| G.5 Remote Internet Access (VPN) Policy |
| @Information Services |
General
The purpose of the Remote Internet Access Policy is to
provide guidelines for IPSec or L2TP Virtual Private Network (VPN) connections
to the West Chester University network. This policy applies to all employees,
contractors, consultants, temporaries, and other workers including all personnel
affiliated with third parties utilizing VPNs to access the WCU network. This
policy applies to implementations of VPN that are directed through an IPSec
Concentrator.
Policy
Approved West Chester University employees and authorized
third parties (customers, vendors, etc. ) may utilize the benefits of VPNs,
which are a "user managed" service. This means that the user is responsible for
selecting an Internet Service Provider (ISP), coordinating installation,
installing any required software, and paying associated fees.
Additionally, it is the responsibility of employees with
VPN privileges to ensure that unauthorized users are not allowed access to WCU
internal networks.
- VPN use is to be controlled using either a one-time
password authentication such as a token device or a public/private key system
with a strong pass phrase.
- When actively connected to the university network, VPNs
will force all traffic to and from the PC over the VPN tunnel: all other
traffic will be dropped.
- Dual (split) tunneling is NOT permitted; only one
network connection is allowed. VPN gateways will be set up and managed by WCU
Network Operations Center (NOC).
- All computers connected to WCU internal networks via VPN
or any other technology must use the most up-to-date anti-virus software that
is the university standard; this includes personal computers. Users should
contact the HelpDesk for further information about anti-virus software.
- VPN users will be automatically disconnected from WCU's
network after thirty minutes of inactivity. The user must then logon again to
reconnect to the network. Pings or other artificial network processes are not
to be used to keep the connection open.
- The VPN concentrator is limited to an absolute
connection time of 24 hours.
- Only VPN clients approved by the Office of Information
Security may be used.
By using VPN technology with personal equipment, users must
understand that their machines are a de facto extension of WCU’s network, and as
such are subject to the same rules and regulations that apply to WCU-owned
equipment, i.e., their machines must be configured to comply with the
Information Services’ Security Policies.