

Users accessing the View Connection Servers from the LAN must be granted access using just their Active Directory credentials: Getting started However only remote users must be forced to authenticate using RSA SecurID.

To enhance security, the following design decision has also been made: The Access Point will connect to the view3 connection server: The design assumes this is in place and has been secured accordingly ( part 1, Assumptions, A5). The Access Point will be placed in the DMZ network. Therefore this single point of failure must be flagged as a risk and recorded. Unfortunately, the design is constrained by budget ( part 1, Constraints, C4), so whilst deploying multiple Access Points would not increase costs, to make use of them would require an additional load-balancer.
