<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hướng dẫn cấu hình Captive Portal xác thực người dùng khi truy cập internet bằng tài khoản từ AD &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/huong-dan-cau-hinh-captive-portal-xac-thuc-nguoi-dung-khi-truy-cap-internet-bang-tai-khoan-tu-ad/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Fri, 25 Jun 2021 19:51:24 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Hướng dẫn cấu hình Captive Portal xác thực người dùng khi truy cập internet bằng tài khoản từ AD &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hướng dẫn cấu hình Captive Portal xác thực người dùng khi truy cập internet bằng tài khoản từ AD</title>
		<link>https://thegioifirewall.com/huong-dan-cau-hinh-captive-portal-xac-thuc-nguoi-dung-khi-truy-cap-internet-bang-tai-khoan-tu-ad/</link>
					<comments>https://thegioifirewall.com/huong-dan-cau-hinh-captive-portal-xac-thuc-nguoi-dung-khi-truy-cap-internet-bang-tai-khoan-tu-ad/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Fri, 18 Jun 2021 03:31:00 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Hướng dẫn cấu hình Captive Portal xác thực người dùng khi truy cập internet bằng tài khoản từ AD]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=10525</guid>

					<description><![CDATA[1.Mục đích bài viết Ở bài viết trước thegioifirewall đã hướng dẫn các bạn cách cấu hình Catpive Portal để xác thực người dùng khi sử dụng internet bằng tài khoản local trên thiết bị Palo Alto. Trong bài viết hôm nay thegioifirewall sẽ hướng dẫn các bạn cách cấu hình Captive Portal cũng với [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h3 class="wp-block-heading"><strong>1.Mục đích bài viết</strong></h3>



<p class="wp-block-paragraph">Ở bài viết trước thegioifirewall đã hướng dẫn các bạn cách cấu hình Catpive Portal để xác thực người dùng khi sử dụng internet bằng tài khoản local trên thiết bị Palo Alto.</p>



<p class="wp-block-paragraph">Trong bài viết hôm nay thegioifirewall sẽ hướng dẫn các bạn cách cấu hình Captive Portal cũng với mục đích là xác thực người dùng khi sử dụng internet nhưng là bằng tài khoản từ AD Server có trong hệ thống.</p>



<h3 class="wp-block-heading"><strong>2.Sơ đồ mạng</strong></h3>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="466" src="https://thegioifirewall.com/wp-content/uploads/Drawing1-1-1024x466.png" alt="" class="wp-image-10526" srcset="https://thegioifirewall.com/wp-content/uploads/Drawing1-1-1024x466.png 1024w, https://thegioifirewall.com/wp-content/uploads/Drawing1-1-300x136.png 300w, https://thegioifirewall.com/wp-content/uploads/Drawing1-1-768x349.png 768w, https://thegioifirewall.com/wp-content/uploads/Drawing1-1.png 1515w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Chi tiết:</strong></p>



<ul class="wp-block-list"><li>Thiết bị tường lửa Palo Alto đã được kết nối internet thông qua cổng ethernet1/1 với IP WAN là 192.168.219.129.</li><li>Vùng mạng LAN của thiết bị Palo Alto được cấu hình ở cổng ethernet1/2 cấp phát lớp mạng 10.145.41.0/24 bằng DHCP.</li><li>Trong lớp LAN còn có 1 AD Server có IP 10.145.41.10/24, trên server này đã tạo 1 OU IT, trong OU IT có group Support, trong group Support có các user là user1,user2,user3.</li><li>Máy tính Laptop 1 được kết nối tại port ethernet1/2 và nhận DHCP với IP 10.145.41.3/24.</li></ul>



<h3 class="wp-block-heading"><strong>3.Tình huống cấu hình</strong></h3>



<ul class="wp-block-list"><li>Thegioifirewal sẽ thực hiện cấu hình Captive Portal trên thiết bị Palo Alto để khi các thiết bị trong vùng mạng LAN truy cập và sử dụng internet sẽ phải thực hiện xác thực bằng tài khoản đã đồng bộ từ AD Server.</li></ul>



<h3 class="wp-block-heading"><strong>4.Các bước thực hiện</strong></h3>



<ul class="wp-block-list"><li>Tạo Certificate</li><li>Cấu hình Decryption Policy</li><li>Thêm Certificate vào Laptop 1</li><li>Tạo SSL/TLS Service Profile</li><li>Đồng bộ AD</li><li>Tạo Authentication Profile</li><li>Bật Captive Portal</li><li>Tạo Authentication policy</li><li>Kiểm tra kết quả</li></ul>



<h3 class="wp-block-heading"><strong>5.Hướng dẫn cấu hình</strong></h3>



<h4 class="wp-block-heading"><strong>5.1. Tạo Certificate</strong></h4>



<p class="wp-block-paragraph">Để cấu hình Decryption vào Device &gt; Certificates Management &gt; Certificates.</p>



<p class="wp-block-paragraph">Click Generate để tạo certificate mới với thông số sau :</p>



<ul class="wp-block-list"><li>Certificate Name : trusted-ca</li><li>Common Name : 10.145.41.1 (địa chỉ IP cổng LAN)</li><li>Certificate Authority : tích chọn Certificate Authority.</li></ul>



<p class="wp-block-paragraph">Nhấn Generate để tạo.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="690" height="1024" src="https://thegioifirewall.com/wp-content/uploads/1-23-690x1024.png" alt="" class="wp-image-10527" srcset="https://thegioifirewall.com/wp-content/uploads/1-23-690x1024.png 690w, https://thegioifirewall.com/wp-content/uploads/1-23-202x300.png 202w, https://thegioifirewall.com/wp-content/uploads/1-23-768x1140.png 768w, https://thegioifirewall.com/wp-content/uploads/1-23.png 996w" sizes="(max-width: 690px) 100vw, 690px" /></figure></div>



<p class="wp-block-paragraph">Click Generate để tạo 1 certificate mới khác với thông số sau :</p>



<ul class="wp-block-list"><li>Common Name : untrusted-ca</li><li>Common Name : untrusted</li><li>Certificate Authority : tích chọn Certificate Authority.</li></ul>



<p class="wp-block-paragraph">Nhấn Generate để tạo.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="692" height="1024" src="https://thegioifirewall.com/wp-content/uploads/2-19-692x1024.png" alt="" class="wp-image-10528" srcset="https://thegioifirewall.com/wp-content/uploads/2-19-692x1024.png 692w, https://thegioifirewall.com/wp-content/uploads/2-19-203x300.png 203w, https://thegioifirewall.com/wp-content/uploads/2-19-768x1136.png 768w, https://thegioifirewall.com/wp-content/uploads/2-19.png 1000w" sizes="(max-width: 692px) 100vw, 692px" /></figure></div>



<p class="wp-block-paragraph">Nhấn vào tên trusted-ca để chỉnh sửa như sau :</p>



<ul class="wp-block-list"><li>Tích chọn vào ô Forward Trust Certificate.</li></ul>



<p class="wp-block-paragraph">Nhấn OK để lưu.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="597" src="https://thegioifirewall.com/wp-content/uploads/3-22-1024x597.png" alt="" class="wp-image-10529" srcset="https://thegioifirewall.com/wp-content/uploads/3-22-1024x597.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-22-300x175.png 300w, https://thegioifirewall.com/wp-content/uploads/3-22-768x447.png 768w, https://thegioifirewall.com/wp-content/uploads/3-22.png 1500w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure></div>



<p class="wp-block-paragraph">Tương tự với nhấn vào tên untrusted-ca để chỉnh sửa như sau :</p>



<ul class="wp-block-list"><li>Tích chọn Forward Untrust Certificate.</li></ul>



<p class="wp-block-paragraph">Nhấn OK để lưu.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="597" src="https://thegioifirewall.com/wp-content/uploads/4-22-1024x597.png" alt="" class="wp-image-10530" srcset="https://thegioifirewall.com/wp-content/uploads/4-22-1024x597.png 1024w, https://thegioifirewall.com/wp-content/uploads/4-22-300x175.png 300w, https://thegioifirewall.com/wp-content/uploads/4-22-768x447.png 768w, https://thegioifirewall.com/wp-content/uploads/4-22.png 1500w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure></div>



<p class="wp-block-paragraph">Tiếp theo tích chọn trusted-ca certificate và nhấn Export Certificate để tải xuống certificate này về máy tính.</p>



<h4 class="wp-block-heading"><strong>5.2 Tạo Decryption Policy</strong></h4>



<p class="wp-block-paragraph">Tiếp theo chúng ta sẽ tạo Decryption Policy, để tạo vào Policies &gt; Decryption &gt; Click Add và cấu hình với các thông số sau :</p>



<ul class="wp-block-list"><li>Name : Decryption</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="527" src="https://thegioifirewall.com/wp-content/uploads/5-19-1024x527.png" alt="" class="wp-image-10531" srcset="https://thegioifirewall.com/wp-content/uploads/5-19-1024x527.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-19-300x154.png 300w, https://thegioifirewall.com/wp-content/uploads/5-19-768x395.png 768w, https://thegioifirewall.com/wp-content/uploads/5-19-1536x790.png 1536w, https://thegioifirewall.com/wp-content/uploads/5-19.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list"><li>Source: Trust-Player3</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://thegioifirewall.com/wp-content/uploads/6-21-1024x600.png" alt="" class="wp-image-10532" srcset="https://thegioifirewall.com/wp-content/uploads/6-21-1024x600.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-21-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/6-21-768x450.png 768w, https://thegioifirewall.com/wp-content/uploads/6-21-1536x901.png 1536w, https://thegioifirewall.com/wp-content/uploads/6-21.png 1750w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list"><li>Destination: Untrust</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="599" src="https://thegioifirewall.com/wp-content/uploads/7-15-1024x599.png" alt="" class="wp-image-10533" srcset="https://thegioifirewall.com/wp-content/uploads/7-15-1024x599.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-15-300x175.png 300w, https://thegioifirewall.com/wp-content/uploads/7-15-768x449.png 768w, https://thegioifirewall.com/wp-content/uploads/7-15-1536x898.png 1536w, https://thegioifirewall.com/wp-content/uploads/7-15.png 1750w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list"><li>Service/URL Category : Any</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="553" src="https://thegioifirewall.com/wp-content/uploads/8-16-1024x553.png" alt="" class="wp-image-10534" srcset="https://thegioifirewall.com/wp-content/uploads/8-16-1024x553.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-16-300x162.png 300w, https://thegioifirewall.com/wp-content/uploads/8-16-768x415.png 768w, https://thegioifirewall.com/wp-content/uploads/8-16-1536x829.png 1536w, https://thegioifirewall.com/wp-content/uploads/8-16.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list"><li>Options : Chọn Decrypt ở Action và chọn SSL Forward Proxy ở Type</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="320" src="https://thegioifirewall.com/wp-content/uploads/9-18-1024x320.png" alt="" class="wp-image-10535" srcset="https://thegioifirewall.com/wp-content/uploads/9-18-1024x320.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-18-300x94.png 300w, https://thegioifirewall.com/wp-content/uploads/9-18-768x240.png 768w, https://thegioifirewall.com/wp-content/uploads/9-18-1536x480.png 1536w, https://thegioifirewall.com/wp-content/uploads/9-18.png 1750w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.Thêm Certificate vào máy tính</strong></h4>



<p class="wp-block-paragraph">Trên khung tìm kiếm của Windows gõ mmc và nhấn phím Enter để mở Microsoft Management Console.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="837" src="https://thegioifirewall.com/wp-content/uploads/20-5-1024x837.png" alt="" class="wp-image-10536" srcset="https://thegioifirewall.com/wp-content/uploads/20-5-1024x837.png 1024w, https://thegioifirewall.com/wp-content/uploads/20-5-300x245.png 300w, https://thegioifirewall.com/wp-content/uploads/20-5-768x628.png 768w, https://thegioifirewall.com/wp-content/uploads/20-5-1536x1256.png 1536w, https://thegioifirewall.com/wp-content/uploads/20-5.png 1954w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chọn Console Root &gt; Click File &gt; Click Add/Remove Snap-in…</p>



<p class="wp-block-paragraph">Bảng Add or Remove Snap-ins hiện ra, tích chọn Certificate và nhấn Add.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="725" src="https://thegioifirewall.com/wp-content/uploads/10-13-1024x725.png" alt="" class="wp-image-10538" srcset="https://thegioifirewall.com/wp-content/uploads/10-13-1024x725.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-13-300x212.png 300w, https://thegioifirewall.com/wp-content/uploads/10-13-768x544.png 768w, https://thegioifirewall.com/wp-content/uploads/10-13-1536x1087.png 1536w, https://thegioifirewall.com/wp-content/uploads/10-13.png 1684w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Bảng Certificates snap-in hiện ra, chọn Computer account &gt; Next &gt; chọn Local computer &gt; nhấn Finish &gt; Nhấn OK.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="765" src="https://thegioifirewall.com/wp-content/uploads/11-14-1024x765.png" alt="" class="wp-image-10539" srcset="https://thegioifirewall.com/wp-content/uploads/11-14-1024x765.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-14-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/11-14-768x573.png 768w, https://thegioifirewall.com/wp-content/uploads/11-14-400x300.png 400w, https://thegioifirewall.com/wp-content/uploads/11-14.png 1299w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="765" src="https://thegioifirewall.com/wp-content/uploads/12-13-1024x765.png" alt="" class="wp-image-10540" srcset="https://thegioifirewall.com/wp-content/uploads/12-13-1024x765.png 1024w, https://thegioifirewall.com/wp-content/uploads/12-13-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/12-13-768x573.png 768w, https://thegioifirewall.com/wp-content/uploads/12-13-400x300.png 400w, https://thegioifirewall.com/wp-content/uploads/12-13.png 1299w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="725" src="https://thegioifirewall.com/wp-content/uploads/13-11-1024x725.png" alt="" class="wp-image-10537" srcset="https://thegioifirewall.com/wp-content/uploads/13-11-1024x725.png 1024w, https://thegioifirewall.com/wp-content/uploads/13-11-300x212.png 300w, https://thegioifirewall.com/wp-content/uploads/13-11-768x544.png 768w, https://thegioifirewall.com/wp-content/uploads/13-11-1536x1087.png 1536w, https://thegioifirewall.com/wp-content/uploads/13-11.png 1684w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Vào Certificates (Local Computer) &gt; click chuột phải vào Trusted Root Certification Authorities &gt; Certificates &gt; chọn All Task &lt; Import.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="516" src="https://thegioifirewall.com/wp-content/uploads/14-10-1024x516.png" alt="" class="wp-image-10541" srcset="https://thegioifirewall.com/wp-content/uploads/14-10-1024x516.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-10-300x151.png 300w, https://thegioifirewall.com/wp-content/uploads/14-10-768x387.png 768w, https://thegioifirewall.com/wp-content/uploads/14-10-1536x773.png 1536w, https://thegioifirewall.com/wp-content/uploads/14-10-2048x1031.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cửa sổ Certificate Import Wizard hiện ra, nhấn Next &gt; ở mục File name nhấn Browse và tìm đến nơi bạn đã lưu certificate lúc export.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1003" src="https://thegioifirewall.com/wp-content/uploads/15-10-1024x1003.png" alt="" class="wp-image-10542" srcset="https://thegioifirewall.com/wp-content/uploads/15-10-1024x1003.png 1024w, https://thegioifirewall.com/wp-content/uploads/15-10-300x294.png 300w, https://thegioifirewall.com/wp-content/uploads/15-10-768x752.png 768w, https://thegioifirewall.com/wp-content/uploads/15-10.png 1337w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="642" src="https://thegioifirewall.com/wp-content/uploads/16-10-1024x642.png" alt="" class="wp-image-10543" srcset="https://thegioifirewall.com/wp-content/uploads/16-10-1024x642.png 1024w, https://thegioifirewall.com/wp-content/uploads/16-10-300x188.png 300w, https://thegioifirewall.com/wp-content/uploads/16-10-768x482.png 768w, https://thegioifirewall.com/wp-content/uploads/16-10-1536x964.png 1536w, https://thegioifirewall.com/wp-content/uploads/16-10.png 1884w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Next &gt; Finish để hoàn thành việc import.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1003" src="https://thegioifirewall.com/wp-content/uploads/17-9-1024x1003.png" alt="" class="wp-image-10544" srcset="https://thegioifirewall.com/wp-content/uploads/17-9-1024x1003.png 1024w, https://thegioifirewall.com/wp-content/uploads/17-9-300x294.png 300w, https://thegioifirewall.com/wp-content/uploads/17-9-768x752.png 768w, https://thegioifirewall.com/wp-content/uploads/17-9.png 1337w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1003" src="https://thegioifirewall.com/wp-content/uploads/18-7-1024x1003.png" alt="" class="wp-image-10545" srcset="https://thegioifirewall.com/wp-content/uploads/18-7-1024x1003.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-7-300x294.png 300w, https://thegioifirewall.com/wp-content/uploads/18-7-768x752.png 768w, https://thegioifirewall.com/wp-content/uploads/18-7.png 1337w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1003" src="https://thegioifirewall.com/wp-content/uploads/19-7-1024x1003.png" alt="" class="wp-image-10546" srcset="https://thegioifirewall.com/wp-content/uploads/19-7-1024x1003.png 1024w, https://thegioifirewall.com/wp-content/uploads/19-7-300x294.png 300w, https://thegioifirewall.com/wp-content/uploads/19-7-768x752.png 768w, https://thegioifirewall.com/wp-content/uploads/19-7.png 1337w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading">5.4.Tạo SSL/TLS Service Profile</h4>



<p class="wp-block-paragraph">Vào Device &gt; Certificate Management &gt; SSL/TLS Service Profile.</p>



<p class="wp-block-paragraph">Nhấn Add để tạo với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: local-portal</li><li>Certificate: trusted-ca</li><li>Min Version: TLSv1.0</li><li>Max Version: Max</li><li>Nhấn OK để lưu</li></ul>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu thay đổi cấu hình.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="999" height="557" src="https://thegioifirewall.com/wp-content/uploads/26-4.png" alt="" class="wp-image-10547" srcset="https://thegioifirewall.com/wp-content/uploads/26-4.png 999w, https://thegioifirewall.com/wp-content/uploads/26-4-300x167.png 300w, https://thegioifirewall.com/wp-content/uploads/26-4-768x428.png 768w" sizes="auto, (max-width: 999px) 100vw, 999px" /></figure>



<h4 class="wp-block-heading">5.5.Đồng bộ AD</h4>



<h4 class="wp-block-heading">5.5.1. Cấu hình Service Features</h4>



<p class="wp-block-paragraph">Đầu tiên chúng ta cần cấu hình Service Features để routing một số service đến port đang kết nối với server AD.</p>



<p class="wp-block-paragraph">Ở đây chúng ta sẽ routing các service như DNS, Kerberos, LDAP,UID Agent.</p>



<p class="wp-block-paragraph">Để mở các service này chúng ta truy cập vào trang cấu hình của Palo Alto. Vào mục Device &gt; Setup &gt; Service &gt; Service Features &gt; Service Route Configuration.</p>



<p class="wp-block-paragraph">Bảng Service Route Configuration hiện lên tích chọn Customize.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="994" height="1024" src="https://thegioifirewall.com/wp-content/uploads/4-23-994x1024.png" alt="" class="wp-image-10548" srcset="https://thegioifirewall.com/wp-content/uploads/4-23-994x1024.png 994w, https://thegioifirewall.com/wp-content/uploads/4-23-291x300.png 291w, https://thegioifirewall.com/wp-content/uploads/4-23-768x791.png 768w, https://thegioifirewall.com/wp-content/uploads/4-23.png 1250w" sizes="auto, (max-width: 994px) 100vw, 994px" /></figure>



<p class="wp-block-paragraph">Để cấu hình dịch vụ chúng ta nhấp chuột trái vào dịch vụ cần cấu hình, ở đây mình chọn DNS, bảng Service Route Source hiện lên chúng ta sẽ chọn port ethernet1/2 ở Source Interface và ở Source Address sẽ tự động hiện lên IP của port ethernet1/2 là 10.145.41.10/24.</p>



<p class="wp-block-paragraph">Click OK để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="346" src="https://thegioifirewall.com/wp-content/uploads/5-20-1024x346.png" alt="" class="wp-image-10549" srcset="https://thegioifirewall.com/wp-content/uploads/5-20-1024x346.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-20-300x102.png 300w, https://thegioifirewall.com/wp-content/uploads/5-20-768x260.png 768w, https://thegioifirewall.com/wp-content/uploads/5-20.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Các service còn lại chúng ta cũng thực hiện tương tự.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="346" src="https://thegioifirewall.com/wp-content/uploads/6-22-1024x346.png" alt="" class="wp-image-10550" srcset="https://thegioifirewall.com/wp-content/uploads/6-22-1024x346.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-22-300x102.png 300w, https://thegioifirewall.com/wp-content/uploads/6-22-768x260.png 768w, https://thegioifirewall.com/wp-content/uploads/6-22.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="346" src="https://thegioifirewall.com/wp-content/uploads/7-16-1024x346.png" alt="" class="wp-image-10551" srcset="https://thegioifirewall.com/wp-content/uploads/7-16-1024x346.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-16-300x102.png 300w, https://thegioifirewall.com/wp-content/uploads/7-16-768x260.png 768w, https://thegioifirewall.com/wp-content/uploads/7-16.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="346" src="https://thegioifirewall.com/wp-content/uploads/8-17-1024x346.png" alt="" class="wp-image-10552" srcset="https://thegioifirewall.com/wp-content/uploads/8-17-1024x346.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-17-300x102.png 300w, https://thegioifirewall.com/wp-content/uploads/8-17-768x260.png 768w, https://thegioifirewall.com/wp-content/uploads/8-17.png 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Click OK ở bảng Service Route Configuration để lưu.</p>



<p class="wp-block-paragraph">Click Commit và OK để lưu thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.5.2. Bật tính năng User Identification trên zone LAN</h4>



<p class="wp-block-paragraph">Để có thể đồng bộ user từ server AD chúng ta cần bật tính năng User Identification trên zone chứa các máy trạm đã john domain, ở đây chúng ta sẽ thực hiện bật tính năng này trên zone Trust-Player3.</p>



<p class="wp-block-paragraph">Để bật vào Network &gt; Zones &gt; nhấp chuột trái vào zone Trust-Player3 &gt; bảng Zone hiện lên &gt; chúng ta sẽ đánh dấu vào ô Enable User Identification ở phần User Identification ACL.</p>



<p class="wp-block-paragraph">Click OK để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="759" src="https://thegioifirewall.com/wp-content/uploads/9-19-1024x759.png" alt="" class="wp-image-10553" srcset="https://thegioifirewall.com/wp-content/uploads/9-19-1024x759.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-19-300x222.png 300w, https://thegioifirewall.com/wp-content/uploads/9-19-768x569.png 768w, https://thegioifirewall.com/wp-content/uploads/9-19-1536x1139.png 1536w, https://thegioifirewall.com/wp-content/uploads/9-19.png 1751w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Click Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.5.3. Cấu hình LDAP Service Profile</h4>



<p class="wp-block-paragraph">Để tạo vào Device &gt; Server Profiles &gt; LDAP &gt; Click Add và tạo theo thông tin như sau :</p>



<ul class="wp-block-list"><li>Profile Name : learningit</li><li>Server List : click Add, nhập Name là adserver, LDAP Server là ip của server 10.145.41.10 và Port là 389.</li><li>Ở Server Settings :</li><li>Type : chọn active-directory</li><li>Base DN : DC=learningit,DC=xyz</li><li>Bind DN : administrator@learningit.xyz</li><li>Password và Confirm Password : nhập password của tài khoản administrator.</li><li>Bind Timeout : 30</li><li>Search Timeout : 30</li><li>Retry Interval : 60</li><li>Required SSL/TLS secured connection : bỏ check nếu có.</li><li>Click OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="546" src="https://thegioifirewall.com/wp-content/uploads/10-14-1024x546.png" alt="" class="wp-image-10554" srcset="https://thegioifirewall.com/wp-content/uploads/10-14-1024x546.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-14-300x160.png 300w, https://thegioifirewall.com/wp-content/uploads/10-14-768x409.png 768w, https://thegioifirewall.com/wp-content/uploads/10-14-1536x819.png 1536w, https://thegioifirewall.com/wp-content/uploads/10-14.png 2000w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Click Commit và OK để lưu thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.5.4. Cấu hình User Mapping</h4>



<p class="wp-block-paragraph">Để cấu hình vào Device &gt; User Identification &gt; User Mapping.</p>



<p class="wp-block-paragraph">Ở đây chúng ta có 3 phần cần phải cấu hình là Palo Alto Networks User-ID Agent Setup, Server Monitoring, Include/Exclude Networks.</p>



<p class="wp-block-paragraph">Ở phần Palo Alto Networks User-ID Agent Setup để cấu hình chúng ta click vào icon bánh xe phía bên phải, một bảng cấu hình sẽ hiện ra và cần cấu hình các thông số như sau.</p>



<p class="wp-block-paragraph">Tab Server Monitor Account :</p>



<ul class="wp-block-list"><li>User Name : learningit\administrator</li><li>Password và Confirm Passoword : nhập mật khẩu của tài khoản administrator vào 2 ô này</li><li>Kerberos Server Profile : None</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="360" src="https://thegioifirewall.com/wp-content/uploads/11-15-1024x360.png" alt="" class="wp-image-10555" srcset="https://thegioifirewall.com/wp-content/uploads/11-15-1024x360.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-15-300x105.png 300w, https://thegioifirewall.com/wp-content/uploads/11-15-768x270.png 768w, https://thegioifirewall.com/wp-content/uploads/11-15-1536x539.png 1536w, https://thegioifirewall.com/wp-content/uploads/11-15.png 1848w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Server Monitor :</p>



<ul class="wp-block-list"><li>Enable Security Log : check</li><li>Server Log Monitor Frequency (sec) : 2</li><li>Enable Session : uncheck</li><li>Server Session Read Frequency (sec) : 10</li><li>Novell eDirectory Query Interval (sec) : 30</li><li>Syslog Service Profile : None</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="542" src="https://thegioifirewall.com/wp-content/uploads/12-14-1024x542.png" alt="" class="wp-image-10556" srcset="https://thegioifirewall.com/wp-content/uploads/12-14-1024x542.png 1024w, https://thegioifirewall.com/wp-content/uploads/12-14-300x159.png 300w, https://thegioifirewall.com/wp-content/uploads/12-14-768x406.png 768w, https://thegioifirewall.com/wp-content/uploads/12-14-1536x812.png 1536w, https://thegioifirewall.com/wp-content/uploads/12-14.png 1849w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Client Probing :</p>



<ul class="wp-block-list"><li>Enable Probing : check</li><li>Probe Interval (min) : 5</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="256" src="https://thegioifirewall.com/wp-content/uploads/13-12-1024x256.png" alt="" class="wp-image-10557" srcset="https://thegioifirewall.com/wp-content/uploads/13-12-1024x256.png 1024w, https://thegioifirewall.com/wp-content/uploads/13-12-300x75.png 300w, https://thegioifirewall.com/wp-content/uploads/13-12-768x192.png 768w, https://thegioifirewall.com/wp-content/uploads/13-12-1536x384.png 1536w, https://thegioifirewall.com/wp-content/uploads/13-12.png 1850w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Cache :</p>



<ul class="wp-block-list"><li>Enable User Identification Timeout : check</li><li>User Identification Timeout (min) : 120</li><li>Allow matching usernames without domains : uncheck</li><li>Click OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="292" src="https://thegioifirewall.com/wp-content/uploads/14-11-1024x292.png" alt="" class="wp-image-10558" srcset="https://thegioifirewall.com/wp-content/uploads/14-11-1024x292.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-11-300x86.png 300w, https://thegioifirewall.com/wp-content/uploads/14-11-768x219.png 768w, https://thegioifirewall.com/wp-content/uploads/14-11-1536x438.png 1536w, https://thegioifirewall.com/wp-content/uploads/14-11.png 1850w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tiếp theo chúng ta sẽ cấu hình Server Monitoring, click Add bảng User Identification Monitored Server hiện ra và cấu hình các thông số sau :</p>



<ul class="wp-block-list"><li>Name : learningit</li><li>Check Enable</li><li>Type : Microsoft Active Directory</li><li>Transport Protocol : WMI</li><li>Network Address : 10.145.41.10</li><li>Click OK để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="470" src="https://thegioifirewall.com/wp-content/uploads/15-11-1024x470.png" alt="" class="wp-image-10559" srcset="https://thegioifirewall.com/wp-content/uploads/15-11-1024x470.png 1024w, https://thegioifirewall.com/wp-content/uploads/15-11-300x138.png 300w, https://thegioifirewall.com/wp-content/uploads/15-11-768x352.png 768w, https://thegioifirewall.com/wp-content/uploads/15-11.png 1374w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cuối cùng là phần Include/Exclude Networks, click Add bảng Include Exclude Network hiện ra và cấu hình theo các thông số sau :</p>



<ul class="wp-block-list"><li>Name : All</li><li>Check Enable</li><li>Discovery : Include</li><li>Network Address : 0.0.0.0/0</li><li>Click OK để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1000" height="481" src="https://thegioifirewall.com/wp-content/uploads/16-11.png" alt="" class="wp-image-10560" srcset="https://thegioifirewall.com/wp-content/uploads/16-11.png 1000w, https://thegioifirewall.com/wp-content/uploads/16-11-300x144.png 300w, https://thegioifirewall.com/wp-content/uploads/16-11-768x369.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></figure>



<p class="wp-block-paragraph">Sau khi cấu hình xong chúng ta để ý ở phần Server Monitoring, status của server mà chúng ta kết nối đã hiện thị Connected.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="564" src="https://thegioifirewall.com/wp-content/uploads/17-10-1024x564.png" alt="" class="wp-image-10561" srcset="https://thegioifirewall.com/wp-content/uploads/17-10-1024x564.png 1024w, https://thegioifirewall.com/wp-content/uploads/17-10-300x165.png 300w, https://thegioifirewall.com/wp-content/uploads/17-10-768x423.png 768w, https://thegioifirewall.com/wp-content/uploads/17-10-1536x847.png 1536w, https://thegioifirewall.com/wp-content/uploads/17-10.png 1867w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Click Commit và OK để lưu thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.5.5. Cấu hình Group Mapping Setting</h4>



<p class="wp-block-paragraph">Để cấu hình vào Device &gt; User Identification &gt; Group Mapping Settings &gt; Click Add bảng Group Mapping hiện ra và chúng ta sẽ cấu hình Server Profile, Group Incude List.</p>



<p class="wp-block-paragraph">Tab Server Profile :</p>



<ul class="wp-block-list"><li>Name : learningit</li><li>Server Profile : learningit</li><li>User Domain : learningit.xyz</li><li>Object Class (Gourp Object) : group</li><li>Object Class (User Object) : person</li><li>Check Enable</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="787" src="https://thegioifirewall.com/wp-content/uploads/18-8-1024x787.png" alt="" class="wp-image-10562" srcset="https://thegioifirewall.com/wp-content/uploads/18-8-1024x787.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-8-300x231.png 300w, https://thegioifirewall.com/wp-content/uploads/18-8-768x591.png 768w, https://thegioifirewall.com/wp-content/uploads/18-8-1536x1181.png 1536w, https://thegioifirewall.com/wp-content/uploads/18-8.png 1562w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Group Include List :</p>



<ul class="wp-block-list"><li>Chúng ta sẽ nhấn vào mũi tên ở DC=learningit,DC=xyz để nó hiển thị danh sách các OU, Group mà nó đã đồng với AD sau đó chọn OU hoặc Group mà mình muốn sử dụng rồi ấn dấu “+” để chuyển nó qua bảng Include Group.</li><li>Ở đây mình sẽ đồng bộ group support nằm trong OU IT.</li><li>Click OK để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="681" src="https://thegioifirewall.com/wp-content/uploads/19-8-1024x681.png" alt="" class="wp-image-10563" srcset="https://thegioifirewall.com/wp-content/uploads/19-8-1024x681.png 1024w, https://thegioifirewall.com/wp-content/uploads/19-8-300x199.png 300w, https://thegioifirewall.com/wp-content/uploads/19-8-768x511.png 768w, https://thegioifirewall.com/wp-content/uploads/19-8-1536x1021.png 1536w, https://thegioifirewall.com/wp-content/uploads/19-8.png 1560w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Click Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.6. Tạo Authentication Profile</h4>



<p class="wp-block-paragraph">Chúng ta cần tạo Authentication Profile dành cho các user local để cho thiết bị tường lửa có thể dựa vào cái này để xác thực liệu tài khoản của người dùng dùng để đăng nhập có nằm trong danh sách được cho phép sử dụng VPN hay không và nếu có trong danh sách thì dùng để xác thực xem người dùng để đăng nhập đúng tài khoản và mật khẩu chưa.</p>



<p class="wp-block-paragraph">Để tạo Authentication Profile vào Device &gt; Authentication Profile &gt; nhấn Add và cấu hình theo các thông số sau.</p>



<p class="wp-block-paragraph">Tab Authentication:</p>



<ul class="wp-block-list"><li>Name: Learningit Auth.</li><li>Type: chọn LDAP.</li><li>Server Profile: learningit.</li><li>Password Expiry Warning: 7</li><li>Username Modifier: chọn %USERDOMAIN%\%USERINPUT%</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="711" src="https://thegioifirewall.com/wp-content/uploads/20-6-1024x711.png" alt="" class="wp-image-10564" srcset="https://thegioifirewall.com/wp-content/uploads/20-6-1024x711.png 1024w, https://thegioifirewall.com/wp-content/uploads/20-6-300x208.png 300w, https://thegioifirewall.com/wp-content/uploads/20-6-768x533.png 768w, https://thegioifirewall.com/wp-content/uploads/20-6.png 1500w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Advanced:</p>



<ul class="wp-block-list"><li>Tại bảng Allow List nhấn Add và chọn all.</li><li>Nếu bạn chọn all tức là tất cả các user sẽ được sử dụng, bạn cũng có thể tùy chọn user mà mình muốn thay vì chọn all.</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="848" src="https://thegioifirewall.com/wp-content/uploads/21-6-1024x848.png" alt="" class="wp-image-10565" srcset="https://thegioifirewall.com/wp-content/uploads/21-6-1024x848.png 1024w, https://thegioifirewall.com/wp-content/uploads/21-6-300x248.png 300w, https://thegioifirewall.com/wp-content/uploads/21-6-768x636.png 768w, https://thegioifirewall.com/wp-content/uploads/21-6.png 1500w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.7.Bật Captive Portal</h4>



<p class="wp-block-paragraph">Vào Device &gt; User Identification &gt; Captive Portal.</p>



<p class="wp-block-paragraph">Nhấn vào icon bánh xe và cấu hình theo các thông số sau:</p>



<ul class="wp-block-list"><li>Tích chọn Enable Captive Portal.</li><li>SSL/TLS Service Profile: chọn local-portal</li><li>Authentication Profile: chọn Learning Auth</li><li>Mode: chọn Redirect</li><li>Tích chọn Enable tại Session Cookie</li><li>Redirect Host: nhập vào IP của cổng LAN 10.145.41.1</li><li>Nhấn OK để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="773" src="https://thegioifirewall.com/wp-content/uploads/1-1-1-1024x773.png" alt="" class="wp-image-10566" srcset="https://thegioifirewall.com/wp-content/uploads/1-1-1-1024x773.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-1-1-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/1-1-1-768x580.png 768w, https://thegioifirewall.com/wp-content/uploads/1-1-1-1536x1160.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-1-1.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading">5.8.Tạo Authentication Policy</h4>



<p class="wp-block-paragraph">Vào Policies &gt; Authentication &gt; nhấn Add và tạo theo các thông tin sau:</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: Captive_Portal</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="672" src="https://thegioifirewall.com/wp-content/uploads/28-4-1024x672.png" alt="" class="wp-image-10567" srcset="https://thegioifirewall.com/wp-content/uploads/28-4-1024x672.png 1024w, https://thegioifirewall.com/wp-content/uploads/28-4-300x197.png 300w, https://thegioifirewall.com/wp-content/uploads/28-4-768x504.png 768w, https://thegioifirewall.com/wp-content/uploads/28-4.png 1375w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Source:</p>



<ul class="wp-block-list"><li>Source Zone: chọn Trust-Player3 (đây là zone của vùng LAN)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="763" src="https://thegioifirewall.com/wp-content/uploads/29-3-1024x763.png" alt="" class="wp-image-10568" srcset="https://thegioifirewall.com/wp-content/uploads/29-3-1024x763.png 1024w, https://thegioifirewall.com/wp-content/uploads/29-3-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/29-3-768x572.png 768w, https://thegioifirewall.com/wp-content/uploads/29-3.png 1375w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Destination:</p>



<ul class="wp-block-list"><li>Destination Zone: chọn Untrust (Đây là zone của vùng WAN internet)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="763" src="https://thegioifirewall.com/wp-content/uploads/30-4-1024x763.png" alt="" class="wp-image-10569" srcset="https://thegioifirewall.com/wp-content/uploads/30-4-1024x763.png 1024w, https://thegioifirewall.com/wp-content/uploads/30-4-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/30-4-768x572.png 768w, https://thegioifirewall.com/wp-content/uploads/30-4.png 1374w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Service/URL Category:</p>



<ul class="wp-block-list"><li>Service: chọn service-http và service-https</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="722" src="https://thegioifirewall.com/wp-content/uploads/31-5-1024x722.png" alt="" class="wp-image-10570" srcset="https://thegioifirewall.com/wp-content/uploads/31-5-1024x722.png 1024w, https://thegioifirewall.com/wp-content/uploads/31-5-300x211.png 300w, https://thegioifirewall.com/wp-content/uploads/31-5-768x541.png 768w, https://thegioifirewall.com/wp-content/uploads/31-5.png 1375w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Action:</p>



<ul class="wp-block-list"><li>Authetication Enforcement: chọn default-web-form</li><li>Timeout (min): 60</li><li>Tích chọn Log Authentication Timeouts</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="514" src="https://thegioifirewall.com/wp-content/uploads/32-3-1024x514.png" alt="" class="wp-image-10571" srcset="https://thegioifirewall.com/wp-content/uploads/32-3-1024x514.png 1024w, https://thegioifirewall.com/wp-content/uploads/32-3-300x151.png 300w, https://thegioifirewall.com/wp-content/uploads/32-3-768x385.png 768w, https://thegioifirewall.com/wp-content/uploads/32-3.png 1375w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn OK để lưu.</p>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<p class="wp-block-paragraph">Với cấu hình này thì chúng ta sẽ bắt người dùng phải xác thực khi họ sử dụng giao thức http và https để kết nối internet. Khi họ kết nối thì Palo Alto sẽ tự động chuyển hướng kết nối về đến trang web xác thực với ip 10.145.41.1 bắt user phải nhâp tài khoản mật khẩu đã tạo để xác thực.</p>



<p class="wp-block-paragraph">Lý do chúng ta cần cấu hình Decryption là vì những traffic https đều là những traffic bị mã hóa khi đi qua tường lửa Palo Alto thì sẽ không nhận dạng được.</p>



<p class="wp-block-paragraph">Vì vậy nếu muốn xác thực khi người dùng sử dụng https thì chúng ta cần cấu hình Decryption để tưởng lửa có thể nhận biết các traffic https đi qua để thực thi xác thực.</p>



<h4 class="wp-block-heading">5.9.Kết quả</h4>



<p class="wp-block-paragraph">Chúng ta sẽ lấy Laptop 1 với IP 10.145.41.3 truy cập internet bằng trình duyệt web.</p>



<p class="wp-block-paragraph">Lúc này trình duyệt sẽ chuyển hướng chúng ta sang trang web xác thực của palo alto.</p>



<p class="wp-block-paragraph">Chúng ta cần nhập username và password mà chúng ta đã đồng bộ từ AD để xác thực, nếu xác thực thành công chúng ta sẽ được phép truy cập internet.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="637" src="https://thegioifirewall.com/wp-content/uploads/1-3-1-1024x637.png" alt="" class="wp-image-10572" srcset="https://thegioifirewall.com/wp-content/uploads/1-3-1-1024x637.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-3-1-300x187.png 300w, https://thegioifirewall.com/wp-content/uploads/1-3-1-768x478.png 768w, https://thegioifirewall.com/wp-content/uploads/1-3-1-1536x955.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-3-1-2048x1274.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="638" src="https://thegioifirewall.com/wp-content/uploads/1-5-1-1024x638.png" alt="" class="wp-image-10573" srcset="https://thegioifirewall.com/wp-content/uploads/1-5-1-1024x638.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-5-1-300x187.png 300w, https://thegioifirewall.com/wp-content/uploads/1-5-1-768x479.png 768w, https://thegioifirewall.com/wp-content/uploads/1-5-1-1536x958.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-5-1-2048x1277.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Việc xác thực thành công này cũng được thiết bị Palo Alto ghi lại log, để xem vào Monitor &gt; Authentication.</p>



<p class="wp-block-paragraph">Log này sẽ cung cấp cho các bạn biết được IP nào trong hệ thống đã xác thực và xác thực bằng user nào, user này được lấy từ đâu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="320" src="https://thegioifirewall.com/wp-content/uploads/1-2-1-1024x320.png" alt="" class="wp-image-10574" srcset="https://thegioifirewall.com/wp-content/uploads/1-2-1-1024x320.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-2-1-300x94.png 300w, https://thegioifirewall.com/wp-content/uploads/1-2-1-768x240.png 768w, https://thegioifirewall.com/wp-content/uploads/1-2-1-1536x480.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-2-1-2048x640.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-cau-hinh-captive-portal-xac-thuc-nguoi-dung-khi-truy-cap-internet-bang-tai-khoan-tu-ad/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
