<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Checkpoint Firewall &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/checkpoint-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Tue, 13 Aug 2024 08:04:11 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Checkpoint Firewall &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hướng dẫn điều chỉnh QoS dựa vào MAC Address trên Check Point Firewall</title>
		<link>https://thegioifirewall.com/huong-dan-dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewall/</link>
					<comments>https://thegioifirewall.com/huong-dan-dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewall/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 13 Aug 2024 07:52:39 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[MAC Address]]></category>
		<category><![CDATA[QoS]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=20081</guid>

					<description><![CDATA[Bài viết này sẽ hướng dẫn các bạn cách điều chỉnh QoS dựa trên MAC Address trên thiết bị Check Point Firewall. Cấu hình gồm các bước: &#8211; Bật tính năng QoS trên Check Point Firewall &#8211; Điều chỉnh QoS dựa trên MAC Address của thiết bị Tốc độ Download và Upload của thiết bị [&#8230;]]]></description>
										<content:encoded><![CDATA[
<ol class="wp-block-list">
<li><strong>Mục đích bài viết</strong></li>
</ol>



<p class="wp-block-paragraph">Bài viết này sẽ hướng dẫn các bạn cách điều chỉnh QoS dựa trên MAC Address trên thiết bị Check Point Firewall.</p>



<ol start="2" class="wp-block-list">
<li><strong>Hướng dẫn cấu hình</strong></li>
</ol>



<p class="wp-block-paragraph">Cấu hình gồm các bước:</p>



<p class="wp-block-paragraph">&#8211; Bật tính năng QoS trên Check Point Firewall</p>



<p class="wp-block-paragraph">&#8211; Điều chỉnh QoS dựa trên MAC Address của thiết bị</p>



<ol class="wp-block-list">
<li><strong>Bật tính năng QoS trên Check Point Firewall</strong>
<ol class="wp-block-list">
<li>Vào phần <strong>Device</strong> -> <strong>Network </strong>-> <strong>Internet</strong>, chọn <strong>Edit</strong></li>
</ol>
</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-1.png" alt="" /></figure>



<ol start="2" class="wp-block-list">
<li>Vào phần Advanced, tích vào 2 ô <strong>Enable</strong> <strong>QoS</strong> <strong>(download)</strong> và <strong>Enable</strong> <strong>QoS (upload)</strong>. Có thể điều chỉnh QoS mong muốn vào ô, sau đó ấn <strong>Save</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-2.png" alt="" /></figure>



<ol start="3" class="wp-block-list">
<li>Vào website để kiểm tra tốc độ download và upload</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-3.png" alt="" /></figure>



<ol start="2" class="wp-block-list">
<li><strong>Điều chỉnh QoS dựa trên MAC Address của thiết bị</strong>
<ol class="wp-block-list">
<li>Kiểm tra MAC Address trên thiết bị</li>
</ol>
</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-4.png" alt="" /></figure>



<ol start="2" class="wp-block-list">
<li>Vào phần <strong>Access Policy</strong> -> <strong>QoS</strong> -> <strong>Policy</strong> -> <strong>New</strong> -> <strong>Top Rule</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-5.png" alt="" /></figure>



<ol start="3" class="wp-block-list">
<li>Vào phần <strong>Source</strong> -> <strong>New</strong> -> <strong>Network Object</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-6.png" alt="" /></figure>



<ol start="4" class="wp-block-list">
<li>Ở phần <strong>Type</strong>, chọn <strong>Device</strong>. Ở phần <strong>Host MAC address</strong>, điền <strong>MAC Address</strong> vào, lưu ý đổi các dấu “<strong>–</strong>“ thành “<strong>:</strong>”. Điền tên muốn đặt cho thiết bị đó. Sau đó ấn <strong>Save</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-7.png" alt="" /></figure>



<ol start="5" class="wp-block-list">
<li>Vào phần <strong>Guarantee/Limit</strong> -> Tích vào ô <strong>Guarantee/Limit</strong> -> Tích vào ô <strong>Limit</strong>. Điền số mong muốn. Sau đó ấn <strong>OK</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-8.png" alt="" /></figure>



<ol start="6" class="wp-block-list">
<li>Ấn <strong>Save</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-9.png" alt="" /></figure>



<ol start="3" class="wp-block-list">
<li><strong>Kết quả</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewal-0.png" alt="" /></figure>



<p class="wp-block-paragraph">Tốc độ Download và Upload của thiết bị chỉ định đã bị giới hạn bởi Check Point Firewall.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-dieu-chinh-qos-dua-vao-mac-address-tren-check-point-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng dẫn chặn ứng dụng trên Check Point Firewall</title>
		<link>https://thegioifirewall.com/huong-dan-chan-ung-dung-tren-check-point-firewall/</link>
					<comments>https://thegioifirewall.com/huong-dan-chan-ung-dung-tren-check-point-firewall/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 12 Aug 2024 08:16:42 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=20060</guid>

					<description><![CDATA[Bài viết này sẽ hướng dẫn các bạn cách chặn các ứng dụng mong muốn trên thiết bị Check Point Firewall. Cấu hình gồm các bước: &#8211; Bật tính năng SSL Inspection &#8211; Tạo group các ứng dụng muốn chặn &#8211; Áp dụng các group đó vào Policy Lưu lượng khi đi tới các ứng [&#8230;]]]></description>
										<content:encoded><![CDATA[
<ol class="wp-block-list">
<li><strong>Mục đích bài viết</strong></li>
</ol>



<p class="wp-block-paragraph">Bài viết này sẽ hướng dẫn các bạn cách chặn các ứng dụng mong muốn trên thiết bị Check Point Firewall.</p>



<ol start="2" class="wp-block-list">
<li><strong>Hướng dẫn cấu hình</strong></li>
</ol>



<p class="wp-block-paragraph">Cấu hình gồm các bước:</p>



<p class="wp-block-paragraph">&#8211; Bật tính năng SSL Inspection</p>



<p class="wp-block-paragraph">&#8211; Tạo group các ứng dụng muốn chặn</p>



<p class="wp-block-paragraph">&#8211; Áp dụng các group đó vào Policy</p>



<ol class="wp-block-list">
<li><strong>Bật tính năng SSL Inspection</strong>
<ol class="wp-block-list">
<li>Vào phần <strong>Access Policy</strong> -> <strong>SSL Inspection</strong> -> <strong>Policy</strong>, chọn <strong>SSL traffic inspection</strong>. Sau đó ấn Save</li>
</ol>
</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-1.png" alt="""/></figure>



<ol start="2" class="wp-block-list">
<li>Tải CA Certificate về máy</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-2.png" alt="""/></figure>



<ol start="3" class="wp-block-list">
<li>Dùng tổ hợp phím <strong>Window + R</strong>, nhập <strong>mmc</strong>, nhấn <strong>OK</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-3.png" alt="""/></figure>



<ol start="4" class="wp-block-list">
<li>Ấn <strong>File </strong>-> <strong>Add/Remove Snap-ins</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-4.png" alt="""/></figure>



<ol start="5" class="wp-block-list">
<li>Chọn <strong>Certificates </strong>-> Computer account -> Next -> Finish -> OK</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-5.png" alt="""/></figure>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-6.png" alt="""/></figure>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-7.png" alt="""/></figure>



<ol start="6" class="wp-block-list">
<li>Ấn <strong>Certificates (Local Computer)</strong> -> <strong>Trusted Root Certification Authorities</strong>. Sau đó nhấp <strong>chuột phải</strong> vào <strong>Certificates</strong> -> <strong>All Tasks</strong> -> <strong>Import</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-8.png" alt="""/></figure>



<ol start="7" class="wp-block-list">
<li>Ấn <strong>Next</strong> -> <strong>Browse</strong> -> <strong>Chọn ca</strong> -> <strong>Open </strong>-> <strong>Next</strong> -> <strong>Finish</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-9.png" alt="""/></figure>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-10.png" alt="""/></figure>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-11.png" alt="""/></figure>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-12.png" alt="""/></figure>



<ol start="2" class="wp-block-list">
<li><strong>Tạo group các trang web muốn chặn</strong>
<ol class="wp-block-list">
<li>Vào phần <strong>Users &amp; Objects</strong> -> <strong>Applications &amp; URLs</strong> -> <strong>New</strong> -> <strong>Application Group</strong></li>
</ol>
</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-13.png" alt="""/></figure>



<ol start="2" class="wp-block-list">
<li>Chọn các ứng dụng muốn chặn, sau đó ấn<strong> Save</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-14.png" alt="""/></figure>



<ol start="3" class="wp-block-list">
<li><strong>Áp dụng các group đó vào Policy</strong>
<ol class="wp-block-list">
<li>Vào phần <strong>Access Policy</strong> -> <strong>Firewall</strong> -> <strong>Policy</strong> -> <strong>New</strong> -> <strong>Top Rule</strong></li>
</ol>
</li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-15.png" alt="""/></figure>



<ol start="2" class="wp-block-list">
<li>Ở phần <strong>Application / Service</strong>, hãy chọn group ứng dụng muốn chặn. Ở phần <strong>Action</strong>, chọn <strong>Block. </strong>Sau đó ấn <strong>Save</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-16.png" alt="""/></figure>



<ol start="3" class="wp-block-list">
<li><strong>Kết quả</strong></li>
</ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/chan-ung-dung-tren-check-point-firewall-0.png" alt="""/></figure>



<p class="wp-block-paragraph">Lưu lượng khi đi tới các ứng dụng đã bị chặn bởi Check Point Firewall.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-chan-ung-dung-tren-check-point-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình đồng bộ User từ AD (Active Directory) lên Checkpoint Firewall.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-dong-bo-user-tu-ad-active-directory-len-checkpoint-firewall/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-dong-bo-user-tu-ad-active-directory-len-checkpoint-firewall/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sat, 21 May 2022 04:34:07 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[Active Directory Queries Checkpoint]]></category>
		<category><![CDATA[Browser-Based Authentication]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15846</guid>

					<description><![CDATA[1.Overview. Với tính năng User Awareness bạn có thể cấu hình để xác định các nguồn nhằm lấy danh tính người dùng, cho mục đích ghi log và cấu hình. User Awareness sẽ giúp hiển thị log dựa trên người dùng thay vì dựa trên địa chỉ IP và thực thi kiểm soát truy cập [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">1<strong>.Overview.</strong></p>



<p class="wp-block-paragraph">Với tính năng <strong>User Awareness</strong> bạn có thể cấu hình để xác định các nguồn nhằm lấy danh tính người dùng, cho mục đích ghi log và cấu hình. <strong>User Awareness</strong> sẽ giúp hiển thị log dựa trên người dùng thay vì dựa trên địa chỉ IP và thực thi kiểm soát truy cập cho người dùng và nhóm người dùng.</p>



<p class="wp-block-paragraph">Để sử dụng <strong>User Awareness</strong> bạn phải cấu hình các phương pháp nhận dạng để lấy thông tin về người dùng và nhóm người dùng. Sau khi gateway có được danh tính của người dùng, các quy tắc dựa trên người dùng có thể được thực thi trên network traffic trong Access Policy.</p>



<p class="wp-block-paragraph"><strong>User Awareness</strong> có thể sử dụng các nguồn sau để xác định người dùng:</p>



<p class="wp-block-paragraph">+ <strong>Active Directory Queries: </strong>Truy vấn đến máy chủ AD (Active Directory) để lấy thông tin người dùng.</p>



<p class="wp-block-paragraph">+ <strong>Browser-Based Authentication: </strong>Sử dụng cổng thông tin để xác thực người dùng được xác định cục bộ hoặc như một bản sao lưu cho các phương pháp nhận dạng khác.</p>



<p class="wp-block-paragraph">2<strong>. Network Diagram</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img fetchpriority="high" decoding="async" width="723" height="380" src="https://thegioifirewall.com/wp-content/uploads/image-4327.png" alt="" class="wp-image-15847" srcset="https://thegioifirewall.com/wp-content/uploads/image-4327.png 723w, https://thegioifirewall.com/wp-content/uploads/image-4327-300x158.png 300w" sizes="(max-width: 723px) 100vw, 723px" /></figure></div>



<p class="wp-block-paragraph">Bài viết hôm nay sẽ hướng dẫn các bạn cấu hình đồng bộ user từ AD lên Checkpoint Firewall sử dụng user được đồng bộ để xác thực VPN Remote Access và cấu hình policy theo group user đã đồng bộ.</p>



<p class="wp-block-paragraph"><strong>3.Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Cấu hình Active Directory Queries</strong>.</p>



<p class="wp-block-paragraph"><strong>Ví dụ:</strong> Trên AD Server có 3 group: <strong>Accounting, Sale và IT. </strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img decoding="async" width="722" height="328" src="https://thegioifirewall.com/wp-content/uploads/image-4331.png" alt="" class="wp-image-15851" srcset="https://thegioifirewall.com/wp-content/uploads/image-4331.png 722w, https://thegioifirewall.com/wp-content/uploads/image-4331-300x136.png 300w" sizes="(max-width: 722px) 100vw, 722px" /></figure></div>



<p class="wp-block-paragraph">Mỗi group có 1 user là: <strong>John, Kane, Kevin.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img decoding="async" width="727" height="322" src="https://thegioifirewall.com/wp-content/uploads/image-4332.png" alt="" class="wp-image-15852" srcset="https://thegioifirewall.com/wp-content/uploads/image-4332.png 727w, https://thegioifirewall.com/wp-content/uploads/image-4332-300x133.png 300w" sizes="(max-width: 727px) 100vw, 727px" /></figure></div>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint > Access Policy > User Awareness > Blade Control.</strong></p>



<p class="wp-block-paragraph">Click chọn <strong>ON User Awareness > Click chọn Active Directory Queries > Configure&#8230;</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="231" src="https://thegioifirewall.com/wp-content/uploads/image-4328.png" alt="" class="wp-image-15848" srcset="https://thegioifirewall.com/wp-content/uploads/image-4328.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4328-300x111.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>Active Directory Queries</strong>, click chọn <strong>Define a new Active Directory</strong> và điền các thông số sau:</p>



<ul class="wp-block-list"><li><strong>Domain</strong>: Điền tên domain của AD</li><li><strong>IPv4 address</strong>: Điền địa chỉ IP của AD Server</li><li><strong>User name</strong>: Điền user domain (Nên đùng user admin domain)</li><li><strong>Password</strong>: Nhập password user</li><li><strong>User DN</strong>: Điền FQDN user (Ex: CN=Administrator,CN=Users,DC=vacif,DC=local).</li></ul>



<p class="wp-block-paragraph">Click chọn <strong>Discover</strong>, nếu không có thông báo lỗi nào là bạn đã queries thành công. Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="480" height="445" src="https://thegioifirewall.com/wp-content/uploads/image-4329.png" alt="" class="wp-image-15849" srcset="https://thegioifirewall.com/wp-content/uploads/image-4329.png 480w, https://thegioifirewall.com/wp-content/uploads/image-4329-300x278.png 300w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Khi bạn click chọn lại <strong>Configure</strong>, domain &#8220;<strong>vacif.local</strong>&#8221; sẽ xuất hiện trong bảng <strong>Use existing Active Directory</strong> servers.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="814" height="357" src="https://thegioifirewall.com/wp-content/uploads/image-4333.png" alt="" class="wp-image-15853" srcset="https://thegioifirewall.com/wp-content/uploads/image-4333.png 814w, https://thegioifirewall.com/wp-content/uploads/image-4333-300x132.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4333-768x337.png 768w" sizes="auto, (max-width: 814px) 100vw, 814px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo bạn di chuyển xuống phần <strong>User &amp; Objects > User Management > Authentication Servers > Active Directory.</strong></p>



<p class="wp-block-paragraph">Click chọn <strong>&#8220;Permissions for Active Directory users&#8221;</strong>, trong <strong>Grant remote access permissions to</strong>: click chọn &#8220;<strong>Selected AD user group</strong>&#8221; để có thể sử dụng các user group đã được đồng bộ để xác thực VPN Remote Access. Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="810" height="330" src="https://thegioifirewall.com/wp-content/uploads/image-4334.png" alt="" class="wp-image-15854" srcset="https://thegioifirewall.com/wp-content/uploads/image-4334.png 810w, https://thegioifirewall.com/wp-content/uploads/image-4334-300x122.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4334-768x313.png 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Add các User Group cho Remote Access Users.</strong></p>



<p class="wp-block-paragraph">Bạn di chuyển đến phần<strong> VPN > Remote Access > Remote Access Users > Edit Permissions > Active Directory.</strong></p>



<p class="wp-block-paragraph">Ở đây bạn sẽ thấy các User Group đã được đồng bộ từ AD.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="810" height="398" src="https://thegioifirewall.com/wp-content/uploads/image-4335.png" alt="" class="wp-image-15855" srcset="https://thegioifirewall.com/wp-content/uploads/image-4335.png 810w, https://thegioifirewall.com/wp-content/uploads/image-4335-300x147.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4335-768x377.png 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure></div>



<p class="wp-block-paragraph">Bạn click chọn các User Group bạn muốn dùng để xác thực. Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="555" height="498" src="https://thegioifirewall.com/wp-content/uploads/image-4336.png" alt="" class="wp-image-15856" srcset="https://thegioifirewall.com/wp-content/uploads/image-4336.png 555w, https://thegioifirewall.com/wp-content/uploads/image-4336-300x269.png 300w" sizes="auto, (max-width: 555px) 100vw, 555px" /></figure></div>



<p class="wp-block-paragraph">Như vậy bạn đã add thành công 3 Group: <strong>Accounting, Sales và IT.</strong></p>



<p class="wp-block-paragraph"><strong>Note: Bạn sẽ không thể chọn add 1 user cụ thể từ AD, bạn chỉ có thể chọn group có chứa user đó.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="267" src="https://thegioifirewall.com/wp-content/uploads/image-4337.png" alt="" class="wp-image-15857" srcset="https://thegioifirewall.com/wp-content/uploads/image-4337.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4337-300x128.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 3: Kiểm tra xác thực VPN Remote Access sử dụng User Syn từ AD.</strong></p>



<p class="wp-block-paragraph">Bạn có thể tham khảo cấu hình<strong> VPN Remote Access</strong> sử dụng <strong>Checkpoint VPN Client</strong> qua bài viết sau: <a href="https://www.thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/">https://www.thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/</a></p>



<p class="wp-block-paragraph">Kiểm tra kết nối VPN user <strong>Kevin</strong> nằm trong <strong>Group Accounting</strong>: Kết nối thành công</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="554" height="358" src="https://thegioifirewall.com/wp-content/uploads/image-4338.png" alt="" class="wp-image-15858" srcset="https://thegioifirewall.com/wp-content/uploads/image-4338.png 554w, https://thegioifirewall.com/wp-content/uploads/image-4338-300x194.png 300w" sizes="auto, (max-width: 554px) 100vw, 554px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="826" height="162" src="https://thegioifirewall.com/wp-content/uploads/image-4339.png" alt="" class="wp-image-15859" srcset="https://thegioifirewall.com/wp-content/uploads/image-4339.png 826w, https://thegioifirewall.com/wp-content/uploads/image-4339-300x59.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4339-768x151.png 768w" sizes="auto, (max-width: 826px) 100vw, 826px" /></figure></div>



<p class="wp-block-paragraph"> Kiểm tra kết nối VPN user <strong>Kane </strong>nằm trong <strong>Group Sale</strong>: Kết nối thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="571" height="372" src="https://thegioifirewall.com/wp-content/uploads/image-4340.png" alt="" class="wp-image-15860" srcset="https://thegioifirewall.com/wp-content/uploads/image-4340.png 571w, https://thegioifirewall.com/wp-content/uploads/image-4340-300x195.png 300w" sizes="auto, (max-width: 571px) 100vw, 571px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="825" height="165" src="https://thegioifirewall.com/wp-content/uploads/image-4341.png" alt="" class="wp-image-15861" srcset="https://thegioifirewall.com/wp-content/uploads/image-4341.png 825w, https://thegioifirewall.com/wp-content/uploads/image-4341-300x60.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4341-768x154.png 768w" sizes="auto, (max-width: 825px) 100vw, 825px" /></figure></div>



<p class="wp-block-paragraph">  Kiểm tra kết nối VPN user <strong>John </strong>nằm trong <strong>Group Sale</strong>: Kết nối thành công. </p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="568" height="369" src="https://thegioifirewall.com/wp-content/uploads/image-4342.png" alt="" class="wp-image-15862" srcset="https://thegioifirewall.com/wp-content/uploads/image-4342.png 568w, https://thegioifirewall.com/wp-content/uploads/image-4342-300x195.png 300w" sizes="auto, (max-width: 568px) 100vw, 568px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="821" height="129" src="https://thegioifirewall.com/wp-content/uploads/image-4343.png" alt="" class="wp-image-15863" srcset="https://thegioifirewall.com/wp-content/uploads/image-4343.png 821w, https://thegioifirewall.com/wp-content/uploads/image-4343-300x47.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4343-768x121.png 768w" sizes="auto, (max-width: 821px) 100vw, 821px" /></figure></div>



<p class="wp-block-paragraph">Bạn cũng có thể tạo Policy riêng cho group trong <strong>Access Policy > Firewall > Policy</strong> <strong>> New Policy.</strong></p>



<p class="wp-block-paragraph">Trong <strong>Source > Active Directory > chọn Group (Ex: Accounting)</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="723" height="382" src="https://thegioifirewall.com/wp-content/uploads/image-4344.png" alt="" class="wp-image-15864" srcset="https://thegioifirewall.com/wp-content/uploads/image-4344.png 723w, https://thegioifirewall.com/wp-content/uploads/image-4344-300x159.png 300w" sizes="auto, (max-width: 723px) 100vw, 723px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-dong-bo-user-tu-ad-active-directory-len-checkpoint-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình tính năng SSL Inspection trên Checkpoint Firewall.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-tinh-nang-ssl-inspection-tren-checkpoint-firewall/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-tinh-nang-ssl-inspection-tren-checkpoint-firewall/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 15 May 2022 13:10:40 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[cấu hình tính năng SSL Inspection trên Checkpoint Firewall]]></category>
		<category><![CDATA[SSL Inspection Checkpoint]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15628</guid>

					<description><![CDATA[1.Overview Với tính năng SSL Inspection bạn sẽ cho phép nhiều Software Blades khác nhau hỗ trợ kiểm tra SSL kiểm tra lưu lượng được mã hóa bởi giao thức Secure Sockets Layer (SSL). Để cho phép gateway kiểm tra các kết nối bảo mật, tất cả các endpoint phía sau gateway phải cài đặt [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong></p>



<p class="wp-block-paragraph">Với tính năng SSL Inspection bạn sẽ cho phép nhiều Software Blades khác nhau hỗ trợ kiểm tra SSL kiểm tra lưu lượng được mã hóa bởi giao thức Secure Sockets Layer (SSL). Để cho phép gateway kiểm tra các kết nối bảo mật, tất cả các endpoint phía sau gateway phải cài đặt gateway CA certificate. </p>



<p class="wp-block-paragraph">Software Blades&nbsp;hỗ trợ SSL traffic inspection bao gồm:</p>



<ul class="wp-block-list"><li>Application &amp; URL Filtering</li><li>IPS</li><li>Anti-Virus</li><li>Anti-Bot</li><li>Threat Emulation</li></ul>



<p class="wp-block-paragraph">Bài viết sẽ hướng dẫn các bạn cấu hình SSL Inspection, cài đặt CA certificate trên máy trạm, cũng cấu hình bypass các traffic bạn tin tưởng khỏi sự kiểm tra của tính năng SSL Inspection.</p>



<p class="wp-block-paragraph"><strong>2. Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Bật SSL Inspection.</strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị của<strong> Checkpoint Firewall &gt; Access Policy &gt; SSL Inspection &gt;Policy</strong></p>



<p class="wp-block-paragraph">Click chọn <strong>SSL traffic inspection</strong> để enable tính năng này.</p>



<p class="wp-block-paragraph">P<strong>rotocols to inspect</strong> chọn <strong>HTTPS.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="623" height="288" src="https://thegioifirewall.com/wp-content/uploads/image-4216.png" alt="" class="wp-image-15630" srcset="https://thegioifirewall.com/wp-content/uploads/image-4216.png 623w, https://thegioifirewall.com/wp-content/uploads/image-4216-300x139.png 300w" sizes="auto, (max-width: 623px) 100vw, 623px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo click chọn <strong>Download CA Certificate </strong>để tải xuống<strong> CA Certificate</strong>.</p>



<p class="wp-block-paragraph"><strong>Bước 2: Cài đặt CA Certificate.</strong></p>



<p class="wp-block-paragraph">Trên máy trạm trong mạng LAN của Checkpoint Firewall. Nhấn tổ hợp phím <strong>Window + R.</strong> Gõ &#8220;<strong>mmc</strong>&#8221; để add CA <strong>Certificate</strong> vào <strong>Trust Root Certificate Authorities.</strong></p>



<p class="wp-block-paragraph">CLick chọn <strong>File &gt; Add/Remove Snap-in</strong>..</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="636" height="324" src="https://thegioifirewall.com/wp-content/uploads/image-4222.png" alt="" class="wp-image-15636" srcset="https://thegioifirewall.com/wp-content/uploads/image-4222.png 636w, https://thegioifirewall.com/wp-content/uploads/image-4222-300x153.png 300w" sizes="auto, (max-width: 636px) 100vw, 636px" /></figure></div>



<p class="wp-block-paragraph">Chọn mục <strong>Certificates</strong> trong bảng <strong>Available snap-in</strong> và click <strong>Add</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="612" height="433" src="https://thegioifirewall.com/wp-content/uploads/image-4218.png" alt="" class="wp-image-15632" srcset="https://thegioifirewall.com/wp-content/uploads/image-4218.png 612w, https://thegioifirewall.com/wp-content/uploads/image-4218-300x212.png 300w" sizes="auto, (max-width: 612px) 100vw, 612px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>Computer Account &gt; Next</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="480" height="360" src="https://thegioifirewall.com/wp-content/uploads/image-4219.png" alt="" class="wp-image-15633" srcset="https://thegioifirewall.com/wp-content/uploads/image-4219.png 480w, https://thegioifirewall.com/wp-content/uploads/image-4219-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4219-400x300.png 400w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>Local computer &gt; Finish.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="485" height="362" src="https://thegioifirewall.com/wp-content/uploads/image-4220.png" alt="" class="wp-image-15634" srcset="https://thegioifirewall.com/wp-content/uploads/image-4220.png 485w, https://thegioifirewall.com/wp-content/uploads/image-4220-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4220-400x300.png 400w" sizes="auto, (max-width: 485px) 100vw, 485px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo mở mục <strong>Certificates (Local Computer) &gt; Trusted Root Certification Authorities &gt; Certificate &gt; Right click &gt; All task &gt; Import.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="736" height="376" src="https://thegioifirewall.com/wp-content/uploads/image-4221.png" alt="" class="wp-image-15635" srcset="https://thegioifirewall.com/wp-content/uploads/image-4221.png 736w, https://thegioifirewall.com/wp-content/uploads/image-4221-300x153.png 300w" sizes="auto, (max-width: 736px) 100vw, 736px" /></figure></div>



<p class="wp-block-paragraph">Click chọn <strong>Next &gt; Browse</strong> chọn file <strong>CA Certificate</strong> đã tải xuống ở bước 1.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="737" height="365" src="https://thegioifirewall.com/wp-content/uploads/image-4223.png" alt="" class="wp-image-15637" srcset="https://thegioifirewall.com/wp-content/uploads/image-4223.png 737w, https://thegioifirewall.com/wp-content/uploads/image-4223-300x149.png 300w" sizes="auto, (max-width: 737px) 100vw, 737px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>file Ca.crt &gt; Open</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="694" height="485" src="https://thegioifirewall.com/wp-content/uploads/image-4224.png" alt="" class="wp-image-15638" srcset="https://thegioifirewall.com/wp-content/uploads/image-4224.png 694w, https://thegioifirewall.com/wp-content/uploads/image-4224-300x210.png 300w" sizes="auto, (max-width: 694px) 100vw, 694px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Next &gt;</strong> chọn <strong>Place all certificates in the following store</strong> là <strong>&#8220;Trusted Root Certification Authorities&#8221;</strong>. Click <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="709" height="355" src="https://thegioifirewall.com/wp-content/uploads/image-4225.png" alt="" class="wp-image-15639" srcset="https://thegioifirewall.com/wp-content/uploads/image-4225.png 709w, https://thegioifirewall.com/wp-content/uploads/image-4225-300x150.png 300w" sizes="auto, (max-width: 709px) 100vw, 709px" /></figure></div>



<p class="wp-block-paragraph">Cuối cùng chọn <strong>Finish.</strong> Thông báo <strong>&#8220;The import was successful&#8221;</strong> bạn đã add <strong>CA certificate</strong> thành công.</p>



<p class="wp-block-paragraph"></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="606" height="354" src="https://thegioifirewall.com/wp-content/uploads/image-4227.png" alt="" class="wp-image-15641" srcset="https://thegioifirewall.com/wp-content/uploads/image-4227.png 606w, https://thegioifirewall.com/wp-content/uploads/image-4227-300x175.png 300w" sizes="auto, (max-width: 606px) 100vw, 606px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 3: Cấu hình Bypass các traffic khỏi SSL Inspection</strong>.</p>



<p class="wp-block-paragraph">Bạn đi chuyển đến <strong>Log and Monitoring &gt; Log &gt; Security Logs.</strong> Bạn sẽ thấy tất cả các traffic đều bị <strong>HTTPS Inspect.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="215" src="https://thegioifirewall.com/wp-content/uploads/image-4228.png" alt="" class="wp-image-15642" srcset="https://thegioifirewall.com/wp-content/uploads/image-4228.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4228-300x103.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Hầu hết các trang web đều vẫn có thể truy cập được khi bật tính năng này như facebook.com</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="370" src="https://thegioifirewall.com/wp-content/uploads/image-4229.png" alt="" class="wp-image-15643" srcset="https://thegioifirewall.com/wp-content/uploads/image-4229.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4229-300x178.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Nhưng cũng có những trang web không thể truy cập nếu bật tính năng SSL Inspection này như chat.zalo.me</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="280" src="https://thegioifirewall.com/wp-content/uploads/image-4230.png" alt="" class="wp-image-15644" srcset="https://thegioifirewall.com/wp-content/uploads/image-4230.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4230-300x135.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="354" src="https://thegioifirewall.com/wp-content/uploads/image-4231.png" alt="" class="wp-image-15645" srcset="https://thegioifirewall.com/wp-content/uploads/image-4231.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4231-300x170.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Để bypass web chat.zalo.me khỏi SSL Inspection bạn cần add URL website này vào mục <strong>Exceptions.</strong></p>



<p class="wp-block-paragraph">Trong <strong>SSL Inspection &gt; Exceptions &gt;New.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="317" src="https://thegioifirewall.com/wp-content/uploads/image-4232.png" alt="" class="wp-image-15646" srcset="https://thegioifirewall.com/wp-content/uploads/image-4232.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4232-300x152.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Điền các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Source: </strong>LAN Network</p>



<p class="wp-block-paragraph"><strong>Destination: </strong>Internet</p>



<p class="wp-block-paragraph">Se<strong>rvice: </strong>HTTPS</p>



<p class="wp-block-paragraph">C<strong>ategory/Custom Application: </strong>Chọn <strong>New &gt; URL</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="302" src="https://thegioifirewall.com/wp-content/uploads/image-4233.png" alt="" class="wp-image-15647" srcset="https://thegioifirewall.com/wp-content/uploads/image-4233.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4233-300x145.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Điền <strong>URL &#8220;chat.zalo.me&#8221;</strong>. CLick <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="321" height="164" src="https://thegioifirewall.com/wp-content/uploads/image-4234.png" alt="" class="wp-image-15648" srcset="https://thegioifirewall.com/wp-content/uploads/image-4234.png 321w, https://thegioifirewall.com/wp-content/uploads/image-4234-300x153.png 300w" sizes="auto, (max-width: 321px) 100vw, 321px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Apply. </strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="256" src="https://thegioifirewall.com/wp-content/uploads/image-4235.png" alt="" class="wp-image-15649" srcset="https://thegioifirewall.com/wp-content/uploads/image-4235.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4235-300x123.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Truy cập lần nữa vào trang <strong>web chat.zalo.me</strong>, bạn đã truy cập vào trang web bình thường.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="324" src="https://thegioifirewall.com/wp-content/uploads/image-4236.png" alt="" class="wp-image-15650" srcset="https://thegioifirewall.com/wp-content/uploads/image-4236.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4236-300x156.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Kiểm tra Logs trên Checkpoint, bạn sẽ thấy log web chat.zalo.me đã được Bypass.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="120" src="https://thegioifirewall.com/wp-content/uploads/image-4237.png" alt="" class="wp-image-15651" srcset="https://thegioifirewall.com/wp-content/uploads/image-4237.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4237-300x58.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="382" src="https://thegioifirewall.com/wp-content/uploads/image-4238.png" alt="" class="wp-image-15652" srcset="https://thegioifirewall.com/wp-content/uploads/image-4238.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4238-300x184.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-tinh-nang-ssl-inspection-tren-checkpoint-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình tính năng Browser-Based Authentication (Captive portal) xác thực người dùng truy cập Internet.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-tinh-nang-browser-based-authentication-captive-portal-xac-thuc-nguoi-dung-truy-cap-internet/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-tinh-nang-browser-based-authentication-captive-portal-xac-thuc-nguoi-dung-truy-cap-internet/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 15 May 2022 13:10:34 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[Browser-Based Authentication]]></category>
		<category><![CDATA[Browser-Based Authentication (Captive portal)]]></category>
		<category><![CDATA[Captive portal]]></category>
		<category><![CDATA[Checkpoint Browser-Based Authentication]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15656</guid>

					<description><![CDATA[1.Overview Với tính năng Browser-Based Authentication trên Checkpoint sử dụng giao diện web để xác thực người dùng trước khi họ có thể truy cập tài nguyên mạng hoặc Internet. Khi người dùng cố gắng truy cập một tài nguyên được bảo vệ, họ phải đăng nhập xác thực để tiếp tục truy cập. 2. [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong></p>



<p class="wp-block-paragraph">Với tính năng <strong>Browser-Based Authentication</strong> trên Checkpoint sử dụng giao diện web để xác thực người dùng trước khi họ có thể truy cập tài nguyên mạng hoặc Internet. Khi người dùng cố gắng truy cập một tài nguyên được bảo vệ, họ phải đăng nhập xác thực để tiếp tục truy cập.</p>



<p class="wp-block-paragraph"><strong>2. Network Diagram.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="876" height="347" src="https://thegioifirewall.com/wp-content/uploads/image-4239.png" alt="" class="wp-image-15657" srcset="https://thegioifirewall.com/wp-content/uploads/image-4239.png 876w, https://thegioifirewall.com/wp-content/uploads/image-4239-300x119.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4239-768x304.png 768w" sizes="auto, (max-width: 876px) 100vw, 876px" /></figure></div>



<p class="wp-block-paragraph">Bài viết hôm nay sẽ hướng dẫn các bạn cấu hình tính năng <strong>Browser-Based Authentication</strong> trên Checkpoint Firewall để xác thực, cũng như tạo các policy theo người dùng trước khi truy cập Internet.</p>



<p class="wp-block-paragraph"><strong>3. Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Cấu hình Browser-Based Authentication</strong>.</p>



<p class="wp-block-paragraph">Để enable tính năng <strong>Browser-Based Authentication</strong> trên giao diện quản trị của <strong>Checkpoint Firewall &gt; Access Policy &gt; User Awareness &gt; Blade Control &gt; Click chọn ON User Awareness. </strong></p>



<p class="wp-block-paragraph">Dưới phần<strong> Policy Configuration &gt;</strong> click chọn <strong>Browser-Based Authentication</strong> &gt; click <strong>Configure.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="252" src="https://thegioifirewall.com/wp-content/uploads/image-4240.png" alt="" class="wp-image-15658" srcset="https://thegioifirewall.com/wp-content/uploads/image-4240.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4240-300x121.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>Identification tab: </strong></p>



<p class="wp-block-paragraph">Bạn có thể chọn <strong>Block unauthenticated users when the captive portal is not applicable</strong> cho các user chưa được xác thực.</p>



<p class="wp-block-paragraph">S<strong>pecific destinations: </strong>Chọn <strong>Internet.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="533" height="270" src="https://thegioifirewall.com/wp-content/uploads/image-4241.png" alt="" class="wp-image-15659" srcset="https://thegioifirewall.com/wp-content/uploads/image-4241.png 533w, https://thegioifirewall.com/wp-content/uploads/image-4241-300x152.png 300w" sizes="auto, (max-width: 533px) 100vw, 533px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua <strong>Customization</strong>&nbsp;tab: Bạn có thể để mặc định, hoặc có thể dùng logo khác theo ý muốn bằng cách click chọn <strong>Upload.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="529" height="356" src="https://thegioifirewall.com/wp-content/uploads/image-4242.png" alt="" class="wp-image-15660" srcset="https://thegioifirewall.com/wp-content/uploads/image-4242.png 529w, https://thegioifirewall.com/wp-content/uploads/image-4242-300x202.png 300w" sizes="auto, (max-width: 529px) 100vw, 529px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua <strong>Advanced</strong>&nbsp;tab:</p>



<p class="wp-block-paragraph"><strong>Portal Address</strong>: Điền địa chỉ IP sẽ dùng để làm trang xác thực user.</p>



<p class="wp-block-paragraph"><strong>Session timeout</strong>: Cài đặt thời gian user có thể truy cập network hoặc Internet trước khi cần xác thực lại.</p>



<p class="wp-block-paragraph">Sau cùng click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="529" height="282" src="https://thegioifirewall.com/wp-content/uploads/image-4243.png" alt="" class="wp-image-15661" srcset="https://thegioifirewall.com/wp-content/uploads/image-4243.png 529w, https://thegioifirewall.com/wp-content/uploads/image-4243-300x160.png 300w" sizes="auto, (max-width: 529px) 100vw, 529px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Tạo Users.</strong></p>



<p class="wp-block-paragraph">Trong giao diện quản trị của <strong>Checkpoint Firewall &gt; User &amp; Objects &gt; User Awareness &gt;User &gt; New &gt; Local User.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="705" height="163" src="https://thegioifirewall.com/wp-content/uploads/image-4244.png" alt="" class="wp-image-15662" srcset="https://thegioifirewall.com/wp-content/uploads/image-4244.png 705w, https://thegioifirewall.com/wp-content/uploads/image-4244-300x69.png 300w" sizes="auto, (max-width: 705px) 100vw, 705px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>Remote Access</strong> tab: Điền các thông số như hình dưới. Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="532" height="479" src="https://thegioifirewall.com/wp-content/uploads/image-4245.png" alt="" class="wp-image-15663" srcset="https://thegioifirewall.com/wp-content/uploads/image-4245.png 532w, https://thegioifirewall.com/wp-content/uploads/image-4245-300x270.png 300w" sizes="auto, (max-width: 532px) 100vw, 532px" /></figure></div>



<p class="wp-block-paragraph">Ở đây mình tạo 2 user là <strong>John</strong> và <strong>Steven.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="708" height="168" src="https://thegioifirewall.com/wp-content/uploads/image-4246.png" alt="" class="wp-image-15664" srcset="https://thegioifirewall.com/wp-content/uploads/image-4246.png 708w, https://thegioifirewall.com/wp-content/uploads/image-4246-300x71.png 300w" sizes="auto, (max-width: 708px) 100vw, 708px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 3: Kiểm tra cấu hình</strong>.</p>



<p class="wp-block-paragraph">Bạn sử dụng máy tính trong mạng LAN của Checkpoint thử truy cập các trang web thì sẽ xuất hiện 1 trang web của Checkpoint yêu cầu xác thực thông tin người dùng trước khi được truy cập Internet.</p>



<p class="wp-block-paragraph">Bạn điền <strong>Username và Password</strong> của <strong>John</strong> đã tạo ở bước 2. Click <strong>Log In.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="601" height="394" src="https://thegioifirewall.com/wp-content/uploads/image-4247.png" alt="" class="wp-image-15665" srcset="https://thegioifirewall.com/wp-content/uploads/image-4247.png 601w, https://thegioifirewall.com/wp-content/uploads/image-4247-300x197.png 300w" sizes="auto, (max-width: 601px) 100vw, 601px" /></figure></div>



<p class="wp-block-paragraph">Click chọn &#8220;<strong>I have read and agreed to the terms and conditions</strong>&#8220;. Click <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="281" src="https://thegioifirewall.com/wp-content/uploads/image-4248.png" alt="" class="wp-image-15666" srcset="https://thegioifirewall.com/wp-content/uploads/image-4248.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4248-300x135.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Khi đã xác thực thành công bạn sẽ truy cập internet bình thường. Sẽ hiện thông báo thời gian bạn có thể truy cập Internet bình thường trước khi cần phải xác thực lại. </p>



<p class="wp-block-paragraph"><strong>Note: Bạn không được tắt trang xác thực này để duy trì việc truy cập Internet.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="593" height="418" src="https://thegioifirewall.com/wp-content/uploads/image-4249.png" alt="" class="wp-image-15667" srcset="https://thegioifirewall.com/wp-content/uploads/image-4249.png 593w, https://thegioifirewall.com/wp-content/uploads/image-4249-300x211.png 300w" sizes="auto, (max-width: 593px) 100vw, 593px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 4: Tạo Policy xác thực theo User.</strong></p>



<p class="wp-block-paragraph">Tiếp theo mình sẽ tạo <strong>1 policy cấm truy cập facebook </strong>đối với user <strong>John.</strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; User &amp; Objects &gt; Network Resources &gt;Network Object Groups &gt; New</strong>.</p>



<p class="wp-block-paragraph">Điền tên cho <strong>Network Object Groups</strong> <strong>(Ex: Block_FB_VN) &gt; New &gt; Type: Domain Name &gt; Domain: Facebook.com</strong>. Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="873" height="321" src="https://thegioifirewall.com/wp-content/uploads/image-4250.png" alt="" class="wp-image-15668" srcset="https://thegioifirewall.com/wp-content/uploads/image-4250.png 873w, https://thegioifirewall.com/wp-content/uploads/image-4250-300x110.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4250-768x282.png 768w" sizes="auto, (max-width: 873px) 100vw, 873px" /></figure></div>



<p class="wp-block-paragraph">Để tạo Policy bạn đi đến <strong>Access Policy &gt; Firewall &gt; Policy &gt; New &gt; On Top.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="715" height="182" src="https://thegioifirewall.com/wp-content/uploads/image-4251.png" alt="" class="wp-image-15669" srcset="https://thegioifirewall.com/wp-content/uploads/image-4251.png 715w, https://thegioifirewall.com/wp-content/uploads/image-4251-300x76.png 300w" sizes="auto, (max-width: 715px) 100vw, 715px" /></figure></div>



<p class="wp-block-paragraph">Trong phần <strong>Source: </strong>chọn <strong>User tab &gt; chọn John</strong>.</p>



<p class="wp-block-paragraph">D<strong>estination:</strong> chọn <strong>Network Object Groups</strong> <strong>(Ex: Block_FB_VN)</strong>.</p>



<p class="wp-block-paragraph"><strong>Action:</strong> chọn <strong>Block</strong>.</p>



<p class="wp-block-paragraph">Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="691" height="370" src="https://thegioifirewall.com/wp-content/uploads/image-4252.png" alt="" class="wp-image-15670" srcset="https://thegioifirewall.com/wp-content/uploads/image-4252.png 691w, https://thegioifirewall.com/wp-content/uploads/image-4252-300x161.png 300w" sizes="auto, (max-width: 691px) 100vw, 691px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="278" src="https://thegioifirewall.com/wp-content/uploads/image-4253.png" alt="" class="wp-image-15671" srcset="https://thegioifirewall.com/wp-content/uploads/image-4253.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4253-300x134.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Đã tạo xong policy chặn truy cập facebook với user John.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="704" height="170" src="https://thegioifirewall.com/wp-content/uploads/image-4254.png" alt="" class="wp-image-15672" srcset="https://thegioifirewall.com/wp-content/uploads/image-4254.png 704w, https://thegioifirewall.com/wp-content/uploads/image-4254-300x72.png 300w" sizes="auto, (max-width: 704px) 100vw, 704px" /></figure></div>



<p class="wp-block-paragraph">K<strong>iểm tra:</strong> Xác thực với user John và thử truy cập facebook, kết quả là không thể truy cập được. Nhưng các trang web khác vẫn truy cập bình thường.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="533" height="283" src="https://thegioifirewall.com/wp-content/uploads/image-4255.png" alt="" class="wp-image-15673" srcset="https://thegioifirewall.com/wp-content/uploads/image-4255.png 533w, https://thegioifirewall.com/wp-content/uploads/image-4255-300x159.png 300w" sizes="auto, (max-width: 533px) 100vw, 533px" /></figure></div>



<p class="wp-block-paragraph">Kiểm tra Log trên Checkpoint Firewall. Các traffic user John đều bị <strong>Drop.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="777" height="219" src="https://thegioifirewall.com/wp-content/uploads/image-4256.png" alt="" class="wp-image-15674" srcset="https://thegioifirewall.com/wp-content/uploads/image-4256.png 777w, https://thegioifirewall.com/wp-content/uploads/image-4256-300x85.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4256-768x216.png 768w" sizes="auto, (max-width: 777px) 100vw, 777px" /></figure></div>



<p class="wp-block-paragraph">Tiếp tục <strong>Login bằng user Steven</strong> thì truy cập facebook bình thường.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="525" height="340" src="https://thegioifirewall.com/wp-content/uploads/image-4257.png" alt="" class="wp-image-15675" srcset="https://thegioifirewall.com/wp-content/uploads/image-4257.png 525w, https://thegioifirewall.com/wp-content/uploads/image-4257-300x194.png 300w" sizes="auto, (max-width: 525px) 100vw, 525px" /></figure></div>



<p class="wp-block-paragraph"> Kiểm tra Log trên Checkpoint Firewall. Log thể hiện user John đã log out và user Steven đã login thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="835" height="231" src="https://thegioifirewall.com/wp-content/uploads/image-4258.png" alt="" class="wp-image-15676" srcset="https://thegioifirewall.com/wp-content/uploads/image-4258.png 835w, https://thegioifirewall.com/wp-content/uploads/image-4258-300x83.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4258-768x212.png 768w" sizes="auto, (max-width: 835px) 100vw, 835px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="691" height="345" src="https://thegioifirewall.com/wp-content/uploads/image-4259.png" alt="" class="wp-image-15677" srcset="https://thegioifirewall.com/wp-content/uploads/image-4259.png 691w, https://thegioifirewall.com/wp-content/uploads/image-4259-300x150.png 300w" sizes="auto, (max-width: 691px) 100vw, 691px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="689" height="369" src="https://thegioifirewall.com/wp-content/uploads/image-4260.png" alt="" class="wp-image-15678" srcset="https://thegioifirewall.com/wp-content/uploads/image-4260.png 689w, https://thegioifirewall.com/wp-content/uploads/image-4260-300x161.png 300w" sizes="auto, (max-width: 689px) 100vw, 689px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-tinh-nang-browser-based-authentication-captive-portal-xac-thuc-nguoi-dung-truy-cap-internet/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn tạo và check các quyền Administrator Roles trên Checkpoint Firewall.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-tao-va-check-cac-quyen-administrator-roles-tren-checkpoint-firewall/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-tao-va-check-cac-quyen-administrator-roles-tren-checkpoint-firewall/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 15 May 2022 13:10:15 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[Administrator Roles Checkpoint]]></category>
		<category><![CDATA[Super Administrator Checkpoint]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15681</guid>

					<description><![CDATA[1.Overview Trên Checkpoint Firewall cung cấp các Administrator Roles sau: Super Administrator: Có tất cả các quyền cấu hình. Quản trị viên cấp cao có thể tạo quản trị viên mới được xác định và thay đổi quyền cho những người khác. Read Only Administrator: Quyền hạn chế. Read Only Administrator không thể cập nhật [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">1<strong>.Overview</strong></p>



<p class="wp-block-paragraph">Trên Checkpoint Firewall cung cấp các <strong>Administrator Roles</strong> sau:</p>



<p class="wp-block-paragraph"><strong>Super Administrator</strong>: Có tất cả các quyền cấu hình. Quản trị viên cấp cao có thể tạo quản trị viên mới được xác định và thay đổi quyền cho những người khác.</p>



<p class="wp-block-paragraph"><strong>Read Only Administrator</strong>: Quyền hạn chế. <strong>Read Only Administrator</strong> không thể cập nhật cấu hình nhưng có thể thay đổi mật khẩu của riêng mình hoặc chạy báo cáo giám sát lưu lượng từ trang Tool.</p>



<p class="wp-block-paragraph"><strong>Networking Administrator</strong>: Quyền hạn chế. <strong>Networking Administrator</strong>&nbsp;có thể cập nhật hoặc sửa đổi operating system settings. Và cũng có thể chọn service hoặc network object nhưng không thể tạo hoặc sửa đổi nó.</p>



<p class="wp-block-paragraph"><strong>Mobile Administrator</strong>: <strong>Mobile administrators</strong> cho phép thực hiện tất cả các hoạt động mạng trên tất cả các giao diện. Có thể tự thay đổi mật khẩu của riêng mình, tạo báo cáo, reboot, thay đổi sự kiện và chính sách di động. <strong>Mobile administrators</strong> không thể đăng nhập hoặc truy cập vào WebUI.</p>



<p class="wp-block-paragraph">Hai quản trị viên có write permissions không thể đăng nhập cùng một lúc. Nếu một quản trị viên đã đăng nhập, một thông báo sẽ hiển thị. Bạn có thể chọn đăng nhập với Read-Only permission hoặc tiếp tục. Nếu bạn tiếp tục quá trình đăng nhập, phiên quản trị viên đầu tiên sẽ tự động kết thúc. </p>



<p class="wp-block-paragraph"><strong>2. Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Tạo các Administrator Roles</strong>.</p>



<p class="wp-block-paragraph">Trên trang quản trị của <strong>Checkpoint Firewall &gt; Device &gt; System &gt; Administrators &gt; New.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="233" src="https://thegioifirewall.com/wp-content/uploads/image-4261.png" alt="" class="wp-image-15682" srcset="https://thegioifirewall.com/wp-content/uploads/image-4261.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4261-300x112.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Vì đã có mặc định<strong> Super Admin</strong>, nên ta sẽ tạo thêm các <strong>Administrator Roles</strong> còn lại. </p>



<p class="wp-block-paragraph">Ở đây mình sẽ tạo thêm <strong>Administrator Roles</strong> là <strong>Read-Only Admin</strong> và <strong>Networking Admin.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="670" height="207" src="https://thegioifirewall.com/wp-content/uploads/image-4262.png" alt="" class="wp-image-15683" srcset="https://thegioifirewall.com/wp-content/uploads/image-4262.png 670w, https://thegioifirewall.com/wp-content/uploads/image-4262-300x93.png 300w" sizes="auto, (max-width: 670px) 100vw, 670px" /></figure></div>



<p class="wp-block-paragraph">Bạn có thể tinh chỉnh các yêu cầu cho các <strong>Administrator Roles</strong> trong <strong>Security Setting.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="407" height="385" src="https://thegioifirewall.com/wp-content/uploads/image-4263.png" alt="" class="wp-image-15684" srcset="https://thegioifirewall.com/wp-content/uploads/image-4263.png 407w, https://thegioifirewall.com/wp-content/uploads/image-4263-300x284.png 300w" sizes="auto, (max-width: 407px) 100vw, 407px" /></figure></div>



<p class="wp-block-paragraph">Đã tạo xong các <strong>Administrator Roles</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="779" height="293" src="https://thegioifirewall.com/wp-content/uploads/image-4264.png" alt="" class="wp-image-15685" srcset="https://thegioifirewall.com/wp-content/uploads/image-4264.png 779w, https://thegioifirewall.com/wp-content/uploads/image-4264-300x113.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4264-768x289.png 768w" sizes="auto, (max-width: 779px) 100vw, 779px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Kiểm tra các quyền của</strong> <strong>Administrator Roles</strong>.</p>



<p class="wp-block-paragraph"><strong>Read-Only Admin:</strong> Đăng nhập bằng user admin <strong>John</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="861" height="250" src="https://thegioifirewall.com/wp-content/uploads/image-4265.png" alt="" class="wp-image-15686" srcset="https://thegioifirewall.com/wp-content/uploads/image-4265.png 861w, https://thegioifirewall.com/wp-content/uploads/image-4265-300x87.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4265-768x223.png 768w" sizes="auto, (max-width: 861px) 100vw, 861px" /></figure></div>



<p class="wp-block-paragraph">Thử cập nhật các Firewall Policy sẽ nhận được thông báo không có quyền để cấu hình.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="674" height="292" src="https://thegioifirewall.com/wp-content/uploads/image-4266.png" alt="" class="wp-image-15687" srcset="https://thegioifirewall.com/wp-content/uploads/image-4266.png 674w, https://thegioifirewall.com/wp-content/uploads/image-4266-300x130.png 300w" sizes="auto, (max-width: 674px) 100vw, 674px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo là <strong>Networking Admin</strong>: Đăng nhập với user admin <strong>Steven</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="826" height="241" src="https://thegioifirewall.com/wp-content/uploads/image-4267.png" alt="" class="wp-image-15688" srcset="https://thegioifirewall.com/wp-content/uploads/image-4267.png 826w, https://thegioifirewall.com/wp-content/uploads/image-4267-300x88.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4267-768x224.png 768w" sizes="auto, (max-width: 826px) 100vw, 826px" /></figure></div>



<p class="wp-block-paragraph"> Thử cập nhật các Firewall Policy sẽ nhận được thông báo không có quyền để cấu hình. </p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="280" src="https://thegioifirewall.com/wp-content/uploads/image-4268.png" alt="" class="wp-image-15689" srcset="https://thegioifirewall.com/wp-content/uploads/image-4268.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4268-300x135.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">User Steven chỉ có quyền chỉnh sửa trong phần <strong>Device &gt; Network.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="705" height="232" src="https://thegioifirewall.com/wp-content/uploads/image-4269.png" alt="" class="wp-image-15690" srcset="https://thegioifirewall.com/wp-content/uploads/image-4269.png 705w, https://thegioifirewall.com/wp-content/uploads/image-4269-300x99.png 300w" sizes="auto, (max-width: 705px) 100vw, 705px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 3: Cấu hình cho Mobile Admin.</strong></p>



<p class="wp-block-paragraph">Trên trang quản trị của <strong>Checkpoint Firewall &gt; Device &gt; System &gt; Administrators &gt; New</strong>.</p>



<p class="wp-block-paragraph">Tạo user admin <strong>Mark </strong>với admin role là <strong>Mobile Admin.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="680" height="264" src="https://thegioifirewall.com/wp-content/uploads/image-4270.png" alt="" class="wp-image-15691" srcset="https://thegioifirewall.com/wp-content/uploads/image-4270.png 680w, https://thegioifirewall.com/wp-content/uploads/image-4270-300x116.png 300w" sizes="auto, (max-width: 680px) 100vw, 680px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo click chọn <strong>Mobile Pairing Code</strong>.</p>



<p class="wp-block-paragraph"><strong>Select administrator: </strong>chọn user <strong>admin Mark &gt; click chọn Generate.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="689" height="431" src="https://thegioifirewall.com/wp-content/uploads/image-4271.png" alt="" class="wp-image-15692" srcset="https://thegioifirewall.com/wp-content/uploads/image-4271.png 689w, https://thegioifirewall.com/wp-content/uploads/image-4271-300x188.png 300w" sizes="auto, (max-width: 689px) 100vw, 689px" /></figure></div>



<p class="wp-block-paragraph">Trên thiết bị Mobile của <strong>admin Mark</strong>, download ứng dụng <strong>CheckPoint WatchTower</strong>.</p>



<p class="wp-block-paragraph">Tiếp theo điền tên và cung cấp email để đăng kí tài khoản.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="498" height="372" src="https://thegioifirewall.com/wp-content/uploads/image-4272.png" alt="" class="wp-image-15693" srcset="https://thegioifirewall.com/wp-content/uploads/image-4272.png 498w, https://thegioifirewall.com/wp-content/uploads/image-4272-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4272-400x300.png 400w" sizes="auto, (max-width: 498px) 100vw, 498px" /></figure></div>



<p class="wp-block-paragraph">Bạn mở email đã đùng để đăng kí trước đó, sẽ nhận được 1 email của Checkpoint có chứa dòng code token để xác thực.</p>



<p class="wp-block-paragraph">Copy và paste code trong email vào mục Code như hình dưới.</p>



<p class="wp-block-paragraph">Click <strong>Continue </strong>và tạo Password đăng nhập cho WatchTower. Cuối cùng click <strong>Activate.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="542" height="398" src="https://thegioifirewall.com/wp-content/uploads/image-4273.png" alt="" class="wp-image-15694" srcset="https://thegioifirewall.com/wp-content/uploads/image-4273.png 542w, https://thegioifirewall.com/wp-content/uploads/image-4273-300x220.png 300w" sizes="auto, (max-width: 542px) 100vw, 542px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Add Gateway</strong>. Bạn sẽ Scan mã <strong>QR</strong> ở phần <strong>Mobile Pairing Code</strong> đã tạo. </p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="496" height="516" src="https://thegioifirewall.com/wp-content/uploads/image-4274.png" alt="" class="wp-image-15695" srcset="https://thegioifirewall.com/wp-content/uploads/image-4274.png 496w, https://thegioifirewall.com/wp-content/uploads/image-4274-288x300.png 288w" sizes="auto, (max-width: 496px) 100vw, 496px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo nhập<strong> Admin Name là Mark và password</strong> đã tạo ở trên. Kết nối thành công thì giao diện <strong>CheckPoint WatchTower</strong> sẽ hiển thị như hình dưới.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="467" height="522" src="https://thegioifirewall.com/wp-content/uploads/image-4275.png" alt="" class="wp-image-15696" srcset="https://thegioifirewall.com/wp-content/uploads/image-4275.png 467w, https://thegioifirewall.com/wp-content/uploads/image-4275-268x300.png 268w" sizes="auto, (max-width: 467px) 100vw, 467px" /></figure></div>



<p class="wp-block-paragraph">Click chọn <strong>Settings </strong>bạn có thể kiểm tra các thông số cơ bản đã cấu hình của thiết bị Checkpoint.</p>



<p class="wp-block-paragraph">Click chọn icon dấu 3 chấm. Sẽ có các tùy chọn như <strong>Reboot</strong> và <strong>Additional Gateway Settings.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="484" height="521" src="https://thegioifirewall.com/wp-content/uploads/image-4276.png" alt="" class="wp-image-15697" srcset="https://thegioifirewall.com/wp-content/uploads/image-4276.png 484w, https://thegioifirewall.com/wp-content/uploads/image-4276-279x300.png 279w" sizes="auto, (max-width: 484px) 100vw, 484px" /></figure></div>



<p class="wp-block-paragraph">Tiếp tục click chọn <strong>Additional Gateway Settings</strong>. Bạn có thể đăng nhập quyền <strong>super admin</strong> để chỉnh sửa cấu hình thiết bị trên giao diện Mobile.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="464" height="512" src="https://thegioifirewall.com/wp-content/uploads/image-4277.png" alt="" class="wp-image-15698" srcset="https://thegioifirewall.com/wp-content/uploads/image-4277.png 464w, https://thegioifirewall.com/wp-content/uploads/image-4277-272x300.png 272w" sizes="auto, (max-width: 464px) 100vw, 464px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-tao-va-check-cac-quyen-administrator-roles-tren-checkpoint-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình VPN Remote Access cho Users sử dụng Checkpoint VPN Clients.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 08 May 2022 11:40:12 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[Checkpoint VPN Clients]]></category>
		<category><![CDATA[VPN Remote Access]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15363</guid>

					<description><![CDATA[1.Overview Với tính năng VPN Remote Access bạn có thể thiết lập các kết nối được mã hóa an toàn giữa các thiết bị như thiết bị di động, máy tính để bàn tại nhà và máy tính xách tay cũng như tổ chức thông qua Internet. Để truy cập từ xa, bạn phải xác [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong></p>



<p class="wp-block-paragraph">Với tính năng VPN Remote Access bạn có thể thiết lập các kết nối được mã hóa an toàn giữa các thiết bị như thiết bị di động, máy tính để bàn tại nhà và máy tính xách tay cũng như tổ chức thông qua Internet.</p>



<p class="wp-block-paragraph">Để truy cập từ xa, bạn phải xác định người dùng trong hệ thống bằng thông tin đăng nhập và đặt quyền cho người dùng được chỉ định. Thiết bị phải có thể truy cập được từ Internet.</p>



<p class="wp-block-paragraph">Các phương thức Checkpoint hỗ trợ để VPN:</p>



<p class="wp-block-paragraph"><strong>Check Point&nbsp;VPN clients</strong>: Để kết nối máy tính xách tay và máy tính để bàn</p>



<p class="wp-block-paragraph"><strong>Mobile client</strong>: Để kết nối điện thoại thông minh và máy tính bảng</p>



<p class="wp-block-paragraph"><strong>SSLVPN: </strong>Để kết nối thông qua SSL VPN</p>



<p class="wp-block-paragraph"><strong>Windows VPN Client</strong>: Để kết nối thông qua VPN Client (L2TP)</p>



<p class="wp-block-paragraph"><strong>2. Network Diagram</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="872" height="346" src="https://thegioifirewall.com/wp-content/uploads/image-4034.png" alt="" class="wp-image-15364" srcset="https://thegioifirewall.com/wp-content/uploads/image-4034.png 872w, https://thegioifirewall.com/wp-content/uploads/image-4034-300x119.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4034-768x305.png 768w" sizes="auto, (max-width: 872px) 100vw, 872px" /></figure></div>



<p class="wp-block-paragraph">Bài viết hôm nay sẽ hướng dẫn các bạn cấu hình VPN Remote Access cho người dùng truy cập từ xa vào mạng nội bộ sử dụng Checkpoint VPN Client cài đặt trên máy tính người dùng với Checkpoint Firewall.</p>



<p class="wp-block-paragraph"><strong>3. Hướng dẫn cấu hình</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Tạo tên DDNS cho IP PPPOE trên Modem</strong>.</p>



<p class="wp-block-paragraph"><strong>Note: </strong>Như mô hình ở trên do Modem quay PPPOE, Checkpoint Firewall chỉ là lớp mạng local do Modem cấp nên ta không thể cấu hình VPN với IP WAN của Checkpoint Firewall.</p>



<p class="wp-block-paragraph">Nên bạn cần tạo 1 tên miền DDNS cho IP PPPOE <strong>(IP: 115.78.xx.xx)</strong> này <strong>(Ex: vpncheckpoint.ddns.net)</strong>, kể cả là IP động hay IP tĩnh để kết nối VPN thành công.</p>



<p class="wp-block-paragraph"><strong>Note:</strong> Nếu là mô hình Checkpoint đứng ra quay số PPPOE thì không cần đăng kí tên miền này. Bạn có thể cấu hình VPN Remote Access từ <strong>Bước 3.</strong></p>



<p class="wp-block-paragraph">Bạn có thể tạo 1 tài khoản tạo tên miền DDNS miễn phí như No-IP để sử dụng.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="796" height="193" src="https://thegioifirewall.com/wp-content/uploads/image-4035.png" alt="" class="wp-image-15365" srcset="https://thegioifirewall.com/wp-content/uploads/image-4035.png 796w, https://thegioifirewall.com/wp-content/uploads/image-4035-300x73.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4035-768x186.png 768w" sizes="auto, (max-width: 796px) 100vw, 796px" /></figure></div>



<p class="wp-block-paragraph">Trong khi tạo tên miền DDNS bạn cần tạo <strong>username </strong>để add tên miền này lên Checkpoint Firewall.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="799" height="141" src="https://thegioifirewall.com/wp-content/uploads/image-4036.png" alt="" class="wp-image-15366" srcset="https://thegioifirewall.com/wp-content/uploads/image-4036.png 799w, https://thegioifirewall.com/wp-content/uploads/image-4036-300x53.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4036-768x136.png 768w" sizes="auto, (max-width: 799px) 100vw, 799px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Enable DDNS trên Checkpoint Firewall</strong>.</p>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; Device &gt; System &gt; DDNS &amp; Device Access.</strong></p>



<p class="wp-block-paragraph">Click chọn <strong>&#8220;Connect to the applicance by name from the Internet (DDNS)&#8221;</strong>.</p>



<p class="wp-block-paragraph">Cung cấp các thông tin như hình dưới:</p>



<p class="wp-block-paragraph"><strong>Provider</strong>: chọn no-ip</p>



<p class="wp-block-paragraph"><strong>User name:</strong> Nhập tên user đã tạo trên tài khoản No-ip</p>



<p class="wp-block-paragraph">P<strong>assword: </strong>Nhập password đăng kí tài khoản No-IP</p>



<p class="wp-block-paragraph"><strong>Host name:</strong> Nhập tên miền đã cấu hình với IP PPPOE ở bước 1.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="623" height="351" src="https://thegioifirewall.com/wp-content/uploads/image-4038.png" alt="" class="wp-image-15368" srcset="https://thegioifirewall.com/wp-content/uploads/image-4038.png 623w, https://thegioifirewall.com/wp-content/uploads/image-4038-300x169.png 300w" sizes="auto, (max-width: 623px) 100vw, 623px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 3: Tạo User VPN Remote Access</strong>.</p>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; VPN &gt; Remote Access &gt; Remote Access Users</strong> <strong>&gt; Add.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="259" src="https://thegioifirewall.com/wp-content/uploads/image-4039.png" alt="" class="wp-image-15369" srcset="https://thegioifirewall.com/wp-content/uploads/image-4039.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4039-300x125.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Điền các thông số cho user như hình dưới. </p>



<p class="wp-block-paragraph">Click chọn &#8220;<strong>Remote Access Permissions&#8221;.</strong> Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="490" height="446" src="https://thegioifirewall.com/wp-content/uploads/image-4040.png" alt="" class="wp-image-15370" srcset="https://thegioifirewall.com/wp-content/uploads/image-4040.png 490w, https://thegioifirewall.com/wp-content/uploads/image-4040-300x273.png 300w" sizes="auto, (max-width: 490px) 100vw, 490px" /></figure></div>



<p class="wp-block-paragraph">Nếu bạn yêu cầu bảo mật cao bạn có thể đổi port của SSL VPN (mặc định: 443), còn không bạn có thể để mặc định. Tiếp tục <strong>Bước 4.</strong></p>



<p class="wp-block-paragraph">Bạn có thể đổi port SSL VPN, di chuyển đến <strong>Device &gt; Advanced &gt; Advanced Settings.</strong> Bạn search &#8220;<strong>SSL VPN</strong>&#8220;.</p>



<p class="wp-block-paragraph">Tìm và click chọn dòng &#8220;<strong>VPN Remote Access &#8211; Remote Access Port</strong>&#8220;.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="695" height="295" src="https://thegioifirewall.com/wp-content/uploads/image-4041.png" alt="" class="wp-image-15371" srcset="https://thegioifirewall.com/wp-content/uploads/image-4041.png 695w, https://thegioifirewall.com/wp-content/uploads/image-4041-300x127.png 300w" sizes="auto, (max-width: 695px) 100vw, 695px" /></figure></div>



<p class="wp-block-paragraph">Bạn đổi port như hình dưới.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="468" height="238" src="https://thegioifirewall.com/wp-content/uploads/image-4042.png" alt="" class="wp-image-15372" srcset="https://thegioifirewall.com/wp-content/uploads/image-4042.png 468w, https://thegioifirewall.com/wp-content/uploads/image-4042-300x153.png 300w" sizes="auto, (max-width: 468px) 100vw, 468px" /></figure></div>



<p class="wp-block-paragraph">Nếu đã đổi port như mô hình ở trên ta cần mở port 4435 trên modem. Để modem có thể forwarding traffic VPN.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="273" src="https://thegioifirewall.com/wp-content/uploads/image-4043.png" alt="" class="wp-image-15373" srcset="https://thegioifirewall.com/wp-content/uploads/image-4043.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4043-300x131.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Check port đã mở thành công hay chưa với các trang web check port open như <strong>yougetsignal.com</strong></p>



<p class="wp-block-paragraph">&#8220;<strong>Port 4435 is open on&#8230;.</strong>&#8221; là đã mở port thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="650" height="232" src="https://thegioifirewall.com/wp-content/uploads/image-4046.png" alt="" class="wp-image-15376" srcset="https://thegioifirewall.com/wp-content/uploads/image-4046.png 650w, https://thegioifirewall.com/wp-content/uploads/image-4046-300x107.png 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 4: Tải và cài đặt Checkpoint VPN Clients.</strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; VPN &gt; Remote Access &gt; Remote Control</strong>. Click <strong>ON Remote Access.</strong></p>



<p class="wp-block-paragraph">Trong phần <strong>Checkpoint VPN Clients</strong>, click <strong>How to connect</strong>&#8230;</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="296" src="https://thegioifirewall.com/wp-content/uploads/image-4047.png" alt="" class="wp-image-15377" srcset="https://thegioifirewall.com/wp-content/uploads/image-4047.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4047-300x142.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Tại đây sẽ hướng dẫn bạn cách cấu hình Checkpoint VPN Client. Click <strong>&#8220;here&#8221; </strong>để đi trang tải Checkpoint VPN Client.</p>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-4049.png" alt="" class="wp-image-15379" width="624" height="394" srcset="https://thegioifirewall.com/wp-content/uploads/image-4049.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4049-300x189.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Click chọn <strong>&#8220;Remote Access (VPN) Clients product page&#8221;</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="655" height="388" src="https://thegioifirewall.com/wp-content/uploads/image-4050.png" alt="" class="wp-image-15380" srcset="https://thegioifirewall.com/wp-content/uploads/image-4050.png 655w, https://thegioifirewall.com/wp-content/uploads/image-4050-300x178.png 300w" sizes="auto, (max-width: 655px) 100vw, 655px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua mục <strong>&#8220;Downloads&#8221;</strong> và chọn các trang gần cuối để tìm phiên bản Checkpoint VPN Client mới nhất</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="343" src="https://thegioifirewall.com/wp-content/uploads/image-4051.png" alt="" class="wp-image-15381" srcset="https://thegioifirewall.com/wp-content/uploads/image-4051.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4051-300x165.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Click chọn <strong>&#8220;E86.30 Checkpoint&#8230;..for Windows&#8221;</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="810" height="311" src="https://thegioifirewall.com/wp-content/uploads/image-4052.png" alt="" class="wp-image-15382" srcset="https://thegioifirewall.com/wp-content/uploads/image-4052.png 810w, https://thegioifirewall.com/wp-content/uploads/image-4052-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4052-768x295.png 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure></div>



<p class="wp-block-paragraph">Click chọn <strong>Download.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="210" src="https://thegioifirewall.com/wp-content/uploads/image-4053.png" alt="" class="wp-image-15383" srcset="https://thegioifirewall.com/wp-content/uploads/image-4053.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4053-300x101.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Mở phần mềm Checkpoint VPN Client vừa tải xuống để cài đặt xuống máy. Click <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="483" height="370" src="https://thegioifirewall.com/wp-content/uploads/image-4055.png" alt="" class="wp-image-15385" srcset="https://thegioifirewall.com/wp-content/uploads/image-4055.png 483w, https://thegioifirewall.com/wp-content/uploads/image-4055-300x230.png 300w" sizes="auto, (max-width: 483px) 100vw, 483px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>Endpoint Security VPN</strong>. CLick <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="499" height="380" src="https://thegioifirewall.com/wp-content/uploads/image-4056.png" alt="" class="wp-image-15386" srcset="https://thegioifirewall.com/wp-content/uploads/image-4056.png 499w, https://thegioifirewall.com/wp-content/uploads/image-4056-300x228.png 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Install.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="498" height="379" src="https://thegioifirewall.com/wp-content/uploads/image-4057.png" alt="" class="wp-image-15387" srcset="https://thegioifirewall.com/wp-content/uploads/image-4057.png 498w, https://thegioifirewall.com/wp-content/uploads/image-4057-300x228.png 300w" sizes="auto, (max-width: 498px) 100vw, 498px" /></figure></div>



<p class="wp-block-paragraph">Sau khi cài xong, click chọn <strong>Finish</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="499" height="381" src="https://thegioifirewall.com/wp-content/uploads/image-4058.png" alt="" class="wp-image-15388" srcset="https://thegioifirewall.com/wp-content/uploads/image-4058.png 499w, https://thegioifirewall.com/wp-content/uploads/image-4058-300x229.png 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 5: Cấu hình Site cho Checkpoint VPN Client.</strong></p>



<p class="wp-block-paragraph">Click chọn icon ổ khóa màu vàng trong taskbar, bảng thông báo hiện lên click <strong>Yes.</strong> </p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="245" src="https://thegioifirewall.com/wp-content/uploads/image-4059.png" alt="" class="wp-image-15389" srcset="https://thegioifirewall.com/wp-content/uploads/image-4059.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4059-300x118.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="481" height="386" src="https://thegioifirewall.com/wp-content/uploads/image-4060.png" alt="" class="wp-image-15390" srcset="https://thegioifirewall.com/wp-content/uploads/image-4060.png 481w, https://thegioifirewall.com/wp-content/uploads/image-4060-300x241.png 300w" sizes="auto, (max-width: 481px) 100vw, 481px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>Server address or Name:</strong> Điền tên miền DDNS + Port đã cấu hình ở bước 1. Click <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="483" height="390" src="https://thegioifirewall.com/wp-content/uploads/image-4061.png" alt="" class="wp-image-15391" srcset="https://thegioifirewall.com/wp-content/uploads/image-4061.png 483w, https://thegioifirewall.com/wp-content/uploads/image-4061-300x242.png 300w" sizes="auto, (max-width: 483px) 100vw, 483px" /></figure></div>



<p class="wp-block-paragraph">Bạn đợi để thiết lập site kết nối.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="482" height="390" src="https://thegioifirewall.com/wp-content/uploads/image-4062.png" alt="" class="wp-image-15392" srcset="https://thegioifirewall.com/wp-content/uploads/image-4062.png 482w, https://thegioifirewall.com/wp-content/uploads/image-4062-300x243.png 300w" sizes="auto, (max-width: 482px) 100vw, 482px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="480" height="389" src="https://thegioifirewall.com/wp-content/uploads/image-4063.png" alt="" class="wp-image-15393" srcset="https://thegioifirewall.com/wp-content/uploads/image-4063.png 480w, https://thegioifirewall.com/wp-content/uploads/image-4063-300x243.png 300w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Chọn kiểu xác thực là <strong>Username and Password.</strong> Click <strong>Next.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="480" height="386" src="https://thegioifirewall.com/wp-content/uploads/image-4064.png" alt="" class="wp-image-15394" srcset="https://thegioifirewall.com/wp-content/uploads/image-4064.png 480w, https://thegioifirewall.com/wp-content/uploads/image-4064-300x241.png 300w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Thiết lập site kết nối thành công. CLick <strong>Finish</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="480" height="388" src="https://thegioifirewall.com/wp-content/uploads/image-4065.png" alt="" class="wp-image-15395" srcset="https://thegioifirewall.com/wp-content/uploads/image-4065.png 480w, https://thegioifirewall.com/wp-content/uploads/image-4065-300x243.png 300w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Yes.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="219" height="119" src="https://thegioifirewall.com/wp-content/uploads/image-4066.png" alt="" class="wp-image-15396"/></figure></div>



<p class="wp-block-paragraph">Nhập Username và Password đã tạo ở bước 3. Click chọn <strong>Connect.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="555" height="448" src="https://thegioifirewall.com/wp-content/uploads/image-4067.png" alt="" class="wp-image-15397" srcset="https://thegioifirewall.com/wp-content/uploads/image-4067.png 555w, https://thegioifirewall.com/wp-content/uploads/image-4067-300x242.png 300w" sizes="auto, (max-width: 555px) 100vw, 555px" /></figure></div>



<p class="wp-block-paragraph">Bạn đợi để thiết lập kết nối.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="539" height="213" src="https://thegioifirewall.com/wp-content/uploads/image-4069.png" alt="" class="wp-image-15399" srcset="https://thegioifirewall.com/wp-content/uploads/image-4069.png 539w, https://thegioifirewall.com/wp-content/uploads/image-4069-300x119.png 300w" sizes="auto, (max-width: 539px) 100vw, 539px" /></figure></div>



<p class="wp-block-paragraph">VPN Remote Access đã kết nối thành công với status là &#8220;<strong>Connected&#8221;</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="675" height="452" src="https://thegioifirewall.com/wp-content/uploads/image-4070.png" alt="" class="wp-image-15400" srcset="https://thegioifirewall.com/wp-content/uploads/image-4070.png 675w, https://thegioifirewall.com/wp-content/uploads/image-4070-300x201.png 300w" sizes="auto, (max-width: 675px) 100vw, 675px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 6: Kiểm tra.</strong></p>



<p class="wp-block-paragraph">Bạn có thể đăng nhập vào Checkpoint Firewall sau khi VPN thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="357" src="https://thegioifirewall.com/wp-content/uploads/image-4072.png" alt="" class="wp-image-15402" srcset="https://thegioifirewall.com/wp-content/uploads/image-4072.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4072-300x172.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Check trên Checkpoint Firewall phần &#8220;<strong>Connected Remote Users&#8221;</strong> đã thấy xuất hiện user <strong>John </strong>kết nối.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="863" height="191" src="https://thegioifirewall.com/wp-content/uploads/image-4073.png" alt="" class="wp-image-15403" srcset="https://thegioifirewall.com/wp-content/uploads/image-4073.png 863w, https://thegioifirewall.com/wp-content/uploads/image-4073-300x66.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4073-768x170.png 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure></div>



<p class="wp-block-paragraph">Kiểm tra trên máy user John đã nhận đúng IP <strong>172.16.10.2.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="562" height="200" src="https://thegioifirewall.com/wp-content/uploads/image-4074.png" alt="" class="wp-image-15404" srcset="https://thegioifirewall.com/wp-content/uploads/image-4074.png 562w, https://thegioifirewall.com/wp-content/uploads/image-4074-300x107.png 300w" sizes="auto, (max-width: 562px) 100vw, 562px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình VPN Site to Site giữa Sophos Firewall XG230 với Checkpoint Firewall 1590.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-sophos-firewall-xg230-voi-checkpoint-firewall-1590/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-sophos-firewall-xg230-voi-checkpoint-firewall-1590/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 08 May 2022 11:15:48 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[cấu hình VPN Site to Site trên checkpoint firewall]]></category>
		<category><![CDATA[VPN Site to Site checkpoint firewall]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15514</guid>

					<description><![CDATA[1.Overview. Với VPN Site to Site, bạn có thể tạo các đường hầm VPN kết nối với các remote site. Site to Site VPN có thể kết nối hai mạng được phân tách bằng Internet thông qua một đường hầm VPN được mã hóa an toàn. Điều này cho phép kết nối an toàn liền [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong>.</p>



<p class="wp-block-paragraph">Với VPN Site to Site, bạn có thể tạo các đường hầm VPN kết nối với các remote site. Site to Site VPN có thể kết nối hai mạng được phân tách bằng Internet thông qua một đường hầm VPN được mã hóa an toàn. Điều này cho phép kết nối an toàn liền mạch giữa hai mạng trong cùng một tổ chức mặc dù chúng cách xa nhau về vật lý.</p>



<p class="wp-block-paragraph"><strong>2. Network Diagram</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="667" height="396" src="https://thegioifirewall.com/wp-content/uploads/image-4141.png" alt="" class="wp-image-15515" srcset="https://thegioifirewall.com/wp-content/uploads/image-4141.png 667w, https://thegioifirewall.com/wp-content/uploads/image-4141-300x178.png 300w" sizes="auto, (max-width: 667px) 100vw, 667px" /></figure></div>



<p class="wp-block-paragraph">Bài viết hôm nay sẽ hướng dẫn các bạn cấu hình VPN site to site trên thiết bị Checkpoint Firewall kết nối với site Sophos XG230.</p>



<p class="wp-block-paragraph"><strong>3. Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Cấu hình VPN site to site trên Checkpoint</strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; VPN &gt; Site to site &gt; Blade Control. Click On Site to Site VPN</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="489" height="274" src="https://thegioifirewall.com/wp-content/uploads/image-4142.png" alt="" class="wp-image-15516" srcset="https://thegioifirewall.com/wp-content/uploads/image-4142.png 489w, https://thegioifirewall.com/wp-content/uploads/image-4142-300x168.png 300w" sizes="auto, (max-width: 489px) 100vw, 489px" /></figure></div>



<p class="wp-block-paragraph">Di chuyển xuống phần<strong> VPN Sites &gt; New.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="492" height="314" src="https://thegioifirewall.com/wp-content/uploads/image-4143.png" alt="" class="wp-image-15517" srcset="https://thegioifirewall.com/wp-content/uploads/image-4143.png 492w, https://thegioifirewall.com/wp-content/uploads/image-4143-300x191.png 300w" sizes="auto, (max-width: 492px) 100vw, 492px" /></figure></div>



<p class="wp-block-paragraph">Trong phần<strong> New VPN Site</strong>. điền các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Site name:</strong> Điền tên kết nối VPN bạn muốn.</p>



<p class="wp-block-paragraph"><strong>Connection Type:</strong> chọn hostname or IP address.</p>



<p class="wp-block-paragraph">I<strong>P address: </strong>Điền IP WAN của SOPHOS XG site</p>



<p class="wp-block-paragraph">Au<strong>thentication: </strong>chọn <strong>Pre-Shared secret</strong>.</p>



<p class="wp-block-paragraph"><strong>Passwword + Confirm: </strong>Điền và nhập lại pre-share key (Bạn sẽ tự tạo key này, key sẽ được sử dụng lại để cấu hình tạo kết nối bên Sophos site)</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="483" height="283" src="https://thegioifirewall.com/wp-content/uploads/image-4144.png" alt="" class="wp-image-15518" srcset="https://thegioifirewall.com/wp-content/uploads/image-4144.png 483w, https://thegioifirewall.com/wp-content/uploads/image-4144-300x176.png 300w" sizes="auto, (max-width: 483px) 100vw, 483px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>Remote Site Encryption Domain</strong> chọn <strong>New</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="487" height="181" src="https://thegioifirewall.com/wp-content/uploads/image-4145.png" alt="" class="wp-image-15519" srcset="https://thegioifirewall.com/wp-content/uploads/image-4145.png 487w, https://thegioifirewall.com/wp-content/uploads/image-4145-300x111.png 300w" sizes="auto, (max-width: 487px) 100vw, 487px" /></figure></div>



<p class="wp-block-paragraph">Chọn<strong> Type l</strong>à <strong>Network</strong></p>



<p class="wp-block-paragraph"><strong>Network address: </strong>Điền remote network của bên Site Sophos</p>



<p class="wp-block-paragraph"><strong>Object name: </strong>Đặt tên cho remote network. Click <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="384" height="341" src="https://thegioifirewall.com/wp-content/uploads/image-4146.png" alt="" class="wp-image-15520" srcset="https://thegioifirewall.com/wp-content/uploads/image-4146.png 384w, https://thegioifirewall.com/wp-content/uploads/image-4146-300x266.png 300w" sizes="auto, (max-width: 384px) 100vw, 384px" /></figure></div>



<p class="wp-block-paragraph">Bạn có thể add nhiều LAN Network bằng cách tiếp tục click chọn <strong>New </strong>để tạo.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="488" height="187" src="https://thegioifirewall.com/wp-content/uploads/image-4147.png" alt="" class="wp-image-15521" srcset="https://thegioifirewall.com/wp-content/uploads/image-4147.png 488w, https://thegioifirewall.com/wp-content/uploads/image-4147-300x115.png 300w" sizes="auto, (max-width: 488px) 100vw, 488px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua <strong>Encryption</strong> tab. Bạn điền các thông số <strong>IKE (Phase 1) và IPsec (Phase 2)</strong> đã thống nhất giữa 2 site như hình dưới.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="489" height="427" src="https://thegioifirewall.com/wp-content/uploads/image-4148.png" alt="" class="wp-image-15522" srcset="https://thegioifirewall.com/wp-content/uploads/image-4148.png 489w, https://thegioifirewall.com/wp-content/uploads/image-4148-300x262.png 300w" sizes="auto, (max-width: 489px) 100vw, 489px" /></figure></div>



<p class="wp-block-paragraph"> Chuyển qua <strong>Advanced</strong> tab. Chọn <strong>Encryption Method </strong>là <strong>IKEv2</strong>. Cuối cùng click chọn <strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="489" height="423" src="https://thegioifirewall.com/wp-content/uploads/image-4149.png" alt="" class="wp-image-15523" srcset="https://thegioifirewall.com/wp-content/uploads/image-4149.png 489w, https://thegioifirewall.com/wp-content/uploads/image-4149-300x260.png 300w" sizes="auto, (max-width: 489px) 100vw, 489px" /></figure></div>



<p class="wp-block-paragraph">Đã cấu hình xong VPN bên Site Checkpoint.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="586" height="247" src="https://thegioifirewall.com/wp-content/uploads/image-4151.png" alt="" class="wp-image-15525" srcset="https://thegioifirewall.com/wp-content/uploads/image-4151.png 586w, https://thegioifirewall.com/wp-content/uploads/image-4151-300x126.png 300w" sizes="auto, (max-width: 586px) 100vw, 586px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Cấu hình VPN site to site trên Sophos XG.</strong></p>



<p class="wp-block-paragraph"><strong>2.1. Cấu hình IPsec Profiles. </strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị <strong>Sophos XG &gt; Configure &gt; Site to Site VPN &gt; IPsec Profiles</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="479" height="402" src="https://thegioifirewall.com/wp-content/uploads/image-4152.png" alt="" class="wp-image-15526" srcset="https://thegioifirewall.com/wp-content/uploads/image-4152.png 479w, https://thegioifirewall.com/wp-content/uploads/image-4152-300x252.png 300w" sizes="auto, (max-width: 479px) 100vw, 479px" /></figure></div>



<p class="wp-block-paragraph">Để tạo <strong>IPsec Profile click Add.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="149" src="https://thegioifirewall.com/wp-content/uploads/image-4153.png" alt="" class="wp-image-15527" srcset="https://thegioifirewall.com/wp-content/uploads/image-4153.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4153-300x72.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>IPsec Profile</strong>, điền các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Name: </strong>Điền tên cho profile</p>



<p class="wp-block-paragraph"><strong>Key Exchange:</strong> chọn <strong>IKEv2</strong></p>



<p class="wp-block-paragraph"><strong>Authentication Mode:</strong> chọn <strong>Main Mode</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="715" height="242" src="https://thegioifirewall.com/wp-content/uploads/image-4154.png" alt="" class="wp-image-15528" srcset="https://thegioifirewall.com/wp-content/uploads/image-4154.png 715w, https://thegioifirewall.com/wp-content/uploads/image-4154-300x102.png 300w" sizes="auto, (max-width: 715px) 100vw, 715px" /></figure></div>



<p class="wp-block-paragraph">Điền các thông số <strong>Phase 1 và 2 </strong>như đã thống nhất giữa 2 site. Click <strong>Save.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="700" height="226" src="https://thegioifirewall.com/wp-content/uploads/image-4155.png" alt="" class="wp-image-15529" srcset="https://thegioifirewall.com/wp-content/uploads/image-4155.png 700w, https://thegioifirewall.com/wp-content/uploads/image-4155-300x97.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="698" height="318" src="https://thegioifirewall.com/wp-content/uploads/image-4156.png" alt="" class="wp-image-15530" srcset="https://thegioifirewall.com/wp-content/uploads/image-4156.png 698w, https://thegioifirewall.com/wp-content/uploads/image-4156-300x137.png 300w" sizes="auto, (max-width: 698px) 100vw, 698px" /></figure></div>



<p class="wp-block-paragraph"><strong>2.2. Cấu hình tạo Local Network và Remote Network.</strong></p>



<p class="wp-block-paragraph">Tiếp theo tạo các <strong>Local Network </strong>bên Sophos Site <strong>(LAN_SOPHOS) </strong>và <strong>Remote Network (LAN_CHECKPOINT)</strong> bên Checkpoint Site.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="696" height="277" src="https://thegioifirewall.com/wp-content/uploads/image-4157.png" alt="" class="wp-image-15531" srcset="https://thegioifirewall.com/wp-content/uploads/image-4157.png 696w, https://thegioifirewall.com/wp-content/uploads/image-4157-300x119.png 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="696" height="276" src="https://thegioifirewall.com/wp-content/uploads/image-4158.png" alt="" class="wp-image-15532" srcset="https://thegioifirewall.com/wp-content/uploads/image-4158.png 696w, https://thegioifirewall.com/wp-content/uploads/image-4158-300x119.png 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></figure></div>



<p class="wp-block-paragraph"><strong>2.3 Cấu hình kêt nối IPsec VPN site to site</strong>.</p>



<p class="wp-block-paragraph">Trên giao diện quản trị <strong>Sophos XG &gt; Configure &gt; Site to Site VPN &gt; IPsec &gt; Add.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="702" height="206" src="https://thegioifirewall.com/wp-content/uploads/image-4159.png" alt="" class="wp-image-15533" srcset="https://thegioifirewall.com/wp-content/uploads/image-4159.png 702w, https://thegioifirewall.com/wp-content/uploads/image-4159-300x88.png 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>Genaral Setting,</strong> điền các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Name: </strong>Điền tên cho kết nối VPN bạn muốn</p>



<p class="wp-block-paragraph">C<strong>onnection type: </strong>chọn Site-to-site</p>



<p class="wp-block-paragraph">G<strong>ateway type: Respond only.</strong></p>



<p class="wp-block-paragraph">Click chọn<strong> Active on save và Create firewall rule.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="699" height="227" src="https://thegioifirewall.com/wp-content/uploads/image-4160.png" alt="" class="wp-image-15534" srcset="https://thegioifirewall.com/wp-content/uploads/image-4160.png 699w, https://thegioifirewall.com/wp-content/uploads/image-4160-300x97.png 300w" sizes="auto, (max-width: 699px) 100vw, 699px" /></figure></div>



<p class="wp-block-paragraph">Kéo xuống phần <strong>Encryption:</strong></p>



<p class="wp-block-paragraph"><strong>Profile: </strong>chọn IPsec Profile đã tạo ở <strong>bước 2.1</strong></p>



<p class="wp-block-paragraph"><strong>Authentication type: </strong>chọn <strong>Preshared key.</strong></p>



<p class="wp-block-paragraph">Nhập và xác nhận preshared key như đã cấu hình bên Checkpoint site.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="696" height="215" src="https://thegioifirewall.com/wp-content/uploads/image-4161.png" alt="" class="wp-image-15535" srcset="https://thegioifirewall.com/wp-content/uploads/image-4161.png 696w, https://thegioifirewall.com/wp-content/uploads/image-4161-300x93.png 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></figure></div>



<p class="wp-block-paragraph">Kéo xuống phần <strong>Gateway settings:</strong></p>



<p class="wp-block-paragraph"><strong>Listenning interface: c</strong>họn IP port WAN của Sophos site</p>



<p class="wp-block-paragraph"><strong>Gateway address: </strong>Điền<strong> IP WAN </strong>bên Checkpoint site</p>



<p class="wp-block-paragraph"><strong>Local Subnet: </strong>Chọn <strong>LAN_SOPHOS</strong> đã tạo ở bước 2.2</p>



<p class="wp-block-paragraph">R<strong>emote Subnet: </strong>Chọn <strong>LAN_CHECKPOINT</strong> đã tạo ở bước 2.2 </p>



<p class="wp-block-paragraph">Click <strong>Save.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="481" height="370" src="https://thegioifirewall.com/wp-content/uploads/image-4162.png" alt="" class="wp-image-15536" srcset="https://thegioifirewall.com/wp-content/uploads/image-4162.png 481w, https://thegioifirewall.com/wp-content/uploads/image-4162-300x231.png 300w" sizes="auto, (max-width: 481px) 100vw, 481px" /></figure></div>



<p class="wp-block-paragraph"><strong>2.4 Active kết nối VPN site to site</strong></p>



<p class="wp-block-paragraph">Dưới mục <strong>Status</strong> phần <strong>Active</strong> click chọn icon chấm đỏ và click <strong>OK</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="696" height="157" src="https://thegioifirewall.com/wp-content/uploads/image-4163.png" alt="" class="wp-image-15537" srcset="https://thegioifirewall.com/wp-content/uploads/image-4163.png 696w, https://thegioifirewall.com/wp-content/uploads/image-4163-300x68.png 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></figure></div>



<p class="wp-block-paragraph">Đã kết nối VPN Site to Site thành công khi <strong>Status </strong>phần<strong> Active và Connection </strong>đều hiện chấm màu xanh.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="693" height="222" src="https://thegioifirewall.com/wp-content/uploads/image-4164.png" alt="" class="wp-image-15538" srcset="https://thegioifirewall.com/wp-content/uploads/image-4164.png 693w, https://thegioifirewall.com/wp-content/uploads/image-4164-300x96.png 300w" sizes="auto, (max-width: 693px) 100vw, 693px" /></figure></div>



<p class="wp-block-paragraph">Kiểm tra bên Checkpoint Site. Đi đến phần <strong>VPN Tunnels </strong>kiểm tra<strong> Status là Active</strong> là kết nối VPN thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="698" height="218" src="https://thegioifirewall.com/wp-content/uploads/image-4165.png" alt="" class="wp-image-15539" srcset="https://thegioifirewall.com/wp-content/uploads/image-4165.png 698w, https://thegioifirewall.com/wp-content/uploads/image-4165-300x94.png 300w" sizes="auto, (max-width: 698px) 100vw, 698px" /></figure></div>



<p class="wp-block-paragraph">Để kiểm tra kết nối giữa 2 site. Bạn sử dụng 1 máy bên Checkpoint Site ping đến 1 máy bên Sophos Site.</p>



<p class="wp-block-paragraph">Kết quả ping thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="594" height="235" src="https://thegioifirewall.com/wp-content/uploads/image-4166.png" alt="" class="wp-image-15540" srcset="https://thegioifirewall.com/wp-content/uploads/image-4166.png 594w, https://thegioifirewall.com/wp-content/uploads/image-4166-300x119.png 300w" sizes="auto, (max-width: 594px) 100vw, 594px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="595" height="311" src="https://thegioifirewall.com/wp-content/uploads/image-4167.png" alt="" class="wp-image-15541" srcset="https://thegioifirewall.com/wp-content/uploads/image-4167.png 595w, https://thegioifirewall.com/wp-content/uploads/image-4167-300x157.png 300w" sizes="auto, (max-width: 595px) 100vw, 595px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-sophos-firewall-xg230-voi-checkpoint-firewall-1590/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình VPN Remote Access cho users sử dụng Mobile Client.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-mobile-client/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-mobile-client/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Fri, 29 Apr 2022 01:47:16 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[Mobile Client]]></category>
		<category><![CDATA[VPN Remote Access]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=15415</guid>

					<description><![CDATA[1.Overview Với tính năng VPN Remote Access bạn có thể thiết lập các kết nối được mã hóa an toàn giữa các thiết bị như thiết bị di động, máy tính để bàn tại nhà và máy tính xách tay cũng như tổ chức thông qua Internet. Để truy cập từ xa, bạn phải xác [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong></p>



<p class="wp-block-paragraph">Với tính năng VPN Remote Access bạn có thể thiết lập các kết nối được mã hóa an toàn giữa các thiết bị như thiết bị di động, máy tính để bàn tại nhà và máy tính xách tay cũng như tổ chức thông qua Internet.</p>



<p class="wp-block-paragraph">Để truy cập từ xa, bạn phải xác định người dùng trong hệ thống bằng thông tin đăng nhập và đặt quyền cho người dùng được chỉ định. Thiết bị phải có thể truy cập được từ Internet.</p>



<p class="wp-block-paragraph">Các phương thức Checkpoint hỗ trợ để VPN:</p>



<p class="wp-block-paragraph"><strong>Check Point&nbsp;VPN clients</strong>: Để kết nối máy tính xách tay và máy tính để bàn</p>



<p class="wp-block-paragraph"><strong>Mobile client</strong>: Để kết nối điện thoại thông minh và máy tính bảng</p>



<p class="wp-block-paragraph"><strong>SSLVPN:&nbsp;</strong>Để kết nối thông qua SSL VPN</p>



<p class="wp-block-paragraph"><strong>Windows VPN Client</strong>: Để kết nối thông qua VPN Client (L2TP)</p>



<p class="wp-block-paragraph"><strong>2. Network Diagram</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="873" height="346" src="https://thegioifirewall.com/wp-content/uploads/image-4079.png" alt="" class="wp-image-15416" srcset="https://thegioifirewall.com/wp-content/uploads/image-4079.png 873w, https://thegioifirewall.com/wp-content/uploads/image-4079-300x119.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4079-768x304.png 768w" sizes="auto, (max-width: 873px) 100vw, 873px" /></figure></div>



<p class="wp-block-paragraph">Bài viết hôm nay sẽ hướng dẫn các bạn cấu hình VPN Remote Access cho người dùng truy cập từ xa vào mạng nội bộ sử dụng Mobile Client cài đặt trên điện thoại hoặc máy tính bảng của người dùng với Checkpoint Firewall.</p>



<p class="wp-block-paragraph">Với cấu hình VPN Remote Access bạn có thể tham khảo trước bài biết: <a href="https://www.thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/">https://www.thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-checkpoint-vpn-clients/</a></p>



<p class="wp-block-paragraph"><strong>3. Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Tạo User VPN Remote Access</strong>.</p>



<p class="wp-block-paragraph">Trên giao diện quản trị của&nbsp;<strong>Checkpoint Firewall &gt; VPN &gt; Remote Access &gt; Remote Access Users</strong>&nbsp;<strong>&gt; Add.</strong></p>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-4039.png" alt=""/></figure></div>



<p class="wp-block-paragraph">Điền các thông số cho user như hình dưới.</p>



<p class="wp-block-paragraph">Click chọn “<strong>Remote Access Permissions”.</strong>&nbsp;Click&nbsp;<strong>Apply.</strong></p>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-4040.png" alt=""/></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Tải và cài đặt Mobile Clients.</strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị của&nbsp;<strong>Checkpoint Firewall &gt; VPN &gt; Remote Access &gt; Remote Control</strong>. Click&nbsp;<strong>ON Remote Access.</strong></p>



<p class="wp-block-paragraph">Trong phần&nbsp;<strong>Mobile Clients</strong>, click&nbsp;<strong>How to connect</strong>…</p>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-4047.png" alt=""/></figure></div>



<p class="wp-block-paragraph">Tại đây sẽ hướng dẫn bạn cách cấu hình <strong>Mobile Client.</strong> Đầu tiên trên điện thoại hoặc máy tính bảng của user bạn cần tải phần mềm Checkpoint Mobile tương ứng.</p>



<p class="wp-block-paragraph">E<strong>x: </strong>Với điện thoại Android bạn vào CH Play tải ứng dụng <strong>&#8220;Checkpoint Capsule VPN&#8221;.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="458" src="https://thegioifirewall.com/wp-content/uploads/image-4080.png" alt="" class="wp-image-15417" srcset="https://thegioifirewall.com/wp-content/uploads/image-4080.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4080-300x220.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Sau khi cài đặt xong click <strong>&#8220;Mở&#8221;.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="613" height="260" src="https://thegioifirewall.com/wp-content/uploads/image-4081.png" alt="" class="wp-image-15418" srcset="https://thegioifirewall.com/wp-content/uploads/image-4081.png 613w, https://thegioifirewall.com/wp-content/uploads/image-4081-300x127.png 300w" sizes="auto, (max-width: 613px) 100vw, 613px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Continue.</strong></p>



<p class="wp-block-paragraph"><strong>Name: </strong>Điền tên cho kết nối VPN</p>



<p class="wp-block-paragraph"><strong>Server:</strong> Điền tên miền DDNS đã cấu hình. Click <strong>Create</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="553" height="360" src="https://thegioifirewall.com/wp-content/uploads/image-4082.png" alt="" class="wp-image-15419" srcset="https://thegioifirewall.com/wp-content/uploads/image-4082.png 553w, https://thegioifirewall.com/wp-content/uploads/image-4082-300x195.png 300w" sizes="auto, (max-width: 553px) 100vw, 553px" /></figure></div>



<p class="wp-block-paragraph">Click chọn &#8220;<strong>Trust</strong>&#8221; và chọn xác thực kiểu là <strong>Username and Password.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="483" height="531" src="https://thegioifirewall.com/wp-content/uploads/image-4083.png" alt="" class="wp-image-15420" srcset="https://thegioifirewall.com/wp-content/uploads/image-4083.png 483w, https://thegioifirewall.com/wp-content/uploads/image-4083-273x300.png 273w" sizes="auto, (max-width: 483px) 100vw, 483px" /></figure></div>



<p class="wp-block-paragraph">Nhập Usernamr và Password đã cấu hình ở bước 1. Click <strong>Connect.</strong> Kết quả đã kết nối thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="494" height="467" src="https://thegioifirewall.com/wp-content/uploads/image-4084.png" alt="" class="wp-image-15421" srcset="https://thegioifirewall.com/wp-content/uploads/image-4084.png 494w, https://thegioifirewall.com/wp-content/uploads/image-4084-300x284.png 300w" sizes="auto, (max-width: 494px) 100vw, 494px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua <strong>Detail tab.</strong> Các thông tin kết nối sẽ hiển thị tại đây.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="265" height="490" src="https://thegioifirewall.com/wp-content/uploads/image-4085.png" alt="" class="wp-image-15422" srcset="https://thegioifirewall.com/wp-content/uploads/image-4085.png 265w, https://thegioifirewall.com/wp-content/uploads/image-4085-162x300.png 162w" sizes="auto, (max-width: 265px) 100vw, 265px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-vpn-remote-access-cho-users-su-dung-mobile-client/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Checkpoint Firewall: Hướng dẫn cấu hình các Local Network trên Checkpoint Firewall.</title>
		<link>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-cac-local-network-tren-checkpoint-firewall/</link>
					<comments>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-cac-local-network-tren-checkpoint-firewall/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 24 Apr 2022 12:38:55 +0000</pubDate>
				<category><![CDATA[Checkpoint Firewall]]></category>
		<category><![CDATA[Local Network trên Checkpoint Firewall]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=14969</guid>

					<description><![CDATA[1.Overview Với Local Network sẽ cho phép bạn thiết lập và cấu hình các kết nối switches, tạo vlan, bridge port hoặc wireless network. + Cấu hình Switch giữa các cổng LAN cục bộ có sẵn và mạng không dây. Traffic cổng này không được giám sát hoặc kiểm tra. + Cấu hình nhiều bridge [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong></p>



<p class="wp-block-paragraph">Với Local Network sẽ cho phép bạn thiết lập và cấu hình các kết nối switches, tạo vlan, bridge port hoặc wireless network.</p>



<p class="wp-block-paragraph">+ Cấu hình Switch giữa các cổng LAN cục bộ có sẵn và mạng không dây. Traffic cổng này không được giám sát hoặc kiểm tra.</p>



<p class="wp-block-paragraph">+ Cấu hình nhiều bridge port các cổng. Các traffic trong bridge port luôn được thiết bị giám sát và kiểm tra.</p>



<p class="wp-block-paragraph">+ Tạo và cấu hình các VLAN trên bất kỳ cổng LAN hoặc DMZ nào.</p>



<p class="wp-block-paragraph">+ Tạo và cấu hình các đường hầm VPN (VTI) có thể được sử dụng để tạo các quy tắc định tuyến nhằm xác định lưu lượng nào được định tuyến qua đường hầm và do đó cũng được mã hóa (Route based VPN).</p>



<p class="wp-block-paragraph"><strong>2.</strong> <strong>Hướng dẫn cấu hình</strong>.</p>



<p class="wp-block-paragraph"><strong>2.1 Cấu hình tạo VLAN</strong>.</p>



<p class="wp-block-paragraph">Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; Device &gt; Network &gt; Local Network &gt; New &gt; Vlan.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="221" src="https://thegioifirewall.com/wp-content/uploads/image-3818.png" alt="" class="wp-image-14970" srcset="https://thegioifirewall.com/wp-content/uploads/image-3818.png 624w, https://thegioifirewall.com/wp-content/uploads/image-3818-300x106.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>New VLAN &gt; Configuration:</strong> Điền các thông số sau</p>



<p class="wp-block-paragraph"><strong>Vlan ID: </strong>Điền vlan id bạn muốn tạo.</p>



<p class="wp-block-paragraph"><strong>Local Network port: </strong>chọn 1 port trên Checkpoint để cấu hình cho VLAN.</p>



<p class="wp-block-paragraph">A<strong>ssigned to: </strong>chọn <strong>Separate Network.</strong></p>



<p class="wp-block-paragraph"><strong>Local IP address: </strong>điền ip gateway của VLAN.</p>



<p class="wp-block-paragraph"><strong>DHCPv4 Serve</strong>r: chọn <strong>Enable</strong>.</p>



<p class="wp-block-paragraph"><strong>Ip address range: </strong>Điền dải ip bạn muốn cấp cho VLAN</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="480" height="412" src="https://thegioifirewall.com/wp-content/uploads/image-3819.png" alt="" class="wp-image-14971" srcset="https://thegioifirewall.com/wp-content/uploads/image-3819.png 480w, https://thegioifirewall.com/wp-content/uploads/image-3819-300x258.png 300w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua <strong>DHCPv4 Settings tab</strong>, bạn có thể để mặc định.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="484" height="414" src="https://thegioifirewall.com/wp-content/uploads/image-3821.png" alt="" class="wp-image-14973" srcset="https://thegioifirewall.com/wp-content/uploads/image-3821.png 484w, https://thegioifirewall.com/wp-content/uploads/image-3821-300x257.png 300w" sizes="auto, (max-width: 484px) 100vw, 484px" /></figure></div>



<p class="wp-block-paragraph">Khi đã tạo xong VLAN bạn cần enable cổng LAN để có thể sử dụng. Chọn cổng LAN đã cấu hình <strong>(Ex: LAN6)</strong>, click <strong>Enable.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="799" height="205" src="https://thegioifirewall.com/wp-content/uploads/image-3822.png" alt="" class="wp-image-14974" srcset="https://thegioifirewall.com/wp-content/uploads/image-3822.png 799w, https://thegioifirewall.com/wp-content/uploads/image-3822-300x77.png 300w, https://thegioifirewall.com/wp-content/uploads/image-3822-768x197.png 768w" sizes="auto, (max-width: 799px) 100vw, 799px" /></figure></div>



<p class="wp-block-paragraph">Khi cổng LAN6.100 hiện trạng thái đã <strong>&#8220;UP&#8221;</strong> thì bạn đã cấu hình xong VLan, bây giờ chỉ cần bạn gắn switch vào cổng LAN6 access Vlan là đã có thể sử dụng.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="794" height="203" src="https://thegioifirewall.com/wp-content/uploads/image-3823.png" alt="" class="wp-image-14975" srcset="https://thegioifirewall.com/wp-content/uploads/image-3823.png 794w, https://thegioifirewall.com/wp-content/uploads/image-3823-300x77.png 300w, https://thegioifirewall.com/wp-content/uploads/image-3823-768x196.png 768w" sizes="auto, (max-width: 794px) 100vw, 794px" /></figure></div>



<p class="wp-block-paragraph"><strong>2.2 Cấu hình tạo Bridge Port.</strong></p>



<p class="wp-block-paragraph"> Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; Device &gt; Network &gt; Local Network &gt; New &gt; Bridge</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="284" src="https://thegioifirewall.com/wp-content/uploads/image-3824.png" alt="" class="wp-image-14976" srcset="https://thegioifirewall.com/wp-content/uploads/image-3824.png 624w, https://thegioifirewall.com/wp-content/uploads/image-3824-300x137.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>New Bridge &gt; Configuration:</strong> click chọn các cổng LAN bạn cần Bridge.</p>



<p class="wp-block-paragraph"><strong>Name: </strong>Điền tên bạn muốn cho cổng Bridge.</p>



<p class="wp-block-paragraph"><strong>Local IPv4 address:</strong> Điền ip gateway cho cổng bridge.</p>



<p class="wp-block-paragraph"><strong>DHCPv4 Server: </strong>chọn<strong> Enable</strong>.</p>



<p class="wp-block-paragraph">I<strong>P address range: </strong>Điền dải ip bạn muốn cấp cho cổng Bridge.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="487" height="418" src="https://thegioifirewall.com/wp-content/uploads/image-3825.png" alt="" class="wp-image-14977" srcset="https://thegioifirewall.com/wp-content/uploads/image-3825.png 487w, https://thegioifirewall.com/wp-content/uploads/image-3825-300x257.png 300w" sizes="auto, (max-width: 487px) 100vw, 487px" /></figure></div>



<p class="wp-block-paragraph"> Chuyển qua <strong>DHCPv4 Settings tab</strong>, bạn có thể để mặc định. </p>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-3821.png" alt="Hình ảnh này chưa có thuộc tính alt; tên tệp của nó là image-3821.png"/></figure></div>



<p class="wp-block-paragraph">Click <strong>Apply</strong>. Đã tạo xong <strong>Port Bridge.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="796" height="202" src="https://thegioifirewall.com/wp-content/uploads/image-3826.png" alt="" class="wp-image-14978" srcset="https://thegioifirewall.com/wp-content/uploads/image-3826.png 796w, https://thegioifirewall.com/wp-content/uploads/image-3826-300x76.png 300w, https://thegioifirewall.com/wp-content/uploads/image-3826-768x195.png 768w" sizes="auto, (max-width: 796px) 100vw, 796px" /></figure></div>



<p class="wp-block-paragraph">Để kiểm tra bạn có thể gắn dây mạng lần lượt vào LAN7 và LAN8 để xem Checkpoint sẽ cấp cùng lớp IP hay không.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="918" height="238" src="https://thegioifirewall.com/wp-content/uploads/image-3828.png" alt="" class="wp-image-14980" srcset="https://thegioifirewall.com/wp-content/uploads/image-3828.png 918w, https://thegioifirewall.com/wp-content/uploads/image-3828-300x78.png 300w, https://thegioifirewall.com/wp-content/uploads/image-3828-768x199.png 768w" sizes="auto, (max-width: 918px) 100vw, 918px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="916" height="232" src="https://thegioifirewall.com/wp-content/uploads/image-3829.png" alt="" class="wp-image-14981" srcset="https://thegioifirewall.com/wp-content/uploads/image-3829.png 916w, https://thegioifirewall.com/wp-content/uploads/image-3829-300x76.png 300w, https://thegioifirewall.com/wp-content/uploads/image-3829-768x195.png 768w" sizes="auto, (max-width: 916px) 100vw, 916px" /></figure></div>



<p class="wp-block-paragraph">Cả 2 cổng đều cấp IP lớp 192.168.201.0 như đã cấu hình.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="572" height="243" src="https://thegioifirewall.com/wp-content/uploads/image-3830.png" alt="" class="wp-image-14982" srcset="https://thegioifirewall.com/wp-content/uploads/image-3830.png 572w, https://thegioifirewall.com/wp-content/uploads/image-3830-300x127.png 300w" sizes="auto, (max-width: 572px) 100vw, 572px" /></figure></div>



<p class="wp-block-paragraph"><strong>2.3 Cấu hình Switch Port.</strong></p>



<p class="wp-block-paragraph"> Trên giao diện quản trị của <strong>Checkpoint Firewall &gt; Device &gt; Network &gt; Local Network &gt; New &gt;</strong> <strong>Switch</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="225" src="https://thegioifirewall.com/wp-content/uploads/image-3832.png" alt="" class="wp-image-14984" srcset="https://thegioifirewall.com/wp-content/uploads/image-3832.png 624w, https://thegioifirewall.com/wp-content/uploads/image-3832-300x108.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trong <strong>New Bridge &gt; Configuration:</strong> click chọn các cổng LAN bạn cần.</p>



<p class="wp-block-paragraph"><strong>Local IPv4 address:</strong> Điền ip gateway cho cổng.</p>



<p class="wp-block-paragraph"><strong>DHCPv4 Server: </strong>chọn<strong> Enable</strong>.</p>



<p class="wp-block-paragraph">I<strong>P address range: </strong>Điền dải ip bạn muốn cấp.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="484" height="381" src="https://thegioifirewall.com/wp-content/uploads/image-3833.png" alt="" class="wp-image-14985" srcset="https://thegioifirewall.com/wp-content/uploads/image-3833.png 484w, https://thegioifirewall.com/wp-content/uploads/image-3833-300x236.png 300w" sizes="auto, (max-width: 484px) 100vw, 484px" /></figure></div>



<p class="wp-block-paragraph">Click <strong>Apply.</strong> Đã tạo xong <strong>Switch Port.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="902" height="145" src="https://thegioifirewall.com/wp-content/uploads/image-3834.png" alt="" class="wp-image-14986" srcset="https://thegioifirewall.com/wp-content/uploads/image-3834.png 902w, https://thegioifirewall.com/wp-content/uploads/image-3834-300x48.png 300w, https://thegioifirewall.com/wp-content/uploads/image-3834-768x123.png 768w" sizes="auto, (max-width: 902px) 100vw, 902px" /></figure></div>



<p class="wp-block-paragraph">Kiểm tra thiết bị đã nhận đúng dải IP đã cấu hình.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="582" height="254" src="https://thegioifirewall.com/wp-content/uploads/image-3835.png" alt="" class="wp-image-14987" srcset="https://thegioifirewall.com/wp-content/uploads/image-3835.png 582w, https://thegioifirewall.com/wp-content/uploads/image-3835-300x131.png 300w" sizes="auto, (max-width: 582px) 100vw, 582px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/checkpoint-firewall-huong-dan-cau-hinh-cac-local-network-tren-checkpoint-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
