User Tools

Site Tools


auth:howto:linux:vpnclient

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
auth:howto:linux:vpnclient [2012/04/05 14:00] – [Instructions for Linux Cisco AnyConnect Client (recommened)] kohoferauth:howto:linux:vpnclient [2014/08/07 15:40] kohofer
Line 1: Line 1:
-====== VPN (Virtual Private Network) at the Free University of Bolzano/Bozen ======+====== VPN (Virtual Private Network) at the Free University of Bolzano/Bozen and EURAC ======
  
 ===== Infos regarding the usage of VPN ===== ===== Infos regarding the usage of VPN =====
Line 14: Line 14:
 ==== Instructions for MacOS X 10.6 ==== ==== Instructions for MacOS X 10.6 ====
  
-There is no need to install a Client, simply install (doubleclick) the\\+There is no need to install a Client, simply download and install (doubleclick) the\\
 following file: following file:
  
 {{:auth:howto:linux:unibz.networkconnect.zip|}} {{:auth:howto:linux:unibz.networkconnect.zip|}}
  
-===== Instructions for Linux Cisco AnyConnect Client (recommened) =====+===== Instructions for Linux vpnc Client (recommended===== 
 + 
 +1. Install vpnc 
 + 
 +  sudo aptitude install vpnc 
 + 
 +2. For Unibz: 
 + 
 +  * Create configuration file unibz.conf. Download from here: {{:auth:howto:linux:unibz.conf|}} 
 + 
 +2.a For Eurac: 
 + 
 +   * Create configuration file eurac.conf. Download from here: {{:auth:howto:linux:eurac.conf|}} 
 +    
 +<note important>IPSec obfuscated secret needs to be on a single line.</note> 
 +    
 +<note important>Replace <your-windows-login> with your username.</note> 
 + 
 + 
 +For Unibz: 
 + 
 +  sudo vi /etc/vpnc/unibz.conf 
 + 
 +<code> 
 +####################################### 
 +IPSec gateway vpn.unibz.it 
 +IPSec ID Unibz 
 +IPSec obfuscated secret 06294C134E0BEBDA4B449B56BFD305D35D12DABF4044EDB6794926C2CA6D5AEDFE6342DF190E566EB11215DDC1591D5CB6ABEBEB593693C6D0B2077D78034B6AFEEA3221E77F4 
 +C9858DD711AA8DE58F6 
 +Xauth username <your-windows-login> 
 +####################################### 
 +</code> 
 + 
 +apply this rights: 
 + 
 +  sudo chmod 600 /etc/vpnc/unibz.conf 
 +   
 +  sudo chown root.root /etc/vpnc/unibz.conf 
 + 
 +<code> 
 +sudo ls -l /etc/vpnc/unibz.conf 
 +-rw------- 1 root root 250 2009-05-02 15:54 /etc/vpnc/unibz.conf 
 +</code> 
 + 
 +For Eurac: 
 + 
 +  sudo vi /etc/vpnc/eurac.conf 
 + 
 +<code> 
 +####################################### 
 +IPSec gateway vpn.scientificnet.org  
 +IPSec ID Eurac 
 +IPSec obfuscated secret 56A1CD68CC3AD33B48DB0F727ADDBC0A354DE3287D15C8526ED4CEDE4BC2ACDD1BB2460BC2354671A405F6150EA7C294C4DBC4CF9FFE45873BECAD3A2A738C5053BE34F709D592B50AD5BC472CDFF350 
 +Xauth username <your-windows-login> 
 +####################################### 
 +</code> 
 + 
 +apply this rights: 
 + 
 +  sudo chmod 600 /etc/vpnc/eurac.conf 
 +   
 +  sudo chown root.root /etc/vpnc/eurac.conf 
 + 
 +<code> 
 +sudo ls -l /etc/vpnc/eurac.conf 
 +-rw------- 1 root root 250 2009-05-02 15:54 /etc/vpnc/eurac.conf 
 +</code> 
 + 
 +3. Start vpnc 
 + 
 +For Unibz: 
 + 
 +  sudo vpnc-connect --domain unibz unibz 
 + 
 +This will first ask for your sudo password and then 
 +your <unibz-password> 
 + 
 +For Eurac: 
 + 
 +  sudo vpnc-connect --domain eurac eurac 
 + 
 +This will first ask for your sudo password and then 
 +your <eurac-password> 
 + 
 + 
 +4. Stop vpnc 
 + 
 +  sudo vpnc-disconnect 
 + 
 + 
 +==== Possible errors ==== 
 + 
 +If you get the following error:  **vpnc-connect: no response from target**\\ 
 +try adding the line below to your configuration file (unibz.conf) 
 + 
 +**NAT Traversal Mode cisco-udp** 
 + 
 +---- 
 + 
 +When one attempts to connect to their VPN after installing and configuring vpnc on Ubuntu Oneiric,\\ 
 +the following error occurs: 
 + 
 +<code> 
 +root@ubuntu:~# vpnc-connect 
 +Error: either "to" is duplicate, or "ipid" is a garbage. 
 +</code> 
 + 
 +It appears that the Ubuntu package vpnc comes with an old version of vpnc-script.\\ 
 +This script is what sets up all the addresses and routes for you. The OpenConnect project\\ 
 +provides an updated / revised release of this script. Download the latest copy from [[http://git.infradead.org/users/dwmw2/vpnc-scripts.git/blob_plain/HEAD:/vpnc-script|here]].\\ 
 +Replace the vpnc-script script that comes with the Ubuntu vpnc package: /etc/vpnc/vpnc-script 
 + 
 +==== Decode Group Password ==== 
 + 
 +[[https://www.unix-ag.uni-kl.de/~massar/bin/cisco-decode|cisco vpnclient password decoder]] 
 + 
 + 
 +===== Instructions for Linux Cisco AnyConnect Client =====
  
 === Installation === === Installation ===
Line 33: Line 150:
  
 4. Press **Run** on the "Warning - Security" Window 4. Press **Run** on the "Warning - Security" Window
 +
 +{{:auth:howto:linux:cisco-anyconnect_1.png?direct&200}}
  
 5. In order to install Cisco AnyConnect, Admin (sudo) rights are required; a Window opens,\\ 5. In order to install Cisco AnyConnect, Admin (sudo) rights are required; a Window opens,\\
 enter your local password. enter your local password.
 +
 +{{:auth:howto:linux:cisco-anyconenct_2.png?direct&200|}}
  
 6. The Cisco AnyConnect is installed and running, you can close the URL. 6. The Cisco AnyConnect is installed and running, you can close the URL.
 +
 +{{:auth:howto:linux:cisco-anyconnect_3.png?direct&200|}}
  
 === Launching Cisco AnyConnect GUI === === Launching Cisco AnyConnect GUI ===
Line 58: Line 181:
   * /opt/cisco/anyconnect/bin/vpn   * /opt/cisco/anyconnect/bin/vpn
  
-<file>+<code>
 Cisco AnyConnect Secure Mobility Client (version 3.0.5080) . Cisco AnyConnect Secure Mobility Client (version 3.0.5080) .
  
Line 99: Line 222:
  
  
-</file>+</code>
  
 === Uninstalling the AnyConnect Client === === Uninstalling the AnyConnect Client ===
Line 113: Line 236:
  
 Per-user configuration is stored in your home directory in a file called .anyconnect Per-user configuration is stored in your home directory in a file called .anyconnect
- 
- 
-More infos to follow... 
- 
- 
-===== Instructions for Linux vpnc Client (fails to work since update to Cisco ASA) ===== 
- 
-1. Install vpnc 
- 
-  sudo aptitude install vpnc 
- 
-2. Create configuration file unibz.conf. 
-   Please Note: IPSec obfuscated secret ... needs to be on a single line. Replace <your-windows-login> with your username. 
- 
-  sudo vi /etc/vpnc/unibz.conf 
- 
-<code> 
-####################################### 
-IPSec gateway vpn.unibz.it 
-IPSec ID Unibz 
-IPSec obfuscated secret 06294C134E0BEBDA4B449B56BFD305D35D12DABF4044EDB6794926C2CA6D5AEDFE6342DF190E566EB11215DDC1591D5CB6ABEBEB593693C6D0B2077D78034B6AFEEA3221E77F4 
-C9858DD711AA8DE58F6 
-Xauth username <your-windows-login> 
-####################################### 
-</code> 
- 
-apply this rights: 
- 
-  sudo chmod 600 /etc/vpnc/unibz.conf 
-   
-  sudo chown root.root /etc/vpnc/unibz.conf 
- 
-<code> 
-sudo ls -l /etc/vpnc/unibz.conf 
--rw------- 1 root root 250 2009-05-02 15:54 /etc/vpnc/unibz.conf 
-</code> 
- 
-3. Start vpnc 
- 
-  sudo vpnc-connect unibz 
- 
-This will first ask for your sudo password and then 
-you <windows-password> 
- 
-4. Stop vpnc 
- 
-  sudo vpnc-disconnect 
  
 ===== Shrew Soft VPN Client Instructions for 32 or 64 bit version of Windows 2000, XP, Vista and 7 (recommened) ===== ===== Shrew Soft VPN Client Instructions for 32 or 64 bit version of Windows 2000, XP, Vista and 7 (recommened) =====
/data/www/wiki.inf.unibz.it/data/pages/auth/howto/linux/vpnclient.txt · Last modified: 2022/06/20 11:40 by kohofer