Set up VPN


     ITS Home  |  Service Catalog  |  Self Help  |  Support Center  |  Contact ITS Service Desk     

Set up VPN

Cal Poly’s Virtual Private Network (VPN) service allows faculty, staff, and students to access campus technology resources securely.

Items to consider before installing the Global Protect VPN client on your computer:

  • You must be enrolled in Multi-Factor Authentication (Duo) before setting up VPN.

  • You will need administrative access or “elevated rights” to install VPN software on your device.

  • The GlobalProtect VPN app uses your default browser for you to input your login information and to display messages related to connectivity. (Learn more about changing your default browser on Mac, or Windows)

  • Department email accounts will not connect to the VPN. Connect using your personal Cal Poly account.

  • If prompted to update to the newest version of GlobalProtect VPN client, please do so.

If you’re using a Cal Poly state-owned computer or a tech rental, the GlobalProtect VPN is typically preinstalled. If GlobalProtect VPN is not pre-installed please see the support page for installing software on Windows or Mac.

VPN is currently not compatible with Microsoft Surfaces.

Install VPN Client - (On Mac, Windows, iOS, Android, & Linux)

Mac

STEP 1 | IMPORTANT: BEFORE setting up VPN, you must enroll your device(s) with Multi-Factor Authentication (Duo). You will need to add a primary and secondary device. STEP 2 | Go to cpvpn.calpoly.edu. Sign in with your Cal Poly username (do not include @calpoly.edu) and password, then click the Login button. Do not press the ENTER key on your keyboard. STEP 3 | You will be prompted to authenticate with Duo.  STEP 4 | Click on the Download Mac 32/64 bit GlobalProtect agent link. STEP 5 | Once downloaded, double-click the file to launch the GlobalProtect.pkg installer. STEP 6 | Start the installation by clicking Continue. STEP 7 | Select your computer disk (generally labeled Macintosh HD), then click Continue. STEP 8 | Select BOTH GlobalProtect and GlobalProtect System extensions, then click Continue. STEP 9 | Next, click Install. STEP 10 | Here you should receive a prompt asking you to enter your password to allow this installation. Enter the password you use for your Mac, then click Install Software. STEP 11 | You should get a message indicating that The installation was successful. Then click Close. STEP 12 | From the top screen menu bar, Click the GlobalProtect icon, then click Get Started.  STEP 13 | Enter cpvpn.calpoly.edu as the portal address, then click Connect.  Did you receive a security warning/pop-up, or is the app not connecting? Follow these steps to authorize/unlock and allow the GlobalProtect App: For macOS 10.13 through 12.x [1] Open the Apple Menu at the top left of your screen and select System Preferences. Go to the Security & Privacy pane and open the General tab. Click the padlock icon in the bottom left corner and enter your password (must be an admin user) to unlock the settings. Look for an alert stating that system software from developer Palo Alto Networks was blocked. Click Allow. [1, 2, 3, 4, 5] For macOS 13.x and Newer Open the Apple Menu and select System Settings. Click Privacy & Security in the sidebar. Scroll down to the Security section and make sure "Allow applications downloaded from" is set to App Store and identified developers. Under the Extensions or Login Items sections, ensure all toggles for Palo Alto Networks are turned on so the VPN extension can run in the background. [1, 2, 3] If you are still experiencing connection drops or "stuck" statuses, you should try restarting your computer to finalize the extension loading. For further troubleshooting, you can refer to the official Palo Alto Networks GlobalProtect User Guide. [1, 2] STEP 14 | Type your Cal Poly username (do not include @calpoly.edu) and password, then click the Login button. Do not press the ENTER key on your keyboard. NOTE: If GlobalProtect App security warnings pop up on-screen, always click Allow. STEP 15 | You are now connected to Cal Poly's VPN. The Connected status is displayed in the Mac Menu Bar. STEP 16 | Once you are done with your session, click the GlobalProtect icon, then click the ≡ menu icon, then select Disconnect.

Windows

IMPORTANT: BEFORE setting up VPN, you must enroll your device(s) with Multi-Factor Authentication (Duo).You will need to add a primary and secondary device. STEP 1 | Go to cpvpn.calpoly.edu. Sign in with your Cal Poly username (do not include @calpoly.edu) and password, then click the Login button. Do not press the ENTER key on your keyboard. STEP 2 | You will be prompted to authenticate with Duo. STEP 3 | Click the Download Windows 64 bit or Windows 32 bit GlobalProtect agent link, depending on your operating system version. STEP 4 | Run the downloaded file. Then, after the GlobalProtect Setup Wizard opens, install it by clicking Next.  If asked "Do you want to allow this app to make changes to your device?" click Yes.  STEP 5 | If you do not see the GlobalProtect window, go to the system tray located in the bottom right section of the Windows taskbar, and click on the globe icon. STEP 6 | Click Get Started. STEP 7 | Enter cpvpn.calpoly.edu as the portal address, then click Connect.  STEP 8 | Type your Cal Poly username (do not include @calpoly.edu) and password, then click the Login button. Do not press the ENTER key on your keyboard. STEP 9 | You are now connected to Cal Poly's VPN. The Connected status is displayed in the system tray located in the bottom right section of the Windows taskbar.  STEP 10 | Once you are done with your session, click the GlobalProtect icon, then click the ≡ menu icon, then select Disconnect.

iOS

STEP 1 | Before setting up VPN, you must enroll your device(s) with Multi-Factor Authentication (Duo). You will need to add a primary and secondary device. STEP 2 | Go to the Apple App Store, and search for Global Protect. Download and launch the free app. STEP 3 | Open the GlobalProctect app. Choose to Allow for the dialog box asking “GlobalProtect” Would Like to Send You Notifications. STEP 4 | In the Address field type cpvpn.calpoly.edu as the portal address, then tap the Connect button. STEP 5 | Tap the Allow button to allow GlobalProtect to add VPN configurations. STEP 6 | Use Touch ID or enter your passcode to add the VPN configuration. STEP 7 | Log in with your Cal Poly username (do not include @calpoly.edu) and password. STEP 8 | You will be prompted to authenticate with Duo. Please be aware of Cal Poly's Responsible Use Policy. STEP 9 | You are now connected to Cal Poly's VPN. STEP 10 | Once you are done with your session, go to the GlobalProtecft app screen and tap the circle and shield icon button to disconnect.

Android

STEP 1 | Before setting up VPN, you must enroll your device(s) with Multi-Factor Authentication (Duo). You will need to add a primary and secondary device. STEP 2 | Go to the Google Play Store, and search for Global Protect. Tap the Install button to download and launch the free app. STEP 3 | Enter cpvpn.calpoly.edu as the portal address, then click the Connect button. GlobalProtect will begin retrieving your VPN configuration. STEP 4 | Log in with your Cal Poly username (do not include @calpoly.edu) and password. STEP 5 | You will be prompted to authenticate using Duo. STEP 6 | Tap OK to confirm your VPN connection request. STEP 7 | Please be aware of Cal Poly's Responsible Use Policy. STEP 8 | You are now connected to Cal Poly's VPN. STEP 9 | Once you are done with your session, tap the Disconnect button to disconnect.

Linux

STEP 1 | Before setting up VPN, you must enroll your device(s) with Multi-Factor Authentication (Duo). You will need to add a primary and secondary device. STEP 2 | Download and install the openconnect package for the operating system using one of the following methods.
  • Using openconnect, download and install the binary package for the operating system.

    1. Use a package manager.
      Sample Commands

      OS/Distribution Family 

      Command

      OS/Distribution Family 

      Command

      Debian/Ubuntu

      apt install openconnect

      Fedora

      dnf install openconnect

      Red Hat/CentOS

      yum install openconnect

      SUSE

      zypper install openconnect

      Arch Linux

      pacman -S openconnect

      OpenBSD

      pkg add openconnect

      FreeBSD

      pkg install openconnect

    2. Run openconnect --version

    3. If the version of openconnect < 8:00 and the gp option is not listed under Supported protocols, uninstall openconnect using the package manager, and build from source

  • To build from source, confirm the GNU development toolchain is installed and that you have (at least) the following tools installed: gcc, make, automake, tar.

  •  

    1. Download the latest source file from: https://www.infradead.org/openconnect/download.html

    2. Extract the source tarball with tar. X.YZ is the version number.

      xzf openconnect-X.YZ.gz

       

    3. Run the following commands:

      cd openconnect-X.YZ
      ./configure
      make

       

      This step may require administrator/root privileges.

      make install

       

STEP 3 | Connect to the VPN. This step may require administrator/root privileges. Use your Cal Poly username (do not include @calpoly.edu). openconnect --protocol=gp cpvpn.calpoly.edu --user=<YOUR CAL POLY USERNAME> STEP 4 | When prompted, enter your Cal Poly password. STEP 5 | You are now connected to Cal Poly's VPN. To install a Graphical User Interface (GUI) for openconnect, see:

Uninstall the VPN Client

If you need to uninstall the VPN client from your computer, please visit the Paloalto GlobalProtect support site for uninstall instructions.

Version 6.2x

Version 5.2x

If you’re using a Cal Poly state-owned computer or a tech rental, the GlobalProtect VPN is typically preinstalled. If GlobalProtect VPN is not pre-installed please see the support page for installing software on Windows or Mac.