I did have other things to do... (I'm the author.) Also, I fumbled on the VM setup with VirtualBox—should have just used my vSphere Windows 10 instance, but it was already set up for sandboxing malware.
By VPN startups, they mean initiation of a VPN session. Specifically, this means they can grab the credentials at the beginning of a PPTP VPN session, and then decrypt it. PPTP has been known to be vulnerable to this sort of attack for some time.
With the contract switching from Raytheon to Lockheed, the general NSF support contract should have a bunch of IT positions opening up next research season, I'd think.