I really think you should consider securing things on both ends of the VPN and using several layers of securty

If you want some semblence of security with remote users
Users should run on limited...