Remote Access Using the USDA LincPass

Similar documents
Manufacturing Representative SSL VDM Login User s Guide

Citrix Remote Access Portal U s e r M a n u a l

Aventail Connect Client with Smart Tunneling

How to Connect to Remote Desktop & How to Use Cisco AnyConnect Secure Mobility Client Secure VPN Connection

TAMUS Terminal Server Setup BPP SQL/Alva

ATTENTION: End users should take note that Main Line Health has not verified within a Citrix

COOK COUNTY OFFICE 365 MIGRATION USER GUIDE

Accessing The Doctors Clinic Physician Connect

Using VPN. DJJ Staff

Basic Web Fullerton College

Learning Management System (LMS) Quick Tips. Contents LMS REFERENCE GUIDE

UF Health SharePoint 2010 Introduction to Content Administration

Setting up Remote Desktop

Trauma/Recon Sales. Step by step guide to using the Smith & Nephew User Gateway (SNUG) Global Remote Access

Passport Installation. Windows 8 + Internet Explorer 10

Using the FDO Remote Access Portal

Using the FDO Remote Access Portal

Network Connect Installation and Usage Guide

SSL VPN Support Guide

How to Use Remote Access Using Internet Explorer

How to Install the Cisco AnyConnect VPN Client. Installing Cisco AnyConnect VPN Client on Windows with the Chrome Browser (Recommended)

ecstudent-ts Terminal Server How to Use

ecfshome-ts Terminal Server How to Use

Windows Installation 1. On a Windows PC (For MAC, skip to next section), at the file download prompt click Run.

SSL VPN Support Guide

How do I Install and Configure MS Remote Desktop for the Haas Terminal Server on my Mac?

Windows and MAC User Handbook Remote and Secure Connection Version /19/2013. User Handbook

Remote Access Services Microsoft Windows - Installation Guide

Configuring VPN Using Windows XP

Connecting to Miami University s EHR Solution (GE Centricity)

Installing VPN for PC v1.3

educ Office Remove & create new Outlook profile

University of Central Florida UCF VPN User Guide UCF Service Desk

Remote Desktop Solution, (RDS), replacing CITRIX Home Access

How to Set Up SSL VPN for Off Campus Access to UC eresources

How do I Install and Configure MS Remote Desktop for the Haas Terminal Server on my Mac?

User guide. Business

These additional levels of security are NOT required if you are using a Derbyshire County Council machine on council premises.

Install and End User Reference Guide for Direct Access to Citrix Applications

OFFICE 365 SELF- CONFIGURATION GUIDE

University Computing & Telecommunications Virtual Private Networking: How To/Self- Help Guide Windows 8.1 Operating System.

Passport Installation. Windows XP + Internet Explorer 8

VPN Web Portal Usage Guide

BEFORE YOU START... 1 Set Up Your PC Desktop Computer/Laptop... 1 Set Up Remote Desktop on Your ipad... 3

Remote Desktop Services

Virtual Private Network (VPN)

Quick Connect. Overview. Client Instructions. LabTech

Installation and Troubleshooting Guide for SSL-VPN CONNECTIONS Access

Clientless SSL VPN Users

TAMUS Remote Desktop Setup For BPP SQL & Alva

How To Use Senior Systems Cloud Services

Junos Pulse VPN Client Installation

TxEIS on Internet Explorer 7

Remote Access End User Reference Guide for SHC Portal Access

Citrix Access Gateway Plug-in for Windows User Guide

CONNECT-TO-CHOP USER GUIDE

Accessing Derbyshire County Council s Outlook Web Access (OWA) Service. Smart Phone App version

ACCESSING LEO USING AN UNCONFIGURED LAPTOP

End User Service Desk Guide

SSL VPN Setup for Windows

Remote Access with Outlook 2003 Using RPC over HTTPS

Wireless Network Configuration Guide

Disabling Microsoft SharePoint in order to install the OneDrive for Business Client

Guide to Remote Desktop Connection

A) Setting Screen Resolution to 1024 x 768

The initial set up takes a few steps, but then each time you want to connect it is just a two set process.

SSL VPN Service. To get started using the NASA IV&V/WVU SSL VPN service, you must verify that you meet all required criteria specified here:

Allianz Global Investors Remote Access Guide

Virtual Office Remote Installation Guide

Three Rivers Community College Wireless Network

Off Site Access PPD IT How to Guides December 2010

Mac - Juniper Remote Desktop Instructions

Undergraduate Academic Affairs \ Student Affairs IT Services. VPN and Remote Desktop Access from a Windows 7 PC

SHC Client Remote Access User Guide for Citrix & F5 VPN Edge Client

Installing and Configuring Remote Desktop Connection Client for Mac

Accessing the Media General SSL VPN

How to make a VPN connection to our servers from Windows 8

How do I Install and Use the Cisco VPN Any Connect Client for the Berkeley Campus?

Mercy s Remote Access Instructions

Tips for Wireless VPN

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government.

Virtual Private Network (VPN)

Towson University s VPN Virtual Private Network

Please apply to the DIOS Helpdesk (see Information and communication at the end of this document) for further assistance.

Access NSF Frequently Asked Questions

Those who wish to remotely log on to a Pepperdine Windows desktop computer will also need to have these instructions with them when they connect.

Vodafone PC SMS (Software version 4.7.1) User Manual

Managing Contacts in Outlook

Citrix Shared Desktop

(You will use the login ID and password below to login through the first two websites.)

Instructions to Sign On and Off of Self Service Applications. Internet Explorer 9 (IE9) Users: Turn Off Compatibility View:

Getting Started with Citrix Remote Connectivity Service

Phone: Fax: Box: 230

Allianz Global Investors Remote Access Guide

Office of Information Technology VPN Client Instructions

Accessing the Mercy Remote Access Portal (SSL VPN)

NS Financials. Client Platform Guide for Mac Using Safari Incl Citrix Setup As A Local Client

OneDrive for Business from Desktop or Laptop Windows devices

MetroHealth Information Services

To add Citrix XenApp Client Setup for home PC/Office using the 32bit Windows client.

Transcription:

If you require an accessible version of this course please follow these directions. Press Shift+Control+Y to activate the Adobe Read Out Loud function. Once you have activated the Read Out Loud function you must disable your assistive technology as it will conflict with Read Out Loud. To begin reading the course press Shift+Control+B. Remote Access Using the USDA LincPass 1

Topics Introduction What is a VPN? About the Enterprise VPN Getting Started Two Connection Options Network Connect Proxy Connect Troubleshooting Where to Go for Help 2

Introduction This course describes the USDA Enterprise Virtual Private Network (VPN) and explains how to use it. Each Agency has customized the VPN for their business needs, so some of the instructions are generic. Please refer to your Agency s Enterprise VPN User Guide for specific instructions and policies on using the Enterprise VPN. 3

What is a VPN? The USDA Enterprise VPN Requires your LincPass and PIN Creates a secure tunnel between the remote computer and the USDA network Virtual Private Network (VPN) Logical computer network that allows remote users from any location to securely connect to the USDA physical computer network as if they were on-site You may have more than one VPN The Enterprise VPN is remotely accessing your Agency s network securely. If you have other VPNs for accessing internal resources, such as data centers, you ll still need those VPNs to do that 4

About the Enterprise VPN The USDA Enterprise VPN: Provides secure remote access to your Agency s and USDA networks Is Web-based or local client-based Lets you connect to your work network from any remote location that has Internet access (conference room, hotel room, AirCard, home office, airport, etc.) Leverages the USDA LincPass, so you won t have to keep track of yet another ID and password 5

Getting Started To use the USDA Enterprise VPN, you will need: USDA computer (e.g., laptop) with a card reader and the ActivClient software installed An activated LincPass card and PIN Microsoft Internet Explorer browser ver. 6.x, or above, or other Agency-approved Web browser Approval from your Agency to use Enterprise VPN service The URL(s) for your Agency s VPN portal An Internet connection https://vpn... 6

Two Connection Options The Enterprise VPN has two connection options: Network Connect: A full connection to the USDA network, with all the capability of working in your office. Use this option when you need access to a client-server application such as Outlook from your local computer, or Agency network resources such as a shared drive or a specialty printer (e.g., a plotter). While connected via the Network Connect option, you will not have access to any local network resources, such as a home network printer or another local computer. 7

Two Connection Options (continued) Proxy Connect: A limited service connection that allows you to access Web-based resources or file shares not accessible outside of USDA networks. Use this option when all you need is access to Web-based resources, such as Outlook Web Access. While connected via the Proxy Connect, you will have access to local network resources, such as a home network printer or another local computer. 8

Two Connection Options (continued) Which Connection Type Should I Use? I want to Run Web-based applications (e.g., SharePoint, Outlook Web Access, internal Web apps) Run clientbased applications (e.g., MS Outlook, Office Communicator, Lotus SameTime) Access network file shares (e.g., Home drive) Keep local connections (e.g., local printer, local database) Use network resources (e.g., network printer in the office) Network Connect X X X X Proxy Connect X X X The following sections explain how to run the two types of USDA Enterprise VPN connections. 9

Network Connect 1. Start your computer. Make sure you can connect to the Internet, and that your LincPass is inserted in your computer s card reader. 2. Double-click on the Juniper VPN icon on your desktop OR Start Microsoft Internet Explorer (or other approved browser). In the browser s address field, enter the URL your Agency gave you when you received approval to use the VPN. 3. The first time you connect, you ll have to enter the URL your Agency gave you when you received approval to use the VPN. The system will remember this URL for the next time you connect. 10

Network Connect (continued) 4. If this is the first time you have used the Juniper software, you will receive a message asking if you want to load the Host Check. Click the Always button to allow the software to run. 5. The system is checking your computer to make sure it meets all security requirements to connect to the USDA network (it may take a few minutes). If your computer passes the check, you ll see a message that the security is satisfactory. 11

Network Connect (continued) 6. The ActivClient PIN prompt may appear if you have not entered your LincPass PIN recently. If so, provide your LincPass PIN number. NOTE: The system will remember ( cache ) the entry of your PIN for up to 4 hours. If you used your LincPass & PIN to log into your computer or another internet session, you won t be prompted again within the 4-hour window or until the LincPass is removed from the card reader. 12

Network Connect (continued) 7. If this is the first time you have used the Juniper software, you will receive the following message to load the Network Connect. Click the Always button to allow the software to run. 8. When a successful connection is made, you will see a connection session window (it will go away automatically after a few seconds). 9. A new Juniper VPN icon appears in your system tray (bottom right side of your Windows screen). To see the details of the VPN connection, right click on the icon in the system tray and select Advanced View. This will show you your IP address and connection information. 13

Network Connect (continued) 10. To sign out of the USDA Enterprise VPN, rightclick on the Juniper Connected icon in your system tray and select Sign Out. The icon will disappear from your system tray in a few seconds, indicating the connection is closed. NOTE: The next time you use the Network Connect option, it will go faster, since you will have already given permission for the Juniper software to run the host-check and connection applications. 14

Proxy Connect 1. Start your computer, and connect to the Internet with Microsoft Internet Explorer (or other approved browser). Make sure your LincPass is inserted in your computer s card reader. 2. In the browser s address field, enter the URL your Agency gave you when you received approval to use the VPN. 3. Depending on your browser settings, you may receive a security warning message. Click the OK button. 4. If this is the first time you have used the Juniper software, you will receive a message asking if you want to load the Host Check. Click the Always button to allow the software to run. 15

Proxy Connect (continued) 5. The system is checking your computer to make sure it meets all security requirements to connect to the USDA network (it may take a few minutes). If your computer passes the check, you ll see a message that the security is satisfactory. 16

Proxy Connect (continued) 6. You may see a pop-up box titled Choose a digital certificate. If multiple options are available, only one will work and you will have to identify the correct certificate. To do so, highlight the first certificate on the list and click the View Certificate button. The correct certificate will show Smart Card Logon in the Intended Purposes list. If the selected certificate doesn t say this, close the Certificate window, then in the Choose a Digital Certificate box, select the next certificate and click the View Certificate button again and make sure it says Smart Card Logon. Once you ve identified the correct certificate, highlight it and click the OK button. 17

Proxy Connect (continued) 7. The ActivClient PIN prompt may appear if you haven t entered your LincPass PIN recently. If so, enter your LincPass PIN number. NOTE: The system will cache the entry of your PIN for up to 4 hours. If you have used your LincPass & PIN to log into your computer or another internet session, you won t be prompted again within the 4-hour window or until the LincPass is removed from the card reader. 18

Proxy Connect (continued) 8. In your browser, your agency s portal appears. The screenshot below is a sample; your agency s portal will probably look different. VPN menu Browse to USDA Web resources The menu option buttons at the upper right hand corner of your screen follow you through all subsequent pages. Home takes you to the front page of your VPN session. Sign Out logs you off the VPN. 19

Proxy Connect (continued) You can customize your Proxy page by setting bookmarks to USDA Web locations and files. To create a Web Bookmark, enter the URL in the blank field just below the menu, then click the Browse button. 20

Proxy Connect (continued) Once you re at the page you want to bookmark, click the Bookmark icon button in the upper right menu bar. In the Add Web Bookmark page that appears, complete the description and select the display options you want. Click the Add Bookmark button when you re done. 21

Proxy Connect (continued) You can also add bookmarks (shortcuts) to files you use often. Ask your Agency for instructions. If you are connected via the Proxy Connect, but need temporary access to the full Network Connect, you can create a temporary Network session by going to your Home page and clicking the Start button for the Network Connect application. The system will tell you to Please wait, then return to the proxy page. You can tell you re actually connected to the full Network Connect because a new icon appears in your system tray. To end the Network Connect session, right-click the icon in your system tray and select Sign Out. (You ll have to sign in to the Proxy Connect again if needed.) 22

Troubleshooting To check your connectivity when using the Network Connect option: Right-click on the Network Connect icon in the lower right system tray, then select Basic View. To see the details of the VPN connection, right-click on the Network Connect icon and select Advanced View, then click the Session tab. This shows how long you ve been connected, your IP address, and other connection information, which is useful when getting help from IT support. 23

Troubleshooting (continued) Connection drops The Host Check application runs the entire time you are connected to the USDA network. If you try to do something that is against its rules, it will automatically drop the connection within 5 minutes of the detected activity. Each agency can set the rules for what the Host Check looks for. Examples of behavior that might be monitored include: The anti-virus files or the machine s certificate are out of date or not recognized. The Host Check detects installation of peer-to-peer software or other nonapproved applications. The BigFix service has been stopped or uninstalled. 24

Troubleshooting (continued) Connection problems If you can t log into your computer with your LincPass card, you may still be able to connect to the VPN. Log into your computer with your network credentials (user ID & password), then insert your LincPass card into the reader and start the VPN (Network Connect or Proxy Connect). You ll be asked to enter your PIN. If you start the VPN without the LincPass card inserted, you ll see a message that says Missing certificate. Put your LincPass card in the reader and click the Connect button. NOTE: If you still see the missing certificate message, you may have to close the browser (not just the tab) and start it again for the system to recognize that the certificate is there. 25

Troubleshooting (continued) Other VPNs (e.g., Cisco) If you have other VPNs on your system and have questions about them, contact your Agency s IT help desk for assistance. If you re a system administrator, you may have other VPNs on your system for accessing remote servers and domains. The Juniper client doesn t replace them. Session expired If the VPN detects no activity for 15 minutes, the VPN will automatically log you off. If you were connected via Network Connect, click the link on your desktop again to start a new session. If you were connected via Proxy Connect, the system displays a Sorry, your session on the machine expired message. Click the Connect button to start a new session. 26

Where to Go for Help Your agency s Enterprise VPN User Guide has detailed instructions, troubleshooting tips, and more. If you need more help, contact your Agency s IT help desk. To request approval from your Agency to use the USDA Enterprise VPN service, contact your supervisor. 27

Review Introduction What is a VPN? About the Enterprise VPN Getting Started Two Connection Options Network Connect Proxy Connect Troubleshooting Where to Go for Help 28

Remote Access Using the USDA LincPass 29