Indiana University
University Information Technology Services
  
What are archived documents?

In Windows XP, how do I make a VPN connection to the IU network?

Note: At Indiana University Bloomington and IUPUI, you can now access the wireless network without using VPN. See What is IU Secure?

Before you start: If you are behind a NAT device (e.g., a home or small business router) or your IP address is a private IP address, you must download an update from Microsoft before you can successfully connect using an IPsec VPN connection. To determine if this situation applies to you, refer to For Windows 2000, XP, or Vista, how do I download and install the L2TP/IPsecNAT-T update?

This document explains how to manually set up a VPN connection in Windows XP at Indiana University Bloomington and IUPUI. UITS recommends that you set up a VPN connection to IU for Windows XP by using the VPN Installers, available from the IUware CD or from IUware Online.

This software automatically does what the instructions in this document describe how to do manually.

On this page:


Introduction

Note: IU's VPN is intended for individual computing accounts only. Group and departmental accounts cannot access the VPN. See Why can't I make a VPN connection through an IU group or departmental account?

Note: If you are a student, faculty member, or staff member at Indiana University Bloomington or IUPUI, use the IU Secure network for wireless access. For help, see What is IU Secure? If you are visiting IU, instead see At IUB and IUPUI, what is a Network Access account, and how do I get one?

Creating a VPN connection

To create a virtual private network (VPN) connection to the IU network using Windows XP, either wirelessly or remotely:

  1. In the Windows XP default view, from the Start menu, right-click Network Places and select Properties. In the Windows XP Classic View, from the Start menu:

    1. Click Settings, and then Control Panel.
    2. In the Control Panel window, if "Pick a category" appears in large print, on the left frame in the "Control Panel" section, click Switch to Classic View.
    3. In the main window, you should now see all the control panels. Double-click Network Connections.

  2. In the left frame in the "Network Tasks" section, click Create a new connection.

    Note: If you do not see "Network Tasks", look for New Connection Wizard in the main window, and double-click it. You also may go to the File menu and choose New Connection there.

  3. The New Connection Wizard should open. Click Next and select Connect to the network at my workplace. Click Next again.

  4. Select Virtual Private Network connection and click Next.

    Note: If the Virtual Private Network option is not available, you may need to enable the Remote Access Connection Manager service; see In Windows 2000 or XP Professional, why is the option to create a VPN connection unavailable?

  5. Type a name for the connection (e.g., IU-VPN ) and click Next. You can enter any name you wish.

  6. Note: If your computer already has a Dial-Up Networking icon, at this point you may see the following message:

    "Windows can automatically dial the initial connection to the Internet or other public network before establishing the virtual connection".

    If you don't see the above message, proceed directly to the VPN Server Selection window (see step 7). If you do see the message:

    • In the Public Network window, you must tell Windows what public network connection you will use to attach to your VPN:

      • If you are connected to a persistent Internet connection (e.g., Ethernet), you should choose Do not dial the initial connection.
      • If you must dial in to be connected to the Internet, you should choose Automatically dial this initial connection and select your Internet service provider (ISP) connection.

    • Click Next.

  7. In the VPN Server Selection window, type the name or IP address of the VPN server, and then click Next.

    Use the table below to find your VPN server for both remote (e.g., cable modem, DSL, or outside Internet service provider) and wireless VPN connections:

    Campus VPN server

    IU Bloomington ipsec.indiana.edu
    IU East vpn.iue.edu
    IU Kokomo vpn.iuk.edu
    IU Northwest 149.162.8.2
    IUPUI ipsec.iupui.edu
    IU South Bend vpn.iusb.edu
    IU Southeast vpn.ius.edu

  8. At this point, you may see the message:

    "You can configure this connection to use your smart card to log you into the remote network. Select whether to use your smart card with this connection".

    Choose Do not use my smart card and click Next.

  9. In the Connection Availability window, select the option most appropriate for your situation. Click Next.

    Note: If you are using a wireless card and wish to log into a domain (including ADS) upon starting Windows XP, you must select the Anyone's use option. Selecting this option will make the VPN connection available when you choose Log on using dial-up connection at the login screen.

  10. On the last screen, if you want a shortcut icon on your desktop for the new connection, select Add a shortcut to this connection to my desktop. Click Finish.

Configuring your VPN connection

To properly configure your VPN connection:

  1. After you've created your VPN connection, Windows XP should open the connection automatically for you. If it does, select Properties. If it does not, right-click the new connection icon, and then select Properties.

  2. Click the Options tab. Check Prompt for name and password, certificate, etc. and Include Windows Logon Domain.

  3. Click the Networking tab. If you're on the Bloomington or Indianapolis campus, set "Type of VPN:" to L2TP IPSec VPN. If you're on any other campus, set it to PPTP VPN.

  4. In the "This connection uses the following items:" field, only the following should be checked:

    • Internet Protocol (TCP/IP)
    • File and Printer Sharing for Microsoft Networks
    • Client for Microsoft Networks
    • QoS Packet Scheduler

  5. Select TCP/IP, and then click Properties.

  6. Select both Obtain an IP address automatically and Obtain DNS server address automatically, and then click OK.

  7. Click the Security tab.

  8. If you selected PPTP VPN in step 3 above (i.e., if you set "Type of VPN:" to PPTP VPN), skip ahead to step 10.

    If you selected L2TP IPSec VPN, click the IPSec Settings... button and proceed to the next step.

  9. Check the box labeled Use pre-shared key for authentication. Then, in the "Key:" field, type hermanbwells . Click OK.

  10. Select Advanced (custom settings), and then click Settings... .

  11. Under "Logon Security", select Allow these protocols, and make sure the only checkbox selected is Microsoft CHAP Version 2 (MS-CHAP v2). Click OK and then Close.

Establishing a VPN connection

To establish a VPN connection:
  1. After configuring your VPN connection, you should be back to the authentication screen for your new connection. If not, get there by double-clicking the new connection icon. Or, in XP's default Start menu, find it by clicking Start, then Connect To, and finally the name of the connection. In XP's Classic Start menu, click Start, then Settings, then Network Connections, and finally the name of the connection.

  2. You will see a place to enter a username, password, and domain. Enter your IU username and password, and in the domain field, enter ADS . Click Connect.

    Note: It may take up to a minute to establish a connection with the VPN server. Please be patient. If you have problems connecting, note any error messages and contact your campus Support Center.

  3. When the connection is established, you should see a new icon in the system tray. This icon is identical to the one for dial-up connections.

  4. To disconnect and terminate the connection, double-click the icon in the system tray and choose Disconnect.

Also see:

This is document akko in domain all.
Last modified on November 24, 2008.
Please tell us, did you find the answer to your question?