Pitt and UPMC Virtual Network Extension

Pitt Digital — Help Desk Staff Reference

Pitt and UPMC Network Access Guide

Wireless access via Eduroam, VPN, and wired VLAN extension between Pitt and UPMC

 
Article ID: PITT-KB-NET-622  |  Category: Network Services > PittNet  |  Audience: Help Desk Staff  |  Owner: Pitt Digital Network Operations

1. Quick Reference — Which Access Method Should I Use?

Use the table below to quickly direct callers to the correct solution. Most wireless access needs are now solved by Eduroam without any ticket required.

Choose the right access method based on the caller's situation
Caller's Situation Best Solution Ticket Required? See Section
Pitt user needs internet access at a UPMC Pittsburgh hospital Eduroam Wi-Fi No — self-service Section 3
UPMC user needs internet access at a Pitt campus location Eduroam Wi-Fi No — self-service Section 3c
Pitt user needs to access Pitt-firewalled resources (journals, databases, dept. servers) while at UPMC Eduroam + PittNet VPN (GlobalProtect) No — self-service install Section 3d
Pitt user at UPMC does not have Eduroam access (non-Pittsburgh UPMC location, or UPMC device without Eduroam) UPMC GIA Wi-Fi + PittNet VPN No — use UPMC guest Wi-Fi Section 3e
Device needs to function as part of the Pitt network at a physical UPMC location (enterprise systems, IP assignment, VLAN membership) Physical VLAN Extension (wired) Yes — both Pitt and UPMC tickets needed Section 7a
Device needs to function as part of the UPMC network at a physical Pitt location (enterprise systems, IP assignment, VLAN membership) Physical VLAN Extension (wired) Yes — both Pitt and UPMC tickets needed Section 7b

2. Service Overview

The University of Pittsburgh and UPMC collaborate extensively in research, patient care, operations, and technology. Pitt Digital and UPMC jointly maintain multiple mechanisms to enable network connectivity between the two organizations. Currently there are three distinct access methods, each suited to different use cases:

Access Method What It Provides Connection Type Requires Ticket?
Eduroam Wi-Fi Internet access at Pitt and UPMC locations using home institution credentials. No guest accounts needed. Wireless — available at 5 UPMC hospitals and all Pitt campuses No
PittNet VPN (GlobalProtect) Encrypted tunnel to access Pitt-firewalled resources (databases, departmental servers, research systems) from any network including UPMC Wi-Fi. Software client — works over any internet connection except over UPMC networks.  Only the UPMC guest network will allow you to login to PITTNET Portal No — software install only.  See your RC Admin for access to secured resources via Global Protect VPN. 
Physical VLAN Extension Extends a Pitt or UPMC network segment to a physical port in the other organization's building. Devices receive IP addresses from the originating organization's network. Wired — physical data ports only. Wireless VLAN extension is not available. Yes — coordinated between both organizations
ℹ Important Distinction for Help Desk Staff: Many callers who previously needed a physical VLAN extension ticket simply need internet access at the other organization's location. Eduroam resolves this without any ticket. Only escalate to the VLAN extension process when a device must receive a Pitt- or UPMC-assigned IP address, or when an enterprise system requires layer-2 network membership at the physical level.

3. Wireless Access at UPMC Facilities (Eduroam)

✓ Current Status: Eduroam is Live at UPMC

As of November 2020, Pitt Digital and UPMC jointly deployed Eduroam at five UPMC Pittsburgh hospitals. Pitt students, faculty, and staff can connect to the internet at these locations using their Pitt credentials — no guest approval or ticket is needed. Likewise, UPMC associates can connect to the internet at all Pitt campus locations using their UPMC credentials.

Eduroam was developed for the international research and education community and is available in over 100 territories worldwide. This deployment enables Pitt and UPMC collaborators to connect at thousands of additional institutions globally using a single set of credentials.

3a. UPMC Locations with Eduroam

Eduroam is currently available at the following UPMC Pittsburgh facilities:

UPMC Facility Neighborhood / Area Eduroam SSID
UPMC Presbyterian Oakland eduroam
UPMC Montefiore Oakland (connected walkway to Presbyterian) eduroam
UPMC Children's Hospital of Pittsburgh Lawrenceville (North Oakland) eduroam
UPMC Shadyside Shadyside eduroam
UPMC Mercy Uptown eduroam
⚠ Other UPMC Locations: Eduroam coverage is specific to the five Pittsburgh-area facilities listed above. UPMC facilities outside of the Oakland, Shadyside, Lawrenceville, and Uptown corridors are not confirmed as Eduroam participants. For callers at other UPMC sites, direct them to the UPMC GIA (Guest Internet Access) Wi-Fi option and the PittNet VPN. See Section 3e.

3b. How to Connect — Pitt Users at UPMC

Pitt students, faculty, and staff can connect to Eduroam at UPMC locations using their standard University Computing Account credentials:

  1. On your device, open the Wi-Fi network list.
  2. Select the network named eduroam.
  3. When prompted for credentials, enter your Pitt email address (username@pitt.edu) and your University Computing Account password.
  4. If prompted to trust or install a certificate, accept it to complete the connection.

Note: Eduroam provides internet access only. To access Pitt resources that are protected by University firewalls (such as digital research journals, departmental databases, or departmental printers), you must also connect to the PittNet VPN. See Section 3d below.

⚠ Password Change Reminder: If a caller has recently changed their University Computing Account password, they must forget the Eduroam network on their device and reconnect, entering the new password. Devices will not automatically re-authenticate with new credentials.

3c. How to Connect — UPMC Users at Pitt

UPMC associates visiting any University of Pittsburgh campus location can connect to Eduroam using their UPMC credentials:

  1. On your device, open the Wi-Fi network list.
  2. Select the network named eduroam.
  3. When prompted, enter your UPMC email address and password (home institution credentials).

Note: Eduroam at Pitt is not available in residence halls. For UPMC visitors to Pitt academic and administrative buildings, Eduroam is available at most campus locations. Pitt Guest Wi-Fi is also available campus-wide but is not available at UPMC facilities. For Eduroam support issues, UPMC users should contact the UPMC Help Desk at 412-647-HELP (4357) — Pitt's Help Desk cannot support UPMC account credentials.

3d. Using PittNet VPN Over Eduroam or UPMC Wi-Fi

Eduroam provides internet access only. To access University resources protected by Pitt's firewalls (research databases, departmental servers, printers, remote desktop), users must also run the PittNet VPN (GlobalProtect) client:

Step Action
1 Connect to eduroam at the UPMC location (or to UPMC GIA if Eduroam is not available).
2 Open the GlobalProtect VPN client on your device. If not installed, download it from the Software Download Service at software.pitt.edu. Search for "GlobalProtect" and select the appropriate version.
3 In the portal address field, enter: portal-palo.pitt.edu
4 Enter your Pitt University Computing Account username and password, then click Connect.
5 Complete Duo multifactor authentication (enter "push" for the default push notification, or enter a passcode).
6 Once connected, you can access all Pitt-firewalled resources as if you were on campus. The GlobalProtect icon will show green/connected in the system tray or menu bar.
ℹ Note for UPMC Workstations: Some UPMC-managed workstations may experience issues connecting to the Pitt VPN due to UPMC's network security policies. In these cases, the recommendation is to use a personal or Pitt-managed device for VPN connectivity. If a caller is experiencing this issue on a UPMC workstation, note it in the TDX ticket and route to Pitt Digital Network Engineering for assessment.

3e. UPMC Guest Internet Access (GIA) — Fallback for Non-Eduroam UPMC Locations

At UPMC facilities where Eduroam is not available (non-Pittsburgh locations or other facilities not listed in Section 3a), Pitt users can connect to UPMC's public GIA (Guest Internet Access) Wi-Fi network for basic internet access:

  1. Open your device's Wi-Fi settings at the UPMC location.
  2. Connect to the network named GIA (Guest Internet Access).
  3. Accept the UPMC network usage terms if prompted.
  4. Once connected to GIA, launch GlobalProtect and connect to portal-palo.pitt.edu to access Pitt-firewalled resources (see Section 3d above).

GIA provides basic internet access only. It does not authenticate with Pitt systems. Always use GlobalProtect VPN on top of GIA to securely access Pitt resources.

📋 Help Desk Quick Summary — Wireless Calls
  • Pitt user at UPMC Presbyterian, Montefiore, Children's, Shadyside, or Mercy: Use Eduroam with Pitt credentials. No ticket needed.
  • Pitt user needs to access Pitt-firewalled resources while at UPMC: Eduroam + GlobalProtect VPN (portal-palo.pitt.edu). No ticket needed.
  • UPMC user at any Pitt campus building: Use Eduroam with UPMC credentials. Support the account with UPMC Help Desk (412-647-HELP).
  • Pitt user at UPMC location without Eduroam: Connect to UPMC GIA Wi-Fi, then run GlobalProtect VPN. No ticket needed.
  • Device needs to be on the Pitt or UPMC network at the physical/IP level: Physical VLAN extension — tickets required. See Sections 5–8.

4. Help Desk Role and Responsibilities

When a caller contacts the Help Desk regarding Pitt–UPMC network connectivity, Help Desk staff should first assess whether the caller's need is met by Eduroam or VPN (Sections 3a–3e above). Only proceed to the physical VLAN extension process below when the caller's situation requires enterprise-level network integration at the physical layer.

Step Responsibility Detail
1 Triage the Access Need Use the decision table in Section 1 to determine whether Eduroam, VPN, or a physical VLAN extension is needed. Resolve wireless/VPN issues without ticketing where possible.
2 Qualify the VLAN Request If a physical VLAN extension is confirmed necessary, gather all required information before opening any tickets. See Step 1 checklist in Section 5.
3 Determine Request Type Identify whether this is Pitt→UPMC or UPMC→Pitt. See Section 6.
4 Create and Route the Pitt TDX Ticket Open the ticket, populate with all gathered information, and route to the correct Pitt Digital team. See Section 7.
5 Advise Caller on UPMC Ticket Instruct the caller how to open the corresponding UPMC ticket, including the routing group and the Pitt TDX ticket number to reference.
6 Cross-Reference Both Ticket Numbers Ensure the Pitt TDX ticket number is in the UPMC ticket and vice versa. Both systems must reference each other for technical teams to coordinate.

5. Step 1 — Pre-Qualification Checklist (Physical VLAN Extension)

Gather the following information from the caller before opening any tickets. This information is required for both the Pitt TDX ticket and the UPMC ticket.

A. Caller Identity and Departmental Information

# Question to Ask the Caller Staff Notes
1 Are you a Pitt employee, a UPMC employee, or dual-employed by both? Determines which process and ticket routing applies. If dual-employed, ask Q2.
2 (If dual-employed) Are you making this request as a Pitt employee or as a UPMC employee? Follow the process for the organization they are representing for this specific request.
3 What department are you in? Required in both Pitt and UPMC tickets.
4 Name of your departmental administrator Required for both Pitt and UPMC employees.
5 Name of your departmental IT contact Required for both Pitt and UPMC employees.
6 (Pitt employees) Name of your RC (Responsibility Center) administrator Required for Pitt employees only.
7 (UPMC employees) Name of your site PC Support contact Required for UPMC employees only.

B. Physical Location Details

# Information to Collect Staff Notes
1 Building name and full street address The location where the extended network access is needed — may differ from the caller's primary location.
2 Floor number  
3 Room or suite number  
4 Data port IDs (if available) Usually labeled on the wall jack. The caller's departmental IT contact may be able to supply these.

C. Network and Technical Information

# Information to Collect Staff Notes
1 IP subnet to be extended (if known) Departmental IT contact can provide if caller is unsure. Ticket can proceed without it.
2 VLAN ID to be extended (if known) Departmental IT contact can provide if caller is unsure.
3 Description of the resources the device must access What systems, applications, or services require access from the remote facility?

6. Step 2 — Determine Request Type

Scenario A — Pitt Network → UPMC Scenario B — UPMC Network → Pitt

Caller is: A Pitt employee with sponsored access to UPMC

Need: Device must be on the Pitt network at a UPMC physical location

Pitt TDX Routes To: Pitt Digital Security

UPMC Ticket Routes To: "ECGDatacenter" group

IP Addresses Assigned By: Pitt — devices subject to Pitt's IT Security policies

Caller is: A UPMC employee with sponsored access to Pitt

Need: Device must be on the UPMC network at a Pitt physical location

Pitt TDX Routes To: Pitt Digital Network Engineering

UPMC Ticket Routes To: "ECG-Datacenter" group

IP Addresses Assigned By: UPMC — devices subject to UPMC's IT Security policies

⚠ UPMC Routing Group Spelling: The UPMC routing group names differ by a hyphen. Verify carefully before routing: "ECGDatacenter" (no hyphen, Scenario A) vs. "ECG-Datacenter" (with hyphen, Scenario B).
⚠ Physical VLAN Extension — Wired Only: Physical VLAN extensions apply to wired network ports only. There is no wireless VLAN extension between Pitt and UPMC. Wireless access needs are addressed by Eduroam (Section 3) and/or PittNet VPN (Section 3d), not by this process.

7. Step 3 — Ticket Creation Procedures

Scenario A: Pitt Network Extended to UPMC

Use when: A Pitt-managed device must receive a Pitt IP address and operate on the Pitt network from a physical UPMC location.

Part 1 of 3 — Open the Pitt TDX Ticket

  1. Navigate to the Pitt network service request form at services.pitt.edu, or open the ticket internally via 412-624-HELP (4357).
  2. Populate the ticket with all information gathered in the Section 5 checklist.
  3. Include the phrase: "Request to extend Pitt VLAN to UPMC facility."
  4. Route to: Pitt Digital Security for initial review and approval.
  5. Record the Pitt TDX ticket number — needed for the UPMC ticket.

Part 2 of 3 — Instruct the Caller to Open a UPMC Ticket

  • Phone: 412-647-HELP (4357)
  • Portal: UPMC IT Service Portal (contact UPMC Help Desk for current URL if needed)
  • Include: "Request to extend Pitt VLAN to UPMC facility."
  • Include the Pitt TDX ticket number in the UPMC ticket body.
  • Route to UPMC group: "ECGDatacenter"

Part 3 of 3 — Cross-Reference Both Tickets

  • Update the Pitt TDX ticket with the UPMC ticket number once available.
  • Confirm the Pitt ticket number is in the UPMC ticket.
  • Help Desk's active role ends here — both technical teams will coordinate directly.
⚠ Security Policy: When Pitt's network is extended to a UPMC facility, all IP addresses are assigned by Pitt and all connected devices are subject to Pitt's IT Security policies. Direct security policy questions to Pitt Digital Security via the TDX ticket.

New Physical Ports at UPMC (Scenario A)

  • Submit wiring requests through the UPMC system, routed to "ECGDatacenter".
  • Costs are billed to the requesting business unit.
  • If part of a Facilities Management project, charges may be billed to the project; otherwise they revert to the business unit.

Scenario B: UPMC Network Extended to Pitt

Use when: A UPMC-managed device must receive a UPMC IP address and operate on the UPMC network from a physical Pitt location.

Part 1 of 3 — Open the UPMC Ticket First

For Scenario B, the UPMC ticket must be opened first:

  • Phone: 412-647-HELP (4357)
  • Portal: UPMC IT Service Portal (contact UPMC Help Desk for current URL if needed)
  • Include: "Request to extend UPMC VLAN to Pitt facility."
  • Route to UPMC group: "ECG-Datacenter"
  • Record the UPMC ticket number for inclusion in the Pitt ticket.

Part 2 of 3 — Open the Pitt TDX Ticket

  1. Navigate to the Pitt network service request form, or open the ticket internally.
  2. Populate with all information from the Section 5 checklist.
  3. Include: "Request to extend UPMC VLAN to Pitt facility."
  4. Include the UPMC ticket number in the Pitt ticket body.
  5. Route to: Pitt Digital Network Engineering.
  6. Record the Pitt TDX ticket number.

Part 3 of 3 — Cross-Reference Both Tickets

  • Confirm the UPMC ticket number is in the Pitt TDX ticket.
  • Advise the caller to ensure the Pitt TDX ticket number is also added to the UPMC ticket.
  • Help Desk's active role ends here — both technical teams coordinate directly.
⚠ Security Policy: When UPMC's network is extended to a Pitt facility, all IP addresses are assigned by UPMC and all connected devices are subject to UPMC's IT Security policies. Direct security questions to the UPMC Help Desk at 412-647-HELP (4357).

New Physical Ports at Pitt (Scenario B)

  • A Pitt GL number (General Ledger account number) is required before installation begins.
  • Charges are billed to the requesting department or RC — one-time charges, subject to annual adjustment.
  • Complete a service request at tsrforms.pitt.edu to initiate the Pitt Telecommunications work order.

8. Step 4 — Post-Ticket Follow-Up

After both tickets have been opened and cross-referenced:

  • Pitt Digital and UPMC technical teams will review, verify, and begin coordinating the requested work.
  • Either team may contact the requestor to confirm details or request clarification.
  • Status updates will flow through the respective ticketing systems as work progresses.
  • Help Desk staff are not expected to monitor progress after tickets are created. Direct status inquiries to the assigned technical team via the TDX ticket.
ℹ Caller Expectations: Physical VLAN extension timelines vary depending on:
  • Whether new physical data ports must be installed at either facility
  • Availability of a Pitt GL number for new Pitt port installations
  • Security review timelines at either organization
  • Scheduling and coordination between two independent IT teams

Remind callers who only need internet access at the other organization's site that Eduroam is available immediately — no ticket or wait time involved.

9. Escalation Path

Situation Escalate To How
Pitt user cannot connect to Eduroam at UPMC Pitt Help Desk / Pitt Digital Open TDX ticket; verify Pitt credentials and device configuration
UPMC user cannot connect to Eduroam at Pitt UPMC Help Desk 412-647-HELP (4357) — Pitt cannot support UPMC credentials
Pitt VPN (GlobalProtect) installation or connection issues Pitt Help Desk Standard TDX ticket; portal address is portal-palo.pitt.edu
Pitt IT Security policy questions (Scenario A VLAN) Pitt Digital Security Route TDX ticket to Pitt Digital Security
Network engineering questions — Scenario B VLAN Pitt Digital Network Engineering Route TDX ticket to Pitt Digital Network Engineering
New data port installation at a Pitt building Pitt Telecommunications Caller submits service request at tsrforms.pitt.edu — GL number required
New data port installation at a UPMC building UPMC ECGDatacenter Group Via UPMC ticketing system — costs billed to requesting business unit
After-hours network incident or routing uncertainty Pitt Digital NOC Staffed 24×7×365 — escalate via TDX ticket assignment to NOC team
Walk-in technical support Help Desk Walk-In 1st Floor Hillman Library, Pittsburgh campus

10. Contact Directory

Group Phone Portal / Email / URL Hours
Pitt Technology Help Desk 412-624-HELP (4357) services.pitt.edu
helpdesk@pitt.edu
Chat with an Expert
See services.pitt.edu for current hours
Help Desk Walk-In 412-624-HELP (4357) 1st Floor, Hillman Library
Pittsburgh Campus
See services.pitt.edu for walk-in hours
Pitt Digital NOC Via TDX ticket escalation services.pitt.edu 24×7×365
Pitt Digital Network Engineering Via TDX ticket routing services.pitt.edu Business hours
Pitt Digital Security Via TDX ticket routing digital.pitt.edu/information-security Business hours
Pitt Telecommunications Via service request form tsrforms.pitt.edu Business hours
PittNet VPN Download software.pitt.edu — search "GlobalProtect"
Portal: portal-palo.pitt.edu
Self-service, 24/7
UPMC Help Desk 412-647-HELP (4357) UPMC IT Service Portal
(contact UPMC for current URL)
Contact UPMC for hours
Pitt Digital Admin Offices digital.pitt.edu Cathedral of Learning, 7th Floor
4200 Fifth Ave., Pittsburgh PA 15260

Article ID: PITT-KB-NET-622 v2.0  |  Revised: March 2026  |  Help Desk: 412-624-HELP (4357)  |  services.pitt.edu

Review this article periodically. Verify UPMC ticketing system URLs, UPMC routing group names, and Eduroam location coverage remain current. Contact Pitt Digital Network Engineering to confirm any changes.

Print Article

Related Services / Offerings (1)

CONTINUOUS IMPROVEMENT AND INNOVATION Pitt Digital offers a broad array of high-quality IT support options that are tailored to fit your school or department's specific needs on the Pittsburgh campus.