Virtual Private Network (VPN)

Slides:



Advertisements
Similar presentations
The future of Desktops Transform Your Desktop with Virtualization.
Advertisements

© Copyright RES Software. v2012-Mar30. RES HyperDrive Patrik Zander, Product Manager 1.
OAAIS Enterprise Information Security Security Awareness, Training & Education (SATE) Program or UCSF Campus VPN.
0-1 Team # Status Report (1 of 4) Client Contact –Point 1 –Point 2 Team Meetings –Point 1 –Point 2 Team Organization –Point 1 –Point 2 Team #: Team Name.
0-1 Team # Status Report (1 of 4) Client Contact –Status Point 1 –Status Point 2 Team Meetings –Status Point 1 –Status Point 2 Team Organization –Description.
SESSION 9 THE INTERNET AND THE NEW INFORMATION NEW INFORMATIONTECHNOLOGYINFRASTRUCTURE.
CMS Fall Forum Fall 2003 November 18, 2003 Lorraine Frost.
Fermilab VPN Service What is a VPN ?.
Managing BYOD Legal IT’s Next Great Challenge. Agenda  The BYOD Trend – benefits and risks  Best practices for managing mobile device usage  Overview.
Website Hardening HUIT IT Security | Sep
Eric Holtel.  Introduction  Project Description  Demonstration  Deliverables  Conclusion.
CUONG NGUYEN PRIYA PAKHANAVAR RUSSELL ROBINSON RPC Hotels.
Ali Pabrai, CISSP, CSCS ecfirst, chairman & ceo Preparing for a HIPAA Security Audit.
2  Supervisor : MENG Sreymom  SNA 2012_Group4  Group Member  CHAN SaratYUN Sinot  PRING SithaPOV Sopheap  CHUT MattaTHAN Vibol  LON SichoeumBEN.
Lieberman Software Random Password Manager & Two-Factor Authentication.
©2015 BOMGAR CORPORATION ALL RIGHTS RESERVED WORLDWIDE. 1 Bomgar Remote Support.
Computer Security Risks for Control Systems at CERN Denise Heagerty, CERN Computer Security Officer, 12 Feb 2003.
CAIU Technology Essentials All Staff Day, 2016 Instructor: Stefan Moyer.
Introduction to ITIL and ITIS. CONFIDENTIAL Agenda ITIL Introduction  What is ITIL?  ITIL History  ITIL Phases  ITIL Certification Introduction to.
Managed IT Services JND Consulting Group LLC
The BEST Citrix/Microsoft RDS alternative
Short Customer Presentation September The Company  Storgrid delivers a secure software platform for creating secure file sync and sharing solutions.
Avtec Inc Virtualization - Securely Moving to the Cloud.
Managed Desktop Andrea Beesing April 5, 2016.
The BEST Citrix/Microsoft RDS alternative
Printing (Net-Print) Joanne Button August 23rd 2016.
Getting Connected to NGS while on the Road…
IT Service Management Suite
Cloud Faxing for Law Firms
Network Service Laurie Collinsworth 10/18/2016.
SharePoint Online (Office 365)
Telephone Service Andrea Beesing November 15, 2016.
PCI Compliance Service
Web and Video Conferencing
Andrea Beesing September 6, 2016
Enterprise Content Management
Video Streaming and Hosting
IT Service Desk Service
Digital Signage M Scott Walters 4 Oct 2016.
Domain Name Service (DNS) Network Registry
Course Management System (Blackboard)
Scanning and Digitizing
Wi-Fi Network Service Laurie Collinsworth 10/18/2016.
Backup, Archive & Recovery
Electronic Lab Notebook (LabArchives)
Managed Server Service
Best Practices in IT / Facilities Management 5/30/2013 Ballroom E
Antivirus Service Rob Bandler May 17, 2016.
Plagiarism Detection (Turnitin)
Classroom Polling Service (i>clicker)
Confluence Wiki Vicky Mikula July 26th 2016.
(Presented by Eric Nobel)
Event Technical Support
Online Training (Lynda.com)
Lecture Capture Service (Panopto)
Managed IT Systems, Manager
Password Escrow Service
Data Center Service Brian Messenger 11/15/2016.
Service Owner: Andrea Beesing 9 February 2016
End User Computing UNM Tech Days 2017 June 9, 2017 Luke Abeling
Antiphishing & Verified Communications
Cloudification Sarah Christen 1/26/2016.
Document Storage and Collaboration
Welcome To : Group 1 VC Presentation
SharePoint On Premises
Zero Clients and Virtual Desktops in Academic Environments
Getting Connected to NGS while on the Road…
Connecting Remotely Winter 2014.
Designing IIS Security (IIS – Internet Information Service)
Presentation transcript:

Virtual Private Network (VPN) Laurie Collinsworth 4/5/2016

Agenda Introductions Service Description Value Proposition Metrics Cost Security More information Q&A

Introductions Service owner: Laurie Collinsworth Service manager: Eric Cronise Other service delivery team members: Eng: Kevin Feeney / Dan Eckstrom Ops: Jenny Signor / Leisha Redfield IT Communications, Knowledge Mgmt & Training IT Support Desk

Service Description Service name: Virtual Private Network (VPN) Product(s): CISCO AnyConnect Brief text description: The VPN service provides the Cornell community with secure, authenticated remote access to the campus data network. Departments can request a locally-administered pool. Departmental pools can be protected by Two Step Duo login. Available to: Faculty, Staff & Students departmental pools are requested and managed by Technical Support Providers (TSP). Fee? No Service tier: Zero

AnyConnect clients Clients available on 4/4//2016 Source OS Versions MacOS CUVPN headend 10.8, 10.9, 10.10, 10.11 Windows Windows7, 8, 8.1, 10 (x86(32-bit) & x64(64-bit)) Linux 64-bit Linux only iOS (iPhone, iPad) AppStore - Android GooglePlay ChromeOS Chrome Web Store For TSP: http://www.it.cornell.edu/services/vpn/howto/tsp/installers.cfm

Value Proposition Value proposition Customer impact Key benefits Reduces risk of data compromise during network transmission Reduces risk of server compromise (if locked to campus, departmental pool, or Two Step Duo Login) http://www.it.cornell.edu/services/vpn/howto/tsp/vpn_twostep.cfm Customer impact Ubiquitous access with no fee encourages use Key benefits Cost savings by leveraging central staff & support Monitored, securely patched, redundant Integration into core of campus network

Metrics FY16 Q2 FY 16 Q2 Metrics Number of Connections 111,343 Number of department pools 144 Maximum concurrent sessions 496 Number of unique users 6577 FY 16 Unit cost/year Per user $2.52 Per connection $0.15

Cost to deliver the service: *5yr Hardware cost: $21,055 Fee for service: None FY 16 Total Cost $16,535 Hardware* & Software $5,294 Labor $9,737 Staff Support $752 Administrative Overhead

Security What risks does use of the service mitigate? Credential loss due to network sniffing Sensitive data loss during network transmission Server compromise due to unprotected administrative access How does the service mitigate risks? Encryption of data transmission over the network User login tracking to VPN IP address Lock administrative access to servers to campus or department pool, not the world. Multi-factor authentication available Service is protected, actively patched, monitored 7/24/365

More information Service web page: http://www.it.cornell.edu/services/vpn/ Service level expectations: https://www.it.cornell.edu/services/sle.cfm?doc=55 Service catalog entry: https://catalog.it.cornell.edu/admin/60 Service quarterly report: http://cio.cornell.edu/resources/it-reports-documents-and-presentations/itcornell-quarterly-metrics/virtual-private-network

Questions? Email questions to: Laurie Collinsworth ljc1@cornell.edu