skip to content

IT Help and Support

University Information Services

Configuring the UIS VPN service on Android

The following instructions are for Android 9 and below.

If you would like to use the VPN on an Android 10 device, please follow the instructions for the strongSwan client.

Before you start, you will need to know:

  • your Network Access Token username and password
    – create your token on the UIS Network Access Tokens site and keep the window or tab open – perhaps in an adjacent screen on a separate device – in readiness for when you'll need to copy the username and password.
  • If you have been advised to use a Managed VPN, rather than the general University VPN service, you will need the VPN server hostname.  Available VPNs and their server hostnames are listed on the Managed VPN page.

To set up the VPN service:-

  1. Using the web browser on your Android device (Chrome or other browser), download the VPN client identity file (you do this by either visiting this page on your device and selecting the above link, or by directly entering the above web address). You may be asked which program you wish to use to open the file - if so, select Chrome (if installed) or your web browser.
  2. You will be prompted to enter a password to extract the certificates in the file. Enter the password "vpn" (note lower case, without the quotes) and tap OK:
    extracting certificates
  3. You will now be asked to name the certificate and confirm its installation. The default name of Cambridge VPN client identity and and use (VPN and apps) should be as shown and can simply be acknowledged with OK. At this point you may be prompted to enter the passcode or PIN; if you are, enter the code used to unlock your Android device:
    name the certificate
  4. Using your web browser download the VPN server certificate.
    Alternatively, if you are using an institutional Managed VPN, you should select the server certificate (at the bottom of the Managed VPN Service for Institutions page) that corresponds to your institution.
  5. You will be prompted to name this certificate. This time, the name will be blank and you should enter 2019 and tap OK.  Alternatively, if you are using a Managed VPN, substitute this for the VPN server hostname followed by the current year (e.g. " 2015").
    Note that the year is required, as the certificate must be periodically updated (typically every 2-3 years) and it is necessary to record which certificate was stored:
    name the certificate
  6. Go back to the Home screen (via the house button [Android 4.x] or the circle [Android 5.0] under the screen).
  7. From the home screen go to the Apps Menu:
    home menu
  8. Find the Settings application and start it:
  9. In the Wireless & Networks section at the top select More...:
    More setting
  10. On the menu which appears, select the VPN option:
    VPN option
  11. You will see a list of configured VPN services (most likely be empty at this point). Tap the + (Add) button in the top right corner:
  12. A box will appear, prompting for details for the VPN service. Enter the details as follows and tap Save:
    • Name: Cambridge VPN
    • Type: IPSec Xauth RSA
    • Server address: or, if you are using a Managed VPN, use the VPN server hostname
    • IPSec user certificate: Cambridge VPN client ID (this will match the name entered when adding the user certificate earlier)
    • IPSec CA certificate: (don't verify server) (the default)
    • IPSec server certificate: 2014 (this will match the name entered for the server certificate earlier: if you are using a Managed VPN, you should select the certificate you stored, instead)

    Add details

  13. The list of VPN connections will return, with the new connection now displayed:
    VPN list
  14. Tap on the new connection (Cambridge VPN) and the connection box will be displayed, prompting for your username and password. Enter them as shown below and press Connect:
    • Username: The username for the Network Access Token you made for this device. It will be in the format – for example,
    • Password: The password for the Network Access Token you created for this device.
    • Save account information: Check (to remember your username/password)

    Connection dialogue

  15. If the connection is successful, the VPN connection list will show Connected under the Cambridge VPN entry and a key symbol displayed in the top left corner of the screen:
  16. The key symbol will remain on screen whilst you are connected. If you pull down the Notification Area (by dragging down from the top left of the screen in any application) you will see the connection listed:
    Connection list

To disconnect

To disconnect, drag down the Notification Area and tap the connection. Then tap the Disconnect button:
Disconnect buttton

To reconnect

Whenever you wish to reconnect to the VPN:

  1. From the home screen, select the Apps Menu
  2. Run the Settings app
  3. Under Wireless & Networks, select More...
  4. Tap the VPN option
  5. Tap the Cambridge VPN to bring up the Connect box
  6. Tap Connect

Last updated: 1st December 2017

UIS Service Desk

UIS Service Status

Phone padded  Service status line: (01223 7)67999
Website  Sign up for SMS/email status alerts
Website  Read major IT incident reports

UIS bITe-size bulletin

A regular newsletter aimed at the University's IT community, highlighting service and project news from UIS.

Sign up >

Latest news

University Wireless Service maintenance: Tuesday 21 September, 08:00–09:00

16 September 2021

The University Wireless Service will be undergoing essential maintenance between 08:00 and 09.00 on Tuesday 21 September while we apply a security software patch. This is a security update to ClearPass, which provides Wireless Service network access control. We're not expecting any disruption to service, but it should be...

Mailing list migrations from Mailman to Sympa

31 August 2021

We intend to migrate all remaining lists associated with colleges from Mailman to Sympa during the week commencing 13 September 2020. The current total is 1,567. How this will affect users of the mailing list management service Most mailing list subscribers shouldn't notice any difference. During the switchover, there will...

Managed Zone Service closedown and migration to Mythic Beasts

24 August 2021

The Managed Zone Service (MZS) is being shut down, and its data content migrated to a commercial provider, Mythic Beasts. There will be no interruption to the service, but MZS users in institutions will need to make arrangements to retain management access to their zones. What is changing? UIS set up the MZS many years ago...