navigation bar it admin ed tech library it services
information technology
information technology services home policies
information technology services
   
 
Common Links
Request Assistance
Online
   
GroupWise Web Access
   
Moving Equipment
Checklist
   
Latest Tech Tip
   



Remote Access Policy

1.0 Purpose

The purpose of this policy is to define standards for connecting to University of Kansas, School of Medicine - Wichita's network from any host. These standards are designed to minimize the potential exposure to the University from damages which may result from unauthorized use of university resources. Damages include the loss of sensitive or company confidential data, intellectual property, damage to public image, damage to critical internal systems, etc.

2.0 Scope

This policy applies to all University of Kansas, School of Medicine - Wichita employees, contractors, vendors and agents with a university owned or personally-owned computer or workstation used to connect to the University of Kansas, School of Medicine - Wichita network. This policy applies to remote access connections used to do work on behalf of University of Kansas, School of Medicine - Wichita, including reading or sending email and viewing intranet web resources.

Remote access implementations that are covered by this policy include, but are not limited to, dial-in modems, frame relay, ISDN, DSL, VPN, SSH, and cable modems, etc.

3.0 Policy

3.1 General

  1. It is the responsibility of University of Kansas, School of Medicine - Wichita employees, contractors, vendors and agents with remote access privileges to University of Kansas, School of Medicine - Wichita's university network to ensure that their remote access connection is given the same consideration as the user's on-site connection.
  2. Please review the following policies for details of protecting information when accessing the university network via remote access methods, and acceptable use of University of Kansas, School of Medicine - Wichita's network:
    1. Password Policy
    2. Virtual Private Network (VPN) Policy
    3. Acceptable Use Policy
    These policies can be read in their entirety on our website at http://wichita.kumc.edu/nts/policies.
  3. For additional information regarding University of Kansas, School of Medicine - Wichita's remote access connection options, including how to order or disconnect service, cost comparisons, troubleshooting, etc., go to the IT Services website http://wichita.kumc.edu/nts/policies.

3.2 Requirements

  1. Secure remote access must be strictly controlled. Control will be enforced via one-time password authentication or public/private keys with strong pass-phrases. For information on creating a strong pass-phrase see the Password Policy.
  2. At no time should any University of Kansas, School of Medicine - Wichita employee provide their login or email password to anyone, not even family members.
  3. University of Kansas, School of Medicine - Wichita employees and contractors with remote access privileges must ensure that their University owned or personal computer or workstation, which is remotely connected to the university network, is not connected to any other network at the same time.
  4. Routers for dedicated ISDN lines configured for access to the University of Kansas, School of Medicine - Wichita network must meet minimum authentication requirements of CHAP.
  5. Reconfiguration of a home user's equipment for the purpose of split-tunneling or dual homing is not permitted at any time.
  6. Frame Relay must meet minimum authentication requirements of DLCI standards.
  7. Non-standard hardware configurations must be approved by IT Services, and IT Services must approve security configurations for access to hardware.
  8. All hosts that are connected to University of Kansas, School of Medicine - Wichita internal networks via remote access technologies must use the most up-to-date anti-virus software, this includes personal computers.
  9. Personal equipment that is used to connect to University of Kansas, School of Medicine - Wichita's networks must meet the requirements of University of Kansas, School of Medicine - Wichita-owned equipment for remote access.

4.0 Enforcement

Any employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.

5.0 Definitions

Term Definition

Cable Modem Cable companies such as AT&T Broadband provide Internet access over Cable TV coaxial cable. A cable modem accepts this coaxial cable and can receive data from the Internet at over 1.5 Mbps. Cable is currently available only in certain communities.

CHAP Challenge Handshake Authentication Protocol is an authentication method that uses a one-way hashing function. DLCI Data Link Connection Identifier (DLCI) is a unique number assigned to a Permanent Virtual Circuit (PVC) end point in a frame relay network. DLCI identifies a particular PVC endpoint within a user's access channel in a frame relay network, and has local significance only to that channel.

Dial-in Modem A peripheral device that connects computers to each other for sending communications via the telephone lines. The modem modulates the digital data of computers into analog signals to send over the telephone lines, then demodulates back into digital signals to be read by the computer on the other end; thus the name "modem" for modulator/demodulator.

Dual Homing Having concurrent connectivity to more than one network from a computer or network device. Examples include: Being logged into the University network via a local Ethernet connection, and dialing into AOL or other Internet service provider (ISP). Being on a University of Kansas, School of Medicine - Wichita-provided Remote Access home network, and connecting to another network, such as a spouse's remote access. Configuring an ISDN router to dial into University of Kansas, School of Medicine - Wichita and an ISP, depending on packet destination.

DSL Digital Subscriber Line (DSL) is a form of high-speed Internet access competing with cable modems. DSL works over standard phone lines and supports data speeds of over 2 Mbps downstream (to the user) and slower speeds upstream (to the Internet).

Frame Relay A method of communication that incrementally can go from the speed of an ISDN to the speed of a T1 line. Frame Relay has a flat-rate billing charge instead of a per time usage. Frame Relay connects via the telephone company's network.

ISDN There are two flavors of Integrated Services Digital Network or ISDN: BRI and

BRI BRI is used for home office/remote access. BRI has two "Bearer" channels at 64kbit (aggregate 128kb) and 1 D channel for signaling info.

Remote Access Any access to University of Kansas, School of Medicine - Wichita's university network through a non-university controlled network, device, or medium.

Split-tunneling Simultaneous direct access to a non-University of Kansas, School of Medicine - Wichita network (such as the Internet, or a home network) from a remote device (PC, PDA, WAP phone, etc.) while connected into University of Kansas, School of Medicine - Wichita's university network via a VPN tunnel. VPN Virtual Private Network (VPN) is a method for accessing a remote network via "tunneling" through the Internet.

Top


ku school of medicine-wichita home

Page last updated: October 7, 2004
For more information contact: Information Technology Services
For site development questions and comments, contact: The Web Development Unit

Copyright © 2001-2006, The University of Kansas School of Medicine - Wichita