VPN - Frequently Asked Questions (FAQ)
Yes, it is possible. If you just want to tunnel the net traffic with the TUD via the VPN connection, choose Group TUD-vpn-split-campus before connecting.
Yes, the parallel access to private addresses (10.x.x.x, 172.16.x.x and 192.168.x.x) is allowed. Thereby the access to local network ressources (e.g. printer) is still possible. Precondition is the activation of "Enable local LAN access" under Advanced->Preferences.
The combination of a firewall with the AnyConnect-Client on a PC can possibly lead to problems. Known issues come from firewalls from F-Secure, Sygate, Agnitum or Zonelabs.
Here it is necessary to follow the right installation order:
- first install the AnyConnect-Client
- install the firewall afterwards
Please check if your VPN-client works behind a firewall (or router with firewall features). In this case, make sure the following IP-protocols and ports to the ZIH VPN gateway (vpn2.zih.tu-dresden.de) are enabled. In diesem Fall müssen Sie sicherstellen, dass folgende IP-Protokolle und Ports zum VPN-Gateway des ZIH freigeschaltet sind:
- TCP Port 443
- UDP Port 443 (DTLS) is preferred, because of higher performance
If you connect to the TUD network via the VPN gateway, the connection is - indeed - encrypted, but your pc is practically a part of the TUD network (141.30.0.0/24). Please check if the local security policy allowes a connection to this network. The VPN access is protected by the central firewall of the ZIH. Find the firewall-policy here.
Possible reason: after the installation of the AnyConnect-Client, 'Internet Connection Sharing' has been activated in one or more of the computer's network interfaces.
Solution: disable the the common use of the internet connection
Therefore do the following steps:
- Start System Control --> Network and Release Center.
- Rightclick on Network Adapter LAN-Connection --> Properties
- Click on the tab Release and uncheck Allow other Users in theis network to use this PC for Internet Connection if it is set
- Click on OK
- Repeat step 2 for the W-LAN Adapter (if existed)