Body
The Brandeis Virtual Private Network (VPN) provides a secure, encrypted connection to university resources and restricted campus systems when you are working off-campus.
Do You Need the VPN?
Not all Brandeis online services require a VPN connection.
-
VPN Required: Network drives and file shares (files.brandeis.edu), BitLocker, PowerFAIDS, Remote Desktop / SSH, Cascade CMS editor, Student Housing (Adirondack), and off-campus printing (PaperCut).
-
No VPN Needed: Google Workspace (Gmail, Drive), Workday, Zoom, Slack, Moodle, and Box.
Prerequisites
Before setting up GlobalProtect, ensure you have:
-
An active Brandeis username and password.
-
A registered Duo Multi-Factor Authentication (MFA) device.
-
The portal server URL: vpn-connect.brandeis.edu.
Installation & Setup Instructions
Note for Managed/University-Owned Computers: GlobalProtect may already be pre-installed on your device. If you see the GlobalProtect globe icon in your system tray or menu bar, skip the installation steps and jump directly to connecting.
🖥️ Windows
-
Find your system architecture: Go to Start > Settings > System > About, then check System type under Device specifications.
-
Download the installer: Go to vpn-connect.brandeis.edu and log in. Select the installer matching your system (64-bit x64 is most common).
-
Install: Run the downloaded .msi file using default settings. Grant permission if prompted, enter admin credentials if required, and restart your computer when finished.
-
Connect:
-
Open GlobalProtect from the lower-right system tray or search menu.
-
Enter vpn-connect.brandeis.edu as the portal address and click Connect.
-
Sign in through the browser popup using your Brandeis credentials and complete Duo MFA.
🍏 macOS
Supported versions: macOS 13 (Ventura), macOS 14 (Sonoma), macOS 15 (Sequoia), and macOS 26 (Tahoe).
-
Download & Install: Download the macOS installer package from vpn-connect.brandeis.edu. Double-click the file in your Downloads folder, ensure Global Protect and Global Protect System extensions are selected, then click Install.
-
Allow Extension: If prompted about a blocked system extension, go to System Preferences / Settings > Security & Privacy, click Allow, enter administrative credentials if required, and reboot your Mac.
-
Connect:
-
Click the GlobalProtect globe icon in the top menu bar.
-
Enter vpn-connect.brandeis.edu and click Connect.
-
Complete the login and Duo MFA prompts.
To uninstall on macOS: Re-run the downloaded installer package, check Uninstall GlobalProtect, click Continue/Install, and restart your Mac.
🐧 Linux (GUI Only)
Brandeis requires single sign-on (Shibboleth) and Duo MFA, so command-line interface (CLI)-only configurations are not supported. Supported distributions include Ubuntu (20.04, 22.04, 24.04) and Red Hat Enterprise Linux (8.9, 9.1, 9.3).
-
Download the version 6.2 package from vpn-connect.brandeis.edu.
-
Install via Terminal:
-
Enable Default Browser for SAML:
-
Open /opt/paloaltonetworks/globalprotect/pangps.xml in an editor with elevated privileges (e.g., sudo vi pangps.xml).
-
Add <default-browser>yes</default-browser> under <Settings> and save.
-
Reboot your system and connect using vpn-connect.brandeis.edu.
📱 iOS & Android Mobile Devices
-
Search for GlobalProtect (developed by Palo Alto Networks) in the Apple App Store or Google Play Store and install it.
-
Open the app and enter portal address: vpn-connect.brandeis.edu.
-
Tap Connect and allow the device to add the VPN configuration if prompted.
-
Log in with your Brandeis credentials and authenticate with Duo MFA.
Duo Multi-Factor Authentication (MFA)
When authenticating, enter your standard password in the first password field. In the second field, type one of the following commands to trigger Duo:
-
push — Sends a push notification to your Duo Mobile app (Recommended).
-
phone — Initiates an automated phone call to your registered phone number.
-
sms — Sends a passcode via text message.
-
Passcode — Enter a 6-digit passcode generated by your Duo app or security key.
Network Tunnel Modes
-
Faculty & Staff: Automatically assigned a Full-Tunnel connection.
-
Students: Automatically assigned a Split-Tunnel connection.
-
Note: Tunnel modes are configured automatically by ITS and cannot be manually selected.
Need Assistance?
If you encounter issues or require administrative access to install software on a university device, please contact the Brandeis Technology Help Desk: