WiscVPN - Manifest Integration

This document covers how the WiscVPN (uwmadison.vpn.wisc.edu) service uses Manifest to control who can authenticate to the service.

General Information

  • 2 of 6 Manifest groups control WiscVPN access and access to the WiscVPN Static IP assignment site.
    • 3 = Middleware/IAM takes the "initial" population(where NS puts other groups)
    • 2 = Substracts out the "disable VPN" population
    • 1 = Leaving the population allowed to use either service.
    • Think: "3 - 2 = 1"
  • There are several populations in both groups. The general list can be seen in:
  • The helpdesk can add users to their own groups to temporarily allow someone access to either service. Normally they apply a two week end date.
    • Customers should reach out to their HR department to have a $0 affiliate appointment created. This will get them a SpecAuth account which will give them both MFA-Duo and WiscVPN access automatically.
  • When someone requests WiscVPN or Static WiscVPN services through a Manifest request, see Manifest - Services . 
    • A notification is sent to IAM for approval
    • If approve, Network Services designated staff will be notified to approve or deny.
    • If approved, they'll automatically be added to the "initial" group(s) mentioned above.

WiscVPN Access

The 1-FINAL-VPN-USER-LIST Manifest group is the list of all users who can authenticate to uwmadison.vpn.wisc.edu (WiscVPN).

We use 3 different Manifest groups today to give someone the ability to disable a user's VPN access. Think "3 - 2 = 1"

WiscVPN Static IP assignments

Q: Where can a user reserve or delete a static IP address for uwmadison.vpn.wisc.edu?

A: https://access.services.wisc.edu/IPaddress

Q: How many IPs can a user reserve?

A: 4 = https://access.services.wisc.edu/CIDR/Edit/1

Q: What determines who's allowed to reserve a Static IP for uwmadison.vpn.wisc.edu via https://access.services.wisc.edu/IPaddress?

A: The short answer is, Manifest group: "1-STATIC-IP_FINAL-VPN-USER-LIST"

We use 3 different Manifest groups today to give someone the ability to disable a user from reserving IP addresses. Think "3 - 2 = 1"

Q: How does this service compare to a Departmental VPN?

A: See Palo Alto Based Departmental & Central VPN concentrators - Manifest Integrated

References:



Keywords:
uwmadison uwmadison.vpn.wisc.edu vpn wiscvpn manifest groups, manifest, eligible, eligibility, access, group, allow, allowed, disable, disabled, IP, virtual private network, list, search
Doc ID:
108188
Owned by:
Scott B. in Network Services
Created:
2021-01-07
Updated:
2025-06-27
Sites:
Cybersecurity-internal, DoITHelpDesk-internal, NetworkSrvcs-internal, SNCC-internal