GlobalProtect Logo With Virtual Private Network (VPN), staff and students can make secure connection from their home computers or mobile devices to the campus network over the Internet. Data transmitted via VPN connection are encrypted. Users can access certain restricted IT services such as DMS, use SPSS and make connection to some central network servers using SFTP client software outside the campus.

The “Palo Alto GlobalProtect” technology (GlobalProtect VPN) was launched in September 2014. The GlobalProtect VPN requires users to install the GlobalProtect software on their device(s). It then establishes a virtual tunnel to the campus network with authentication using the user’s EdUHK network account and password. For security reasons, the GlobalProtect VPN client software should NOT be used on public computers. Please install and use the software only on computers protected with up-to-date anti-virus software and firewall protection.

 

VPN Network Diagram

 


News:

With effect from 10 Jan 2022, the University’s Virtual Private Network (VPN) service is covered by Multi-Factor Authentication (MFA) on Duo for enhanced protection. Colleagues will be prompted by Duo when they log in the VPN gateway. MFA on Duo provides an additional level of protection for secured login, protecting not only the colleague himself/herself, but also the University. Please see https://www.eduhk.hk/ocio/mfa-duo for more information.

In an effort to provide better user experience for users residing in mainland China, OCIO has subscribed a service via a network operator in China. Starting from 28 May 2020, users can connect to EdUHK VPN using this new VPN gateway in mainland China. For details, please refer to GlobalProtect VPN gateway for Mainland China.



Using GlobalProtect VPN

1. Client Software for Windows and Mac

Desktop computer or notebook users please visit https://vpn.eduhk.hk to download and install the “GlobalProtect” client software.

Supported systems:

Note: For details, please visit Palo Alto Networks® Compatibility Matrix


GlobalProtect portal address configuration

Once you installed the GlobalProtect client on your computer, you have to configure the portal address.

  • Click on the GlobalProtect icon on the system tray (For Windows) / menu bar (For macOS), click the more icon and choose settings.
    GlobalProtect portal address

GlobalProtect VPN gateway for Mainland China

In an effort to provide better user experience for users residing in mainland China, OCIO has subscribe a service via a network operator in China. Users can add the new China VPN portal address in GlobalProtect client. For details, please refer to the user guides.

Please refer to the following user guides for detail instructions.

 



2. Native Apps for Mobile devices

Mobile device users can install “GlobalProtect” app available on Apple App Store (iOS) or Google Play Store (Android).

Supported systems:

 

Please refer to the following user guides for more information on making VPN connection using the respective mobile apps:

 



Tips and best practice on using GlobalProtect VPN

 

  1. The VPN connection is based on the Internet connection of your device to set up a tunnel back to HK. User are recommended to use a fast and reliable connection to enjoy good VPN experience. After the VPN is connected, you could test the network speed by using "www.speedtest.net" which could measure the network throughout. Anything over 10Mbps is good.
  2. Mobile network on mobile devices are not designed for long connection, such as, Zoom meeting which requires higher bandwidth and reliable connection throughout the session.
  3. VPN redirect all the traffic to HK through VPN gateway. If you are in mainland and you just want to access the public web sites in mainland, don’t use VPN as all the traffic will go to HK and back to mainland which introduce unnecessary delay.
  4. VPN usage might be affected by the “Great Firewall” in mainland and the restriction imposed might change from time to time and from location to location.

 



Note: VPN connection ceases automatically every 8 hours. The time out for idle sessions is 4 hours.



If you enter gateway error connecting to the VPN as below, please download the "Sectigo Certificate" at here and install on your system.
VPN Gateway Error