|
| 1 | +This repository contains a C# console application that uses the OpenConnect library to establish a vpn connection to a specified url. Credentials are provided using standard Windows apis, with the option to persist the credentials in the Windows Credentials Manager. |
| 2 | + |
| 3 | +# Getting started |
| 4 | + |
| 5 | +1. Download OpenConnect from https://gitlab.com/openconnect/openconnect/-/jobs/artifacts/master/download?job=MinGW64/GnuTLS |
| 6 | + The link only works sporadically, for unknown reasons. If it doesn't work, follow these steps to find the download: |
| 7 | + 1. Start at https://gitlab.com/openconnect/openconnect/-/pipelines?scope=finished&page=1&ref=master |
| 8 | + 2. From above, try the "Download artifacts" button until you find the pipeline that has downloads. |
| 9 | + 3. Download the artifact named `MinGW64/GnuTLS:archive` |
| 10 | +2. Extract openconnect-installer.exe from the downloaded file. |
| 11 | +3. Right-click openconnect-installer.exe, click Properties. If the notice "This file came from another computer and might be blocked to help protect your computer" is visible, check the checkbox "Unlock". Click OK to save any changes and close the properties window. |
| 12 | +4. Run openconnect-installer.exe |
| 13 | + 1. When asked, accept to install TAP-Windows. |
| 14 | + 2. When TAP-Windows asks, choose to install TAP Utilities. |
| 15 | +5. Download the latest release from https://github.com/sisve/openconnect-wrapper/releases |
| 16 | +6. Create a shortcut on your desktop to `\path\to\connect-to-url.exe https://vpn.domain.com/group` |
| 17 | +7. Configure the shortcut to run as administrator. |
| 18 | + |
| 19 | +To connect to several vpns, read more about multiple connections below, and repeat step 6 and 7 above to create a shortcut for every vpn. |
| 20 | + |
| 21 | +# Commandline options |
| 22 | + |
| 23 | +* `--secondary-password push` will enter "push" as a secondary password. This is meant to automate the connection process when using Duo MFA. |
| 24 | +* `--log-level (error|warning|info|debug|trace)` configures the logging level. This is intended for debugging purposes. |
| 25 | + |
| 26 | +# Persisting credentials |
| 27 | + |
| 28 | +This application can persist your vpn credentials between logins. Just check the checkbox to save the credentials, and Windows will handle it internally. The credentials are stored in Windows Credential Manager. To remove any persisted credentials, remove them from Windows Credential Manager. |
| 29 | + |
| 30 | +# Multiple connections |
| 31 | + |
| 32 | +This applications supports multiple concurrent vpn connections, with some requirements. |
| 33 | + |
| 34 | +* Only one vpn can have a default gateway (sends all traffic over the vpn). |
| 35 | +* All vpn networks should have unique addresses. We cannot handle cases where an ip address is available in two different places. |
| 36 | +* You need to add more virtual ethernet adapters, one for every vpn. |
| 37 | + |
| 38 | +If the option exists, prefer connect to vpns that are running as "split tunneling". This means that they declare some routes that should go over the vpn connection, and let the rest of the traffic stay on your local network. |
| 39 | + |
| 40 | +## Add more virtual ethernet adapters. |
| 41 | + |
| 42 | +Every vpn connection uses a "TAP virtual ethernet adapter". TAP-Windows created one during installation, but you need to create more if you want to connect to several vpns concurrently. To add another ethernet adapter, find the "Add a new TAP virtual ethernet adapter" on your start menu, and execute it with administrator privileges. |
| 43 | + |
| 44 | +The start menu entry, and the bat file mention below, is part of the TAP Utilities that was installed during the TAP-Windows installation. |
| 45 | + |
| 46 | +* You can right-click the start menu entry, wait for the folder `C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows\Utilities` to open, then rightclick the shortcut and click Run as administrator. You're done. |
| 47 | +* If the start menu entry is missing, open a command prompt as Administrator and execute `"C:\Program Files\TAP-Windows\bin\tapinstall.exe" install "C:\Program Files\TAP-Windows\driver\OemVista.inf" tap0901` |
| 48 | + |
| 49 | +To later remove all virtual ethernet adapters, use the above steps for the start menu entry "Delete ALL TAP virtual ethernet adapters", or execute `"C:\Program Files\TAP-Windows\bin\tapinstall.exe" remove tap0901` in a command prompt running with administrator privileges. |
0 commit comments