Setup Procedures for HKUVPN with 2-Factor Authentication (2FA) for Linux

1. Prerequisite

  1. 2-factor authentication (2FA) is required for accessing the HKUVPN service.
  2. Please uninstall any earlier version of Cisco Anyconnect VPN or Cisco Secure Client from your PC before you start the following installation.

2. Configuration Procedures (to be done once only)

The following steps are illustrated using Ubuntu 23.04.
  1. Download the VPN client for Linux from here.
  2. Obtain superuser rights to run the installation script. For example-
  3. sudo bash
  4. Unzip the VPN client with the following command-
  5. tar zxvf cisco-secure-client-linux64-*.tar.gz
  6. The files extracted will be saved in a directory with a name that begins with “cisco-secure-client-linux64-“ under the current directory.
  7. Go to the VPN client directory named “cisco-secure-client-linux64-*/vpn/” and enter the following command:
  8. ./vpn_install.sh
  9. You will be prompted to accept the license agreement as shown below-
  10. Do you accept the terms in the license agreement? [y/n]
  11. Press “y”and “Enter” key to accept the license agreement.
  12. After installation is completed, you will see-
  13. Starting Cisco Secure Client Agent… Done!

3. Connection Procedures

3.1 By command line

  1. Start the VPN client by following command-
  2. /opt/cisco/secureclient/bin/vpn connect vpn2fa.hku.hk
  3. Enter your HKU Portal UID and PIN when you see the username and password command line.
  4. Username: Password:
  5. (i) Applicable to staff/students who choose EMAIL TOKENYou will receive an email containing the 6-digit email token to your registered alternate email address. The token is valid for 5 minutes after its sent out time.
  6. vpn_connect_03

    (ii) Applicable to staff who choose APP TOKEN

    Please retrieve the app token from your mobile device. The token is valid for 1 minute after it is obtained.

    Note: For installation of the mobile app, please refer to here.

    On Android devices- On iOS devices-
    • Open FortiToken Mobile
    .vpn_connect_10
    • Open FortiToken.
    vpn_connect_08
    • Enter your PIN of 4 digits to unlock the app.
    2fa_token_01
    • Enter your PIN of 4 digits to unlock the app.
    2fa_token code_02
    • App token will be retrieved.
    vpn_connect_12v
    • App token will be retrieved.
    vpn_connect_13
  7. Enter the 6-digit One Time Password in the Answer command line and press Enter.
    >> Authentication Message >> Please enter your token code: Answer: <6-digit One Time Password>
  8. When connected, you will see-
    >> notice: Establishing VPN… >> state: Connected
  9. To disconnect from VPN connection, type the following command-
    /opt/cisco/anyconnect/bin/vpn disconnect

3.2 By GUI client

  1. Start the VPN client by the following command-
    /opt/cisco/anyconnect/bin/vpnui
  2. Type “vpn2fa.hku.hk” in the Connect to field and click Connect.
  3. Type “vpn2fa.hku.hk” in the Connect to field and click Connect.
  4. Enter your HKU Portal UID and PIN in the Username and Password fields respectively and click Connect.
  5. Enter your HKU Portal UID and PIN in the Username and Password fields respectively and click Connect.
  6. (i) For students and staff who choose to use email token. You will receive an email containing the 6-digit email token to your registered alternate email address. The token is valid for 5 minutes after its sent out time.vpn_connect_03

    (ii) For staff who choose to use app token, please retrieve the app token from your mobile device. The token is valid for 1 minute after it is obtained. Note: For installation of the mobile app, please refer to here  

    On Android devices- On iOS devices-
    • Open FortiToken Mobile.
    • vpn_connect_10
    • Open FortiToken.
    • vpn_connect_08
    • Enter your PIN of 4 digits to unlock the app.
    • 2fa_token_01
    • Enter your PIN of 4 digits to unlock the app.
    • 2fa_token code_02
    • App token will be retrieved.
    • vpn_connect_12v
    • App token will be retrieved.
    • vpn_connect_13
  7. Enter the 6-digit One Time Password in the Answer box and click Continue.
  8. e.	Enter the 6-digit One Time Password in the Answer box and click Continue.
  9. To disconnect from HKUVPN server, click Disconnect.
  10. To disconnect from HKUVPN server, click Disconnect.
1
2

MFA

Multi-Factor Authentication

February 2024
February 2024

Mandatory for all staff accounts

May 2024
May 2024

Mandatory for all student accounts