# VPN

The University of Windsor uses a firewall. Many protocols or ports are blocked by the firewall, so you may need to establish a connection through the campus Virtual Private Network (VPN) to access resources and data on the campus private network.

#### What does the VPN connection do?

The VPN connection *tunnels* network traffic over a securely encrypted connection. Once connected to the VPN portal, your device will receive a new IP address and IP route provided by the university and recognized internally by the campus firewall.

<p class="callout info">[Why do I need to use the Campus VPN?](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/Requests/ServiceDet?ID=10002)</p>

#### ITS Documents related to the Campus VPN

<table border="1" id="bkmrk-installing-globalpro" style="border-collapse: collapse; width: 100%;"><colgroup><col style="width: 11.5663%;"></col><col style="width: 88.4337%;"></col></colgroup><tbody><tr><td class="align-center">[![windows (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/HMBwindows-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/HMBwindows-custom.png)</td><td>[Installing GlobalProtect VPN client on a Windows computer](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/KB/ArticleDet?ID=44347)</td></tr><tr><td class="align-center">[![macOS (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/macos-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/macos-custom.png)</td><td>[Installing GlobalProtect VPN client on macOS](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/KB/ArticleDet?ID=44348)</td></tr><tr><td class="align-center">[![android (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/650android-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/650android-custom.png)</td><td>[Installing GlobalProtect VPN client on mobile devices (Apple, Android)](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/KB/ArticleDet?ID=112514)</td></tr><tr><td class="align-center">[![linux (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/linux-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/linux-custom.png)</td><td>[Installing GlobalProtect VPN client on Linux Devices](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/KB/ArticleDet?ID=120611)</td></tr></tbody></table>

#### Download

##### Windows and macOS

Authenticate with your UWinID and password on the university's GlobalProtect Portal to get to the GlobalProtect Client download links.

<table id="bkmrk-download-for-windows"><tbody><tr><td colspan="2"><table class="plainlinks imbox imbox-style" role="presentation"><tbody><tr><td class="mbox-image">[![windows (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/HMBwindows-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/HMBwindows-custom.png)[![macOS (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/macos-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/macos-custom.png)</td><td class="mbox-text">[Download for Windows and macOS](https://securelogin.uwindsor.ca)</td></tr></tbody></table>

</td></tr><tr><td colspan="2"><table class="plainlinks metadata ambox ambox-notice" role="presentation"><tbody><tr><td class="mbox-image"><div style="width: 52px;">![Information_icon4.svg.png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-11/information-icon4-svg.png)</div></td><td class="mbox-text"><div class="mbox-text-span">GlobalProtect may seem to install properly in macOS, but sometimes will not work if it failed to allow access to the installed system extension. See [Installing GlobalProtect VPN client on macOS](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/KB/ArticleDet?ID=44348).</div></td></tr></tbody></table>

</td></tr></tbody></table>

**Checking the Windows version**

If you are running Windows, please check the version to determine if you should install the 32-bit or 64-bit version.

[![image6.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/image6.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/image6.jpg)

Press the Windows + Pause keys

#### Android, iOS, Chromebook and Windows UMP

Download the GlobalProtect Client from the respective device's app store.

<table id="bkmrk-android-and-chrome-o"><tbody><tr><td>### <span class="mw-headline" id="bkmrk-android-and-chrome-o-2">Android and Chrome OS devices</span>

<table class="plainlinks imbox imbox-style" role="presentation"><tbody><tr><td class="mbox-image">[![android (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/650android-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/650android-custom.png)[![chrome (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/chrome-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/chrome-custom.png)</td><td class="mbox-text">[Download the GlobalProtect App for Android](https://play.google.com/store/apps/details?id=com.paloaltonetworks.globalprotect)</td></tr></tbody></table>

[Check which Chrome OS Systems support Android Apps](https://www.chromium.org/chromium-os/chrome-os-systems-supporting-android-apps/)

</td></tr><tr><td>### <span class="mw-headline" id="bkmrk-ios-devices-1">iOS devices</span>

<table class="plainlinks imbox imbox-style" role="presentation" style="width: 92.3176%;"><tbody><tr><td class="mbox-image" style="width: 10.0305%;">[![macOS (Custom).png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/scaled-1680-/macos-custom.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-07/macos-custom.png)</td><td class="mbox-text" style="width: 89.9151%;">[Download the GlobalProtect App for iOS](https://apps.apple.com/ca/app/globalprotect/id1400555706)</td></tr></tbody></table>

</td></tr></tbody></table>

##### Linux

Install [**openconnect**](http://www.infradead.org/openconnect/) using the package manager for your Linux distribution.

#### Connecting to the campus VPN

##### Using GlobalProtect Clients

Windows and macOS devices use the **networklogin.uwindsor.ca** portal.

Mobile devices, including Android, iOS, Chromebook, and ARM-based Surface tablets, use the **mobilevpn.uwindsor.ca** portal. Refer to [VPN#ITS\_Document\_related\_to\_the\_Campus\_VPN](https://uwindsor.teamdynamix.com/TDClient/1975/Portal/KB/ArticleDet?ID=112514 "VPN") for detailed instructions for setting up a connection on your device.

##### Using Openconnect with Linux

<p class="callout info">The Openconnect integration with NetworkManager does not properly open the connection to the portal. You must use the command-line for your VPN connection to work correctly.</p>

Reserve a terminal window for the VPN connection, and run the command below, replacing **userid** with your **UWinID**, in the reserved terminal:

<table id="bkmrk-sudo-openconnect---p"><tbody><tr><td>```bash
sudo openconnect --protocol=gp mobilevpn.uwindsor.ca -u userid

```

</td></tr></tbody></table>

Linux, like mobile devices, uses the **mobilevpn.uwindsor.ca** portal.

#### PAN GlobalProtect HIP with open-connect

And because you are in Computer Science ...

You may notice a message like

```
POST https://mobilevpn.uwindsor.ca/ssl-vpn/hipreportcheck.esp
WARNING: Server asked us to submit HIP report with md5sum 923700b124549fa2954cc08845be3c60.
    VPN connectivity may be disabled or limited without HIP report submission.
    You need to provide a --csd-wrapper argument with the HIP report submission script.
```

this when you run open connect as shown in [VPN#Using\_Openconnect\_with\_Linux](https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-user-guide/globalprotect-app-for-linux/download-and-install-the-globalprotect-app-for-linux "VPN").

[Host Integrity Protection](http://www.infradead.org/openconnect/hip.html) provides an explanation. If you want to include the *--csd-wrapper* option, you will need to specify the location of the script required.

For Debian-based distributions, for example, you can find the location of the scripts like this

```
~$ dpkg -L openconnect|grep hipreport
/usr/libexec/openconnect/hipreport-android.sh
/usr/libexec/openconnect/hipreport.sh
```

To avoid the above warning on a Linux client you can use

#### Testing the VPN Connection

The ping command is the simplest way to test if your active VPN Connection is working.

##### Windows

[![photo_1.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/photo-1.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/photo-1.jpg)

Launch the hidden menu for power users using one of these methods:

- Press the *Win + X* keys on your keyboard
- Right-click on the Windows logo in the bottom-left corner of your desktop

In older versions of Windows 10, this menu will include shortcuts for the *Command Prompt* instead of *Windows Powershell*. Either is suitable for this test!

[![photo_2.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/photo-2.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/photo-2.jpg)

ping 10.10.10.10 results

Run

```
ping 10.10.10.10
```

to determine if the campus DNS server is available.

[![image_3.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/image-3.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/image-3.jpg)

New VPN provider IP address

Run

```
ipconfig
```

to display the new IP address while actively connected to the campus VPN portal.

[![image_4.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/image-4.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/image-4.jpg)

New VPN provided routes

Run

```
route print -4
```

to display the new IP routes while actively connected to the campus VPN portal.

##### macOS

[![image_5.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/image-5.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/image-5.jpg)

[Open or quit Terminal on Mac](https://support.apple.com/en-gb/guide/terminal/apd5265185d-f365-44cb-8b09-71a064a42125/mac)

This link can be found in the [Terminal User Guide](https://support.apple.com/en-gb/guide/terminal/welcome/mac) menu

Open a terminal and run

```
ping 10.10.10.10
```

to determine if the campus DNS server is available.

Your output should look similar to the Windows Powershell ping results above.

#### Linux

[![image_6.jpg](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/image-6.jpg)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/image-6.jpg)

ping -c 5 10.10.10.10 results

Run

```
ping -c 5 10.10.10.10
```

to determine if the campus DNS server is available.

[![image.png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/ZtWimage.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/ZtWimage.png)

New VPN provided IP address

Using Debian, run

```
ip addr show tun0
```

to display the new IP address while actively connected to the campus VPN portal.

The network interface name may vary depending on the Linux distribution you use, but the IP will begin with the first two octets 172.18.

[![image.png](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/scaled-1680-/GH4image.png)](https://help.cs.uwindsor.ca/uploads/images/gallery/2024-01/GH4image.png)

New VPN provided IP routes

Run

```
ip route
```

to display the new IP routes while actively connected to the campus VPN portal.