This article explains how to set up a client VPN on your DNA.
- Log in to the DNA and choose the Security tab.
- Choose the Client VPN tab from the left pane and download the VPN gateway certificate to the desired machine.
- From an Admin user account, open Microsoft Management Console (search for or run "mmc.exe").
- In the Console dialog box, select File > Add or Remove Snap-in.
- From the Available snap-ins list, select "Certificates," then click Add. In the resulting window, select "Computer Account" and click Next. Then select "Local Computer" and click Finish. Finally, click OK to close the Add or Remove Snap-ins dialog.
- Back in the Console1 dialog, expand the Certificates category and select Trusted Root Certification Authorities > Certificates. Choose Action in the menu bar > All tasks > Import. From here, click next on the Welcome screen.
- Click browse and make sure the drop down for file type is set to All Files shown at the bottom right. Then choose the Certificate you saved earlier from Step 2 and click open. Click Next and then Finished.
- Click the Windows start button and type "network". From the list of options, choose Network and Sharing Center. Select Set Up a new Connection or Network > Connect to a Workplace > Use my Internet Connection (VPN) and enter the Assigned Public Address of the DNA which you can find on the Network Overview tab of the DNA under Router Details.
- Back on the "Network and Sharing Center" Click Change Adapter Settings, right click on the VPN Connection and click "properties".
- From the connection's Properties window, choose the Security tab and choose "IKEv2" for the Type of VPN. For Authentication, choose Microsoft: Secured Password (EAP-MSCHAP v2) (encryption enabled) and then click the Networking tab, select IPv4 -> click Properties -> select Advanced and verify that "Use default gateway" is checked. Click OK to and exit all dialogue boxes. You should now be able to connect to the VPN.
- When you choose connect for the first time, it will prompt you for login credentials which you should have set from the DNA client VPN page.