|
Virtual Private Network (VPN) Policy
1.0 Purpose
The purpose of this policy is to provide guidelines for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the AUS corporate network.
2.0 Scope
This policy applies to all AUS faculty, staff, contractors, consultants, temporaries, and other workers including all personnel affiliated with third parties utilizing VPNs to access the AUS network. This policy applies to implementations of VPN that are directed through an IPSec Concentrator.
3.0 Policy
Approved AUS faculty and staff and authorized third parties (customers, vendors, etc.) may utilize the benefits of VPNs, which are a "user managed" service. This means that the user is responsible for selecting an Internet Service Provider (ISP), coordinating installation, installing any required software, and paying associated fees. Further details may be found in the Remote Access Policy.
Additionally,
- It is the responsibility of faculty and staff with VPN privileges to ensure that unauthorized users are not allowed access to AUS internal networks.
- VPN use is to be controlled using a public/private key system with a strong passphrase.
- When actively connected to the corporate network, VPNs will force all traffic to and from the PC over the VPN tunnel: all other traffic will be dropped.
- Dual (split) tunneling is NOT permitted; only one network connection is allowed.
- VPN gateways will be set up and managed by the AUS IT Department.
- All computers connected to AUS internal networks via VPN or any other technology must use the most up-to-date anti-virus software that is the University standard; this includes personal computers.
- VPN users will be automatically disconnected from AUS's network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. Pings or other artificial network processes are not to be used to keep the connection open.
- Users of computers that are not AUS-owned equipment must configure the equipment to comply with AUS's VPN and Network policies.
- Only IT Department provided VPN clients may be used.
- By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of AUS's network, and as such are subject to the same rules and regulations that apply to AUS-owned equipment, i.e., their machines must be configured to comply with IT Department's Security Policies.
4.0 Enforcement
Any faculty and staff found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
5.0 Definitions
Term Definition
IPSec Concentrator A device in which VPN connections are terminated.
6.0 Revision History
|