The IESO currently utilizes an on-premises Secure Sockets Layer Virtual Private Network (SSL VPN) solution (“VPN Solution”) to enable secure remote access for users. Remote users authenticate using Multi-Factor Authentication (MFA) to establish a secure SSL tunnel between their endpoint device and the corporate network.
To optimize bandwidth and enhance performance of cloud-based collaboration tools, split tunneling is employed, allowing traffic destined for collaboration platforms to route directly to the Internet while other traffic is directed to the internal network.
The VPN Solution also supports contractor access via a web-based interface, enabling users with non-IESO-managed assets to securely connect to internal resources through a terminal server. All authentication logs, both successful and unsuccessful, are forwarded to IESO’s on-premises Security Information and Event Management (SIEM) system for monitoring and analysis.
The VPN replacement project will replace the existing SSL VPN solution, including hardware, with a Internet Protocol Security (IPSec) VPN solution that will enforce MFA for all users, provide an option for “always-on” VPN connectivity, support contractor access via a secure web interface for non-IESO-managed devices and forward all authentication logs (successful and unsuccessful) to the existing on-premises SIEM for centralized logging and monitoring.