<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IPSec Site to site VPN &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/ipsec-site-to-site-vpn/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Wed, 24 Aug 2022 04:39:04 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>IPSec Site to site VPN &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Sophos Firewall: Hướng dẫn cấu hình cho phép Users SSL VPN Remote Access kết nối với IPSec Site to site VPN.</title>
		<link>https://thegioifirewall.com/sophos-firewall-huong-dan-cau-hinh-cho-phep-users-ssl-vpn-remote-access-ket-noi-voi-ipsec-site-to-site-vpn/</link>
					<comments>https://thegioifirewall.com/sophos-firewall-huong-dan-cau-hinh-cho-phep-users-ssl-vpn-remote-access-ket-noi-voi-ipsec-site-to-site-vpn/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 19 Jun 2022 14:22:09 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Sophos XG]]></category>
		<category><![CDATA[IPSec Site to site VPN]]></category>
		<category><![CDATA[Sophos firewall]]></category>
		<category><![CDATA[SSL VPN Remote Access]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=16259</guid>

					<description><![CDATA[1.Overview SSL VPN Remote Access với IPsec Site to Site VPN đều là những tính năng cho phép kết nối user ở nhiều site hoặc không có mặt trong mạng nội bộ có thể kết nối truy cập vào tài nguyên của hệ thống. 2. Network Diagram Bài viết hôm nay sẽ hướng dẫn các [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>1.Overview</strong></p>



<p class="wp-block-paragraph">SSL VPN Remote Access với IPsec Site to Site VPN đều là những tính năng cho phép kết nối user ở nhiều site hoặc không có mặt trong mạng nội bộ có thể kết nối truy cập vào tài nguyên của hệ thống.</p>



<p class="wp-block-paragraph">2<strong>. Network Diagram</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img fetchpriority="high" decoding="async" width="634" height="400" src="https://thegioifirewall.com/wp-content/uploads/image-4887.png" alt="" class="wp-image-16801" srcset="https://thegioifirewall.com/wp-content/uploads/image-4887.png 634w, https://thegioifirewall.com/wp-content/uploads/image-4887-300x189.png 300w" sizes="(max-width: 634px) 100vw, 634px" /></figure>
</div>


<p class="wp-block-paragraph">Bài viết hôm nay sẽ hướng dẫn các bạn cấu hình cho phép user sử dụng SSL Remote Access VPN kết nối đến Remote Network thông qua IPSec VPN.</p>



<p class="wp-block-paragraph">Bài viết sẽ không đi vô chi tiết việc cấu hình SSL VPN Remote Access và IPSec site to site VPN, bạn có thể tham khảo các link bài biết sau:</p>



<p class="wp-block-paragraph">SSL VPN Remote Access: <a href="https://www.thegioifirewall.com/sophos-xg-firewall-huong-dan-cau-hinh-remote-access-ssl-vpn-voi-sophos-connect-client/">https://www.thegioifirewall.com/sophos-xg-firewall-huong-dan-cau-hinh-remote-access-ssl-vpn-voi-sophos-connect-client/</a></p>



<p class="wp-block-paragraph"> IPSec site to site VPN: <a href="https://www.thegioifirewall.com/video-huong-dan-cau-hinh-ipsec-vpn-site-to-site-giua-hai-thiet-bi-sophos-firewall/">https://www.thegioifirewall.com/video-huong-dan-cau-hinh-ipsec-vpn-site-to-site-giua-hai-thiet-bi-sophos-firewall/</a></p>



<p class="wp-block-paragraph"><strong>3. Hướng dẫn cấu hình.</strong></p>



<p class="wp-block-paragraph"><strong>3.1. Cấu hình trên Sophos Firewall 1</strong></p>



<p class="wp-block-paragraph">B<strong>ước 1: Tạo các Host &amp; Service.</strong></p>



<p class="wp-block-paragraph">Trên giao diện quản trị <strong>Sophos Firewall 1 &gt; System &gt; Host &amp; Services &gt; IP host &gt; Add.</strong> Tạo <strong>Remote Network</strong>.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img decoding="async" width="727" height="233" src="https://thegioifirewall.com/wp-content/uploads/image-4604.png" alt="" class="wp-image-16261" srcset="https://thegioifirewall.com/wp-content/uploads/image-4604.png 727w, https://thegioifirewall.com/wp-content/uploads/image-4604-300x96.png 300w" sizes="(max-width: 727px) 100vw, 727px" /></figure>
</div>


<p class="wp-block-paragraph">Di chuyển lên phần <strong>Configure &gt; Remote Access VPN (SFOS v19) &gt; SSL VPN.</strong> Kéo xuống phần <strong>Tunnel Access &gt;</strong> <strong>Permitted network resources (IPv4) &gt; Add Remote Network</strong> đã tạo.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img decoding="async" width="725" height="378" src="https://thegioifirewall.com/wp-content/uploads/image-4605.png" alt="" class="wp-image-16262" srcset="https://thegioifirewall.com/wp-content/uploads/image-4605.png 725w, https://thegioifirewall.com/wp-content/uploads/image-4605-300x156.png 300w" sizes="(max-width: 725px) 100vw, 725px" /></figure>
</div>


<p class="wp-block-paragraph">Tiếp theo bạn cần xác định <strong>SSL VPN Range. </strong>Bạn di chuyển đến <strong>Configure &gt; Remote Access VPN (SFOS v19) &gt; SSL VPN</strong> <strong>&gt; SSL VPN Global Settings</strong>.</p>



<p class="wp-block-paragraph">Dải <strong>IP SSL VPN Range</strong> là <strong>10.81.234.5/24.</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="624" height="240" src="https://thegioifirewall.com/wp-content/uploads/image-4606.png" alt="" class="wp-image-16263" srcset="https://thegioifirewall.com/wp-content/uploads/image-4606.png 624w, https://thegioifirewall.com/wp-content/uploads/image-4606-300x115.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure>
</div>


<p class="wp-block-paragraph">Bạn sẽ tạo <strong>SSL VPN Network</strong> trong <strong>Host &amp; Services</strong>.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="323" src="https://thegioifirewall.com/wp-content/uploads/image-4607-1024x323.png" alt="" class="wp-image-16264" srcset="https://thegioifirewall.com/wp-content/uploads/image-4607-1024x323.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-4607-300x94.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4607-768x242.png 768w, https://thegioifirewall.com/wp-content/uploads/image-4607.png 1089w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph">Tiếp theo bạn cấu hình trong <strong>IPSec Connections</strong>. Bạn add thêm <strong>SSL VPN Range</strong> vào <strong>Local Subnet.</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="723" height="406" src="https://thegioifirewall.com/wp-content/uploads/image-4609.png" alt="" class="wp-image-16266" srcset="https://thegioifirewall.com/wp-content/uploads/image-4609.png 723w, https://thegioifirewall.com/wp-content/uploads/image-4609-300x168.png 300w" sizes="auto, (max-width: 723px) 100vw, 723px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Bước 2: Cấu</strong> <strong>hình Firewall Rule.</strong></p>



<p class="wp-block-paragraph">Tạo firewall như hình dưới.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="401" src="https://thegioifirewall.com/wp-content/uploads/image-4610-1024x401.png" alt="" class="wp-image-16267" srcset="https://thegioifirewall.com/wp-content/uploads/image-4610-1024x401.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-4610-300x117.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4610-768x301.png 768w, https://thegioifirewall.com/wp-content/uploads/image-4610.png 1050w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph">Tiếp theo bạn cần bật <strong>Ping cho Zone VPN</strong>. Bạn di chuyển <strong>System &gt; Administraion &gt; Device Access.</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="418" src="https://thegioifirewall.com/wp-content/uploads/image-4611-1024x418.png" alt="" class="wp-image-16268" srcset="https://thegioifirewall.com/wp-content/uploads/image-4611-1024x418.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-4611-300x123.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4611-768x314.png 768w, https://thegioifirewall.com/wp-content/uploads/image-4611.png 1104w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>3.2. Cấu hình trên Sophos Firewall </strong>2</p>



<p class="wp-block-paragraph">B<strong>ước 1: Tạo Host &amp; Service.</strong></p>



<p class="wp-block-paragraph">Bạn sẽ tạo IP Host là <strong>Internal Network</strong>.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="326" src="https://thegioifirewall.com/wp-content/uploads/image-4612-1024x326.png" alt="" class="wp-image-16269" srcset="https://thegioifirewall.com/wp-content/uploads/image-4612-1024x326.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-4612-300x96.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4612-768x245.png 768w, https://thegioifirewall.com/wp-content/uploads/image-4612.png 1089w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph">Tạo<strong> SSL VPN Range</strong> như <strong>Sophos Firewall 1</strong></p>


<div class="wp-block-image">
<figure class="aligncenter"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-4607-1024x323.png" alt="Hình ảnh này chưa có thuộc tính alt; tên tệp của nó là image-4607-1024x323.png"/></figure>
</div>


<p class="wp-block-paragraph"><strong>Bước 2: Cấu hình IPSec Connections.</strong></p>



<p class="wp-block-paragraph">Bạn thêm <strong>SSL VPN Range</strong> vào mục <strong>Remote Subnet.</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="726" height="406" src="https://thegioifirewall.com/wp-content/uploads/image-4613.png" alt="" class="wp-image-16270" srcset="https://thegioifirewall.com/wp-content/uploads/image-4613.png 726w, https://thegioifirewall.com/wp-content/uploads/image-4613-300x168.png 300w" sizes="auto, (max-width: 726px) 100vw, 726px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Bước 3: Cấu hình Firewall Rule.</strong></p>



<p class="wp-block-paragraph">Bạn tạo firewall rule như hình dưới.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="1024" height="406" src="https://thegioifirewall.com/wp-content/uploads/image-4614-1024x406.png" alt="" class="wp-image-16271" srcset="https://thegioifirewall.com/wp-content/uploads/image-4614-1024x406.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-4614-300x119.png 300w, https://thegioifirewall.com/wp-content/uploads/image-4614-768x305.png 768w, https://thegioifirewall.com/wp-content/uploads/image-4614.png 1051w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph"> Tiếp theo bạn cũng cần bật <strong>Ping cho Zone VPN</strong>. </p>


<div class="wp-block-image">
<figure class="aligncenter"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-4611-1024x418.png" alt="Hình ảnh này chưa có thuộc tính alt; tên tệp của nó là image-4611-1024x418.png"/></figure>
</div>


<p class="wp-block-paragraph">Như vậy bạn đã định cấu hình các VPN policies và firewall rules, vì vậy traffic từ SSL VPN sẽ kết nối đến remote network thông qua VPN Tunnel.</p>



<p class="wp-block-paragraph"><strong>Bước 4: Cấu hình IPsec Route</strong></p>



<p class="wp-block-paragraph">Trên giao diện <strong>Sophos Firewall > admin > Console</strong> <strong>> Chọn 4.Device Console</strong>.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="400" height="243" src="https://thegioifirewall.com/wp-content/uploads/image-4888.png" alt="" class="wp-image-16803" srcset="https://thegioifirewall.com/wp-content/uploads/image-4888.png 400w, https://thegioifirewall.com/wp-content/uploads/image-4888-300x182.png 300w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
</div>


<p class="wp-block-paragraph">Add IPsec Route như sau:</p>



<p class="wp-block-paragraph">console> system ipsec_route add net 172.16.10.0/255.255.255.0 tunnelname &lt;điền tên tunnel tạo kết nối IPsec với firewall 1>.</p>



<p class="wp-block-paragraph">Check route vừa tạo: </p>



<p class="wp-block-paragraph">console> system ipsec_route show.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/sophos-firewall-huong-dan-cau-hinh-cho-phep-users-ssl-vpn-remote-access-ket-noi-voi-ipsec-site-to-site-vpn/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
