auth:howto:linux:vpnclient
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionLast revisionBoth sides next revision | ||
auth:howto:linux:vpnclient [2016/04/28 10:04] – [Possible errors] kohofer | auth:howto:linux:vpnclient [2022/05/06 16:22] – [Install openconnect-sso macOS with SAML] kohofer | ||
---|---|---|---|
Line 3: | Line 3: | ||
===== Infos regarding the usage of VPN ===== | ===== Infos regarding the usage of VPN ===== | ||
- | http://www.unibz.it/en/ict/ | + | https://knowledge.scientificnet.org/workspace/#nd=ab7442f9-c4d0-4ffc-a4f7-1e0d84515cc9& |
- | + | ||
- | ==== Instructions for Windows 7 - 32bit and 64bit ==== | + | |
- | + | ||
- | http:// | + | |
==== Instructions for MacOS X ==== | ==== Instructions for MacOS X ==== | ||
Line 55: | Line 51: | ||
- Enter Password if not already entered above | - Enter Password if not already entered above | ||
- | ===== Instructions for Linux vpnc Client (recommended) ===== | + | === Instructions for Android 7 === |
+ | |||
+ | - Press Settings | ||
+ | - Find VPN Settings, depends on Model | ||
+ | - Next click: Add VPN Configuration... | ||
+ | - **Name:** Unibz VPN | ||
+ | - **Type:** IPSec Xauth PSK | ||
+ | - **Server-Address: | ||
+ | - **IPSec Identifier: | ||
+ | - **IPSec Pre-shared Key:** NrW2z9sj8g3kjJrzXxJwRPbIRNInWakL | ||
+ | - **Account: | ||
+ | - **Password: | ||
+ | |||
+ | - Press Done | ||
+ | - Status: Slide Button to the right to connect | ||
+ | - Enter Password if not already entered above | ||
+ | |||
+ | ===== Instructions for Linux using openconnect | ||
+ | |||
+ | Run this command to install openconnect client and OpenConnect plugin GNOME GUI | ||
+ | |||
+ | sudo apt install openconnect network-manager-openconnect network-manager-openconnect-gnome | ||
+ | |||
+ | Once installed open Settings and go to Network, press + right of the VPN section. | ||
+ | |||
+ | {{: | ||
+ | |||
+ | Select **Cisco AnyConnect Compatible VPN (openconnect)** and fill out as shown below: | ||
+ | |||
+ | {{: | ||
+ | |||
+ | {{: | ||
+ | |||
+ | {{: | ||
+ | |||
+ | **Details** | ||
+ | - Make available to other users: tick if you want to allow other users on your system to use the VPN | ||
+ | |||
+ | **Identity** | ||
+ | - Name: VPN work (use a descriptive name) | ||
+ | - VPN Protocol: Cisco AnyConnect | ||
+ | - Gateway: vpn.scientificnet.org | ||
+ | - CA Certificate: | ||
+ | |||
+ | The rest can be left as it is. | ||
+ | |||
+ | **IPv4/ | ||
+ | - IPv4 Method: Automatic (DHCP) | ||
+ | - DNS: ON | ||
+ | - Routes: ON | ||
+ | |||
+ | Press <color # | ||
+ | |||
+ | Now you can enable the VPN connection! | ||
+ | |||
+ | Move the slider from OFF to ON, a small window should open, | ||
+ | |||
+ | {{: | ||
+ | |||
+ | make sure that for VPN Host you select: **vpn.scientificnet.org** | ||
+ | |||
+ | Enter your unibz Username, without @unibz.it and your unibz Password. | ||
+ | |||
+ | {{: | ||
+ | |||
+ | Press **Login** | ||
+ | |||
+ | If all goes well the slider should remain in ON position, if not check the Log. | ||
+ | To verify launch this command in a terminal: | ||
+ | |||
+ | ifconfig | grep 172* | ||
+ | |||
+ | You should get a new interface --> vpn0: with an IP Address: 172.21.66.xxx | ||
+ | |||
+ | ===== Instructions for Linux vpnc Client | ||
1. Install vpnc | 1. Install vpnc | ||
- | sudo aptitude | + | sudo apt-get |
2. For Unibz: | 2. For Unibz: | ||
Line 82: | Line 152: | ||
IPSec gateway vpn.unibz.it | IPSec gateway vpn.unibz.it | ||
IPSec ID Unibz | IPSec ID Unibz | ||
- | IPSec obfuscated secret | + | IPSec obfuscated secret |
- | C9858DD711AA8DE58F6 | + | |
Xauth username your-windows-login | Xauth username your-windows-login | ||
+ | # e.g. Xauth username fmoser (not fmoser@unibz.it) | ||
####################################### | ####################################### | ||
</ | </ | ||
Line 109: | Line 179: | ||
IPSec obfuscated secret 56A1CD68CC3AD33B48DB0F727ADDBC0A354DE3287D15C8526ED4CEDE4BC2ACDD1BB2460BC2354671A405F6150EA7C294C4DBC4CF9FFE45873BECAD3A2A738C5053BE34F709D592B50AD5BC472CDFF350 | IPSec obfuscated secret 56A1CD68CC3AD33B48DB0F727ADDBC0A354DE3287D15C8526ED4CEDE4BC2ACDD1BB2460BC2354671A405F6150EA7C294C4DBC4CF9FFE45873BECAD3A2A738C5053BE34F709D592B50AD5BC472CDFF350 | ||
Xauth username your-windows-login | Xauth username your-windows-login | ||
+ | # e.g. Xauth username fmoser (not fmoser@eurac.edu) | ||
####################################### | ####################################### | ||
</ | </ | ||
Line 195: | Line 266: | ||
/ | / | ||
+ | |||
+ | ---- | ||
+ | |||
+ | Allow local (LAN) access when using VPN (MacOS) | ||
+ | |||
+ | |||
+ | {{: | ||
Line 303: | Line 381: | ||
Per-user configuration is stored in your home directory in a file called .anyconnect | Per-user configuration is stored in your home directory in a file called .anyconnect | ||
- | ===== Shrew Soft VPN Client Instructions for 32 or 64 bit version of Windows 2000, XP, Vista and 7 (recommened) | + | ====== Install openconnect-sso macOS with SAML ====== |
- | 1. Go to http:// | + | If you don't want to use Cisco Anyconnect on the Apple Mac, you can install openconnect |
+ | and openconnect-sso | ||
- | 2. Download unibz profile (need to login with unibz login& | + | **Requirements**: Python3 |
- | https:// | + | |
- | 3. Install | + | Install brew |
+ | /bin/bash -c " | ||
+ | |||
+ | Install | ||
+ | brew install openconnect pipx | ||
+ | pipx ensurepath | ||
+ | |||
+ | Install pipx | ||
+ | pip install --user pipx | ||
+ | |||
+ | Install openconnect-sso | ||
+ | pipx install " | ||
+ | pipx ensurepath | ||
+ | |||
+ | Launch openconnect-sso | ||
+ | / | ||
+ | |||
+ | < | ||
+ | ... | ||
+ | ... | ||
+ | [info ] Loading page | ||
+ | [info ] Terminate requested. | ||
+ | [info ] Exiting browser | ||
+ | [info ] Browser exited | ||
+ | [info ] Response received | ||
+ | [sudo] password | ||
+ | |||
+ | Connected to 193.106.xxx.xxx: | ||
+ | SSL negotiation with vpn.scientificnet.org | ||
+ | Server certificate verify failed: signer not found | ||
+ | Connected to HTTPS on vpn.scientificnet.org | ||
+ | Got CONNECT response: HTTP/1.1 200 OK | ||
+ | CSTP connected. DPD 30, Keepalive 20 | ||
+ | Connected as 172.xx.xx.xx + 2a02: | ||
+ | Established DTLS connection (using GnuTLS). Ciphersuite (DTLS1.2)-(ECDHE-RSA)-(AES-256-GCM). | ||
+ | Error: any valid prefix is expected rather than " | ||
+ | |||
+ | </ | ||
- | 4. Start Shrew Soft VPN Client, unzip unibz profile | + | A browser-window will ask for your username |
+ | to generate with an Authenticator! | ||
+ | Last thing to enter is the sudo password to enable the network interface. | ||
/data/www/wiki.inf.unibz.it/data/pages/auth/howto/linux/vpnclient.txt · Last modified: 2022/06/20 11:40 by kohofer