5.2 Virtual Private Network (VPN) Standard
5.2.1. Overview
See Purpose.
5.2.2. Purpose
The purpose of this standard is to provide guidelines for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the Highline College corporate network.
5.2.3. Scope
This standard applies to all Highline College employees, contractors, consultants, temporaries, and other workers including all personnel affiliated with third parties utilizing VPNs to access the Highline College network. This standard applies to implementations of VPN that are directed through an IPSec Concentrator.
5.2.4. Standard
Approved Highline College employees and authorized third parties (customers, vendors, etc.) may utilize the benefits of VPNs, which are a “user managed” service. This means that the user is responsible for selecting an Internet Service Provider (ISP), coordinating installation, installing any required software, and paying associated fees. Further details may be found in the Remote Access Standard.
Additionally,
- It is the responsibility of employees with VPN privileges to ensure that unauthorized users are not allowed access to Highline College internal networks.
- VPN use is to be controlled using either a one-time password authentication such as a token device or a public/private key system with a strong passphrase.
- When actively connected to the corporate network, VPNs will force all traffic to and from the PC over the VPN tunnel: all other traffic will be dropped.
- Dual (split) tunneling is NOT permitted; only one network connection is allowed.
- VPN gateways will be set up and managed by Highline College network operational groups.
- All computers connected to Highline College internal networks via VPN or any other technology must use the most up-to-date anti-virus software that meet the Highline College Antivirus Software Guideline; this includes personal computers.
- VPN users will be automatically disconnected from Highline College’s network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. Pings or other artificial network processes are not to be used to keep the connection open.
- The VPN concentrator is limited to an absolute connection time of 24 hours.
- Users of computers that are not Highline College-owned equipment must configure the equipment to comply with Highline College’s VPN and Network policies.
- Only ITS-approved VPN clients may be used.
- By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of Highline College’s network, and as such are subject to the same rules and regulations that apply to Highline College-owned equipment.
5.2.5. Compliance
5.2.5.1 Compliance Measurement
ITS will verify compliance to this standard through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and feedback to the standard owner.
5.2.5.2 Exceptions
Any exception to the standard must be approved by ITS in advance.
5.2.5.3 Non-Compliance
An employee found to have violated this standard may be subject to disciplinary action, up to and including termination of employment.
5.2.6. Related Standards, Policies, and Processes
2.6 Antivirus Software Guideline
5.2.7. Revision History
Date | By | Summary |