General Information About MSU's Network Systems - Firewalls and Virtual Private Networks

Summary

MSU Information Technology protects data transferred over the MSU network by assessing, installing, and configuring security devices, such as firewalls and intrusion detection and prevention (IDP) systems, and investigating security incidents. Previously hosted at https://tech.msu.edu/network/network-systems/fi...

Body

Navigation

Select a link below to jump to that section:

Overview

MSU Information Technology protects data transferred over the MSU network by assessing, installing, and configuring security devices, such as firewalls and intrusion detection and prevention (IDP) systems, and investigating security incidents.

Back to Top

Firewall Design and Operation

MSU IT works with customers to design and implement network firewalls. This includes working with customers to determine their needs and design firewall zones to complement those needs.

Campus departments and units can utilize the expertise of MSU IT to minimize the time and cost of firewall implementation regardless of who implements the design.

MSU IT can also oversee the operation of network firewalls, including the configuration and troubleshooting.

The firewall operation service also provides changes to firewall rulesets, software/firewall upgrades, IPS signature upgrades, and device management. Troubleshooting includes a detailed analysis of traffic flows and packet captures to help determine necessary firewall ruleset updates.

A virtual private network is also an option when it comes to virtual networking.

Back to Top

Virtual Private Networks (VPN)

Also known as Campus VPN, MSU secure remote access, or F5 BIG-IP Edge, this service provides the MSU community to securely connect to the MSU campus network. This VPN connection works from any location, whether in East Lansing or anywhere around the world.

Faculty, staff, students, and other authorized users can access and download the new Campus VPN (F5 BIG-IP Edge Client) using their MSU NetID at vpn.msu.edu.

An MSU VPN override may be requested by a sponsoring faculty or staff member for VPN access for temporary/on-call employees, vendors, affiliates, retirees, and other NetIDs associated with university business.

Learn How to download F5 Campus VPN

When is it necessary to connect to Campus VPN?

Not everyone will need to connect to Campus VPN.

To determine if you need to connect:

  1. Test your application without the VPN.
  2. If your application does not work, connect to the VPN and test again.
  3. If it still doesn’t work, contact the IT Service Desk at (517) 432-6200 or visit ithelp.msu.edu.

The following list of examples will help you determine whether or not to use the VPN:

Never required for:

  • External MSU and college websites
  • Avaya IX SIP
  • Spartan 365
  • Zoom
  • Microsoft Teams
  • EBS
  • Athena EMR

Always required for:

  • MSU E-Data Warehouse
  • MSU FileShare
  • Mainframe SIS

Always required (MSU IT):

  • In general, if you work for MSU IT and access things in the Data Center, you will likely need the Campus VPN to work remotely
  • SEP Management Console
  • Quest Active Roles
  • SolarWinds

Requesting access to the VPN

You can request access to the VPN by following the steps in KB 33.

Back to Top

Discrete Point-to-Point VPN

MSU IT can consult with MSU departments on whether a local discrete point-to-point VPN may also be needed as part of a unit’s local network needs. A VPN can span physical locations on campus so employees in several different buildings can still be part of one network. A virtual firewall is also an option when it comes to virtual networking.

Back to Top

Details

Details

Article ID: 2241
Created
Fri 11/21/25 2:11 PM
Modified
Fri 11/21/25 2:11 PM

Related Services / Offerings

Related Services / Offerings (2)

MSU operates one of the largest networks in the world which provides connectivity across the Internet for hundreds of thousands of users. Our computing resources are under constant attack from external threat actors so we use next-generation firewalls to provide network segmentation from the public Internet and its various internal computing environments. This is a goal of the NIST Cybersecurity Framework (PR.PT-4 Segmentation and Filtering).
Virtual Private Network (VPN) is used to secure remote access to internal-only (non-public) services. MSU faculty and staff need to connect to trusted computing resources from remote networks across the general public Internet. ​​​​​​​VPN provides secure remote access and protects these communications across untrusted networks.