<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hướng dẫn cấu hình IPSec VPN giữa Sophos và Palo Alto khi thiết bị Sophos nằm phía sau một thiết bị Sophos khác &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Tue, 07 Sep 2021 06:13:32 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Hướng dẫn cấu hình IPSec VPN giữa Sophos và Palo Alto khi thiết bị Sophos nằm phía sau một thiết bị Sophos khác &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hướng dẫn cấu hình IPSec VPN giữa Sophos và Palo Alto khi thiết bị Sophos nằm phía sau một thiết bị Sophos khác</title>
		<link>https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/</link>
					<comments>https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Mon, 06 Sep 2021 03:44:00 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Hướng dẫn cấu hình Firewall Sophos XG]]></category>
		<category><![CDATA[Hướng dẫn cấu hình IPSec VPN giữa Sophos và Palo Alto khi thiết bị Sophos nằm phía sau một thiết bị Sophos khác]]></category>
		<category><![CDATA[IPSec VPN]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=11852</guid>

					<description><![CDATA[1.Mục đích bài viết Trong bài viết này thegioifirewall sẽ hướng dẫn các bạn cách cấu hình IPSec VPN Site to site giữa thiết bị Sophos Firewall và Palo Alto với thiết bị Sophos nằm phía sau một thiết bị Sophos Firewall khác. 2.Sơ đồ mạng Chi tiết sơ đồ mạng: Head Office: Tại head [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>1.Mục đích bài viết</strong></h2>



<p class="wp-block-paragraph">Trong bài viết này thegioifirewall sẽ hướng dẫn các bạn cách cấu hình IPSec VPN Site to site giữa thiết bị Sophos Firewall và Palo Alto với thiết bị Sophos nằm phía sau một thiết bị Sophos Firewall khác.</p>



<h2 class="wp-block-heading"><strong>2.Sơ đồ mạng</strong></h2>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="582" src="https://thegioifirewall.com/wp-content/uploads/Drawing1-8-1024x582.png" alt="" class="wp-image-11853" srcset="https://thegioifirewall.com/wp-content/uploads/Drawing1-8-1024x582.png 1024w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8-300x170.png 300w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8-768x436.png 768w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8-1536x873.png 1536w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8.png 1772w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Chi tiết sơ đồ mạng:</strong></p>



<p class="wp-block-paragraph"><strong>Head Office:</strong></p>



<ul class="wp-block-list"><li>Tại head office site chúng ta sẽ có mô hình external và internal firewall với 2 thiết bị Sophos Firewal 1 là external firewall và Sophos Firewall 2 là internal firewall.</li><li>Đường truyền internet được kết nối tại Port 2 của thiết bị Sophos Firewall 1 với IP 192.168.2.111.</li><li>Mạng LAN của thiết bị Sophos Firewall 1 được cấu hình tại Port 1 với IP 10.145.41.1/24 và đã cấu hình DHCP để cấp phát cho các thiết bị kết nối tới nó.</li><li>Tại Sophos Firewall 2 cổng WAN sẽ là Port 2 và nó sẽ được kết nối đến Port 1 của Sophos Firewall 1, Port 2 trên Sophos Firewall 2 được đặt IP tĩnh là 10.145.41.50/24.</li><li>Mạng LAN của Sophos Firewall 2 được cấu hình tại Port 1 với IP 10.146.41.1/24 và đã được cấu hình DHCP.</li></ul>



<p class="wp-block-paragraph"><strong>Branch office:</strong></p>



<ul class="wp-block-list"><li>Đường truyền internet được kết nối tại port ethernet1/1 của thiết bị Palo Alto firewall với IP 192.168.2.115.</li><li>Mạng LAN được cấu hình tại port ethernet1/2 với IP 172.16.16.16/24 và đã cấu hình DHCP để cấp phát IP cho các thiết bị kết nối vào.</li></ul>



<h2 class="wp-block-heading"><strong>3.Tình huống cấu hình</strong></h2>



<p class="wp-block-paragraph">Dựa theo sơ đồ trên chúng ta sẽ cấu hình IPSec VPN Site to site giữa thiết bị Sophos Firewall 2 tại Head Office site và thiết bị Palo Alto Firewall 3 tại Branch Office site để cả 2 mạng LAN của 2 site có thể giao tiếp với nhau.</p>



<h2 class="wp-block-heading"><strong>4.Các bước cấu hình</strong></h2>



<p class="wp-block-paragraph"><strong>Sophos Firewall 1:</strong></p>



<ul class="wp-block-list"><li>Tạo profile cho IPSec service.</li><li>Tạo Profile cho IP WAN của Sophos Firewall 2.</li><li>Thực hiện NAT IP WAN của Sophos Firewall 2 với IPSec service ra internet.</li></ul>



<p class="wp-block-paragraph"><strong>Sophos Firewall 2:</strong></p>



<ul class="wp-block-list"><li>Tạo profile cho Local và Remote subnet.</li><li>Tạo IPSec policy.</li><li>Tạo kết nối IPSec connection.</li><li>Tạo policy cho phép traffic giữa 2 zone LAN và VPN.</li><li>Bật dịch vụ PING và HTTPS trên VPN zone.</li></ul>



<p class="wp-block-paragraph"><strong>Palo Alto Firewall:</strong></p>



<ul class="wp-block-list"><li>Tạo VPN zone.</li><li>Tạo Address Object.</li><li>Tạo tunnel interface.</li><li>Tạo Virtual Routers.</li><li>Tạo IKE Crypto.</li><li>Tạo IPSec Crypto.</li><li>Tạo IKE Gateways.</li><li>Tạo IPSec Tunnels.</li><li>Tạo policy.</li></ul>



<p class="wp-block-paragraph"><strong>Kiểm tra kết quả.</strong></p>



<h2 class="wp-block-heading"><strong>5.Hướng dẫn cấu hình.</strong></h2>



<h3 class="wp-block-heading"><strong>5.1.Sophos Firewall 1.</strong></h3>



<h4 class="wp-block-heading"><strong>5.1.1.Tạo profile cho IPSec service</strong></h4>



<p class="wp-block-paragraph">Kết nối IPSec VPN Site to site sẽ sử dụng các port là UDP 500 và UDP 4500.</p>



<p class="wp-block-paragraph">Chúng ta cần tạo profile cho 2 service này.</p>



<p class="wp-block-paragraph">Để tạo vào SYSTEM &gt; Hosts and services &gt; Services &gt; nhấn Add.</p>



<p class="wp-block-paragraph">Tạo với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: IPSec S2S VPN</li><li>Type*: chọn TCP/UDP.</li><li>Protocol: chọn UDP.</li><li>Source port: 1:65535.</li><li>Destination port: 500</li><li>Nhấn biểu tượng dấu + để thêm 1 hàng.</li><li>Protocol: chọn UDP.</li><li>Source port: 1:65535.</li><li>Destination port: 4500.</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="211" src="https://thegioifirewall.com/wp-content/uploads/1-40-1024x211.png" alt="" class="wp-image-11854" srcset="https://thegioifirewall.com/wp-content/uploads/1-40-1024x211.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-40-300x62.png 300w, https://thegioifirewall.com/wp-content/uploads/1-40-768x158.png 768w, https://thegioifirewall.com/wp-content/uploads/1-40-1536x316.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-40-2048x422.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.2.Tạo profile cho IP WAN của Sophos Firewall 2.</strong></h4>



<p class="wp-block-paragraph">Để tạo vào SYSTEM &gt; Hosts and services &gt; IP Host &gt; Nhấn Add.</p>



<p class="wp-block-paragraph">Tạo với các thông tin sau:</p>



<ul class="wp-block-list"><li>Name*: Sophos Firewall 2.</li><li>IP version*: chọn IPv4.</li><li>Type*: chọn IP.</li><li>IP address*: nhập IP WAN của Sophos Firewall 2 là 10.145.41.50.</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/2-35-1024x272.png" alt="" class="wp-image-11855" srcset="https://thegioifirewall.com/wp-content/uploads/2-35-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-35-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/2-35-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/2-35-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-35-2048x543.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.3.Thực hiện NAT IP WAN của Sophos Firewall 2 với IPSec service ra ngoài internet.</strong></h4>



<p class="wp-block-paragraph">Để NAT chúng ta vào PROTECT &gt; Rules and policies &gt; Add firewall rule &gt; Server access assistant [DNAT].</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="451" src="https://thegioifirewall.com/wp-content/uploads/3-40-1024x451.png" alt="" class="wp-image-11856" srcset="https://thegioifirewall.com/wp-content/uploads/3-40-1024x451.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-40-300x132.png 300w, https://thegioifirewall.com/wp-content/uploads/3-40-768x338.png 768w, https://thegioifirewall.com/wp-content/uploads/3-40-1536x677.png 1536w, https://thegioifirewall.com/wp-content/uploads/3-40-2048x902.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Sau khi nhấn vào Server access assistant [DNAT] một bảng cấu hình hiện lên.</p>



<p class="wp-block-paragraph">Ở Internal server IP address chúng ta tích chọn Select IP host và chọn Sophos Firewall 2 – 10.145.41.50 từ danh sách thả xuống.</p>



<p class="wp-block-paragraph">Nhấn Next để tiếp tục.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="274" src="https://thegioifirewall.com/wp-content/uploads/4-40-1024x274.png" alt="" class="wp-image-11857" srcset="https://thegioifirewall.com/wp-content/uploads/4-40-1024x274.png 1024w, https://thegioifirewall.com/wp-content/uploads/4-40-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/4-40-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/4-40-1536x410.png 1536w, https://thegioifirewall.com/wp-content/uploads/4-40-2048x547.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Public IP address tích chọn Select public ip address or WAN interface và chọn #Port 2 – 192.168.2.111 từ danh sách thả xuống.</p>



<p class="wp-block-paragraph">Nhấn Next để tiếp tục.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="273" src="https://thegioifirewall.com/wp-content/uploads/5-37-1024x273.png" alt="" class="wp-image-11858" srcset="https://thegioifirewall.com/wp-content/uploads/5-37-1024x273.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-37-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/5-37-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/5-37-1536x410.png 1536w, https://thegioifirewall.com/wp-content/uploads/5-37-2048x547.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Service nhấn Add new item và chọn profile IPSec S2S VPN.</p>



<p class="wp-block-paragraph">Nhấn Next để tiếp tục.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="284" src="https://thegioifirewall.com/wp-content/uploads/6-38-1024x284.png" alt="" class="wp-image-11859" srcset="https://thegioifirewall.com/wp-content/uploads/6-38-1024x284.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-38-300x83.png 300w, https://thegioifirewall.com/wp-content/uploads/6-38-768x213.png 768w, https://thegioifirewall.com/wp-content/uploads/6-38-1536x426.png 1536w, https://thegioifirewall.com/wp-content/uploads/6-38-2048x568.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở External source networks or devices giữ nguyên lựa chọn Any và nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="282" src="https://thegioifirewall.com/wp-content/uploads/7-32-1024x282.png" alt="" class="wp-image-11860" srcset="https://thegioifirewall.com/wp-content/uploads/7-32-1024x282.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-32-300x83.png 300w, https://thegioifirewall.com/wp-content/uploads/7-32-768x211.png 768w, https://thegioifirewall.com/wp-content/uploads/7-32-1536x423.png 1536w, https://thegioifirewall.com/wp-content/uploads/7-32-2048x564.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cuối cùng là bước review các lựa chọn đã chọn trước đó, nếu đã chọn đúng nhấn Save and finish để hoàn thành.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="787" src="https://thegioifirewall.com/wp-content/uploads/8-31-1024x787.png" alt="" class="wp-image-11861" srcset="https://thegioifirewall.com/wp-content/uploads/8-31-1024x787.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-31-300x231.png 300w, https://thegioifirewall.com/wp-content/uploads/8-31-768x591.png 768w, https://thegioifirewall.com/wp-content/uploads/8-31-1536x1181.png 1536w, https://thegioifirewall.com/wp-content/uploads/8-31.png 1883w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.2.Sophos Firewall 2</strong></h3>



<h4 class="wp-block-heading"><strong>5.2.1.Tạo profile cho Local và Remote subnet</strong></h4>



<p class="wp-block-paragraph">Chúng ta sẽ thực hiện tạo profile cho Local và Remote subnet.</p>



<p class="wp-block-paragraph">Để tạo vào SYSTEM &gt; Hosts and Services &gt; IP Host &gt; nhấn Add.</p>



<p class="wp-block-paragraph">Tạo profile cho Local subnet với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: SF2_LAN.</li><li>IP version*: IPv4.</li><li>Type*: Network.</li><li>IP address*: 10.146.41.0 Subnet /24[255.255.255.0]</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="262" src="https://thegioifirewall.com/wp-content/uploads/9-33-1024x262.png" alt="" class="wp-image-11862" srcset="https://thegioifirewall.com/wp-content/uploads/9-33-1024x262.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-33-300x77.png 300w, https://thegioifirewall.com/wp-content/uploads/9-33-768x197.png 768w, https://thegioifirewall.com/wp-content/uploads/9-33-1536x393.png 1536w, https://thegioifirewall.com/wp-content/uploads/9-33-2048x524.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tương tự các bước trên chúng ta sẽ tạo profile cho Remote subnet theo các thông số sau:</p>



<p class="wp-block-paragraph">Name*: PA_LAN.</p>



<p class="wp-block-paragraph">IP version*: IPv4.</p>



<p class="wp-block-paragraph">Type*: Network.</p>



<p class="wp-block-paragraph">IP address*: 172.16.16.0 Subnet /24[255.255.255.0]</p>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="261" src="https://thegioifirewall.com/wp-content/uploads/10-28-1024x261.png" alt="" class="wp-image-11863" srcset="https://thegioifirewall.com/wp-content/uploads/10-28-1024x261.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-28-300x76.png 300w, https://thegioifirewall.com/wp-content/uploads/10-28-768x196.png 768w, https://thegioifirewall.com/wp-content/uploads/10-28-1536x392.png 1536w, https://thegioifirewall.com/wp-content/uploads/10-28-2048x522.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.2.Tạo IPSec policy</strong></h4>



<p class="wp-block-paragraph">Do đây là kết nối IPSec VPN giữa 2 thiết bị khác hãng nên chúng ta cần tạo IPSec policy chung cho cả 2 thiết bị.</p>



<p class="wp-block-paragraph">Để tạo IPSec policy vào CONFIGURE &gt; VPN &gt; IPSec policies &gt; Nhấn Add.</p>



<p class="wp-block-paragraph">Tạo IPSec policy với các thông số sau.</p>



<p class="wp-block-paragraph">General settings:</p>



<ul class="wp-block-list"><li>Name: VPN_S2S_PaloAlto.</li><li>Key exchange: IKEv2.</li><li>Authentication mode: Main mode</li><li>Tích chọn Re-key connection.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="322" src="https://thegioifirewall.com/wp-content/uploads/19-17-1024x322.png" alt="" class="wp-image-11864" srcset="https://thegioifirewall.com/wp-content/uploads/19-17-1024x322.png 1024w, https://thegioifirewall.com/wp-content/uploads/19-17-300x94.png 300w, https://thegioifirewall.com/wp-content/uploads/19-17-768x241.png 768w, https://thegioifirewall.com/wp-content/uploads/19-17-1536x482.png 1536w, https://thegioifirewall.com/wp-content/uploads/19-17-2048x643.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Phrase 1:</p>



<ul class="wp-block-list"><li>Key life: 5400.</li><li>Re-key margin: 360.</li><li>Randomize re-keying margin by: 50.</li><li>DH group (key group): 2 (DH1024).</li><li>Encryption: AES256.</li><li>Authentication: SHA2 256.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="325" src="https://thegioifirewall.com/wp-content/uploads/20-14-1024x325.png" alt="" class="wp-image-11865" srcset="https://thegioifirewall.com/wp-content/uploads/20-14-1024x325.png 1024w, https://thegioifirewall.com/wp-content/uploads/20-14-300x95.png 300w, https://thegioifirewall.com/wp-content/uploads/20-14-768x244.png 768w, https://thegioifirewall.com/wp-content/uploads/20-14-1536x487.png 1536w, https://thegioifirewall.com/wp-content/uploads/20-14-2048x650.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Phrase 2:</p>



<ul class="wp-block-list"><li>PFS group (DH group): None.</li><li>Key life: 3600.</li><li>Encryption: AES128.</li><li>Authentication: SHA2 256.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="264" src="https://thegioifirewall.com/wp-content/uploads/21-13-1024x264.png" alt="" class="wp-image-11866" srcset="https://thegioifirewall.com/wp-content/uploads/21-13-1024x264.png 1024w, https://thegioifirewall.com/wp-content/uploads/21-13-300x77.png 300w, https://thegioifirewall.com/wp-content/uploads/21-13-768x198.png 768w, https://thegioifirewall.com/wp-content/uploads/21-13-1536x395.png 1536w, https://thegioifirewall.com/wp-content/uploads/21-13-2048x527.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Dead Peer Detection:</p>



<ul class="wp-block-list"><li>Dead Peer Detection: tích chọn.</li><li>Check peer after every: 30.</li><li>Wait for response up to: 120.</li><li>When peer unreachable: Re-initiate.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="187" src="https://thegioifirewall.com/wp-content/uploads/22-9-1024x187.png" alt="" class="wp-image-11867" srcset="https://thegioifirewall.com/wp-content/uploads/22-9-1024x187.png 1024w, https://thegioifirewall.com/wp-content/uploads/22-9-300x55.png 300w, https://thegioifirewall.com/wp-content/uploads/22-9-768x140.png 768w, https://thegioifirewall.com/wp-content/uploads/22-9-1536x280.png 1536w, https://thegioifirewall.com/wp-content/uploads/22-9-2048x373.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<h4 class="wp-block-heading"><strong>5.2.3.Tạo kết nối IPSec connection</strong></h4>



<p class="wp-block-paragraph">Để tạo chúng ta vào CONFIGURE &gt; VPN &gt; IPSec connections &gt; nhấn Add.</p>



<p class="wp-block-paragraph">Ở General chúng ta cấu hình với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: VPN_SOPHOS_TO_PA.</li><li>IP version: IPv4.</li><li>Connection type: Site-to-site.</li><li>Gateway type: Respond only.</li><li>Active on save: bỏ chọn.</li><li>Create firewall rule: bỏ chọn.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="274" src="https://thegioifirewall.com/wp-content/uploads/11-29-1024x274.png" alt="" class="wp-image-11868" srcset="https://thegioifirewall.com/wp-content/uploads/11-29-1024x274.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-29-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/11-29-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/11-29-1536x411.png 1536w, https://thegioifirewall.com/wp-content/uploads/11-29-2048x548.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Encryption chúng ta cấu hình với các thông số sau:</p>



<ul class="wp-block-list"><li>Policy: chọn VPN_S2S_PaloAlto.</li><li>Authentication type: chọn Preshared key.</li><li>Preshared key: nhập mật khẩu kết nối.</li><li>Repeat preshared key: nhập lại mật khẩu kết nối.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="281" src="https://thegioifirewall.com/wp-content/uploads/12-27-1024x281.png" alt="" class="wp-image-11869" srcset="https://thegioifirewall.com/wp-content/uploads/12-27-1024x281.png 1024w, https://thegioifirewall.com/wp-content/uploads/12-27-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/12-27-768x211.png 768w, https://thegioifirewall.com/wp-content/uploads/12-27-1536x422.png 1536w, https://thegioifirewall.com/wp-content/uploads/12-27-2048x563.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Gateway settings chúng ta cấu hình theo các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Local Gateway:</strong></p>



<ul class="wp-block-list"><li>Listening interface: chọn Port2 – 10.145.41.50.</li><li>Local ID type: chọn IP address.</li><li>Local ID: nhập 10.145.41.50.</li><li>Local subnet: chọn profile SF2_LAN.</li></ul>



<p class="wp-block-paragraph"><strong>Remote Gateway:</strong></p>



<ul class="wp-block-list"><li>Gateway address: nhập IP WAN của Palo Alto firewall là 192.168.2.115.</li><li>Remote ID type: chọn IP address.</li><li>Remote ID: nhập 192.168.2.115.</li><li>Remote subnet: chọn profile PA_LAN.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="480" src="https://thegioifirewall.com/wp-content/uploads/13-23-1024x480.png" alt="" class="wp-image-11870" srcset="https://thegioifirewall.com/wp-content/uploads/13-23-1024x480.png 1024w, https://thegioifirewall.com/wp-content/uploads/13-23-300x141.png 300w, https://thegioifirewall.com/wp-content/uploads/13-23-768x360.png 768w, https://thegioifirewall.com/wp-content/uploads/13-23-1536x719.png 1536w, https://thegioifirewall.com/wp-content/uploads/13-23-2048x959.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<p class="wp-block-paragraph">Sau khi nhấn Save kết nối IPSec sẽ được tạo như hình dưới đây.</p>



<p class="wp-block-paragraph">Tuy nhiên kết nối này vẫn chưa được bật, để bật nhấn vào biểu tượng hình tròn tại cột Active và nhấn OK.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="238" src="https://thegioifirewall.com/wp-content/uploads/14-22-1024x238.png" alt="" class="wp-image-11871" srcset="https://thegioifirewall.com/wp-content/uploads/14-22-1024x238.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-22-300x70.png 300w, https://thegioifirewall.com/wp-content/uploads/14-22-768x178.png 768w, https://thegioifirewall.com/wp-content/uploads/14-22-1536x357.png 1536w, https://thegioifirewall.com/wp-content/uploads/14-22-2048x476.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Lúc này biểu tượng hình tròn tại cột Active chuyển sang màu xanh lá tức là đã bật kết nối thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="232" src="https://thegioifirewall.com/wp-content/uploads/15-21-1024x232.png" alt="" class="wp-image-11872" srcset="https://thegioifirewall.com/wp-content/uploads/15-21-1024x232.png 1024w, https://thegioifirewall.com/wp-content/uploads/15-21-300x68.png 300w, https://thegioifirewall.com/wp-content/uploads/15-21-768x174.png 768w, https://thegioifirewall.com/wp-content/uploads/15-21-1536x348.png 1536w, https://thegioifirewall.com/wp-content/uploads/15-21-2048x464.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.4.Tạo policy cho phép traffic giữa 2 zone LAN và VPN.</strong></h4>



<p class="wp-block-paragraph">Mặc định tường lửa sẽ khóa hết các traffic qua lại giữa các zone.</p>



<p class="wp-block-paragraph">Vì vậy chúng ta cần tạo policy để cho phép các traffic qua lại giữa 2 zone LAN và VPN.</p>



<p class="wp-block-paragraph">Để tạo vào PROTECT &gt; Rules and policies &gt; Add firewall rule và tạo policy theo như hình sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="726" src="https://thegioifirewall.com/wp-content/uploads/16-21-1024x726.png" alt="" class="wp-image-11873" srcset="https://thegioifirewall.com/wp-content/uploads/16-21-1024x726.png 1024w, https://thegioifirewall.com/wp-content/uploads/16-21-300x213.png 300w, https://thegioifirewall.com/wp-content/uploads/16-21-768x545.png 768w, https://thegioifirewall.com/wp-content/uploads/16-21-1536x1089.png 1536w, https://thegioifirewall.com/wp-content/uploads/16-21.png 1582w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="746" src="https://thegioifirewall.com/wp-content/uploads/17-19-1024x746.png" alt="" class="wp-image-11874" srcset="https://thegioifirewall.com/wp-content/uploads/17-19-1024x746.png 1024w, https://thegioifirewall.com/wp-content/uploads/17-19-300x218.png 300w, https://thegioifirewall.com/wp-content/uploads/17-19-768x559.png 768w, https://thegioifirewall.com/wp-content/uploads/17-19-1536x1118.png 1536w, https://thegioifirewall.com/wp-content/uploads/17-19.png 1585w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<h4 class="wp-block-heading"><strong>5.2.5.Bật dịch vụ PING và HTTPS trên VPN zone.</strong></h4>



<p class="wp-block-paragraph">Mặc định trên VPN zone sẽ tắt hết các dịch vụ.</p>



<p class="wp-block-paragraph">Để bật vào SYSTEM &gt; Administration &gt; Device Access.</p>



<p class="wp-block-paragraph">Tích chọn 2 dịch vụ HTTPS và Ping/Ping6 tại hàng VPN zone và nhấn Apply để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="415" src="https://thegioifirewall.com/wp-content/uploads/18-18-1024x415.png" alt="" class="wp-image-11875" srcset="https://thegioifirewall.com/wp-content/uploads/18-18-1024x415.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-18-300x122.png 300w, https://thegioifirewall.com/wp-content/uploads/18-18-768x311.png 768w, https://thegioifirewall.com/wp-content/uploads/18-18-1536x622.png 1536w, https://thegioifirewall.com/wp-content/uploads/18-18-2048x830.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.3.Palo Alto Firewall</strong></h3>



<h4 class="wp-block-heading"><strong>5.3.1.Tạo Zone</strong></h4>



<p class="wp-block-paragraph">Chúng ta cần tạo zone cho các kết nối VPN.</p>



<p class="wp-block-paragraph">Để tạo vào Network &gt; Zones.</p>



<p class="wp-block-paragraph">Nhấn Add và tạo theo các thông tin sau:</p>



<ul class="wp-block-list"><li>Name: VPN</li><li>Type: Layer3</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="761" src="https://thegioifirewall.com/wp-content/uploads/23-9-1024x761.png" alt="" class="wp-image-11876" srcset="https://thegioifirewall.com/wp-content/uploads/23-9-1024x761.png 1024w, https://thegioifirewall.com/wp-content/uploads/23-9-300x223.png 300w, https://thegioifirewall.com/wp-content/uploads/23-9-768x571.png 768w, https://thegioifirewall.com/wp-content/uploads/23-9-1536x1141.png 1536w, https://thegioifirewall.com/wp-content/uploads/23-9.png 1750w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.2.Tạo Address Object</strong></h4>



<p class="wp-block-paragraph">Chúng ta sẽ tạo Address Object cho 2 lớp mạng LAN của thiết bị Palo Alto và Sophos.</p>



<p class="wp-block-paragraph">Để tạo vào Object &gt; Addresses.</p>



<p class="wp-block-paragraph">Nhấn Add và tạo theo các thông số như sau.</p>



<p class="wp-block-paragraph">Palo Alto LAN:</p>



<ul class="wp-block-list"><li>Name: PA_LAN</li><li>Type: IP Netmask – 172.16.16.0/24</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="306" src="https://thegioifirewall.com/wp-content/uploads/24-12-1024x306.png" alt="" class="wp-image-11877" srcset="https://thegioifirewall.com/wp-content/uploads/24-12-1024x306.png 1024w, https://thegioifirewall.com/wp-content/uploads/24-12-300x90.png 300w, https://thegioifirewall.com/wp-content/uploads/24-12-768x229.png 768w, https://thegioifirewall.com/wp-content/uploads/24-12-1536x459.png 1536w, https://thegioifirewall.com/wp-content/uploads/24-12.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Sophos Firewall 2 LAN:</p>



<ul class="wp-block-list"><li>Name: SF2_LAN</li><li>Type: IP Netmask – 10.146.41.0/24</li><li>Nhấn OK để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="306" src="https://thegioifirewall.com/wp-content/uploads/25-11-1024x306.png" alt="" class="wp-image-11878" srcset="https://thegioifirewall.com/wp-content/uploads/25-11-1024x306.png 1024w, https://thegioifirewall.com/wp-content/uploads/25-11-300x90.png 300w, https://thegioifirewall.com/wp-content/uploads/25-11-768x230.png 768w, https://thegioifirewall.com/wp-content/uploads/25-11-1536x460.png 1536w, https://thegioifirewall.com/wp-content/uploads/25-11.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.3.Tạo Interface Tunnel</strong></h4>



<p class="wp-block-paragraph">Để tạo vào Network &gt; Interface &gt; Tunnel.</p>



<p class="wp-block-paragraph">Nhấn Add và tạo theo các thông tin như sau:</p>



<ul class="wp-block-list"><li>Interface Name: tunnel – 2</li><li>Virtual Router: None</li><li>Security Zone: VPN</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="438" src="https://thegioifirewall.com/wp-content/uploads/26-10-1024x438.png" alt="" class="wp-image-11879" srcset="https://thegioifirewall.com/wp-content/uploads/26-10-1024x438.png 1024w, https://thegioifirewall.com/wp-content/uploads/26-10-300x128.png 300w, https://thegioifirewall.com/wp-content/uploads/26-10-768x329.png 768w, https://thegioifirewall.com/wp-content/uploads/26-10-1536x657.png 1536w, https://thegioifirewall.com/wp-content/uploads/26-10.png 1748w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.4.Tạo Virtual Routers</strong></h4>



<p class="wp-block-paragraph">Để tạo Virtual Routers vào Network &gt; Virtual Routers &gt; nhấn Add và cấu hình theo các thông tin sau.</p>



<p class="wp-block-paragraph">Tab Router Settings:</p>



<ul class="wp-block-list"><li>Name: VR1</li><li>Tab General: nhấn Add và chọn các cổng ethernet1/2 (cổng LAN), ethernet1/1(cổng internet) và tunnel.2(là tunnel dùng để kết nối VPN).</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="640" src="https://thegioifirewall.com/wp-content/uploads/27-10-1024x640.png" alt="" class="wp-image-11880" srcset="https://thegioifirewall.com/wp-content/uploads/27-10-1024x640.png 1024w, https://thegioifirewall.com/wp-content/uploads/27-10-300x188.png 300w, https://thegioifirewall.com/wp-content/uploads/27-10-768x480.png 768w, https://thegioifirewall.com/wp-content/uploads/27-10-1536x960.png 1536w, https://thegioifirewall.com/wp-content/uploads/27-10.png 2000w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Static Routes &gt; IPv4:</p>



<p class="wp-block-paragraph">Nhấn Add để thêm static routes và điền vào các thông tin sau:</p>



<ul class="wp-block-list"><li>Name: Route-1</li><li>Destination: SF2_LAN</li><li>Interface: tunnel.2</li><li>Nhấn OK 2 lần để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="862" src="https://thegioifirewall.com/wp-content/uploads/28-11-1024x862.png" alt="" class="wp-image-11881" srcset="https://thegioifirewall.com/wp-content/uploads/28-11-1024x862.png 1024w, https://thegioifirewall.com/wp-content/uploads/28-11-300x253.png 300w, https://thegioifirewall.com/wp-content/uploads/28-11-768x646.png 768w, https://thegioifirewall.com/wp-content/uploads/28-11.png 1498w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.5.Tạo IKE Crypto</strong></h4>



<p class="wp-block-paragraph">Chúng ta sẽ tạo IKE Crypto tức Phrase 1 cho kết nối VPN.</p>



<p class="wp-block-paragraph">Để tạo vào Network &gt; IKE Crypto nhấn Add và tạo theo các thông tin sau:</p>



<ul class="wp-block-list"><li>Name: IKE_Crypto_Phrase1</li><li>DH Group: group2</li><li>Encryption: aes-256-cbc</li><li>Authentication: sha256</li><li>Key Lifetime: Seconds – 5400</li><li>Nhấn OK Để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="508" src="https://thegioifirewall.com/wp-content/uploads/29-8-1024x508.png" alt="" class="wp-image-11882" srcset="https://thegioifirewall.com/wp-content/uploads/29-8-1024x508.png 1024w, https://thegioifirewall.com/wp-content/uploads/29-8-300x149.png 300w, https://thegioifirewall.com/wp-content/uploads/29-8-768x381.png 768w, https://thegioifirewall.com/wp-content/uploads/29-8-1536x763.png 1536w, https://thegioifirewall.com/wp-content/uploads/29-8.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.6.Tạo IPSec Crypto</strong></h4>



<p class="wp-block-paragraph">Để tạo IPSec Crypto vào Network &gt; IPSec Crypto và nhấn Add.</p>



<p class="wp-block-paragraph">Cấu hình theo các thông số sau:</p>



<ul class="wp-block-list"><li>Name: IPSec_Crypto_Phrase2</li><li>IPSec Protocol: ESP</li><li>Encryption: aes-128-cbc</li><li>Authentication: sha256</li><li>DH Group: no-pfs</li><li>Lifetime: Seconds – 3600</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="545" src="https://thegioifirewall.com/wp-content/uploads/30-8-1024x545.png" alt="" class="wp-image-11883" srcset="https://thegioifirewall.com/wp-content/uploads/30-8-1024x545.png 1024w, https://thegioifirewall.com/wp-content/uploads/30-8-300x160.png 300w, https://thegioifirewall.com/wp-content/uploads/30-8-768x408.png 768w, https://thegioifirewall.com/wp-content/uploads/30-8-1536x817.png 1536w, https://thegioifirewall.com/wp-content/uploads/30-8.png 1999w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.7.Tạo IKE Gateways</strong></h4>



<p class="wp-block-paragraph">Để tao vào Network &gt; IKE Gateways và nhấn Add.</p>



<p class="wp-block-paragraph">Cấu hình theo các thông số sau</p>



<p class="wp-block-paragraph">Bảng General:</p>



<ul class="wp-block-list"><li>Name: IKE_Gateway</li><li>Version: IKEv2 only mode</li><li>Address Type: IPv4</li><li>Interface: ethernet1/1 (cổng WAN của Palo Alto)</li><li>Local IP Address: None</li><li>Peer Address: Nhập IP WAN của Sophos Firewall 1 là 192.168.2.111</li><li>Authentication: Pre-shared Key</li><li>Pre-shared key: nhập mật khẩu kết nối (mật khẩu này phải giống với mật khẩu đã đặt trên Sophos)</li><li>Confirm Pre-shared key: nhập lại mật khẩu kết nối.</li><li>Local Identification: chọn IP address – nhập 192.168.2.115.</li><li>Peer Identification: chọn IP address – nhập IP WAN của Sophos Firewall 2 là 10.145.41.50</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="788" src="https://thegioifirewall.com/wp-content/uploads/31-9-1024x788.png" alt="" class="wp-image-11884" srcset="https://thegioifirewall.com/wp-content/uploads/31-9-1024x788.png 1024w, https://thegioifirewall.com/wp-content/uploads/31-9-300x231.png 300w, https://thegioifirewall.com/wp-content/uploads/31-9-768x591.png 768w, https://thegioifirewall.com/wp-content/uploads/31-9.png 1490w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Bảng Advanced Options:</p>



<ul class="wp-block-list"><li>IKE Crypto Profile: chọn IKE_Crypto_Phrase1</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="635" src="https://thegioifirewall.com/wp-content/uploads/32-5-1024x635.png" alt="" class="wp-image-11885" srcset="https://thegioifirewall.com/wp-content/uploads/32-5-1024x635.png 1024w, https://thegioifirewall.com/wp-content/uploads/32-5-300x186.png 300w, https://thegioifirewall.com/wp-content/uploads/32-5-768x476.png 768w, https://thegioifirewall.com/wp-content/uploads/32-5.png 1497w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.8.Tạo IPSec Tunnels</strong></h4>



<p class="wp-block-paragraph">Giờ chúng ta sẽ bắt đầu tạo kết nối VPN với thiết bị Sophos Firewall.</p>



<p class="wp-block-paragraph">Để tạo vào Network &gt; IPSec Tunnels và nhấn Add.</p>



<p class="wp-block-paragraph">Tạo với các thông tin như sau.</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: VPN_PA_TO_SOPHOS</li><li>Tunnel Interface: tunnel.2</li><li>Type: Auto Key</li><li>Address Type: IPv4</li><li>IKE Gateways: IKE_Gateway</li><li>IPSec Crypto Profile: IPSec_Crypto_Phrase2</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="410" src="https://thegioifirewall.com/wp-content/uploads/33-5-1024x410.png" alt="" class="wp-image-11886" srcset="https://thegioifirewall.com/wp-content/uploads/33-5-1024x410.png 1024w, https://thegioifirewall.com/wp-content/uploads/33-5-300x120.png 300w, https://thegioifirewall.com/wp-content/uploads/33-5-768x308.png 768w, https://thegioifirewall.com/wp-content/uploads/33-5-1536x615.png 1536w, https://thegioifirewall.com/wp-content/uploads/33-5.png 1993w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Proxy IDs:</p>



<p class="wp-block-paragraph">Nhấn Add và cấu hình các thông tin sau:</p>



<ul class="wp-block-list"><li>Proxy ID: Peer-1</li><li>Local: 172.16.16.0/24</li><li>Remote: 10.146.41.0/24</li><li>Protocol: Any</li><li>Nhấn OK 2 lần để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="453" src="https://thegioifirewall.com/wp-content/uploads/34-3-1024x453.png" alt="" class="wp-image-11887" srcset="https://thegioifirewall.com/wp-content/uploads/34-3-1024x453.png 1024w, https://thegioifirewall.com/wp-content/uploads/34-3-300x133.png 300w, https://thegioifirewall.com/wp-content/uploads/34-3-768x340.png 768w, https://thegioifirewall.com/wp-content/uploads/34-3.png 1201w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="592" src="https://thegioifirewall.com/wp-content/uploads/35-3-1024x592.png" alt="" class="wp-image-11888" srcset="https://thegioifirewall.com/wp-content/uploads/35-3-1024x592.png 1024w, https://thegioifirewall.com/wp-content/uploads/35-3-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/35-3-768x444.png 768w, https://thegioifirewall.com/wp-content/uploads/35-3-1536x889.png 1536w, https://thegioifirewall.com/wp-content/uploads/35-3.png 2000w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.9.Tạo Policy</strong></h4>



<p class="wp-block-paragraph">Chúng ta cần tạo policy cho phép các traffic từ lớp mạng LAN của Palo Alto đi qua lớp mạng LAN của Sophos Firewall và ngược lại.</p>



<p class="wp-block-paragraph">Để tạo policy vào Policies &gt; Security và nhấn Add.</p>



<p class="wp-block-paragraph">Tạo policy cho phép traffic từ lớp mạng LAN của Palo Alto đi qua lớp mạng LAN của Sophos Firewall với các thông tin như sau:</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: LAN_TO_VPN</li><li>Rule Type: universal (default)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="565" src="https://thegioifirewall.com/wp-content/uploads/36-2-1024x565.png" alt="" class="wp-image-11889" srcset="https://thegioifirewall.com/wp-content/uploads/36-2-1024x565.png 1024w, https://thegioifirewall.com/wp-content/uploads/36-2-300x166.png 300w, https://thegioifirewall.com/wp-content/uploads/36-2-768x424.png 768w, https://thegioifirewall.com/wp-content/uploads/36-2-1536x848.png 1536w, https://thegioifirewall.com/wp-content/uploads/36-2.png 1743w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Source:</p>



<ul class="wp-block-list"><li>Source Zone: nhấn Add và chọn Trust-Layer3 (Đây là zone của lớp LAN)</li><li>Source Address: nhấn Add và chọn PA_LAN (PA_LAN là Address Object mà chúng ta đã tạo trước đó)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://thegioifirewall.com/wp-content/uploads/37-2-1024x600.png" alt="" class="wp-image-11890" srcset="https://thegioifirewall.com/wp-content/uploads/37-2-1024x600.png 1024w, https://thegioifirewall.com/wp-content/uploads/37-2-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/37-2-768x450.png 768w, https://thegioifirewall.com/wp-content/uploads/37-2-1536x900.png 1536w, https://thegioifirewall.com/wp-content/uploads/37-2.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Destination:</p>



<ul class="wp-block-list"><li>Destination Zone: VPN</li><li>Destination Address: SF2-LAN (đây là Address Object đã tạo lúc đầu)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="595" src="https://thegioifirewall.com/wp-content/uploads/38-2-1024x595.png" alt="" class="wp-image-11891" srcset="https://thegioifirewall.com/wp-content/uploads/38-2-1024x595.png 1024w, https://thegioifirewall.com/wp-content/uploads/38-2-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/38-2-768x446.png 768w, https://thegioifirewall.com/wp-content/uploads/38-2-1536x892.png 1536w, https://thegioifirewall.com/wp-content/uploads/38-2.png 1740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Action:</p>



<ul class="wp-block-list"><li>Action: chọn Allow để cho phép.</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="521" src="https://thegioifirewall.com/wp-content/uploads/39-2-1024x521.png" alt="" class="wp-image-11892" srcset="https://thegioifirewall.com/wp-content/uploads/39-2-1024x521.png 1024w, https://thegioifirewall.com/wp-content/uploads/39-2-300x153.png 300w, https://thegioifirewall.com/wp-content/uploads/39-2-768x390.png 768w, https://thegioifirewall.com/wp-content/uploads/39-2-1536x781.png 1536w, https://thegioifirewall.com/wp-content/uploads/39-2.png 1735w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tiếp theo chúng ta sẽ nhấn Add và tạo policy cho phép các traffic đi từ lớp mạng LAN của Sophos Firewall sang lớp mạng LAN của Palo Alto với các thông tin sau:</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: VPN_TO_LAN</li><li>Rule Type: universal (default)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="564" src="https://thegioifirewall.com/wp-content/uploads/40-3-1024x564.png" alt="" class="wp-image-11893" srcset="https://thegioifirewall.com/wp-content/uploads/40-3-1024x564.png 1024w, https://thegioifirewall.com/wp-content/uploads/40-3-300x165.png 300w, https://thegioifirewall.com/wp-content/uploads/40-3-768x423.png 768w, https://thegioifirewall.com/wp-content/uploads/40-3-1536x846.png 1536w, https://thegioifirewall.com/wp-content/uploads/40-3.png 1743w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Source:</p>



<ul class="wp-block-list"><li>Source Zone: nhấn Add và chọn VPN</li><li>Source Address: nhấn Add và chọn SF2_LAN (SF2_LAN là Address Object mà chúng ta đã tạo trước đó)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="601" src="https://thegioifirewall.com/wp-content/uploads/41-3-1024x601.png" alt="" class="wp-image-11894" srcset="https://thegioifirewall.com/wp-content/uploads/41-3-1024x601.png 1024w, https://thegioifirewall.com/wp-content/uploads/41-3-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/41-3-768x451.png 768w, https://thegioifirewall.com/wp-content/uploads/41-3-1536x902.png 1536w, https://thegioifirewall.com/wp-content/uploads/41-3.png 1747w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Destination:</p>



<ul class="wp-block-list"><li>Destination Zone: Trust-Layer3 (Zone của lớp mạng LAN)</li><li>Destination Address: PA-LAN (đây là Address Object đã tạo lúc đầu)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://thegioifirewall.com/wp-content/uploads/42-2-1024x600.png" alt="" class="wp-image-11895" srcset="https://thegioifirewall.com/wp-content/uploads/42-2-1024x600.png 1024w, https://thegioifirewall.com/wp-content/uploads/42-2-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/42-2-768x450.png 768w, https://thegioifirewall.com/wp-content/uploads/42-2-1536x899.png 1536w, https://thegioifirewall.com/wp-content/uploads/42-2.png 1747w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Action:</p>



<ul class="wp-block-list"><li>Action: chọn Allow để cho phép.</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="526" src="https://thegioifirewall.com/wp-content/uploads/43-2-1024x526.png" alt="" class="wp-image-11896" srcset="https://thegioifirewall.com/wp-content/uploads/43-2-1024x526.png 1024w, https://thegioifirewall.com/wp-content/uploads/43-2-300x154.png 300w, https://thegioifirewall.com/wp-content/uploads/43-2-768x395.png 768w, https://thegioifirewall.com/wp-content/uploads/43-2-1536x789.png 1536w, https://thegioifirewall.com/wp-content/uploads/43-2.png 1734w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.4.Kiểm tra kết quả.</strong></h3>



<p class="wp-block-paragraph">Trên thiết bị Palo Alto sau khi tạo kết nối IPSec tunnels thì kết nối sẽ được liệt kê ra như hình dưới.</p>



<p class="wp-block-paragraph">Chúng ta chú ý đến cột Status chúng ta thấy rằng biểu tượng port mạng đang là màu xanh tức kết nối IPSec này đã được Enable.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="173" src="https://thegioifirewall.com/wp-content/uploads/44-2-1024x173.png" alt="" class="wp-image-11897" srcset="https://thegioifirewall.com/wp-content/uploads/44-2-1024x173.png 1024w, https://thegioifirewall.com/wp-content/uploads/44-2-300x51.png 300w, https://thegioifirewall.com/wp-content/uploads/44-2-768x130.png 768w, https://thegioifirewall.com/wp-content/uploads/44-2-1536x260.png 1536w, https://thegioifirewall.com/wp-content/uploads/44-2-2048x346.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để kích hoạt kết nối IPSec giữa 2 thiết bị chúng ta vào thiết bị Sophos Firewall &gt; CONFIGURE &gt; VPN &gt; IPSec connections.</p>



<p class="wp-block-paragraph">Chúng ta chú ý đến biểu tượng hình tròn tại cột Connection của kết nối IPSec VPN mà chúng ta đã tạo trước đó đang là màu đỏ tức kết nối chưa được kích hoạt đến thiết bị Palo Alto firewall.</p>



<p class="wp-block-paragraph">Để kích hoạt nhấn chuột trái vào biểu tượng hình tròn tại cột Connection và nhấn Yes.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="239" src="https://thegioifirewall.com/wp-content/uploads/45-2-1024x239.png" alt="" class="wp-image-11898" srcset="https://thegioifirewall.com/wp-content/uploads/45-2-1024x239.png 1024w, https://thegioifirewall.com/wp-content/uploads/45-2-300x70.png 300w, https://thegioifirewall.com/wp-content/uploads/45-2-768x179.png 768w, https://thegioifirewall.com/wp-content/uploads/45-2-1536x358.png 1536w, https://thegioifirewall.com/wp-content/uploads/45-2-2048x478.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Biểu tượng hình tròn này sẽ chuyển sang màu xanh lá tức là chúng ta đã kích hoạt thành công kết nối IPSec VPN giữa 2 thiết bị.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="237" src="https://thegioifirewall.com/wp-content/uploads/46-1-1024x237.png" alt="" class="wp-image-11899" srcset="https://thegioifirewall.com/wp-content/uploads/46-1-1024x237.png 1024w, https://thegioifirewall.com/wp-content/uploads/46-1-300x69.png 300w, https://thegioifirewall.com/wp-content/uploads/46-1-768x177.png 768w, https://thegioifirewall.com/wp-content/uploads/46-1-1536x355.png 1536w, https://thegioifirewall.com/wp-content/uploads/46-1-2048x473.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Trên thiết bị Palo Alto firewall chúng ta cũng sẽ thây được 2 biểu tượng hình tròn tại 2 cột Status đều chuyển sang màu xanh lá.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="187" src="https://thegioifirewall.com/wp-content/uploads/47-1024x187.png" alt="" class="wp-image-11900" srcset="https://thegioifirewall.com/wp-content/uploads/47-1024x187.png 1024w, https://thegioifirewall.com/wp-content/uploads/47-300x55.png 300w, https://thegioifirewall.com/wp-content/uploads/47-768x140.png 768w, https://thegioifirewall.com/wp-content/uploads/47-1536x281.png 1536w, https://thegioifirewall.com/wp-content/uploads/47-2048x374.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để kiểm tra sự giao tiếp giữa 2 lớp mạng LAN của mỗi site với nhau, thegioifirewall sẽ dùng 1 máy tính tại mỗi site để ping lẫn nhau kiểm tra kết quả.</p>



<p class="wp-block-paragraph">Ở site Head Office thegioifirewall đã chuẩn bị sẵn máy chủ có IP 10.146.41.10/24 và ở site Branch Office đã chuẩn bị máy Windows 10 có IP 172.16.16.50/24.</p>



<p class="wp-block-paragraph">Kết quả ping từ máy chủ IP 10.146.41.10/24 đến máy Windows 10.</p>



<p class="wp-block-paragraph">Kết quả ping thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="561" src="https://thegioifirewall.com/wp-content/uploads/48-1-1024x561.png" alt="" class="wp-image-11901" srcset="https://thegioifirewall.com/wp-content/uploads/48-1-1024x561.png 1024w, https://thegioifirewall.com/wp-content/uploads/48-1-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/48-1-768x421.png 768w, https://thegioifirewall.com/wp-content/uploads/48-1-1536x841.png 1536w, https://thegioifirewall.com/wp-content/uploads/48-1-2048x1121.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Kết quả ping từ máy Windows 10 IP 172.16.16.50 đến máy chủ.</p>



<p class="wp-block-paragraph">Kết quả ping thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="559" src="https://thegioifirewall.com/wp-content/uploads/49-1-1024x559.png" alt="" class="wp-image-11902" srcset="https://thegioifirewall.com/wp-content/uploads/49-1-1024x559.png 1024w, https://thegioifirewall.com/wp-content/uploads/49-1-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/49-1-768x419.png 768w, https://thegioifirewall.com/wp-content/uploads/49-1-1536x838.png 1536w, https://thegioifirewall.com/wp-content/uploads/49-1-2048x1118.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
