VPN unter Windows/en: Unterschied zwischen den Versionen

ZIM HilfeWiki - das Wiki
 
(7 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 7: Zeile 7:
 
<br clear=all>
 
<br clear=all>
  
==== You need VPN, if you ====
+
==== You need VPN if you ====
 
* want to access licensed databases of the University Library,
 
* want to access licensed databases of the University Library,
 
* want to access a [[Netzlaufwerk_einbinden_(Windows_10)|Network drive/ group storage]]
 
* want to access a [[Netzlaufwerk_einbinden_(Windows_10)|Network drive/ group storage]]
Zeile 16: Zeile 16:
 
<br clear=all>
 
<br clear=all>
  
==== You do not need VPN, if you ====
+
==== You do <span style="color:red">not</span> need VPN if you ====
 
* want to read your e-mails on webmail,
 
* want to read your e-mails on webmail,
 
* want to send e-mails via the ZIM mail server (see [[Mail]]).
 
* want to send e-mails via the ZIM mail server (see [[Mail]]).
 +
* want to use BigBlueButton or other services for conferences.
 
<br clear=all>
 
<br clear=all>
  
Zeile 48: Zeile 49:
 
<br clear=all>
 
<br clear=all>
  
[[Datei:Eduroam-under-android-4.png|links|mini|ohne|350px]]
+
[[Datei:Eduroam-unter-android-4.png|links|mini|ohne|350px]]
 
<br>
 
<br>
* Click ''''Neues Zertifikat erstellen'''.
+
* Click '''Neues Zertifikat erstellen'''.
 
<br clear=all>
 
<br clear=all>
  
Zeile 65: Zeile 66:
 
* A new network certificate has been created for you.
 
* A new network certificate has been created for you.
 
* First copy the '''Import Password''' to the clipboard.
 
* First copy the '''Import Password''' to the clipboard.
* Now click on ''''Download Network Certificate'''.
+
* Now click on '''Download Network Certificate'''.
 
<br clear=all>
 
<br clear=all>
 +
 +
After saving it on the computer, the network certificate must be installed under the account that is to be used with Eduroam. Open the certificate with a double click. The certificate import wizard then starts automatically.
 +
 +
[[Datei:Eduroam-windows11-01.png|links|mini|ohne|450px]]
 +
<br>
 +
* Click on '''Continue'''.
 +
<br clear=all>
 +
 +
[[Datei:Eduroam-windows11-02.png|links|mini|ohne|450px]]
 +
<br>
 +
* Paste the import password that we just copied.
 +
* Leave the default settings intact.
 +
* <span style="color:orange">'''Note:''' It is not allowed to tick "Activate high security for the private key". The Windows WLAN client currently does not support this function and therefore no connection to eduroam would be possible.</span>
 +
* Then click '''Next'''
 +
<br>
 +
* In the following window, if necessary, click on '''Next''' and finally on '''Finish'''.
 +
<br clear=all>
 +
 +
[[Datei:Eduroam-windows11-03.png|links|mini|ohne|450px]]
 +
<br>
 +
* If a security warning appears, click Yes.
 +
<br clear=all>
 +
 +
[[Datei:Eduroam-windows11-04.png|links|mini|ohne|450px]]
 +
<br>
 +
* Now click on '''"OK"'''.
 +
<br clear=all>
 +
 +
<span style="color:red">'''Note:''' Now open the same certificate again and install it a second time. This allows us to work around an error in the Windows certificate manager. Do not create a new certificate for this! </span>
 +
</bootstrap_panel>
 +
</bootstrap_accordion>
 +
 +
<br clear=all>
 +
 +
<span style="color:green"> Note:</span> Only one network certificate from the University of Paderborn may be installed. Multiple certificates can cause problems. More about this [https://hilfe.uni-paderborn.de/VPN_unter_Windows_10#Zertifikate here.]
 +
 +
===Download OpenVPN===
 +
Now download the OpenVPN program from the manufacturer's website. <br>
 +
https://openvpn.net/community-downloads/
 +
: '''ATTENTION''': DO NOT install the BETA version!
 +
 +
[[File:Vpn-win-10-1.png|550px|mini|without|Download the program here. Not via '''Get OpenVPN!''']]
 +
<br clear=all>
 +
 +
=== Install OpenVPN ===
 +
Now let's install the program.
 +
 +
<div class="tleft" style="clear:none">[[Datei:OpenVPN-25 Win10 Install-1.png|600px|mini|ohne|'''Step 1:''' Click on "Install Now ".]]</div>
 +
<div class="tleft" style="clear:none">[[Datei:OpenVPN-25 Win10 Install-2.png|600px|mini|ohne|'''Step 2:''' A security warning appears first User Account Control. Click "Yes".]]</div>
 +
<div class="tleft" style="clear:none">[[Datei:OpenVPN-25 Win10 Install-3.png|600px|mini|ohne|'''Step 3:''' The installation is complete. Click "Close".]]</div>
 +
 +
<br clear=all>
 +
 +
After successful installation, the new “OpenVPN GUI” icon will appear on the desktop.
 +
 +
[[Datei:OpenVPN-25 Win10 Install-4.png|0px]] '''Step 8:''' The OpenVPN client is started using this symbol.
 +
 +
<br clear=all>
 +
 +
=== Download configuration file ===
 +
 +
Download the configuration file, select the VPN you want to connect to in the box below and click on Download.
 +
Normally "Uni-VPN (Standard)" should be the right choice, but if you have problems with the connection, try "Uni-VPN-TCP" instead.
 +
<br clear=all>
 +
<span style="color:green"> Note:</span> You can click '''"Download"''' here and download your configuration file. This is not a screenshot ;-)
 +
<center><iframe key="infoboard" width="600" height="330" path="vpn-config/index.php?group=uni&os=win&redirect_gateway=1" /></center>
 +
<br clear=all>
 +
 +
<bootstrap_accordion>
 +
<bootstrap_panel heading="Direct all internet traffic through the tunnel?">
 +
*Accessing online resources may require that you route all network traffic through the tunnel.
 +
* You do not need this option to simply access the network drives.
 +
</bootstrap_panel>
 +
</bootstrap_accordion>
 +
 +
=== Start OpenVPN ===
 +
If OpenVPN is not already started (see tray icon), start it using the "OpenVPN GUI" icon on your desktop.
 +
 +
[[Datei:OpenVPN-25 Win10 Install-4.png|links|200px|mini|ohne]]
 +
<br>
 +
* The OpenVPN client is started via this symbol.
 +
<br clear=all>
 +
 +
[[Datei:OpenVPN-25 Win10 Install-5.png|links|400px|mini|ohne]]
 +
<br>
 +
* An icon with a small lock will now appear at the bottom of the taskbar.
 +
* Do not confuse it with the Windows network icon.
 +
<br clear=all>
 +
 +
===Load configuration===
 +
Open the configuration file with a double click. Alternatively, you can also do the following:
 +
 +
[[Datei:OpenVPN-Win10-1.png|links|mini|ohne|350px]]
 +
<br>
 +
* Right-click on the OpenVPN icon at the bottom right of the task bar.
 +
* Then click '''Import File'''.
 +
<br clear=all>
 +
 +
[[Datei:VPN-unter-Windows-01.png|links|mini|ohne|350px|select config]]
 +
<br>
 +
* Now open the file '''"OpenVPN-UPB-NG_*.ovpn"''' - We have just downloaded it.
 +
<br clear=all>
 +
 +
=== Establish connection===
 +
Now we set up a VPN connection. <br>
 +
<div class="tleft" style="clear:none">[[Datei:OpenVPN Windows10 12.png|x265px|mini|ohne|'''Step 3:''' Please right-click on the icon and then click "'''Connect"/"Connect"''" to establish a connection to the VPN server.]]</div>
 +
<div class="tleft" style="clear:none">[[Datei:OpenVPN Windows10 13.png|x265px|mini|ohne|'''Step 4:''' When you run the program for the first time, the Windows Firewall is required If necessary, the consent to trust OpenVPN in the future. Please click on "'''Allow access'''".]]</div>
 +
 +
<br clear=all>
 +
 +
<div class="tleft" style="clear:none">[[Datei:OpenVPN Windows10 verbunden.png|400px|mini|without|'''Step 5:''' Finally, your computer will be assigned an IP address and the icon turns green.]]</div>
 +
<br clear=all>
 +
 +
You can see the status of the VPN by the color of the symbol:
 +
{| class="wikitable"
 +
|-
 +
|  [[Datei:VPN-Win10-4.png]] || No VPN connection active
 +
|-
 +
| [[Datei:VPN-Win10-5.png]] || VPN connection is being established
 +
|-
 +
| [[Datei:VPN-Win10-3.png]] || VPN connection active
 +
|}
 +
 +
As soon as a green status is displayed, you are connected to the internal university network.
 +
 +
 +
===Disconnect===
 +
Disconnect the VPN connection when you no longer need it.
 +
 +
[[Datei:VPN-unter-Windows-02.png|links|mini|ohne|350px|Disconnect VPN]]
 +
<br>
 +
* Click on the OpenVPN icon.
 +
* Click '''Disconnect'''.
 +
<br clear=all>
 +
 +
==Check VPN==
 +
You can check the functionality of the VPN by visiting:
 +
: [https://go.upb.de/ip https://go.upb.de/ip]
 +
Your IP will be displayed there and it will show whether you are in the university network.
 +
 +
[[Datei:OpenVPN verbunden - go_ip.png|mitte|400px|mini|ohne|Example: Existing connection to the university network.]]
 +
<br clear=all>
 +
 +
==Troubleshooting==
 +
===Red status messages===
 +
There are some red status messages when connecting, but these are completely normal and do not represent a real problem. See:<br>[[VPN_-_Erklaerung_zu_Meldungen_(Log)|VPN Declaration of Messages (Log)]]
 +
 +
===Error messages===
 +
<bootstrap_accordion>
 +
<bootstrap_panel heading="Cannot load certificate" color="info">
 +
Error message:
 +
<pre> Cannot load certificate "SUBJ:@uni-paderborn.de" from Microsoft Certificate Store </pre>
 +
This can have two reasons:
 +
* You do not have a certificate installed
 +
** Install a network certificate (see above)
 +
* You have installed too many network certificates
 +
**Press '''"Win"''' + '''"R"''' to bring up the '''"Run"''' dialog.
 +
**Type the following:
 +
<pre>certmgr.msc </pre>
 +
** Then click '''OK'''.
 +
** Go to the '''My Certificates''' folder and then '''Certificates''' folder.
 +
** There should only be one certificate with the identifier '''"username@uni-paderborn.de"''' in this folder.
 +
** Further certificates with the identifier '''"username@uni-paderborn.de"''' should be deleted.
 +
** If there are several, you can identify the active one by the serial number.
 +
** Double click on the certificate, details, serial number.
 +
** You can find the active certificates with the corresponding serial number in the service portal.
 +
</bootstrap_panel>
 +
<bootstrap_panel heading="Private Key in legacy Store" color="info">
 +
On some systems, the personal user certificate must be installed twice. If you find the following error message in the log:
 +
<br>
 +
<pre>"WARNING: cryptoapicert: private key is in a legacy store. Restricting TLS version to 1.1"</pre>
 +
<br>
 +
Install your personal network certificate a second time. The error message should then disappear.
 +
</bootstrap_panel>
 +
<bootstrap_panel heading="Group VPN ports are blocked - '''TLS Handshake failed''' after a timeout (60 sec)" color="info">
 +
Group VPN connections are established over specific UDP ports. Normally these port sharings are problem-free because they do not overlap with other protocols. However, if your Internet access is of a restrictive nature and only allows certain ports, a connection problem may arise. This affects some university institutions or company networks. Home networks generally do not have this.
 +
 +
'''Solution:'''
 +
* change your location or network
 +
* Release the required port or talk to the IT department whether this is possible
 +
*: You can find the port used for your group network within the config file.
 +
* If it is the '''hpc-pc2''' network, contact the PC2 for alternative SSH access
 +
</bootstrap_panel>
 +
 +
</bootstrap_accordion>
 +
 +
===Configuration file===
 +
<bootstrap_accordion>
 +
<bootstrap_panel heading="Add configuration file manually" color="info">
 +
As an alternative to the '''"Import file"''' function, you can also import the configuration file '''"OpenVPN-UPB-NG_*.ovpn"''' directly into the folder
 +
<pre>C:/Users/<username>/OpenVPN/config/</pre>
 +
place. <br>
 +
You can also delete old configuration files there. <br>
 +
This directory may only be created when OpenVPN is started for the first time.<br>
 +
Files in this folder are only available to the current user account.
 +
<br>
 +
<span style="color:green"> Note:</span> Drive '''C:''' represents the drive with the Windows installation.
 +
<br>
 +
 +
Alternatively, configuration files can also be stored in the program folder
 +
<pre>C:\Program Files\OpenVPN\config</pre>
 +
Here they are available to all users of the computer.
 +
</bootstrap_panel>
 +
</bootstrap_accordion>
 +
 +
==See also==
 +
* [[Netzwerk]]
 +
* [[VPN Problembehandlung]]

Aktuelle Version vom 6. Juli 2024, 23:25 Uhr

Die deutsche Version finden Sie auf der Seite VPN unter Windows

VPN (Virtual Private Network) is needed if you want to use services from outside the University of Paderborn that are only accessible within the university network. VPN guarantees secure access to the University network through other networks (dial-in via other providers, external company or university networks).

You need VPN if you[Bearbeiten | Quelltext bearbeiten]

  • want to access licensed databases of the University Library,
  • want to access a Network drive/ group storage
  • use the green sockets within the university (these are only available via VPN for security reasons)
  • use a license server of the university,
  • want to access secured pages of the university,
  • would like to work with the CMS TYPO3 from home.


You do not need VPN if you[Bearbeiten | Quelltext bearbeiten]

  • want to read your e-mails on webmail,
  • want to send e-mails via the ZIM mail server (see Mail).
  • want to use BigBlueButton or other services for conferences.


What needs to be done?[Bearbeiten | Quelltext bearbeiten]

  • Install personal network certificate
  • Install OpenVPN.
  • Start OpenVPN
  • Download configuration file:

Note: You can click on "Download" here and download your configuration file. This is not a screenshot ;-)

  • Import configuration file
  • Establish a VPN connection

Step-by-step instructions[Bearbeiten | Quelltext bearbeiten]

Install network certificate[Bearbeiten | Quelltext bearbeiten]

In order to use OpenVPN, a personal network certificate must be installed on your PC.

Are you already using the Eduroam WiFi network on this PC?

  • Then you already have a personal network certificate. Skip this step.


Are you not using the Eduroam WiFi network on this PC yet?

Access using a browser, e.g. Firefox or Edge, go to the service portal and log in with your user name and password from your university account.

  • Go to Benutzerverwaltung and then Netzwerkeinstellungen.


Eduroam-unter-android-4.png


  • Click Neues Zertifikat erstellen.


Netzwerkzertifikat-container-v2.png


  • Give the certificate a unique name (e.g.: cell phone)
  • For Windows 11, select Version 2 as the file format.
  • For older versions such as Windows 10 please use version 1.
  • Then click on Neues Zertifikat zusenden.


Netzwerkzertifikat-download.png


  • A new network certificate has been created for you.
  • First copy the Import Password to the clipboard.
  • Now click on Download Network Certificate.


After saving it on the computer, the network certificate must be installed under the account that is to be used with Eduroam. Open the certificate with a double click. The certificate import wizard then starts automatically.

Eduroam-windows11-01.png


  • Click on Continue.


Eduroam-windows11-02.png


  • Paste the import password that we just copied.
  • Leave the default settings intact.
  • Note: It is not allowed to tick "Activate high security for the private key". The Windows WLAN client currently does not support this function and therefore no connection to eduroam would be possible.
  • Then click Next


  • In the following window, if necessary, click on Next and finally on Finish.


Eduroam-windows11-03.png


  • If a security warning appears, click Yes.


Eduroam-windows11-04.png


  • Now click on "OK".


Note: Now open the same certificate again and install it a second time. This allows us to work around an error in the Windows certificate manager. Do not create a new certificate for this!


Note: Only one network certificate from the University of Paderborn may be installed. Multiple certificates can cause problems. More about this here.

Download OpenVPN[Bearbeiten | Quelltext bearbeiten]

Now download the OpenVPN program from the manufacturer's website.
https://openvpn.net/community-downloads/

ATTENTION: DO NOT install the BETA version!
Download the program here. Not via Get OpenVPN!


Install OpenVPN[Bearbeiten | Quelltext bearbeiten]

Now let's install the program.

Step 1: Click on "Install Now ".
Step 2: A security warning appears first User Account Control. Click "Yes".
Step 3: The installation is complete. Click "Close".


After successful installation, the new “OpenVPN GUI” icon will appear on the desktop.

0px Step 8: The OpenVPN client is started using this symbol.


Download configuration file[Bearbeiten | Quelltext bearbeiten]

Download the configuration file, select the VPN you want to connect to in the box below and click on Download. Normally "Uni-VPN (Standard)" should be the right choice, but if you have problems with the connection, try "Uni-VPN-TCP" instead.
Note: You can click "Download" here and download your configuration file. This is not a screenshot ;-)


  • Accessing online resources may require that you route all network traffic through the tunnel.
  • You do not need this option to simply access the network drives.

Start OpenVPN[Bearbeiten | Quelltext bearbeiten]

If OpenVPN is not already started (see tray icon), start it using the "OpenVPN GUI" icon on your desktop.

OpenVPN-25 Win10 Install-4.png


  • The OpenVPN client is started via this symbol.


OpenVPN-25 Win10 Install-5.png


  • An icon with a small lock will now appear at the bottom of the taskbar.
  • Do not confuse it with the Windows network icon.


Load configuration[Bearbeiten | Quelltext bearbeiten]

Open the configuration file with a double click. Alternatively, you can also do the following:

OpenVPN-Win10-1.png


  • Right-click on the OpenVPN icon at the bottom right of the task bar.
  • Then click Import File.


select config


  • Now open the file "OpenVPN-UPB-NG_*.ovpn" - We have just downloaded it.


Establish connection[Bearbeiten | Quelltext bearbeiten]

Now we set up a VPN connection.

Step 3: Please right-click on the icon and then click "'Connect"/"Connect"" to establish a connection to the VPN server.
Step 4: When you run the program for the first time, the Windows Firewall is required If necessary, the consent to trust OpenVPN in the future. Please click on "Allow access".


Step 5: Finally, your computer will be assigned an IP address and the icon turns green.


You can see the status of the VPN by the color of the symbol:

VPN-Win10-4.png No VPN connection active
VPN-Win10-5.png VPN connection is being established
VPN-Win10-3.png VPN connection active

As soon as a green status is displayed, you are connected to the internal university network.


Disconnect[Bearbeiten | Quelltext bearbeiten]

Disconnect the VPN connection when you no longer need it.

Disconnect VPN


  • Click on the OpenVPN icon.
  • Click Disconnect.


Check VPN[Bearbeiten | Quelltext bearbeiten]

You can check the functionality of the VPN by visiting:

https://go.upb.de/ip

Your IP will be displayed there and it will show whether you are in the university network.

Example: Existing connection to the university network.


Troubleshooting[Bearbeiten | Quelltext bearbeiten]

Red status messages[Bearbeiten | Quelltext bearbeiten]

There are some red status messages when connecting, but these are completely normal and do not represent a real problem. See:
VPN Declaration of Messages (Log)

Error messages[Bearbeiten | Quelltext bearbeiten]

Error message:

 Cannot load certificate "SUBJ:@uni-paderborn.de" from Microsoft Certificate Store 

This can have two reasons:

  • You do not have a certificate installed
    • Install a network certificate (see above)
  • You have installed too many network certificates
    • Press "Win" + "R" to bring up the "Run" dialog.
    • Type the following:
certmgr.msc 
    • Then click OK.
    • Go to the My Certificates folder and then Certificates folder.
    • There should only be one certificate with the identifier "username@uni-paderborn.de" in this folder.
    • Further certificates with the identifier "username@uni-paderborn.de" should be deleted.
    • If there are several, you can identify the active one by the serial number.
    • Double click on the certificate, details, serial number.
    • You can find the active certificates with the corresponding serial number in the service portal.

On some systems, the personal user certificate must be installed twice. If you find the following error message in the log:

"WARNING: cryptoapicert: private key is in a legacy store. Restricting TLS version to 1.1"


Install your personal network certificate a second time. The error message should then disappear.

Group VPN connections are established over specific UDP ports. Normally these port sharings are problem-free because they do not overlap with other protocols. However, if your Internet access is of a restrictive nature and only allows certain ports, a connection problem may arise. This affects some university institutions or company networks. Home networks generally do not have this.

Solution:

  • change your location or network
  • Release the required port or talk to the IT department whether this is possible
    You can find the port used for your group network within the config file.
  • If it is the hpc-pc2 network, contact the PC2 for alternative SSH access


Configuration file[Bearbeiten | Quelltext bearbeiten]

As an alternative to the "Import file" function, you can also import the configuration file "OpenVPN-UPB-NG_*.ovpn" directly into the folder

C:/Users/<username>/OpenVPN/config/

place.
You can also delete old configuration files there.
This directory may only be created when OpenVPN is started for the first time.
Files in this folder are only available to the current user account.
Note: Drive C: represents the drive with the Windows installation.

Alternatively, configuration files can also be stored in the program folder

C:\Program Files\OpenVPN\config

Here they are available to all users of the computer.

See also[Bearbeiten | Quelltext bearbeiten]


Bei Fragen oder Problemen wenden Sie sich bitte telefonisch oder per E-Mail an uns:

Tel. IT: +49 (5251) 60-5544 Tel. Medien: +49 (5251) 60-2821 E-Mail: zim@uni-paderborn.de

Das Notebook-Café ist die Benutzerberatung des ZIM - Sie finden uns in Raum I0.401

Wir sind zu folgenden Zeiten erreichbar:


Mo-Do Fr
Vor-Ort-Support 08:30 - 16:00 08:30 - 14:00
Telefonsupport 08:30 - 16:00 08:30 - 14:00


Das ZIM:Servicecenter Medien auf H1 hat aktuell zu folgenden Zeiten geöffnet:

Mo-Do Fr
08:00 - 16:00 08:00 - 14:30
Cookies helfen uns bei der Bereitstellung des ZIM HilfeWikis. Bei der Nutzung vom ZIM HilfeWiki werden die in der Datenschutzerklärung beschriebenen Cookies gespeichert.