Skip Navigation and banner
This site will look much better in a browser that supports web standards, but it is accessible to any browser or Internet device.
skip navigationUniversity of WyomingUniversity of Wyoming
UW Home  |  WyoWeb  |  UW A-Z Index  |  UW Directory  |  Search UW  
Information Technology home     Ask IT Home      UW Email      Computer Security Initiative      Computer Support      Computer Training 
 Hot Page: system status / virus info         IT Home          IT A to Z Index          Departments          About IT 
Ask IT home
 Search: 

 
 

Ask IT FAQs

UW-specific

WyoSecure VPN Frequently Asked Questions

VPN (virtual private network) service allows authorized users to securely connect to the UW data network from off-campus. Using VPN, remote users are connected to the University’s internal network as if they were directly connected to the campus network. This allows UW remote users to access servers and other resources that are restricted to UW network users and isolated from the Internet.

UW's WyoSecure VPN solution allows users convenient access to internal campus resources because most resources can be accessed via a Web application without the need to download and install client software.

Why do I need to use WyoSecure VPN?

If you are working remotely and need to connect to resources on the internal UW computer network, such as your work computer or file shares on university computers, you will need to use WyoSecure. This limits access to internal UW resources to users with authorized UW accounts.


What is "Core Access" and how do I use WyoSecure VPN from a Web page?

WyoSecure offers a web-based option (a.k.a. “Core Access”), so installation of client software (a.k.a. “Network Connect”) is not required in most cases.  The web-based option can be accessed by simply opening the webpage https://wyosecure.uwyo.edu. If you have problems, verify that you are using a supported operating system and browser combination.


What is the "Network Connect" client and how do I install it?

The Network Connect client is an IPSec based VPN client that functions like a traditional VPN client, such as the Cisco VPN clients. The Network Connect client gives the user an IP address on the campus network and allows access to internal resources using the following ports:

TCP: 80 and 443 (Web Traffic)
TCP: 3389 (Microsoft Remote Desktop)
TCP:22 (SSH/SFTP)
TCP:445 (IT-controlled file shares)
TCP: 1720 (and necessary UDP ports to H.323 public endpoints)
TCP: 5900 (VNC)

To install the Network Connect client:
sign into the WyoSecure site and click on the Start button next to Network Connect. This will install the Network Connect client on your computer. To use the Network Connect client, launch it from your computer.


What is the difference between accessing WyoSecure VPN using a web browser (Core Access) and using the client (Network Connect)?

“Core Access” is recommended, since it does not require the installation of a separate VPN client. It can be accessed from many different devices, such as public computers, handheld computers, phones equipped with Internet access, etc.  Core Access also has the advantage of "bookmarking" links that allow you to automatically connect to restricted internal websites (“Web Bookmarks”), UW file storage (“Files”), and remote desktops (“Terminal Sessions”).   You can add as many bookmarks as you like.  Some bookmarks are automatically created by the system based on your login credentials.  Single sign on capabilities allow the system to forward your username and password to other applications.

The “Network Connect” client is used when your remote computer needs to connect directly to resources behind the UW firewall.  For example, you can access files on warehouse.uwyo.edu using Core Access – but applications running on your remote computer cannot access the files directly.  The Network Connect client software creates a tunnel between your remote computer and the UW internal network, allowing applications on your remote computer to communicate directly with resources behind the UW firewall. You can use this type of access to install software on your remote computer or connect to a UW disk drive.


Why is Network Connect access into campus limited and how can I get expanded access?

Network Connect client access (as well as WyoSecure VPN web access) restricts access to internal UW computing resources to users with UW accounts.  However, without restricting the TCP ports reachable, legitimate users who access the UW network remotely from machines infected with viruses will still (unintentionally) be able to spread the virus to the UW network.  In order to provide expanded access and still prevent the spread of viruses to the UW network, expanded access is available using the Network Connect client.  In order to use the expanded access, the Network Connect client will check to ensure that the user’s remote computer is not a risk to the network. The checking varies with the operating system, but in general the remote computer will be checked for an active firewall and for up-to-date software patches and antivirus.  To use the Network Connect client with expanded access, launch the Network Connect client and replace the default sign-in page, https://wyosecure.uwyo.edu/, withhttps://wyosecure.uwyo.edu/expanded.

In addition to the default ports described under the FAQ “What is the Network Connect client and how do I install it?”, expanded access users will have access to the following port:

TCP:445 (Non-IT Managed File Shares)


For any given task, should I use Core Access or Network Connect?

The table below describes what tasks can be accomplished with each remote access method:

Desired task: Core Access or Network Connect?
Remote desktop Core Access or Network Connect (wyosecure.uwyo.edu)
Telnet or SSH Core Access or Network Connect (wyosecure.uwyo.edu)
Download files from IT file servers Core Access or Network Connect (wyosecure.uwyo.edu)
Access non-public websites Core Access or Network Connect (wyosecure.uwyo.edu)
Map drive to (or install software from) IT file servers Network Connect (wyosecure.uwyo.edu)
Map drive to (or install software from) non-IT file server Network Connect (wyosecure.uwyo.edu/expanded)
Use SAS, SPSS, VNC or H.323 Network Connect (wyosecure.uwyo.edu)



What are the timeouts for WyoSecure VPN?

WyoSecure will timeout after 2 hours of inactivity or 12 hours of login time. The remaining session time will appear in the toolbar after logging in.

SSL VPN toolbar


How do I create a remote desktop bookmark to my office computer when using Core Access?

If you are using a Windows operating system, click on the Add terminal service icon in the Terminal Session toolbar.

Add Terminal Service icon

In the Add Terminal Services Session window use the following configuration:

  1. Session Type: Windows Terminal Services
  2. Bookmark Name: Type a descriptive name for the bookmark
  3. Description: Type a useful description of the terminal connection
  4. Host: Enter the DNS name of the computer to which you are trying to connect.
  5. Username: Type your username or enter <user> to use the same username with which you logged into WyoSecure.
  6. Password: If you would like to enable single sign on (SSO) then enter <password> to use the same password with which you logged into WyoSecure.
  7. Click the Add button to save the bookmark.

This bookmark will be available whenever you sign into WyoSecure using Core Access.

Add Terminal Services Session window


Do I need to use WyoSecure to administer my systems in the DMZ?

Yes. Administration of DMZ machines must be performed from the campus network.


Do I need to use WyoSecure to edit my UW Web site from an off-campus Internet connection?

Yes. You must open the Web site share using WyoSecure VPN to upload content from off-campus.


How do I access files shares on campus when using Core Access?

Type the path of the file share in the format \\servername\sharename into the browse field and click the Browse button. For example, type \\warehouse\antivirus into the browse field to open the antivirus share on the warehouse server.

Browse field


What happens if I close the main web page that is presented after signing on to WyoSecure using Core Access?

As long as you do not “sign out” prior to closing the page, all resources you have accessed through the WyoSecure VPN server since signing on will remain available. However, it is recommended that you do not close this page until you are finished using the VPN server. When you are finished using the VPN server, please click on the “Sign Out” button – and then close the page.


What does it mean if I get a message stating "there are already other user sessions in progress"?

You can only have one WyoSecure session per username open at any given time.


Reviewed: 1009 By: MK, RM, GG

Additional help with the installation and configuration of UW-supported software is available:
Faculty/Staff
Contact your IT user consultant. (http://www.uwyo.edu/InfoTech/Support/uclist.asp)
Contact the IT Help Desk at 766-HELP (4357), option 1.
E-mail UserHelp@uwyo.edu.
Students
E-mail ASU-IT@uwyo.edu.
Contact the IT Help Desk at 766-HELP (4357), option 1.
Come to the student computer lab in the lobby of the Information Technology Center.


    Copyright © 1998-2009, University of Wyoming Information Technology • All rights reserved.