What’s the Process for Granting VPN Access to Vendors?

0
5
Asked By CuriousCat88 On

Hey everyone! I'm curious about the typical process for granting VPN access to vendors. When you have a vendor needing access, what do you usually ask them to fill out on the VPN request form? For instance, do they just provide the system names and the access types like RDP, SSH, or Web? Are they also expected to give details like IP addresses and ports? Additionally, how do you typically manage this internally after receiving their requests? I'm looking to see how different organizations handle this in practice. Thanks!

3 Answers

Answered By SecureNetGuru On

For vendors needing VPN access, we ensure the access is restricted strictly to what they need. Their accounts are set to expire after 7 days unless they request an extension. All connections must go through the VPN; we don't expose RDP or SSH directly to the internet to ensure security.

Answered By TechWizard42 On

In our setup, we usually don't grant vendors VPN access for brief tasks. If they need access to a production environment, we typically set it up through a supervised session on Zoom with our admin overseeing the work. For longer-term needs, like development, we create a specific VPN profile on a unique IP range. Then, we update both our North/South firewalls and apply policies to limit access to just the systems they need, often on test or dev VLANs to prevent access to production from the VPN.

Answered By AdminAce7 On

We have a strict policy requiring justification for the scope of access, setting time limits, and enforcing least privilege access principles to keep everything secure.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.