Virtual Private Network (VPN) Policy


Policy No.:ETP-01-3                                                                                                                                                                                                       Effective:04/11/13


KSAU-HS            King Saud bin Abdulaziz University for Health Sciences

UNIVERSITY       King Saud bin Abdulaziz University for Health Sciences

EDUTECH            CorporateOffice of Educational Technology Services

DIRECTOR          Director of the Corporate Office of Educational Technology Services

IT                       Information Technology


The purpose of this policy is to provide guidelines for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the KSAU-HS corporate network.


This policy applies to all University staff, contractors, consultants, vendors, and third party support technicians who use VPNs to access the KSAU-HS network. This policy applies to implementations of VPN that are directed through an IPSec Concentrator.


  • POLICY ETP-12-1 Remote Access Policy
  • POLICY ETP-18-3 Firewall Usage Policy 


  • Approved University employees and authorized third parties (contractors, consultants, vendors, etc.) may utilize the benefits of VPNs, which are a "user managed" service.  This means that the user is responsible for selecting an Internet Service Provider (ISP), coordinating installation, installing any required software, and paying associated fees. Further details may be found in the Remote Access Policy.
  • VPN use is to be controlled using either a one-time password authentication such as a token device or a public/private key system with a strong passphrase.
  • When actively connected to the corporate network, VPNs will force all traffic to and from the PC over the VPN tunnel: all other traffic will be dropped.
  • Dual (split) tunneling is NOT permitted; only one network connection is allowed.
  • VPN gateways will be set up and managed by Edutech network operations.
  • All computers connected to the University’s internal networks via VPN or any other technology must use the most up-to-date anti-virus software.
  • VPN users will be automatically disconnected from University's network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. Pings or other artificial network processes are not to be used to keep the connection open.
  • The VPN concentrator is limited to an absolute connection time of 8 hours.
  • Users of computers that are not University owned equipment must configure the equipment to comply with University's VPN and Network policies.
  • Only Edutech approved VPN clients may be used.
  • By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of the University's network and as such are subject to the same rules and regulations that apply to University owned equipment, i.e., their machines must be configured to comply with Edutech Security Policies.

Approved By:

Director Corporate, Educational Technology Service
King Saud bin Abdulaziz University for Health Sciences


Related Links