pub:conf-vpn-en
Differenze
Queste sono le differenze tra la revisione selezionata e la versione attuale della pagina.
Entrambe le parti precedenti la revisioneRevisione precedenteProssima revisione | Revisione precedenteUltima revisioneEntrambe le parti successive la revisione | ||
pub:conf-vpn-en [2016/02/09 14:57] – m.fiorazzo@unitn.it | pub:conf-vpn-en [2019/11/05 09:34] – m.fiorazzo@unitn.it | ||
---|---|---|---|
Linea 9: | Linea 9: | ||
|Windows, Macosx|Pulse Secure|[[pub: | |Windows, Macosx|Pulse Secure|[[pub: | ||
|Linux|Pulse Secure|[[pub: | |Linux|Pulse Secure|[[pub: | ||
- | |Dispositivi Mobili | + | |Mobile devices |
+ | |||
+ | **NEWS:** | ||
+ | The new version for linux (5.3r4.1) is 64bit native and provide a stable connection. | ||
===== MACOSX, Windows (Pulse Secure) ===== | ===== MACOSX, Windows (Pulse Secure) ===== | ||
- | ^Junos Pulse Download^ | + | ^Pulse |
- | |{{: | + | |{{: |
- | |{{: | + | |{{: |
- | |{{:pub:vpn: | + | |{{: |
+ | |{{: | ||
+ | |{{: | ||
+ | |{{: | ||
+ | |{{: | ||
For Mac and Safari: Warning !!! Be sure that your browser is saving the file with .dmg extension (and not .exe) as " | For Mac and Safari: Warning !!! Be sure that your browser is saving the file with .dmg extension (and not .exe) as " | ||
Linea 49: | Linea 56: | ||
===== Linux Pulse Secure Client ===== | ===== Linux Pulse Secure Client ===== | ||
+ | |||
+ | **NEWS:** | ||
+ | The new version for linux (5.3r3) is 64bit native and provide a stable connection. | ||
^Pulse Secure for Linux Download^ | ^Pulse Secure for Linux Download^ | ||
- | |{{: | + | |{{: |
- | |{{: | + | |{{: |
+ | |{{: | ||
+ | |{{: | ||
+ | |{{: | ||
+ | |{{: | ||
Download the package installer to the Linux client then run the installer using the following command: | Download the package installer to the Linux client then run the installer using the following command: | ||
Linea 67: | Linea 81: | ||
< | < | ||
- | sudo dpkg -i / | + | sudo dpkg -i / |
</ | </ | ||
- | The script will prompt | + | Install |
< | < | ||
- | user@host: | + | user@host: |
- | (Reading database ... 154703 files and directories currently installed.) | + | |
- | Preparing to replace pulse 8.1 (using | + | |
- | .../ | + | |
- | Unpacking replacement pulse ... | + | |
- | Setting up pulse (8.1) ... | + | |
- | | + | |
- | apt-get install libc6-i386 | + | |
- | apt-get install lib32z1 | + | |
- | Please refer / | + | |
</ | </ | ||
- | You have to download | + | if you want to launch |
- | **NB: this is has to be done only one time** | + | |
< | < | ||
- | user@host:~$ openssl s_client -connect vpn-ssl.unitn.it:443 -showcerts < /dev/null 2> /dev/null | openssl x509 -outform der > /$HOME/Downloads/vpn-ssl.crt | + | export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/usr/local/pulse |
</ | </ | ||
- | You can also download the certificate | + | Or you can launch Pulse from your Applications by clicking on the Pulse icon. |
- | < | + | - Main screen |
- | user@host:~$ unzip / | + | |
- | </ | + | {{:pub:vpn:pulseui-linux-1.png?200|}} |
+ | |||
+ | - Create the connection: | ||
+ | |||
+ | {{: | ||
+ | |||
+ | - Login: | ||
+ | |||
+ | {{: | ||
+ | |||
+ | - Connection state: | ||
+ | |||
+ | {{: | ||
- | Use the following command to launch the VPN client (you will be asked for the UniTN password): | + | If you don't want to use the UI, use the following command to launch the VPN client (you will be asked for the UniTN password): |
< | < | ||
- | / | + | / |
</ | </ | ||
Linea 106: | Linea 122: | ||
< | < | ||
- | user@host: | + | user@host: |
Reading package lists... Done | Reading package lists... Done | ||
Building dependency tree | Building dependency tree | ||
Linea 113: | Linea 129: | ||
libc6-i386 is already the newest version. | libc6-i386 is already the newest version. | ||
0 upgraded, 0 newly installed, 0 to remove and 557 not upgraded. | 0 upgraded, 0 newly installed, 0 to remove and 557 not upgraded. | ||
- | executing command : / | + | executing command : / |
VPN Password: | VPN Password: | ||
</ | </ | ||
Linea 139: | Linea 155: | ||
</ | </ | ||
- | References - official documentation: | + | ===== Mobile Devices |
- | + | ||
- | ===== Dispositivi Mobili | + | |
**REQUISITI** | **REQUISITI** | ||
* iPhone, iPod Touch, iPad | * iPhone, iPod Touch, iPad | ||
- | * Android devices 4.0 o superiori | + | * Android devices 4.0 or higher |
* Windows Mobile 6.5 | * Windows Mobile 6.5 | ||
- | **ISTRUZIONI:** (screenshots | + | **INSTRUCTIONS:** (screenshots |
- | * installare l'app "Pulse Secure" | + | * Install the app "Pulse Secure" |
- | * avviare l' applicazione | + | * Start the application |
{{: | {{: | ||
- | * Creare una nuova connessione inserendo: | + | * Create a new connection by entering: |
- | * "Nome connessione" (a scelta) | + | * "Connection Name" (your choice) |
* " | * " | ||
- | * "Nome utente" (nella forma nomeutente@unitn.it) | + | * "User Name" (in the form username@unitn.it) |
- | * toccare su "Crea connessione" | + | * Touch on "Create Connection" |
{{: | {{: | ||
- | * toccare su "Connetti", | + | * Tap on "Connect", |
{{: | {{: | ||
{{: | {{: | ||
- | * a questo punto viene stabilita la connessione, verificabile tramite un tocco su "Stato" | + | * after a while, the connection is established, |
{{: | {{: | ||
{{: | {{: | ||
- | * al termine della sessione, per terminare la connessione, | + | * to terminate the session, tap on "Disconnect" |
===== Features of vpn-ssl service ===== | ===== Features of vpn-ssl service ===== | ||
Linea 184: | Linea 199: | ||
NB: the routing change doesn' | NB: the routing change doesn' | ||
+ | |||
==== User-side Firewall rules ==== | ==== User-side Firewall rules ==== | ||
VPN traffic is encrypted in SSL and uses TCP destination port 443. For the ESP mode (which increases performance) you must open the UDP destination port 4500 too. | VPN traffic is encrypted in SSL and uses TCP destination port 443. For the ESP mode (which increases performance) you must open the UDP destination port 4500 too. | ||
- | |||
- | ==== Supported clients ==== | ||
- | |||
- | ^Platform^SO^Browsers and Java Environment^ | ||
- | |Windows|- Windows 8 on 32-bit or 64-bit platforms.- Windows 8 Enterprise on 32-bit. \\ - Windows 7 on 32-bit or 64-bit platforms \\ - Windows 7 SP1 Enterprise on 32-bit \\ - Windows Vista on 32-bit or 64-bit platforms \\ - Windows XP with SP3 on 32 bit|- Internet Explorer 10 \\ - Internet Explorer 9.0 \\ - Internet Explorer 8.0 \\ - Internet Explorer 7.0 \\ - Firefox 3.0 and above including FF10 \\ - Oracle JRE 6 and above| | ||
- | |Mac|- Mac OS X 10.6.x, 32 bit and 64 bit \\ - Mac OS X 10.7.x, 32 bit \\ - Mac OS X 10.8.x, 32 bit|- Safari 6.0 Sun JRE 6 \\ - Safari 5.1 Sun JRE 6 \\ - Safari 5.0 Sun JRE 6| | ||
- | |Linux|- OpenSuse 10.x and 11.x \\ - Ubuntu 9.10, 10.x and 11.x \\ - Red Hat Enterprise Linux 5|- Firefox 3.0 and above \\ - Oracle JRE 6 and above| | ||
- | |Solaris|- Solaris 10, 32 bit only|- Mozilla 2.0 and above| | ||
- | **NOTE:**\\ \\ | ||
- | 1) IE 10 is supported in Windows 8 Desktop Mode on Windows 8\\ | ||
- | 2) 32 bit Network Connect is supported only on the following distributions: | ||
- | ^Platform^Operating System^Browsers and Java Environment^ | ||
- | |Linux|- Ubuntu 12.04 LTS \\ - OpenSUSe 12.1 \\ - Fedora 17|- FireFox 10-ESR \\ - Oracle JRE 6 and 7 \\ - IcedTea-Web 1.2 with OpenJDK 6 and 7| | ||
- | |||
- | Other operating systems, browsers and versions of Java, it may work by requiring, in some cases, possible interventions configuration on the client. | ||
- |