<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Remote Access SSL VPN &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/remote-access-ssl-vpn/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Tue, 31 Aug 2021 06:37:05 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Remote Access SSL VPN &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Sophos XG Firewall: Hướng dẫn cấu hình Remote Access SSL VPN với Sophos Connect Client.</title>
		<link>https://thegioifirewall.com/sophos-xg-firewall-huong-dan-cau-hinh-remote-access-ssl-vpn-voi-sophos-connect-client/</link>
					<comments>https://thegioifirewall.com/sophos-xg-firewall-huong-dan-cau-hinh-remote-access-ssl-vpn-voi-sophos-connect-client/#respond</comments>
		
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Tue, 29 Jun 2021 04:28:58 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Sophos XG]]></category>
		<category><![CDATA[Remote Access SSL VPN]]></category>
		<category><![CDATA[Remote Access SSL VPN với Sophos Connect Client]]></category>
		<category><![CDATA[Sophos Connect Client]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=10598</guid>

					<description><![CDATA[Overview. Sophos Connect Client cho phép bạn thực thi các cài đặt bảo mật nâng cao và linh hoạt, chẳng hạn như kết nối đường hầm tự động. Bạn cũng có thể cấu hình và thiết lập kết nối SSL VPN truy cập từ xa bằng Sophos Connect Client bạn chỉ cần thực hiện các [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Overview.</strong></p>



<p class="wp-block-paragraph">Sophos Connect Client cho phép bạn thực thi các cài đặt bảo mật nâng cao và linh hoạt, chẳng hạn như kết nối đường hầm tự động. Bạn cũng có thể cấu hình và thiết lập kết nối SSL VPN truy cập từ xa bằng Sophos Connect Client bạn chỉ cần thực hiện các bước sau:</p>



<p class="wp-block-paragraph">+ Cấu hình cài đặt SSL VPN (Remote Access).</p>



<p class="wp-block-paragraph">+ Gửi tệp cấu hình cho người dùng.</p>



<p class="wp-block-paragraph">+ Cấu hình Firewall Rule.</p>



<p class="wp-block-paragraph">+ Gửi ứng dụng Sophos Connect Client cho người dùng. Ngoài ra, người dùng có thể tải xuống từ User Portal.</p>



<p class="wp-block-paragraph">Hiện tại, Sophos Connect Client không hỗ trợ macOS cho SSL VPN. Nó cũng không hỗ trợ các nền tảng di động cho IPsec và SSL VPN. Đối với macOS và các nền tảng di động, bạn nên sử dụng ứng dụng OpenVPN Connect Client.</p>



<p class="wp-block-paragraph">Bài viết sẽ hướng dẫn các bạn cấu hình SSL VPN (Remote Access) với Sophos Connect Client.</p>



<p class="wp-block-paragraph"><strong>Sơ đồ mạng</strong></p>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" src="https://i1.wp.com/static.techbast.com/2021/07/image-3.png?resize=868%2C192&amp;ssl=1" alt=""/></figure></div>



<p class="wp-block-paragraph"><strong>Hướng dẫn</strong></p>



<p class="wp-block-paragraph"><strong>Bước 1: Tạo User và Group remote access</strong></p>



<p class="wp-block-paragraph">Để tạo <strong>Group</strong>: Bạn đi đến phần <strong>Configure &gt; Authentication &gt; Group &gt; Add</strong>.</p>



<p class="wp-block-paragraph"><strong>Group Name: </strong>Điền tên group bạn muốn.</p>



<p class="wp-block-paragraph"><strong>Surting quota: </strong>Chọn <strong>Unlimited internet Access</strong></p>



<p class="wp-block-paragraph"><strong>Access time:</strong> Allowed all the time</p>



<p class="wp-block-paragraph">Click<strong> Save.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img fetchpriority="high" decoding="async" width="624" height="454" src="https://thegioifirewall.com/wp-content/uploads/image-2281.png" alt="" class="wp-image-10599" srcset="https://thegioifirewall.com/wp-content/uploads/image-2281.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2281-300x218.png 300w" sizes="(max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Bạn chuyển qua tab <strong>User.</strong></p>



<p class="wp-block-paragraph"><strong>User name:</strong> Điền tên user (Đây là tên dùng để xác thực user)</p>



<p class="wp-block-paragraph"><strong>Name: </strong>Tên người dùng.</p>



<p class="wp-block-paragraph"><strong>Password:</strong> Điền password cho user</p>



<p class="wp-block-paragraph"><strong>Email:</strong> Điền email của user</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="516" height="461" src="https://thegioifirewall.com/wp-content/uploads/image-2282.png" alt="" class="wp-image-10600" srcset="https://thegioifirewall.com/wp-content/uploads/image-2282.png 516w, https://thegioifirewall.com/wp-content/uploads/image-2282-300x268.png 300w" sizes="(max-width: 516px) 100vw, 516px" /></figure></div>



<p class="wp-block-paragraph">Kéo xuống phần <strong>Policies</strong>.</p>



<p class="wp-block-paragraph">Chọn<strong> Group</strong> là tên Group đã tạo ở bước trên. Click <strong>Save.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" width="624" height="365" src="https://thegioifirewall.com/wp-content/uploads/image-2283.png" alt="" class="wp-image-10601" srcset="https://thegioifirewall.com/wp-content/uploads/image-2283.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2283-300x175.png 300w" sizes="(max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 2: Tạo Local Subnet và remote SSL VPN range</strong>.</p>



<p class="wp-block-paragraph">Tạo <strong>Local Subnet</strong>:</p>



<p class="wp-block-paragraph">Đi đến <strong>Hosts and Services &gt; IP Host &gt; Add.</strong></p>



<p class="wp-block-paragraph"><strong>Name:</strong> Điền tên Local Subnet bạn muốn</p>



<p class="wp-block-paragraph"><strong>Type: </strong>chọn <strong>Network</strong></p>



<p class="wp-block-paragraph"><strong>Ip address:<em> Điền ip subnet local của bạn.</em></strong></p>



<p class="wp-block-paragraph">Click <strong>Save.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="280" src="https://thegioifirewall.com/wp-content/uploads/image-2284.png" alt="" class="wp-image-10602" srcset="https://thegioifirewall.com/wp-content/uploads/image-2284.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2284-300x135.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Tạo <strong>Remote SSL Range.</strong></p>



<p class="wp-block-paragraph">Bạn check trong <strong>VPN &gt; Show VPN setting.</strong></p>



<p class="wp-block-paragraph"><strong>Ipv4 lease range: </strong>Đây là SSL VPN range mặc định của Sophos. Bạn cũng có thể chỉnh tạo range mới.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="679" height="267" src="https://thegioifirewall.com/wp-content/uploads/image-2285.png" alt="" class="wp-image-10603" srcset="https://thegioifirewall.com/wp-content/uploads/image-2285.png 679w, https://thegioifirewall.com/wp-content/uploads/image-2285-300x118.png 300w" sizes="auto, (max-width: 679px) 100vw, 679px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>Ip host &gt; Add.</strong></p>



<p class="wp-block-paragraph"><strong>Name:</strong> Điền tên ban muốn</p>



<p class="wp-block-paragraph"><strong>Type:</strong> chọn <strong>IP range.</strong></p>



<p class="wp-block-paragraph"><strong>Ip address:</strong> Điền ip range như đã check ở bước trên.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="257" src="https://thegioifirewall.com/wp-content/uploads/image-2286.png" alt="" class="wp-image-10604" srcset="https://thegioifirewall.com/wp-content/uploads/image-2286.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2286-300x124.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 3: Cấu hình SSL VPN (Remote Access)</strong></p>



<p class="wp-block-paragraph">Đi đến <strong>Configure &gt; VPN &gt; SSL VPN (Remote Access) &gt; Add</strong></p>



<p class="wp-block-paragraph"><strong>General Settings:</strong></p>



<p class="wp-block-paragraph"><strong>Name:</strong> Điền tên bạn muốn</p>



<p class="wp-block-paragraph"><strong>Policy Member:</strong> Chọn group đã tạo ở bước 1.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="458" src="https://thegioifirewall.com/wp-content/uploads/image-2287.png" alt="" class="wp-image-10605" srcset="https://thegioifirewall.com/wp-content/uploads/image-2287.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2287-300x220.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Permitted network resource (Ipv4):</strong> Chọn local subnet tạo ở bước 2 và các subnet khác trong LAN bạn muốn sử dụng để SSL VPN. Click <strong>Apply</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="592" src="https://thegioifirewall.com/wp-content/uploads/image-2288.png" alt="" class="wp-image-10606" srcset="https://thegioifirewall.com/wp-content/uploads/image-2288.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2288-300x285.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 4: Check Authentication Service</strong></p>



<p class="wp-block-paragraph">Đi đến&nbsp;<strong>Authentication</strong><strong>&nbsp;&gt;&nbsp;</strong><strong>Services</strong>.&nbsp; Check <strong>Firewall authentication methods</strong>.</p>



<p class="wp-block-paragraph">Check <strong>Selected authentication server</strong> là <strong>Local</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="480" height="442" src="https://thegioifirewall.com/wp-content/uploads/image-2289.png" alt="" class="wp-image-10607" srcset="https://thegioifirewall.com/wp-content/uploads/image-2289.png 480w, https://thegioifirewall.com/wp-content/uploads/image-2289-300x276.png 300w" sizes="auto, (max-width: 480px) 100vw, 480px" /></figure></div>



<p class="wp-block-paragraph">Kéo xuống và check <strong>SSL VPN authentication methods</strong> là <strong>Local</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="589" height="605" src="https://thegioifirewall.com/wp-content/uploads/image-2290.png" alt="" class="wp-image-10608" srcset="https://thegioifirewall.com/wp-content/uploads/image-2290.png 589w, https://thegioifirewall.com/wp-content/uploads/image-2290-292x300.png 292w" sizes="auto, (max-width: 589px) 100vw, 589px" /></figure></div>



<p class="wp-block-paragraph">Check <strong>Device Access Setting</strong></p>



<p class="wp-block-paragraph">Đi điến <strong>Administration&nbsp;&gt;&nbsp;Device access</strong>. Check <strong>SSL VPN</strong> và <strong>User Portal</strong> được tích chọn trong LAN và WAN.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="249" src="https://thegioifirewall.com/wp-content/uploads/image-2291.png" alt="" class="wp-image-10609" srcset="https://thegioifirewall.com/wp-content/uploads/image-2291.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2291-300x120.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 5: Tạo Firewall rule cho SSL VPN remote access.</strong></p>



<p class="wp-block-paragraph">Bạn tạo rule như hình dưới.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="376" src="https://thegioifirewall.com/wp-content/uploads/image-2292.png" alt="" class="wp-image-10610" srcset="https://thegioifirewall.com/wp-content/uploads/image-2292.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2292-300x181.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="178" src="https://thegioifirewall.com/wp-content/uploads/image-2293.png" alt="" class="wp-image-10611" srcset="https://thegioifirewall.com/wp-content/uploads/image-2293.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2293-300x86.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 6: Download Sophos Connect Client</strong></p>



<p class="wp-block-paragraph">Có 2 cách để download Sophos Connect.</p>



<p class="wp-block-paragraph"><strong>Cách 1:</strong> Người dùng tự downlaod. Đăng nhập và Download trên <strong>User Portal</strong>. Click <strong>Download client for Windows</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="136" src="https://thegioifirewall.com/wp-content/uploads/image-2294.png" alt="" class="wp-image-10612" srcset="https://thegioifirewall.com/wp-content/uploads/image-2294.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2294-300x65.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"><strong>Cách 2: </strong>Trên <strong>Sophos v17</strong> bạn download bằng cách đi đến <strong>VPN &gt; Sophos Connect Client &gt; Download</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="269" src="https://thegioifirewall.com/wp-content/uploads/image-2295.png" alt="" class="wp-image-10613" srcset="https://thegioifirewall.com/wp-content/uploads/image-2295.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2295-300x129.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Trên <strong>Sophos V18</strong>, nếu bạn <strong>không thấy tab Sophos Connect client</strong>, bạn có thể đi đến <strong>Ipsec (Remote Access)</strong> chọn <strong>Download client</strong> để tải xuống Sophos Connect.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="386" height="425" src="https://thegioifirewall.com/wp-content/uploads/image-2296.png" alt="" class="wp-image-10614" srcset="https://thegioifirewall.com/wp-content/uploads/image-2296.png 386w, https://thegioifirewall.com/wp-content/uploads/image-2296-272x300.png 272w" sizes="auto, (max-width: 386px) 100vw, 386px" /></figure></div>



<p class="wp-block-paragraph"><strong>Bước 7: Download file cấu hình để Import lên Sophos Connect.</strong></p>



<p class="wp-block-paragraph">Download file cấu hình trên <strong>User Portal</strong>. Click chọn<strong> Download configuration for other OSs.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="570" height="276" src="https://thegioifirewall.com/wp-content/uploads/image-2297.png" alt="" class="wp-image-10615" srcset="https://thegioifirewall.com/wp-content/uploads/image-2297.png 570w, https://thegioifirewall.com/wp-content/uploads/image-2297-300x145.png 300w" sizes="auto, (max-width: 570px) 100vw, 570px" /></figure></div>



<p class="wp-block-paragraph">Bạn sẽ tải xuống <strong>1 file có đuôi .ovpn</strong></p>



<p class="wp-block-paragraph"><strong>Bước 8:</strong> Cài đặt và cấu hình Sophos Connect Client trên máy người dùng.</p>



<p class="wp-block-paragraph">Sau khi tải sophos connect bạn click chọn <strong>run SophosConnect_2.1.20 (Ipsec_and_SSLVPN).msi</strong> và cài đặt theo hướng dẫn.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="215" src="https://thegioifirewall.com/wp-content/uploads/image-2300.png" alt="" class="wp-image-10618" srcset="https://thegioifirewall.com/wp-content/uploads/image-2300.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2300-300x103.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph">Import file đuôi chấm <strong>.ovpn</strong></p>



<p class="wp-block-paragraph">Sau khi cài đặt bạn ở <strong>Sophos Connect &gt; click Import connection</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="619" height="303" src="https://thegioifirewall.com/wp-content/uploads/image-2302.png" alt="" class="wp-image-10620" srcset="https://thegioifirewall.com/wp-content/uploads/image-2302.png 619w, https://thegioifirewall.com/wp-content/uploads/image-2302-300x147.png 300w" sizes="auto, (max-width: 619px) 100vw, 619px" /></figure></div>



<p class="wp-block-paragraph">Chọn file đuôi .ovpn ở bước trên. Click <strong>Open</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="616" height="367" src="https://thegioifirewall.com/wp-content/uploads/image-2303.png" alt="" class="wp-image-10621" srcset="https://thegioifirewall.com/wp-content/uploads/image-2303.png 616w, https://thegioifirewall.com/wp-content/uploads/image-2303-300x179.png 300w" sizes="auto, (max-width: 616px) 100vw, 616px" /></figure></div>



<p class="wp-block-paragraph">Chọn <strong>Connect.</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="603" height="273" src="https://thegioifirewall.com/wp-content/uploads/image-2304.png" alt="" class="wp-image-10622" srcset="https://thegioifirewall.com/wp-content/uploads/image-2304.png 603w, https://thegioifirewall.com/wp-content/uploads/image-2304-300x136.png 300w, https://thegioifirewall.com/wp-content/uploads/image-2304-600x273.png 600w" sizes="auto, (max-width: 603px) 100vw, 603px" /></figure></div>



<p class="wp-block-paragraph"><strong>Authenticate user</strong>. Nhập <strong>user và password</strong> được cấp để VPN. Click <strong>Sign in</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="605" height="457" src="https://thegioifirewall.com/wp-content/uploads/image-2305.png" alt="" class="wp-image-10623" srcset="https://thegioifirewall.com/wp-content/uploads/image-2305.png 605w, https://thegioifirewall.com/wp-content/uploads/image-2305-300x227.png 300w" sizes="auto, (max-width: 605px) 100vw, 605px" /></figure></div>



<p class="wp-block-paragraph">SSL VPN thành công.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="604" height="308" src="https://thegioifirewall.com/wp-content/uploads/image-2306.png" alt="" class="wp-image-10624" srcset="https://thegioifirewall.com/wp-content/uploads/image-2306.png 604w, https://thegioifirewall.com/wp-content/uploads/image-2306-300x153.png 300w" sizes="auto, (max-width: 604px) 100vw, 604px" /></figure></div>



<p class="wp-block-paragraph">Check trên máy tính đã nhận ip range <strong>SSL VPN là 10.81.234.6</strong>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="553" height="327" src="https://thegioifirewall.com/wp-content/uploads/image-2310.png" alt="" class="wp-image-10628" srcset="https://thegioifirewall.com/wp-content/uploads/image-2310.png 553w, https://thegioifirewall.com/wp-content/uploads/image-2310-300x177.png 300w" sizes="auto, (max-width: 553px) 100vw, 553px" /></figure></div>



<p class="wp-block-paragraph">Check trên Sophos. Bạn đi đến <strong>Current Activities &gt; Live User.</strong></p>



<p class="wp-block-paragraph"><strong>User johnD </strong>đang kết nối.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="624" height="230" src="https://thegioifirewall.com/wp-content/uploads/image-2311.png" alt="" class="wp-image-10629" srcset="https://thegioifirewall.com/wp-content/uploads/image-2311.png 624w, https://thegioifirewall.com/wp-content/uploads/image-2311-300x111.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></figure></div>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/sophos-xg-firewall-huong-dan-cau-hinh-remote-access-ssl-vpn-voi-sophos-connect-client/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
