G.5 Remote Internet Access (VPN) Policy
@Information Services

General

The purpose of the Remote Internet Access Policy is to provide guidelines for IPSec or L2TP Virtual Private Network (VPN) connections to the West Chester University network. This policy applies to all employees, contractors, consultants, temporaries, and other workers including all personnel affiliated with third parties utilizing VPNs to access the WCU network. This policy applies to implementations of VPN that are directed through an IPSec Concentrator.

Policy

Approved West Chester University employees and authorized third parties (customers, vendors, etc. ) may utilize the benefits of VPNs, which are a "user managed" service. This means that the user is responsible for selecting an Internet Service Provider (ISP), coordinating installation, installing any required software, and paying associated fees.

Additionally, it is the responsibility of employees with VPN privileges to ensure that unauthorized users are not allowed access to WCU internal networks.

  • VPN use is to be controlled using either a one-time password authentication such as a token device or a public/private key system with a strong pass phrase.
  • When actively connected to the university network, VPNs will force all traffic to and from the PC over the VPN tunnel: all other traffic will be dropped.
  • Dual (split) tunneling is NOT permitted; only one network connection is allowed. VPN gateways will be set up and managed by WCU Network Operations Center (NOC).
  • All computers connected to WCU internal networks via VPN or any other technology must use the most up-to-date anti-virus software that is the university standard; this includes personal computers. Users should contact the HelpDesk for further information about anti-virus software.
  • VPN users will be automatically disconnected from WCU's network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. Pings or other artificial network processes are not to be used to keep the connection open.
  • The VPN concentrator is limited to an absolute connection time of 24 hours.
  • Only VPN clients approved by the Office of Information Security may be used.

By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of WCU’s network, and as such are subject to the same rules and regulations that apply to WCU-owned equipment, i.e., their machines must be configured to comply with the Information Services’ Security Policies.