<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>server &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/server/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Tue, 25 Apr 2023 15:15:34 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>server &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>SOPHOS FIREWALL :HƯỚNG DẪN CẤU HÌNH CHẶN DỊCH VỤ REMOTE DESKTOP VÀ SSH, LỚP MẠNG KHÔNG MONG MUỐN ĐẾN SERVER</title>
		<link>https://thegioifirewall.com/sophos-firewall-huong-dan-cau-hinh-chan-dich-vu-remote-desktop-va-ssh-lop-mang-khong-mong-muon-den-server/</link>
					<comments>https://thegioifirewall.com/sophos-firewall-huong-dan-cau-hinh-chan-dich-vu-remote-desktop-va-ssh-lop-mang-khong-mong-muon-den-server/#respond</comments>
		
		<dc:creator><![CDATA[Dino]]></dc:creator>
		<pubDate>Tue, 18 Apr 2023 17:08:33 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Sophos XG]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[remote desktop]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[Sophos firewall]]></category>
		<category><![CDATA[ssh]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=17407</guid>

					<description><![CDATA[Overview Bài viết hướng dẫn cấu hình chỉ cho phép phòng ban IT SSH tới web server và remote desktop vào windows server, không cho người dùng phòng ban Sale thực hiện tương tự như phòng ban IT,bằng 2 phương pháp . Sơ đồ mạng: Các cấu hình chuẩn bị trước: -Windows srv được cài [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Overview</strong></p>



<p class="wp-block-paragraph">Bài viết hướng dẫn cấu hình chỉ cho phép phòng ban IT SSH tới web server và remote desktop vào windows server, không cho người dùng phòng ban Sale thực hiện tương tự như phòng ban IT,bằng 2 phương pháp .</p>



<p class="wp-block-paragraph"><strong>Sơ đồ mạng:</strong></p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img fetchpriority="high" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/image-5201.png" alt="" class="wp-image-17412" width="577" height="352" srcset="https://thegioifirewall.com/wp-content/uploads/image-5201.png 624w, https://thegioifirewall.com/wp-content/uploads/image-5201-300x183.png 300w" sizes="(max-width: 577px) 100vw, 577px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Các cấu hình chuẩn bị trước</strong>:</p>



<p class="wp-block-paragraph">-Windows srv được cài AD,các PC phòng IT và Sale ping được lớp mạng windows srv,web srv</p>



<p class="wp-block-paragraph">-Ubuntu cài đặt Web srv,cấu hình SSH </p>



<p class="wp-block-paragraph">Cài web link tham khảo: https://www.thegioifirewall.com/linux-huong-dan-cai-dat-lamp-stack-tren-ubuntu-server/</p>



<p class="wp-block-paragraph">-Windows srv cấu hình remote desktop</p>



<p class="wp-block-paragraph">-PC phòng ban IT và Sale tất cả được join domain</p>



<p class="wp-block-paragraph"><strong>Hướng dẫn cấu hình:</strong></p>



<p class="wp-block-paragraph"><strong>Cách 1: Application Control<br>1.1.Cấu hình Application Control cho remode desktop và SSH</strong></p>



<ul class="wp-block-list">
<li>Ta vào<strong> Protect</strong>-&gt;chọn <strong>Applications</strong>-&gt;tiếp <strong>Application Filter</strong>-&gt;nhấn <strong>Add</strong></li>



<li><strong>Name</strong>: Nhập tên tùy ý</li>



<li><strong>Template</strong>: Allow All</li>



<li>Nhấn <strong>Save</strong> để tạo</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img decoding="async" src="https://thegioifirewall.com/wp-content/uploads/1-119-1024x391.png" alt="" class="wp-image-17420" width="840" height="320" srcset="https://thegioifirewall.com/wp-content/uploads/1-119-1024x391.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-119-300x115.png 300w, https://thegioifirewall.com/wp-content/uploads/1-119-768x293.png 768w, https://thegioifirewall.com/wp-content/uploads/1-119.png 1312w" sizes="(max-width: 840px) 100vw, 840px" /></figure>
</div>


<ul class="wp-block-list">
<li>Tại <strong>smart filter</strong> ta nhập lần lược <strong>SSH</strong> và <strong>windows remote desktop</strong></li>



<li>Tại <strong>Action</strong> chọn <strong>deny</strong></li>



<li>Nhấn <strong>save</strong> để tạo</li>
</ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="407" src="https://thegioifirewall.com/wp-content/uploads/2-118-1024x407.png" alt="" class="wp-image-17455" srcset="https://thegioifirewall.com/wp-content/uploads/2-118-1024x407.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-118-300x119.png 300w, https://thegioifirewall.com/wp-content/uploads/2-118-768x305.png 768w, https://thegioifirewall.com/wp-content/uploads/2-118.png 1304w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="403" src="https://thegioifirewall.com/wp-content/uploads/3-114-1024x403.png" alt="" class="wp-image-17457" srcset="https://thegioifirewall.com/wp-content/uploads/3-114-1024x403.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-114-300x118.png 300w, https://thegioifirewall.com/wp-content/uploads/3-114-768x303.png 768w, https://thegioifirewall.com/wp-content/uploads/3-114.png 1297w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>1.2 Định danh cho lớp mạng</strong></p>



<ul class="wp-block-list">
<li>Ta vào <strong>System</strong>-&gt;chọn <strong>Hosts and services</strong> -&gt;nhấn <strong>Add</strong></li>



<li><strong>Name</strong>: Nhập tên tùy ý</li>



<li><strong>Type</strong>:Chọn network</li>



<li><strong>IP address</strong>:Nhập ip local</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="371" src="https://thegioifirewall.com/wp-content/uploads/17-43-1024x371.png" alt="" class="wp-image-17459" srcset="https://thegioifirewall.com/wp-content/uploads/17-43-1024x371.png 1024w, https://thegioifirewall.com/wp-content/uploads/17-43-300x109.png 300w, https://thegioifirewall.com/wp-content/uploads/17-43-768x278.png 768w, https://thegioifirewall.com/wp-content/uploads/17-43.png 1198w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Làm tương tự</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="366" src="https://thegioifirewall.com/wp-content/uploads/18-42-1024x366.png" alt="" class="wp-image-17460" srcset="https://thegioifirewall.com/wp-content/uploads/18-42-1024x366.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-42-300x107.png 300w, https://thegioifirewall.com/wp-content/uploads/18-42-768x275.png 768w, https://thegioifirewall.com/wp-content/uploads/18-42.png 1199w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>1.3 Tạo rule và add block applications vào Identify and control applications (App control)</strong></p>



<ul class="wp-block-list">
<li>Ta vào <strong>Protect</strong>-&gt;chọn <strong>rules and policies</strong>-&gt; nhấn <strong>add firewall rule</strong></li>



<li><strong>Source zones</strong>:ta chọn mạng nội bộ LAN</li>



<li><strong>Source networks and devices</strong>:ta chọn lớp mạng cần đi</li>



<li><strong>Destination zones</strong>:ta chọn lớp mạng của server (có thể LAN hoặc DMZ)</li>



<li><strong>Destination networks</strong>:ta chọn lớp mạng của server</li>



<li><strong>Identify and control applications</strong>:ta add Block_RDP vào</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/4-109-1024x662.png" alt="" class="wp-image-17429" width="678" height="438" srcset="https://thegioifirewall.com/wp-content/uploads/4-109-1024x662.png 1024w, https://thegioifirewall.com/wp-content/uploads/4-109-300x194.png 300w, https://thegioifirewall.com/wp-content/uploads/4-109-768x497.png 768w, https://thegioifirewall.com/wp-content/uploads/4-109.png 1200w" sizes="auto, (max-width: 678px) 100vw, 678px" /></figure>
</div>

<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/5-106-1024x757.png" alt="" class="wp-image-17430" width="678" height="500" srcset="https://thegioifirewall.com/wp-content/uploads/5-106-1024x757.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-106-300x222.png 300w, https://thegioifirewall.com/wp-content/uploads/5-106-768x568.png 768w, https://thegioifirewall.com/wp-content/uploads/5-106.png 1194w" sizes="auto, (max-width: 678px) 100vw, 678px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Kết Quả</strong>: Dùng máy PC thuộc Sale điều bị block khi SSH vào web server và remote desktop vào windows server<br><strong>Kết quả</strong> không remote desktop được</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/7-83.png" alt="" class="wp-image-17432" width="544" height="379" srcset="https://thegioifirewall.com/wp-content/uploads/7-83.png 544w, https://thegioifirewall.com/wp-content/uploads/7-83-300x209.png 300w" sizes="auto, (max-width: 544px) 100vw, 544px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Kết quả</strong> không SSH tới web server được</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/8-80-1024x592.png" alt="" class="wp-image-17433" width="674" height="389" srcset="https://thegioifirewall.com/wp-content/uploads/8-80-1024x592.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-80-300x173.png 300w, https://thegioifirewall.com/wp-content/uploads/8-80-768x444.png 768w, https://thegioifirewall.com/wp-content/uploads/8-80.png 1100w" sizes="auto, (max-width: 674px) 100vw, 674px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>Cách 2: Cấu hình cấu hình services trong rules and policies</strong></p>



<p class="wp-block-paragraph">1.<strong>Tạo services cho giao thức UDP và TCP có thể join domain</strong></p>



<ul class="wp-block-list">
<li>Ta vào <strong>system</strong>-&gt;chọn <strong>Hosts and services</strong> -&gt; vào <strong>services</strong>-&gt;gõ như hình</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/9-79-1024x527.png" alt="" class="wp-image-17436" width="739" height="380" srcset="https://thegioifirewall.com/wp-content/uploads/9-79-1024x527.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-79-300x154.png 300w, https://thegioifirewall.com/wp-content/uploads/9-79-768x395.png 768w, https://thegioifirewall.com/wp-content/uploads/9-79-1536x790.png 1536w, https://thegioifirewall.com/wp-content/uploads/9-79.png 1614w" sizes="auto, (max-width: 739px) 100vw, 739px" /></figure>
</div>


<ol class="wp-block-list" start="2">
<li><strong>Tạo rules cho từng phòng ban đến server<br>2.1 Rules cho phòng ban IT đến server</strong></li>
</ol>



<p class="wp-block-paragraph">          Tạo lớp mạng local cho phòng ban IT</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/20-36-1024x376.png" alt="" class="wp-image-17466" width="733" height="269" srcset="https://thegioifirewall.com/wp-content/uploads/20-36-1024x376.png 1024w, https://thegioifirewall.com/wp-content/uploads/20-36-300x110.png 300w, https://thegioifirewall.com/wp-content/uploads/20-36-768x282.png 768w, https://thegioifirewall.com/wp-content/uploads/20-36.png 1287w" sizes="auto, (max-width: 733px) 100vw, 733px" /></figure>
</div>


<ul class="wp-block-list">
<li> Tương tự tạo rule ở trên (xem tại mục 1.3)</li>



<li> Phần<strong> services</strong> ta <strong>add</strong> như hình</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/10-70-1024x756.png" alt="" class="wp-image-17437" width="729" height="537" srcset="https://thegioifirewall.com/wp-content/uploads/10-70-1024x756.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-70-300x221.png 300w, https://thegioifirewall.com/wp-content/uploads/10-70-768x567.png 768w, https://thegioifirewall.com/wp-content/uploads/10-70.png 1207w" sizes="auto, (max-width: 729px) 100vw, 729px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>2.2 Rules cho phòng ban Sale đến server</strong></p>



<ul class="wp-block-list">
<li>Cách tạo rules như trên (xem tại mục 1.3)</li>



<li>Phần <strong>services</strong>:ta add <strong>DNS,Ping,UDP&amp;TCP-AD</strong></li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/13-54.png" alt="" class="wp-image-17442" width="732" height="504" srcset="https://thegioifirewall.com/wp-content/uploads/13-54.png 1013w, https://thegioifirewall.com/wp-content/uploads/13-54-300x207.png 300w, https://thegioifirewall.com/wp-content/uploads/13-54-768x530.png 768w" sizes="auto, (max-width: 732px) 100vw, 732px" /></figure>
</div>


<p class="wp-block-paragraph"><strong>2.3 Tạo rule cho Server đi đến mạng lan<br></strong>Cách tạo rules như trên (xem mục 1.3)</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/14-51.png" alt="" class="wp-image-17443" width="729" height="505" srcset="https://thegioifirewall.com/wp-content/uploads/14-51.png 990w, https://thegioifirewall.com/wp-content/uploads/14-51-300x208.png 300w, https://thegioifirewall.com/wp-content/uploads/14-51-768x533.png 768w" sizes="auto, (max-width: 729px) 100vw, 729px" /></figure>
</div>


<p class="wp-block-paragraph">Kết quả:<br>U2 thuộc sale không thể SSH tới web server và không remote desktop tới windows server</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://thegioifirewall.com/wp-content/uploads/16-47-1024x585.png" alt="" class="wp-image-17447" width="721" height="411" srcset="https://thegioifirewall.com/wp-content/uploads/16-47-1024x585.png 1024w, https://thegioifirewall.com/wp-content/uploads/16-47-300x171.png 300w, https://thegioifirewall.com/wp-content/uploads/16-47-768x439.png 768w, https://thegioifirewall.com/wp-content/uploads/16-47.png 1292w" sizes="auto, (max-width: 721px) 100vw, 721px" /></figure>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/sophos-firewall-huong-dan-cau-hinh-chan-dich-vu-remote-desktop-va-ssh-lop-mang-khong-mong-muon-den-server/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
