<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.bathcs.com/index.php?action=history&amp;feed=atom&amp;title=StrongSwan_VPN_on_Linux</id>
	<title>StrongSwan VPN on Linux - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.bathcs.com/index.php?action=history&amp;feed=atom&amp;title=StrongSwan_VPN_on_Linux"/>
	<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;action=history"/>
	<updated>2026-08-26T06:43:47Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=178&amp;oldid=prev</id>
		<title>Pcs47: Move strongswan package warning higher up.</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=178&amp;oldid=prev"/>
		<updated>2026-06-19T17:24:26Z</updated>

		<summary type="html">&lt;p&gt;Move strongswan package warning higher up.&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:24, 19 June 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l6&quot;&gt;Line 6:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Before starting&amp;#039;&amp;#039;&amp;#039;, make sure you have Microsoft Authenticator enabled. Then, navigate to https://mysignins.microsoft.com/security-info. Make sure that the sign-in method fallback is set to &amp;quot;Microsoft Authenticator - notification&amp;quot; (via the &amp;quot;Change&amp;quot; link). This is something not listed on https://connect.bath.ac.uk and may cause later steps to fail.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Before starting&amp;#039;&amp;#039;&amp;#039;, make sure you have Microsoft Authenticator enabled. Then, navigate to https://mysignins.microsoft.com/security-info. Make sure that the sign-in method fallback is set to &amp;quot;Microsoft Authenticator - notification&amp;quot; (via the &amp;quot;Change&amp;quot; link). This is something not listed on https://connect.bath.ac.uk and may cause later steps to fail.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;If you&#039;re on Ubuntu&#039;&#039;&#039;, you should also install the following packages that aren&#039;t mentioned by the DDaT instructions: &amp;lt;code&amp;gt;libstrongswan-standard-plugins&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;libstrongswan-extra-plugins&amp;lt;/code&amp;gt;. &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You should then follow the instructions at https://connect.bath.ac.uk.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You should then follow the instructions at https://connect.bath.ac.uk.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l65&quot;&gt;Line 65:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 67:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== I keep getting connection failed for an unknown reason ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== I keep getting connection failed for an unknown reason ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This may happen on Ubuntu, the https://connect.bath.ac.uk/ instructions only mention installing a few packages, namely: &amp;lt;code&amp;gt;libcharon-extra-plugins&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;network-manager-strongswan&amp;lt;/code&amp;gt;, and possibly &amp;lt;code&amp;gt;network-manager-strongswan-gnome&amp;lt;/code&amp;gt;. However, to fetch the Sectigo certificate used for the VPN automatically, you will also need to install the following: &amp;lt;code&amp;gt;libstrongswan-standard-plugins&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;libstrongswan-extra-plugins&amp;lt;/code&amp;gt;.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You may want to check the output of the following command (on systemd machines):&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Try to connect again once installed, and see if you get any further. &lt;/del&gt;You may want to check the output of the following command (on systemd machines):&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;journalctl -u NetworkManager | grep charon  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;journalctl -u NetworkManager | grep charon  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pcs47</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=177&amp;oldid=prev</id>
		<title>Pcs47: Update connect instructions to not restate connect.bath.ac.uk and also add a warning about MS authenticator.</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=177&amp;oldid=prev"/>
		<updated>2026-06-19T17:20:53Z</updated>

		<summary type="html">&lt;p&gt;Update connect instructions to not restate connect.bath.ac.uk and also add a warning about MS authenticator.&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:20, 19 June 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot;&gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Connect instructions =&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Connect instructions =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;section covers the basic connection instructions from &lt;/del&gt;https://connect.bath.ac.uk and &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;what &lt;/del&gt;to &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;expect for a successful connection. This might help your troubleshooting. If it doesn’t, giving DDaT information about what happens here might be useful&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;Before starting&#039;&#039;&#039;, make sure you have Microsoft Authenticator enabled. Then, navigate to https://mysignins.microsoft.com/security-info. Make sure that the sign-in method fallback is set to &quot;Microsoft Authenticator - notification&quot; (via the &quot;Change&quot; link). &lt;/ins&gt;This &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;is something not listed on &lt;/ins&gt;https://connect.bath.ac.uk and &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;may cause later steps &lt;/ins&gt;to &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;fail&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# Install &lt;/del&gt;the &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;correct packages. The name of these packages differs from distro to distro, so you might have to do some searching. These packages (in the Ubuntu &amp;lt;code&amp;gt;apt&amp;lt;/code&amp;gt; repositories) are &amp;lt;code&amp;gt;libcharon-extra-plugins&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;network-manager-strongswan&amp;lt;&lt;/del&gt;/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;code&amp;gt;, and possibly &amp;lt;code&amp;gt;network-manager-strongswan-gnome&amp;lt;&lt;/del&gt;/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;code&amp;gt; (if you’re using the Gnome desktop environment).&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;You should then follow &lt;/ins&gt;the &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;instructions at https:&lt;/ins&gt;//&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;connect&lt;/ins&gt;.bath.ac.uk.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# Using the NetworkManager GUI (might just be called network settings or similar), add a VPN connection with the following:&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;#* Connection Name: University of Bath VPN&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;#* Server Name: vpn&lt;/del&gt;.bath.ac.uk&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;#* VPN Type: IKEv2&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;#* Type of sign-in: Username and Password/EAP-MSCHAPv2 or simply “EAP”&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;#* Other Options: Request an inner IP address, Enforce UDP encapsulation&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# You may need to use the university’s DNS servers (&amp;lt;code&amp;gt;138.38.1.1&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;138.38.1.2&amp;lt;/code&amp;gt;) or a public DNS server like Cloudflare’s &amp;lt;code&amp;gt;1.1.1.1&amp;lt;/code&amp;gt;&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The instructions &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;also &lt;/del&gt;give the following troubleshooting advice:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The instructions give the following troubleshooting advice:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;blockquote&amp;gt;You may also need to run the command below if you find DNS lookups fail for some university resources:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;blockquote&amp;gt;You may also need to run the command below if you find DNS lookups fail for some university resources:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l22&quot;&gt;Line 22:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 15:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;sudo ln -sfv /run/systemd/resolve/resolv.conf /etc/resolv.conf&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;sudo ln -sfv /run/systemd/resolve/resolv.conf /etc/resolv.conf&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/blockquote&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/blockquote&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Though, we’re not sure this is a great idea, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;nor are we sure this &lt;/del&gt;will work on any distro.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Though, we’re not sure this is a great idea, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and it &lt;/ins&gt;will &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;not &lt;/ins&gt;work on any distro&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. Ubuntu is currently the only distro actively supported by DDaT, though they have been known to respond to tickets for other distros&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== What to expect ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== What to expect ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pcs47</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=176&amp;oldid=prev</id>
		<title>Pcs47: /* I keep getting connection failed for an unknown reason */ Update link</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=176&amp;oldid=prev"/>
		<updated>2026-06-19T17:12:54Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;I keep getting connection failed for an unknown reason: &lt;/span&gt; Update link&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:12, 19 June 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l78&quot;&gt;Line 78:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 78:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If you see anything like &amp;lt;code&amp;gt;EAP/FAIL&amp;lt;/code&amp;gt; but certificates are good, you should [[#file-a-ticket|file a ticket]]. If certificates are bad, you can try the instructions in [[#&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;im-&lt;/del&gt;not&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-&lt;/del&gt;getting&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-&lt;/del&gt;a&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-microsoft-&lt;/del&gt;authenticator&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-&lt;/del&gt;request|this section]].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If you see anything like &amp;lt;code&amp;gt;EAP/FAIL&amp;lt;/code&amp;gt; but certificates are good, you should [[#file-a-ticket|file a ticket]]. If certificates are bad, you can try the instructions in [[&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;StrongSwan VPN on Linux&lt;/ins&gt;#&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;I’m &lt;/ins&gt;not getting a &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Microsoft &lt;/ins&gt;authenticator request|this section]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== I’m not getting a Microsoft authenticator request ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== I’m not getting a Microsoft authenticator request ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pcs47</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=175&amp;oldid=prev</id>
		<title>Pcs47: Add issues encountered while setting up VPN for someone on Ubuntu.</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=175&amp;oldid=prev"/>
		<updated>2026-06-19T16:57:57Z</updated>

		<summary type="html">&lt;p&gt;Add issues encountered while setting up VPN for someone on Ubuntu.&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 16:57, 19 June 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l68&quot;&gt;Line 68:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 68:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You can now attempt to connect again, following the same steps as before. If you get a connection, great! If not, look for the section that best describes your issue.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;You can now attempt to connect again, following the same steps as before. If you get a connection, great! If not, look for the section that best describes your issue.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;== I keep getting connection failed for an unknown reason ==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This may happen on Ubuntu, the https://connect.bath.ac.uk/ instructions only mention installing a few packages, namely: &amp;lt;code&amp;gt;libcharon-extra-plugins&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;network-manager-strongswan&amp;lt;/code&amp;gt;, and possibly &amp;lt;code&amp;gt;network-manager-strongswan-gnome&amp;lt;/code&amp;gt;. However, to fetch the Sectigo certificate used for the VPN automatically, you will also need to install the following: &amp;lt;code&amp;gt;libstrongswan-standard-plugins&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;libstrongswan-extra-plugins&amp;lt;/code&amp;gt;.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Try to connect again once installed, and see if you get any further. You may want to check the output of the following command (on systemd machines):&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;syntaxhighlight lang=&quot;sh&quot;&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;journalctl -u NetworkManager | grep charon &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;If you see anything like &amp;lt;code&amp;gt;EAP/FAIL&amp;lt;/code&amp;gt; but certificates are good, you should [[#file-a-ticket|file a ticket]]. If certificates are bad, you can try the instructions in [[#im-not-getting-a-microsoft-authenticator-request|this section]].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== I’m not getting a Microsoft authenticator request ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== I’m not getting a Microsoft authenticator request ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pcs47</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=107&amp;oldid=prev</id>
		<title>Hw2210: Translate from boss.bathcs.com (written by Peter Chaplin-Smith - pcs47)</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=StrongSwan_VPN_on_Linux&amp;diff=107&amp;oldid=prev"/>
		<updated>2026-06-04T07:33:23Z</updated>

		<summary type="html">&lt;p&gt;Translate from boss.bathcs.com (written by Peter Chaplin-Smith - pcs47)&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The GlobalProtect VPN has been decommissioned by DDaT. Unfortunately, this was the only easily working VPN on Linux. The new strongSwan VPN &amp;#039;&amp;#039;should&amp;#039;&amp;#039; just work on popular distros like Mint with the instructions given at https://connect.bath.ac.uk/. Unfortunately, for the rest of us, it often does not “just work”.&lt;br /&gt;
&lt;br /&gt;
This page contains troubleshooting steps for if a basic connection doesn’t work.&lt;br /&gt;
&lt;br /&gt;
= Connect instructions =&lt;br /&gt;
&lt;br /&gt;
This section covers the basic connection instructions from https://connect.bath.ac.uk and what to expect for a successful connection. This might help your troubleshooting. If it doesn’t, giving DDaT information about what happens here might be useful.&lt;br /&gt;
&lt;br /&gt;
# Install the correct packages. The name of these packages differs from distro to distro, so you might have to do some searching. These packages (in the Ubuntu &amp;lt;code&amp;gt;apt&amp;lt;/code&amp;gt; repositories) are &amp;lt;code&amp;gt;libcharon-extra-plugins&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;network-manager-strongswan&amp;lt;/code&amp;gt;, and possibly &amp;lt;code&amp;gt;network-manager-strongswan-gnome&amp;lt;/code&amp;gt; (if you’re using the Gnome desktop environment).&lt;br /&gt;
# Using the NetworkManager GUI (might just be called network settings or similar), add a VPN connection with the following:&lt;br /&gt;
#* Connection Name: University of Bath VPN&lt;br /&gt;
#* Server Name: vpn.bath.ac.uk&lt;br /&gt;
#* VPN Type: IKEv2&lt;br /&gt;
#* Type of sign-in: Username and Password/EAP-MSCHAPv2 or simply “EAP”&lt;br /&gt;
#* Other Options: Request an inner IP address, Enforce UDP encapsulation&lt;br /&gt;
# You may need to use the university’s DNS servers (&amp;lt;code&amp;gt;138.38.1.1&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;138.38.1.2&amp;lt;/code&amp;gt;) or a public DNS server like Cloudflare’s &amp;lt;code&amp;gt;1.1.1.1&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The instructions also give the following troubleshooting advice:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;You may also need to run the command below if you find DNS lookups fail for some university resources:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;sudo ln -sfv /run/systemd/resolve/resolv.conf /etc/resolv.conf&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
Though, we’re not sure this is a great idea, nor are we sure this will work on any distro.&lt;br /&gt;
&lt;br /&gt;
== What to expect ==&lt;br /&gt;
&lt;br /&gt;
Now that you’ve followed the university’s instructions, you should be able to connect using the NetworkManager GUI, it should ask you for a username and password (if you haven’t already supplied the username in the configuration), put your university credentials in (the username should be &amp;#039;&amp;#039;&amp;#039;without&amp;#039;&amp;#039;&amp;#039; the &amp;lt;code&amp;gt;@bath.ac.uk&amp;lt;/code&amp;gt;), and you should get a Microsoft authenticator request via the app.&lt;br /&gt;
&lt;br /&gt;
To confirm you are connected to the university VPN correctly, check you can visit any internal site. For example, go to https://2024-25.moodle-archive.bath.ac.uk/. If the page loads, you’re connected! If not, you’ll need to do some troubleshooting.&lt;br /&gt;
&lt;br /&gt;
= Troubleshooting =&lt;br /&gt;
&lt;br /&gt;
First, wipe the slate clean (delete the connection), update your system, and reboot. Once you’ve done that, try again. This should narrow the chances of your system being in some weird state. If it works, great! If not, it’s time to get troubleshooting.&lt;br /&gt;
&lt;br /&gt;
Some of the following sections will require the use of the command line. If you’re unfamiliar, there are plenty of good guides out there and unfortunately teaching the command line is out of scope for this document. We assume basic command line competence from here on out.&lt;br /&gt;
&lt;br /&gt;
== I can’t add the connection whatsoever ==&lt;br /&gt;
&lt;br /&gt;
First of all, check if &amp;lt;code&amp;gt;NetworkManager&amp;lt;/code&amp;gt; has the connection saved, you can list connections with:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli connection&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Or, &amp;lt;code&amp;gt;nmcli&amp;lt;/code&amp;gt; has short-hand commands:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli c&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
This should list all your connections, look for one with the name you gave it (which would be &amp;lt;code&amp;gt;University of Bath VPN&amp;lt;/code&amp;gt; if you followed the instructions in [[#connect-instructions|the first section]]). If it does exist, try connecting with:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli c up &amp;quot;University of Bath VPN&amp;quot; --ask&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
You’ll be asked for your password and you should get a Microsoft authenticator request. If you get a successful connection as per [[#what-to-expect|this section]], great! If not and you didn’t get a Microsoft authenticator request, carry on reading this section. If you didn’t get a successful connection but did get a Microsoft authenticator request, check the next section.&lt;br /&gt;
&lt;br /&gt;
First, let’s clean the slate. Check your connections with:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli c&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Then delete the VPN connections by their UUID (UUIDs look something like &amp;lt;code&amp;gt;7abdc95a-4b2a-42bb-9a4a-38104d288737&amp;lt;/code&amp;gt;, yours will be different):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli c delete &amp;lt;uuid of the VPN connection&amp;gt;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Now, we’d suggest adding the connection via &amp;lt;code&amp;gt;nmcli&amp;lt;/code&amp;gt;, the command line for &amp;lt;code&amp;gt;NetworkManager&amp;lt;/code&amp;gt;. To do this, you can use the following command. &amp;#039;&amp;#039;&amp;#039;Note that you’ll have replace the placeholder text with your Bath username&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli connection add \&lt;br /&gt;
    con-name &amp;quot;University of Bath VPN&amp;quot; \&lt;br /&gt;
    type vpn \&lt;br /&gt;
    vpn-type org.freedesktop.NetworkManager.strongswan \&lt;br /&gt;
    ifname &amp;quot;*&amp;quot; \&lt;br /&gt;
    ipv4.dns &amp;quot;138.38.1.1,138.38.1.2&amp;quot; \&lt;br /&gt;
    ipv4.ignore-auto-dns yes \&lt;br /&gt;
    vpn.data &amp;quot;address=vpn.bath.ac.uk, method=eap, user=&amp;lt;your bath username without the @bath.ac.uk&amp;gt;, encap=yes, virtual=yes&amp;quot;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
This sets up a strongSwan VPN connection using the university’s DNS servers and the &amp;lt;code&amp;gt;vpn.bath.ac.uk&amp;lt;/code&amp;gt; VPN server. It should also use your username, set UDP encapsulation enforcement, and should request an inner IP.&lt;br /&gt;
&lt;br /&gt;
You can now attempt to connect again, following the same steps as before. If you get a connection, great! If not, look for the section that best describes your issue.&lt;br /&gt;
&lt;br /&gt;
== I’m not getting a Microsoft authenticator request ==&lt;br /&gt;
&lt;br /&gt;
Before you start this section, make sure to follow the instructions in the previous subsection so you’re in a known state.&lt;br /&gt;
&lt;br /&gt;
When you connect with &amp;lt;code&amp;gt;nmcli c up &amp;amp;quot;University of Bath VPN --ask&amp;amp;quot;&amp;lt;/code&amp;gt;, if you get an error such as:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;Error: Connection activation failed: No valid secrets&amp;lt;/pre&amp;gt;&lt;br /&gt;
You might need a certificate, or you may have entered your password incorrectly. To check the latter, delete the VPN connection and try again.&lt;br /&gt;
&lt;br /&gt;
If you’re not getting a Microsoft authenticator request still, you might need a certificate. The university uses Sectigo certificates for the strongSwan VPN. These &amp;#039;&amp;#039;should&amp;#039;&amp;#039; be bundled in your distro’s trust store, but either &amp;lt;code&amp;gt;charon-nm&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;NetworkManager&amp;lt;/code&amp;gt; might not be checking for them properly and so your connection might be failing. Unfortunately, there is no easy way with a VPN connection to get around this.&lt;br /&gt;
&lt;br /&gt;
The following instructions are a bit messy, but are mostly distro-agnostic and &amp;#039;&amp;#039;should&amp;#039;&amp;#039; resolve the issue &amp;#039;&amp;#039;if it is a certificate problem&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
There are some extra steps you can do first to confirm it is a certificate issue, though different distros package software differently and so this isn’t guaranteed to give results:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;# look for anything that suggests a certificate is missing or untrusted&lt;br /&gt;
journalctl -u NetworkManager | grep charon&lt;br /&gt;
&lt;br /&gt;
# if the above doesn&amp;#039;t show anything, try just looking through NetworkManager&amp;#039;s logs&lt;br /&gt;
journalctl -u NetworkManager&lt;br /&gt;
&lt;br /&gt;
# if that doesn&amp;#039;t immediately show anything, you can try the following&lt;br /&gt;
journalctl | grep Sectigo&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Anything that &amp;#039;&amp;#039;does&amp;#039;&amp;#039; come up may be useful to DDaT for troubleshooting if our troubleshooting steps don’t resolve the issue.&lt;br /&gt;
&lt;br /&gt;
Firstly, you’ll have to download the &amp;lt;code&amp;gt;Sectigo Public Server Authentication Root R46&amp;lt;/code&amp;gt; certificate. This can be found here: https://crt.sh/?d=4256644734. If you don’t trust us or the certificate has changed, find the correct certificate on this page: https://www.sectigo.com/knowledge-base/detail/Sectigo-Public-Intermediates-and-Roots.&lt;br /&gt;
&lt;br /&gt;
Once you’ve got the certificate, move it somewhere you won’t accidentally delete it. We recommend something like &amp;lt;code&amp;gt;~/.uni-vpn/sectigo-root.crt&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Now, delete your VPN connection (again, just to make sure you’re in a known state) and add the following connection. &amp;#039;&amp;#039;&amp;#039;You will need to replace your username AND the path to the Sectigo root certificate&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli connection add \&lt;br /&gt;
    con-name &amp;quot;University of Bath VPN&amp;quot; \&lt;br /&gt;
    type vpn \&lt;br /&gt;
    vpn-type org.freedesktop.NetworkManager.strongswan \&lt;br /&gt;
    ifname &amp;quot;*&amp;quot; \&lt;br /&gt;
    ipv4.dns &amp;quot;138.38.1.1,138.38.1.2&amp;quot; \&lt;br /&gt;
    ipv4.ignore-auto-dns yes \&lt;br /&gt;
    vpn.data &amp;quot;address=vpn.bath.ac.uk, method=eap, user=&amp;lt;your bath username without the @bath.ac.uk&amp;gt;, encap=yes, virtual=yes, certificate=/full/path/to/sectigo-root.crt&amp;quot;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
If you used our suggested location, you can replace the certificate path with &amp;lt;code&amp;gt;$HOME/.uni-vpn/sectigo-root.crt&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Attempt to connect as before. If you get a Microsoft authenticator request but don’t get a connection afterwards, go to the next section. If you don’t get a Microsoft authenticator request, [[#file-a-ticket|file a ticket]].&lt;br /&gt;
&lt;br /&gt;
== I get a Microsoft authenticator request, but no connection ==&lt;br /&gt;
&lt;br /&gt;
Firstly, try to connect again, accept the Microsoft authenticator request, and then wait ~40-50 seconds without retrying. If you get a secondary Microsoft authenticator request, this may be due to a routing misconfiguration.&lt;br /&gt;
&lt;br /&gt;
First, check for a rule under &amp;lt;code&amp;gt;210&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;220&amp;lt;/code&amp;gt; with the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;ip rule&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
If you don’t see a line similar to:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;210:    not from all fwmark 0xd2 lookup 210&amp;lt;/pre&amp;gt;&lt;br /&gt;
You may have a configuration or routing issue. Double check you’ve installed all the correct packages for your distro.&lt;br /&gt;
&lt;br /&gt;
To test if routing is your issue, you can add the following route:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;ip route add 138.38.3.176/28 via &amp;lt;default gateway&amp;gt; table 210&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Replacing the default gateway with the IP after “default via” from running &amp;lt;code&amp;gt;ip r&amp;lt;/code&amp;gt;. Then, try connecting again. If that doesn’t work, [[#file-a-ticket|file a ticket]]. If that works, &amp;#039;&amp;#039;&amp;#039;disconnect and delete the route&amp;#039;&amp;#039;&amp;#039; by replacing the &amp;lt;code&amp;gt;add&amp;lt;/code&amp;gt; with &amp;lt;code&amp;gt;del&amp;lt;/code&amp;gt; in the above command. You can configure &amp;lt;code&amp;gt;NetworkManager&amp;lt;/code&amp;gt; to create the route for you when you connect to the VPN, this way it won’t be forever lingering on your system.&lt;br /&gt;
&lt;br /&gt;
To do so, you can run the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;nmcli c modify &amp;quot;University of Bath VPN&amp;quot; ipv4.route-table 210&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
You may need to restart the &amp;lt;code&amp;gt;NetworkManager&amp;lt;/code&amp;gt; daemon, &amp;#039;&amp;#039;&amp;#039;this will temporarily disconnect you&amp;#039;&amp;#039;&amp;#039;. On a &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; based system, this can be done with:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;sh&amp;quot;&amp;gt;systemctl restart NetworkManager.service&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Now, you should be able to connect to the VPN without issues. If not, [[#file-a-ticket|file a ticket]].&lt;br /&gt;
&lt;br /&gt;
= File a ticket =&lt;br /&gt;
&lt;br /&gt;
If the troubleshooting steps given here don’t work, you should file a ticket with DDaT at: https://topdesk.bath.ac.uk/ (&amp;lt;code&amp;gt;DDaT Support: IT &amp;amp;amp; Audio Visual &amp;amp;gt; Report an Issue &amp;amp;gt; Report a Network Issue&amp;lt;/code&amp;gt;).&lt;/div&gt;</summary>
		<author><name>Hw2210</name></author>
	</entry>
</feed>