Principal Investigators (PIs) are required to sponsor external (non-Mount Sinai) collaborators via SailPoint. All Minerva login nodes are internal, meaning all users require an active Mount Sinai VPN account for off-campus cluster access. External collaborators cannot request institutional or cluster access on their own.

Essential Access & Renewal Rules:

  • Mandatory VPN: Required for all off-campus connections to Minerva internal login nodes.
  • 120-Day Expiration: Network/VPN access expires every 120 days. PIs will receive an automated SailPoint notification 21 days prior to expiration to extend or terminate sponsorship.

Step 1: PI Sponsorship Actions (SailPoint)

The PI must initiate the onboarding process from within the Mount Sinai network:

  1. Create External Researcher Identity: Submit an identity request via the Non-Employee Registration Portal. Under School Department, select Minerva Restricted User.
  2. Provision Network & MFA Entitlements: Submit a “Request Access” request through SailPoint Application Access for:
    • School VPN Tunnel
    • Azure MFA Registration
  3. Provide Mount Sinai ID: Once approved, provide the assigned Mount Sinai user ID (Life Number / network ID) to the external collaborator.

Step 2: Collaborator MFA & VPN Connection

Once the PI confirms your identity profile is active, complete your authentication and VPN setup:

  1. Configure Azure MFA: Self-register your passwordless authentication or push notifications via Microsoft MFA Setup.
  2. Connect to Mount Sinai VPN: Log in to the VPN gateway at Mount Sinai VPN Portal using your institutional credentials and Azure MFA (see IT Security for documentation).
Browser Recommendation: Use Mozilla Firefox when accessing the F5 VPN portal. Chrome may encounter launch issues with the F5 endpoint client.

F5 Setup Instructions for Linux (Ubuntu)

If connecting from an Ubuntu environment:

  1. Navigate to https://mshmsvpn.mssm.edu/my.policy and sign in with Azure MFA.
  2. Download the linux_deb client package from the landing page.
  3. Open your terminal, navigate to your download directory, and install the package:
Shell
sudo apt install ./<package_name>.deb

On the web portal, click Tunnel. When prompted by F5, select the client executable located at /opt/f5/vpn/f5vpn.

Step 3: Request Minerva Account & Log In

With an active VPN tunnel established, you can now apply for your cluster credentials and log in:

  1. Apply for a Minerva Account: Navigate to the Minerva Account Request Portal. Ensure you:
    • Enter the Mount Sinai ID provided by your PI.
    • Select the “external account” checkbox on the application form.
  2. Receive Confirmation: Await the confirmation notification stating your Minerva cluster account is active.
  3. Connect via SSH: Log into the Minerva cluster login nodes using your terminal:
Shell
ssh your_Minerva_userid@minerva.hpc.mssm.edu

Enter your school password and verify the session using Azure MFA. For further connection settings, visit Minerva Login Documentation.

Step 4: Technical Support & Help Desk

For assistance with school VPN, MFA, or SailPoint identity requests, contact Academic Support Computing (ASCIT):

For questions regarding your Minerva cluster account, job submission, or computational resources, reach out directly to the HPC team:

Minerva High-Performance Computing • Scientific Computing & Data