VPN Activity Review A growing service which should be fully supported by Computing Services
Description:
CISCO 3030 VPN Concentrator. Two 3030's located in A84 machine room ... We have found mixed information on this from CISCO and other sources. ... – PowerPoint PPT presentation
Appears to use as part of Network Registration System
9 Is the Service Unique? No
CMU CS SEI (PKI)
Dartmouth (PKI)
University of Virginia (PKI)
Duke
Georgetown in Qatar
Harvard
MIT
New York University
Pennsylvania State University
ULCA Berkeley
Rice University
Oregon State University
University of Colorado Boulder
University of Delaware
University of Michigan
University of Minnesota
University of Southern California
University of Texas at Austin
University of Wisconsin
University of Chicago
Colorado State University
University of Florida
UC Irvine
Seattle University
10 VPN Usage Totals 11 VPN Sessions by Department 12 VPN Clients by Department 13 VPN Hours by Department 14 User Mechanics/Experience
Download VPN client and instructions
https//www.cmu.edu/myandrew/
Register client and create/download certificate
https//netreg.net.cmu.edu/
Install client software on machine
Install certificate
Edit connection profile
Use it
15 VPN Support Process
Currently DSP, ACIS, other department support groups are handling First Level Support
Help Center has handled some First Level Support
Second Level Support has been handled by Network Development Group.
Limited Consulting has been done by ISAM for DSP
16 VPN Support Process (cont) Help Center Remedy IncidentsMarch 2005 through November 2005
CISCO VPN Client
1 Accounts
33 Setup
16 Usage
50 Total
IP Address Extension
4 Accounts
77 Setup
39 Usage
120 Total
Note IP Address Extension statistics shown for comparison purposes 17 VPN Support Issues
Road Warrior Usage Problems
User may need to try both TCP and UDP configurations
Due to ISP configuration issues
Some ISPs NAT policies do not permit VPN traffic
Some ISPs filter policies do not permit VPN traffic
Some Conflicting use of private (RFC1918) addresses
18 VPN Support Issues (cont.)
Many Novice Users are not able to follow the installation instructions. It is a little too technical for some.
There have been cases related to the Windows XP Firewall with the installation and use of the software. We have found mixed information on this from CISCO and other sources. We are investigating further.
19 VPN Support Issues (cont.)
The Andrew Domain Design has caused some issues in regards to certain configurations. They include User Profile Use, Folder Redirection, Home Folder Creation
These are specific to Department Group Policy Design
DSP Results from Windows Domain Configuration Issues
Removed User Profile Use from Domain Users
Are phasing out Folder Redirection for Domain Users
Removed the Home Directory Configuration
Migrated to Login Scripts with a Mapped Drive Configuration like used in many businesses
20 CISCO VPN Support Issues
CISCO 3030 support
Multiple firmware image upgrades
To resolve WEBSSL java problems
To resolve WEBSSL crashing problems
CISCO client software support
Multiple client software upgrades
Has resolved some problems
Currently two documented bugs that are not fixed both related to Disconnect problems
Lack of understanding of related windows configuration issues
21 Expected Service Growth
ACIS has phased out internal VPN service
IP Address Extension Service phase out plans
Departmental Needs Appearing to Grow
ISO and others see growing need for service
ISAM use for A100 service subnet plans
FMS/ACIS access to private VLANS
22 Future Support Needs
Network Development/Engineering
Ongoing support of the concentrator
Ongoing Client Support
ISAM
Operating system specific support
Windows Firewall
Active Directory GPO settings
Escalation of installation issues from Help Center for Windows and MAC
23 Future Support Needs (cont.)
ACIS
Application specific support related to products
Connection issues documented related to servers
ISO
Security related issues pertaining to the VPN
Oversight as to when the VPN should be used and the security benefits it provides
24 Future Support Issues
VPN Service Support Issues Summary
VPN Service is needed by some
VPN Service is expected to grow
VPN Service needs more complete support within Computing Services to be a fully supported service
PowerShow.com is a leading presentation sharing website. It has millions of presentations already uploaded and available with 1,000s more being uploaded by its users every day. Whatever your area of interest, here you’ll be able to find and view presentations you’ll love and possibly download. And, best of all, it is completely free and easy to use.
You might even have a presentation you’d like to share with others. If so, just upload it to PowerShow.com. We’ll convert it to an HTML5 slideshow that includes all the media types you’ve already added: audio, video, music, pictures, animations and transition effects. Then you can share it with your target audience as well as PowerShow.com’s millions of monthly visitors. And, again, it’s all free.
About the Developers
PowerShow.com is brought to you by CrystalGraphics, the award-winning developer and market-leading publisher of rich-media enhancement products for presentations. Our product offerings include millions of PowerPoint templates, diagrams, animated 3D characters and more.