Virtual Private Network (VPN) Policy
- It is the responsibility of employees with VPN privileges to ensure that unauthorized users are not allowed access to <Company Name> internal networks.
- VPN use is to be controlled using either a one-time password authentication such as a token device or a public/private key system with a strong passphrase.
- When actively connected to the corporate network, VPNs will force all traffic to and from the PC over the VPN tunnel: all other traffic will be dropped.
- Dual (split) tunneling is NOT permitted; only one network connection is allowed.
- VPN gateways will be set up and managed by <Company Name> network operational groups.
- All computers connected to <Company Name> internal networks via VPN or any other technology must use the most up-to-date anti-virus software that is the corporate standard (provide URL to this software); this includes personal computers.
Related Virtual Private Network (VPN) Policy: vpn concentrator, virtual private network, split tunneling, operational groups, network processes, anti virus software, vpn users, network policies, owned equipment, time password, personal equipment, internal networks, connection time, passphrase, network vpn