Quantcast
0
0

Guide to SSL VPN

NetworkWorld

Wednesday, May 14, 2008 12:00 PM PDT

Best Practices for deploying SSL VPNs

Wide client support, authentication support are crucial

By Tim Green

? Part of the reason for using SSL VPNs is to allow users to connect using something other than a company-issued machine. If that is an important goal, check whether the product under consideration supports Windows, Linux, Mac and even the operating systems for handhelds and smart phones equipped with browsers.

? Check out the management platform and its ability to support multiple policies per user and user group. Because the technology can support such granular access, it may become desirable to issue more than one policy per person or group. For instance, a single user may require access rights that differ depending on what machine and what access method are used and what the security posture of the devices is.

? To tighten up security, use two-factor authentication to log into the VPN.

? Use options that delete from the remote machine any traces of transactions performed during the SSL VPN session. This is especially important if the corporation does not own the remote device and is readily accessible to others, such as a computer at an Internet kiosk.

? Use options that force sessions to time-out and demand reauthentication to prevent unauthorized access should the remote user walk away from the machine, leaving it vulnerable to someone else using it while it is logged into the VPN.

? Weigh how important SSL VPN access is to doing business. If it's essential, install gateways in high-availability mode, so if one gateway fails, the other can kick in.

? If SSL VPNs are to be used for network access in case of a disaster, build in capacity to handle the extra load. If the gateway is not sized to support all the additional users, it will become yet another problem after disaster strikes.

? Run penetration testing against the VPN. It allows access to corporate resources and is supposed to be secure, but it pays to check.

Community Comments

PC World's Marketplace

PC World's Free Whitepapers

Utilities News
More

Latest Expert Blogs

All Blogs
Featured Resources

Premier Content From Our Sponsors

  • HP Ink Center
    HP Ink Center You don't need a big budget to produce high quality marketing materials. Click here for more info...
  • CDW Virtualization Center
    CDW Virtualization Center What is Virtualization and how can it help you save money? Click here for more info...
Featured Whitepapers

White papers, case studies and product info from top brands

  • Small Business Webcast: Are You Ready for CRM? Seven Ways to Know Knowing your customers and their needs as thoroughly as possible is central to any business. And that's the very point of customer-relationship management software, which is sophisticated business software commonly known as CRM. For those unfamiliar...
  • The Future Sales Force - A Consultative Approach In recent years many organizations have found their sales processes have become more challenging while the performance of their former star sales professionals has deteriorated. This white paper discusses the challenges of selling complex products a...
Featured Webcasts

Watch webcast presentations and videos from industry thought leaders on today's most important business and technology topics. For free.