<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hướng dẫn triển khai giải pháp Sophos Zero Trust Network Access phần 1 &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/huong-dan-trien-khai-giai-phap-sophos-zero-trust-network-access-phan-1/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Sun, 19 Jun 2022 19:31:28 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Hướng dẫn triển khai giải pháp Sophos Zero Trust Network Access phần 1 &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hướng dẫn triển khai giải pháp Sophos Zero Trust Network Access phần 1</title>
		<link>https://thegioifirewall.com/huong-dan-trien-khai-giai-phap-sophos-zero-trust-network-access-phan-1/</link>
					<comments>https://thegioifirewall.com/huong-dan-trien-khai-giai-phap-sophos-zero-trust-network-access-phan-1/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Fri, 17 Jun 2022 04:11:00 +0000</pubDate>
				<category><![CDATA[Sophos ZTNA]]></category>
		<category><![CDATA[Hướng dẫn triển khai giải pháp Sophos Zero Trust Network Access phần 1]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=16314</guid>

					<description><![CDATA[1.Mục đích bài viết Chuỗi bài viết này sẽ cung cấp cho các bạn chi tiết các bước cần thực hiện cũng như cách triển khai toàn diện giải pháp Sophos Zero Trust Network Access. 2.Sơ đồ mạng Chi tiết: Chúng ta sẽ thiết bị tường lửa Sophos được kết nối với internet tại Port [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>1.Mục đích bài viết</strong></h2>



<p class="wp-block-paragraph">Chuỗi bài viết này sẽ cung cấp cho các bạn chi tiết các bước cần thực hiện cũng như cách triển khai toàn diện giải pháp Sophos Zero Trust Network Access.</p>



<h2 class="wp-block-heading"><strong>2.Sơ đồ mạng</strong></h2>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="439" src="https://thegioifirewall.com/wp-content/uploads/Drawing3-1024x439.png" alt="" class="wp-image-16315" srcset="https://thegioifirewall.com/wp-content/uploads/Drawing3-1024x439.png 1024w, https://thegioifirewall.com/wp-content/uploads/Drawing3-300x129.png 300w, https://thegioifirewall.com/wp-content/uploads/Drawing3-768x329.png 768w, https://thegioifirewall.com/wp-content/uploads/Drawing3-1536x658.png 1536w, https://thegioifirewall.com/wp-content/uploads/Drawing3-2048x878.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Chi tiết:</strong></p>



<p class="wp-block-paragraph">Chúng ta sẽ thiết bị tường lửa Sophos được kết nối với internet tại Port 2 với IP WAN tĩnh là 115.78.x.x.</p>



<p class="wp-block-paragraph">Mạng nội bộ sẽ được cấu hình tại Port 1 của thiết bị Sophos Firewall với IP 172.16.31.1/24 và đã được cấu hình DHCP.</p>



<p class="wp-block-paragraph">Trong mạng nội bộ sẽ có một máy chủ chạy hạ tầng ảo hóa VMWware Esxi có IP 172.16.31.11/24 và có các máy ảo như sau:</p>



<ul class="wp-block-list"><li>Active Directory kiêm DNS server có hostname là pdc.valab.xyz với IP 172.16.31.250/24.</li><li>Sophos ZTNA Gateway có hostname là ztna.valab.xyz với IP 172.16.31.251/24.</li></ul>



<p class="wp-block-paragraph">Ở phía ngoài internet chúng ta sẽ có các thành phần dùng để triển khai Sophos ZTNA như sau:</p>



<ul class="wp-block-list"><li>Public domain: đang sử dụng domain của Mắt Bảo.</li><li>Identity Provider: Okta.</li><li>Sophos Central: nơi quản lý các policy, user, logs.</li><li>Hai máy tính Windows 10 với 1 máy đã được cài Agent và 1 máy không cài Agent.</li></ul>



<h2 class="wp-block-heading"><strong>3.Tình huống cấu hình</strong></h2>



<p class="wp-block-paragraph">Trong phần 1 của series này thegioifirewall sẽ hướng dẫn các bạn cấu hình 3 thành phần đầu tiên của là khai báo record trên public domain trỏ FQDN của Sophos ZTNA Gateway về IP WAN của Sophos Firewall, cấu hình Wildcard certificate và cấu hình Okta.</p>



<h2 class="wp-block-heading"><strong>4.Các bước thực hiện</strong></h2>



<p class="wp-block-paragraph">Public Domain:</p>



<ul class="wp-block-list"><li>Tạo record.</li></ul>



<p class="wp-block-paragraph">Cấu hình Wildcard certificate:</p>



<ul class="wp-block-list"><li>Get wildcard certificate cho domain valab.xyz.</li></ul>



<p class="wp-block-paragraph">Identity Provider Okta:</p>



<ul class="wp-block-list"><li>Sync user từ Active Directory</li><li>Tạo Application cho Sophos ZTNA.</li><li>Tạo Authorization Server cho Sophos ZTNA.</li><li>Khai báo Identity Provider Okta trên Sophos Central.</li></ul>



<h2 class="wp-block-heading"><strong>5.Hướng dẫn cấu hình</strong></h2>



<h3 class="wp-block-heading"><strong>5.1.Public Domain</strong></h3>



<h4 class="wp-block-heading"><strong>5.1.1.Tạo record.</strong></h4>



<p class="wp-block-paragraph">Do Sophos ZTNA hoạt động bằng tên miền nên thegioifirewall đã chuẩn bị sẵn một tên miền được mua từ Mắt Bảo là valab.xyz.</p>



<p class="wp-block-paragraph">Việc đầu tiên chúng ta cần làm với tên miền này là trỏ FQDN của Sophos ZTNA về IP WAN của Sophos Firewall.</p>



<p class="wp-block-paragraph">Để làm chúng ta cần đăng nhập vào trang quản trị DNS cho tên miền valab.xyz trên trang web của Mắt Bảo.</p>



<p class="wp-block-paragraph">Chúng ta sẽ tạo các record trỏ FQDN của Sophos ZTNA Gateway về IP WAN của Sophos Firewall như hình sau:</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="633" src="https://thegioifirewall.com/wp-content/uploads/1-110-1024x633.png" alt="" class="wp-image-16316" srcset="https://thegioifirewall.com/wp-content/uploads/1-110-1024x633.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-110-300x185.png 300w, https://thegioifirewall.com/wp-content/uploads/1-110-768x475.png 768w, https://thegioifirewall.com/wp-content/uploads/1-110-1536x949.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-110-2048x1265.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để kiểm tra xem record đã hoạt động chưa chúng ta bật Command Prompt trên máy tính.</p>



<p class="wp-block-paragraph">Nhập lệnh nslookup &gt; gõ vào tên miền ztna.valab.xyz và chúng ta sẽ thấy tên miền này sẽ được phân giải thành địa chỉ IP 115.78.x.x.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="507" src="https://thegioifirewall.com/wp-content/uploads/33-12-1024x507.png" alt="" class="wp-image-16317" srcset="https://thegioifirewall.com/wp-content/uploads/33-12-1024x507.png 1024w, https://thegioifirewall.com/wp-content/uploads/33-12-300x149.png 300w, https://thegioifirewall.com/wp-content/uploads/33-12-768x380.png 768w, https://thegioifirewall.com/wp-content/uploads/33-12.png 1064w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.2.Cấu hình Wildcard certificate</strong></h3>



<h4 class="wp-block-heading"><strong>5.2.1.Đăng kí wildcard certificate cho domain valab.xyz.</strong></h4>



<p class="wp-block-paragraph">Do giải pháp Sophos ZTNA sẽ sử dụng tất cả các subdomain của domain valab.xyz và kết nối mà nó sử dụng là https nên chúng ta cần phải có một wildcard certificate về https để áp dụng cho tất cả subdomain của domain valab.xyz.</p>



<p class="wp-block-paragraph">Trong bài viết này chúng ta sẽ đăng kí wildcard certificate miễn phí từ Let’s Encrypt.</p>



<p class="wp-block-paragraph">Đầu tiên chúng ta cần tải xuống phần mềm Certbot client về máy tính cá nhân.</p>



<p class="wp-block-paragraph">Vào link phía dưới để download.</p>



<p class="wp-block-paragraph"><a href="https://dl.eff.org/certbot-beta-installer-win32.exe">https://dl.eff.org/certbot-beta-installer-win32.exe</a></p>



<p class="wp-block-paragraph">Tiếp theo thực hiện cài đặt phần mềm certbot client vào máy và mở nó lên.</p>



<p class="wp-block-paragraph">Khi mở lên thì nó sẽ có giao diện như hình dưới đây.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="561" src="https://thegioifirewall.com/wp-content/uploads/52-4-1024x561.png" alt="" class="wp-image-16318" srcset="https://thegioifirewall.com/wp-content/uploads/52-4-1024x561.png 1024w, https://thegioifirewall.com/wp-content/uploads/52-4-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/52-4-768x420.png 768w, https://thegioifirewall.com/wp-content/uploads/52-4-1536x841.png 1536w, https://thegioifirewall.com/wp-content/uploads/52-4-2048x1121.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta sẽ nhập câu lệnh sau để đăng kí wild certificate cho tên miền valab.xyz.</p>



<p class="wp-block-paragraph">certbot certonly &#8211;manual &#8211;preferred-challenges=dns &#8211;server https://acme-v02.api.letsencrypt.org/directory &#8211;agree-tos &#8211;domain valab.xyz</p>



<p class="wp-block-paragraph">Sau khi chạy dòng lệnh certbot sẽ yêu cầu chúng ta tạo DNS TXT record trên domain valab.xyz với các thông số phía dưới.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="561" src="https://thegioifirewall.com/wp-content/uploads/53-4-1024x561.png" alt="" class="wp-image-16319" srcset="https://thegioifirewall.com/wp-content/uploads/53-4-1024x561.png 1024w, https://thegioifirewall.com/wp-content/uploads/53-4-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/53-4-768x420.png 768w, https://thegioifirewall.com/wp-content/uploads/53-4-1536x841.png 1536w, https://thegioifirewall.com/wp-content/uploads/53-4-2048x1121.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta cần đăng nhập vào trang quản trị của domain valab.xyz và thêm TXT record như sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="397" src="https://thegioifirewall.com/wp-content/uploads/54-4-1024x397.png" alt="" class="wp-image-16320" srcset="https://thegioifirewall.com/wp-content/uploads/54-4-1024x397.png 1024w, https://thegioifirewall.com/wp-content/uploads/54-4-300x116.png 300w, https://thegioifirewall.com/wp-content/uploads/54-4-768x298.png 768w, https://thegioifirewall.com/wp-content/uploads/54-4-1536x596.png 1536w, https://thegioifirewall.com/wp-content/uploads/54-4-2048x795.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Sau đó chúng ta vào <a href="https://toolbox.googleapps.com/apps/dig/#TXT/">https://toolbox.googleapps.com/apps/dig/#TXT/</a> để kiểm tra xem TXT record đã hoạt động hay chưa.</p>



<p class="wp-block-paragraph">Nhập _acme-challenge.valab.xyz vào ô và nhấn enter, chúng ta sẽ thấy kết quả là TXT record đã hoạt động.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="472" src="https://thegioifirewall.com/wp-content/uploads/55-4-1024x472.png" alt="" class="wp-image-16321" srcset="https://thegioifirewall.com/wp-content/uploads/55-4-1024x472.png 1024w, https://thegioifirewall.com/wp-content/uploads/55-4-300x138.png 300w, https://thegioifirewall.com/wp-content/uploads/55-4-768x354.png 768w, https://thegioifirewall.com/wp-content/uploads/55-4-1536x707.png 1536w, https://thegioifirewall.com/wp-content/uploads/55-4-2048x943.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Quay trở lại certbot client nhấn Enter để tiếp tục.</p>



<p class="wp-block-paragraph">Chúng ta thấy việc đăng kí wild certfificate đã thành công.</p>



<p class="wp-block-paragraph">Hai file certificate có tên là fullchain.pem và file key có tên là privkey.pem được lưu tại ổ C:/Certbot/Archive/valab.xyz-0001</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="561" src="https://thegioifirewall.com/wp-content/uploads/56-3-1024x561.png" alt="" class="wp-image-16322" srcset="https://thegioifirewall.com/wp-content/uploads/56-3-1024x561.png 1024w, https://thegioifirewall.com/wp-content/uploads/56-3-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/56-3-768x420.png 768w, https://thegioifirewall.com/wp-content/uploads/56-3-1536x841.png 1536w, https://thegioifirewall.com/wp-content/uploads/56-3-2048x1121.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="459" src="https://thegioifirewall.com/wp-content/uploads/57-3-1024x459.png" alt="" class="wp-image-16323" srcset="https://thegioifirewall.com/wp-content/uploads/57-3-1024x459.png 1024w, https://thegioifirewall.com/wp-content/uploads/57-3-300x135.png 300w, https://thegioifirewall.com/wp-content/uploads/57-3-768x345.png 768w, https://thegioifirewall.com/wp-content/uploads/57-3-1536x689.png 1536w, https://thegioifirewall.com/wp-content/uploads/57-3-2048x919.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Lưu ý: chúng ta cần giữ 2 file này để dùng cho việc triển khai Sophos ZTNA Gateway ở phần sau.</p>



<h3 class="wp-block-heading"><strong>5.3.Identity Provider Okta</strong></h3>



<h4 class="wp-block-heading"><strong>5.3.1.Sync user từ Active Directory</strong></h4>



<p class="wp-block-paragraph">Mục đích của việc sync user này là để Okta sẽ sử dụng trực tiếp user từ Active Directory cho bước xác thực người dùng.</p>



<p class="wp-block-paragraph">Hình dưới đây là danh sách các user và groups sẽ được sync lên Okta.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="619" src="https://thegioifirewall.com/wp-content/uploads/2-111-1024x619.png" alt="" class="wp-image-16324" srcset="https://thegioifirewall.com/wp-content/uploads/2-111-1024x619.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-111-300x181.png 300w, https://thegioifirewall.com/wp-content/uploads/2-111-768x464.png 768w, https://thegioifirewall.com/wp-content/uploads/2-111-1536x928.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-111-2048x1237.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để sync chúng ta truy cập vào trang quản trị của Okta.</p>



<p class="wp-block-paragraph">Vào Directory &gt; Directory Integrations &gt; nhấn Add Active Directory.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="540" src="https://thegioifirewall.com/wp-content/uploads/3-108-1024x540.png" alt="" class="wp-image-16325" srcset="https://thegioifirewall.com/wp-content/uploads/3-108-1024x540.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-108-300x158.png 300w, https://thegioifirewall.com/wp-content/uploads/3-108-768x405.png 768w, https://thegioifirewall.com/wp-content/uploads/3-108-1536x811.png 1536w, https://thegioifirewall.com/wp-content/uploads/3-108-2048x1081.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Set Up Active Directory.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="791" height="1024" src="https://thegioifirewall.com/wp-content/uploads/4-104-791x1024.png" alt="" class="wp-image-16326" srcset="https://thegioifirewall.com/wp-content/uploads/4-104-791x1024.png 791w, https://thegioifirewall.com/wp-content/uploads/4-104-232x300.png 232w, https://thegioifirewall.com/wp-content/uploads/4-104-768x994.png 768w, https://thegioifirewall.com/wp-content/uploads/4-104.png 1081w" sizes="auto, (max-width: 791px) 100vw, 791px" /></figure>



<p class="wp-block-paragraph">Nhấn Download Agent.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="433" src="https://thegioifirewall.com/wp-content/uploads/5-99-1024x433.png" alt="" class="wp-image-16327" srcset="https://thegioifirewall.com/wp-content/uploads/5-99-1024x433.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-99-300x127.png 300w, https://thegioifirewall.com/wp-content/uploads/5-99-768x325.png 768w, https://thegioifirewall.com/wp-content/uploads/5-99-1536x650.png 1536w, https://thegioifirewall.com/wp-content/uploads/5-99-2048x866.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta sẽ cài đặt file OktaADAgentSetup vừa tải vừa và chúng ta cần copy thông số Your Okta Orgnization URL để sử dụng cho quá trình cài đặt.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="767" src="https://thegioifirewall.com/wp-content/uploads/6-90-1024x767.png" alt="" class="wp-image-16328" srcset="https://thegioifirewall.com/wp-content/uploads/6-90-1024x767.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-90-300x225.png 300w, https://thegioifirewall.com/wp-content/uploads/6-90-768x575.png 768w, https://thegioifirewall.com/wp-content/uploads/6-90-1536x1151.png 1536w, https://thegioifirewall.com/wp-content/uploads/6-90-2048x1534.png 2048w, https://thegioifirewall.com/wp-content/uploads/6-90-1200x900.png 1200w, https://thegioifirewall.com/wp-content/uploads/6-90-600x450.png 600w, https://thegioifirewall.com/wp-content/uploads/6-90-400x300.png 400w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="798" src="https://thegioifirewall.com/wp-content/uploads/7-78-1024x798.png" alt="" class="wp-image-16329" srcset="https://thegioifirewall.com/wp-content/uploads/7-78-1024x798.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-78-300x234.png 300w, https://thegioifirewall.com/wp-content/uploads/7-78-768x599.png 768w, https://thegioifirewall.com/wp-content/uploads/7-78.png 1242w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Install.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="800" src="https://thegioifirewall.com/wp-content/uploads/8-75-1024x800.png" alt="" class="wp-image-16330" srcset="https://thegioifirewall.com/wp-content/uploads/8-75-1024x800.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-75-300x234.png 300w, https://thegioifirewall.com/wp-content/uploads/8-75-768x600.png 768w, https://thegioifirewall.com/wp-content/uploads/8-75.png 1243w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Okta AD Agent sẽ tự động phát hiện được tên domain trên máy chủ Active Directory.</p>



<p class="wp-block-paragraph">Nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="803" src="https://thegioifirewall.com/wp-content/uploads/9-72-1024x803.png" alt="" class="wp-image-16331" srcset="https://thegioifirewall.com/wp-content/uploads/9-72-1024x803.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-72-300x235.png 300w, https://thegioifirewall.com/wp-content/uploads/9-72-768x602.png 768w, https://thegioifirewall.com/wp-content/uploads/9-72.png 1240w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chọn Create or use the OktaService account (recommended), với lựa chọn này Okta Agent sẽ tạo ra một tài khoản với username OktaService chỉ dùng để chạy cho duy nhất dịch vụ của Okta.</p>



<p class="wp-block-paragraph">Nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="800" src="https://thegioifirewall.com/wp-content/uploads/15-44-1024x800.png" alt="" class="wp-image-16332" srcset="https://thegioifirewall.com/wp-content/uploads/15-44-1024x800.png 1024w, https://thegioifirewall.com/wp-content/uploads/15-44-300x234.png 300w, https://thegioifirewall.com/wp-content/uploads/15-44-768x600.png 768w, https://thegioifirewall.com/wp-content/uploads/15-44.png 1240w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta nhập password cho tài khoản OktaService và nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="801" src="https://thegioifirewall.com/wp-content/uploads/16-42-1024x801.png" alt="" class="wp-image-16333" srcset="https://thegioifirewall.com/wp-content/uploads/16-42-1024x801.png 1024w, https://thegioifirewall.com/wp-content/uploads/16-42-300x235.png 300w, https://thegioifirewall.com/wp-content/uploads/16-42-768x601.png 768w, https://thegioifirewall.com/wp-content/uploads/16-42.png 1241w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Next nếu chúng ta không sử dụng proxy trong hệ thống.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="798" src="https://thegioifirewall.com/wp-content/uploads/10-65-1024x798.png" alt="" class="wp-image-16334" srcset="https://thegioifirewall.com/wp-content/uploads/10-65-1024x798.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-65-300x234.png 300w, https://thegioifirewall.com/wp-content/uploads/10-65-768x599.png 768w, https://thegioifirewall.com/wp-content/uploads/10-65.png 1243w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Copy Okta Organization URL mà chúng ta đã lưu tại bước download Okta Agent vào ô Enter Organization URL.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="800" src="https://thegioifirewall.com/wp-content/uploads/11-64-1024x800.png" alt="" class="wp-image-16335" srcset="https://thegioifirewall.com/wp-content/uploads/11-64-1024x800.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-64-300x234.png 300w, https://thegioifirewall.com/wp-content/uploads/11-64-768x600.png 768w, https://thegioifirewall.com/wp-content/uploads/11-64.png 1242w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Một cửa sổ đăng nhập hiện ta, chúng ta cần đăng nhập tài khoản quản trị của Okta và nhấn Sign in.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="673" height="1024" src="https://thegioifirewall.com/wp-content/uploads/12-59-673x1024.png" alt="" class="wp-image-16336" srcset="https://thegioifirewall.com/wp-content/uploads/12-59-673x1024.png 673w, https://thegioifirewall.com/wp-content/uploads/12-59-197x300.png 197w, https://thegioifirewall.com/wp-content/uploads/12-59-768x1168.png 768w, https://thegioifirewall.com/wp-content/uploads/12-59.png 994w" sizes="auto, (max-width: 673px) 100vw, 673px" /></figure>



<p class="wp-block-paragraph">Nhấn Allow Access để cho phép các service cần thiết Okta Agent có thể hoạt động.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="992" height="643" src="https://thegioifirewall.com/wp-content/uploads/13-50.png" alt="" class="wp-image-16337" srcset="https://thegioifirewall.com/wp-content/uploads/13-50.png 992w, https://thegioifirewall.com/wp-content/uploads/13-50-300x194.png 300w, https://thegioifirewall.com/wp-content/uploads/13-50-768x498.png 768w" sizes="auto, (max-width: 992px) 100vw, 992px" /></figure>



<p class="wp-block-paragraph">Quá trình đăng kí Okta Agent và cài đặt sẽ diễn ra trong khoảng 5 giây.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="801" src="https://thegioifirewall.com/wp-content/uploads/14-47-1024x801.png" alt="" class="wp-image-16338" srcset="https://thegioifirewall.com/wp-content/uploads/14-47-1024x801.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-47-300x235.png 300w, https://thegioifirewall.com/wp-content/uploads/14-47-768x601.png 768w, https://thegioifirewall.com/wp-content/uploads/14-47.png 1243w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta nhấn Finish để hoàn thành việc cài đặt Okta Agent.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="799" src="https://thegioifirewall.com/wp-content/uploads/18-38-1024x799.png" alt="" class="wp-image-16339" srcset="https://thegioifirewall.com/wp-content/uploads/18-38-1024x799.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-38-300x234.png 300w, https://thegioifirewall.com/wp-content/uploads/18-38-768x599.png 768w, https://thegioifirewall.com/wp-content/uploads/18-38.png 1241w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Quay trở lại trang quản trị chúng ta sẽ tiếp tục phần cấu hình còn lại.</p>



<p class="wp-block-paragraph">Tại Basic Settings, chúng ta sẽ chọn OU mà chúng ta sẽ sync lên Okta.</p>



<p class="wp-block-paragraph">Ở đây chúng ta sẽ chọn OU valab vì đây là nơi chứa users và group.</p>



<p class="wp-block-paragraph">Tại Okta username format, chúng ta sẽ chọn Email Address và nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="919" src="https://thegioifirewall.com/wp-content/uploads/19-36-1024x919.png" alt="" class="wp-image-16340" srcset="https://thegioifirewall.com/wp-content/uploads/19-36-1024x919.png 1024w, https://thegioifirewall.com/wp-content/uploads/19-36-300x269.png 300w, https://thegioifirewall.com/wp-content/uploads/19-36-768x689.png 768w, https://thegioifirewall.com/wp-content/uploads/19-36-1536x1379.png 1536w, https://thegioifirewall.com/wp-content/uploads/19-36.png 1883w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Next.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="846" height="397" src="https://thegioifirewall.com/wp-content/uploads/20-33.png" alt="" class="wp-image-16341" srcset="https://thegioifirewall.com/wp-content/uploads/20-33.png 846w, https://thegioifirewall.com/wp-content/uploads/20-33-300x141.png 300w, https://thegioifirewall.com/wp-content/uploads/20-33-768x360.png 768w" sizes="auto, (max-width: 846px) 100vw, 846px" /></figure>



<p class="wp-block-paragraph">Tại Build User Profile nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="897" src="https://thegioifirewall.com/wp-content/uploads/21-30-1024x897.png" alt="" class="wp-image-16342" srcset="https://thegioifirewall.com/wp-content/uploads/21-30-1024x897.png 1024w, https://thegioifirewall.com/wp-content/uploads/21-30-300x263.png 300w, https://thegioifirewall.com/wp-content/uploads/21-30-768x673.png 768w, https://thegioifirewall.com/wp-content/uploads/21-30-1536x1346.png 1536w, https://thegioifirewall.com/wp-content/uploads/21-30.png 1955w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Done để hoàn thành.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="305" src="https://thegioifirewall.com/wp-content/uploads/22-24-1024x305.png" alt="" class="wp-image-16343" srcset="https://thegioifirewall.com/wp-content/uploads/22-24-1024x305.png 1024w, https://thegioifirewall.com/wp-content/uploads/22-24-300x89.png 300w, https://thegioifirewall.com/wp-content/uploads/22-24-768x229.png 768w, https://thegioifirewall.com/wp-content/uploads/22-24-1536x457.png 1536w, https://thegioifirewall.com/wp-content/uploads/22-24.png 2012w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Vào Directory &gt; Directory Integrations và chúng ta sẽ thấy Okta đã kết nối với máy chủ Active Directory thành công.</p>



<p class="wp-block-paragraph">Tiếp theo chúng ta sẽ import users và groups lên Okta, để import chúng ta nhấn chuột trái vào Active Directory.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="412" src="https://thegioifirewall.com/wp-content/uploads/32-13-1024x412.png" alt="" class="wp-image-16345" srcset="https://thegioifirewall.com/wp-content/uploads/32-13-1024x412.png 1024w, https://thegioifirewall.com/wp-content/uploads/32-13-300x121.png 300w, https://thegioifirewall.com/wp-content/uploads/32-13-768x309.png 768w, https://thegioifirewall.com/wp-content/uploads/32-13-1536x617.png 1536w, https://thegioifirewall.com/wp-content/uploads/32-13-2048x823.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại tab Import nhấn Import Now.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="608" src="https://thegioifirewall.com/wp-content/uploads/24-26-1024x608.png" alt="" class="wp-image-16346" srcset="https://thegioifirewall.com/wp-content/uploads/24-26-1024x608.png 1024w, https://thegioifirewall.com/wp-content/uploads/24-26-300x178.png 300w, https://thegioifirewall.com/wp-content/uploads/24-26-768x456.png 768w, https://thegioifirewall.com/wp-content/uploads/24-26-1536x912.png 1536w, https://thegioifirewall.com/wp-content/uploads/24-26-2048x1216.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chọn Incremental import (fastest) và nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1014" src="https://thegioifirewall.com/wp-content/uploads/25-24-1024x1014.png" alt="" class="wp-image-16347" srcset="https://thegioifirewall.com/wp-content/uploads/25-24-1024x1014.png 1024w, https://thegioifirewall.com/wp-content/uploads/25-24-300x297.png 300w, https://thegioifirewall.com/wp-content/uploads/25-24-150x150.png 150w, https://thegioifirewall.com/wp-content/uploads/25-24-768x760.png 768w, https://thegioifirewall.com/wp-content/uploads/25-24.png 1421w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Quá trình import sẽ diễn ra trong vài giây.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="639" src="https://thegioifirewall.com/wp-content/uploads/26-22-1024x639.png" alt="" class="wp-image-16348" srcset="https://thegioifirewall.com/wp-content/uploads/26-22-1024x639.png 1024w, https://thegioifirewall.com/wp-content/uploads/26-22-300x187.png 300w, https://thegioifirewall.com/wp-content/uploads/26-22-768x479.png 768w, https://thegioifirewall.com/wp-content/uploads/26-22-1536x958.png 1536w, https://thegioifirewall.com/wp-content/uploads/26-22-2048x1277.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Okta đã scan thành công 7 user và 2 group.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="866" src="https://thegioifirewall.com/wp-content/uploads/27-23-1024x866.png" alt="" class="wp-image-16349" srcset="https://thegioifirewall.com/wp-content/uploads/27-23-1024x866.png 1024w, https://thegioifirewall.com/wp-content/uploads/27-23-300x254.png 300w, https://thegioifirewall.com/wp-content/uploads/27-23-768x650.png 768w, https://thegioifirewall.com/wp-content/uploads/27-23-1536x1300.png 1536w, https://thegioifirewall.com/wp-content/uploads/27-23.png 1943w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để import user lên Okta chúng ta tích chọn tất cả user và nhấn Confirm Assignments.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="940" height="1024" src="https://thegioifirewall.com/wp-content/uploads/28-23-940x1024.png" alt="" class="wp-image-16350" srcset="https://thegioifirewall.com/wp-content/uploads/28-23-940x1024.png 940w, https://thegioifirewall.com/wp-content/uploads/28-23-275x300.png 275w, https://thegioifirewall.com/wp-content/uploads/28-23-768x837.png 768w, https://thegioifirewall.com/wp-content/uploads/28-23-1410x1536.png 1410w, https://thegioifirewall.com/wp-content/uploads/28-23.png 1603w" sizes="auto, (max-width: 940px) 100vw, 940px" /></figure>



<p class="wp-block-paragraph">Tích chọn Auto-active users after confirmation và nhấn Confirm.</p>



<p class="wp-block-paragraph">Với việc tích chọn Auto-active users after confirmation thì sau khi confirm thành công Okta sẽ gửi email đến cho từng người dùng thông báo về việc tài khoản Okta của user đó đã được tạo và username và mật khẩu sẽ tương tự như của tài khoản domain mà user đang dùng.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="901" height="645" src="https://thegioifirewall.com/wp-content/uploads/29-20.png" alt="" class="wp-image-16351" srcset="https://thegioifirewall.com/wp-content/uploads/29-20.png 901w, https://thegioifirewall.com/wp-content/uploads/29-20-300x215.png 300w, https://thegioifirewall.com/wp-content/uploads/29-20-768x550.png 768w" sizes="auto, (max-width: 901px) 100vw, 901px" /></figure>



<p class="wp-block-paragraph">Email được gửi đến người dùng sẽ có nội dung như hình sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="488" src="https://thegioifirewall.com/wp-content/uploads/2-112-1024x488.png" alt="" class="wp-image-16353" srcset="https://thegioifirewall.com/wp-content/uploads/2-112-1024x488.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-112-300x143.png 300w, https://thegioifirewall.com/wp-content/uploads/2-112-768x366.png 768w, https://thegioifirewall.com/wp-content/uploads/2-112-1536x732.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-112-2048x976.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để xem danh sách user vừa được import vào Directory &gt; People, chúng ta sẽ thấy danh sách user đã được import như hình dưới đây.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="683" src="https://thegioifirewall.com/wp-content/uploads/30-17-1024x683.png" alt="" class="wp-image-16354" srcset="https://thegioifirewall.com/wp-content/uploads/30-17-1024x683.png 1024w, https://thegioifirewall.com/wp-content/uploads/30-17-300x200.png 300w, https://thegioifirewall.com/wp-content/uploads/30-17-768x512.png 768w, https://thegioifirewall.com/wp-content/uploads/30-17-1536x1024.png 1536w, https://thegioifirewall.com/wp-content/uploads/30-17-2048x1366.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để xem các group đã được import vào Directory &gt; Groups.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="615" src="https://thegioifirewall.com/wp-content/uploads/31-16-1024x615.png" alt="" class="wp-image-16356" srcset="https://thegioifirewall.com/wp-content/uploads/31-16-1024x615.png 1024w, https://thegioifirewall.com/wp-content/uploads/31-16-300x180.png 300w, https://thegioifirewall.com/wp-content/uploads/31-16-768x462.png 768w, https://thegioifirewall.com/wp-content/uploads/31-16-1536x923.png 1536w, https://thegioifirewall.com/wp-content/uploads/31-16-2048x1231.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.2.Tạo Application cho Sophos ZTNA</strong></h4>



<p class="wp-block-paragraph">Chúng ta cần tạo một Application cho Sophos ZTNA để khi người dùng truy cập và xác thực thì sẽ được chuyển hướng tới trang xác thực của Okta.</p>



<p class="wp-block-paragraph">Để tạo vào trang quản trị của Okta &gt; Applications &gt; Applications &gt; Create App Integration.</p>



<ul class="wp-block-list"><li>Sign-in method: chọn OIDC – OpenID Connect.</li><li>Application type: chọn Web Application.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="891" src="https://thegioifirewall.com/wp-content/uploads/34-11-1024x891.png" alt="" class="wp-image-16357" srcset="https://thegioifirewall.com/wp-content/uploads/34-11-1024x891.png 1024w, https://thegioifirewall.com/wp-content/uploads/34-11-300x261.png 300w, https://thegioifirewall.com/wp-content/uploads/34-11-768x668.png 768w, https://thegioifirewall.com/wp-content/uploads/34-11-1536x1336.png 1536w, https://thegioifirewall.com/wp-content/uploads/34-11-2048x1781.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">App integration name: Sophos ZTNA.</p>



<p class="wp-block-paragraph">Tại Grand type: tích chọn Client Credentials và Refresh Token.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="615" src="https://thegioifirewall.com/wp-content/uploads/35-12-1024x615.png" alt="" class="wp-image-16358" srcset="https://thegioifirewall.com/wp-content/uploads/35-12-1024x615.png 1024w, https://thegioifirewall.com/wp-content/uploads/35-12-300x180.png 300w, https://thegioifirewall.com/wp-content/uploads/35-12-768x461.png 768w, https://thegioifirewall.com/wp-content/uploads/35-12-1536x922.png 1536w, https://thegioifirewall.com/wp-content/uploads/35-12-2048x1230.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại Sign-in redirect URIs chúng ta nhập vào đường dẫn, đây là đường dẫn mà người dùng sẽ được chuyển hướng tới để thực hiện xác thực.</p>



<p class="wp-block-paragraph">Đường dẫn này sẽ có định dạng là https://FQDN&lt;Sophos ZTNA Gateway&gt;/oauth2/callback.</p>



<p class="wp-block-paragraph">Ví dụ: FQDN của Sophos ZTNA Gateway sẽ được triển khai trong phần sau là ztna.valab.xyz =&gt; đường dẫn sẽ là https://ztna.valab.xyz/oauth2/callback.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="209" src="https://thegioifirewall.com/wp-content/uploads/36-10-1024x209.png" alt="" class="wp-image-16359" srcset="https://thegioifirewall.com/wp-content/uploads/36-10-1024x209.png 1024w, https://thegioifirewall.com/wp-content/uploads/36-10-300x61.png 300w, https://thegioifirewall.com/wp-content/uploads/36-10-768x156.png 768w, https://thegioifirewall.com/wp-content/uploads/36-10-1536x313.png 1536w, https://thegioifirewall.com/wp-content/uploads/36-10.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại Assignments chọn Skip group assignment for now và nhấn Save.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="322" src="https://thegioifirewall.com/wp-content/uploads/37-10-1024x322.png" alt="" class="wp-image-16360" srcset="https://thegioifirewall.com/wp-content/uploads/37-10-1024x322.png 1024w, https://thegioifirewall.com/wp-content/uploads/37-10-300x94.png 300w, https://thegioifirewall.com/wp-content/uploads/37-10-768x241.png 768w, https://thegioifirewall.com/wp-content/uploads/37-10-1536x482.png 1536w, https://thegioifirewall.com/wp-content/uploads/37-10.png 1997w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Quay lại Applications &gt; Applications chúng ta sẽ thấy Sophos ZTNA đã được tạo.</p>



<p class="wp-block-paragraph">Chúng ta sẽ cần assign group và điều chỉnh scope cho app Sophos ZTNA này.</p>



<p class="wp-block-paragraph">Để điều chỉnh nhấn chuột trái vào tên Sophos ZTNA.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="552" src="https://thegioifirewall.com/wp-content/uploads/38-10-1024x552.png" alt="" class="wp-image-16361" srcset="https://thegioifirewall.com/wp-content/uploads/38-10-1024x552.png 1024w, https://thegioifirewall.com/wp-content/uploads/38-10-300x162.png 300w, https://thegioifirewall.com/wp-content/uploads/38-10-768x414.png 768w, https://thegioifirewall.com/wp-content/uploads/38-10-1536x827.png 1536w, https://thegioifirewall.com/wp-content/uploads/38-10-2048x1103.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại tab General chúng ta sẽ cần phải nhấn vào biểu tượng copy tại Client ID và Client Secrets và lưu chúng lại để sử dụng ở phần khai báo Identity Okta trên Sophos Central.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="895" src="https://thegioifirewall.com/wp-content/uploads/39-10-1024x895.png" alt="" class="wp-image-16362" srcset="https://thegioifirewall.com/wp-content/uploads/39-10-1024x895.png 1024w, https://thegioifirewall.com/wp-content/uploads/39-10-300x262.png 300w, https://thegioifirewall.com/wp-content/uploads/39-10-768x671.png 768w, https://thegioifirewall.com/wp-content/uploads/39-10-1536x1342.png 1536w, https://thegioifirewall.com/wp-content/uploads/39-10.png 1807w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại tab Okta API Scopes chúng ta nhấn Grant tại okta.idps.read.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="792" src="https://thegioifirewall.com/wp-content/uploads/40-10-1024x792.png" alt="" class="wp-image-16363" srcset="https://thegioifirewall.com/wp-content/uploads/40-10-1024x792.png 1024w, https://thegioifirewall.com/wp-content/uploads/40-10-300x232.png 300w, https://thegioifirewall.com/wp-content/uploads/40-10-768x594.png 768w, https://thegioifirewall.com/wp-content/uploads/40-10-1536x1188.png 1536w, https://thegioifirewall.com/wp-content/uploads/40-10.png 1603w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại tab Assignments, nhấn Assign &gt; Assign to Groups để chỉ định các groups nào sẽ được sử dụng app Sophos ZTNA này.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="613" src="https://thegioifirewall.com/wp-content/uploads/41-10-1024x613.png" alt="" class="wp-image-16364" srcset="https://thegioifirewall.com/wp-content/uploads/41-10-1024x613.png 1024w, https://thegioifirewall.com/wp-content/uploads/41-10-300x180.png 300w, https://thegioifirewall.com/wp-content/uploads/41-10-768x460.png 768w, https://thegioifirewall.com/wp-content/uploads/41-10-1536x920.png 1536w, https://thegioifirewall.com/wp-content/uploads/41-10-2048x1226.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại Assign Sophos ZTNA to Groups nhấn Assign 2 group SALE TEAM và TECHNICAL TEAM.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1019" src="https://thegioifirewall.com/wp-content/uploads/42-9-1024x1019.png" alt="" class="wp-image-16365" srcset="https://thegioifirewall.com/wp-content/uploads/42-9-1024x1019.png 1024w, https://thegioifirewall.com/wp-content/uploads/42-9-300x298.png 300w, https://thegioifirewall.com/wp-content/uploads/42-9-150x150.png 150w, https://thegioifirewall.com/wp-content/uploads/42-9-768x764.png 768w, https://thegioifirewall.com/wp-content/uploads/42-9.png 1374w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta sẽ thấy phía bên phải của 2 group hiện chữ Assigned tức đã chỉ định thành công.</p>



<p class="wp-block-paragraph">Nhấn Done.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="1021" src="https://thegioifirewall.com/wp-content/uploads/43-8-1024x1021.png" alt="" class="wp-image-16366" srcset="https://thegioifirewall.com/wp-content/uploads/43-8-1024x1021.png 1024w, https://thegioifirewall.com/wp-content/uploads/43-8-300x300.png 300w, https://thegioifirewall.com/wp-content/uploads/43-8-150x150.png 150w, https://thegioifirewall.com/wp-content/uploads/43-8-768x766.png 768w, https://thegioifirewall.com/wp-content/uploads/43-8.png 1371w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Quay trở lại với trang quản trị tại Assignments &gt; Groups, chúng ta sẽ thấy 2 group mà chúng ta vừa Assign đã được liệt kê.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="648" src="https://thegioifirewall.com/wp-content/uploads/44-7-1024x648.png" alt="" class="wp-image-16367" srcset="https://thegioifirewall.com/wp-content/uploads/44-7-1024x648.png 1024w, https://thegioifirewall.com/wp-content/uploads/44-7-300x190.png 300w, https://thegioifirewall.com/wp-content/uploads/44-7-768x486.png 768w, https://thegioifirewall.com/wp-content/uploads/44-7-1536x972.png 1536w, https://thegioifirewall.com/wp-content/uploads/44-7-2048x1296.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tại Assignments &gt; People chúng ta cũng sẽ thấy các các user thuộc 2 group đã được liệt kê.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="966" src="https://thegioifirewall.com/wp-content/uploads/45-7-1024x966.png" alt="" class="wp-image-16368" srcset="https://thegioifirewall.com/wp-content/uploads/45-7-1024x966.png 1024w, https://thegioifirewall.com/wp-content/uploads/45-7-300x283.png 300w, https://thegioifirewall.com/wp-content/uploads/45-7-768x724.png 768w, https://thegioifirewall.com/wp-content/uploads/45-7-1536x1448.png 1536w, https://thegioifirewall.com/wp-content/uploads/45-7.png 1737w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.3.Tạo Authorization Server cho Sophos ZTNA.</strong></h4>



<p class="wp-block-paragraph">Để tạo chúng ta truy cập trang quản trị Okta vào Security &gt; API &gt; Nhấn Add Authorization Server</p>



<p class="wp-block-paragraph">Bảng Add Authorization Server hiện ra, điền ZTNA vào Name và Audience và nhấn Save.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="477" src="https://thegioifirewall.com/wp-content/uploads/46-6-1024x477.png" alt="" class="wp-image-16369" srcset="https://thegioifirewall.com/wp-content/uploads/46-6-1024x477.png 1024w, https://thegioifirewall.com/wp-content/uploads/46-6-300x140.png 300w, https://thegioifirewall.com/wp-content/uploads/46-6-768x358.png 768w, https://thegioifirewall.com/wp-content/uploads/46-6-1536x716.png 1536w, https://thegioifirewall.com/wp-content/uploads/46-6.png 1554w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chúng ta sẽ thấy là Authorization Server ZTNA đã được tạo, chúng ta cần lưu lại thông tin Issuer URI để phục vụ cho việc khai báo Identity Provider Okta trên Sophos Central.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="416" src="https://thegioifirewall.com/wp-content/uploads/47-5-1024x416.png" alt="" class="wp-image-16370" srcset="https://thegioifirewall.com/wp-content/uploads/47-5-1024x416.png 1024w, https://thegioifirewall.com/wp-content/uploads/47-5-300x122.png 300w, https://thegioifirewall.com/wp-content/uploads/47-5-768x312.png 768w, https://thegioifirewall.com/wp-content/uploads/47-5-1536x625.png 1536w, https://thegioifirewall.com/wp-content/uploads/47-5-2048x833.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tiếp theo chúng ta nhấn vào tên ZTNA để điều chỉnh một vài thông số.</p>



<p class="wp-block-paragraph">Đầu tiên chúng ta cần tạo Scope tên làm customScope với mục đích duy nhất là kiểm tra kết nối giữa Okta và Sophos Central.</p>



<p class="wp-block-paragraph">Để tạo vào tab Scope &gt; nhấn Add Scope.</p>



<p class="wp-block-paragraph">Tại Name điền vào customScope và nhấn Save.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="915" src="https://thegioifirewall.com/wp-content/uploads/48-6-1024x915.png" alt="" class="wp-image-16371" srcset="https://thegioifirewall.com/wp-content/uploads/48-6-1024x915.png 1024w, https://thegioifirewall.com/wp-content/uploads/48-6-300x268.png 300w, https://thegioifirewall.com/wp-content/uploads/48-6-768x686.png 768w, https://thegioifirewall.com/wp-content/uploads/48-6-1536x1373.png 1536w, https://thegioifirewall.com/wp-content/uploads/48-6.png 1552w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Trên Claim tab, nhấn Add Claim. Một Claim cho phép ZTNA xem các nhóm để xác thực. Nhập các thông tin chi tiết như sau:</p>



<ul class="wp-block-list"><li>Name: groups.</li><li>Inlcude in token type: ID Token – Iserinfo / id_token request.</li><li>Value type: chọn Expression.</li><li>Value: Arrays.isEmpty(Arrays.toCsvString(Groups.startsWith(&#8220;active_directory&#8221;,&#8221;&#8221;,100))) ? Groups.startsWith(&#8220;OKTA&#8221;,&#8221;&#8221;,100) : Arrays.flatten(Groups.startsWith(&#8220;OKTA&#8221;,&#8221;&#8221;,100), Groups.startsWith(&#8220;active_directory&#8221;,&#8221;&#8221;,100))</li><li>Include in: chọn Any scope.</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="813" src="https://thegioifirewall.com/wp-content/uploads/49-5-1024x813.png" alt="" class="wp-image-16372" srcset="https://thegioifirewall.com/wp-content/uploads/49-5-1024x813.png 1024w, https://thegioifirewall.com/wp-content/uploads/49-5-300x238.png 300w, https://thegioifirewall.com/wp-content/uploads/49-5-768x610.png 768w, https://thegioifirewall.com/wp-content/uploads/49-5-1536x1220.png 1536w, https://thegioifirewall.com/wp-content/uploads/49-5.png 1553w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để mà Sophos Central có thể kết nối đến customScope trên Okta chúng ta cần phải tạo policy cho phép.</p>



<p class="wp-block-paragraph">Tại tab Access Policies nhấn Add New Access Policy và cấu hình theo thông số sau:</p>



<ul class="wp-block-list"><li>Name: ZTNA.</li><li>Description: ZTNA.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="570" src="https://thegioifirewall.com/wp-content/uploads/50-4-1024x570.png" alt="" class="wp-image-16373" srcset="https://thegioifirewall.com/wp-content/uploads/50-4-1024x570.png 1024w, https://thegioifirewall.com/wp-content/uploads/50-4-300x167.png 300w, https://thegioifirewall.com/wp-content/uploads/50-4-768x427.png 768w, https://thegioifirewall.com/wp-content/uploads/50-4.png 1440w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.4.Khai báo Identity Provider Okta trên Sophos Central,</strong></h4>



<p class="wp-block-paragraph">Để khai báo chúng ta truy cập vào trang quản trị của Sophos Central bằng quyền admin.</p>



<p class="wp-block-paragraph">Vào ZTNA &gt; Identity Providers &gt; nhấn Add identity provider.</p>



<ul class="wp-block-list"><li>Name: Okta.0</li><li>Provider: Okta</li><li>Client ID: nhập vào Client ID đã copy ở bước tạo App Integration Sophos ZTNA.</li><li>Client secret: nhập vào Client secrets đã copy ở bước tạo App Integration Sophos ZTNA.</li><li>Issue URI: nhập vào Issue URI đã copy ở bước tạo Authorization Server ZTNA.</li><li>Scope: nhập vào customScope và nhấn Test connection để kiểm tra kết nối giữa Sophos Central và Okta.</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="911" src="https://thegioifirewall.com/wp-content/uploads/51-4-1024x911.png" alt="" class="wp-image-16374" srcset="https://thegioifirewall.com/wp-content/uploads/51-4-1024x911.png 1024w, https://thegioifirewall.com/wp-content/uploads/51-4-300x267.png 300w, https://thegioifirewall.com/wp-content/uploads/51-4-768x683.png 768w, https://thegioifirewall.com/wp-content/uploads/51-4-1536x1367.png 1536w, https://thegioifirewall.com/wp-content/uploads/51-4.png 1915w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-trien-khai-giai-phap-sophos-zero-trust-network-access-phan-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
