NACT IT — 遠端連線服務
在家或出差時,安全連回公司完成 Okta / Gmail 登入。本服務取代舊的 FortiClient SSL-VPN。
舊的 FortiClient SSL-VPN 將於 7/31 停止服務,8/1 起全面改用 NetBird。仍在使用舊 VPN 的同仁,請務必在期限內完成轉換。
📬 已在使用舊 VPN 但還沒收到邀請信?請儘速聯絡 IT 課。
ℹ️ 本網頁預計開放至 8/31;相同內容在公司內部 Outline「IT 公告」也有,之後請改看:
outline.readtw.local/doc/vpn-netbird-cmNzhocKvV(公司內網開啟)
部分公司服務(如 Okta / Gmail)僅允許從受信任的公司網路登入。連上 VPN 後,你在外面的登入視同從公司出發。
只有經核准的公司系統與登入流量走 VPN,一般私人網站流量不經過公司,對日常上網影響較小。
電腦到公司之間全程加密,降低資料在傳輸途中遭竊聽的風險。提醒:依集團政策,請避免在公共場所處理公司事務。
三件事先確認,少走回頭路
私人電腦、手機、平板即使自行安裝了 App,也不會取得任何公司存取權限,Okta 同樣會拒絕登入 —— 這是集團裝置信任政策,不是故障。
從收到邀請信開始,全程約 10 分鐘;卡住任何一步都可以直接找 IT 課
公司信箱會收到一封來自 noreply@nidec-read.com.tw 的邀請信,點信中連結設定密碼。
密碼需 14 碼以上,含大寫、小寫、數字、符號。
接著畫面會要求設定「兩步驟驗證」 —— 意思是:除了密碼,還要用手機上顯示的 6 位數字證明是你本人。照著做:
以後每次登入 VPN:輸入密碼後,再打開手機 Authenticator,輸入當下顯示的 6 位數字(數字每 30 秒會換,輸入最新的就對了)。手機只是當鑰匙用,不需要在手機上裝 VPN。
IT 會提供安裝檔;也可以自行到官方下載頁,點「MSI installer」下載:
docs.netbird.io/get-started/install/windows
下載後打開安裝檔(.msi),一路按「下一步」到完成即可。
若系統要求系統管理員權限,或無法自行安裝,請聯絡 IT 課協助。
App 裝好後先不要按連線,要先把公司的網址填給它。整段只做一次,以後不用再改。
網址請整段複製貼上,不要手打 —— 少一個字母就連不上。
wang.xiaoming,不含 @ 後面的部分)、步驟 1 設定的密碼,以及手機 Authenticator 當下顯示的 6 位數字依序檢查三件事:
① Networks 開關沒打開 —— 開 App 的 Networks(網路)頁面,把列出來的每一項開關都打開,再試一次。
② Networks 列表是空的 —— 把連線開關關掉再打開一次(會重新登入);還是空的,聯絡 IT 課。
③ 你用的是私人裝置 —— Okta 只放行公司管理的裝置,換公司配發的裝置即可。
先確認電腦本身連得上網路(開個一般網頁試試),再關掉開關重開一次。仍然不行,截圖畫面找 IT 課。
直接聯絡 IT 課重設,重設後照步驟 1 重新設定即可。
VPN 能連到的範圍,是依你在 Spendia 申請單勾選的權限開通的 —— 申請單上沒填的系統就連不到,這不是故障。需要新的權限,請再提一張申請單註明用途。
公司電腦直接開就可以(所需設定已由公司系統預先配置)。打得開但登入不了,代表你還沒有該系統的帳號 —— 依各系統的申請流程辦理。
IT 課 — Jasmine(分機 112)/ Yunus(分機 218)/ Den(分機 217),或 email。
帳號為個人專用,請勿共用;離職時帳號將由 IT 停用。
NACT IT — リモート接続サービス
在宅勤務や出張先から、Okta / Gmail へ安全にログインするためのサービスです。従来の FortiClient SSL-VPN に代わるものです。
従来の FortiClient SSL-VPN は 7月31日でサービス終了し、8月1日より NetBird に全面移行します。旧 VPN をご利用中の方は、期限までに切替をお済ませください。
📬 旧 VPN をご利用中で招待メールがまだ届いていない方は、至急 IT 課までご連絡ください。
ℹ️ 本ページの公開は 8月31日までを予定しています。同じ内容は社内 Outline「IT 公告」にもあります:
outline.readtw.local/doc/vpn-netbird-cmNzhocKvV(社内ネットワークから)
一部の会社サービス(Okta / Gmail など)は、信頼された社内ネットワークからのログインのみ許可されています。VPN 接続中は、社外からのログインも社内からのアクセスとして扱われます。
承認された会社システムとログイン通信のみが VPN を経由します。一般的な私的通信は会社を経由せず、日常利用への影響は軽微です。
PC と会社の間は全区間暗号化され、転送中のデータが盗聴されるリスクを低減します。なお、グループポリシーにより、公共の場所での業務はお控えください。
3 点を先にご確認ください
私物の PC・スマホ・タブレットにアプリをインストールしても、会社リソースへのアクセス権は一切付与されず、Okta もログインを拒否します。これはグループのデバイス信頼ポリシーによるものであり、故障ではありません。
招待メール受信から約 10 分。途中で詰まったら IT 課へ
会社メールに noreply@nidec-read.com.tw から招待メールが届きます。メール内のリンクからパスワードを設定してください。
パスワードは 14 文字以上、大文字・小文字・数字・記号をすべて含む必要があります。
続いて「二段階認証」の設定を求められます — パスワードに加え、スマホに表示される 6 桁の数字で本人確認を行う仕組みです:
以後のログインは毎回:パスワード入力後、スマホの Authenticator にその時表示されている 6 桁を入力します(数字は 30 秒ごとに変わります)。スマホは鍵として使うだけで、スマホ側に VPN を入れる必要はありません。
IT がインストーラーを提供します。公式ダウンロードページから 「MSI installer」をクリックしてダウンロードすることもできます:
docs.netbird.io/get-started/install/windows
ダウンロードしたインストーラー(.msi)を開き、「次へ」を押していけば完了です。
管理者権限を求められた場合や、インストールできない場合は、IT 課までご連絡ください。
インストール後、まだ接続ボタンを押さず、先に会社の URL を設定します。この作業は一度だけです。
URL は必ずコピー&ペーストしてください。手入力は一文字違うだけで接続できません。
wang.xiaoming、@ 以降は不要)、ステップ 1 のパスワード、スマホの Authenticator の 6 桁を入力順にご確認ください:
① Networks のスイッチが OFF — アプリの Networks 画面で、表示されている項目のスイッチをすべて ON にして再試行。
② Networks の一覧が空 — 接続スイッチを OFF → ON(再ログインが走ります)。それでも空の場合は IT 課へ。
③ 私物端末を使用している — 会社支給 PC に切り替えてください。
まず PC 自体がインターネットに接続できるか確認(通常のウェブページを開いてみる)し、その後スイッチを OFF → ON。改善しない場合は、画面のスクリーンショットを添えて IT 課へ。
IT 課へご連絡ください。リセット後、ステップ 1 の手順で再設定できます。
接続範囲は Spendia 申請書で選択した権限に基づいて付与されます。申請していないシステムには接続できません(故障ではありません)。追加が必要な場合は、用途を明記のうえ再度ご申請ください。
会社 PC ならそのまま開けます(必要な設定は配布済みです)。ページは開けるがログインできない場合は、そのシステムのアカウントが未発行です — 各システムの申請フローに従ってください。
IT課 — Jasmine(内線 112)/ Yunus(内線 218)/ Den(内線 217)、または email。
アカウントは本人専用です。共有はお控えください。退職時は IT がアカウントを停止します。
NACT IT — Remote Access Service
Sign in to Okta / Gmail securely while working from home or on business trips. This service replaces the legacy FortiClient SSL-VPN.
The legacy FortiClient SSL-VPN shuts down on 7/31, and NetBird becomes the only remote-access VPN from 8/1. If you still use the old VPN, please complete the switch before the deadline.
📬 Already using the old VPN but haven't received your invitation email? Please contact IT as soon as possible.
ℹ️ This page is planned to remain available until Aug 31. The same guide lives on the internal Outline ("IT announcements"):
outline.readtw.local/doc/vpn-netbird-cmNzhocKvV (company network)
Some company services (e.g. Okta / Gmail) only allow sign-ins from the trusted company network. With the VPN on, signing in from outside looks like signing in from the office.
Only approved company systems and sign-in traffic use the VPN; ordinary personal browsing bypasses the company, with minimal impact on daily use.
Everything between your PC and the company is encrypted end to end, reducing the risk of eavesdropping in transit. Reminder: per group policy, please avoid handling company business in public places.
Three things to confirm first
Installing the app on a personal PC, phone, or tablet grants no access whatsoever, and Okta will still reject the sign-in. This is group device-trust policy, not a malfunction.
About 10 minutes from the invitation email; stuck anywhere, just contact IT
An invitation from noreply@nidec-read.com.tw arrives in your company mailbox. Click the link and set your password.
Passwords must be at least 14 characters and include uppercase, lowercase, a number, and a symbol.
You'll then be asked to set up two-factor authentication — on top of your password, a 6-digit code on your phone proves it's really you:
Every future VPN sign-in: enter your password, then the 6-digit code currently shown in Authenticator (it changes every 30 seconds — always use the latest one). Your phone is just the key; you do not install the VPN on it.
IT provides the installer, or download it yourself from the official page — click the "MSI installer":
docs.netbird.io/get-started/install/windows
Open the downloaded .msi file and click "Next" until finished.
If Windows asks for administrator rights or the install fails, contact IT for assistance.
After installing, don't press Connect yet — first give the app the company URL. You only do this once.
Always copy-paste the URL — one wrong letter and it won't connect.
wang.xiaoming, nothing after @), your Step-1 password, and the current 6-digit code from AuthenticatorCheck in order:
① Networks switches are off — In the app's Networks page, turn every listed switch on and retry.
② The Networks list is empty — Toggle the connection off and on (it re-authenticates); still empty, contact IT.
③ You're on a personal device — switch to a company-issued PC.
First confirm the PC itself is online (open any normal website), then toggle off and on. If it still fails, send IT a screenshot.
Contact IT for a reset, then repeat Step 1.
Access is granted per the permissions ticked on your Spendia application. Systems you didn't apply for are unreachable by design, not broken. Submit a new application stating the purpose if you need more.
On a company PC they just open (required settings are pre-deployed). If a page opens but you can't log in, you don't have an account for that system yet — follow its own application process.
IT — Jasmine (ext. 112) / Yunus (ext. 218) / Den (ext. 217), or email.
Accounts are personal; do not share them. IT disables accounts upon resignation.