OUCS VPN Service Bridget Lewis OUCS. The Problem Resources restricted by IP Address Resources restricted by IP Address Web pages e.g. OXAM, OxLIP, bibliographic.

Slides:



Advertisements
Similar presentations
1 Configuring Internet- related services (April 22, 2015) © Abdou Illia, Spring 2015.
Advertisements

11 TROUBLESHOOTING Chapter 12. Chapter 12: TROUBLESHOOTING2 OVERVIEW  Determine whether a network communications problem is related to TCP/IP.  Understand.
Module 5: Configuring Access for Remote Clients and Networks.
1 Objectives Configure Network Access Services in Windows Server 2008 RADIUS 1.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Planning Network Access.
Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 14: Troubleshooting Remote Connections.
Hands-On Microsoft Windows Server 2003 Administration Chapter 11 Administering Remote Access Services.
© 2007 Cisco Systems, Inc. All rights reserved.ISCW-Mod9_L8 1 Implementing Secure Converged Wide Area Networks (ISCW)
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Twelve Implementing Terminal.
Chapter 8: Configuring Network Connectivity. Installing Network Adapters Network adapter cards connect a computer to a network. Installation –Plug and.
Understanding Networks I. Objectives Compare client and network operating systems Learn about local area network technologies, including Ethernet, Token.
MCITP Guide to Microsoft Windows Server 2008 Server Administration (Exam #70-646) Chapter 10 Configuring Remote Access.
Computer Network (MASQ/NAT/PROXY)
Network Address Translation, Remote Access and Virtual Private Networks BSAD 146 Dave Novak Sources: Network+ Guide to Networks, Dean 2013.
Virtual Private Network (VPN) © N. Ganesan, Ph.D..
Fermilab VPN Service What is a VPN ?.
Module 11: Supporting Remote Users. Overview Establishing Remote Access Connections Connecting to Virtual Private Networks Configuring Authentication.
Guide to MCSE , Second Edition, Enhanced1 Objectives Understand remote access under Windows XP Configure various remote access connection types for.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 10: Remote Access.
© 2007 Cisco Systems, Inc. All rights reserved.ISCW-Mod3_L7 1 Network Security 2 Module 6 – Configure Remote Access VPN.
DrayTek VPN Solution. Outline What is VPN What does VPN Do Supported VPN Protocol How Many Tunnels does Vigor Support VPN Application Special VPN Application.
1 Microsoft Windows NT 4.0 Authentication Protocols Password Authentication Protocol (PAP) Challenge Handshake Authentication Protocol (CHAP) Microsoft.
Getting Connected to NGS while on the Road… Donna V. Shaw, NGS Convocation.
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
NORTEL NETWORKS CONFIDENTIAL CallPilot 150 Modem Access Jan 03, 2005 Version 1.5.
Course 201 – Administration, Content Inspection and SSL VPN
Virtual Private Networks Alberto Pace. IT/IS Technical Meeting – January 2002 What is a VPN ? u A technology that allows to send confidential data securely.
Windows Server 2008 Chapter 9 Last Update
Windows Internet Connection Sharing Dave Eitelbach Program Manager Networking And Communications Microsoft Corporation.
Guide to Operating System Security Chapter 9 Web, Remote Access, and VPN Security.
Module 7: Configuring TCP/IP Addressing and Name Resolution.
WISER: Remote access to databases and datasets This session will help you to set up access to Oxford online resources from your home computer. The key.
Chapter 7: Using Windows Servers to Share Information.
Module 8: Configuring Virtual Private Network Access for Remote Clients and Networks.
© 2007 Cisco Systems, Inc. All rights reserved.ISCW-Mod9_L8 1 Network Security 2 Module 6 – Configure Remote Access VPN.
A+ Guide to Software Managing, Maintaining and Troubleshooting THIRD EDITION Chapter 12 Windows on the Internet.
© 2009 FP Mailing Solutions. All rights reserved. Customer Service Training Basic Computer Training.
A+ Guide to Software: Managing, Maintaining, and Troubleshooting, 5e
Remote Access Chapter 4. Learning Objectives Understand implications of IEEE 802.1x and how it is used Understand VPN technology and its uses for securing.
11.59 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 19 PCs on the Internet.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
1 Chapter Overview Installing the TCP/IP Protocols Configuring TCP/IP.
1 Chapter Overview Using the New Connection Wizard to configure network and Internet connections Using the New Connection Wizard to configure outbound.
1 Chapter 12: VPN Connectivity in Remote Access Designs Designs That Include VPN Remote Access Essential VPN Remote Access Design Concepts Data Protection.
VIRTUAL PRIVATE NETWORK By: Tammy Be Khoa Kieu Stephen Tran Michael Tse.
What’s New in Fireware v11.9.5
11.59 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
Hands-On Microsoft Windows Server Introduction to Remote Access Routing and Remote Access Services (RRAS) –Enable routing and remote access through.
BZUPAGES.COM. What is a VPN VPN is an acronym for Virtual Private Network. A VPN provides an encrypted and secure connection "tunnel" path from a user's.
Page 1 TCP/IP Networking and Remote Access Lecture 9 Hassan Shuja 11/23/2004.
The University of Oklahoma Virtual Private Network How it works.
Computer Networking From LANs to WANs: Hardware, Software, and Security Chapter 13 FTP and Telnet.
WISER: Remote access to databases and datasets This session will help you to set up access to Oxford online resources from your home computer. The session.
Networking in Linux. ♦ Introduction A computer network is defined as a number of systems that are connected to each other and exchange information across.
1 Week #5 Routing and NAT Network Overview Configuring Routing Configuring Network Address Translation Troubleshooting Routing and Remote Access.
NetTech Solutions Common Connectivity Problems Lesson Eight.
17 Establishing Dial-up Connection to the Internet Using Windows 9x 1.Install and configure the modem 2.Configure Dial-Up Adapter 3.Configure Dial-Up Networking.
Chapter Eight Internetworking with Remote Access.
Windows Vista Configuration MCTS : Advanced Networking.
Virtual Private Networks
Getting Connected to NGS while on the Road…
Chapter 7: Using Windows Servers
Chapter Objectives In this chapter, you will learn:
Microsoft Windows NT 4.0 Authentication Protocols
Getting Connected to NGS while on the Road…
Cengage Learning: Computer Networking from LANs to WANs
Presentation transcript:

OUCS VPN Service Bridget Lewis OUCS

The Problem Resources restricted by IP Address Resources restricted by IP Address Web pages e.g. OXAM, OxLIP, bibliographic resources Web pages e.g. OXAM, OxLIP, bibliographic resources Resources inaccessible through firewall Resources inaccessible through firewall Full OxLIP Full OxLIP Microsoft and Samba shares Microsoft and Samba shares OU members may need to access resources from anywhere in the world OU members may need to access resources from anywhere in the world

OXAM ftp://micros.oucs/ Full OxLIP    Oxford University Network Anywhere else

The Solution PCs need to appear to be within OU Network PCs need to appear to be within OU Network Authentication mechanism Authentication mechanism Encrypted traffic across WAN Encrypted traffic across WAN Virtual Private Network (VPN) Virtual Private Network (VPN)

OXAM ftp://micros.oucs/ Full OxLIP Oxford University Network Anywhere else

What is a Virtual Private Network? Secure private communications over public internet Secure private communications over public internet Private IP packets encapsulated within public packets (tunnel) Private IP packets encapsulated within public packets (tunnel) Additional header added Additional header added Authentication Authentication Private packet may also be encrypted (desirable) Private packet may also be encrypted (desirable)

Variations VPN connection types VPN connection types Client to Server, Server to Server Client to Server, Server to Server Types of VPN Types of VPN Hardware, software, firewall Hardware, software, firewall Protocols Protocols PPTP, L2F, L2TP, IPSec PPTP, L2F, L2TP, IPSec

How does VPN solve our Problem? VPN connection uses ESP protocol VPN connection uses ESP protocol Allowed through firewall Allowed through firewall TCP/IP traffic tunnelled within VPN connection TCP/IP traffic tunnelled within VPN connection Client part of virtual network Client part of virtual network Allocated Oxford IP address ( xyz) Allocated Oxford IP address ( xyz)

VPN in Oxford CISCO 3000 Series VPN Concentrator CISCO 3000 Series VPN Concentrator Software client for various platforms Software client for various platforms Client to Server only Client to Server only IPSec IPSec IP only (not NetBEUI, IPX etc.) IP only (not NetBEUI, IPX etc.) Split tunnelling disabled Split tunnelling disabled NAT enabled NAT enabled

Requirements Existing Internet connection Existing Internet connection Modem, LAN, cable, ADSL, ISDN etc. Modem, LAN, cable, ADSL, ISDN etc. Cisco client software Cisco client software Windows, Mac OS X, some Linux Windows, Mac OS X, some Linux Or third party client Or third party client Mac OS 8, 9 Mac OS 8, 9 OUCS Remote Access username and passwords OUCS Remote Access username and passwords

Cisco Clients Windows 95, 98, Me, NT, 2000, XP Windows 95, 98, Me, NT, 2000, XP 95 requires Dial-up Networking upgrade 95 requires Dial-up Networking upgrade Cannot use Windows 2000/XP native VPN support Cannot use Windows 2000/XP native VPN support Mac OS X Mac OS X v or later v or later

Cisco Clients RedHat 6.2 or compatible RedHat 6.2 or compatible Kernel or later (not 2.5) Kernel or later (not 2.5) Currently being tested and documented Currently being tested and documented Problems on 7.3 (7.2 OK) Problems on 7.3 (7.2 OK) Solaris UltraSPARC running 32-bit kernel OS v2.6 or later Solaris UltraSPARC running 32-bit kernel OS v2.6 or later Untested Untested

Non-Cisco Clients Mac OS 8.6 to OS 9.2.x Mac OS 8.6 to OS 9.2.x Netlock VPN Client for Cisco Netlock VPN Client for Cisco Evaluation copy available Evaluation copy available Let us know results if you try it! Let us know results if you try it! Around £80 Around £80 Untested by OUCS Untested by OUCS

Installation — General Instructions available — s-service/ Instructions available — s-service/ s-service/ s-service/ Windows version is mostly preconfigured Windows version is mostly preconfigured Mac OS X client available Mac OS X client available Linux client not yet available Linux client not yet available

Installation — 2000/XP When installing, will get warning about disabling IPSec policies When installing, will get warning about disabling IPSec policies Default IPSec policies not restrictive Default IPSec policies not restrictive Only likely to be a problem if you have enabled more rigorous IPSec policies Only likely to be a problem if you have enabled more rigorous IPSec policies

Installation —XP May want to turn off driver signing before installation May want to turn off driver signing before installation Installation process will warn you about this Installation process will warn you about this Otherwise be prepared to click on Continue several times Otherwise be prepared to click on Continue several times Upgrading to XP with Cisco client installed Upgrading to XP with Cisco client installed May warn about incompatibility May warn about incompatibility It is compatible, but may be best to uninstall prior to upgrade It is compatible, but may be best to uninstall prior to upgrade

Installation — Mac OS X Not a GUI install! Not a GUI install! Command line familiarity Command line familiarity Knowledge of paths Knowledge of paths Edit text file Edit text file Enable root account prior to installation Enable root account prior to installation Install from command line Install from command line Contrary to documentation, v3.5.1 of client allows Classic apps to use the tunnel Contrary to documentation, v3.5.1 of client allows Classic apps to use the tunnel

Configuring — Windows Need to enter initial connection password (once only) Need to enter initial connection password (once only) Options/Properties/Authentication Options/Properties/Authentication Optional configuration Optional configuration Options/Properties/Connection Options/Properties/Connection Automatically connect via dial-up or… Automatically connect via dial-up or… Automatically connect via application Automatically connect via application Stateful firewall — release Stateful firewall — release

Configuring — NT/2000/XP Full domain login possible Full domain login possible Requires VPN start before login Requires VPN start before login Options/Windows Logon Properties Options/Windows Logon Properties Probably necessary also to set to automatically establish dialup connection Probably necessary also to set to automatically establish dialup connection

Configuring — Mac OS X Not preconfigured Not preconfigured Create profile from sample Create profile from sample Text editor Text editor Full documentation from Cisco Full documentation from Cisco

Connecting – General Test from computer on OU network Test from computer on OU network Except OUCS in-house network Except OUCS in-house network IP address assigned is xyz IP address assigned is xyz May not be easy to see as will also have IP address assigned by ISP etc. May not be easy to see as will also have IP address assigned by ISP etc. DNS server addresses passed across DNS server addresses passed across

Connecting – Windows WINS addresses also assigned WINS addresses also assigned Check DNS and WINS addresses using winipcfg or ipconfig /all Check DNS and WINS addresses using winipcfg or ipconfig /all VPN icon displayed in system tray VPN icon displayed in system tray Status including IP address assigned Status including IP address assigned Statistics Statistics Disconnect Disconnect

Connecting – Mac OS X Started from command line Started from command line Or use VPNConnect utility Or use VPNConnect utility Allows start from GUI Allows start from GUI Also available from micros.oucs.ox.ac.uk ftp server Also available from micros.oucs.ox.ac.uk ftp server

Limitations Split tunnelling disabled Split tunnelling disabled No access to local LAN resources when VPN connection is active No access to local LAN resources when VPN connection is active Security concern Security concern Client behaves as if within Oxford network Client behaves as if within Oxford network Client unable to access local resources e.g. servers, networked printers Client unable to access local resources e.g. servers, networked printers

Limitations Full version of OxLIP may be too slow to use over VPN over dialup Full version of OxLIP may be too slow to use over VPN over dialup Starting full OxLIP downloads about 1.8MB data (e.g. 10 minutes over dialup) Starting full OxLIP downloads about 1.8MB data (e.g. 10 minutes over dialup) May be similar problems accessing e.g. files on Microsoft shares May be similar problems accessing e.g. files on Microsoft shares If full OxLIP is essential, broadband may be the answer If full OxLIP is essential, broadband may be the answer

Caveats Worth reading release notes Worth reading release notes E.g systems may need to install Client for MS networks E.g systems may need to install Client for MS networks Windows 98 shutdown problem Windows 98 shutdown problem Non-DHCP 95/98 may not get WINS addresses Non-DHCP 95/98 may not get WINS addresses No network browsing with AOL 6.0 No network browsing with AOL 6.0 MSN install fails with VPN installed MSN install fails with VPN installed

Password Confusion 1 Usernames/passwords to use the service Usernames/passwords to use the service Remote Access Services account details Remote Access Services account details VPN Initial connection password VPN Initial connection password Provided when user registers to use Remote Access Services Provided when user registers to use Remote Access Services OUCS Registration/Web registration OUCS Registration/Web registration NB If registered to use dial-up pre-November 2001, contact OUCS Registration for VPN initial connection password NB If registered to use dial-up pre-November 2001, contact OUCS Registration for VPN initial connection password

Password Confusion 2 Username/password to obtain the client software Username/password to obtain the client software micros.oucs FTP Server username and password for client download micros.oucs FTP Server username and password for client download OUCS Shop OUCS Shop NB only accessible from OU network (including dialup) — special cases contact Helpcentre NB only accessible from OU network (including dialup) — special cases contact Helpcentre

Personal Firewalls Must allow ISAKMP (UDP 500) Must allow ISAKMP (UDP 500) Initial exchange Initial exchange Must allow ESP protocol (number 50) Must allow ESP protocol (number 50) Subsequent IPSEC traffic Subsequent IPSEC traffic VPN connection OK, but no internet response, suspect ESP not allowed VPN connection OK, but no internet response, suspect ESP not allowed XP firewall appears OK without change XP firewall appears OK without change

Firewalls Departmental/College firewalls Departmental/College firewalls VPN connection made outside departmental/college firewall VPN connection made outside departmental/college firewall Access to departmental/college resources dependent on firewall configuration Access to departmental/college resources dependent on firewall configuration External organisations External organisations May cause problems for individuals connecting from e.g. another university May cause problems for individuals connecting from e.g. another university

Web Proxy Servers Configured by some ISPs Configured by some ISPs Freeserve Freeserve Symptom: with VPN connection, can telnet, ftp but not access web with IE Symptom: with VPN connection, can telnet, ftp but not access web with IE Reason: trying to use ISP web proxy server but access denied Reason: trying to use ISP web proxy server but access denied Solution: configure exceptions to proxy for restricted web pages Solution: configure exceptions to proxy for restricted web pages

Miscellaneous OUCS Dial-up users don’t generally require VPN! OUCS Dial-up users don’t generally require VPN! Watch SMTP settings Watch SMTP settings ISP require own SMTP server ISP require own SMTP server With VPN must use smtp.ox.ac.uk With VPN must use smtp.ox.ac.uk Generally connection will be slower over VPN Generally connection will be slower over VPN Only use as required Only use as required

MTU Size MTU = Maximum Transmission Unit MTU = Maximum Transmission Unit Setting determines largest packet size Setting determines largest packet size Some devices fragment large packets Some devices fragment large packets Some firewalls reject fragments Some firewalls reject fragments Slows performance Slows performance Set MTU utility to change defaults Set MTU utility to change defaults Set to 1400 or less, 576 default for dial- up adapters Set to 1400 or less, 576 default for dial- up adapters Hasn’t yet solved any problems Hasn’t yet solved any problems

Service Usage Figures by Month

References Cisco Documentation Cisco Documentation uct/vpn/client/ uct/vpn/client/ uct/vpn/client/ uct/vpn/client/ VPNConnect utility for Mac VPNConnect utility for Mac Netlock Cisco VPN Client for Mac Netlock Cisco VPN Client for Mac

References Comparison of VPN Protocols: IPSec, PPTP and L2TP Comparison of VPN Protocols: IPSec, PPTP and L2TP 01/arveal.pdf 01/arveal.pdf 01/arveal.pdf 01/arveal.pdf VPN FAQ VPN FAQ html html html html

Questions?