User Tools

Site Tools


auth:howto:linux:vpnclient

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
Next revisionBoth sides next revision
auth:howto:linux:vpnclient [2006/08/21 16:06] kohoferauth:howto:linux:vpnclient [2012/11/15 17:33] – external edit 127.0.0.1
Line 1: Line 1:
-===== VPN (Virtual Private Network) at the Free University of Bolzano/Bozen =====+====== VPN (Virtual Private Network) at the Free University of Bolzano/Bozen ======
  
-==== Infos regarding the usage of VPN ====+===== Infos regarding the usage of VPN =====
  
-http://www.unibz.it/ict/vpn/index.html?LanguageID=EN+http://www.unibz.it/en/ict/ComputerInternet/network/vpn/default.html
  
 +==== Instructions for Windows 2000, XP, VISTA and 7 - 32bit and 64bit ====
  
-==== Instructions for Windows 98, ME, NT 4.0, 2000 and XP ==== +http://www.unibz.it/en/ict/ComputerInternet/network/vpn/InstallationWindows.html
-http://www.unibz.it/ict/vpn/win/index.html?LanguageID=EN+
  
-==== Instructions for MacOS X 10.2-10.4 ==== +==== Instructions for MacOS X 10.4 ==== 
-http://www.unibz.it/ict/vpn/mac/index.html?LanguageID=EN+http://www.unibz.it/en/ict/ComputerInternet/network/vpn/InstallationMacOSX.html
  
-==== Instructions for Linux ====+==== Instructions for MacOS X 10.6 ====
  
-1. Download and install the kernel headers corresponding to the kernel in use. Some distributions name this package kernel-headers, others name it linux-headers:+There is no need to install a Client, simply download and install (doubleclick) the\\ 
 +following file:
  
-    # sudo apt-get install kernel-headers-X.X.XX-X-XXX +{{:auth:howto:linux:unibz.networkconnect.zip|}}
-or +
-    # sudo apt-get install linux-headers-X.X.XX-XXX+
  
-Substitute the notation X.X.XX with the actual version of your kernel. +===== Instructions for Linux vpnc Client (recommended) =====
-You can get the version of your kernel by issuing the following command:+
  
-    # uname -a+1. Install vpnc
  
-A valid version number could be, for example, 2.6.12-9-386.+  sudo aptitude install vpnc
  
-2. Download and install the vpnclient:+2. Create configuration file unibz.conf. Download from here{{:auth:howto:linux:unibz.conf|}} 
 +    
 +<note important>IPSec obfuscated secret needs to be on a single line.</note> 
 +    
 +<note important>Replace <your-windows-login> with your username.</note>
  
-Substitute the notation X Z with your university network's username and password:+  sudo vi /etc/vpnc/unibz.conf
  
-wget --no-check-certificate --http-user=X --http-password=Z https://pro.unibz.it/vpn/Linux/vpnclient-linux-x86_64-4.8.00.0490-k9.tar.gz+<code> 
 +####################################### 
 +IPSec gateway vpn.unibz.it 
 +IPSec ID Unibz 
 +IPSec obfuscated secret 06294C134E0BEBDA4B449B56BFD305D35D12DABF4044EDB6794926C2CA6D5AEDFE6342DF190E566EB11215DDC1591D5CB6ABEBEB593693C6D0B2077D78034B6AFEEA3221E77F4 
 +C9858DD711AA8DE58F6 
 +Xauth username <your-windows-login> 
 +####################################### 
 +</code>
  
 +apply this rights:
  
-3. Untar the source of vpnclient and install it+  sudo chmod 600 /etc/vpnc/unibz.conf 
-   Depending on the Linux Distribution you might need to install ''make'' and ''gcc-3.4'' +   
-   apt-get install make gcc-3.4+  sudo chown root.root /etc/vpnc/unibz.conf
  
-    # tar xfz vpnclient-linux-4.7.00.0640-k9.tar.gz +<code> 
-      +sudo ls -l /etc/vpnc/unibz.conf 
-    # cd vpnclient +-rw------- 1 root root 250 2009-05-02 15:54 /etc/vpnc/unibz.conf 
-     +</code>
-    # ./vpn_install+
  
-You will get some messages and you will be requested to answer to some questions:+3. Start vpnc
  
-    Directory where binaries will be installed [/usr/local/bin] +  sudo vpnc-connect --domain unibz unibz
-     +
-    Automatically start the VPN service at boot time [yes] +
-     +
-    Directory containing linux kernel source code [/lib/modules/X.X.XX-X-XXX/build]+
  
-You only have to modify the predefined answers if they do not correspond to your actual situation. +This will first ask for your sudo password and then 
-If everything works, you will see some compilation messages and then the installation program will stop.+your <unibz-password>
  
-4. Download the unibz.pcf configuration file from the site of the university. +4. Stop vpnc
-Substitute the notation XXX ZZZ with your university network's username and password:+
  
-    # wget --no-check-certificate --http-user=XXX --http-password=ZZZ https://pro.unibz.it/vpn/Configuration/unibz.zip+  sudo vpnc-disconnect
  
-5. Unzip the configuration file and copy it to the correct location:+==== Possible errors ====
  
-    # unzip unibz.zip +If you get the following error:  **vpnc-connect: no response from target**\\ 
-     +try adding the line below to your configuration file (unibz.conf)
-    # cp unibz.pcf /etc/opt/cisco-vpnclient/Profiles/.+
  
-6. Initialize the vpnclient:+**NAT Traversal Mode cisco-udp**
  
-    # sudo /etc/init.d/vpnclient_init start+----
  
-7. You can now start the vpnclient using sudo:+When one attempts to connect to their VPN after installing and configuring vpnc on Ubuntu Oneiric,\\ 
 +the following error occurs:
  
-    $ sudo vpnclient connect unibz+<code> 
 +root@ubuntu:~# vpnc-connect 
 +Error: either "to" is duplicate, or "ipid" is a garbage. 
 +</code>
  
-You will see some messages and then you will be requested to insert your username and password:+It appears that the Ubuntu package vpnc comes with an old version of vpnc-script.\\ 
 +This script is what sets up all the addresses and routes for you. The OpenConnect project\\ 
 +provides an updated / revised release of this script. Download the latest copy from [[http://git.infradead.org/users/dwmw2/vpnc-scripts.git/blob_plain/HEAD:/vpnc-script|here]].\\ 
 +Replace the vpnc-script script that comes with the Ubuntu vpnc package/etc/vpnc/vpnc-script
  
-    Cisco Systems VPN Client Version 4.8.00 (0490) 
-    Copyright (C) 1998-2005 Cisco Systems, Inc. All Rights Reserved. 
-    Client Type(s): Linux 
-    Running on: Linux 2.6.15-26-686 #1 SMP PREEMPT Thu Aug 3 03:13:28 UTC 2006 i686 
-    Config file directory: /etc/opt/cisco-vpnclient 
  
-    Initializing the VPN connection. +===== Instructions for Linux Cisco AnyConnect Client =====
-    Contacting the gateway at 193.206.186.111 +
-    User Authentication for unibz...+
  
-    Enter Username and Password.+=== Installation ===
  
-    Username []: X +1Open with your browser (tested with firefox 11.0) the following URL:
-    Password []: Z +
-    Authenticating user. +
-    Negotiating security policies. +
-    Securing communication channel.+
  
-    Your VPN connection is secure.+https://vpn.scientificnet.org
  
-    VPN tunnel information+2Enter your Username and password, then press **Login** 
-    Client address172.21.204.1 + 
-    Server address193.206.186.111 +3. A "Warning - Security" Windows opens: This will install the Cisco AnyConnect Client \\ 
-    Encryption128-bit AES +in /opt/cisco of your Platform. 
-    AuthenticationHMAC-SHA + 
-    IP CompressionNone +4. Press **Run** on the "Warning - Security" Window 
-    NAT passthrough is active on port UDP 4500 + 
-    Local LAN Access is disabled+{{:auth:howto:linux:cisco-anyconnect_1.png?direct&200}} 
 + 
 +5In order to install Cisco AnyConnect, Admin (sudo) rights are required; a Window opens,\\ 
 +enter your local password
 + 
 +{{:auth:howto:linux:cisco-anyconenct_2.png?direct&200|}} 
 + 
 +6The Cisco AnyConnect is installed and running, you can close the URL
 + 
 +{{:auth:howto:linux:cisco-anyconnect_3.png?direct&200|}} 
 + 
 +=== Launching Cisco AnyConnect GUI === 
 + 
 +This allows you to connect and disconnect the VPN service. 
 + 
 +  /opt/cisco/anyconnect/bin/vpnui 
 + 
 +Please note the vpnagentd must be running for this 
 + 
 +  * ps auxww | grep vpn 
 +<code> 
 +root      1759  0.0  0.3  17984  7644 ?        S    12:58   0:00 /opt/cisco/anyconnect/bin/vpnagentd 
 +</code> 
 + 
 +=== Launching Cisco AnyConnect NON-GUI === 
 + 
 +This allows you to connect and disconnect the VPN service. 
 + 
 +  * /opt/cisco/anyconnect/bin/vpn 
 + 
 +<code> 
 +Cisco AnyConnect Secure Mobility Client (version 3.0.5080) . 
 + 
 +Copyright (c) 2004 - 2011 Cisco Systems, Inc. 
 +All Rights Reserved. 
 + 
 + 
 +  >> stateDisconnected 
 +  >> state: Disconnected 
 +  >> notice: Ready to connect. 
 +  >> registered with local VPN subsystem. 
 +VPN> connect vpn.unibz.it 
 +connect vpn.unibz.it 
 +  >> contacting host (vpn.unibz.it) for login information... 
 +  >> notice: Contacting vpn.unibz.it. 
 +VPN>  
 +  >> Please enter your username and password. 
 +    0) clientless 
 +    1) scientificnetwork 
 +Group: [clientless]  
 + 
 +Username: <your-username> 
 +Password:  
 +  >> state: Connecting 
 +  >> notice: Establishing VPN session... 
 +  >> notice: Checking for profile updates... 
 +  >> notice: Checking for product updates... 
 +  >> notice: Checking for customization updates... 
 +  >> notice: Performing any required updates... 
 +  >> state: Connecting 
 +  >> notice: Establishing VPN session... 
 +  >> notice: Establishing VPN - Initiating connection... 
 +  >> notice: Establishing VPN - Examining system... 
 +  >> notice: Establishing VPN - Activating VPN adapter... 
 +  >> notice: Establishing VPN - Configuring system... 
 +  >> notice: Establishing VPN... 
 +  >> state: Connected 
 +  >> notice: Connected to vpn.unibz.it. 
 +VPN>exit 
 + 
 + 
 +</code> 
 + 
 +=== Uninstalling the AnyConnect Client === 
 + 
 +The client comes with an uninstallation script 
 + 
 +  * sudo /opt/cisco/vpn/bin/vpn_uninstall.sh 
 + 
 +However it doesn't actually uninstall everything properly, it removes files but leaves behind directories.\\ 
 +You can clean up what it leaves behind by deleting the directory /opt/cisco/ and /opt/.cisco/ 
 + 
 +  * sudo rm -r /opt/cisco /opt/.cisco 
 + 
 +Per-user configuration is stored in your home directory in a file called .anyconnect 
 + 
 +===== Shrew Soft VPN Client Instructions for 32 or 64 bit version of Windows 2000, XP, Vista and 7 (recommened) ===== 
 + 
 +1. Go to http://www.shrew.net/home and download latest stable release of Shrew Soft VPN Client for Windows: http://www.shrew.net/download/vpn 
 + 
 +2. Download unibz profile (need to login with unibz login&password) 
 +https://pro.unibz.it/vpn/profiles/unibz/Free%20University%20of%20Bozen-Bolzano.zip 
 + 
 +3. Install Shrew Soft VPN Client for Windows 
 + 
 +4. Start Shrew Soft VPN Client, unzip unibz profile and Import in VPN client
  
-Please notice that you will have to leave the console open in order to have the VPN running. 
  
/data/www/wiki.inf.unibz.it/data/pages/auth/howto/linux/vpnclient.txt · Last modified: 2022/06/20 11:40 by kohofer