As of May 16, 2019, UI Anywhere VPN users are required to use Two-Step Login to verify and complete their VPN connections. If you do not have devices enrolled in Duo Two-Step Login, review the Two-Step Login set-up and management instructions.

After downloading and installing Cisco AnyConnect software, UI faculty, staff, and students access the VPN using their HawkID credentials. To connect to the VPN with Cisco AnyConnect, enter your HawkID and password in the "Username" and "Password" fields, then enter your preferred Two-Step Login authentication method into the "Second Password" field.

Step 1: Check your Two-Step Login enrollment

Please review the authentication method you are using for Two-Step login. Your authentication method and other setup details are found on the Two-Step enrollment page:

Screenshot showing Duo setup details

Push notifications to the Duo Mobile app on your phone are the fastest, easiest authentication method, but you also can use phone calls, text messages, and pre-generated passcodes to connect to the VPN. (Follow these instructions to switch to push notifications.)

If you’ve enrolled more than one phone or another device in Two-Step Login, your default device will receive Two-Step notifications unless otherwise specified. Find your default device by looking for the message "This is your default device" in green text:

Screenshot showing Duo setup details

If you need to make changes to your device list, follow these instructions to add/delete a device or change your default device.

Step 2: Complete VPN login with Two-Step authentication

Follow these instructions to complete your VPN login:

  1. Launch the Cisco AnyConnect client. (If you do not have AnyConnect installed, review the AnyConnect download/installation instructions.) If necessary, enter or select "vpn.uiowa.edu" and click/tap the "Connect" button.

  2. Leave "Default" selected in the "Group" field.

  3. Enter your HawkID in the “Username” field.

    Screenshot with username field highlighted

     
  4. Enter your HawkID password in the “Password” field.

    Screenshot with password field highlighted

     
  5. Enter your preferred method in the "Second Password" field in Cisco AnyConnect to complete your VPN login. (Note that the characters you enter will not be shown.)

    Screenshot with second password field highlighted

     

    Refer to the table below for available methods to enter in the "Second Password" field.

     

    push

    Enter “push” (without quotation marks) to receive a push notification if you are using the Duo Mobile Push app. Tap "Approve" on the notification to complete your login.

    phone

    Enter “phone” to receive a phone call at the number you’ve enrolled for two-step logins. Respond to the call to complete your login.

    sms

    Enter “sms” to receive a list of passcodes via text. Your initial authentication attempt will be denied. Repeat the process and enter one of the new passcodes you’ve received.

    (passcode number)

    Enter a valid passcode number received via text, generated by the Duo Mobile app or a token device, or generated from the Two-Step enrollment page.


    The above methods will send notifications to your default device unless otherwise specified. You can direct push notifications, phone calls, or texts to your secondary device by entering “push2,” “phone2,” or “sms2,” respectively.

  6. Click or tap the “Connect” or “OK” button.

  7. After approving the Two-Step Login request, you should receive a message indicating you are now connected to VPN.

Article number: 
115421
Last updated: 
March 16, 2020