VPN Security Dilemma
Posted: Wed Sep 19, 2007 9:11 am
Here's an interesting scenario that keeps cropping up:
You've got a corporate network behind a firewall, fairly standard setup. An external company has a system within your network on one of your servers, and they want VPN access in to the server to carry out support work.
You can't trust an external company with unrestricted access to your network.
But they legitimately need access to the server.
What would be your approach to solving this? The best solution I've come up with so far is an on-demand VPN where the dial-in right is disabled for the user and needs to be enabled each time by local IT staff.
Ideas?
You've got a corporate network behind a firewall, fairly standard setup. An external company has a system within your network on one of your servers, and they want VPN access in to the server to carry out support work.
You can't trust an external company with unrestricted access to your network.
But they legitimately need access to the server.
What would be your approach to solving this? The best solution I've come up with so far is an on-demand VPN where the dial-in right is disabled for the user and needs to be enabled each time by local IT staff.
Ideas?