Contact Us |
Info for students | Our Courses | About Us  
 

 

Virtual Private Network (VPN) Policy
 

 

1.0 PURPOSE

The purpose of this policy is to provide guidelines for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the ASCL corporate network.

2.0 SCOPE

This policy applies to all ASCL employees, contractors, consultants, temporaries, and other workers including all personnel affiliated with third parties utilizing VPNs to access the ASCL network. This policy applies to implementations of VPN that are directed through an IPSec Concentrator.

3.0 POLICY

Approved ASCL employees and authorized third parties (customers, vendors, etc.) may utilize the benefits of VPNs, which are a "user managed" service. This means that the user is responsible for selecting an Internet Service Provider (ISP), coordinating installation, installing any required software, and paying associated fees. Further details may be found in the Remote Access Policy.

Additionally,

  1. It is the responsibility of employees with VPN privileges to ensure that unauthorized users are not allowed access to ASCL internal networks.

  2. VPN use is to be controlled using either a one-time password authentication such as a token device or a public/private key system with a strong passphrase.

  3. When actively connected to the corporate network, VPNs will force all traffic to and from the PC over the VPN tunnel: all other traffic will be dropped.

  4. Dual (split) tunneling is NOT permitted; only one network connection is allowed.

  5. VPN gateways will be set up and managed by ASCL network operational groups.

  6. All computers connected to ASCL internal networks via VPN or any other technology must use the most up-to-date anti-virus software that is the corporate standard; this includes personal computers.

  7. VPN users will be automatically disconnected from ASCL's network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. Pings or other artificial network processes are not to be used to keep the connection open.

  8. The VPN concentrator is limited to an absolute connection time of 24 hours.

  9. Users of computers that are not ASCL-owned equipment must configure the equipment to comply with ASCL's VPN and Network policies.

  10. Only the ASCL Information Security Department-approved VPN clients may be used.

  11. By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of ASCL's network, and as such are subject to the same rules and regulations that apply to ASCL-owned equipment, i.e., their machines must be configured to comply with the ASCL Information Security Department's Security Policies.

4.0 ENFORCEMENT

Any person bound by this policy who intentionally and/or knowingly violates this policy shall be subject to action deemed fit by the Governing Board of the Asian School of Cyber Laws and shall also be liable to pay adequate and prompt compensation. Such action shall not preclude adequate civil and / or criminal remedy as per the applicable law.

5.0 DEFINITIONS

  1. IPSec Concentrator: A device in which VPN connections are terminated.

6.0 REVISION HISTORY

This document is created on 12-02-2002 and has been last updated on 22-02-2003. Please note that this document is updated on a regular basis and the latest version can be obtained from:

 

 


© 2007 Asian School of Cyber Laws. All rights reserved.
  Reprint Permission | Privacy Policy | Disclaimer