HomeMy WebLinkAboutF11.0 Remote Access �'l3llRl�ll `Y 111CJ-
1' E A S
CITY OF GRAPEVINE ADMINISTRATIVE POLICY
SUBJECT- REMOTE ACCESS SECTION. F NUMBER: 11.0
PREPARED BY- Information Technology REVISED DATE: 02/01/2014
PAGE: 1 of 2
PURPOSE
11.1 The purpose of the Remote Access policy is to provide guidelines for IPSec or SSL
Virtual Private Network (VPN) remote access connections to the City of Grapevine
City network.
POLICY
11.2 This policy applies to all City of Grapevine employees, contractors, temporaries, and
other workers, including all personnel affiliated with third parties using VPNs to
access the City of Grapevine network. The Remote Access policy applies to
implementations of VPN directed through an IPSec or SSL Concentrator.
11.3 Approved City of Grapevine employees and authorized third party vendors,
contractors, etc; may use the benefits of VPNs, which are a "user managed" service.
The individual using the service is responsible for selecting an Internet Service
Provider (ISP), coordinating installation, installing any required software, and paying
associated fees.
11.4 Any City employee needing VPN access needs an EMPLOYEE REMOTE ACCESS
AGREEMENT signed and submitted by their director to IT (see AttachmentA number
11 .0). All third parties needing VPN access must go through an engagement process
and sign a THIRD PARTY CONNECTION AGREEMENT (see Attachment C number
11 .0).
11.5 The Police Department manages their own VPN accounts, therefore, the Police
Technical services division handles all Police and Fire employee VPN accounts. The
requesting employee needs signed permission from the Police Technical services
division using the EMPLOYEE REMOTE ACCESS AGREEMENT(see Attachment A
number 11 .0).
11.6 When using remote access services the following rules apply:
11.6.1 It is the responsibility of employees with VPN privileges to ensure that
unauthorized users are not allowed access to City of Grapevine internal
networks.
11.6.2 VPN use is to be controlled with an assigned password. All City
�'l3llRl�ll `Y 111CJ-
1' E A S
CITY OF GRAPEVINE ADMINISTRATIVE POLICY
SUBJECT- REMOTE ACCESS SECTION. F NUMBER: 11.0
PREPARED BY- Information Technology REVISED DATE: 02/01/2014
PAGE: 2 of 2
password policies about not sharing passwords apply to the VPN
password.
11.6.3 When actively connected to the corporate network, VPNs will force all
traffic to and from the PC over the VPN tunnel. All other traffic will be
dropped.
11.6.4 Dual (split) tunneling is NOT permitted; only one network connection is
allowed.
11.6.5 VPN gateways will be set-up and managed by City of Grapevine IT or
Police Technical Services.
11.6.6 All computers connected to City of Grapevine internal networks via VPN
or any other technology must use the most up-to-date anti-virus software
that is the corporate standard. This includes personal computers.
11.6.7 By using VPN technology with personal equipment, users understand
that their machines are a de facto extension of City of Grapevine's
network and, as such all rules for computer usage; that apply at City
facilities also apply when connected remotely.