Gear up virtual private networks (VPNs)

Your Chromebook tin connect to a private network, like the network at your work or school, using a Virtual Private Network (VPN) connectedness.

Note: If y'all're using your Chromebook at work or school and have problems setting upward your VPN, contact your administrator for more help.

L2TP/IPsec VPN support

Your Chromebook has built-in back up for VPNs that utilize L2TP over IPsec. The IPsec layer volition either employ a pre-shared central (PSK) or user certificates to fix the secure tunnel. The L2TP layer requires a username and password.

Tip: Cisco ASA devices can be prepare to support L2TP over IPSec. Learn how to gear up a Cisco ASA device.

  1. At the lesser right, select the time.
  2. Select Settings.
  3. In the "Network" department, select Add connection.
  4. Next to OpenVPN / L2TP, select Add .
  5. In the box that appears, fill in the info. If you're using your Chromebook with an arrangement, you might need to become this information from your administrator.
    • Server hostname: This can either be the IP address or the full server hostname.
    • Service name: This can exist anything you want to name this connection. For case: "Piece of work VPN."
    • Provider type: Select L2TP/IPsec + Pre-shared key or L2TP/IPsec + User certificate.
    • Username, Password: Your L2TP/PPP credentials. Each VPN user should have their own unique username and password.
    • Group proper noun: The client's IPsec identity field, which some VPN servers apply to set the Tunnel Group or User Realm. If yous're unsure, leave this field empty.
    • Pre-shared key: Used for PSK connections only. This central isn't your personal password, just a passphrase or key used in the IPsec configuration. In a typical set-up, anybody who connects to the aforementioned VPN server will use the same PSK.
    • Server CA document: Used for user document connections only. Select your installed document authority certificate from the list. The server's document volition exist checked to ensure that it was signed past the right certificate authority (CA). If you are having problem with your server certificate, y'all can select "Don't check" to skip CA validation; notwithstanding, this skips an of import security measure.
    • User certificate: Used for user document connections only. Select your installed user VPN certificate from the listing. If yous don't take whatever certificates installed, you'll see an mistake message. To install a certificate, see the instructions below.
  6. SelectConnect.

OpenVPN support

Your Chromebook has bones back up for OpenVPN servers. OpenVPN connections can use username/password authentication, customer certificate authentication, or a combination of both.

If you need to set upwardly more avant-garde features of OpenVPN or import an ".ovpn" configuration file, and your Chromebook supports the Play Store, consider installing OpenVPN for Android instead of using the built-in OpenVPN client.

  1. At the bottom right, select the fourth dimension.
  2. Select Settings.
  3. In the "Network" department, select Add connection.
  4. Side by side to OpenVPN / L2TP, select Add .
  5. In the box that appears, fill in the info. If you're using your Chromebook with an arrangement, you might need to get this information from your ambassador.
    • Server hostname: This tin either be the IP address or the full server hostname.
    • Service name: This tin can be anything you lot want to proper name this connectedness. For example: "Work VPN."
    • Provider type: Select OpenVPN.
    • Username and password: Your VPN credentials. This can be left blank if your server merely uses client certificate authentication.
    • OTP: If yous have an OTP card or VPN token that generates one-time passwords, become a password and enter it hither. In most cases, you'll go out it blank.
    • Server CA document: Select your installed certificate authority certificate from the listing. The server's certificate will be checked to ensure that information technology was signed by the correct document dominance (CA). If you are having trouble with your server certificate, you tin select "Don't check" to skip CA validation; withal, this skips an of import security measure.
    • User certificate: If your VPN server requires client certificate authentication, select your installed user VPN document from the list. To install a document, see the instructions below.
  6. SelectConnect.

PPTP VPN back up

Chromebooks with the Play Store can connect to PPTP VPN services.

  1. At the bottom right, select the fourth dimension.
  2. Select Settings.
  3. Whorl downwardly and selectGoogle Play Store.
  4. SelectManage Android Preferences.
  5. Scroll down and selectPPTP VPN.
  6. In the upper correct, select Add .
  7. In the box that appears, make full in the info. If you're using your Chromebook with an organization, you might need to become this information from your administrator.
    • Name: This tin can exist anything y'all desire to name this connection. For example: "Work VPN."
    • Server accost: The name of the server you demand to connect with to access your VPN. This tin either be the IP address or the full server hostname.
    • PPP encryption (MPPE): Leave this checked unless your administrator says otherwise.
    • Show advanced options: Leave this unchecked unless your administrator says otherwise.
    • Username and password: Your VPN credentials. Each VPN user should have their own unique username and password.
  8. SelectRelieve.

To connect to a PPTP VPN, go to the PPTP VPN menu and select the name of the VPN connection.

Note: Currently, the Google Play Store is merely available for some Chromebooks. Learn which Chromebooks support Android apps.

Android VPN apps

Chromebooks with the Play Store can install Android VPN apps.

Important: Currently, the Google Play Shop is only available for some Chromebooks. Learn which Chromebooks support Android apps.

To create a new connection or to connect to a VPN provided by an Android app:

Stride 1: Install an Android VPN app on your Chromebook

  1. In the corner of your screen, select the Launcher and then Up pointer .
  2. Select Play Store Google Play.
  3. Search for the VPN app you desire to install.
  4. Select the VPN app.
  5. On the right, select Install.

Step 2: Configure the VPN app to your Chromebook

  1. At the bottom right, select the fourth dimension.
  2. Select Settings .
  3. In the "Network" department, select Add connection.
  4. Next to a connection, select Add [app name]... .
  5. Follow the onscreen instructions.

Stride 3: Go on your VPN connection on

Some VPNs tin can always stay connected unless your VPN connexion stops.

  1. Brand sure y'all configured a VPN app to your Chromebook.
  2. At the bottom right, select the time.
  3. Select Settings .
  4. On the left panel, select Apps.
  5. Under "Apps," select Google Play Shop.
  6. Select Manage Android preferences.
  7. In the window that appears, select Network & net.
  8. Select VPN. Your VPN app should now be listed.
  9. To the correct of your app, select Settings .
  10. Plough on Always-on VPN. If your Always-on VPN connectedness stops, you lot get a notification that stays on until you reconnect. To clear the notification, turn off that specific Always-on VPN.

Tip: If your VPN connection stops and you don't want to connect directly to the internet, turn on Cake connections without VPN.

Dissever tunnel and full tunnel

Typically VPNs implement a full tunnel, which ways that all traffic from all Chrome windows, Chrome apps, and Android apps will pass through the VPN connection. Sometimes you'll want to use a split tunnel so that only sure sites will be accessed through the tunnel, while other traffic will skip the VPN and utilize your Chromebook's physical network connection instead. This is useful if:

  • Your VPN only provides access to internal sites, merely not total cyberspace access.
  • You need to communicate with devices on your local network, such every bit printers, while connected to the VPN.

Many Chrome and Android VPN apps, and the built-in OpenVPN customer, can exist prepare to utilize split tunnel manner. For help setting this upwards, enquire your administrator.

Install certificates

Y'all might need certificates to connect to a VPN, WPA2 Enterprise network, like EAP-TLS, or a website that requires mutual TLS authentication. If so, your administrator might inquire y'all to visit a special website while continued direct to your organization's network, or download and install the certificates directly yourself.

You'll demand:

  • A server certificate that'due south for anybody at your system
  • A user document that is specific to you

Install your server document

  1. Download your server certificate, co-ordinate to the steps your administrator gives you.
  2. Open a new tab in Chrome Chrome.
  3. In the address bar, enter chrome://settings/certificates
  4. Select the Government tab.
  5. SelectImport and cull the X.509 certificate file, which is ordinarily a file with a .pem, .der, .crt, or .p7b extension.
  6. In the box that appears, make full out the info. None of these settings demand to be turned on, and then nosotros recommend that yous leave these unchecked.
  7. The certificate volition open and install itself on your Chromebook.

Install your user certificate

  1. Download your user certificate, according to the steps your administrator gives you. Your certificate filename should end with .pfx or .p12.
  2. Open a new tab in Chrome Chrome.
  3. In the address bar, enter chrome://settings/certificates
  4. SelectYour certificates.
  5. SelectImport and Demark.
  6. In the box that opens, select the document file and selectOpen.
  7. When prompted, enter the password for your certificate. If y'all don't know the countersign, contact your network ambassador. If you don't have a password, selectOK.
  8. The certificate will open and install itself on your Chromebook.

Chromebooks but support RSA client certificates for authenticating to VPNs or EAP wireless networks. ECC client certificates aren't supported.

Related articles

  • If y'all're a network administrator, you lot tin assistance your users install user certificates at scale using an extension.
  • Set up VPN on a Cisco ASA device
  • Prepare DNS issues

Was this helpful?

How can we improve it?