<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Palo Alto &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/palo-alto/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Tue, 27 Feb 2024 04:35:09 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Palo Alto &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>PALO ALTO : CÁCH CẤU HÌNH QOS GIỚI HẠN BĂNG THÔNG DOWNLOAD</title>
		<link>https://thegioifirewall.com/palo-alto-cach-cau-hinh-qos-gioi-han-bang-thong-download/</link>
					<comments>https://thegioifirewall.com/palo-alto-cach-cau-hinh-qos-gioi-han-bang-thong-download/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Tue, 27 Feb 2024 04:35:07 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<category><![CDATA[QoS]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=18825</guid>

					<description><![CDATA[I. Tổng quan Quality of Service (QoS) là một khía cạnh quan trọng trong việc quản lý mạng và điều chỉnh việc sử dụng tài nguyên mạng để đảm bảo chất lượng dịch vụ cho các ứng dụng và dịch vụ mạng. QoS cho phép phân bổ và quản lý băng thông mạng một cách [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>I. Tổng quan</strong></p>



<p class="wp-block-paragraph">Quality of Service (QoS) là một khía cạnh quan trọng trong việc quản lý mạng và điều chỉnh việc sử dụng tài nguyên mạng để đảm bảo chất lượng dịch vụ cho các ứng dụng và dịch vụ mạng.</p>



<p class="wp-block-paragraph">QoS cho phép phân bổ và quản lý băng thông mạng một cách hiệu quả, giúp ngăn chặn quá trình kẹt mạng và đảm bảo rằng các dịch vụ quan trọng có đủ băng thông để hoạt động một cách mượt mà.</p>



<p class="wp-block-paragraph"><strong>II. Mục lục</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình policy QoS</strong></p>



<p class="wp-block-paragraph"><strong>2. Cấu hình giới hạn băng thông</strong></p>



<p class="wp-block-paragraph"><strong>3. Test kết quả</strong></p>



<p class="wp-block-paragraph"><strong>III. Nội dung bài lab</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình policy QoS</strong></p>



<p class="wp-block-paragraph">Đầu tiên truy cập <strong>Policies >> QoS</strong></p>



<p class="wp-block-paragraph"><strong>General</strong> : điền tên tho mong muốn</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img fetchpriority="high" decoding="async" width="975" height="415" src="https://thegioifirewall.com/wp-content/uploads/image-6100.png" alt="" class="wp-image-18826" srcset="https://thegioifirewall.com/wp-content/uploads/image-6100.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6100-300x128.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6100-768x327.png 768w" sizes="(max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab Source</strong></p>



<p class="wp-block-paragraph"><strong>Source Zone :</strong> LAN</p>



<p class="wp-block-paragraph"><strong>Source User :</strong> abc\hr-browsing</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="702" height="413" src="https://thegioifirewall.com/wp-content/uploads/image-6109.png" alt="" class="wp-image-18835" style="width:733px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6109.png 702w, https://thegioifirewall.com/wp-content/uploads/image-6109-300x176.png 300w" sizes="(max-width: 702px) 100vw, 702px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab Destination</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="975" height="578" src="https://thegioifirewall.com/wp-content/uploads/image-6102.png" alt="" class="wp-image-18828" style="width:737px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6102.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6102-300x178.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6102-768x455.png 768w" sizes="(max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab Application :</strong> web-browsing, ssl, mega-base (mình sẽ test download link mega)</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="536" src="https://thegioifirewall.com/wp-content/uploads/image-6103.png" alt="" class="wp-image-18829" style="width:768px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6103.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6103-300x165.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6103-768x422.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab Other Settings</strong></p>



<p class="wp-block-paragraph"><strong>Class :</strong> 1</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="267" src="https://thegioifirewall.com/wp-content/uploads/image-6104.png" alt="" class="wp-image-18830" srcset="https://thegioifirewall.com/wp-content/uploads/image-6104.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6104-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6104-768x210.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>2. Cấu hình giới hạn băng thông</strong></p>



<p class="wp-block-paragraph">Tiếp theo qua tab <strong>Network >>Network Profile>> QoS Profile >> Add</strong></p>



<p class="wp-block-paragraph">Mình đã <strong>add </strong>thêm <strong>Class1</strong> với thông số giới hạng như ảnh</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="379" src="https://thegioifirewall.com/wp-content/uploads/image-6105.png" alt="" class="wp-image-18831" style="width:813px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6105.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6105-300x117.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6105-768x299.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Các bạn truy cập vào <strong>Network >> QoS</strong></p>



<p class="wp-block-paragraph"><strong>Egress Max (Mbps):</strong> điền băng thông của đường truyền</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="424" src="https://thegioifirewall.com/wp-content/uploads/image-6106.png" alt="" class="wp-image-18832" style="width:809px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6106.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6106-300x130.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6106-768x334.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>3. Test kết quả</strong></p>



<p class="wp-block-paragraph">Dung lượng download link mega khi chưa commit cấu hình QoS</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="615" src="https://thegioifirewall.com/wp-content/uploads/image-6107.png" alt="" class="wp-image-18833" style="width:747px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6107.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6107-300x189.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6107-768x484.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Kết quả áp dụng QoS băng thông download bị giảm xuống</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="630" src="https://thegioifirewall.com/wp-content/uploads/image-6108.png" alt="" class="wp-image-18834" style="width:740px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6108.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6108-300x194.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6108-768x496.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/palo-alto-cach-cau-hinh-qos-gioi-han-bang-thong-download/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PALO ALTO FIRMWARE 10.2 : CÁCH CẤU HÌNH DỰ PHÒNG ĐƯỜNG WAN BẰNG PHƯƠNG PHÁP ECMP</title>
		<link>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-du-phong-duong-wan-bang-phuong-phap-ecmp-2/</link>
					<comments>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-du-phong-duong-wan-bang-phuong-phap-ecmp-2/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Wed, 31 Jan 2024 02:56:54 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[ECMP]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=18808</guid>

					<description><![CDATA[Tổng quan : Trong Palo Alto Networks, ECMP (Equal Cost Multi-Path) được sử dụng để cân bằng tải traffic giữa nhiều đường đi có chi phí bằng nhau đến một đích. Tính năng ECMP có thể được sử dụng không chỉ để cân bằng tải mà còn để đảm bảo sự dự phòng (redundancy) và [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Tổng quan :</strong></p>



<p class="wp-block-paragraph">Trong Palo Alto Networks, ECMP (Equal Cost Multi-Path) được sử dụng để cân bằng tải traffic giữa nhiều đường đi có chi phí bằng nhau đến một đích. Tính năng ECMP có thể được sử dụng không chỉ để cân bằng tải mà còn để đảm bảo sự dự phòng (redundancy) và sẵn sàng (resilience) cho đường WAN.</p>



<p class="wp-block-paragraph"><strong>Diagram :</strong></p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="1017" height="646" src="https://thegioifirewall.com/wp-content/uploads/image-6087.png" alt="" class="wp-image-18779" srcset="https://thegioifirewall.com/wp-content/uploads/image-6087.png 1017w, https://thegioifirewall.com/wp-content/uploads/image-6087-300x191.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6087-768x488.png 768w" sizes="auto, (max-width: 1017px) 100vw, 1017px" /></figure>



<p class="wp-block-paragraph"><strong>Mục lục :</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình ECMP</strong></p>



<p class="wp-block-paragraph"><strong>2. Cấu hình rule cho mạng Local ra internet</strong></p>



<p class="wp-block-paragraph"><strong>3. Kết quả</strong></p>



<p class="wp-block-paragraph"><strong>Nội dung cấu hình :</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình ECMP</strong></p>



<p class="wp-block-paragraph">Đầu tiên các bạn vào&nbsp;<strong>Network &gt;&gt; Virtual Routers &gt;&gt; Add</strong></p>



<p class="wp-block-paragraph">Tab&nbsp;<strong>Router Settings</strong></p>



<p class="wp-block-paragraph"><strong>General :</strong>&nbsp;những interface được tham gia router settings</p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="975" height="447" src="https://thegioifirewall.com/wp-content/uploads/image-5971.png" alt="" class="wp-image-18638" srcset="https://thegioifirewall.com/wp-content/uploads/image-5971.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5971-300x138.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5971-768x352.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>Chuyển qua tab ECMP</strong></p>



<p class="wp-block-paragraph">Các bạn nhấn vào&nbsp;<strong>Enable</strong></p>



<p class="wp-block-paragraph"><strong>Method</strong>&nbsp;: chọn&nbsp;<strong>balanced round robin</strong></p>


<div class="wp-block-image">
<figure class="aligncenter is-resized"><img loading="lazy" decoding="async" width="975" height="603" src="https://thegioifirewall.com/wp-content/uploads/image-5972.png" alt="" class="wp-image-18639" style="width:724px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5972.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5972-300x186.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5972-768x475.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tại Tab Static Route</strong></p>



<p class="wp-block-paragraph"><strong>Mạng WAN FPT</strong></p>



<p class="wp-block-paragraph">Các bạn tiến hành điền thông tin tương thích của mình để mạng LAN có thể qua WAN ra internet</p>


<div class="wp-block-image">
<figure class="aligncenter is-resized"><img loading="lazy" decoding="async" width="851" height="735" src="https://thegioifirewall.com/wp-content/uploads/image-5973.png" alt="" class="wp-image-18640" style="width:606px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5973.png 851w, https://thegioifirewall.com/wp-content/uploads/image-5973-300x259.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5973-768x663.png 768w" sizes="auto, (max-width: 851px) 100vw, 851px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tương tự mạng WAN Viettel</strong></p>


<div class="wp-block-image">
<figure class="aligncenter is-resized"><img loading="lazy" decoding="async" width="975" height="641" src="https://thegioifirewall.com/wp-content/uploads/image-5974.png" alt="" class="wp-image-18641" style="width:704px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5974.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5974-300x197.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5974-768x505.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter is-resized"><img loading="lazy" decoding="async" width="975" height="614" src="https://thegioifirewall.com/wp-content/uploads/image-5975.png" alt="" class="wp-image-18642" style="width:700px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5975.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5975-300x189.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5975-768x484.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>2. Cấu hình rule cho mạng Local ra internet</strong></p>



<p class="wp-block-paragraph"><strong>General :</strong>&nbsp;điền tên theo ý muốn</p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="975" height="338" src="https://thegioifirewall.com/wp-content/uploads/image-5976.png" alt="" class="wp-image-18643" srcset="https://thegioifirewall.com/wp-content/uploads/image-5976.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5976-300x104.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5976-768x266.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>Source :</strong>&nbsp;cho source zone mà mình muốn cho ra internet</p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="975" height="373" src="https://thegioifirewall.com/wp-content/uploads/image-5977.png" alt="" class="wp-image-18644" srcset="https://thegioifirewall.com/wp-content/uploads/image-5977.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5977-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5977-768x294.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>Destination</strong>&nbsp;: chọn WAN</p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="975" height="375" src="https://thegioifirewall.com/wp-content/uploads/image-5978.png" alt="" class="wp-image-18645" srcset="https://thegioifirewall.com/wp-content/uploads/image-5978.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5978-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5978-768x295.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="975" height="326" src="https://thegioifirewall.com/wp-content/uploads/image-5979.png" alt="" class="wp-image-18646" srcset="https://thegioifirewall.com/wp-content/uploads/image-5979.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5979-300x100.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5979-768x257.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>3. Kết quả</strong></p>



<p class="wp-block-paragraph">Mình tiến hành lấy PC thuộc mạng LAN ping 8.8.8.8 &gt;&gt; ngắt kết nối 1 đầu WAN &gt;&gt; thì lập tức sẽ chạy ra internet theo đường WAN còn lại (như ảnh)</p>


<div class="wp-block-image">
<figure class="aligncenter is-resized"><img loading="lazy" decoding="async" width="1024" height="593" src="https://thegioifirewall.com/wp-content/uploads/image-5981-1024x593.png" alt="" class="wp-image-18648" style="width:736px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5981-1024x593.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-5981-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5981-768x445.png 768w, https://thegioifirewall.com/wp-content/uploads/image-5981.png 1106w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-du-phong-duong-wan-bang-phuong-phap-ecmp-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PALO ALTO FIRMWARE 10.2 : CÁCH CẤU HÌNH NAT WEB RA MÔI TRƯỜNG INTERNET</title>
		<link>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-nat-web-ra-moi-truong-internet/</link>
					<comments>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-nat-web-ra-moi-truong-internet/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Wed, 31 Jan 2024 02:35:40 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[NAT]]></category>
		<category><![CDATA[NAT Web]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=18650</guid>

					<description><![CDATA[Tổng quan : Trong Palo Alto Networks, tính năng NAT (Network Address Translation) Web đóng một vai trò quan trọng trong việc cung cấp an ninh mạng và kiểm soát truy cập Internet. NAT Web được sử dụng để ẩn địa chỉ IP thực sự của các máy tính trong mạng nội bộ và thay [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Tổng quan :</strong></p>



<p class="wp-block-paragraph">Trong Palo Alto Networks, tính năng NAT (Network Address Translation) Web đóng một vai trò quan trọng trong việc cung cấp an ninh mạng và kiểm soát truy cập Internet. NAT Web được sử dụng để ẩn địa chỉ IP thực sự của các máy tính trong mạng nội bộ và thay thế nó bằng một địa chỉ IP công cộng, giúp bảo vệ sự riêng tư và tăng cường an ninh mạng.</p>



<p class="wp-block-paragraph"><strong>Diagram :</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="1017" height="646" src="https://thegioifirewall.com/wp-content/uploads/image-6088.png" alt="" class="wp-image-18784" style="width:723px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6088.png 1017w, https://thegioifirewall.com/wp-content/uploads/image-6088-300x191.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6088-768x488.png 768w" sizes="auto, (max-width: 1017px) 100vw, 1017px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Mục lục :</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình NAS IP máy chủ Web</strong></p>



<p class="wp-block-paragraph"><strong>2. Cấu hình rule cho web</strong></p>



<p class="wp-block-paragraph"><strong>3. Kiểm tra kết quả</strong></p>



<p class="wp-block-paragraph"><strong>Nội dung cấu hình :</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình NAS IP máy chủ Web</strong></p>



<p class="wp-block-paragraph">Các bạn vào <strong>Policies >> NAT >> Nhấn Add </strong> </p>



<p class="wp-block-paragraph"><strong>Name </strong>: điền tên bất kỳ</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="464" src="https://thegioifirewall.com/wp-content/uploads/image-5983.png" alt="" class="wp-image-18652" style="width:767px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5983.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5983-300x143.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5983-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab Original Packet</strong></p>



<p class="wp-block-paragraph"><strong>Destination Zone : </strong>chọn WAN</p>



<p class="wp-block-paragraph"><strong>Destination Interface :</strong> cổng WAN interface</p>



<p class="wp-block-paragraph"><strong>Service :</strong> chọn https</p>



<p class="wp-block-paragraph"><strong>Source Address :</strong> tích chọn Any</p>



<p class="wp-block-paragraph"><strong>Destination Address : </strong>đây là cổng WAN để web ra vào</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="975" height="479" src="https://thegioifirewall.com/wp-content/uploads/image-5984.png" alt="" class="wp-image-18653" srcset="https://thegioifirewall.com/wp-content/uploads/image-5984.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5984-300x147.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5984-768x377.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab Translated Packet</strong></p>



<p class="wp-block-paragraph"><strong>Translation Type :</strong> chọn Dynamic IP</p>



<p class="wp-block-paragraph"><strong>Translated Address : </strong>IP máy chủ web</p>



<p class="wp-block-paragraph"><strong>Translated Port :</strong> 443</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="346" src="https://thegioifirewall.com/wp-content/uploads/image-5985.png" alt="" class="wp-image-18654" srcset="https://thegioifirewall.com/wp-content/uploads/image-5985.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5985-300x106.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5985-768x273.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="372" src="https://thegioifirewall.com/wp-content/uploads/image-5986.png" alt="" class="wp-image-18655" srcset="https://thegioifirewall.com/wp-content/uploads/image-5986.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5986-300x114.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5986-768x293.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>2. Cấu hình rule cho web</strong></p>



<p class="wp-block-paragraph"><strong>General :</strong> tên bất kỳ</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="336" src="https://thegioifirewall.com/wp-content/uploads/image-5987.png" alt="" class="wp-image-18656" srcset="https://thegioifirewall.com/wp-content/uploads/image-5987.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5987-300x103.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5987-768x265.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>Source Zone :</strong> WAN</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="374" src="https://thegioifirewall.com/wp-content/uploads/image-5988.png" alt="" class="wp-image-18657" srcset="https://thegioifirewall.com/wp-content/uploads/image-5988.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5988-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5988-768x295.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>Destination Zone :</strong> chọn DMZ</p>



<p class="wp-block-paragraph"><strong>Destination :</strong> IP WAN</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="975" height="372" src="https://thegioifirewall.com/wp-content/uploads/image-5989.png" alt="" class="wp-image-18658" style="width:840px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5989.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5989-300x114.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5989-768x293.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="354" src="https://thegioifirewall.com/wp-content/uploads/image-5990.png" alt="" class="wp-image-18659" srcset="https://thegioifirewall.com/wp-content/uploads/image-5990.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5990-300x109.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5990-768x279.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>Service :</strong> chọn HTTPS</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="357" src="https://thegioifirewall.com/wp-content/uploads/image-5991.png" alt="" class="wp-image-18660" srcset="https://thegioifirewall.com/wp-content/uploads/image-5991.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5991-300x110.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5991-768x281.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="323" src="https://thegioifirewall.com/wp-content/uploads/image-5992.png" alt="" class="wp-image-18661" srcset="https://thegioifirewall.com/wp-content/uploads/image-5992.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5992-300x99.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5992-768x254.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>3. Kiểm tra kết quả</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="499" src="https://thegioifirewall.com/wp-content/uploads/image-6089.png" alt="" class="wp-image-18785" srcset="https://thegioifirewall.com/wp-content/uploads/image-6089.png 975w, https://thegioifirewall.com/wp-content/uploads/image-6089-300x154.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6089-768x393.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-nat-web-ra-moi-truong-internet/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PALO ALTO FIRMWARE 10.2 : CÁCH CẤU HÌNH DỰ PHÒNG ĐƯỜNG WAN BẰNG PHƯƠNG PHÁP ECMP</title>
		<link>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-du-phong-duong-wan-bang-phuong-phap-ecmp/</link>
					<comments>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-du-phong-duong-wan-bang-phuong-phap-ecmp/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 04:58:33 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[ECMP]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<category><![CDATA[WAN]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=18637</guid>

					<description><![CDATA[Tổng quan : Trong Palo Alto Networks, ECMP (Equal Cost Multi-Path) được sử dụng để cân bằng tải traffic giữa nhiều đường đi có chi phí bằng nhau đến một đích. Tính năng ECMP có thể được sử dụng không chỉ để cân bằng tải mà còn để đảm bảo sự dự phòng (redundancy) và [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Tổng quan :</strong></p>



<p class="wp-block-paragraph">Trong Palo Alto Networks, ECMP (Equal Cost Multi-Path) được sử dụng để cân bằng tải traffic giữa nhiều đường đi có chi phí bằng nhau đến một đích. Tính năng ECMP có thể được sử dụng không chỉ để cân bằng tải mà còn để đảm bảo sự dự phòng (redundancy) và sẵn sàng (resilience) cho đường WAN.</p>



<p class="wp-block-paragraph"><strong>Diagram :</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="1017" height="646" src="https://thegioifirewall.com/wp-content/uploads/image-6087.png" alt="" class="wp-image-18779" style="width:754px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6087.png 1017w, https://thegioifirewall.com/wp-content/uploads/image-6087-300x191.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6087-768x488.png 768w" sizes="auto, (max-width: 1017px) 100vw, 1017px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Mục lục :</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình ECMP</strong></p>



<p class="wp-block-paragraph"><strong>2. Cấu hình rule cho mạng Local ra internet</strong></p>



<p class="wp-block-paragraph"><strong>3. Kết quả</strong></p>



<p class="wp-block-paragraph"><strong>Nội dung cấu hình :</strong></p>



<p class="wp-block-paragraph"><strong>1. Cấu hình ECMP</strong></p>



<p class="wp-block-paragraph">Đầu tiên các bạn vào <strong>Network &gt;&gt; Virtual Routers &gt;&gt; Add</strong></p>



<p class="wp-block-paragraph">Tab <strong>Router Settings</strong></p>



<p class="wp-block-paragraph"><strong>General :</strong> những interface được tham gia router settings</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="447" src="https://thegioifirewall.com/wp-content/uploads/image-5971.png" alt="" class="wp-image-18638" style="width:779px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5971.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5971-300x138.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5971-768x352.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Chuyển qua tab ECMP</strong></p>



<p class="wp-block-paragraph">Các bạn nhấn vào <strong>Enable</strong></p>



<p class="wp-block-paragraph"><strong>Method</strong> : chọn <strong>balanced round robin</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="603" src="https://thegioifirewall.com/wp-content/uploads/image-5972.png" alt="" class="wp-image-18639" style="width:707px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5972.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5972-300x186.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5972-768x475.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tại Tab Static Route</strong></p>



<p class="wp-block-paragraph"><strong>Mạng WAN FPT</strong></p>



<p class="wp-block-paragraph">Các bạn tiến hành điền thông tin tương thích của mình để mạng LAN có thể qua WAN ra internet</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="851" height="735" src="https://thegioifirewall.com/wp-content/uploads/image-5973.png" alt="" class="wp-image-18640" style="width:599px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5973.png 851w, https://thegioifirewall.com/wp-content/uploads/image-5973-300x259.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5973-768x663.png 768w" sizes="auto, (max-width: 851px) 100vw, 851px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tương tự mạng WAN Viettel</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="641" src="https://thegioifirewall.com/wp-content/uploads/image-5974.png" alt="" class="wp-image-18641" style="width:678px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5974.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5974-300x197.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5974-768x505.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="614" src="https://thegioifirewall.com/wp-content/uploads/image-5975.png" alt="" class="wp-image-18642" style="width:780px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5975.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5975-300x189.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5975-768x484.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>2. Cấu hình rule cho mạng Local ra internet</strong></p>



<p class="wp-block-paragraph"><strong>General :</strong> điền tên theo ý muốn</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="338" src="https://thegioifirewall.com/wp-content/uploads/image-5976.png" alt="" class="wp-image-18643" style="width:773px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5976.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5976-300x104.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5976-768x266.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Source :</strong> cho source zone mà mình muốn cho ra internet</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="373" src="https://thegioifirewall.com/wp-content/uploads/image-5977.png" alt="" class="wp-image-18644" style="width:797px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5977.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5977-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5977-768x294.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Destination</strong> : chọn WAN</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="375" src="https://thegioifirewall.com/wp-content/uploads/image-5978.png" alt="" class="wp-image-18645" srcset="https://thegioifirewall.com/wp-content/uploads/image-5978.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5978-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5978-768x295.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="326" src="https://thegioifirewall.com/wp-content/uploads/image-5979.png" alt="" class="wp-image-18646" srcset="https://thegioifirewall.com/wp-content/uploads/image-5979.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5979-300x100.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5979-768x257.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>3. Kết quả </strong></p>



<p class="wp-block-paragraph">Mình tiến hành lấy PC thuộc mạng LAN ping 8.8.8.8 &gt;&gt; ngắt kết nối 1 đầu WAN &gt;&gt; thì lập tức sẽ chạy ra internet theo đường WAN còn lại (như ảnh)</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="593" src="https://thegioifirewall.com/wp-content/uploads/image-5981-1024x593.png" alt="" class="wp-image-18648" style="width:746px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5981-1024x593.png 1024w, https://thegioifirewall.com/wp-content/uploads/image-5981-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5981-768x445.png 768w, https://thegioifirewall.com/wp-content/uploads/image-5981.png 1106w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-du-phong-duong-wan-bang-phuong-phap-ecmp/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PALO ALTO FIRMWARE 10.2 : CÁCH CẤU HÌNH CLIENT TO SITE CHO NHÂN VIÊN Ở BÊN NGOÀI VẪN TRUY CẬP ĐƯỢC MẠNG NỘI BỘ</title>
		<link>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-client-to-site-cho-nhan-vien-o-ben-ngoai-van-truy-cap-duoc-mang-noi-bo/</link>
					<comments>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-client-to-site-cho-nhan-vien-o-ben-ngoai-van-truy-cap-duoc-mang-noi-bo/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Wed, 17 Jan 2024 02:29:37 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Client to site]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=18597</guid>

					<description><![CDATA[Tổng quan : VPN Client-to-Site là một loại kết nối mạng ảo (Virtual Private Network &#8211; VPN) trong đó người dùng cá nhân hoặc nhóm người dùng có thể kết nối an toàn đến mạng nội bộ của một tổ chức từ xa thông qua Internet. Sơ đồ : Mục lục : Nội dung bài [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Tổng quan :</strong></p>



<p class="wp-block-paragraph">VPN Client-to-Site là một loại kết nối mạng ảo (Virtual Private Network &#8211; VPN) trong đó người dùng cá nhân hoặc nhóm người dùng có thể kết nối an toàn đến mạng nội bộ của một tổ chức từ xa thông qua Internet.</p>



<p class="wp-block-paragraph"><strong>Sơ đồ :</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="932" height="722" src="https://thegioifirewall.com/wp-content/uploads/image-6086.png" alt="" class="wp-image-18764" style="width:667px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-6086.png 932w, https://thegioifirewall.com/wp-content/uploads/image-6086-300x232.png 300w, https://thegioifirewall.com/wp-content/uploads/image-6086-768x595.png 768w" sizes="auto, (max-width: 932px) 100vw, 932px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Mục lục :</strong></p>



<ul class="wp-block-list">
<li><strong>B1. Tạo certificate cho VPN</strong></li>



<li><strong>B2. Tạo SSL/TLS Service Profile</strong></li>



<li><strong>B3. Tạo user dùng đăng nhập VPN</strong></li>



<li><strong>B4. Tạo Authentication Profile</strong></li>



<li><strong>B5. Tạo Portal</strong></li>



<li><strong>B6. Tạo tunnel VPN</strong></li>



<li><strong>B7. Tạo GlobalProtect Gateway</strong></li>



<li><strong>B8. Tiến hành đăng nhập GlobalProtect Portal</strong></li>



<li><strong>B9. Kiểm tra kết quả</strong></li>
</ul>



<p class="wp-block-paragraph"><strong>Nội dung bài viết :</strong></p>



<p class="wp-block-paragraph"><strong>B1. Tạo certificate cho VPN</strong></p>



<p class="wp-block-paragraph">Đầu tiên các bạn vào <strong>Device &gt;&gt; Certificate management &gt;&gt; Generate</strong></p>



<p class="wp-block-paragraph">Các bạn tiến hành điền thông tin như sau ( danh mục name có thể điền tùy ý )</p>



<p class="wp-block-paragraph">Nhấn <strong>Generate</strong> để tạo</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="453" src="https://thegioifirewall.com/wp-content/uploads/image-5935.png" alt="" class="wp-image-18599" style="width:773px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5935.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5935-300x139.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5935-768x357.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"> Tương tự, tạo thêm <strong>Certificate</strong> với <strong>Common Name là IP WAN</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="661" height="1024" src="https://thegioifirewall.com/wp-content/uploads/image-5934-661x1024.png" alt="" class="wp-image-18598" style="width:399px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5934-661x1024.png 661w, https://thegioifirewall.com/wp-content/uploads/image-5934-194x300.png 194w, https://thegioifirewall.com/wp-content/uploads/image-5934-768x1190.png 768w, https://thegioifirewall.com/wp-content/uploads/image-5934.png 794w" sizes="auto, (max-width: 661px) 100vw, 661px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>B2. Tạo SSL/TLS Service Profile</strong></p>



<p class="wp-block-paragraph">Theo đường dẫn <strong>Device &gt; Certificate Management &gt; SSL/TLS Service Profile</strong></p>



<p class="wp-block-paragraph">Các bạn nhấn <strong>Add</strong> và điền thông tin như ảnh</p>



<p class="wp-block-paragraph">Riêng ở mục <strong>Certificate</strong> : chọn <strong>Certificate đã tạo ở bước 1</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="421" src="https://thegioifirewall.com/wp-content/uploads/image-5936.png" alt="" class="wp-image-18600" style="width:806px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5936.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5936-300x130.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5936-768x332.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>B3. Tạo user dùng đăng nhập VPN</strong></p>



<p class="wp-block-paragraph">Các bạn theo đường dẫn sau : <strong>Device &gt; Local User Database &gt; Users</strong></p>



<p class="wp-block-paragraph">Nhấn <strong>Add</strong> để tạo </p>



<p class="wp-block-paragraph">Các bạn tiến hành nhập <strong>Name và Password</strong> &gt;&gt; nhấn <strong>OK</strong> để tạo</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="431" src="https://thegioifirewall.com/wp-content/uploads/image-5937.png" alt="" class="wp-image-18601" style="width:812px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5937.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5937-300x133.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5937-768x339.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>B4. Tạo Authentication Profile</strong></p>



<p class="wp-block-paragraph"><strong>Device &gt; Authentication Profile &gt;</strong> nhấn <strong>Add</strong></p>



<p class="wp-block-paragraph">Tại Tab <strong>Authentication</strong></p>



<p class="wp-block-paragraph"><strong>Name</strong> : nhập tùy ý</p>



<p class="wp-block-paragraph"><strong>Type</strong> : Local Database</p>



<p class="wp-block-paragraph"><strong>Username Modifier</strong> : chọn %USERINPUT%</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="417" src="https://thegioifirewall.com/wp-content/uploads/image-5938.png" alt="" class="wp-image-18602" style="width:811px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5938.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5938-300x128.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5938-768x328.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tab <strong>Advanced :</strong></p>



<p class="wp-block-paragraph">Tại <strong>Allow List</strong> tiến hành Add những User mà bạn đã tạo để được cấp quyền VPN</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="823" src="https://thegioifirewall.com/wp-content/uploads/image-5939.png" alt="" class="wp-image-18603" style="width:590px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5939.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5939-300x253.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5939-768x648.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>B5. Tạo Portal</strong></p>



<p class="wp-block-paragraph">Theo đường dẫn <strong>Network &gt; GlobalProtect &gt; Portals &gt; Add</strong></p>



<p class="wp-block-paragraph"><strong>Tab General:</strong></p>



<p class="wp-block-paragraph"><strong>Name</strong>: gp-portal<br><strong>Interface</strong>: ethernet1/2 (WAN)<br><strong>IP Address Type</strong>: IPv4 Only</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="418" src="https://thegioifirewall.com/wp-content/uploads/image-5940.png" alt="" class="wp-image-18604" style="width:774px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5940.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5940-300x129.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5940-768x329.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Trong bảng <strong>Cient Authentication</strong> nhấn <strong>Add</strong> và cấu hình theo các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Name:</strong> AU<br><strong>OS</strong>: Any<br><strong>Authentication Profile:</strong> Local_User<br>Nhấn <strong>OK</strong> để tạo</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="598" src="https://thegioifirewall.com/wp-content/uploads/image-5941.png" alt="" class="wp-image-18605" style="width:714px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5941.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5941-300x184.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5941-768x471.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tại <strong>SSL/TLS Service Profile</strong> : chọn GW_Portal</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="570" src="https://thegioifirewall.com/wp-content/uploads/image-5942.png" alt="" class="wp-image-18606" style="width:763px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5942.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5942-300x175.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5942-768x449.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tại <strong>Tab Agent:</strong></p>



<p class="wp-block-paragraph">Các bạn làm các bước như trong ảnh</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="579" src="https://thegioifirewall.com/wp-content/uploads/image-5943.png" alt="" class="wp-image-18607" style="width:793px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5943.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5943-300x178.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5943-768x456.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Tab con External </strong></p>



<p class="wp-block-paragraph">Nhấn <strong>Add</strong></p>



<p class="wp-block-paragraph"><strong>Name</strong>: tùy chọn<br><strong>Address:</strong> tùy chọn IP hoặc FQDN<br><strong>IPv4</strong>: IP WAN<br><strong>Source Region &gt; Add </strong>và điền thông tin như ảnh<br>Nhấn <strong>OK</strong> để lưu</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="720" src="https://thegioifirewall.com/wp-content/uploads/image-5944.png" alt="" class="wp-image-18608" style="width:727px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5944.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5944-300x222.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5944-768x567.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="713" src="https://thegioifirewall.com/wp-content/uploads/image-5945.png" alt="" class="wp-image-18610" style="width:723px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5945.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5945-300x219.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5945-768x562.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tiếp theo tại <strong>Trusted Root CA > Add</strong> CA_Global và đánh dấu tích vào mục kế bên</p>



<p class="wp-block-paragraph">Nhấn <strong>OK</strong> để hoàn tất</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="975" height="587" src="https://thegioifirewall.com/wp-content/uploads/image-5946.png" alt="" class="wp-image-18611" style="width:724px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5946.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5946-300x181.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5946-768x462.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>B6. Tạo tunnel</strong></p>



<p class="wp-block-paragraph">Các bạn vào <strong>Network > Interfaces > Tunnel ></strong> nhấn <strong>Add</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="401" src="https://thegioifirewall.com/wp-content/uploads/image-5956.png" alt="" class="wp-image-18621" srcset="https://thegioifirewall.com/wp-content/uploads/image-5956.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5956-300x123.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5956-768x316.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph"><strong>B7. Tạo GlobalProtect Gateway</strong></p>



<p class="wp-block-paragraph">Theo đường dẫn sau <strong>Network > GlobalProtect > Gateways ></strong> nhấn <strong>Add</strong></p>



<p class="wp-block-paragraph">Tại Tab <strong>General:</strong></p>



<p class="wp-block-paragraph"><strong>Name:</strong> GW_GlobalProtect<br><strong>Interface:</strong> cổng WAN<br><strong>IP Address Type:</strong> IPv4 Only<br><strong>IPv4 Address:</strong> None</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="975" height="426" src="https://thegioifirewall.com/wp-content/uploads/image-5947.png" alt="" class="wp-image-18612" srcset="https://thegioifirewall.com/wp-content/uploads/image-5947.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5947-300x131.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5947-768x336.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tab<strong> Authentication</strong></p>



<p class="wp-block-paragraph"><strong>SSL/TLS Service Profile</strong> : chọn SSL/TLS mà ta đã tạo ở bước trên</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5949.png" alt="" class="wp-image-18614" style="width:817px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5949.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5949-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5949-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Nhấn <strong>Add </strong></p>



<p class="wp-block-paragraph">Điền thông tin sau</p>



<p class="wp-block-paragraph"><strong>Name:</strong> điền tên bất kỳ<br><strong>OS:</strong> Any<br><strong>Authentication Profile:</strong> chọn Local_User đã tạo<br>Nhấn <strong>OK</strong> để lưu</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="597" src="https://thegioifirewall.com/wp-content/uploads/image-5948.png" alt="" class="wp-image-18613" style="width:790px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5948.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5948-300x184.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5948-768x470.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5950.png" alt="" class="wp-image-18615" style="width:786px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5950.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5950-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5950-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tại <strong>Tab Agent</strong></p>



<p class="wp-block-paragraph">Tab con<strong> Tunnel Settings</strong></p>



<p class="wp-block-paragraph">Đánh dấu tích vào <strong>Tunnel Mode</strong></p>



<p class="wp-block-paragraph"><strong>Tunnel Interface :</strong> chọn tunnel đã tạo</p>



<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="436" src="https://thegioifirewall.com/wp-content/uploads/image-5951.png" alt="" class="wp-image-18616" style="width:827px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5951.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5951-300x134.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5951-768x343.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Trong tab con <strong>Client Settings ></strong> nhấn <strong>Add</strong></p>



<p class="wp-block-paragraph"><strong>Name :</strong> điền tên bất kỳ</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="826" src="https://thegioifirewall.com/wp-content/uploads/image-5952.png" alt="" class="wp-image-18617" style="width:672px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5952.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5952-300x254.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5952-768x651.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tab con <strong>IP Pools</strong></p>



<p class="wp-block-paragraph">Nhập dãy <strong>IP </strong>mà bạn muốn cấp cho người dùng khi VPN</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="537" src="https://thegioifirewall.com/wp-content/uploads/image-5953.png" alt="" class="wp-image-18618" style="width:790px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5953.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5953-300x165.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5953-768x423.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>INCLUDE :</strong> Nhập nhóm IP mà bạn muốn connect tới khi VPN</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="549" src="https://thegioifirewall.com/wp-content/uploads/image-5954.png" alt="" class="wp-image-18619" style="width:785px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5954.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5954-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5954-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Nhấn <strong>OK</strong> để tạo ra bảng tổng</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="499" src="https://thegioifirewall.com/wp-content/uploads/image-5955.png" alt="" class="wp-image-18620" style="width:813px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5955.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5955-300x154.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5955-768x393.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>B8. Tiến hành đăng nhập GlobalProtect Portal</strong></p>



<p class="wp-block-paragraph">Nhập <strong>IP WAN</strong> để vào giao diện</p>



<p class="wp-block-paragraph">Tiến hành nhập tài khoản user đã tạo</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="491" src="https://thegioifirewall.com/wp-content/uploads/image-5957.png" alt="" class="wp-image-18622" style="width:808px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5957.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5957-300x151.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5957-768x387.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Chọn tải phiên bản thích hợp với máy tính của bạn</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="550" src="https://thegioifirewall.com/wp-content/uploads/image-5958.png" alt="" class="wp-image-18623" style="width:727px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5958.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5958-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5958-768x433.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tiến hành cài phần mềm mới <strong>download</strong> về</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="796" src="https://thegioifirewall.com/wp-content/uploads/image-5959.png" alt="" class="wp-image-18624" style="width:612px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5959.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5959-300x245.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5959-768x627.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="789" src="https://thegioifirewall.com/wp-content/uploads/image-5961.png" alt="" class="wp-image-18626" style="width:636px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5961.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5961-300x243.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5961-768x621.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="969" height="806" src="https://thegioifirewall.com/wp-content/uploads/image-5960.png" alt="" class="wp-image-18625" style="width:762px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5960.png 969w, https://thegioifirewall.com/wp-content/uploads/image-5960-300x250.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5960-768x639.png 768w" sizes="auto, (max-width: 969px) 100vw, 969px" /></figure>
</div>


<p class="wp-block-paragraph">Sau khi cài hoàn tất &gt; sẽ xuất hiện giao diện bên dưới góc phải</p>



<p class="wp-block-paragraph">Các bạn tiến hành nhập <strong>IP WAN vào > nhấn Connect</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5962.png" alt="" class="wp-image-18627" style="width:674px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5962.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5962-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5962-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Nhấn<strong> Show Certificate</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5963.png" alt="" class="wp-image-18628" style="width:729px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5963.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5963-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5963-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Tiến hành <strong>Install </strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5964.png" alt="" class="wp-image-18629" style="width:776px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5964.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5964-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5964-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="946" src="https://thegioifirewall.com/wp-content/uploads/image-5965.png" alt="" class="wp-image-18630" style="width:767px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5965.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5965-300x291.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5965-768x745.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="788" height="1008" src="https://thegioifirewall.com/wp-content/uploads/image-5966.png" alt="" class="wp-image-18631" style="width:607px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5966.png 788w, https://thegioifirewall.com/wp-content/uploads/image-5966-235x300.png 235w, https://thegioifirewall.com/wp-content/uploads/image-5966-768x982.png 768w" sizes="auto, (max-width: 788px) 100vw, 788px" /></figure>
</div>


<p class="wp-block-paragraph">Sau khi cài thành công Certificate</p>



<p class="wp-block-paragraph">Các bạn tiến hành nhập tài khoảng users vào</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5968.png" alt="" class="wp-image-18633" style="width:690px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5968.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5968-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5968-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph">Đã kết nối thành công</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="548" src="https://thegioifirewall.com/wp-content/uploads/image-5969.png" alt="" class="wp-image-18634" style="width:674px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5969.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5969-300x169.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5969-768x432.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>B9. Kiểm tra kết quả</strong></p>



<p class="wp-block-paragraph">Ping IP server đã được cấu hình cho phép kết nối thành công</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="975" height="567" src="https://thegioifirewall.com/wp-content/uploads/image-5970.png" alt="" class="wp-image-18635" style="width:772px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5970.png 975w, https://thegioifirewall.com/wp-content/uploads/image-5970-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5970-768x447.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/palo-alto-firmware-10-2-cach-cau-hinh-client-to-site-cho-nhan-vien-o-ben-ngoai-van-truy-cap-duoc-mang-noi-bo/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CÁCH THÊM FIREWALL PALO ALTO NETWORKS VÀO PANORAMA</title>
		<link>https://thegioifirewall.com/cach-them-firewall-cua-palo-alto-networks-vao-panorama/</link>
					<comments>https://thegioifirewall.com/cach-them-firewall-cua-palo-alto-networks-vao-panorama/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Fri, 24 Nov 2023 03:16:39 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<category><![CDATA[Panorama]]></category>
		<guid isPermaLink="false">https://thegioifirewall.com/?p=18316</guid>

					<description><![CDATA[Tổng quan : Trong nội dung này, chúng ta sẽ khám phá cách thêm Firewall của Palo Alto Networks vào Panorama. Panorama của Palo Alto Networks mang lại khả năng quản lý tập trung cho các sản phẩm như Firewall, Prisma, và nhiều hơn nữa. Điều này đồng nghĩa rằng, ngay cả khi các firewall [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Tổng quan :</strong></p>



<p class="wp-block-paragraph">Trong nội dung này, chúng ta sẽ khám phá cách thêm Firewall của Palo Alto Networks vào Panorama. Panorama của Palo Alto Networks mang lại khả năng quản lý tập trung cho các sản phẩm như Firewall, Prisma, và nhiều hơn nữa. Điều này đồng nghĩa rằng, ngay cả khi các firewall của bạn được cấu hình ở các vị trí địa lý khác nhau, bạn vẫn có thể tích hợp chúng với Panorama để quản lý chúng một cách hiệu quả. Palo Alto Networks khuyến nghị sử dụng cùng phiên bản PAN-OS trên cả Panorama và firewall. Tuy nhiên, nếu phiên bản PAN-OS trên Panorama cao hơn so với firewall, điều này cũng được chấp nhận. Bây giờ, hãy bắt đầu quá trình tích hợp firewall với Panorama.</p>



<p class="wp-block-paragraph"><strong>Mục lục :</strong></p>



<p class="wp-block-paragraph"><strong>I.</strong> <strong>Cách Add Firewall của Palo Alto Networks vào Panorama</strong></p>



<p class="wp-block-paragraph"><strong>1. Add firewall Palo Alto Networks vào Panorama</strong></p>



<p class="wp-block-paragraph"><strong>2. Thêm thông tin Panorama vào Palo Alto Networks </strong></p>



<p class="wp-block-paragraph"><strong>3.  Kiểm tra kết nối Firewall Palo Alto và Panorama</strong></p>



<p class="wp-block-paragraph"><strong>4. Import thiết bị vào Panorama</strong></p>



<p class="wp-block-paragraph"><strong>5. &nbsp;Export cấu hình Palo ALto trong Panorama vào lại Firewall</strong></p>



<p class="wp-block-paragraph"><strong>Nội dung bài lab :</strong></p>



<p class="wp-block-paragraph"><strong>I.</strong> <strong>Cách thêm Firewall của Palo Alto Networks vào Panorama</strong></p>



<p class="wp-block-paragraph">Mặc dù có kết nối hai chiều thông qua TCP/3389 giữa Palo Alto Networks Panorama và Firewalls, ở đây tôi có cả Firewall và Panorama đều nằm trong cùng một subnet.</p>



<p class="wp-block-paragraph">Nếu bạn đang sử dụng firewall VM Series của Palo Alto Networks, hãy đảm bảo rằng bạn có số sê-ri hợp lệ trên Firewall để bắt đầu quá trình tích hợp.</p>



<p class="wp-block-paragraph">Trong trường hợp của tôi, tôi đang sử dụng PA-VM với địa chỉ IP quản lý là 192.168.31.205 và Panorama với địa chỉ IP quản lý là 192.168.31.250.</p>



<p class="wp-block-paragraph"><strong>1. Add firewall Palo Alto Networks vào Panorama</strong></p>



<p class="wp-block-paragraph">Đầu tiên các bạn cần vào giao diện Palo Alto lấy số S/N</p>



<p class="wp-block-paragraph">Tại giao diện Panorama &gt;<strong>&nbsp;Panorama &gt; Managed Devices &gt; Summary &gt; click vào Add.</strong></p>



<p class="wp-block-paragraph">Nhập số <strong>S/N</strong> của firewall vào</p>



<p class="wp-block-paragraph">Click vào <strong>Generate Auth Key</strong> để tạo key &gt; nhấn vào <strong>Copy Auth Key</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="600" height="612" src="https://thegioifirewall.com/wp-content/uploads/image-5733.png" alt="" class="wp-image-18317" style="aspect-ratio:0.9803921568627451;width:520px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5733.png 600w, https://thegioifirewall.com/wp-content/uploads/image-5733-294x300.png 294w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>2. Thêm thông tin Panorama vào Palo Alto Networks </strong></p>



<p class="wp-block-paragraph">Đăng nhập vào Palo Alto Networks Firewall</p>



<p class="wp-block-paragraph">Ta vào <strong>Device &gt; Setup &gt; Management &gt; Panorama Settings</strong></p>



<p class="wp-block-paragraph">Tiến hành điền thông tin<strong> IP</strong> của Panorama và <strong>key</strong> ở bước trên</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="766" height="563" src="https://thegioifirewall.com/wp-content/uploads/image-5734.png" alt="" class="wp-image-18318" style="aspect-ratio:1.3605683836589697;width:678px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5734.png 766w, https://thegioifirewall.com/wp-content/uploads/image-5734-300x220.png 300w" sizes="auto, (max-width: 766px) 100vw, 766px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>3.  Kiểm tra kết nối Firewall Palo Alto và Panorama</strong></p>



<p class="wp-block-paragraph">Login vào Panorama </p>



<p class="wp-block-paragraph">Chúng ta vào <strong>Panorama &gt; Managed Devices &gt; Summary </strong></p>



<p class="wp-block-paragraph">Kiểm tra trạng thái kết nối.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1003" height="174" src="https://thegioifirewall.com/wp-content/uploads/image-5735.png" alt="" class="wp-image-18319" srcset="https://thegioifirewall.com/wp-content/uploads/image-5735.png 1003w, https://thegioifirewall.com/wp-content/uploads/image-5735-300x52.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5735-768x133.png 768w" sizes="auto, (max-width: 1003px) 100vw, 1003px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>4. Import thiết bị vào Panorama</strong></p>



<p class="wp-block-paragraph">Truy cập giao diện Panarama</p>



<p class="wp-block-paragraph"><strong>Panorama &gt; Setup &gt; Operations</strong> và click vào <strong>Import device configuration</strong> trong phần <strong>configuration management.</strong></p>



<p class="wp-block-paragraph"><strong>Device </strong>: chọn thiết bị Firewall Palo Alto mà bạn cần thiết lập</p>



<p class="wp-block-paragraph"><strong>Templade Name</strong> :  tên</p>



<p class="wp-block-paragraph"><strong>Device Group Name</strong> : tên Group</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="927" height="398" src="https://thegioifirewall.com/wp-content/uploads/image-5736.png" alt="" class="wp-image-18323" srcset="https://thegioifirewall.com/wp-content/uploads/image-5736.png 927w, https://thegioifirewall.com/wp-content/uploads/image-5736-300x129.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5736-768x330.png 768w" sizes="auto, (max-width: 927px) 100vw, 927px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>5. &nbsp;Export cấu hình Palo ALto trong Panorama vào lại Firewall</strong></p>



<p class="wp-block-paragraph">Tại giao diện Panarama</p>



<p class="wp-block-paragraph">Các bạn vào <strong>Panorama &gt; Setup &gt; Operations</strong> và click vào <strong>Export or push device config bundle</strong></p>



<p class="wp-block-paragraph">Chọn thiết bị và xác minh số sê-ri của thiết bị</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="495" height="293" src="https://thegioifirewall.com/wp-content/uploads/image-5737.png" alt="" class="wp-image-18324" style="aspect-ratio:1.689419795221843;width:507px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5737.png 495w, https://thegioifirewall.com/wp-content/uploads/image-5737-300x178.png 300w" sizes="auto, (max-width: 495px) 100vw, 495px" /></figure>
</div>


<p class="wp-block-paragraph">Tiếp theo<span style="color: rgb(65, 65, 65); font-family: &quot;Open Sans&quot;, &quot;Helvetica Neue&quot;, Helvetica, Arial, sans-serif; font-size: 17px; white-space-collapse: collapse;">&nbsp;chọn <strong>Push &amp; Commit under Export</strong> hoặc <strong>Push Config Bundle</strong></span>&nbsp;</p>



<p class="wp-block-paragraph">Lúc này cấu hình sẽ được đẩy xuống Palo Alto</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="747" height="620" src="https://thegioifirewall.com/wp-content/uploads/image-5738.png" alt="" class="wp-image-18325" style="aspect-ratio:1.2048387096774194;width:529px;height:auto" srcset="https://thegioifirewall.com/wp-content/uploads/image-5738.png 747w, https://thegioifirewall.com/wp-content/uploads/image-5738-300x249.png 300w" sizes="auto, (max-width: 747px) 100vw, 747px" /></figure>
</div>


<p class="wp-block-paragraph">Các bạn có thể vào giao diện Palo Alto để xem</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="959" height="147" src="https://thegioifirewall.com/wp-content/uploads/image-5739.png" alt="" class="wp-image-18326" srcset="https://thegioifirewall.com/wp-content/uploads/image-5739.png 959w, https://thegioifirewall.com/wp-content/uploads/image-5739-300x46.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5739-768x118.png 768w" sizes="auto, (max-width: 959px) 100vw, 959px" /></figure>



<p class="wp-block-paragraph">Màu hiển thị</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="960" height="235" src="https://thegioifirewall.com/wp-content/uploads/image-5740.png" alt="" class="wp-image-18329" srcset="https://thegioifirewall.com/wp-content/uploads/image-5740.png 960w, https://thegioifirewall.com/wp-content/uploads/image-5740-300x73.png 300w, https://thegioifirewall.com/wp-content/uploads/image-5740-768x188.png 768w" sizes="auto, (max-width: 960px) 100vw, 960px" /></figure>



<p class="wp-block-paragraph">Cuối cùng cần vào giao diện Panorama</p>



<p class="wp-block-paragraph">click vào<strong> commit</strong> và chọn <strong>Push to devices</strong></p>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/cach-them-firewall-cua-palo-alto-networks-vao-panorama/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng dẫn cấu hình IPSec VPN giữa Sophos và Palo Alto khi thiết bị Sophos nằm phía sau một thiết bị Sophos khác</title>
		<link>https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/</link>
					<comments>https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Mon, 06 Sep 2021 03:44:00 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Hướng dẫn cấu hình Firewall Sophos XG]]></category>
		<category><![CDATA[Hướng dẫn cấu hình IPSec VPN giữa Sophos và Palo Alto khi thiết bị Sophos nằm phía sau một thiết bị Sophos khác]]></category>
		<category><![CDATA[IPSec VPN]]></category>
		<category><![CDATA[Palo Alto]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=11852</guid>

					<description><![CDATA[1.Mục đích bài viết Trong bài viết này thegioifirewall sẽ hướng dẫn các bạn cách cấu hình IPSec VPN Site to site giữa thiết bị Sophos Firewall và Palo Alto với thiết bị Sophos nằm phía sau một thiết bị Sophos Firewall khác. 2.Sơ đồ mạng Chi tiết sơ đồ mạng: Head Office: Tại head [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>1.Mục đích bài viết</strong></h2>



<p class="wp-block-paragraph">Trong bài viết này thegioifirewall sẽ hướng dẫn các bạn cách cấu hình IPSec VPN Site to site giữa thiết bị Sophos Firewall và Palo Alto với thiết bị Sophos nằm phía sau một thiết bị Sophos Firewall khác.</p>



<h2 class="wp-block-heading"><strong>2.Sơ đồ mạng</strong></h2>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="582" src="https://thegioifirewall.com/wp-content/uploads/Drawing1-8-1024x582.png" alt="" class="wp-image-11853" srcset="https://thegioifirewall.com/wp-content/uploads/Drawing1-8-1024x582.png 1024w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8-300x170.png 300w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8-768x436.png 768w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8-1536x873.png 1536w, https://thegioifirewall.com/wp-content/uploads/Drawing1-8.png 1772w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Chi tiết sơ đồ mạng:</strong></p>



<p class="wp-block-paragraph"><strong>Head Office:</strong></p>



<ul class="wp-block-list"><li>Tại head office site chúng ta sẽ có mô hình external và internal firewall với 2 thiết bị Sophos Firewal 1 là external firewall và Sophos Firewall 2 là internal firewall.</li><li>Đường truyền internet được kết nối tại Port 2 của thiết bị Sophos Firewall 1 với IP 192.168.2.111.</li><li>Mạng LAN của thiết bị Sophos Firewall 1 được cấu hình tại Port 1 với IP 10.145.41.1/24 và đã cấu hình DHCP để cấp phát cho các thiết bị kết nối tới nó.</li><li>Tại Sophos Firewall 2 cổng WAN sẽ là Port 2 và nó sẽ được kết nối đến Port 1 của Sophos Firewall 1, Port 2 trên Sophos Firewall 2 được đặt IP tĩnh là 10.145.41.50/24.</li><li>Mạng LAN của Sophos Firewall 2 được cấu hình tại Port 1 với IP 10.146.41.1/24 và đã được cấu hình DHCP.</li></ul>



<p class="wp-block-paragraph"><strong>Branch office:</strong></p>



<ul class="wp-block-list"><li>Đường truyền internet được kết nối tại port ethernet1/1 của thiết bị Palo Alto firewall với IP 192.168.2.115.</li><li>Mạng LAN được cấu hình tại port ethernet1/2 với IP 172.16.16.16/24 và đã cấu hình DHCP để cấp phát IP cho các thiết bị kết nối vào.</li></ul>



<h2 class="wp-block-heading"><strong>3.Tình huống cấu hình</strong></h2>



<p class="wp-block-paragraph">Dựa theo sơ đồ trên chúng ta sẽ cấu hình IPSec VPN Site to site giữa thiết bị Sophos Firewall 2 tại Head Office site và thiết bị Palo Alto Firewall 3 tại Branch Office site để cả 2 mạng LAN của 2 site có thể giao tiếp với nhau.</p>



<h2 class="wp-block-heading"><strong>4.Các bước cấu hình</strong></h2>



<p class="wp-block-paragraph"><strong>Sophos Firewall 1:</strong></p>



<ul class="wp-block-list"><li>Tạo profile cho IPSec service.</li><li>Tạo Profile cho IP WAN của Sophos Firewall 2.</li><li>Thực hiện NAT IP WAN của Sophos Firewall 2 với IPSec service ra internet.</li></ul>



<p class="wp-block-paragraph"><strong>Sophos Firewall 2:</strong></p>



<ul class="wp-block-list"><li>Tạo profile cho Local và Remote subnet.</li><li>Tạo IPSec policy.</li><li>Tạo kết nối IPSec connection.</li><li>Tạo policy cho phép traffic giữa 2 zone LAN và VPN.</li><li>Bật dịch vụ PING và HTTPS trên VPN zone.</li></ul>



<p class="wp-block-paragraph"><strong>Palo Alto Firewall:</strong></p>



<ul class="wp-block-list"><li>Tạo VPN zone.</li><li>Tạo Address Object.</li><li>Tạo tunnel interface.</li><li>Tạo Virtual Routers.</li><li>Tạo IKE Crypto.</li><li>Tạo IPSec Crypto.</li><li>Tạo IKE Gateways.</li><li>Tạo IPSec Tunnels.</li><li>Tạo policy.</li></ul>



<p class="wp-block-paragraph"><strong>Kiểm tra kết quả.</strong></p>



<h2 class="wp-block-heading"><strong>5.Hướng dẫn cấu hình.</strong></h2>



<h3 class="wp-block-heading"><strong>5.1.Sophos Firewall 1.</strong></h3>



<h4 class="wp-block-heading"><strong>5.1.1.Tạo profile cho IPSec service</strong></h4>



<p class="wp-block-paragraph">Kết nối IPSec VPN Site to site sẽ sử dụng các port là UDP 500 và UDP 4500.</p>



<p class="wp-block-paragraph">Chúng ta cần tạo profile cho 2 service này.</p>



<p class="wp-block-paragraph">Để tạo vào SYSTEM &gt; Hosts and services &gt; Services &gt; nhấn Add.</p>



<p class="wp-block-paragraph">Tạo với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: IPSec S2S VPN</li><li>Type*: chọn TCP/UDP.</li><li>Protocol: chọn UDP.</li><li>Source port: 1:65535.</li><li>Destination port: 500</li><li>Nhấn biểu tượng dấu + để thêm 1 hàng.</li><li>Protocol: chọn UDP.</li><li>Source port: 1:65535.</li><li>Destination port: 4500.</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="211" src="https://thegioifirewall.com/wp-content/uploads/1-40-1024x211.png" alt="" class="wp-image-11854" srcset="https://thegioifirewall.com/wp-content/uploads/1-40-1024x211.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-40-300x62.png 300w, https://thegioifirewall.com/wp-content/uploads/1-40-768x158.png 768w, https://thegioifirewall.com/wp-content/uploads/1-40-1536x316.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-40-2048x422.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.2.Tạo profile cho IP WAN của Sophos Firewall 2.</strong></h4>



<p class="wp-block-paragraph">Để tạo vào SYSTEM &gt; Hosts and services &gt; IP Host &gt; Nhấn Add.</p>



<p class="wp-block-paragraph">Tạo với các thông tin sau:</p>



<ul class="wp-block-list"><li>Name*: Sophos Firewall 2.</li><li>IP version*: chọn IPv4.</li><li>Type*: chọn IP.</li><li>IP address*: nhập IP WAN của Sophos Firewall 2 là 10.145.41.50.</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/2-35-1024x272.png" alt="" class="wp-image-11855" srcset="https://thegioifirewall.com/wp-content/uploads/2-35-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-35-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/2-35-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/2-35-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-35-2048x543.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.3.Thực hiện NAT IP WAN của Sophos Firewall 2 với IPSec service ra ngoài internet.</strong></h4>



<p class="wp-block-paragraph">Để NAT chúng ta vào PROTECT &gt; Rules and policies &gt; Add firewall rule &gt; Server access assistant [DNAT].</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="451" src="https://thegioifirewall.com/wp-content/uploads/3-40-1024x451.png" alt="" class="wp-image-11856" srcset="https://thegioifirewall.com/wp-content/uploads/3-40-1024x451.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-40-300x132.png 300w, https://thegioifirewall.com/wp-content/uploads/3-40-768x338.png 768w, https://thegioifirewall.com/wp-content/uploads/3-40-1536x677.png 1536w, https://thegioifirewall.com/wp-content/uploads/3-40-2048x902.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Sau khi nhấn vào Server access assistant [DNAT] một bảng cấu hình hiện lên.</p>



<p class="wp-block-paragraph">Ở Internal server IP address chúng ta tích chọn Select IP host và chọn Sophos Firewall 2 – 10.145.41.50 từ danh sách thả xuống.</p>



<p class="wp-block-paragraph">Nhấn Next để tiếp tục.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="274" src="https://thegioifirewall.com/wp-content/uploads/4-40-1024x274.png" alt="" class="wp-image-11857" srcset="https://thegioifirewall.com/wp-content/uploads/4-40-1024x274.png 1024w, https://thegioifirewall.com/wp-content/uploads/4-40-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/4-40-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/4-40-1536x410.png 1536w, https://thegioifirewall.com/wp-content/uploads/4-40-2048x547.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Public IP address tích chọn Select public ip address or WAN interface và chọn #Port 2 – 192.168.2.111 từ danh sách thả xuống.</p>



<p class="wp-block-paragraph">Nhấn Next để tiếp tục.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="273" src="https://thegioifirewall.com/wp-content/uploads/5-37-1024x273.png" alt="" class="wp-image-11858" srcset="https://thegioifirewall.com/wp-content/uploads/5-37-1024x273.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-37-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/5-37-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/5-37-1536x410.png 1536w, https://thegioifirewall.com/wp-content/uploads/5-37-2048x547.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Service nhấn Add new item và chọn profile IPSec S2S VPN.</p>



<p class="wp-block-paragraph">Nhấn Next để tiếp tục.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="284" src="https://thegioifirewall.com/wp-content/uploads/6-38-1024x284.png" alt="" class="wp-image-11859" srcset="https://thegioifirewall.com/wp-content/uploads/6-38-1024x284.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-38-300x83.png 300w, https://thegioifirewall.com/wp-content/uploads/6-38-768x213.png 768w, https://thegioifirewall.com/wp-content/uploads/6-38-1536x426.png 1536w, https://thegioifirewall.com/wp-content/uploads/6-38-2048x568.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở External source networks or devices giữ nguyên lựa chọn Any và nhấn Next.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="282" src="https://thegioifirewall.com/wp-content/uploads/7-32-1024x282.png" alt="" class="wp-image-11860" srcset="https://thegioifirewall.com/wp-content/uploads/7-32-1024x282.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-32-300x83.png 300w, https://thegioifirewall.com/wp-content/uploads/7-32-768x211.png 768w, https://thegioifirewall.com/wp-content/uploads/7-32-1536x423.png 1536w, https://thegioifirewall.com/wp-content/uploads/7-32-2048x564.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cuối cùng là bước review các lựa chọn đã chọn trước đó, nếu đã chọn đúng nhấn Save and finish để hoàn thành.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="787" src="https://thegioifirewall.com/wp-content/uploads/8-31-1024x787.png" alt="" class="wp-image-11861" srcset="https://thegioifirewall.com/wp-content/uploads/8-31-1024x787.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-31-300x231.png 300w, https://thegioifirewall.com/wp-content/uploads/8-31-768x591.png 768w, https://thegioifirewall.com/wp-content/uploads/8-31-1536x1181.png 1536w, https://thegioifirewall.com/wp-content/uploads/8-31.png 1883w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.2.Sophos Firewall 2</strong></h3>



<h4 class="wp-block-heading"><strong>5.2.1.Tạo profile cho Local và Remote subnet</strong></h4>



<p class="wp-block-paragraph">Chúng ta sẽ thực hiện tạo profile cho Local và Remote subnet.</p>



<p class="wp-block-paragraph">Để tạo vào SYSTEM &gt; Hosts and Services &gt; IP Host &gt; nhấn Add.</p>



<p class="wp-block-paragraph">Tạo profile cho Local subnet với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: SF2_LAN.</li><li>IP version*: IPv4.</li><li>Type*: Network.</li><li>IP address*: 10.146.41.0 Subnet /24[255.255.255.0]</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="262" src="https://thegioifirewall.com/wp-content/uploads/9-33-1024x262.png" alt="" class="wp-image-11862" srcset="https://thegioifirewall.com/wp-content/uploads/9-33-1024x262.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-33-300x77.png 300w, https://thegioifirewall.com/wp-content/uploads/9-33-768x197.png 768w, https://thegioifirewall.com/wp-content/uploads/9-33-1536x393.png 1536w, https://thegioifirewall.com/wp-content/uploads/9-33-2048x524.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tương tự các bước trên chúng ta sẽ tạo profile cho Remote subnet theo các thông số sau:</p>



<p class="wp-block-paragraph">Name*: PA_LAN.</p>



<p class="wp-block-paragraph">IP version*: IPv4.</p>



<p class="wp-block-paragraph">Type*: Network.</p>



<p class="wp-block-paragraph">IP address*: 172.16.16.0 Subnet /24[255.255.255.0]</p>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="261" src="https://thegioifirewall.com/wp-content/uploads/10-28-1024x261.png" alt="" class="wp-image-11863" srcset="https://thegioifirewall.com/wp-content/uploads/10-28-1024x261.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-28-300x76.png 300w, https://thegioifirewall.com/wp-content/uploads/10-28-768x196.png 768w, https://thegioifirewall.com/wp-content/uploads/10-28-1536x392.png 1536w, https://thegioifirewall.com/wp-content/uploads/10-28-2048x522.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.2.Tạo IPSec policy</strong></h4>



<p class="wp-block-paragraph">Do đây là kết nối IPSec VPN giữa 2 thiết bị khác hãng nên chúng ta cần tạo IPSec policy chung cho cả 2 thiết bị.</p>



<p class="wp-block-paragraph">Để tạo IPSec policy vào CONFIGURE &gt; VPN &gt; IPSec policies &gt; Nhấn Add.</p>



<p class="wp-block-paragraph">Tạo IPSec policy với các thông số sau.</p>



<p class="wp-block-paragraph">General settings:</p>



<ul class="wp-block-list"><li>Name: VPN_S2S_PaloAlto.</li><li>Key exchange: IKEv2.</li><li>Authentication mode: Main mode</li><li>Tích chọn Re-key connection.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="322" src="https://thegioifirewall.com/wp-content/uploads/19-17-1024x322.png" alt="" class="wp-image-11864" srcset="https://thegioifirewall.com/wp-content/uploads/19-17-1024x322.png 1024w, https://thegioifirewall.com/wp-content/uploads/19-17-300x94.png 300w, https://thegioifirewall.com/wp-content/uploads/19-17-768x241.png 768w, https://thegioifirewall.com/wp-content/uploads/19-17-1536x482.png 1536w, https://thegioifirewall.com/wp-content/uploads/19-17-2048x643.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Phrase 1:</p>



<ul class="wp-block-list"><li>Key life: 5400.</li><li>Re-key margin: 360.</li><li>Randomize re-keying margin by: 50.</li><li>DH group (key group): 2 (DH1024).</li><li>Encryption: AES256.</li><li>Authentication: SHA2 256.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="325" src="https://thegioifirewall.com/wp-content/uploads/20-14-1024x325.png" alt="" class="wp-image-11865" srcset="https://thegioifirewall.com/wp-content/uploads/20-14-1024x325.png 1024w, https://thegioifirewall.com/wp-content/uploads/20-14-300x95.png 300w, https://thegioifirewall.com/wp-content/uploads/20-14-768x244.png 768w, https://thegioifirewall.com/wp-content/uploads/20-14-1536x487.png 1536w, https://thegioifirewall.com/wp-content/uploads/20-14-2048x650.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Phrase 2:</p>



<ul class="wp-block-list"><li>PFS group (DH group): None.</li><li>Key life: 3600.</li><li>Encryption: AES128.</li><li>Authentication: SHA2 256.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="264" src="https://thegioifirewall.com/wp-content/uploads/21-13-1024x264.png" alt="" class="wp-image-11866" srcset="https://thegioifirewall.com/wp-content/uploads/21-13-1024x264.png 1024w, https://thegioifirewall.com/wp-content/uploads/21-13-300x77.png 300w, https://thegioifirewall.com/wp-content/uploads/21-13-768x198.png 768w, https://thegioifirewall.com/wp-content/uploads/21-13-1536x395.png 1536w, https://thegioifirewall.com/wp-content/uploads/21-13-2048x527.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Dead Peer Detection:</p>



<ul class="wp-block-list"><li>Dead Peer Detection: tích chọn.</li><li>Check peer after every: 30.</li><li>Wait for response up to: 120.</li><li>When peer unreachable: Re-initiate.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="187" src="https://thegioifirewall.com/wp-content/uploads/22-9-1024x187.png" alt="" class="wp-image-11867" srcset="https://thegioifirewall.com/wp-content/uploads/22-9-1024x187.png 1024w, https://thegioifirewall.com/wp-content/uploads/22-9-300x55.png 300w, https://thegioifirewall.com/wp-content/uploads/22-9-768x140.png 768w, https://thegioifirewall.com/wp-content/uploads/22-9-1536x280.png 1536w, https://thegioifirewall.com/wp-content/uploads/22-9-2048x373.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<h4 class="wp-block-heading"><strong>5.2.3.Tạo kết nối IPSec connection</strong></h4>



<p class="wp-block-paragraph">Để tạo chúng ta vào CONFIGURE &gt; VPN &gt; IPSec connections &gt; nhấn Add.</p>



<p class="wp-block-paragraph">Ở General chúng ta cấu hình với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: VPN_SOPHOS_TO_PA.</li><li>IP version: IPv4.</li><li>Connection type: Site-to-site.</li><li>Gateway type: Respond only.</li><li>Active on save: bỏ chọn.</li><li>Create firewall rule: bỏ chọn.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="274" src="https://thegioifirewall.com/wp-content/uploads/11-29-1024x274.png" alt="" class="wp-image-11868" srcset="https://thegioifirewall.com/wp-content/uploads/11-29-1024x274.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-29-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/11-29-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/11-29-1536x411.png 1536w, https://thegioifirewall.com/wp-content/uploads/11-29-2048x548.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Encryption chúng ta cấu hình với các thông số sau:</p>



<ul class="wp-block-list"><li>Policy: chọn VPN_S2S_PaloAlto.</li><li>Authentication type: chọn Preshared key.</li><li>Preshared key: nhập mật khẩu kết nối.</li><li>Repeat preshared key: nhập lại mật khẩu kết nối.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="281" src="https://thegioifirewall.com/wp-content/uploads/12-27-1024x281.png" alt="" class="wp-image-11869" srcset="https://thegioifirewall.com/wp-content/uploads/12-27-1024x281.png 1024w, https://thegioifirewall.com/wp-content/uploads/12-27-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/12-27-768x211.png 768w, https://thegioifirewall.com/wp-content/uploads/12-27-1536x422.png 1536w, https://thegioifirewall.com/wp-content/uploads/12-27-2048x563.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Ở Gateway settings chúng ta cấu hình theo các thông số sau:</p>



<p class="wp-block-paragraph"><strong>Local Gateway:</strong></p>



<ul class="wp-block-list"><li>Listening interface: chọn Port2 – 10.145.41.50.</li><li>Local ID type: chọn IP address.</li><li>Local ID: nhập 10.145.41.50.</li><li>Local subnet: chọn profile SF2_LAN.</li></ul>



<p class="wp-block-paragraph"><strong>Remote Gateway:</strong></p>



<ul class="wp-block-list"><li>Gateway address: nhập IP WAN của Palo Alto firewall là 192.168.2.115.</li><li>Remote ID type: chọn IP address.</li><li>Remote ID: nhập 192.168.2.115.</li><li>Remote subnet: chọn profile PA_LAN.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="480" src="https://thegioifirewall.com/wp-content/uploads/13-23-1024x480.png" alt="" class="wp-image-11870" srcset="https://thegioifirewall.com/wp-content/uploads/13-23-1024x480.png 1024w, https://thegioifirewall.com/wp-content/uploads/13-23-300x141.png 300w, https://thegioifirewall.com/wp-content/uploads/13-23-768x360.png 768w, https://thegioifirewall.com/wp-content/uploads/13-23-1536x719.png 1536w, https://thegioifirewall.com/wp-content/uploads/13-23-2048x959.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<p class="wp-block-paragraph">Sau khi nhấn Save kết nối IPSec sẽ được tạo như hình dưới đây.</p>



<p class="wp-block-paragraph">Tuy nhiên kết nối này vẫn chưa được bật, để bật nhấn vào biểu tượng hình tròn tại cột Active và nhấn OK.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="238" src="https://thegioifirewall.com/wp-content/uploads/14-22-1024x238.png" alt="" class="wp-image-11871" srcset="https://thegioifirewall.com/wp-content/uploads/14-22-1024x238.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-22-300x70.png 300w, https://thegioifirewall.com/wp-content/uploads/14-22-768x178.png 768w, https://thegioifirewall.com/wp-content/uploads/14-22-1536x357.png 1536w, https://thegioifirewall.com/wp-content/uploads/14-22-2048x476.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Lúc này biểu tượng hình tròn tại cột Active chuyển sang màu xanh lá tức là đã bật kết nối thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="232" src="https://thegioifirewall.com/wp-content/uploads/15-21-1024x232.png" alt="" class="wp-image-11872" srcset="https://thegioifirewall.com/wp-content/uploads/15-21-1024x232.png 1024w, https://thegioifirewall.com/wp-content/uploads/15-21-300x68.png 300w, https://thegioifirewall.com/wp-content/uploads/15-21-768x174.png 768w, https://thegioifirewall.com/wp-content/uploads/15-21-1536x348.png 1536w, https://thegioifirewall.com/wp-content/uploads/15-21-2048x464.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.4.Tạo policy cho phép traffic giữa 2 zone LAN và VPN.</strong></h4>



<p class="wp-block-paragraph">Mặc định tường lửa sẽ khóa hết các traffic qua lại giữa các zone.</p>



<p class="wp-block-paragraph">Vì vậy chúng ta cần tạo policy để cho phép các traffic qua lại giữa 2 zone LAN và VPN.</p>



<p class="wp-block-paragraph">Để tạo vào PROTECT &gt; Rules and policies &gt; Add firewall rule và tạo policy theo như hình sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="726" src="https://thegioifirewall.com/wp-content/uploads/16-21-1024x726.png" alt="" class="wp-image-11873" srcset="https://thegioifirewall.com/wp-content/uploads/16-21-1024x726.png 1024w, https://thegioifirewall.com/wp-content/uploads/16-21-300x213.png 300w, https://thegioifirewall.com/wp-content/uploads/16-21-768x545.png 768w, https://thegioifirewall.com/wp-content/uploads/16-21-1536x1089.png 1536w, https://thegioifirewall.com/wp-content/uploads/16-21.png 1582w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="746" src="https://thegioifirewall.com/wp-content/uploads/17-19-1024x746.png" alt="" class="wp-image-11874" srcset="https://thegioifirewall.com/wp-content/uploads/17-19-1024x746.png 1024w, https://thegioifirewall.com/wp-content/uploads/17-19-300x218.png 300w, https://thegioifirewall.com/wp-content/uploads/17-19-768x559.png 768w, https://thegioifirewall.com/wp-content/uploads/17-19-1536x1118.png 1536w, https://thegioifirewall.com/wp-content/uploads/17-19.png 1585w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Save để lưu.</p>



<h4 class="wp-block-heading"><strong>5.2.5.Bật dịch vụ PING và HTTPS trên VPN zone.</strong></h4>



<p class="wp-block-paragraph">Mặc định trên VPN zone sẽ tắt hết các dịch vụ.</p>



<p class="wp-block-paragraph">Để bật vào SYSTEM &gt; Administration &gt; Device Access.</p>



<p class="wp-block-paragraph">Tích chọn 2 dịch vụ HTTPS và Ping/Ping6 tại hàng VPN zone và nhấn Apply để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="415" src="https://thegioifirewall.com/wp-content/uploads/18-18-1024x415.png" alt="" class="wp-image-11875" srcset="https://thegioifirewall.com/wp-content/uploads/18-18-1024x415.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-18-300x122.png 300w, https://thegioifirewall.com/wp-content/uploads/18-18-768x311.png 768w, https://thegioifirewall.com/wp-content/uploads/18-18-1536x622.png 1536w, https://thegioifirewall.com/wp-content/uploads/18-18-2048x830.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.3.Palo Alto Firewall</strong></h3>



<h4 class="wp-block-heading"><strong>5.3.1.Tạo Zone</strong></h4>



<p class="wp-block-paragraph">Chúng ta cần tạo zone cho các kết nối VPN.</p>



<p class="wp-block-paragraph">Để tạo vào Network &gt; Zones.</p>



<p class="wp-block-paragraph">Nhấn Add và tạo theo các thông tin sau:</p>



<ul class="wp-block-list"><li>Name: VPN</li><li>Type: Layer3</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="761" src="https://thegioifirewall.com/wp-content/uploads/23-9-1024x761.png" alt="" class="wp-image-11876" srcset="https://thegioifirewall.com/wp-content/uploads/23-9-1024x761.png 1024w, https://thegioifirewall.com/wp-content/uploads/23-9-300x223.png 300w, https://thegioifirewall.com/wp-content/uploads/23-9-768x571.png 768w, https://thegioifirewall.com/wp-content/uploads/23-9-1536x1141.png 1536w, https://thegioifirewall.com/wp-content/uploads/23-9.png 1750w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.2.Tạo Address Object</strong></h4>



<p class="wp-block-paragraph">Chúng ta sẽ tạo Address Object cho 2 lớp mạng LAN của thiết bị Palo Alto và Sophos.</p>



<p class="wp-block-paragraph">Để tạo vào Object &gt; Addresses.</p>



<p class="wp-block-paragraph">Nhấn Add và tạo theo các thông số như sau.</p>



<p class="wp-block-paragraph">Palo Alto LAN:</p>



<ul class="wp-block-list"><li>Name: PA_LAN</li><li>Type: IP Netmask – 172.16.16.0/24</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="306" src="https://thegioifirewall.com/wp-content/uploads/24-12-1024x306.png" alt="" class="wp-image-11877" srcset="https://thegioifirewall.com/wp-content/uploads/24-12-1024x306.png 1024w, https://thegioifirewall.com/wp-content/uploads/24-12-300x90.png 300w, https://thegioifirewall.com/wp-content/uploads/24-12-768x229.png 768w, https://thegioifirewall.com/wp-content/uploads/24-12-1536x459.png 1536w, https://thegioifirewall.com/wp-content/uploads/24-12.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Sophos Firewall 2 LAN:</p>



<ul class="wp-block-list"><li>Name: SF2_LAN</li><li>Type: IP Netmask – 10.146.41.0/24</li><li>Nhấn OK để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="306" src="https://thegioifirewall.com/wp-content/uploads/25-11-1024x306.png" alt="" class="wp-image-11878" srcset="https://thegioifirewall.com/wp-content/uploads/25-11-1024x306.png 1024w, https://thegioifirewall.com/wp-content/uploads/25-11-300x90.png 300w, https://thegioifirewall.com/wp-content/uploads/25-11-768x230.png 768w, https://thegioifirewall.com/wp-content/uploads/25-11-1536x460.png 1536w, https://thegioifirewall.com/wp-content/uploads/25-11.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.3.Tạo Interface Tunnel</strong></h4>



<p class="wp-block-paragraph">Để tạo vào Network &gt; Interface &gt; Tunnel.</p>



<p class="wp-block-paragraph">Nhấn Add và tạo theo các thông tin như sau:</p>



<ul class="wp-block-list"><li>Interface Name: tunnel – 2</li><li>Virtual Router: None</li><li>Security Zone: VPN</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="438" src="https://thegioifirewall.com/wp-content/uploads/26-10-1024x438.png" alt="" class="wp-image-11879" srcset="https://thegioifirewall.com/wp-content/uploads/26-10-1024x438.png 1024w, https://thegioifirewall.com/wp-content/uploads/26-10-300x128.png 300w, https://thegioifirewall.com/wp-content/uploads/26-10-768x329.png 768w, https://thegioifirewall.com/wp-content/uploads/26-10-1536x657.png 1536w, https://thegioifirewall.com/wp-content/uploads/26-10.png 1748w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.3.4.Tạo Virtual Routers</strong></h4>



<p class="wp-block-paragraph">Để tạo Virtual Routers vào Network &gt; Virtual Routers &gt; nhấn Add và cấu hình theo các thông tin sau.</p>



<p class="wp-block-paragraph">Tab Router Settings:</p>



<ul class="wp-block-list"><li>Name: VR1</li><li>Tab General: nhấn Add và chọn các cổng ethernet1/2 (cổng LAN), ethernet1/1(cổng internet) và tunnel.2(là tunnel dùng để kết nối VPN).</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="640" src="https://thegioifirewall.com/wp-content/uploads/27-10-1024x640.png" alt="" class="wp-image-11880" srcset="https://thegioifirewall.com/wp-content/uploads/27-10-1024x640.png 1024w, https://thegioifirewall.com/wp-content/uploads/27-10-300x188.png 300w, https://thegioifirewall.com/wp-content/uploads/27-10-768x480.png 768w, https://thegioifirewall.com/wp-content/uploads/27-10-1536x960.png 1536w, https://thegioifirewall.com/wp-content/uploads/27-10.png 2000w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Static Routes &gt; IPv4:</p>



<p class="wp-block-paragraph">Nhấn Add để thêm static routes và điền vào các thông tin sau:</p>



<ul class="wp-block-list"><li>Name: Route-1</li><li>Destination: SF2_LAN</li><li>Interface: tunnel.2</li><li>Nhấn OK 2 lần để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="862" src="https://thegioifirewall.com/wp-content/uploads/28-11-1024x862.png" alt="" class="wp-image-11881" srcset="https://thegioifirewall.com/wp-content/uploads/28-11-1024x862.png 1024w, https://thegioifirewall.com/wp-content/uploads/28-11-300x253.png 300w, https://thegioifirewall.com/wp-content/uploads/28-11-768x646.png 768w, https://thegioifirewall.com/wp-content/uploads/28-11.png 1498w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.5.Tạo IKE Crypto</strong></h4>



<p class="wp-block-paragraph">Chúng ta sẽ tạo IKE Crypto tức Phrase 1 cho kết nối VPN.</p>



<p class="wp-block-paragraph">Để tạo vào Network &gt; IKE Crypto nhấn Add và tạo theo các thông tin sau:</p>



<ul class="wp-block-list"><li>Name: IKE_Crypto_Phrase1</li><li>DH Group: group2</li><li>Encryption: aes-256-cbc</li><li>Authentication: sha256</li><li>Key Lifetime: Seconds – 5400</li><li>Nhấn OK Để lưu</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="508" src="https://thegioifirewall.com/wp-content/uploads/29-8-1024x508.png" alt="" class="wp-image-11882" srcset="https://thegioifirewall.com/wp-content/uploads/29-8-1024x508.png 1024w, https://thegioifirewall.com/wp-content/uploads/29-8-300x149.png 300w, https://thegioifirewall.com/wp-content/uploads/29-8-768x381.png 768w, https://thegioifirewall.com/wp-content/uploads/29-8-1536x763.png 1536w, https://thegioifirewall.com/wp-content/uploads/29-8.png 1998w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.6.Tạo IPSec Crypto</strong></h4>



<p class="wp-block-paragraph">Để tạo IPSec Crypto vào Network &gt; IPSec Crypto và nhấn Add.</p>



<p class="wp-block-paragraph">Cấu hình theo các thông số sau:</p>



<ul class="wp-block-list"><li>Name: IPSec_Crypto_Phrase2</li><li>IPSec Protocol: ESP</li><li>Encryption: aes-128-cbc</li><li>Authentication: sha256</li><li>DH Group: no-pfs</li><li>Lifetime: Seconds – 3600</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="545" src="https://thegioifirewall.com/wp-content/uploads/30-8-1024x545.png" alt="" class="wp-image-11883" srcset="https://thegioifirewall.com/wp-content/uploads/30-8-1024x545.png 1024w, https://thegioifirewall.com/wp-content/uploads/30-8-300x160.png 300w, https://thegioifirewall.com/wp-content/uploads/30-8-768x408.png 768w, https://thegioifirewall.com/wp-content/uploads/30-8-1536x817.png 1536w, https://thegioifirewall.com/wp-content/uploads/30-8.png 1999w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.7.Tạo IKE Gateways</strong></h4>



<p class="wp-block-paragraph">Để tao vào Network &gt; IKE Gateways và nhấn Add.</p>



<p class="wp-block-paragraph">Cấu hình theo các thông số sau</p>



<p class="wp-block-paragraph">Bảng General:</p>



<ul class="wp-block-list"><li>Name: IKE_Gateway</li><li>Version: IKEv2 only mode</li><li>Address Type: IPv4</li><li>Interface: ethernet1/1 (cổng WAN của Palo Alto)</li><li>Local IP Address: None</li><li>Peer Address: Nhập IP WAN của Sophos Firewall 1 là 192.168.2.111</li><li>Authentication: Pre-shared Key</li><li>Pre-shared key: nhập mật khẩu kết nối (mật khẩu này phải giống với mật khẩu đã đặt trên Sophos)</li><li>Confirm Pre-shared key: nhập lại mật khẩu kết nối.</li><li>Local Identification: chọn IP address – nhập 192.168.2.115.</li><li>Peer Identification: chọn IP address – nhập IP WAN của Sophos Firewall 2 là 10.145.41.50</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="788" src="https://thegioifirewall.com/wp-content/uploads/31-9-1024x788.png" alt="" class="wp-image-11884" srcset="https://thegioifirewall.com/wp-content/uploads/31-9-1024x788.png 1024w, https://thegioifirewall.com/wp-content/uploads/31-9-300x231.png 300w, https://thegioifirewall.com/wp-content/uploads/31-9-768x591.png 768w, https://thegioifirewall.com/wp-content/uploads/31-9.png 1490w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Bảng Advanced Options:</p>



<ul class="wp-block-list"><li>IKE Crypto Profile: chọn IKE_Crypto_Phrase1</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="635" src="https://thegioifirewall.com/wp-content/uploads/32-5-1024x635.png" alt="" class="wp-image-11885" srcset="https://thegioifirewall.com/wp-content/uploads/32-5-1024x635.png 1024w, https://thegioifirewall.com/wp-content/uploads/32-5-300x186.png 300w, https://thegioifirewall.com/wp-content/uploads/32-5-768x476.png 768w, https://thegioifirewall.com/wp-content/uploads/32-5.png 1497w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.8.Tạo IPSec Tunnels</strong></h4>



<p class="wp-block-paragraph">Giờ chúng ta sẽ bắt đầu tạo kết nối VPN với thiết bị Sophos Firewall.</p>



<p class="wp-block-paragraph">Để tạo vào Network &gt; IPSec Tunnels và nhấn Add.</p>



<p class="wp-block-paragraph">Tạo với các thông tin như sau.</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: VPN_PA_TO_SOPHOS</li><li>Tunnel Interface: tunnel.2</li><li>Type: Auto Key</li><li>Address Type: IPv4</li><li>IKE Gateways: IKE_Gateway</li><li>IPSec Crypto Profile: IPSec_Crypto_Phrase2</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="410" src="https://thegioifirewall.com/wp-content/uploads/33-5-1024x410.png" alt="" class="wp-image-11886" srcset="https://thegioifirewall.com/wp-content/uploads/33-5-1024x410.png 1024w, https://thegioifirewall.com/wp-content/uploads/33-5-300x120.png 300w, https://thegioifirewall.com/wp-content/uploads/33-5-768x308.png 768w, https://thegioifirewall.com/wp-content/uploads/33-5-1536x615.png 1536w, https://thegioifirewall.com/wp-content/uploads/33-5.png 1993w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Proxy IDs:</p>



<p class="wp-block-paragraph">Nhấn Add và cấu hình các thông tin sau:</p>



<ul class="wp-block-list"><li>Proxy ID: Peer-1</li><li>Local: 172.16.16.0/24</li><li>Remote: 10.146.41.0/24</li><li>Protocol: Any</li><li>Nhấn OK 2 lần để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="453" src="https://thegioifirewall.com/wp-content/uploads/34-3-1024x453.png" alt="" class="wp-image-11887" srcset="https://thegioifirewall.com/wp-content/uploads/34-3-1024x453.png 1024w, https://thegioifirewall.com/wp-content/uploads/34-3-300x133.png 300w, https://thegioifirewall.com/wp-content/uploads/34-3-768x340.png 768w, https://thegioifirewall.com/wp-content/uploads/34-3.png 1201w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="592" src="https://thegioifirewall.com/wp-content/uploads/35-3-1024x592.png" alt="" class="wp-image-11888" srcset="https://thegioifirewall.com/wp-content/uploads/35-3-1024x592.png 1024w, https://thegioifirewall.com/wp-content/uploads/35-3-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/35-3-768x444.png 768w, https://thegioifirewall.com/wp-content/uploads/35-3-1536x889.png 1536w, https://thegioifirewall.com/wp-content/uploads/35-3.png 2000w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn Commit và OK để lưu các thay đổi cấu hình.</p>



<h4 class="wp-block-heading"><strong>5.3.9.Tạo Policy</strong></h4>



<p class="wp-block-paragraph">Chúng ta cần tạo policy cho phép các traffic từ lớp mạng LAN của Palo Alto đi qua lớp mạng LAN của Sophos Firewall và ngược lại.</p>



<p class="wp-block-paragraph">Để tạo policy vào Policies &gt; Security và nhấn Add.</p>



<p class="wp-block-paragraph">Tạo policy cho phép traffic từ lớp mạng LAN của Palo Alto đi qua lớp mạng LAN của Sophos Firewall với các thông tin như sau:</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: LAN_TO_VPN</li><li>Rule Type: universal (default)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="565" src="https://thegioifirewall.com/wp-content/uploads/36-2-1024x565.png" alt="" class="wp-image-11889" srcset="https://thegioifirewall.com/wp-content/uploads/36-2-1024x565.png 1024w, https://thegioifirewall.com/wp-content/uploads/36-2-300x166.png 300w, https://thegioifirewall.com/wp-content/uploads/36-2-768x424.png 768w, https://thegioifirewall.com/wp-content/uploads/36-2-1536x848.png 1536w, https://thegioifirewall.com/wp-content/uploads/36-2.png 1743w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Source:</p>



<ul class="wp-block-list"><li>Source Zone: nhấn Add và chọn Trust-Layer3 (Đây là zone của lớp LAN)</li><li>Source Address: nhấn Add và chọn PA_LAN (PA_LAN là Address Object mà chúng ta đã tạo trước đó)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://thegioifirewall.com/wp-content/uploads/37-2-1024x600.png" alt="" class="wp-image-11890" srcset="https://thegioifirewall.com/wp-content/uploads/37-2-1024x600.png 1024w, https://thegioifirewall.com/wp-content/uploads/37-2-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/37-2-768x450.png 768w, https://thegioifirewall.com/wp-content/uploads/37-2-1536x900.png 1536w, https://thegioifirewall.com/wp-content/uploads/37-2.png 1749w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Destination:</p>



<ul class="wp-block-list"><li>Destination Zone: VPN</li><li>Destination Address: SF2-LAN (đây là Address Object đã tạo lúc đầu)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="595" src="https://thegioifirewall.com/wp-content/uploads/38-2-1024x595.png" alt="" class="wp-image-11891" srcset="https://thegioifirewall.com/wp-content/uploads/38-2-1024x595.png 1024w, https://thegioifirewall.com/wp-content/uploads/38-2-300x174.png 300w, https://thegioifirewall.com/wp-content/uploads/38-2-768x446.png 768w, https://thegioifirewall.com/wp-content/uploads/38-2-1536x892.png 1536w, https://thegioifirewall.com/wp-content/uploads/38-2.png 1740w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Action:</p>



<ul class="wp-block-list"><li>Action: chọn Allow để cho phép.</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="521" src="https://thegioifirewall.com/wp-content/uploads/39-2-1024x521.png" alt="" class="wp-image-11892" srcset="https://thegioifirewall.com/wp-content/uploads/39-2-1024x521.png 1024w, https://thegioifirewall.com/wp-content/uploads/39-2-300x153.png 300w, https://thegioifirewall.com/wp-content/uploads/39-2-768x390.png 768w, https://thegioifirewall.com/wp-content/uploads/39-2-1536x781.png 1536w, https://thegioifirewall.com/wp-content/uploads/39-2.png 1735w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tiếp theo chúng ta sẽ nhấn Add và tạo policy cho phép các traffic đi từ lớp mạng LAN của Sophos Firewall sang lớp mạng LAN của Palo Alto với các thông tin sau:</p>



<p class="wp-block-paragraph">Tab General:</p>



<ul class="wp-block-list"><li>Name: VPN_TO_LAN</li><li>Rule Type: universal (default)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="564" src="https://thegioifirewall.com/wp-content/uploads/40-3-1024x564.png" alt="" class="wp-image-11893" srcset="https://thegioifirewall.com/wp-content/uploads/40-3-1024x564.png 1024w, https://thegioifirewall.com/wp-content/uploads/40-3-300x165.png 300w, https://thegioifirewall.com/wp-content/uploads/40-3-768x423.png 768w, https://thegioifirewall.com/wp-content/uploads/40-3-1536x846.png 1536w, https://thegioifirewall.com/wp-content/uploads/40-3.png 1743w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Source:</p>



<ul class="wp-block-list"><li>Source Zone: nhấn Add và chọn VPN</li><li>Source Address: nhấn Add và chọn SF2_LAN (SF2_LAN là Address Object mà chúng ta đã tạo trước đó)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="601" src="https://thegioifirewall.com/wp-content/uploads/41-3-1024x601.png" alt="" class="wp-image-11894" srcset="https://thegioifirewall.com/wp-content/uploads/41-3-1024x601.png 1024w, https://thegioifirewall.com/wp-content/uploads/41-3-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/41-3-768x451.png 768w, https://thegioifirewall.com/wp-content/uploads/41-3-1536x902.png 1536w, https://thegioifirewall.com/wp-content/uploads/41-3.png 1747w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Destination:</p>



<ul class="wp-block-list"><li>Destination Zone: Trust-Layer3 (Zone của lớp mạng LAN)</li><li>Destination Address: PA-LAN (đây là Address Object đã tạo lúc đầu)</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="600" src="https://thegioifirewall.com/wp-content/uploads/42-2-1024x600.png" alt="" class="wp-image-11895" srcset="https://thegioifirewall.com/wp-content/uploads/42-2-1024x600.png 1024w, https://thegioifirewall.com/wp-content/uploads/42-2-300x176.png 300w, https://thegioifirewall.com/wp-content/uploads/42-2-768x450.png 768w, https://thegioifirewall.com/wp-content/uploads/42-2-1536x899.png 1536w, https://thegioifirewall.com/wp-content/uploads/42-2.png 1747w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Tab Action:</p>



<ul class="wp-block-list"><li>Action: chọn Allow để cho phép.</li><li>Nhấn OK để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="526" src="https://thegioifirewall.com/wp-content/uploads/43-2-1024x526.png" alt="" class="wp-image-11896" srcset="https://thegioifirewall.com/wp-content/uploads/43-2-1024x526.png 1024w, https://thegioifirewall.com/wp-content/uploads/43-2-300x154.png 300w, https://thegioifirewall.com/wp-content/uploads/43-2-768x395.png 768w, https://thegioifirewall.com/wp-content/uploads/43-2-1536x789.png 1536w, https://thegioifirewall.com/wp-content/uploads/43-2.png 1734w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.4.Kiểm tra kết quả.</strong></h3>



<p class="wp-block-paragraph">Trên thiết bị Palo Alto sau khi tạo kết nối IPSec tunnels thì kết nối sẽ được liệt kê ra như hình dưới.</p>



<p class="wp-block-paragraph">Chúng ta chú ý đến cột Status chúng ta thấy rằng biểu tượng port mạng đang là màu xanh tức kết nối IPSec này đã được Enable.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="173" src="https://thegioifirewall.com/wp-content/uploads/44-2-1024x173.png" alt="" class="wp-image-11897" srcset="https://thegioifirewall.com/wp-content/uploads/44-2-1024x173.png 1024w, https://thegioifirewall.com/wp-content/uploads/44-2-300x51.png 300w, https://thegioifirewall.com/wp-content/uploads/44-2-768x130.png 768w, https://thegioifirewall.com/wp-content/uploads/44-2-1536x260.png 1536w, https://thegioifirewall.com/wp-content/uploads/44-2-2048x346.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để kích hoạt kết nối IPSec giữa 2 thiết bị chúng ta vào thiết bị Sophos Firewall &gt; CONFIGURE &gt; VPN &gt; IPSec connections.</p>



<p class="wp-block-paragraph">Chúng ta chú ý đến biểu tượng hình tròn tại cột Connection của kết nối IPSec VPN mà chúng ta đã tạo trước đó đang là màu đỏ tức kết nối chưa được kích hoạt đến thiết bị Palo Alto firewall.</p>



<p class="wp-block-paragraph">Để kích hoạt nhấn chuột trái vào biểu tượng hình tròn tại cột Connection và nhấn Yes.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="239" src="https://thegioifirewall.com/wp-content/uploads/45-2-1024x239.png" alt="" class="wp-image-11898" srcset="https://thegioifirewall.com/wp-content/uploads/45-2-1024x239.png 1024w, https://thegioifirewall.com/wp-content/uploads/45-2-300x70.png 300w, https://thegioifirewall.com/wp-content/uploads/45-2-768x179.png 768w, https://thegioifirewall.com/wp-content/uploads/45-2-1536x358.png 1536w, https://thegioifirewall.com/wp-content/uploads/45-2-2048x478.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Biểu tượng hình tròn này sẽ chuyển sang màu xanh lá tức là chúng ta đã kích hoạt thành công kết nối IPSec VPN giữa 2 thiết bị.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="237" src="https://thegioifirewall.com/wp-content/uploads/46-1-1024x237.png" alt="" class="wp-image-11899" srcset="https://thegioifirewall.com/wp-content/uploads/46-1-1024x237.png 1024w, https://thegioifirewall.com/wp-content/uploads/46-1-300x69.png 300w, https://thegioifirewall.com/wp-content/uploads/46-1-768x177.png 768w, https://thegioifirewall.com/wp-content/uploads/46-1-1536x355.png 1536w, https://thegioifirewall.com/wp-content/uploads/46-1-2048x473.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Trên thiết bị Palo Alto firewall chúng ta cũng sẽ thây được 2 biểu tượng hình tròn tại 2 cột Status đều chuyển sang màu xanh lá.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="187" src="https://thegioifirewall.com/wp-content/uploads/47-1024x187.png" alt="" class="wp-image-11900" srcset="https://thegioifirewall.com/wp-content/uploads/47-1024x187.png 1024w, https://thegioifirewall.com/wp-content/uploads/47-300x55.png 300w, https://thegioifirewall.com/wp-content/uploads/47-768x140.png 768w, https://thegioifirewall.com/wp-content/uploads/47-1536x281.png 1536w, https://thegioifirewall.com/wp-content/uploads/47-2048x374.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Để kiểm tra sự giao tiếp giữa 2 lớp mạng LAN của mỗi site với nhau, thegioifirewall sẽ dùng 1 máy tính tại mỗi site để ping lẫn nhau kiểm tra kết quả.</p>



<p class="wp-block-paragraph">Ở site Head Office thegioifirewall đã chuẩn bị sẵn máy chủ có IP 10.146.41.10/24 và ở site Branch Office đã chuẩn bị máy Windows 10 có IP 172.16.16.50/24.</p>



<p class="wp-block-paragraph">Kết quả ping từ máy chủ IP 10.146.41.10/24 đến máy Windows 10.</p>



<p class="wp-block-paragraph">Kết quả ping thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="561" src="https://thegioifirewall.com/wp-content/uploads/48-1-1024x561.png" alt="" class="wp-image-11901" srcset="https://thegioifirewall.com/wp-content/uploads/48-1-1024x561.png 1024w, https://thegioifirewall.com/wp-content/uploads/48-1-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/48-1-768x421.png 768w, https://thegioifirewall.com/wp-content/uploads/48-1-1536x841.png 1536w, https://thegioifirewall.com/wp-content/uploads/48-1-2048x1121.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Kết quả ping từ máy Windows 10 IP 172.16.16.50 đến máy chủ.</p>



<p class="wp-block-paragraph">Kết quả ping thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="559" src="https://thegioifirewall.com/wp-content/uploads/49-1-1024x559.png" alt="" class="wp-image-11902" srcset="https://thegioifirewall.com/wp-content/uploads/49-1-1024x559.png 1024w, https://thegioifirewall.com/wp-content/uploads/49-1-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/49-1-768x419.png 768w, https://thegioifirewall.com/wp-content/uploads/49-1-1536x838.png 1536w, https://thegioifirewall.com/wp-content/uploads/49-1-2048x1118.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-giua-sophos-va-palo-alto-khi-thiet-bi-sophos-nam-phia-sau-mot-thiet-bi-sophos-khac/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
