1. Overview

This is a service that allows users to directly access compute nodes through a VPN connection between Supercomputer Fugaku and the user.

2. Client Certification Installation

Client certificate is used when accessing via VPN. Please install it on the OS you want to access via VPN.

This indicates how to install the required client certificate to access to the Supercomputer Fugaku via VPN. Please prepare the followings before installing the client certificate.

  • Client certificate :”user account name .p12” file

  • Client certificate pathphrase

Client certificate Once the account issue is compleded, the client certificate is sent via e-mail to the e-mail address you entered when applying. Please save the attached “local account name.p12” file to the device (e.g. PC) which installs the client certificate. To “local account name.p12” file, the client private key, the client certificate (a public key) and the route certificate of the client certificate issuing authority.

Client certificate pathphrase The passphrase is sent in written form or PDF file separately from the client certificate. It will be required when installing the client certificate. Please store at the safe place

This section describes the procedure for registering a client certificate on your PC.

2.1. Installing the certificate (Windows)

  1. Save a client certificate (“.p12” file) to any location on your device, and then double-click on it.

_images/211.png
  1. Select “ Current User ” on the Certificate Import Wizard screen, and then [ Next ].

_images/212.png
  1. Click on [ Next ] on the File Specification screen.

_images/213.png
  1. Enter the Client certificate pathphrase and click on [ Next ].

_images/214.png
  1. Select “ Automatically select the certificate store based on the type of certificate ” and click on [ Next ].

_images/215.png
  1. Click on [ Finish ].

_images/216.png
  1. If a security warning dialog is displayed, confirm that the Issuer (the following red-letter) is“ RIKEN R-CCS ” and click on [ Yes ].

_images/217.png
  1. Click on [ OK ].

_images/218.png

That’s the end of Client certificate installation procedure.

2.2. Installing the certificate (MacOS)

  1. Save a client certificate (“.p12” file) to any location on your device, and then double-click on it.

_images/221.png
  1. If a dialog about certificate addition is displayed, confirm that Keychain is “ login ” and click on [ Add ].

_images/222.png
  1. Enter Client certificate pathphrase into a password dialog and click on [ OK ].

_images/223.png
  1. Select “ login ” in Keychain and “ Certificates ” in Category at the left pane, and then doubleclick on “ RIKEN R-CCS ” at the right pane.

_images/224.png
  1. Select “ Always Trust ” in “ When using this certificate ”, and close this window.

_images/225.png
  1. If a password dialog is displayed, enter the password of your device and click on [ Update Settings ]. After update, please confirm that the blue plus icon is displayed at the bottom left of“ RIKEN R-CCS

_images/226.png
  1. Click on disclosure triangle at the left your client certificate and double-click on private key (key mark) .

_images/227.png
  1. Change “Name” to the same name of your client certificate , click on [ Save Changes ] and closethis window.

_images/228.png

That’s the end of installation procedure.

3. VPN Connection Setting Procedure

3.1. VPN Connection Setting Procedure (WindowsOS)

3.1.1. Download the installer for the VPN connection tool “FortiClient”.

  1. Access https://www.fortinet.com/support/product-downloads with a web browser.

  2. From 「 FortiClient VPN 」select your OS type ( Windows ) and click DOWNLOAD.

   ※ Download FortiClient VPN, not 「 FortiClient 」.

_images/3111.png

 That’s the end of download procedure.

3.1.2. VPN Tool (FortiClient) Installation Procedure

  1. Save a VPN Tool“ FortiClient VPN ”installer, to any location on your device, and then double-click on it.

_images/3121.png
  1. When the FortiClient Setup Wizard screen opens, check the box for “ Yes, I have read and accept the License Agreement ”, and then click on [ Next ].

_images/3122.png
  1. Click on [ Next ] on the Destination Folder screen.

_images/3123.png
  1. Click on [ Install ].

_images/3124.png
  1. Click on [ Finish ].

_images/3125.png

That’s the end of installation procedure.

3.1.3. VPN New Setting Procedure

  1. Startup ”FortiClient” from “All Programs”

  2. Click on [ Configure VPN ].

_images/3132.png
  1. Click on [ SSL-VPN ] tab in “New VPN Connection”. Then, fill “Connection Name”, ”Description” and Enter [ vpn.fugaku.r-ccs.riken.jp ] in the “Remote Gateway” field.

_images/3133.png
  1. Next, select the installed client certificate from the pull-down menu in the “Client Certificate” field. After selecting, select [ Disable ] in the “Authentication” and click [ Save ].

_images/3134.png

That’s the end of VPN new setting procedure.

3.1.4. VPN Connection Procedure

  1. Click the “VPN Name” pull-down, select the connection destination.

( Make sure that the client certificate of Supercomputer Fugaku is selected.)

_images/3141.png
  1. Click [ Connect ].

  2. When the screen below is displayed, the VPN connection is successful.

_images/3143.png

3.2. VPN Connection Setting Procedure (MacOS)

3.2.1. Download the installer for the VPN connection tool “FortiClient”.

  1. Access https://www.fortinet.com/support/product-downloads with a web browser.

  2. From 「 FortiClient VPN 」select your OS type ( MacOS ) and click DOWNLOAD.

   ※ Download FortiClient VPN, not 「 FortiClient 」.

_images/3211.png

That’s the end of download procedure.

3.2.2. VPN Tool (FortiClient) Installation Procedure

  1. Save a VPN Tool“ FortiClient VPN ”installer, to any location on your device, and then double-click on it.

_images/3221.png
  1. If a warning dialog is displayed, click on [ Open ].

_images/3222.png
  1. Click on [ Install ].

_images/3223.png
  1. Click on [ Continue ] on the Introduction screen.

_images/3224.png
  1. Click on [ Continue ] on the License screen.

_images/3225.png
  1. Click on [ Agree ].

_images/3226.png
  1. Click on [ Install ].

_images/3227.png
  1. If a password dialog is displayed, enter the password of your device and click on [ Install Software ].

_images/3228.png
  1. Click on [ Close ].

_images/3229.png

That’s the end of installation procedure.

3.2.3. VPN New Setting Procedure

  1. Startup ” FortiClient ” by double click on ”FortiClient” from “Application”.

  2. Click on [ Configure VPN ].

_images/3232.png
  1. Click on [ SSL-VPN ] tab in “New VPN Connection”. Then, fill “Connection Name”, ”Description”and Enter [ vpn.fugaku.r-ccs.riken.jp ] in the “Remote Gateway” field.

_images/3233.png
  1. Next, select the installed client certificate from the pull-down menu in the “Client Certificate” field. After selecting, select [ Disable ] in the “ Authentication ” and click [ Save ].

_images/3234.png

That’s the end of VPN new setting procedure.

3.2.4. VPN Connection Procedure

1.Startup ”FortiClient” by double click on ”FortiClient” from “Application”.

2.Click the “VPN Name” pull-down, select the connection destination.

( Make sure that the client certificate of Supercomputer Fugaku is selected.)

_images/3242.png
  1. When the screen below is displayed, the VPN connection is successful.

_images/3243.png

4. Hostname for the compute nodes and Pre/Post nodes

When the VPN connection is used, users can access compute nodes and prepost nodes via following hostname.

  • Compute node

FQDN is the host name followed by cn.fugaku.r-ccs.riken.jp

Example) d22-6008c.cn.fugaku.r-ccs.riken.jp

  • PrePost node

FQDN is the host name followed by pp.fugaku.r-ccs.riken.jp

Example) pps06.pp.fugaku.r-ccs.riken.jp