VPN information for the College of Engineering
What is VPN
Types of VPN available to the CoE
There are two basic types of VPN offered to anyone affiliated with the College of Engineering; WiscVPN and CAE VPN. WiscVPN, also known as Campus VPN allows you to connect to the UW campus network. While some of CAEs resources are available this way, most require some type of CAE VPN. CAE VPN is further broken down into CoE VPN, License (Software) VPN and Collaborator VPN.
WiscVPN
All UW Madison students, faculty and staff should have access to WiscVPN. In addition to general campus use, WiscVPN can be used to access a few CAE resources, such as filespace and groupspace.
CoE Full or Split VPN
The College of Engineering VPN network is automatically given all College of Engineering faculty and staff, and graduate students who have an appointment in the CoE (such as TAs). It allows complete access to engineering resources, as if you were physically connected to the engineering network.
If you are a faculty or staff member, or grad student who does not already have this access, you can activate your access using the information in Activation of VPN access . CoE VPN is generally not available to undergraduate students.
Split Tunnel means that only network traffic that is destined for a computer on the UW-Madison campus will be sent through the VPN tunnel. All other network traffic will travel normally over the internet and will appear to come from your computer's IP address.
Full Tunnel means that *all* internet traffic will travel through the VPN tunnel, regardless of its destination and all of the traffic will appear to come from a College of Engineering IP address.
License VPN
Also known as software VPN or student VPN, the License VPN is a more restricted version of the CoE VPN. It only allows a user to connect to the CAE license servers and a few other services, such as groupspace and userspace. License VPN will not allow access to research clusters and other CoE resources. The license VPN is available to undergraduate students, and is a split tunnel connection.
The advantage of this is that students can locally install and run some CAE owned and controlled software while your computer is connected to the network or Internet.
The license VPN must be activated prior to first use. Activation information can be found here: Activation of VPN access
Collaborator VPN
Collaborator VPN is also a special restricted version of the CoE VPN for users that have affiliations in the College of Engineering, but do not have access to UW paid resources. This version will give access to researcher's systems, but will not give access to CAE resources, software, or any other UW paid resources (library, etc.). Because of the software restriction, a collaborator account will not be able to SSH into a CAE Tux lab computer.
There are, however, provisions (see below) for those who are used to doing this, but no longer have software/lab access. See CoE VPN "Collaborator" for more information.
Activating VPN
If you don't already have access to VPN, but you believe you should, the problem may be that your VPN has not been activated. This will only need to be done once. Note: it can take up to 1 hour after filling out the form for activation to sync.
Instructions for how to activate you VPN can be found here: Activation of VPN access.
Installing and Connecting to the CoE VPN
Please note that there are multiple VPN profiles and GlobalProtect clients. DoIT's instructions in Step 1 will get you started with WiscVPN, but to access the Engineering profiles, you will need to return to this document and add the appropriate CoE profile found in steps 2-6.
- To begin please download and install PaloAlto GlobalProtect (Note: these clients are available only to UW-Madison and require a login to UW-Madison Google Drive. If you are here from another institution, please talk to your institution about how to get the correct client):
- Common OS:
- Windows 10/11: GlobalProtect64-6.3.3-c999 (latest) GlobalProtect64-6.2.8-c948 (previous stable)
- MacOS: GlobalProtect-6.3.3-c999 (latest) GlobalProtect-6.2.8-c948 (previous stable)
- Linux: PanGPLinux-6.3.3-c31 (latest) PanGPLinux-6.2.9-c4 (previous stable)
- Less common OS:
- Windows on ARM64: GlobalProtectARM64-6.3.3.1-999 (latest) GlobalProtectARM64-6.2.8.1-948 (previous stable)
- Windows UWP: PanGPUWP-6.2.4-c1 (latest)
- 32-Bit Windows (what are you up to?!?): GlobalProtect-6.3.3-c999 (latest) GlobalProtect-6.2.8-c948 (previous stable)
- There are more too, and archival versions of clients for very old OS, but contact the Help Desk if you have questions.
- If you need step-by-step instructions, DoIT has provided them in WiscVPN Client Installation Instructions but you will want to use the clients linked above, and the portal addresses in the next step.
- Common OS:
- Once installed, you will be asked for a portal address. Please choose from the following addresses depending on your account type and access needs:
If necessary, more information on account types can be found here. You can find more information on activation on the Activation of VPN access pageVPN Portals by account type Account Type Portal Address Graduate Students / Staff (Activation form) engr-full.vpn.wisc.edu
engr-split.vpn.wisc.eduUndergraduates (Activation form) engr-lic.vpn.wisc.edu Collaborators (Granted Automatically) engr-collab.vpn.wisc.edu - Once you have chosen your address, enter it into the GlobalProtect Client.

- The client will then prompt you to sign in in a popup window. Enter your username and password.
- Once you are connected, a checkmark will be visible and there will be a button to disconnect:.
- On Windows, in the future (after the first time using GlobalProtect), you will be able to use the drop down menu to choose which VPN you would like to connect to (Full, Split, License, or Collaborator). Please note that you will only be able to connect to the VPN's which you are allowed (see chart above).
- For MacOS, in order to switch VPN's you must first disconnect from the VPN you are using, and then switch the portal address (not the gateway). You may find you need to manually enter the different portal addresses before selecting them in the drop-down. You can do so by going to the menu in the upper right hand corner (three bars) and selecting "Settings." See 2nd image below.


Troubleshooting
Here are some solutions to common problems:
GlobalProtect fails to install
See troubleshooting ideas here:
- Windows: WiscVPN GlobalProtect (Windows) - Troubleshooting
- MacOS: WiscVPN GlobalProtect (macOS) - Troubleshooting
Cannot login to GlobalProtect, authentication failed
Make sure to request VPN access (Activation of VPN access) and wait at least 1 hour.
Cannot access best-tux or Linux lab machine
Collaborators do not have access to lab machines. See CoE VPN "Collaborator" for more information.
If you are trying to use best-tux to get to a cluster and cannot use GlobalProtect, see Access via SSH Proxy (SSHVPN)
Linux installation issues
WiscVPN GlobalProtect (Linux) - Connecting and Disconnecting
File Storage or XenApp Remote Access
In general, userspace, groupspace and myfiles can all be reached from UWnet (on campus WiFi), WiscVPN or any of the CoE VPN types.
No VPN of any kind is needed for XenApp (aka Citrix and Engr remote).
Getting Help
Troubleshooting can be split into two categories: Installation of Palo Alto GlobalProtect, and connecting to the CoE VPN. In either case, you may contact the CAE Help Desk at helpdesk@cae.wisc.edu. Problems installing/connecting with the GlobalProtect client (that is, you are unable to install Palo Alto GlobalProtect and/or connect to Wisc VPN) may be referred to the DoIT Help Desk (help@doit.wisc.edu).
