibility Center) administrator |
Required for Pitt employees only. |
| 7 |
(UPMC employees) Name of your site PC Support contact |
Required for UPMC employees only. |
B. Physical Location Details
| # |
Information to Collect |
Staff Notes |
| 1 |
Building name and full street address |
The location where the extended network access is needed — may differ from the caller's primary location. |
| 2 |
Floor number |
|
| 3 |
Room or suite number |
|
| 4 |
Data port IDs (if available) |
Usually labeled on the wall jack. The caller's departmental IT contact may be able to supply these. |
C. Network and Technical Information
| # |
Information to Collect |
Staff Notes |
| 1 |
IP subnet to be extended (if known) |
Departmental IT contact can provide if caller is unsure. Ticket can proceed without it. |
| 2 |
VLAN ID to be extended (if known) |
Departmental IT contact can provide if caller is unsure. |
| 3 |
Description of the resources the device must access |
What systems, applications, or services require access from the remote facility? |
6. Step 2 — Determine Request Type
| Scenario A — Pitt Network → UPMC |
Scenario B — UPMC Network → Pitt |
|
Caller is: A Pitt employee with sponsored access to UPMC
Need: Device must be on the Pitt network at a UPMC physical location
Pitt TDX Routes To: Pitt Digital Security
UPMC Ticket Routes To: "ECGDatacenter" group
IP Addresses Assigned By: Pitt — devices subject to Pitt's IT Security policies
|
Caller is: A UPMC employee with sponsored access to Pitt
Need: Device must be on the UPMC network at a Pitt physical location
Pitt TDX Routes To: Pitt Digital Network Engineering
UPMC Ticket Routes To: "ECG-Datacenter" group
IP Addresses Assigned By: UPMC — devices subject to UPMC's IT Security policies
|
⚠ UPMC Routing Group Spelling: The UPMC routing group names differ by a hyphen. Verify carefully before routing: "ECGDatacenter" (no hyphen, Scenario A) vs. "ECG-Datacenter" (with hyphen, Scenario B).
⚠ Physical VLAN Extension — Wired Only: Physical VLAN extensions apply to wired network ports only. There is no wireless VLAN extension between Pitt and UPMC. Wireless access needs are addressed by Eduroam (Section 3) and/or PittNet VPN (Section 3d), not by this process.
7. Step 3 — Ticket Creation Procedures
Scenario A: Pitt Network Extended to UPMC
Use when: A Pitt-managed device must receive a Pitt IP address and operate on the Pitt network from a physical UPMC location.
Part 1 of 3 — Open the Pitt TDX Ticket
- Navigate to the Pitt network service request form at services.pitt.edu, or open the ticket internally via 412-624-HELP (4357).
- Populate the ticket with all information gathered in the Section 5 checklist.
- Include the phrase: "Request to extend Pitt VLAN to UPMC facility."
- Route to: Pitt Digital Security for initial review and approval.
- Record the Pitt TDX ticket number — needed for the UPMC ticket.
Part 2 of 3 — Instruct the Caller to Open a UPMC Ticket
- Phone: 412-647-HELP (4357)
- Portal: UPMC IT Service Portal (contact UPMC Help Desk for current URL if needed)
- Include: "Request to extend Pitt VLAN to UPMC facility."
- Include the Pitt TDX ticket number in the UPMC ticket body.
- Route to UPMC group: "ECGDatacenter"
Part 3 of 3 — Cross-Reference Both Tickets
- Update the Pitt TDX ticket with the UPMC ticket number once available.
- Confirm the Pitt ticket number is in the UPMC ticket.
- Help Desk's active role ends here — both technical teams will coordinate directly.
⚠ Security Policy: When Pitt's network is extended to a UPMC facility, all IP addresses are assigned by Pitt and all connected devices are subject to Pitt's IT Security policies. Direct security policy questions to Pitt Digital Security via the TDX ticket.
New Physical Ports at UPMC (Scenario A)
- Submit wiring requests through the UPMC system, routed to "ECGDatacenter".
- Costs are billed to the requesting business unit.
- If part of a Facilities Management project, charges may be billed to the project; otherwise they revert to the business unit.
Scenario B: UPMC Network Extended to Pitt
Use when: A UPMC-managed device must receive a UPMC IP address and operate on the UPMC network from a physical Pitt location.
Part 1 of 3 — Open the UPMC Ticket First
For Scenario B, the UPMC ticket must be opened first:
- Phone: 412-647-HELP (4357)
- Portal: UPMC IT Service Portal (contact UPMC Help Desk for current URL if needed)
- Include: "Request to extend UPMC VLAN to Pitt facility."
- Route to UPMC group: "ECG-Datacenter"
- Record the UPMC ticket number for inclusion in the Pitt ticket.
Part 2 of 3 — Open the Pitt TDX Ticket
- Navigate to the Pitt network service request form, or open the ticket internally.
- Populate with all information from the Section 5 checklist.
- Include: "Request to extend UPMC VLAN to Pitt facility."
- Include the UPMC ticket number in the Pitt ticket body.
- Route to: Pitt Digital Network Engineering.
- Record the Pitt TDX ticket number.
Part 3 of 3 — Cross-Reference Both Tickets
- Confirm the UPMC ticket number is in the Pitt TDX ticket.
- Advise the caller to ensure the Pitt TDX ticket number is also added to the UPMC ticket.
- Help Desk's active role ends here — both technical teams coordinate directly.
⚠ Security Policy: When UPMC's network is extended to a Pitt facility, all IP addresses are assigned by UPMC and all connected devices are subject to UPMC's IT Security policies. Direct security questions to the UPMC Help Desk at 412-647-HELP (4357).
New Physical Ports at Pitt (Scenario B)
- A Pitt GL number (General Ledger account number) is required before installation begins.
- Charges are billed to the requesting department or RC — one-time charges, subject to annual adjustment.
- Complete a service request at tsrforms.pitt.edu to initiate the Pitt Telecommunications work order.
8. Step 4 — Post-Ticket Follow-Up
After both tickets have been opened and cross-referenced:
- Pitt Digital and UPMC technical teams will review, verify, and begin coordinating the requested work.
- Either team may contact the requestor to confirm details or request clarification.
- Status updates will flow through the respective ticketing systems as work progresses.
- Help Desk staff are not expected to monitor progress after tickets are created. Direct status inquiries to the assigned technical team via the TDX ticket.
ℹ Caller Expectations: Physical VLAN extension timelines vary depending on:
- Whether new physical data ports must be installed at either facility
- Availability of a Pitt GL number for new Pitt port installations
- Security review timelines at either organization
- Scheduling and coordination between two independent IT teams
Remind callers who only need internet access at the other organization's site that Eduroam is available immediately — no ticket or wait time involved.
9. Escalation Path
| Situation |
Escalate To |
How |
| Pitt user cannot connect to Eduroam at UPMC |
Pitt Help Desk / Pitt Digital |
Open TDX ticket; verify Pitt credentials and device configuration |
| UPMC user cannot connect to Eduroam at Pitt |
UPMC Help Desk |
412-647-HELP (4357) — Pitt cannot support UPMC credentials |
| Pitt VPN (GlobalProtect) installation or connection issues |
Pitt Help Desk |
Standard TDX ticket; portal address is portal-palo.pitt.edu |
| Pitt IT Security policy questions (Scenario A VLAN) |
Pitt Digital Security |
Route TDX ticket to Pitt Digital Security |
| Network engineering questions — Scenario B VLAN |
Pitt Digital Network Engineering |
Route TDX ticket to Pitt Digital Network Engineering |
| New data port installation at a Pitt building |
Pitt Telecommunications |
Caller submits service request at tsrforms.pitt.edu — GL number required |
| New data port installation at a UPMC building |
UPMC ECGDatacenter Group |
Via UPMC ticketing system — costs billed to requesting business unit |
| After-hours network incident or routing uncertainty |
Pitt Digital NOC |
Staffed 24×7×365 — escalate via TDX ticket assignment to NOC team |
| Walk-in technical support |
Help Desk Walk-In |
1st Floor Hillman Library, Pittsburgh campus |
10. Contact Directory
Article ID: PITT-KB-NET-622 v2.0 | Revised: March 2026 | Help Desk: 412-624-HELP (4357) | services.pitt.edu
Review this article periodically. Verify UPMC ticketing system URLs, UPMC routing group names, and Eduroam location coverage remain current. Contact Pitt Digital Network Engineering to confirm any changes.