VPN
What's
a VPN and why do I need it?
A VPN is a Virtual Private Network. There is a firewall
between the ISP systems and the rest of the world. It
serves as a "gatekeeper" for accessing Integrated System. Users
must log into the firewall to gain access to the Integrated System
logon screen.
http://itc.virginia.edu/network/vpn/
Why
must each user download a copy of the software?
The VPN client's encryption methods are considered
munitions and the software is not exportable out
of the United
States. To ensure compliance to the terms, the download
site requires each user to "Agree" to the conditions
prior to download. A similar situation exists for
SecureCRT and SecureFX.
Where
can I get the required VPN software?
Download the Installer (Cisco Systems VPN Client) from Software Central. If you have problems, contact the ITC Help Desk at 924-3731.
Where
do I get an ID/password?
Information on creating a VPN account may be found at
https://vpn-acct.admin.virginia.edu/cgi-bin/sign-up
BACK TO TOP
When
should I be logged in to the VPN?
The VPN must be connected prior to accessing Integrated System.
VPN is NOT required for self-service applications. Users should terminate Integrated System Applications and VPN connections
prior to departing the office. The VPN client will automatically
terminate after 8 hours of nonuse.
How
does this affect my connectivity to other systems?
Your Internet access should be unaffected. The Cisco
VPN client may conflict with other VPN
clients such that only one at a time may be allowable.
I
get a network error when accessing Integrated System, but other
network applications seem OK.
Users MUST be connected to the VPN at all times to access
Integrated System Applications. If the VPN is not connected prior
to accessing Integrated System or is disconnected prior to exiting
Integrated System, it will appear to hang and indicate a network
error. It will not indicate a VPN error.
I
installed VPN client but get error "The IPSECDLR.EXE
file is linked to missing export MAPI32.DLL:19" when
trying to start the VPN.
VPN client requires MAPI32.DLL, which comes with Microsoft
mailers and Internet Explorer. Simeon and Eudora overwrite
the DLL with one that is not VPN compatible. Solution:
execute FIXMAPI.EXE & retry VPN.
XP: C:\WINDOWS\system32\fixmapi.exe
NT: C:\winnt\system\fixmapi.exe
95/98: C:\windows\system\fixmapi.exe
When executed, nothing appears to happen. It simply
replaces the DLL.
What to do about VPN error 412?
Generally, its a certificate issue using JointVPN and iKey, its probably not reading the certificate from the iKey. Close VPN; insert the iKey; wait a few seconds; start VPN; Select (highlight) the "JointVPN" profile; click the "Modify" button at the top of the window. On the "Authentication" tab (which is viewable by default), verify that "Certificate Authentication" is selected and that the correct certificate is displayed in the Name box. The ikey certificate will be the one which does NOT have a number at the end of User's name (i.e. it should say "UserName (Microsoft)" and not "UserName # (Microsoft)" where the # is some numerical number.
- NOTE: Regardless of whether the correct certificate is already selected, please click "Save" at the bottom of the screen to make sure this information is stored properly in the JointVPN profile. It has been seen in a few cases where opening this window and clicking "Save" caused things to start working properly again.
Additional VPN and iKey troubleshooting information can be found on
ITC User Support Services Twiki
What to do about VPN error 433?
The iKey account has been deactivated. Contact the ITC Help Desk for assistance.
VPN sessions are timing out and other VPN issues are addressed on
ITC Network Security Information FAQ.
|