Government of Newfoundland and Labrador - Remote Access Guide SYSTEM OVERVIEW – GOVERNMENT OF NEWFOUNDLAND AND LABRADOR REMOTE ACCESS SOLUTION (SECURID) Version – 1.3 Date – 2012-03-26 Government of Newfoundland and Labrador - Remote Access Guide Contents 1.0 Purpose ........................................................................................................................... 1 2.0 RSA SecurID Remote Access Service ........................................................................... 1 3.0 Connect to the Remote Access Service using Hardware Tokens ............................... 2 3.1 Create a New PIN ...................................................................................................... 2 3.2 Log in with your PIN and Hardware Token ................................................................. 3 4.0 Connect to the Remote Access Service using Software Tokens ................................ 5 4.1 Create a PIN for your RSA Software Token ............................................................... 5 4.2 Logging in with your PIN and software token ............................................................. 7 Government of Newfoundland and Labrador – Remote Access Guide 1.0 Purpose This document instructs the user on the login procedure for the Government of Newfoundland and Labrador’s remote access service, which is also known as SSL VPN. This service is managed and supported by the Office of the Chief Information Officer (OCIO). 2.0 RSA SecurID Remote Access Service RSA SecurID tokens are used as the primary login technology for the Remote Access Service (SSL VPN). The OCIO issues two types of SecurID tokens: 1. Hardware token – this token is given to the user. Hardware token 2. Software token – this token is installed on the user’s computer. Software token There are differences in the login procedure for both types of tokens. The procedures for hardware tokens are detailed in Section 4.0, and the procedures for software tokens are described in Section 5.0. If you currently use the remote access service and have forgotten your PIN, please contact the OCIO IT Service Desk at 709-729-4357. Page 1 of 11 Government of Newfoundland and Labrador – Remote Access Guide 3.0 Connect to the Remote Access Service using Hardware Tokens Section 4.1 describes how to create a SecurID PIN for your hardware token. If you already have a SecurID PIN, please proceed to Section 4.2. 3.1 Create a New PIN As a new user, your SecurID username would have been sent to you via e-mail, and that username is associated with your SecurID only. If you did not receive an e-mail, or can’t remember your username, please contact the OCIO IT Service Desk at 709-729-4357. Please ensure you have your hardware token when you call. You must first contact the OCIO IT Service Desk at 709-729-4357 to activate your account. You will be asked to answer the three questions with the same answers that you provided on the Remote Access Request Form. Once your account is activated, you will need to create a SecurID PIN. Go to the SSL VPN Login Page at the URL https://connect.gov.nl.ca, as shown below: SSL VPN Login Page Page 2 of 11 Government of Newfoundland and Labrador – Remote Access Guide Enter your SecurID username in the username field. In the password field, enter the six digits displayed on the SecurID token. You will then be prompted to create a new SecurID PIN. Your PIN must be four to eight digits, and it cannot start with zero (0). “New PIN Required” Screen Once you have created a PIN and saved it, you will be redirected to the Secure Remote Access login page. You may have noticed that the number on your SecurID token changes every few minutes. Wait for the number on the SecurID token to change and proceed to Section 4.2. 3.2 Log in with your PIN and Hardware Token If not already there, you will first need to go to the Government of Newfoundland and Labrador’s Remote Access website. Open your internet browser, and go to https://connect.gov.nl.ca (we suggest you add this site to your browser “Favorites”). Enter your username in the “username” field. Enter your PIN in the “password” field, and then enter the number which is displayed on the SecurID token (to clarify, you should enter both your PIN and your token number in the password field together, with no spaces between the numbers). Upon successful login, a utility which performs a system check will be installed/activated on your computer. You may be prompted to install a Juniper Active X control during the initial install. Below is a screenshot of the prompt: Juniper Active X Install Please select “Install”, as this host checker is required. If you do not install this software, you will not be able to remotely connect to the government network. The installation of this Active X Page 3 of 11 Government of Newfoundland and Labrador – Remote Access Guide control is a one-time event; the software will validate certain elements of your computer to ensure it is safe to allow a remote connection to the network. Once this process is complete, you will be presented with your profile page. This profile is referred to as “Network Connect”. You may see a message that states: “Network Connect has been enabled on the remote user’s profile.” Network Connect appears as follows: Network Connect Display NOTE: Network Connect has been configured to start automatically. You should notice this icon in your system tray (down in the clock area on your screen). This icon indicates that Network Connect has started. If you don’t see this icon in the system tray, select the start button as noted above to start your Network Connect session. Once Network Connect has started you are now connected to the government network. Page 4 of 11 Government of Newfoundland and Labrador – Remote Access Guide 4.0 Connect to the Remote Access Service using Software Tokens Section 5.1 describes how to create a SecurID PIN for your software token. If you already have a PIN please proceed to Section 5.2. 4.1 Create a PIN for your RSA Software Token As a new user, your SecurID username would have been sent to you via e-mail, and that username is associated with your SecurID only. If you did not receive an e-mail, or can’t remember your username, please contact the OCIO IT Service Desk at 709-729-4357. Please ensure that you have your laptop available when you call. First, you must contact the OCIO IT Service Desk at 709-729-4357 to activate your account. You will be asked to answer the three questions with the same answers that you provided on the Remote Access Request Form. Once your account is activated, you will need to create a SecurID PIN. From your desktop, select the RSA icon. A standard installation by the OCIO includes an RSA icon on the desktop, and this software can also be accessed through the “start” menu in Windows. The following window will be displayed: Software Token Leave the PIN field blank and select the arrow on the right hand side (circled above) and you will be directed to the token code screen. Token Code Screen NOTE: Do not proceed unless there are more than 3 “blue blocks” underneath the token code. If there are less than 3 blocks simply wait a few moments for the number to refresh. Select the “Copy” button to copy the eight digit passcode. Page 5 of 11 Government of Newfoundland and Labrador – Remote Access Guide You will now need to go to the Remote Access website. Open your internet browser and go to https://connect.gov.nl.ca to connect to this site Once you have this site displayed, it is suggested you add it to your browser “Favorites”. SSL VPN Login Page Enter your username in the username field. In the password field, paste the copied eight digit passcode (you may use CTRL-V or simply right-click your mouse to paste). You will then be prompted to create a new PIN. Your PIN must be four to eight digits and cannot start with zero. New PIN Screen Once you have created a PIN and saved it, you will be directed back to the login page. Wait for the number to change in your software token, and follow the steps below to login to the SSL VPN. Select the “Re-enter PIN” button to reset the SecurID software token. Page 6 of 11 Government of Newfoundland and Labrador – Remote Access Guide Software Token You will now return to the screen noted below. Leave this open on your monitor. Software Token 4.2 Logging in with your PIN and software token Before going to the web page to log into SSL, you will need to get a token code. In order to get a code, simply go to the RSA software and enter your PIN and select the arrow on the right hand side. Software Token Select the “Copy” button to hold a copy of your PIN and token number for pasting into the password field of the SSL VPN Login page Software Token Page 7 of 11 Government of Newfoundland and Labrador – Remote Access Guide You will now need to go to the Remote Access website. Open your internet browser and go to https://connect.gov.nl.ca to connect to this site (once you have this site displayed we suggest you add it to your favorites in your browser). SSL VPN Login Page Enter your username in the username field and paste your copied SecurID PIN/token code to the password field (you may use CTRL-V or simply right-click your mouse to paste). Then select the “Login” button. Page 8 of 11 Government of Newfoundland and Labrador – Remote Access Guide You may be prompted to install a Juniper Active X control during the initial install. Juniper Active X Install Please select “Install”, as this host checker is required (if you do not install this software, you will not be able to remotely connect to the government network). The installation of this Active X control is a one-time event. This software validates certain elements of your computer to ensure it is safe to allow a remote connection to the network. Once this process is complete, you will be presented with your profile page. This profile is referred to as “Network Connect”. You may see a message that states: “Network Connect has been enabled on the remote user’s profile”. Network Connect appears as follows: Network Connect Display NOTE: Network Connect has been configured to start automatically. You should notice this icon in your system tray (down in the clock area on your screen). This icon indicates that Network Connect has started. If you don’t see this icon in the system tray, select the start button as noted above to start your Network Connect session. Once Network Connect has started you are now connected to the government network. Page 9 of 11