Table of Contents
VPN via eduVPN
What is eduVPN?
eduVPN makes it possible to use university resources securely and easily from home. Users only need to install an app and log in with their university account. A virtual private network (VPN) extends the university network over the public internet and allows users to send and receive data securely over public networks. It is as if your device is directly connected to the university network.
It is strongly recommended to use eduVPN with the apps of the same name and not to set it up manually, as a specific configuration is only valid for 16 hours at a time.
The most important differences to Cisco AnyConnect
- eduVPN can only be used if you have set up a 2nd factor via id.academiccloud.de/security
- You can find the instructions for setting up the 2nd factor at https://docs.gwdg.de/doku.php?id=de:services:general_services:customer_portal:security:two_factor_authentication
- for computers with TouchID, a fingerprint is recommended as the 2nd factor; however, the eduMFA app https://play.google.com/store/apps/details?id=io.edumfa.authenticator&pcampaignid=web_share or https://apps.apple.com/us/app/edumfa-authenticator/id6479982721?platform=iphone on the smartphone also works very well
- you can (and should) store several 2nd factors in case one is not (or no longer) available
- A new login is required every 16 hours
- eduVPN is significantly faster in “Wireguard” mode
- Cisco AnyConnect will be switched off on 31.01.2025; after that only eduVPN can be used
Setting up eduVPN
Please first enter the 2nd factor for the student account at id.academiccloud.de! Login, click on “Security” and set up a 2nd factor such as a passkey (TouchID, FaceID) or an authenticator app on your phone such as eduMFA
Download and install
At https://www.eduvpn.org/client-apps/ you will find the necessary programs/apps for the usual platforms
- select the operating system of your device (Windows, macOS, Linux, Android, iOS) and click on the corresponding download link to download the installation file.
Windows
- Open the downloaded file to start the installation process
- Follow the instructions of the installation process
- then start the eduVPN application and follow the illustrated instructions below
macOS
- Click on the link provided. This link should take you directly to the eduVPN app in the App Store
- click on the “Download” button to start the download and installation
- tap on the eduVPN icon to open the app. You must agree to the changes and privacy policy; then follow the illustrated instructions below
iOS/Android
- download the app from the relevant app store; the eduVPN app is also available in various alternative stores such as F-Droid
- then follow the illustrated instructions below
Linux
- install the app according to the instructions for your Linux version: https://docs.eduvpn.org/client/linux/installation.html and follow the illustrated instructions below
- the Linux app uses the NetworkManager to manage the VPN tunnels and thus integrates harmoniously into most Linux distributions
- In addition to the graphical application, the packages also include the command line tool eduvpn-cli. This makes it very easy to integrate the tunnel setup into your own workflows.
- Please note: It is not possible to do without the 2nd factor! An unattended tunnel rebuild is not intended for security reasons!
Using the app
- Start the application.
- type in the displayed search field: university of göttingen
- then click on the entry that appears:
- you will be redirected to the AcademicCloud login; please log in there as usual:
You must already have entered a second factor here. If you are asked to select an “additional login factor” but the list is empty, you have not yet done so. Please enter a second factor at id.academiccloud.de/security.
- On the website that then appears, simply confirm the login with 'Approve':
- now you can close the browser window
- and you should see a selection dialog for several profiles in the eduVPN
- in rare cases it is necessary to click on 'University of Göttingen and GWDG' again
- select the desired profile:
- OpenVPN students - proven VPN connection based on the 'OpenVPN' protocol; works in almost all external networks
- Wireguard students - modern VPN connection based on the 'Wireguard' protocol; requires significantly less processor time and is often slightly faster; does not work in all third-party networks/is often blocked
Why do I have to log in again after 16h?
- for security reasons, it was decided that possession of the 2nd factor should be verified once a day
- an expiration after 24h ensured in test operation that the expiration regularly happened the next day in an important conference, therefore the time was set to less than 24h but significantly longer than a 'working day'
- expiration of logins 'every night at 4 a.m. Western European time' is impractical for users in other time zones
I use other Academiccloud accounts in parallel
It can be very frustrating to juggle two SSO (single sign-on, one login for (almost) everything, like Academiccloud) accounts in one browser. Since eduVPN is currently only released for students and not for employees, this is also relevant here. The solution under Firefox is called: Containers
With containers, you can use two different, separate sessions in the browser and thus run two different SSO accounts, for example.
Installation of Firefox containers
- open “Add-ons and Themes” in the Firefox menu
- search for Firefox Multi-Account Containers
- install the extension
- open the extension in the menu and go through the introduction
- under “Manage containers” you can give your study container a nice name, color and a suitable symbol
- you can now hold down the “Plus” button to open tabs and define a container once for new pages
- if you want the login page for eduVPN to always open in the “Study” container, then open https://eduvpn.gwdg.de in a new tab and log in
- Now click on the symbol for “Always open this page in a container”
- you can now log in again or not, it doesn't matter
- now the login for eduVPN is always opened in this container and other open Academiccloud accounts no longer have to frustrate you!
- You can recognize a container by the fact that the tab is highlighted in color and the container name is in the search bar