AC.L2-3.1.14Remote Access Routing
Route remote access via managed access control points.
[a]
managed access control points are identified and implemented; and[b]
remote access is routed through managed network access control points.
All remote paths land on managed VPN or IdP — no direct RDP to enclave
Implementation
AO coverage. Addresses both Remote Access Routing objectives.
Control points. Internet users reach CUI only via (1) IdP SSO to SaaS or (2) full-tunnel VPN into the lab VRF. Edge firewall denies inbound RDP/SMB from the Internet to enclave subnets.
Routing. VPN terminates on managed concentrators; split tunnel disabled for CUI routes. Admin remote work uses the same VPN then a jump host — not a public jump IP.
Maintenance. Quarterly firewall rule review for accidental publish. Continuous monitoring for new listeners on enclave VLANs.
Accepted gap. A facilities vendor needs a temporary camera VPN. It uses a separate non-CUI VRF with no route to the enclave.
What the evidence looks like
- Firewall rules denying inbound RDP/SMB to enclave
- VPN topology showing managed termination points
- Route table / VRF diagram for CUI vs facilities
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.