Design Specifications
Scope:
- ACME Inc has a global presence in different cities and countries
- Internal resources are published in public cloud (mail, sharepoint, unified comms etc)
- Access to the mentioned resources is only allowed from the ACME Inc public resources
Problem:
-
Remote workers wont be able to access the company resources regardless of them resolving FQDNs
Solution:
- Remote access implementation routing the client traffic via the ACME Inc network perimeter
Problem:
- ACME Inc has limited bandwidth on their external circuits and for them it's better to offload as much traffic as possible. Besides, running traffic from, say, EU down under and back is, what they say, less than an ideal solution (leave the compliance questions aside for now)
Solution:
- Implement Split Tunneling and, therefore, segregate ACME Inc traffic from what is meant to be routed over the local ISP circuit