One VPN for Everyone: Why We Rely on eduVPN

The URZ is standardizing its VPN services. Cisco access will be phased out in the medium term, and eduVPN will become the standard. If you switch now, you’ll be all set in five minutes.

In short: The URZ currently operates two VPN services in parallel: eduVPN and the Cisco Secure Client. In the future, there will be only eduVPN. The Cisco service will be phased out in the medium term. There is no specific shutdown date yet, but we will announce it here on the blog well in advance. If you switch now, you’ll have it out of the way. The switch takes less than five minutes.

Why VPN at All?

With a VPN (Virtual Private Network), you can establish a secure connection to the campus network from outside the TUC. Your device will then behave as if it were directly connected to the campus network. You’ll need this, for example, to access licensed literature and databases in the university library, for internal web services and, since December 2023, also to access the Exchange and email systems, which, for security reasons, are now only accessible from the campus network or via VPN.

What’s Changing

We already streamlined our VPN offerings in early 2024: WebVPN access was disabled, and we discontinued support for OpenConnect. The next and final step in this consolidation is now underway: The Cisco Secure Client (AnyConnect) will be phased out in the medium term.

For you, this means:

  • Today: Both access methods will continue to work. Nothing will be removed, and nothing will be shut down.
  • As of now: We recommend that all users switch to eduVPN. New setups should always be done using eduVPN.
  • Later: We will announce the concrete shutdown date for Cisco access in a separate post, well in advance.

Why eduVPN Is the Better Choice for you

eduVPN has been in use at TU Chemnitz since November 2023 and is more convenient for most applications:

  • Log in as usual: Log in via the Chemnitz University of Technology’s Web Trust Center using your URZ user ID. It’s the same procedure as for other central services, including multi-factor authentication.
  • Gültig für 90 Tage: Nach der Anmeldung ist der Zugang 90 Tage gültig. In dieser Zeit ist keine erneute Passworteingabe nötig – Die VPN-Verbindung können Sie während dieser Zeit über einen Schalter in der eduVPN-App bequem ein- und ausschalten.
  • Valid for 90 days: Once you’ve logged in, your access is valid for 90 days. During this time, you won’t need to re-enter your password. You can conveniently turn the VPN connection on and off using a toggle in the eduVPN app.
  • Works on all devices: Windows, macOS, Linux, Android, and iOS are supported. eduVPN is clearly the more convenient solution, especially on smartphones and tablets.
  • Two profiles for two different needs: When connecting, you choose which data is sent through the VPN tunnel (see below).

Which Profile Is the Right One?

  • Standard VPN Access: All data traffic is routed through the VPN tunnel. This option is recommended for laptops used for work and for library research.
  • Groupware only: Only data traffic to the Web Trust Center and to email systems (e.g., Outlook Web Access, IMAP) is routed through the VPN tunnel. All other data traffic remains “private.” This option is ideal for smartphones and tablets that require constant access to the central mailbox system or Exchange.

Why We Do That

Operating two parallel VPN services means twice the effort: twice the maintenance, twice the documentation, and twice the troubleshooting for support. The URZ would rather put that energy into a single service that runs really well.

Above all, the operating costs for the Cisco VPN pose a major challenge. In addition to providing client packages for all operating systems, we must keep the underlying hardware up to date at all times. On top of that, there are licensing costs as well as costs for replacing the hardware in use. In contrast, eduVPN is open source and can therefore be operated without a license via our virtualization infrastructure. Furthermore, eduVPN is being developed in collaboration with the international academic networking community. Updates to end devices occur automatically, and authentication is handled seamlessly through our central solution, the Web Trust Center. This means we have fewer workarounds, less friction, and more time for actual operations.

How to Switch – in Five Minutes

  1. Install the app.
    • Windows: app.eduvpn.org
    • macOS and iOS: „eduVPN Client“ in App Store
    • Android: Play Store orF-Droid
    • Linux: instructions on our VPN-website
  2. Start setup and search for „Chemnitz“ as institution.
  3. Choose „Institute Access“ (not „Secure Internet“ – this is the most common stumbling block).
  4. Register at the Web-Trust-Center using your TUC user ID and confirm VPN access.
  5. Choose profile („Standard VPN access“ or „Groupware only“) and activate connection → Done.

You can find detailed step-by-step instructions for all operating systems on our VPN website.

Frequently Asked Questions

Do I have to change immediately?
No. Cisco access will continue to work normally until it is shut down. However, making the switch is now a stress-free process. Experience has shown that this is no longer the case shortly before a deadline.

Do I have to deinstall the Cisco Client?
No. Both clients can remain installed at the same time, but they should not be connected simultaneously. However, once you have switched to eduVPN, you can uninstall the Cisco client.

Will my login information change?
No. You will continue to use your TUC user ID; eduVPN uses the familiar login process via the Web Trust Center instead of its own login form.

eduVPN isn’t working for me / I have a special case.
That’s exactly what we want to know—and we want to know it now, not just right before the switchover. If a device, application, or workflow isn’t working with eduVPN, please contact the URZ. Any feedback helps us ensure a smooth transition for everyone.

Links and Contact

Leave a Reply