auth:howto:linux:vpnclient
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
auth:howto:linux:vpnclient [2010/08/30 17:12] – kohofer | auth:howto:linux:vpnclient [2014/08/07 15:40] – kohofer | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ===== VPN (Virtual Private Network) at the Free University of Bolzano/ | + | ====== VPN (Virtual Private Network) at the Free University of Bolzano/ |
- | ==== Infos regarding the usage of VPN ==== | + | ===== Infos regarding the usage of VPN ===== |
http:// | http:// | ||
- | ==== Instructions for Windows 2000, XP and VISTA ==== | + | ==== Instructions for Windows 2000, XP, VISTA and 7 - 32bit and 64bit ==== |
http:// | http:// | ||
Line 11: | Line 12: | ||
http:// | http:// | ||
- | ==== Instructions for Linux VPNC Client (recommened) ==== | + | ==== Instructions for MacOS X 10.6 ==== |
+ | |||
+ | There is no need to install a Client, simply download and install (doubleclick) the\\ | ||
+ | following file: | ||
+ | |||
+ | {{: | ||
+ | |||
+ | ===== Instructions for Linux vpnc Client (recommended) ===== | ||
1. Install vpnc | 1. Install vpnc | ||
Line 17: | Line 25: | ||
sudo aptitude install vpnc | sudo aptitude install vpnc | ||
- | 2. Create configuration file unibz.conf. | + | 2. For Unibz: |
- | Please Note: IPSec obfuscated secret | + | |
+ | * Create configuration file unibz.conf. | ||
+ | |||
+ | 2.a For Eurac: | ||
+ | |||
+ | * Create configuration file eurac.conf. Download from here: {{: | ||
+ | |||
+ | <note important> | ||
+ | |||
+ | <note important> | ||
+ | |||
+ | |||
+ | For Unibz: | ||
sudo vi / | sudo vi / | ||
Line 41: | Line 61: | ||
sudo ls -l / | sudo ls -l / | ||
-rw------- 1 root root 250 2009-05-02 15:54 / | -rw------- 1 root root 250 2009-05-02 15:54 / | ||
+ | </ | ||
+ | |||
+ | For Eurac: | ||
+ | |||
+ | sudo vi / | ||
+ | |||
+ | < | ||
+ | ####################################### | ||
+ | IPSec gateway vpn.scientificnet.org | ||
+ | IPSec ID Eurac | ||
+ | IPSec obfuscated secret 56A1CD68CC3AD33B48DB0F727ADDBC0A354DE3287D15C8526ED4CEDE4BC2ACDD1BB2460BC2354671A405F6150EA7C294C4DBC4CF9FFE45873BECAD3A2A738C5053BE34F709D592B50AD5BC472CDFF350 | ||
+ | Xauth username < | ||
+ | ####################################### | ||
+ | </ | ||
+ | |||
+ | apply this rights: | ||
+ | |||
+ | sudo chmod 600 / | ||
+ | | ||
+ | sudo chown root.root / | ||
+ | |||
+ | < | ||
+ | sudo ls -l / | ||
+ | -rw------- 1 root root 250 2009-05-02 15:54 / | ||
</ | </ | ||
3. Start vpnc | 3. Start vpnc | ||
- | | + | For Unibz: |
+ | |||
+ | | ||
This will first ask for your sudo password and then | This will first ask for your sudo password and then | ||
- | you <windows-password> | + | your <unibz-password> |
+ | |||
+ | For Eurac: | ||
+ | |||
+ | sudo vpnc-connect --domain eurac eurac | ||
+ | |||
+ | This will first ask for your sudo password and then | ||
+ | your < | ||
4. Stop vpnc | 4. Stop vpnc | ||
Line 55: | Line 109: | ||
- | ==== Instructions for Linux Cisco VPN Client | + | ==== Possible errors |
- | 1. Download and install | + | If you get the following error: |
+ | try adding the line below to your configuration file (unibz.conf) | ||
- | # sudo apt-get install kernel-headers-`uname -r` | + | **NAT Traversal Mode cisco-udp** |
- | or | + | |
- | # sudo apt-get install linux-headers-`uname -r` | + | |
- | You can get the version of your kernel by issuing the following command: | + | ---- |
- | # uname -a | + | When one attempts to connect to their VPN after installing and configuring vpnc on Ubuntu Oneiric, |
+ | the following error occurs: | ||
- | A valid version number could be, for example, 2.6.12-9-386. | + | < |
+ | root@ubuntu: | ||
+ | Error: either " | ||
+ | </ | ||
- | 2. Download | + | It appears that the Ubuntu package vpnc comes with an old version of vpnc-script.\\ |
+ | This script is what sets up all the addresses | ||
+ | provides an updated / revised release of this script. Download the latest copy from [[http:// | ||
+ | Replace the vpnc-script script that comes with the Ubuntu vpnc package: / | ||
- | If kernel > 2.6.24-xx then download: | + | ==== Decode Group Password ==== |
- | https://pro.unibz.it/vpn/client/ | + | [[https://www.unix-ag.uni-kl.de/~massar/bin/cisco-decode|cisco |
- | otherwise download: | ||
- | https:// | + | ===== Instructions for Linux Cisco AnyConnect Client ===== |
- | 3. Untar the source of vpnclient and install it. | + | === Installation === |
- | | + | |
- | + | ||
- | sudo apt-get install make gcc-3.4 | + | |
- | If kernel > 2.6.24-xx then | + | 1. Open with your browser (tested with firefox 11.0) the following URL: |
- | # tar xfz vpnclient-linux-x86_64-4.8.01.0640-k9_2.6.24-xx.tar.gz | + | https://vpn.scientificnet.org |
- | otherwise | + | 2. Enter your Username and password, then press **Login** |
- | # tar xfz vpnclient-linux-x86_64-4.8.01.0640-k9.tar.gz | + | 3. A " |
+ | in /opt/cisco of your Platform. | ||
- | Next install/ | + | 4. Press **Run** on the " |
- | # cd vpnclient | + | {{: |
- | + | ||
- | # sudo ./ | + | |
- | You will get some messages and you will be requested | + | 5. In order to install Cisco AnyConnect, Admin (sudo) rights are required; a Window opens,\\ |
+ | enter your local password. | ||
- | Directory where binaries will be installed [/ | + | {{: |
- | + | ||
- | Automatically start the VPN service at boot time [yes] no | + | |
- | + | ||
- | Directory containing | + | |
- | + | 6. The Cisco AnyConnect is installed and running, you can close the URL. | |
- | You only have to modify the predefined answers if they do not correspond to your actual situation. | + | |
- | If everything works, you will see some compilation messages and then the installation program will stop. | + | |
- | 4. Download the unibz.pcf configuration file from the site of the university via web: | + | {{:auth: |
- | https:// | + | === Launching Cisco AnyConnect GUI === |
- | 5. Unzip the configuration file and copy it to the correct location: | + | This allows you to connect |
- | # unzip "Free University of Bozen-Bolzano.zip" | + | |
- | + | ||
- | # sudo cp "Free University of Bozen-Bolzano.pcf" | + | |
- | 6. Initialize | + | Please note the vpnagentd must be running for this |
- | # sudo /etc/init.d/vpnclient_init start | + | * ps auxww | grep vpn |
+ | < | ||
+ | root 1759 0.0 0.3 17984 7644 ? S 12:58 | ||
+ | </code> | ||
- | 7. You can now start the vpnclient using sudo: | + | === Launching Cisco AnyConnect NON-GUI === |
- | $ sudo vpnclient | + | This allows you to connect |
- | You will see some messages and then you will be requested to insert your username and password: | + | * / |
- | | + | < |
- | Copyright (C) 1998-2007 Cisco Systems, Inc. All Rights Reserved. | + | Cisco AnyConnect Secure Mobility |
- | Client Type(s): Linux | + | |
- | Running on: Linux 2.6.22-14-generic #1 SMP Tue Dec 18 08:02:57 UTC 2007 i686 | + | |
- | Config file directory: / | + | |
- | Initializing the VPN connection. | + | Copyright (c) 2004 - 2011 Cisco Systems, Inc. |
- | | + | All Rights Reserved. |
- | User Authentication for unibz... | + | |
- | Enter Username and Password. | ||
- | Username []: X | + | >> state: Disconnected |
- | | + | >> state: Disconnected |
- | | + | >> notice: Ready to connect. |
- | | + | >> registered with local VPN subsystem. |
- | | + | VPN> connect vpn.unibz.it |
+ | connect vpn.unibz.it | ||
+ | >> contacting host (vpn.unibz.it) for login information... | ||
+ | >> notice: Contacting vpn.unibz.it. | ||
+ | VPN> | ||
+ | >> Please enter your username and password. | ||
+ | | ||
+ | 1) scientificnetwork | ||
+ | Group: | ||
+ | |||
+ | Username: < | ||
+ | Password: | ||
+ | >> state: Connecting | ||
+ | >> notice: Establishing VPN session... | ||
+ | >> notice: Checking for profile updates... | ||
+ | >> notice: Checking for product updates... | ||
+ | >> notice: Checking for customization updates... | ||
+ | >> notice: Performing any required updates... | ||
+ | >> state: Connecting | ||
+ | >> notice: Establishing VPN session... | ||
+ | >> notice: Establishing VPN - Initiating connection... | ||
+ | >> notice: Establishing VPN - Examining system... | ||
+ | >> notice: Establishing VPN - Activating VPN adapter... | ||
+ | >> notice: Establishing VPN - Configuring system... | ||
+ | >> notice: Establishing VPN... | ||
+ | >> state: Connected | ||
+ | >> notice: Connected to vpn.unibz.it. | ||
+ | VPN> | ||
+ | |||
+ | |||
+ | </ | ||
+ | |||
+ | === Uninstalling the AnyConnect Client === | ||
+ | |||
+ | The client comes with an uninstallation script | ||
+ | |||
+ | * sudo / | ||
+ | |||
+ | However it doesn' | ||
+ | You can clean up what it leaves behind by deleting the directory /opt/cisco/ and / | ||
+ | |||
+ | * sudo rm -r /opt/cisco / | ||
+ | |||
+ | Per-user configuration is stored in your home directory in a file called | ||
+ | |||
+ | ===== Shrew Soft VPN Client Instructions for 32 or 64 bit version of Windows 2000, XP, Vista and 7 (recommened) ===== | ||
+ | |||
+ | 1. Go to http:// | ||
+ | |||
+ | 2. Download unibz profile (need to login with unibz login& | ||
+ | https:// | ||
- | Your VPN connection is secure. | + | 3. Install Shrew Soft VPN Client for Windows |
- | | + | 4. Start Shrew Soft VPN Client, unzip unibz profile and Import in VPN client |
- | | + | |
- | Server address: 193.206.186.111 | + | |
- | Encryption: 128-bit AES | + | |
- | Authentication: | + | |
- | IP Compression: | + | |
- | NAT passthrough is active on port UDP 4500 | + | |
- | Local LAN Access is disabled | + | |
- | Please notice that you will have to leave the console open in order to have the VPN running. | ||
/data/www/wiki.inf.unibz.it/data/pages/auth/howto/linux/vpnclient.txt · Last modified: 2022/06/20 11:40 by kohofer