{"id":20590,"date":"2025-02-12T10:14:26","date_gmt":"2025-02-12T17:14:26","guid":{"rendered":"https:\/\/in.nau.edu\/its\/?page_id=20590"},"modified":"2025-02-13T10:14:44","modified_gmt":"2025-02-13T17:14:44","slug":"2025-vpn-updates","status":"publish","type":"page","link":"https:\/\/in.nau.edu\/its\/2025-vpn-updates\/","title":{"rendered":"Updates to NAU&#8217;s VPN Authentication"},"content":{"rendered":"<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h6 style=\"opacity: 0.5; text-align: center;\">News &amp; Updates \u2022 February 17th, 2025<\/h6>\n<h4 style=\"text-align: center;\">Updates to the authentication process for NAU&#8217;s VPN through Cisco Secure Client<\/h4>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-60px not-in-view\">\n<img loading=\"lazy\" decoding=\"async\" class=\"wp-image-20594 aligncenter\" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/globe-secure-600x551.png\" alt=\"\" width=\"187\" height=\"183\" \/><\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<p style=\"text-align: center; line-height: 80%;\"><span style=\"font-weight: 600; font-size: 1.2rem; opacity: 60%;\">Authentication with Cisco Secure Client will now include NAU&#8217;s official authentication process.<\/span><\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-60px not-in-view\">\n<p>Beginning on February 17th, users will notice a change in the authentication process when connecting to the NAU VPN through the Cisco Secure Client application.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-20598 aligncenter\" style=\"border-radius: 20px; box-shadow: 2px 2px 5px rgba(0, 0, 0, 0.2);\" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/SCR-20250212-issj-600x368.png\" alt=\"The Cisco secure client interface, ready to connect to 1NAUVPN (NEW).\" width=\"550\" height=\"338\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/SCR-20250212-issj-600x368.png 600w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/SCR-20250212-issj-300x184.png 300w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/SCR-20250212-issj-1024x627.png 1024w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/SCR-20250212-issj-768x470.png 768w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/SCR-20250212-issj.png 1084w\" sizes=\"auto, (max-width: 550px) 100vw, 550px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 600; font-size: 1.2rem; opacity: 60%;\">The Cisco Secure Client interface before connecting to the VPN<sup>1<\/sup>.<\/span><\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<p>With this change, when a user clicks to connect to the VPN, a browser window will open with NAU&#8217;s standard CAS login screen, prompting the user to enter their NAU credentials. Once a user enters their NAU username and password, a Duo authorization page will appear with a three-digit code for users to enter into their approved Two-Step Verification mobile device.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-20697 size-uncropped-large\" style=\"border-radius: 20px; box-shadow: 2px 2px 5px rgba(0, 0, 0, 0.2);\" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-600x476.png\" alt=\"\" width=\"600\" height=\"476\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-600x476.png 600w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-300x238.png 300w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-1024x813.png 1024w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-768x610.png 768w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-1536x1219.png 1536w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/updated-saml-2048x1626.png 2048w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-weight: 600; font-size: 1.2rem; opacity: 60%;\">Cisco Secure Client and the prompted login screen.<\/span><\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<p>After the user completes the login process by entering their credentials and approving the authorization prompt in Duo, the connection to the VPN will complete, and the browser window will close.<\/p>\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Why is this change happening?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Why is this change happening? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>NAU is moving to a more secure method for authentication for the VPN service, and is retiring legacy methods that are no longer supported by our partners due to security and compatibility concerns.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"What if I use a Two-Step Fob to authenticate?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>What if I use a Two-Step Fob to authenticate? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>If you use a Two-Step FOB, you&rsquo;ll authenticate in the same way you do for existing NAU web services that require Duo authentication. When prompted to authenticate into Duo, select &ldquo;Hardware Token&rdquo; (if necessary), enter in the code found on your Two-Step FOB, and then select &ldquo;Verify&rdquo;.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"My Cisco Secure application says it\u2019s updating \u2013 is this normal?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>My Cisco Secure application says it\u2019s updating \u2013 is this normal? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Yes, the Cisco Secure Client application will update itself automatically. The application may prompt you to restart the window in order for the change to go into effect.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Notice for users that use the Start Before Login (SBL) feature_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Notice for users that use the Start Before Login (SBL) feature <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>The Start Before Login feature will no longer be supported after these changes go into effect. This means that users who have previously used this feature will need to manually connect to the VPN after login to access protected resources.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<p>If you have any questions or concerns about this change, <a href=\"mailto:ask-its@nau.edu\">reach out to us over email<\/a>.<\/p>\n<\/div><\/div>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<div class=\"eplus-bg-color-row bg-color-nau-yellow\"><div class=\"eplus-bg-color-row-content\">\n<ol style=\"font-size: 1.3rem; line-height: 1.7rem;\">\n<li>The appearance of the window may differ slightly based on a user&#8217;s operating system. The examples shown on this webpage are visuals from MacOS Sequoia (15). Label text will not differ based on OS.<\/li>\n<\/ol>\n<\/div><\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp;<\/p>\n","protected":false},"author":608,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","ring_central_script_selection":"","footnotes":""},"class_list":["post-20590","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/20590","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/users\/608"}],"replies":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/comments?post=20590"}],"version-history":[{"count":30,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/20590\/revisions"}],"predecessor-version":[{"id":20710,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/20590\/revisions\/20710"}],"wp:attachment":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/media?parent=20590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}