translated by Google

Machine-translated page for increased accessibility for English questioners.

Faculty VPN

Motivation

OF for security reasons we provide some faculty services only for machines in the MU network, or only in the FI network. You may also come across some electronic resources available to the university are accessible only from its network. Sometimes it can also be useful to have a secure connection that shields the risk of eavesdropping or modifying your connection on an untrusted local area network. For these cases, you can use a faculty VPN based on OpenVPN .

How to connect

You can find the configuration for the connection in the Faculty Administration:

Download VPN configuration

Log in with faculty login details .

Remember that once connected, they apply to you rules of using the FI MU computer network .

Windows

Take advantage of the client OpenVPN . When connecting, you need to allow the program to access both the internal and external networks in the Security Center notification.

Linux

We recommend using NetworkManager for configuration. You will need an installed package openvpn and VPN support in NetworkManager through the package network-manager-openvpn-gnome or similar depending on your desktop environment.

Import the downloaded VPN configuration via Network Manager. Fill in at least the login name in the dialog, enter your faculty login (otherwise the name of your local account would be used).

For advanced users, the option to connect manually with a command may be appropriate openvpn VPN_FI_MU.ovpn (superuser rights are required). Please note, however, that in this case, DNS servers may not be set up automatically, so your DNS queries will not be VPN protected.

Android

Take advantage of the client OpenVPN for Android . Please note that OpenVPN Connect cannot be used for this purpose. After downloading the configuration, import it via the arrow icon in the upper right corner of the application. Then click on the name of the newly created profile and connect.

macOS

Take advantage of the client Tunnel view .

iOS

Use the application OpenVPN Connect . Then copy the downloaded VPN connection configuration to OpenVPN Connect via sharing.

Functionality verification

Once connected, you will receive internal addresses from the ranges 172.27.0.0/20 and 2001:718:801:207::/64 .

The external address will be 147.251.58.69 and 2001:718:801:23a::45 . You can verify this, for example, on our website https://wifi.fi.muni.cz/ or an external service https://www.whatismyip.com/ .

FAQ

  • My login doesn't work
    Unlike university VPNs, they are used faculty login details , ie faculty login and faculty password. Can you use them to sign up for another FI service?
  • I'm using a Linux distribution (Debian / Ubuntu / ...) and my DNS doesn't work
    Your VPN connection method does not appear to set up DNS sent by the VPN server (for example, when used directly openvpn ) and at the same time your ISP does not allow the use of its DNS servers from outside its network (eg at UPC / Vodafone). Of course, this also means that your DNS queries travel outside of the VPN. You can try to adjust the ovpn configuration according to instructions .
  • Sending mail from the client stopped working for me
    In the FI network, ie MU, it is necessary to use either the faculty SMTP server in the mail client to prevent the spread of unsolicited mail ( relay.fi.muni.cz ) or university ( relay.muni.cz ).
  • Split tunneling does not work for some services at FI / MU
    Configuration for split tunneling must contain a list of all FI networks, resp. HIM. This list may change over the years, so your configuration may become out of date. Try using a full VPN, and if access to it works from you, update your split tunneling configuration by downloading a new version .

Is something missing here? write us .

Alternatives

Because VPN is fundamentally changing your Internet connection, you may want to consider it alternative ways how to act for our faculty or university or other external services as if you were accessing from the FI network.

It can also be used university VPN , although it may not make some services available to you (only available from the FI network).