Why Ad-Hoc Remote Desktop Tools Are Not a Security Policy
Many Dubai SMEs rely on tools like TeamViewer or AnyDesk for convenience. This creates unmonitored, unaudited access paths that bypass your firewall entirely. A proper VPN solution gives you control, logging, and policy enforcement.
Option 1: SSL VPN (Recommended for Most SMEs)
Users connect via browser or lightweight client to an SSL VPN portal. Traffic is encrypted via HTTPS.
Best for: 5 to 100 remote users who need access to internal resources.
Setup on FortiGate:
1. Create SSL VPN portal
2. Define IP pool for VPN clients
3. Create firewall policy: SSL VPN interface to LAN
4. Enable MFA (FortiToken or TOTP app)
5. Set split tunnel to allow only traffic to internal subnets
Option 2: IPsec Site-to-Site VPN
For connecting two offices together permanently.
Best for: Multi-site Dubai businesses, branch to HQ connectivity.
| Parameter | Recommended Setting |
|---|---|
| IKE version | IKEv2 |
| Encryption | AES-256 |
| Authentication | SHA-256 |
| DH Group | Group 14 or higher |
| Dead Peer Detection | Enable |
Option 3: Zero Trust Access (Advanced)
Instead of full network access, users only reach specific applications. Best for high-risk access scenarios.
Tools: Cloudflare Access, Zscaler Private Access, Fortinet ZTNA.
Non-Negotiable Security Controls
| Control | Why |
|---|---|
| MFA on all VPN accounts | Credentials alone are not enough |
| Split tunnelling enabled | Reduces bandwidth and attack surface |
| VPN access log review | Monthly minimum |
| Deactivate accounts on offboarding | Immediate on last day |
| Session timeout | Max 8-hour idle disconnect |
Common Mistakes
- Full-tunnel VPN routing all traffic including social media (kills performance)
- No MFA — one compromised password means full network access
- RDP exposed directly to internet instead of through VPN
- VPN account for ex-employee not disabled after departure
*Related: Networking and Security Dubai | Managed IT Services Dubai*
Tags
SAS IT Services — Dubai
Need expert IT support?
Our certified engineers cover all of Dubai & UAE with same-day response and 24/7 support contracts.
