Why use a VPN?

Off-campus computers are subject to various network restrictions:

A VPN connection bypasses these restrictions by making the client appear as if it were on campus. The VPN provides a private address on Waterloo's network in the subnet 172.16.36.0/22.

For IST managed Windows machines that are being used at home, the VPN is required in order for:


Advantages of a VPN

The most apparent advantage of the VPN is that is allows users off-campus to connect to network resources such as network drives.

Simple to use

Once the VPN connection is started, it works in the background to manage all traffic between the off-campus computer and the campus resources. There is no need to start special file-transfer programs or other software to get at campus resources. Only traffic destined for the University of Waterloo goes through the campus VPN "tunnel". Traffic from your computer to other Internet sites does not go through our VPN.

Connection security

VPN connections are encrypted end-to-end, using the same Secure Sockets Layer (SSL)/Transport Layer Security (TLS) encryption that secure websites use. This means that email, file sharing, web browsing, calendars - all of the data between the off-campus and on-campus computers is encrypted and secure.

Improved campus-wide strategy for IT security

With the campus VPN in place, it is now possible for IT managers on campus to be more pro-active in securing services. In particular, websites that provide sensitive services can be restricted to campus addresses only, and off-campus access can be provided through the authenticated VPN connection.

 


Using the VPN

Accessing on-campus websites

If you only need to access on-campus websites, using the VPN can be done without installing any software on your home computer. You can use the VPN website to access other websites.

Accessing campus network resources

Most users will need to install the VPN client software in order to get access to all campus network resources. In this case, you would run the Cisco AnyConnect client software, then do what you need to do to access the resource. For example, you would start the VPN client before running site-licensed software on your laptop that needs to connect to the University's license server, or before starting your Remote Desktop client.

Settings at a glance

If you already have the Cisco VPN client installed, you can use the following settings to connect: 

Two-factor authentication

In the second password field, enter 'push' if using DUO mobile, enter a code if using a token

Installation guides

Guides are located in the Confluence knowledge base

Common operating systems

Mobile devices


Accessing subscription-based resources through the VPN

The UWaterloo Library and some academic departments have subscriptions for electronic journals and other online resources. In most cases, access to these resources is restricted to on-campus Internet Protocol (IP) addresses.

The VPN technology cannot circumvent this practice directly. When using the VPN from home or elsewhere, traffic to the electronic resource website (for example, a journal website) will not be sent through the VPN because the resource is not on campus. Instead, the VPN client sends requests in the "usual" way for the off-campus system. This will appear to be from an address that is not a UWaterloo IP address, and so access is typically not automatically granted as it would be for an on-campus computer.

Fortunately, the UWaterloo Library has a portal web page that VPN users can use to access most subscription and licensed/restricted-access resources. From there you can reach all of the subscription-based resources that are available to the library.


What's the difference between a VPN and "remote desktop"?

Many people already connect to campus network resources by using Remote Desktop (RDP) to connect to their campus workstation from off-campus.

RDP is now blocked at the campus boundary. When you need to use RDP, a VPN connection is simply established first, using the Cisco AnyConnect client (obtained from campus VPN website), then the RDP connection is established as before. Instructions for obtaining and installing the Cisco AnyConnect client are outlined below.


Technical details for support staff

Client-side modifications