User Tools

Site Tools


auth:howto:linux:vpnclient

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
auth:howto:linux:vpnclient [2008/05/04 23:36] kohoferauth:howto:linux:vpnclient [2012/04/05 12:03] kohofer
Line 1: Line 1:
-===== VPN (Virtual Private Network) at the Free University of Bolzano/Bozen =====+====== VPN (Virtual Private Network) at the Free University of Bolzano/Bozen ======
  
-==== Infos regarding the usage of VPN ====+===== Infos regarding the usage of VPN =====
  
-http://www.unibz.it/ict/vpn/index.html?LanguageID=EN+http://www.unibz.it/en/ict/ComputerInternet/network/vpn/default.html
  
 +==== Instructions for Windows 2000, XP, VISTA and 7 - 32bit and 64bit ====
  
-==== Instructions for Windows 98, ME, NT 4.0, 2000 and XP ==== +http://www.unibz.it/en/ict/ComputerInternet/network/vpn/InstallationWindows.html
-http://www.unibz.it/ict/vpn/win/index.html?LanguageID=EN+
  
-==== Instructions for MacOS X 10.2-10.4 ==== +==== Instructions for MacOS X 10.4 ==== 
-http://www.unibz.it/ict/vpn/mac/index.html?LanguageID=EN+http://www.unibz.it/en/ict/ComputerInternet/network/vpn/InstallationMacOSX.html
  
 +==== Instructions for MacOS X 10.6 ====
  
 +There is no need to install a Client, simply install (doubleclick) the\\
 +following file:
  
 +{{:auth:howto:linux:unibz.networkconnect.zip|}}
  
 +===== Instructions for Linux Cisco AnyConnect Client (recommened) =====
  
 +=== Installation ===
  
-==== Instructions for Linux ====+1. Open with your browser (tested with firefox 11.0) the following URL:
  
-1Download and install the kernel headers corresponding to the kernel in useSome distributions name this package kernel-headers, others name it linux-headers:+https://vpn.scientificnet.org
  
-    # sudo apt-get install kernel-headers-`uname -r` +2. Enter your Username and password, then press **Login**
-or +
-    # sudo apt-get install linux-headers-`uname -r`+
  
-You can get the version of your kernel by issuing the following command:+3. A "Warning - Security" Windows opens: This will install the Cisco AnyConnect\\ 
 +   in /opt/cisco of your System
  
-    # uname -a+4. Press **Run**
  
-A valid version number could befor example2.6.12-9-386.+5. In order to install Cisco AnyConnectAdmin (sudo) rights are required; a Window opens,\\ 
 +   enter your local password.
  
-2Download and install the vpnclient via Web:+6The Cisco AnyConnect is installed and running, you can close the URL.
  
-https://pro.unibz.it/vpn/client/common/linux/vpnclient-linux-x86_64-4.8.01.0640-k9.tar.gz 
  
-2.1 Download and install the vpnclient via wget:+=== Launching Cisco AnyConnect GUI ===
  
-Substitute the notation X Z with your university network's username and password:+This allows you to connect and disconnect the VPN service.
  
-   wget --no-check-certificate --http-user=X --http-password=Z https://pro.unibz.it/vpn/client/common/linux/vpnclient-linux-x86_64-4.8.01.0640-k9.tar.gz+  /opt/cisco/anyconnect/bin/vpnui
  
-3Untar the source of vpnclient and install it. +More infos to come like using OpenConnect...
-   Depending on the Linux Distribution you might need to install ''make'' and ''gcc-3.4'' +
-    +
-   sudo apt-get install make gcc-3.4+
  
-   # tar xfz vpnclient-linux-x86_64-4.8.01.0640-k9.tar.gz 
  
-<del>For kernel versions > 2.6.19 follow this instructions: [[http://tuxx-home.at/archives/2007/05/29/T16_34_26/]]</del>+===== Instructions for Linux vpnc Client (fails to work since update to Cisco ASA) =====
  
-For Hardy Heron 8.04 Kernel (2.6.24-xx) follow this instructions: [[http://www.blog.arun-prabha.com/2008/05/01/cisco-vpn-installation-issue-with-ubuntu-804-hardy-heron/]]+1Install vpnc
  
-   # cd vpnclient +  sudo aptitude install vpnc
-     +
-   sudo ./vpn_install+
  
-You will get some messages and you will be requested to answer to some questions:+2. Create configuration file unibz.conf. 
 +   Please Note: IPSec obfuscated secret ... needs to be on a single line. Replace <your-windows-login> with your username.
  
-    Directory where binaries will be installed [/usr/local/bin] +  sudo vi /etc/vpnc/unibz.conf
-     +
-    Automatically start the VPN service at boot time [yes] +
-     +
-    Directory containing linux kernel source code [/lib/modules/X.X.XX-X-XXX/build]+
  
-You only have to modify the predefined answers if they do not correspond to your actual situation. +<code> 
-If everything works, you will see some compilation messages and then the installation program will stop.+####################################### 
 +IPSec gateway vpn.unibz.it 
 +IPSec ID Unibz 
 +IPSec obfuscated secret 06294C134E0BEBDA4B449B56BFD305D35D12DABF4044EDB6794926C2CA6D5AEDFE6342DF190E566EB11215DDC1591D5CB6ABEBEB593693C6D0B2077D78034B6AFEEA3221E77F4 
 +C9858DD711AA8DE58F6 
 +Xauth username <your-windows-login> 
 +####################################### 
 +</code>
  
-4. Download the unibz.pcf configuration file from the site of the university via web:+apply this rights:
  
-https://pro.unibz.it/vpn/profiles/unibz/Free%20University%20of%20Bozen-Bolzano.zip+  sudo chmod 600 /etc/vpnc/unibz.conf 
 +   
 +  sudo chown root.root /etc/vpnc/unibz.conf
  
-4.1 Download the unibz.pcf configuration file from the site of the university via wget:+<code> 
 +sudo ls -l /etc/vpnc/unibz.conf 
 +-rw------- root root 250 2009-05-02 15:54 /etc/vpnc/unibz.conf 
 +</code>
  
-Substitute the notation XXX ZZZ with your university network's username and password:+3. Start vpnc
  
-    wget --no-check-certificate --http-user=XXX --http-password=ZZZ https://pro.unibz.it/vpn/profiles/unibz/Free%20University%20of%20Bozen-Bolzano.zip+  sudo vpnc-connect unibz
  
-5. Unzip the configuration file and copy it to the correct location:+This will first ask for your sudo password and then 
 +you <windows-password>
  
-    # unzip "Free University of Bozen-Bolzano.zip" +4Stop vpnc
-     +
-    # sudo cp "Free University of Bozen-Bolzano.pcf" /etc/opt/cisco-vpnclient/Profiles/unibz.pcf+
  
-6. Initialize the vpnclient:+  sudo vpnc-disconnect
  
-    # sudo /etc/init.d/vpnclient_init start+===== Shrew Soft VPN Client Instructions for 32 or 64 bit version of Windows 2000, XP, Vista and 7 (recommened) =====
  
-7You can now start the vpnclient using sudo:+1Go to http://www.shrew.net/home and download latest stable release of Shrew Soft VPN Client for Windows: http://www.shrew.net/download/vpn
  
-    $ sudo vpnclient connect unibz +2. Download unibz profile (need to login with unibz login&password) 
- +https://pro.unibz.it/vpn/profiles/unibz/Free%20University%20of%20Bozen-Bolzano.zip
-You will see some messages and then you will be requested to insert your username and password+
- +
-    Cisco Systems VPN Client Version 4.8.01 (0640+
-    Copyright (C) 1998-2007 Cisco Systems, Inc. All Rights Reserved. +
-    Client Type(s)Linux +
-    Running on: Linux 2.6.22-14-generic #1 SMP Tue Dec 18 08:02:57 UTC 2007 i686 +
-    Config file directory: /etc/opt/cisco-vpnclient +
- +
-    Initializing the VPN connection. +
-    Contacting the gateway at 193.206.186.111 +
-    User Authentication for unibz... +
- +
-    Enter Username and Password. +
- +
-    Username []: X +
-    Password []: Z +
-    Authenticating user. +
-    Negotiating security policies. +
-    Securing communication channel.+
  
-    Your VPN connection is secure.+3Install Shrew Soft VPN Client for Windows
  
-    VPN tunnel information. +4. Start Shrew Soft VPN Client, unzip unibz profile and Import in VPN client
-    Client address: 172.21.204.1 +
-    Server address: 193.206.186.111 +
-    Encryption: 128-bit AES +
-    Authentication: HMAC-SHA +
-    IP Compression: None +
-    NAT passthrough is active on port UDP 4500 +
-    Local LAN Access is disabled+
  
-Please notice that you will have to leave the console open in order to have the VPN running. 
  
/data/www/wiki.inf.unibz.it/data/pages/auth/howto/linux/vpnclient.txt · Last modified: 2022/06/20 11:40 by kohofer