[ TOP ] [ UP ]
Remote Access Using a Virtual Private Network
[ General ] [ Windows Vista/XP ] [ Mac OSX ]
Vital Information:
| Location |
VPN Server Address |
| Off Site |
vpn0.external.ameslab.gov |
| Main Wireless |
vpn0.wireless2.ameslab.gov |
SCL Wireless |
vpn0.scl-wireless.ameslab.gov |
| Visitor / Conference |
vpn0.visitor-conference.ameslab.gov |
| Personal |
vpn0.personal-machines.ameslab.gov |
Server Shared Secret: Contact IS office
Setup L2TP VPN connection without Cryptocard (Vista, Works on XP but NOT on Windows 2000):
- Contact the IS office to obtain a static IP address and the group password
- [Windows XP only] Go to Start -> Control Panel -> Network Connections
- [Windows Vista only] Go to Start -> Settings -> Control Panel -> Network and Sharing Center
- Setup a connection or network
- Select the connection option "Connect to a workplace"
- Choose the option "No, create a new connection"
- Choose the option to "Use my Internet Connection (VPN) "
- Fill in the boxes for the Internet address depending on where the system will be:
- Set the destination name to something you'll recognize and remember
- **Check the box to not connect now, but setup connection for later; and click next
- Do not fill in user name or password boxes
- Right-click on the newly created connection, and go to properties
- Click on the "Security" Tab, choose "Advanced (custom settings)", and click on the "Settings" button
- Under "Data Encryption:", choose "Optional encryption (connect even if no encryption)"
- Select "Allow these protocols:" and choose only "Microsoft CHAP (MS-CHAP)" and "Microsoft CHAP Version 2 (MS-CHAP v2)", then click "OK"
- [Windows XP only] Click on the "IPSec Settings" button
- [Windows XP only] Select the radio button "Use preshared key for authentication"
- [Windows XP only] Enter the preshared key provided by the IS office (the same key as for
the client), then click "OK"
- Click on the "Networking" tab and select L2TP IPsec VPN for the Type of VPN
- [Windows Vista only] Click on the IPsec Settings button
- [Windows Vista only] Select the radio button "Use preshared key for authentication"
- [Windows Vista only] Enter the preshared key provided by the IS office (the same key as for
the client), then click "OK"
- Click "OK", the attempt to connect using your username and password
Setup L2TP VPN connection with Crytpocard (Vista, Works on XP but NOT on Windows 2000):
- Contact the IS office to obtain a static IP address and the group password
- [Windows XP only] Go to Start -> Control Panel -> Network Connections
- [Windows Vista only] Go to Start -> Settings -> Control Panel -> Network and Sharing Center
- Setup a connection or network
- Select the connection option "Connect to a workplace"
- Choose the option "No, create a new connection"
- Choose the option to "Use my Internet Connection (VPN) "
- Fill in the boxes for the Internet address depending on where the system will be:
- Set the destination name to something you'll recognize and remember
- **Check the box to not connect now, but setup connection for later; and click next
- Do not fill in user name or password boxes
- Right-click on the newly created connection, and go to properties
- Click on the "Security" Tab, choose "Advanced (custom settings)", and click on the "Settings" button
- Under "Data Encryption:", choose "Optional encryption (connect even if no encryption)"
- Select "Allow these protocols:" and choose only "Unencrpyted password (PAP)" and "Challenge Handshake Authentication Protocol (CHAP)", then click "OK"
- [Windows XP only] Click on the "IPSec Settings" button
- [Windows XP only] Select the radio button "Use preshared key for authentication"
- [Windows XP only] Enter the preshared key provided by the IS office (the same key as for
the client), then click "OK"
- Click on the "Networking" tab and select L2TP IPsec VPN for the Type of VPN
- [Windows Vista only] Click on the IPsec Settings button
- [Windows Vista only] Select the radio button "Use preshared key for authentication"
- [Windows Vista only] Enter the preshared key provided by the IS office (the same key as for
the client), then click "OK"
- Click "OK", the attempt to connect using your username and password
Setup L2TP VPN connection (Mac OSX):
- Contact the IS office to obtain a static IP address and the group password
- Go to Finder -> File -> New Finder Window -> Applications
- Open the "Internet Connect" program
- Go to File -> New VPN Connection...
- Choose "L2TP over IPSec" and click Continue
- Under "Configuration", choose "Edit Configurations..."
- Fill in the Server Address from the table at the top of this document
- Fill in the Account Name with your Ameslab username
- Choose the "Password" option, and fill in your Ameslab password
- Select "Shared Secret" under Machine Authentication, and use the password provided by IS
- Leave "Enable VPN on demand" unchecked, and click OK
- Make sure the box "Show VPN status in menu bar" is checked, and click "Connect"
- You should now be connected to the Ames Laboratory VPN server. Please report any problems to the IS office.