Navigation auf uzh.ch
Q: Where can I download the VPN client manually (separately)?
A: You can download the VPN client from our Sharepoint page.
Hints:
Q: What does the message «Please enter valid ICS URL» mean?
A: Depending on the internet provider, there may be problems with IPv6 in the home office. The following error message appears in the open 'Ivanti Secure Access Client': «… Please enter valid ICS URL.»
Solution for devices managed by Central IT (Software Center available):
macOS: Install the 'IPv6 deaktivieren' app via the Software Center. You can undo this adjustment with the 'IPv6 aktivieren' app.
Solution for all other devices (private devices):
macOS: In the OSX system settings, please change the IPv6 setting value for the corresponding connection type (i.e Wi-Fi) from 'Automatic' to 'Manual' or 'Link local only'.
Depending on the operating system version, the button names may be different. See also ...
Change TCP/IP settings on the Mac.
Q: Why do I get a message on certain websites that my IP address is not authorized for use?
A: The browser-based and platform-independent solutionEZproxy can be used as an immediate solution / alternative (instructions (in german) (PDF, 1 MB)). This enables access to e-resources as well as a connection via VPN / from the UZH network.
Generally, Apple devices (macOS) have a function for hiding IP addresses when surfing via the Safari browser. This 'Private Relay' function must be deactivated for website access.
To prevent visited websites from viewing user data (operating system, location, websites visited), Apple has invented the iCloud Private Relay data protection service. All iCloud+ subscribers can use it to encrypt data traffic via Safari and hide their IP address. In countries where Private Relay is (not) available, it is automatically (de)activated. See also ...
Protect your web browsing with iCloud Private Relay on iPhone
For those interested:
Manage iCloud Private Relay for specific websites, networks, or system settings
Notes:
F: Why can't I access e-resources via my iPhone/iPad?
A: Due to a limitation within these Apple operationg systems, the routing for URLs (Internet addresses) does not work correctly in combination with Ivanti VPN. This has the following consequences for access to e-resources:
Q: Why am I NOT on the network required for access?
A: If you receive a message when accessing an e-resource, despite an active VPN connection, that you are not in the network required for access, check in your browser settings whether you have deactivated the setting for "DNS via HTTPS":
This setting is deactivated by default on managed devices. This function is not available everywhere (e.g. on mobile devices).
For those interested in (Firefox):
Connection settings in Firefox
Firefox DNS-over-HTTPS
Configure DNS over HTTPS protection levels in Firefox
A: Please check the following three points:
Q: Does Ivanti Secure Access Client also run on Suse Linux / openSuse?
A: According to feedback from a user, it works. The following steps are required as a minimum (as 'root'):
A: The Ivanti VPN client would like to open a website within its application (for user authentication) and requires the browser runtime environment (framework) 'Chromium embedded framework'. If the 'cef' installation fails, try to install the framework manually as described in the following links:
If you encounter problems, please try again and enter the path information in the Ivanti script in the 'absolute notation' used by Ubuntu (the absolute notation of a file path can be determined with the 'realpath' command.)
Example:
DF=/usr/bin/df should be corrected with one of the following variants:
1.) DF=df , 2.) DF=/bin/df , 3.) DF=$(which df)
The third variant is recommended because it is also suitable for other Linux distributions as long as the 'which' command is available.
This suggested solution with the fixed version of the script (see setup_cef.pdf (PDF, 270 KB) ) was kindly provided to us by a user and is without any guarantee.
A: To log in to the VPN portal, please enter the server address remoteaccess.uzh.ch/vpn without the protocol name https://.
A: If, on Debian-based Linux computers (e.g. version 12, codename 'bookworm'), the traffic to the network of the University of Zurich (NUZ) does not go through the tunnel despite an existing VPN connection, it is possible that the default route via the network interface card (NIC) enp0s3 has the better metric (connection quality) (metric '0') than the one via the Ivanti Tunnel Interface tun0 (metric '1'). (The higher the value, the worse the metric.)
Solution: Override metric by setting worse than 1.
A: On the Linux distribution 'MX' please use the initialization process systemd.
See also ...
Supported Linux versions (Debian, Ubuntu, CentOS, Fedora, RHEL)
Debian user manual (systemd: set as default)
MX user manual (systemd: not default, Debian packages can be used)