Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Inhalt der Seite

Inhalt


VPN-Verbindungen sind kritische Zugangspunkte zum internen Netzwerk. Ein Passwort allein reicht heute nicht mehr aus, um diese Schlüsselstelle zu sichern. 

Die Mehr-Faktor-Authentifizierung (MFA) sichert die Anmeldung doppelt ab – für die einzelnen Nutzenden und für die HHU. Selbst wenn ein Passwort in falsche Hände gerät, der Zugang bleibt ohne einen zweiten Faktor für Angreifer blockiert.


UI Expand
titleGlossar

VPN (Virtuelles Privates Netzwerk)

Stellt eine geschützte Verbindung zur HHU her – so, als wären Sie mit Ihrem Computer auf dem Campus, obwohl Sie zu Hause sind.

MFA (Mehr-Faktor-Authentifizierung)
Ein zusätzlicher Schutz beim Einloggen. Neben Benutzername und Passwort brauchen Sie z.B. ein Handy oder einen USB-Stick (z.B. YubiKey)

TOTP (Time-based One-Time Password / Zeitbasiertes Einmalpasswort)
Ein Code, der 30 Sekunden lang gültig ist und über eine App auf dem Handy wie z.B. der Google Authenticator, Passwörter App (iOS) generiert wird.

YubiKey (Hardware-Token)
Ein kleiner USB-Stick, auf dem ein Passkey gespeichert ist.  Sie stecken ihn ein, berühren die metallische Kontaktfläche und der Computer weiß, dass Sie es sind.


Piktogramm-ähnlich. links Computerbildschirm, darin ein Feld mit verborgenem Passwort, darüber grüner Haken. rechts davon ein Smartphone, grüner Haken darauf. zwisch und hervorgehoben von den beiden Geräten ein gelbes Schloss. darüber, an der rechten oberen Ecke des Computerbildschirms das OpenVPN Connect Logo


Zuerst MFA einrichten, danach VPN


UI Steps
UI Step

MFA – einen sogenannten zweiten Faktor – einrichten

 Sie benutzen bisher nur Ihr Passwort? Dann folgen Sie diesen Schritten zur Einrichtung eines zweiten Faktors:

keycap: 1 Zeitbasierte Einmalpasswörter (TOTP) mit Handy App nutzen 

Anleitung zur Einrichtung: iOS und Android – Einmal-Passwörter für MFA einrichten

Wir haben die Authentifizierung mit dem Google Authenticator und der Passwörter App (iOS) getestet. Sie können natürlich auch eine andere, bereits von Ihnen genutzte Authenticator App nutzen. Wichtig: Installieren Sie die App, bevor Sie den zweiten Faktor einrichten.

keycap: 2 Weiteren MFA-Token (auf anderem Endgerät) einrichten

Richten Sie weitere zweite Faktoren (Token) mit einem anderen Gerät ein, damit Sie sich nicht aussperren - das passiert bspw., wenn Sie nicht mehr in Besitz Ihres Handys mit der Authenticator App sind.  

Sie können eine Authenticator App für Ihren Desktop wie Ente Auth nutzen: Ohne Smartphone – Einmal-Passwörter mit Ente Auth für MFA einrichten

Oder Sie können sich einen Passkey in Ihrem jeweiligen Betriebssystem einrichten, welcher gerätegebunden ist (bspw. die TouchID Ihres Laptops oder Tablets, auf dem Sie das HHU-VPN nutzen, oder FaceID auf dem iPhone ist bspw. dann sinnvoll, wenn Sie mit dem Handy eine VPN Verbindung herstellen wollen). Alternativ können Sie einen Hardware-Token nutzen, den Sie an das genutzte Gerät stecken.


Info
titleYubikeys für Mitarbeitende

Sind Sie Mitarbeiter:in an der HHU? Dann erhalten Sie als Starthilfe einen Yubikey (solange der Vorrat reicht). Mehr Informationen zur Reservierung und Einrichtung gibt es hier: MFA mit Hardware-Token einrichten

UI Step

VPN einrichten – VPN-Client prüfen und Profil importieren

Das Symbol von OpenVPN Connect sollte so aussehen: OpenVPN Logo. Falls Sie noch Tunnelblick (macOS), OpenVPN GUI, den Networkmanager oder noch gar keinen Client nutzen, dann laden Sie sich den entsprechenden Client für Ihr Betriebssystem hier https://openvpn.net/client/ herunter (wichtig: Deinstallieren Sie zuerst einen möglicherweise vorhandenen alten Client).

Erst nachdem Sie sich Zweite Faktoren eingerichtet haben, können Sie auf diese Seite zugreifen https://mfa.vpn.hhu.de/ und sich die Datei HHU-VPN mit der Endung .opvn herunterladen. Durch den Import der Datei wird das entsprechende VPN-Profil (standardmäßiger Name "node1.vpn.hhu.de [HHU-VPN]") angelegt.


Hier kommen Sie zu detaillierten Anleitungen:

VPN-Verbindung starten


Bildschirmfoto. OpenVPN Connect App. 'Ready to connect', darunter node1.vpn.hhu.de- Profil


Bildschirmfoto. mfa.vpn.hhu.de-Seite 'Login success'

Starten Sie OpenVPN Connect, indem Sie auf das Symbol OpenVPN Logo klicken. Klicken Sie auf "Connect" unter node1.vpn.hhu.de [HHU-VPN]

Es öffnet sich ein Browserfenster:

Geben Sie Ihre Unikennung und Ihr Passwort ein.

Danach werden Sie nach dem zweiten Faktor gefragt:

z.B. TOTP-Code aus Ihrer App eingeben oder

den YubiKey betätigen


Wenn alles geklappt hat, wird "Login Success" angezeigt – Fertig!

Manchmal dauert es ein wenig bis die Verbindung zustande kommt. Geben Sie dem System etwas Zeit. 



Anker
Englische Anleitung VPN-MFA
Englische Anleitung VPN-MFA
English version

VPN connections are critical access points to the internal network. A password alone is no longer sufficient to secure this key point.

Multi-factor authentication (MFA) doubly secures the login – for the university and for all users. Even if a password is compromised, access remains blocked for the attacker without a second factor.


UI Expand
titleGlossar

VPN (Virtual Private Network)

Establishes a protected connection to the university – as if you were on campus with your computer, even though you are at home.

MFA (multi-factor authentication)

Additional protection when logging in. In addition to username and password, you need a cell phone or a USB stick (e.g. YubiKey)

TOTP (Time-based one-time password)

Code that is valid for 30 seconds and is generated via an app on the cell phone, e.g. Google Authenticator or Passwords app (iOS).

YubiKey (hardware token)

A small USB stick on which a passkey is stored.  You insert it, touch the metal contact surfaces and the computer knows it's you.

SVG. On the left, a monitor. On the screen encrypted password characters, with a green check mark above it. To the right smartphone with green check mark. In the middle between the two, open, yellow lock symbol. also in middle, above lock OpenVPN Connect symbol

UI Steps

First set up MFA then VPN


UI Step

Setting up MFA – or a so-called second factor

You are only using your password? Then follow these steps to set up second factors:


keycap: 1 Install Authenticator App and set up a time based one time password (TOTP):

Instruction for the setup: iOS and Android – Set up TOTP token for MFA

We tested authentication with the Google Authenticator, the Passwords app (iOS) and Ente Auth (Windows). You can also use another authenticator app you are already currently working with. IMPORTANT: Install the app before you set up the second factor!


keycap: 2 Set up further factors (on other devices), e.g. a YubiKey: 

Set up additional second factors (tokens) with other devices to prevent getting locked out - this happens e. g. when you are no longer in possession of or unable to access your phone that has the Authenticator App installed.

You can use an Authenticator App for your desktop like Ente AuthNot on Smartphone - Set up TOTP token with Ente Auth for MFA

Or you can set up a passkey in your respective operating system that is device-bound (e.g. the TouchID of your laptop or tablet with which you use the HHU-VPN or FaceID on the iPhone is useful if you want to establish a VPN connection with your cell phone). Alternatively you can use a hardware token, which you plug into the currently used device.


Info
titleYubikeys for university staff

Are you an HHU employee? Then you will receive a Yubikey to help you get started (while stocks last). More information on reservation and setup can be found here: Set up MFA with hardware token

UI Step

Setting up VPN – checking VPN-Client and importing Profile

The symbol for OpenVPN Connect looks like this: OpenVPN logo. In case you are still using Tunnelblick (macOS), OpenVPN GUI, the Networkmanager or do not have yet installed a client at all than download the corresponding client for your operating system here https://openvpn.net/client/ (important: First uninstall a possibly present old client).

Only after setting up second factors, you can access the webpage https://mfa.vpn.hhu.de/ and download the HHU-VPN file with the ".ovpn" ending. By importing the file, the corresponding VPN profile (default name "node1.vpn.hhu.de [HHU-VPN]") is created.


Here you can find detailed instructions:

Start a VPN connection



Screenshot. mfa.vpn.hhu.de 'Login success' page

Start OpenVPN Connect by clicking on the Logo von OpenVPN Connect icon.

Click on the slider to the left of node1.vpn.hhu.de [HHU-VPN].

A browser window will open:

Enter your university username and your password

You will then be asked for the second factor:

e.g. enter TOTP code from your app or

operate the YubiKey


If everything went well “Login success” is displayed – Done!

Sometimes it takes a little while for the connection to be established. Please give the system a little time.