VPN FAQ

VPN FAQ

This is a generalized FAQ with regards to the UCSB Campus VPN

A small reminder that the Engineering Computing Infrastructure (ECI) is not directly responsible for the Campus VPN and we can only give Best Effort Support with regards to the VPN.

VPN server status is one of the reported services at https://status.ucsb.edu/ and you can always check your connection status with https://next.noc.ucsb.edu/ip.

If you cannot find the answers here, you are urged to contact UCSB Information Technology Services (ITS) at:

For additional support or Troubleshooting, you can contact ITS support at:


Where to get Campus VPN

You will want to go to the following webpage:

Download the appropriate client for your machine or device, please note that you may have to download a configuration file.  Instructions for how to install are also provided on this page.


What are the requirements?

As outlined from:

You will need the following:

  • A UCSBNetID

  • An internet connection (Wireless, Dialup, DSL, or Cable Modem)

  • The VPN client for your computer or device OS installed.

  • A supported operating system

  • The Duo two factor authentication app on your phone or a keyfob with a button to push from ITS.


VPN FAQ

ITS has an FAQ for the VPN listed here at:


 

Known Common Issues

We have noticed some of the following issues:

more are listed at Why is my VPN (Virtual Private Network) not Working?

User did not Wait Long Enough...

Please wait 60 seconds after seeing the green arrow appear on the orange Ivanti VPN key icon before trying to connect to secure services.

VPN Version is too Old to Connect...

If you still have a a green S icon for pulse secure or a blue T icon for Tunnelblick you should uninstall your current VPN then install the latest UCSB campus VPN version

https://it.ucsb.edu/services/ivanti-campus-vpn

Connect Button is not Showing...

Quit UCSB VPN application and relaunch it, either via status bar or applications/programs for mac/pc, then click ok.

If connect button is still not showing, right click on UCSB Remote Access, then click Connect

This is often the result of having recently installed a VPN update or a system security update. A restart may be required to permanently fix this issue. 

Failed to Setup Virtual Adapter...

 

  1. If you did not click ok on first launch, you will have to take the following steps on a Mac to run the VPN

  2. Click the Apple menu at the top left of your desktop.

  3. Click System Preferences.

  4. Click Security & Privacy.

  5. Click the lock to make changes (if you are on Catalina, otherwise skip this step as unlocking is not required).

  6. Click the General tab.

  7. Under Allow apps downloaded from, select App Store and identified developers

  8. Look for the following message: System software from developer "Pulse Secure LLC" was blocked from loading.

    1. Note that Pulse Secure is the older version of Ivanti but the error message will still say “Pulse Secure” if you previously had Pulse secure and upgraded in place rather than doing a clean reinstall. If you keep having issues, you might want to do a full uninstall and reinstall of the application. Be sure to click “no” when it asks to save configurations otherwise it will carry forward old cruft from older versions of the VPN.

  9. Next to the message click Allow to enable the extension.

  10. Close the Security & Privacy window.

  11. The kernel extension has been authorized and full functionality of the VPN client should be available.

No Push Notification From Duo...

Typing the word 'push' (without quotes) in the VPN client secondary login field should result in a Duo Push being sent to your 1st registered device.

You may also open the DUO app on your phone, go to UCSB, and click on it (or arrow next to it). A 6 digit number will appear that you can use to login to the VPN.

GUS Freezes while I am using the VPN...

The campus VPN has an idle timeout of 60 minutes and a max session of 720 minutes (12 hours). GUS' encrypted communications are not recognized as user activity. It is recommended you do some non encrypted activity every 30 minutes such as checking your email in order to avoid idle timeouts. If GUS

I can't connect to the machine...

If you are having issues connecting to the machine in question, you may want to test your connection while next to the machine in question...  Often times it may be more directly related to how your computer is setup.

For example, If you are trying to do Remote Desktop Connection to a Windows computer, you may not have Remote Desktop Enabled or the Windows Firewall may be configured on the computer to block.

Firewalls need to be configured to allow the following subnets for whatever service you are trying to access that is blocked by the Campus Border:

  • 128.111.61.0/24 (128.111.61.1-128.111.61.254)

  • 128.111.64.0/22 (128.111.64.1-128.111.67.254)

  • 128.111.180.0/22 (128.111.180.1-128.111.183.254)

  • 128.111.188.0/22 (128.111.188.1-128.111.191.254)

Campus VPN range was expanded multiple times in March 2020 by to include the 65-67, 180-183, and 188-191 subnets 

 


 If this does not help you, please contact ITS VPN support using one of the following options:

  • For Immediate Assistance: Call the ITS Service Desk at (805) 893-5000 (or x5000 from a campus phone). The ITS Service Desk is available Monday through Friday from 8:00 AM to 8:00 PM.

  • Live Chat: Visit http://ithelp.ucsb.edu and click the chat icon in the lower-right corner of your screen.

  • General Inquiries: Email the service desk at techhelp@it.ucsb.edu. (Please note: Email responses may be delayed. For urgent VPN issues, please call or chat).

 

Related Articles