![]() |
![]() |
||||
|
|
|
Usage of the NU SSL VPNAudience:
Purpose:It is Northwestern University’s intent to initially offer SSL VPN access for those departments/users that need specific access to services where a granular level of user access control and/or application control is necessary. In particular, the SSL in intended to provide authenticated/encrypted access to restricted resources such as the administration of departmental servers, administrative systems and applications, and/or systems that house sensitive information. The resources should not be available from the general Internet and need to be clearly identified. The SSL VPN offers remote access using a web browser over SSL (Secure Socket Layer) and does not require client side software (unless full traditional VPN-like access is required, in which case the Network Connect client is required). An additional benefit to the implementation of SSL VPNs is the ability to grant access to specific resources based on group membership as defined by the master University LDAP directory. Further benefits include split tunneling of traffic for more efficient use of bandwidth and allocation of specific client IP address pools for specific groups of users that can be combined with the use of firewall rules to provide very granular access controls. Policy Statement:The SSL VPN shall be used as the only alternate means of remote access (other than the approved traditional VPN) for specific departments/users that require granular user and/or application access controls that are controlled through LDAP directory group membership. The SSL VPN should be viewed as a separate, and at most complementary, service to the benefits provided by the web SSO (Single Sign-On) service. The SSL VPN is not a replacement for the SSO service. ScopeThe SSL VPN service is offered to those departments and users that require specific access controls or clientless access not offered by the traditional NU VPN service. Departments should consult with NUIT (at it-services@northwestern.edu ) to determine if the SSL VPN is appropriate for their application(s). Examples of where an SSL VPN would be preferred and/or required are as follows: Recommended uses for the SSL VPN over the traditional VPN
Inappropriate uses for the SSL VPN
NOTE: Required uses for the SSL VPN follow in Section 9, “Standards” Definitions
Standards
ProceduresIndividual business units are responsible for the development, documentation and implementation of applicable procedures to effectuate this policy. Procedures are subject to review by NUIT. GuidelinesNote that all network activity while connected to the traditional or SSL VPN is subject to the University’s normal acceptable use policies. ComplianceAll parties as delineated under Audience are required to comply with this policy. Individuals who discover or strongly suspect the violation of this policy must promptly notify their management and any of the following:
Non-compliance: Any violation of this policy may be cause for appropriate disciplinary action, including dismissal. Request ProcessAny request for SSL VPN access should be submitted to NUIT at it-services@northwestern.edu using the form described in SSL VPN Access Request - Appendix A. NUIT will coordinate requests for access and contact the requestor, data steward and other authorities as deemed appropriate for consideration and discussion of the access request. Request forms must be completed fully; incomplete forms will be returned without processing. Requestors will be provided with a decision within ten (10) working days from receipt of the completed request. Original Issue Date: June 2007
Revision Dates: June 2007
Related Policies:
|
||||||
Last Updated: 18 June 2007 |
![]() |
Services |
Get Connected |
Support |
Academic Resources |
About NUIT
|
|