The VPN service supports the built-in Android VPN client without the need to install any third-party applications. However the built-in Android client requires careful configuration to set up securely, including manual installation of various certificates. Some users may find it more convenient to use the third-party strongSwan client as this is considerably simpler to set up (eliminating the need to manually install certificates), albeit requiring the installation of an additional application.
Note: the strongSwan client may not be compatible with all Android devices, but should work on Android 4.0+ (including 5.0). If you encounter problems with this application, we recommend you use the built-in Android client.
Before you begin, please ensure:
- You know your Network Access Username - typically your CRSid (username) followed by "@cam.ac.uk". For example, "firstname.lastname@example.org".
- You have your Network Access Token - either written down, or displayed on the screen of an adjacent device. This is a 16 character long password and is NOT the same as your University (Raven) password. You can find out your token by visiting the Network Access Token site.
- If you have been advised to use a Managed VPN, rather than the general University VPN service, you will need the VPN server hostname. Available VPNs and their server hostnames are listed on the Managed VPN page.
To set up the VPN service using the strongSwan client:
- Install the strongSwan VPN Client application from the Google Play Store using the link.
- From the home screen go to the Apps Menu:
- Find the new strongSwan application and start it:
- You will be presented with the strongSwan status screen, listing the configured VPN profiles (which will initially be empty). Press the Add VPN Profile button at the top:
- You will be prompted to give details of the profile (connection). Enter the details as follows and then tap Save:
- Profile Name: Cambridge VPN
- Gateway: vpn.uis.cam.ac.uk or, if you are using a Managed VPN, use the VPN server hostname instead
- Type: IKEv2 EAP (Username/Password) (this should be the default option)
- Username: CRSid@cam.ac.uk (as displayed on the Network Access Token website - note the "@cam.ac.uk" suffix)
- Password: (16 character Network Access Token) (available from the Network Access Token website)
- CA certificate: Select automatically (the default)
- You will be returned to the strongSwan status screen and the new profile will be displayed. Tap on the profile (Cambridge VPN) to connect:
- You will receive a warning that the strongSwan VPN Client wishes to set up a VPN connection that allows it to monitor network traffic. This warning is normal and just Android advising you that your network connection will be redirected over the VPN. Tap OK to continue with the connection:
- The connection should now be established and this displayed on the status screen. A key symbol will also be displayed in the status bar at the top of the screen to remind you:
To disconnect, run the strongSwan application and select Disconnect in the status area:
Whenever you wish to reconnect to the VPN, start the strongSwan application and select the Cambridge VPN profile.