Can I force wireless to only function via VPN?
January 14, 2008 10:24 AM
Subscribe
How do I force WiFi to only work through VPN on company laptops?
I'm behind on my wireless connectivity hacks. I work in an environment which needs tight information security, so all our connections have been wired-only until now.
But we have new needs to send laptops out to the field, work from home, etc. So I need a way to protect these machines once the've left the nest. Intrusion security would be handled by endpoint security software (anti virus/spyware/firewall), so I'm not worried about that so much. But folks will be connecting to the internet via home networks with WEP or less, hotspots, etc. And they're on their own there. I don't want their keys cracked or their packets intercepted, as much as is possible.
I know that a connection can be set up which uses VPN; but from what I can tell, it's voluntary - you can choose to use it or not. I know from past experience that if the secure method is optional and/or takes a few more steps, users will go with the non-secure method more often than not. I'd like this to be automatic, so that it's both invisible or transparent to an end user, and not something they can turn off or choose not to use.
What I'd like to do is configure these machines (all various flavors of ThinkPads, BTW) so that once Wi-Fi is established, a VPN connection would be non-optional. I'd like to set up a web proxy here at HQ as the other end of that VPN, and have all those company laptop connections go through it for internet access, for security and activity monitoring. So you fire up wireless, connect to some available network, then *some magic happens* and if you want internet, it has to go through the VPN/proxy at HQ. That would secure all wireless access, right? Much of their access would be back to company data & email anyway, and awareness that the internet connection is passing through filtering/monitoring at HQ should keep people from torrenting porn on the company laptop while they're on the road.
Laptop -> potentially unsafe Wifi AP -> no internet in or out on laptop except via VPN -> monitoring/safeguarding proxy back at HQ -> The Internets
This is possible, or even commonly done, right?
Like I said, it's new to me and I may not be thinking about this the right way. Please correct me if my assumptions are wrong. If this can be done via some software that runs automatically, I'd like to hear about it. (These are all Thinkpads - can this be done via the Access Connections software we've never used?). If it's a configuration to set up on these machines and something back at HQ, please point me at some resources where I can learn to set up & manage this.
Advise me, O Wise Hive Mind! How do I force VPN-only?
posted by bartleby to computers & internet (4 comments total)
3 users marked this as a favorite
posted by kindall at 10:41 AM on January 14, 2008