Skip to main content
Guidance

Device security guidance

Guidance for organisations on how to choose, configure and use devices securely.

Page 31 of 37

Virtual Private Networks (VPNs)

Choosing, deploying and configuring VPN technologies for use by an organisation

Virtual Private Networks (VPNs) allow organisations to provide secure connectivity between devices in physically separate locations. This guidance helps administrators within choose, deploy and configure VPNs for their organisation. Individuals typically use VPNs for different reasons, and so are not covered in this guidance.


Protecting data in transit is one of the most important security aspects to consider when using mobile devices. Attackers with access to unprotected data (or inadequately-protected data) may be able to intercept and modify data, potentially causing harm. It is therefore important to decide which of the above benefits are relevant to your organisation before deciding which VPN technology to use, and how to use it.



Integrated vs third-party VPN clients

Most operating systems have a built-in VPN client available which can either be configured on the device or managed remotely. Integrated clients are normally free to use, work reliably, and are updated automatically, but can also be relatively limited in functionality. For example, there’s often no ability to configure routing rules, exceptions, or split tunnelling.

We recommend using the native client where possible, and our platform specific guidance provides configuration details. However, a range of commercially available third-party VPN clients exists.

Using a third-party VPN client increases the risk that operating system integration will be poor, and that consequently, some data may be sent outside the VPN. It also increases the number of software packages that need to be kept up to date, adding to the likelihood that some out-of-date software will be in use.

Forced vs optional

Only traffic which is routed over the VPN will be protected by it, so you might want to force all traffic to be routed via the VPN, and for no user traffic to transit outside that connection. This will require either the VPN client itself to enforce this, or a client firewall configured to prevent connections being established outside of the VPN. If a forced VPN is unable to connect, then no network traffic from the device will be possible, unless the VPN is disabled.

Our guidance generally recommends forcing traffic down the VPN, and where possible, the per-platform guidance provides ways of achieving this. Where it's not possible to force traffic, this represents a risk to your data. However, forced connections can sometimes cause incompatibilities with captive portals on public Wi-Fi networks, unless the platform offers a solution for authenticating to them.

Using an optional VPN allows users to disable the VPN and evade protective monitoring and auditing services. This increases the risk of mobile devices being attacked over the network, and of users circumventing corporate policy restrictions.



The use of a captive portal assistant application is less risky and should be preferred if captive Wi-Fi networks are to be used. The risks of disabling forced VPNs are described earlier in this guidance.




Published

Reviewed

Version

2.1