Northern Illinois University

Information Technology Services

VPN Troubleshooting

Account and Password

You need an NIU Z-ID / AccountID and password to access the VPN.

Z-ID / AccountID - If you don't know your Z-ID / AccountID, call the ITS Helpdesk at 815-753-8100.

Password - If your password doesn't work, it may not be synchronized for the service you need.

The provisioning and password checker web pages below are only available once a secure connection is established. Connect to the wired network or use a system that has access to these pages (e.g. ITS lab computers) to see these pages. If your password is not synchronized, reset it at password.niu.edu .

How to choose a client

Wireless/Open Line client - used on campus in areas that have wireless or publicly accessible network jacks. This client secures all network traffic. You receive an NIU IP address (131.156.x.x). This connection has the most amount of overhead because all traffic is encrypted.

Off Campus client - for customers who need a secure connection back to NIU. All traffic that is not bound for the 131.156.x.x network is routed through the customer’s ISP. This connection has the least amount of overhead since only NIU bound traffic is encrypted. Examples of Off Campus connections: Computer Science students who encrypt their mainframe/MVS program submissions, customers who FTP files to a computer on campus who want their plain text password encrypted over the Internet.

Using another client - You can use a PPTP client that supports MS-CHAP2 authentication. A compatible PPTP client is built into Windows XP and 2000. Any additional third party clients are not supported by ITS.

Firewalls

Firewalls must be set to not block the necessary ports for PPTP / VPN. Make sure the box next to VPN or PPTP is checked.

The following addresses /names must be "trusted" by the firewall:

  • vpn1.ess.niu.edu
  • 10.112.0.0 through 10.255.255.255
  • 127.0.0.1
  • Norton Internet Security requires 131.156.169.2 to be allowed

Known Issues

Error #51 - Attempting to run VPN client version 4.8 on an Intel based Mac. Upgrade to version 4.9.

Browser only displays securenet website - If a browser is opened before the VPN client is connected, all websites will be resolved to securenet.niu.edu. The VPN client must be working and the DNS (Domain Name System/Service) cache (not the temporary internet files cache) cleared. This only applies to sites that were visited before the VPN client was connected. Clear the DNS cache by using the /FLUSHDNS option with the IPCONFIG command:

  1. Click Start->Run in the “Open:” field type “CMD”
  2. At the command line (C:\>) type “ipconfig /flushdns”. A message indicating the DNS cache was flushed should appear.
  3. Type “exit” to close the command line window. Browser sessions may still need to be closed for websites to resolve properly.

"Must disable ICS" error with Windows XP Professional or Home Edition -

  1. Right Click on My Computer and select Manage > Services and Applications
  2. Select Services > Internet Connection Sharing located under ICS Firewall
  3. Disable Load on Startup. IPSec is also found under Services.
  4. Restart your computer

Windows Vista Restrictions - the VPN Client for Windows Vista does NOT support the following:

  • System upgraded from Windows XP to Vista (clean OS installation required)
  • Start Before Logon
  • SmartCard Authentication
  • Integrated Firewall
  • InstallShield
  • 64bit support
  • AutoUpdate
  • Translated Online Help - Provided only in English

Frequently Asked Questions

Common questions and answers

Q: Where is wireless or open line access available at NIU?
A: See Connection Locations.

Q: Why can I only see this web site?
A: All requests for web pages are directed to this site until the VPN client is installed. Once a user is authenticated, via the client, full access to the World Wide Web is given.

Q: Who can use the VPN client and NIUnet?
A: NIUnet is a resource for NIU students, faculty, staff.

Q: How do I find my Z-ID / AccountID?
A: Call the ITS Helpdesk at 815-753-8100.

Q: Can I use another VPN client to connect to NIUnet?
A: Yes, you can use a PPTP client that support MS-CHAP2 authentication. A compatible PPTP client is built into Windows XP and 2000. Any additional third party clients are not supported by ITS.

Q: Why do I get an authentication error when using PPTP even though I can login to other university resources with my account?
A: If your password doesn't work, it may not be synchronized for the service you need.

Q: What is the maximum connection time for the Cisco VPN client?
A: A Cisco VPN client connection will be automatically disconnected after 30 minutes of inactivity or 24 after hours.

The provisioning and password checker web pages below are only available once a secure connection is established. Connect to the wired network or use a system that has access to these pages (e.g. ITS lab computers) to see these pages.