Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Stanford university is using different VPN protocols and technologies, so the SLAC VPN client can't be used to connect to Stanford through VPN. But when connected to SLAC VPN you can reach Stanford ressources as if you were in your office at SLAC.
If you are a SLAC employee/user willing to access SLAC ressources you should use SLAC VPN, if you are a Stanford university employee/student you should use the Stanford VPN client provided on http://itservices.stanford.edu/service/vpn.

 

Issue connecting to SLAC vpn gateways with Samsung Galaxy devices

1/8/2015: There is an issue with Samsung Galaxy devices having trouble to successfully validate VPN gateways' SSL certificates. When trying to connect to vpn.slac.stanford.edu with the Cisco anyconnect client, or when trying to go with a browser to https://vpn.slac.stanford.edu the device will complain that the certificate is invalid (unknown CA message or alike). Some old systems (Windows XP) may also have similar issue.

This is because on these devices the default keystore is currently missing some intermediate certificates, particularly the one used by thawte to issue SHA-256 certificates (CA issuer name cn=thawte SSL CA - G2).

To have this fixed just go to http://thawte.tbs-certificats.com/thawte_tj.crt with a web browser, it then will ask a name for this certificate. Put something like "Thawte SHA256" and then valid. The cert will be automatically imported in the keystore.

Then if you try to go to https://vpn.slac.stanford.edu or if you try to connect to the SLAC VPN gateways with the cisco anyconnect client it will work without issuing a warning.