In Windows XP, how do I make an IPsec or PPTP VPN connection to the IU network?
Note: When connecting from off campus, SSL VPN is the replacement for IU's IPsec- and PPTP-based VPN services, and UITS recommends using it now if your campus supports it. PPTP is retired at IU Bloomington and IUPUI, and IPsec VPN service at those campuses will be retired by fall 2010.
IU Secure is the wireless network for students, faculty, and staff to access when on campus. IU Secure uses WPA2 Enterprise (Wi-Fi Protected Access) for authentication; no VPN is needed. IU Northwest will have IU Secure by spring semester 2010; it is available at all other campuses except IPFW.Before you start: If you are behind a NAT device (e.g., a home or small business router) or your IP address is a private IP address, you must download an update from Microsoft before you can successfully connect using an IPsec VPN connection. To determine if this situation applies to you, refer to For Windows 2000, XP, or Vista, how do I download and install the L2TP/IPsecNAT-T update?
This document explains how to manually set up an IPsec or PPTP VPN connection in Windows XP at Indiana University Bloomington and IUPUI. If you wish to make such a connection, UITS recommends that you use the VPN installers, available from IUware Online. This software automatically does what the instructions in this document describe how to do manually.
On this page:
- Introduction
- Creating an IPsec or PPTP VPN connection
- Configuring your VPN connection
- Establishing the VPN connection
Introduction
Note: IU's VPN is intended for individual computing accounts only. Group and departmental accounts cannot access the VPN. See Why can't I make a VPN connection through an IU group or departmental account?
Creating an IPsec or PPTP VPN connection
To create an IPsec or PPTP virtual private network (VPN) connection to the IU network using Windows XP, either wirelessly or remotely:
- In the Windows XP default view, from the
Startmenu, right-clickNetwork Placesand selectProperties. In Classic View, from theStartmenu:
- Click
Settings, and thenControl Panel. - In the
Control Panelwindow, if "Pick a category" appears in large print, on the left frame in the "Control Panel" section, clickSwitch to Classic View. - In the main window, you should now see all the control
panels. Double-click
Network Connections.
- Click
- In the left frame in the "Network Tasks" section, click
Create a new connection.Note: If you do not see "Network Tasks", look for
New Connection Wizardin the main window, and double-click it. You also may go to theFilemenu and chooseNew Connectionthere. - The
New Connection Wizardshould open. ClickNextand selectConnect to the network at my workplace. ClickNextagain.
- Select
Virtual Private Network connectionand clickNext.Note: If the
Virtual Private Networkoption is not available, you may need to enable the Remote Access Connection Manager service; see In Windows 2000 or XP Professional, why is the option to create a VPN connection unavailable? - Type a name for the connection (e.g.,
IU-VPN) and clickNext. You can enter any name you wish.
-
Note: If your computer already has a
Dial-Up Networkingicon, at this point you may see the following message:
If you don't see the above message, proceed directly to the"Windows can automatically dial the initial connection to the Internet or other public network before establishing the virtual connection".
VPN Server Selectionwindow (see step 7). If you do see the message:
- In the
Public Networkwindow, you must tell Windows what public network connection you will use to attach to your VPN:
- If you are connected to a persistent Internet
connection (e.g., Ethernet), choose
Do not dial the initial connection. - If you must dial in to be connected to the Internet, choose
Automatically dial this initial connectionand select your Internet service provider (ISP) connection.
- If you are connected to a persistent Internet
connection (e.g., Ethernet), choose
- Click
Next.
- In the
- In the
VPN Server Selectionwindow, type the name or IP address of the VPN server, and then clickNext.Use the table below to find your VPN server for both remote (e.g., cable modem, DSL, or outside Internet service provider) and wireless VPN connections:
Campus VPN server
IU Bloomington ipsec.indiana.eduIU East vpn.iue.eduIU Kokomo vpn.iuk.eduIU Northwest 149.162.8.2IUPUI ipsec.iupui.eduIU South Bend vpn.iusb.eduIU Southeast vpn.ius.edu - At this point, you may see the message:
Choose"You can configure this connection to use your smart card to log you into the remote network. Select whether to use your smart card with this connection".
Do not use my smart cardand clickNext.
- In the
Connection Availabilitywindow, select the option most appropriate for your situation. ClickNext.Note: If you are using a wireless card and wish to log into a domain (including ADS) upon starting Windows XP, you must select the
Anyone's useoption. Selecting this option will make the VPN connection available when you chooseLog on using dial-up connectionat the login screen. - On the last screen, if you want a shortcut icon on your
desktop for the new connection, select
Add a shortcut to this connection to my desktop. ClickFinish.
Configuring your VPN connection
To properly configure your VPN connection:
- After you've created your VPN connection, Windows XP should open
the connection automatically for you. If it does, select
Properties. If it does not, right-click the new connection icon, and then selectProperties.
- Click the
Optionstab. CheckPrompt for name and password, certificate, etc.andInclude Windows Logon Domain.
- Click the
Networkingtab. If you're on the Bloomington or Indianapolis campus, set "Type of VPN:" toL2TP IPSec VPN. If you're on any other campus, set it toPPTP VPN.
- In the "This connection uses the following items:" field, only the
following should be checked:
Internet Protocol (TCP/IP)File and Printer Sharing for Microsoft NetworksClient for Microsoft NetworksQoS Packet Scheduler
- Select
TCP/IP, and then clickProperties.
- Select both
Obtain an IP address automaticallyandObtain DNS server address automatically, and then clickOK.
- Click the
Securitytab.
- If you selected
PPTP VPNin step 3 above (i.e., if you set "Type of VPN:" toPPTP VPN), skip ahead to step 10.If you selected
L2TP IPSec VPN, clickIPSec Settings...and proceed to the next step. - Check
Use pre-shared key for authentication. Then, in the "Key:" field, typehermanbwells. ClickOK.
- Select
Advanced (custom settings), and then clickSettings....
- Under "Logon Security", select
Allow these protocols, and make sure the only checkbox selected isMicrosoft CHAP Version 2 (MS-CHAP v2). ClickOKand thenClose.
Establishing the VPN connection
To establish a VPN connection:
- After configuring your VPN connection, you should be back to the
authentication screen for your new connection. If not, get
there by double-clicking the new connection icon. Or, in XP's default
Startmenu, clickStart, thenConnect To, and finally the name of the connection. In XP's ClassicStartmenu, clickStart, thenSettings, thenNetwork Connections, and finally the name of the connection.
- You will see a place to enter a username, password, and
domain. Enter your IU Network ID credentials, and in the
domain field, enter
ADS. ClickConnect.Note: It may take up to a minute to establish a connection with the VPN server. Please be patient. If you have problems connecting, note any error messages and contact your campus Support Center.
- When the connection is established, you should see a new icon in
the system tray. This icon is identical to the one for dial-up
connections.
- To disconnect and terminate the connection, double-click the icon
in the system tray and choose
Disconnect.
Last modified on October 12, 2009.







