A Security policy for VPNs should be integrated into the information technology policies. The policy should define who uses the VPN and how the VPN is used. This documentation insures that the end user uses the VPN and that the VPN is used properly. The policy should contain what protocols, ports, firewall rules and devices are used for the VPN. End users connecting to a remote server should only be allowed a connection through a VPN.
The policy should go on to define what security requirements should be met prior to connection. Elements such as Windows Updates, Anti-virus protection and other components must be up to date. This protection should be a part of the hosting server / computer and the remote users. For end users not meeting these requirements, they should be put on a quarantined network where their computer receives updates. Quarantining computers is a process that ensures security measures are met.
Further authentication and security can take place if two-factor authentication is used or if third party VPN software is used.
In the next part of this series, we will look at implementing a virtual private network in Windows Vista.