<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sophos XGS: Hướng dẫn cấu hình Failover cho nhiều đường IPSec VPN bằng SD-WAN &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/sophos-xgs-huong-dan-cau-hinh-failover-cho-nhieu-duong-ipsec-vpn-bang-sd-wan/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Mon, 30 Aug 2021 02:03:56 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Sophos XGS: Hướng dẫn cấu hình Failover cho nhiều đường IPSec VPN bằng SD-WAN &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Sophos XGS: Hướng dẫn cấu hình Failover cho nhiều đường IPSec VPN bằng SD-WAN</title>
		<link>https://thegioifirewall.com/sophos-xgs-huong-dan-cau-hinh-failover-cho-nhieu-duong-ipsec-vpn-bang-sd-wan/</link>
					<comments>https://thegioifirewall.com/sophos-xgs-huong-dan-cau-hinh-failover-cho-nhieu-duong-ipsec-vpn-bang-sd-wan/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Thu, 26 Aug 2021 02:44:00 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Sophos XG]]></category>
		<category><![CDATA[Sophos XGS: Hướng dẫn cấu hình Failover cho nhiều đường IPSec VPN bằng SD-WAN]]></category>
		<guid isPermaLink="false">https://www.thegioifirewall.com/?p=11677</guid>

					<description><![CDATA[1.Mục đích bài viết Bài viết này mô tả các bước để định cấu hình nhiều kết nối VPN IPsec để dự phòng. Nếu liên kết VPN chính không hoạt động, liên kết VPN Internet dự phòng sẽ thay thế. 2.Sơ đồ mạng Chi tiết sơ đồ mạng: Thiết bị tường lửa Sophos Firewall 1 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>1.Mục đích bài viết</strong></h2>



<p class="wp-block-paragraph">Bài viết này mô tả các bước để định cấu hình nhiều kết nối VPN IPsec để dự phòng. Nếu liên kết VPN chính không hoạt động, liên kết VPN Internet dự phòng sẽ thay thế.</p>



<h2 class="wp-block-heading"><strong>2.Sơ đồ mạng</strong></h2>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="464" src="https://thegioifirewall.com/wp-content/uploads/Diagram_Failover-1024x464.png" alt="" class="wp-image-11678" srcset="https://thegioifirewall.com/wp-content/uploads/Diagram_Failover-1024x464.png 1024w, https://thegioifirewall.com/wp-content/uploads/Diagram_Failover-300x136.png 300w, https://thegioifirewall.com/wp-content/uploads/Diagram_Failover-768x348.png 768w, https://thegioifirewall.com/wp-content/uploads/Diagram_Failover-1536x696.png 1536w, https://thegioifirewall.com/wp-content/uploads/Diagram_Failover-2048x928.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Chi tiết sơ đồ mạng:</strong></p>



<p class="wp-block-paragraph"><strong>Thiết bị tường lửa Sophos Firewall 1 (SF1)</strong></p>



<ul class="wp-block-list"><li>Trên thiết bị có 2 đường internet là ISP 1 có IP 192.168.2.103 được cấu hình tại Port 2 và ISP 2 có IP 192.168.2.117 được cấu hình tại Port 3.</li><li>Lớp mạng LAN được cấu hình tại Port 1 với IP 10.145.41.1/24 và đã cấu hình DHCP để cấp phát cho các thiết bị kết nối vào.</li></ul>



<p class="wp-block-paragraph"><strong>Thiết bị tường lửa Sophos Firewall 2 (SF2)</strong></p>



<ul class="wp-block-list"><li>Trên thiết bị có 1 đường internet có IP 192.168.2.119 được cấu hình tại Port 2.</li><li>Lớp mạng LAN được cấu hình tại Port 1 với IP 10.146.41.1/24 và đã cấu hình DHCP để cấp phát cho các thiết bị kết nối vào.</li></ul>



<h2 class="wp-block-heading"><strong>3.Tình huống cấu hình</strong></h2>



<p class="wp-block-paragraph">Chúng ta sẽ thực hiện cấu hình 2 kết nối IPSec Site to site VPN từ thiết bị Sophos Firewall 1 đến Sophos Firewall 2 bằng 2 đường ISP 1 và ISP2.</p>



<p class="wp-block-paragraph">Sau đó sẽ thực hiện cấu hình IPSec failover để khi kết nối IPSec VPN bằng ISP 1 gặp sự cố thì kết nối IPSec VPN bằng ISP 2 sẽ thay thế.</p>



<h2 class="wp-block-heading"><strong>4.Các bước cấu hình</strong></h2>



<p class="wp-block-paragraph"><strong>Cấu hình trên Sophos Firewall 1:</strong></p>



<ul class="wp-block-list"><li>Tạo profile cho lớp mạng local và remote LAN.</li><li>Tạo kết nối IPSec VPN bằng ISP 1.</li><li>Tạo kết nối IPSec VPN bằng ISP 2.</li><li>Thêm 2 firewall rule cho phép lưu lượng VPN.</li><li>Mở 2 dịch vụ HTTPS và PING cho VPN zone.</li></ul>



<p class="wp-block-paragraph"><strong>Cấu hình trên Sophos Firewall 2:</strong></p>



<ul class="wp-block-list"><li>Tạo profile cho lớp mạng local và remote LAN.</li><li>Tạo kết nối IPSec VPN đến ISP 1.</li><li>Tạo kết nối IPSec VPN đến ISP 2.</li><li>Cấu hình Failover cho các kết nối IPSec VPN.</li><li>Thêm 2 firewall rule cho phép lưu lượng VPN.</li><li>Mở 2 dịch vụ HTTPS và PING cho VPN zone.</li></ul>



<p class="wp-block-paragraph"><strong>Kiểm tra kết quả.</strong></p>



<h2 class="wp-block-heading"><strong>5.Hướng dẫn cấu hình.</strong></h2>



<h3 class="wp-block-heading"><strong>5.1.Cấu hình trên Sophos Firewall 1</strong></h3>



<h4 class="wp-block-heading"><strong>5.1.1.Tạo profile cho lớp mạng local và remote LAN</strong></h4>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>Hosts and Services &gt; IP Host</strong>&nbsp;và nhấn&nbsp;<strong>Add</strong>&nbsp;để tạo local LAN với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: SF1_LAN.</li><li>IP version*: IPv4.</li><li>Type*: Network</li><li>IP address*: 10.145.41.0 – Subnet /24[255.255.255.0].</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/1-37-1024x272.png" alt="" class="wp-image-11679" srcset="https://thegioifirewall.com/wp-content/uploads/1-37-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-37-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/1-37-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/1-37-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-37-2048x544.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>Hosts and Services &gt; IP Host</strong>&nbsp;và nhấn&nbsp;<strong>Add</strong>&nbsp;để tạo remote LAN với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: SF2_LAN.</li><li>IP version*: IPv4.</li><li>Type*: Network</li><li>IP address*: 10.146.41.0 – Subnet /24[255.255.255.0].</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/2-32-1024x272.png" alt="" class="wp-image-11680" srcset="https://thegioifirewall.com/wp-content/uploads/2-32-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-32-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/2-32-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/2-32-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-32-2048x544.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.2.Tạo kết nối IPsec VPN bằng ISP 1</strong></h4>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>VPN &gt; IPsec Connection</strong>&nbsp;và nhấn&nbsp;<strong>Add</strong>. Tạo kết nối IPsec VPN bằng các thông số như hình dưới đây và sử dụng cổng&nbsp;<strong>IPS1</strong>&nbsp;là&nbsp;<strong>Listening Interface</strong>.</p>



<p class="wp-block-paragraph">Cấu hình General settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: SF1_to_SF2_ISP1.</li><li>IP version: chọn IPv4.</li><li>Connection type: chọn Site-to-site.</li><li>Gateway type: Respond only.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="273" src="https://thegioifirewall.com/wp-content/uploads/3-37-1024x273.png" alt="" class="wp-image-11681" srcset="https://thegioifirewall.com/wp-content/uploads/3-37-1024x273.png 1024w, https://thegioifirewall.com/wp-content/uploads/3-37-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/3-37-768x205.png 768w, https://thegioifirewall.com/wp-content/uploads/3-37-1536x410.png 1536w, https://thegioifirewall.com/wp-content/uploads/3-37-2048x546.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Encryption với các thông số sau:</p>



<ul class="wp-block-list"><li>Policy: chọn IKEv2</li><li>Authentication type: chọn Preshared key</li><li>Nhập mật khẩu vào 2 ô Preshared key và Repeat preshared key.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="270" src="https://thegioifirewall.com/wp-content/uploads/4-37-1024x270.png" alt="" class="wp-image-11682" srcset="https://thegioifirewall.com/wp-content/uploads/4-37-1024x270.png 1024w, https://thegioifirewall.com/wp-content/uploads/4-37-300x79.png 300w, https://thegioifirewall.com/wp-content/uploads/4-37-768x202.png 768w, https://thegioifirewall.com/wp-content/uploads/4-37-1536x405.png 1536w, https://thegioifirewall.com/wp-content/uploads/4-37-2048x540.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Gateway settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Listening interface: chọn <strong>Port2 – 192.168.2.103</strong>.</li><li>Gateway address: nhập IP WAN của SF2 là 192.168.2.119.</li><li>Local subnet: chọn profile SF1_LAN.</li><li>Remote subnet: chọn profile SF2_LAN.</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="477" src="https://thegioifirewall.com/wp-content/uploads/5-35-1024x477.png" alt="" class="wp-image-11683" srcset="https://thegioifirewall.com/wp-content/uploads/5-35-1024x477.png 1024w, https://thegioifirewall.com/wp-content/uploads/5-35-300x140.png 300w, https://thegioifirewall.com/wp-content/uploads/5-35-768x358.png 768w, https://thegioifirewall.com/wp-content/uploads/5-35-1536x716.png 1536w, https://thegioifirewall.com/wp-content/uploads/5-35-2048x955.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.3.Tạo kết nối IPSec VPN bằng ISP 2.</strong></h4>



<p class="wp-block-paragraph">Tạo 1 kết nối IPsec khác sử dụng các thông tin như hình dưới đây và sử dụng cổng&nbsp;<strong>ISP2</strong>&nbsp;là&nbsp;<strong>Listening Interface</strong>.</p>



<p class="wp-block-paragraph">Cấu hình General settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: SF1_to_SF2_ISP2.</li><li>IP version: chọn IPv4.</li><li>Connection type: chọn Site-to-site.</li><li>Gateway type: chọn Respond only.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="279" src="https://thegioifirewall.com/wp-content/uploads/6-36-1024x279.png" alt="" class="wp-image-11684" srcset="https://thegioifirewall.com/wp-content/uploads/6-36-1024x279.png 1024w, https://thegioifirewall.com/wp-content/uploads/6-36-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/6-36-768x209.png 768w, https://thegioifirewall.com/wp-content/uploads/6-36-1536x418.png 1536w, https://thegioifirewall.com/wp-content/uploads/6-36-2048x557.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Encryption với các thông số sau:</p>



<ul class="wp-block-list"><li>Policy: chọn IKEv2.</li><li>Authentication type: chọn Preshared key.</li><li>Nhập mật khẩu vào 2 ô Preshared key và Repeat preshared key.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="274" src="https://thegioifirewall.com/wp-content/uploads/7-30-1024x274.png" alt="" class="wp-image-11685" srcset="https://thegioifirewall.com/wp-content/uploads/7-30-1024x274.png 1024w, https://thegioifirewall.com/wp-content/uploads/7-30-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/7-30-768x206.png 768w, https://thegioifirewall.com/wp-content/uploads/7-30-1536x411.png 1536w, https://thegioifirewall.com/wp-content/uploads/7-30-2048x548.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Gateway settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Listening interface: chọn <strong>Port3 – 192.168.2.117</strong>.</li><li>Gateway address: nhập IP WAN của SF2 là 192.168.2.119.</li><li>Local subnet: chọn profile SF1_LAN.</li><li>Remote subnet: chọn profile SF2_LAN.</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="484" src="https://thegioifirewall.com/wp-content/uploads/8-28-1024x484.png" alt="" class="wp-image-11687" srcset="https://thegioifirewall.com/wp-content/uploads/8-28-1024x484.png 1024w, https://thegioifirewall.com/wp-content/uploads/8-28-300x142.png 300w, https://thegioifirewall.com/wp-content/uploads/8-28-768x363.png 768w, https://thegioifirewall.com/wp-content/uploads/8-28-1536x725.png 1536w, https://thegioifirewall.com/wp-content/uploads/8-28-2048x967.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Hai kết nối IPsec VPN vừa tạo sẽ hiển thị như sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="278" src="https://thegioifirewall.com/wp-content/uploads/10-25-1024x278.png" alt="" class="wp-image-11688" srcset="https://thegioifirewall.com/wp-content/uploads/10-25-1024x278.png 1024w, https://thegioifirewall.com/wp-content/uploads/10-25-300x81.png 300w, https://thegioifirewall.com/wp-content/uploads/10-25-768x208.png 768w, https://thegioifirewall.com/wp-content/uploads/10-25-1536x416.png 1536w, https://thegioifirewall.com/wp-content/uploads/10-25-2048x555.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn vào biểu tượng hình tròn màu đỏ ở cột&nbsp;<strong>Status Active</strong>&nbsp;để bật 2 kết nối VPN này.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="279" src="https://thegioifirewall.com/wp-content/uploads/11-26-1024x279.png" alt="" class="wp-image-11689" srcset="https://thegioifirewall.com/wp-content/uploads/11-26-1024x279.png 1024w, https://thegioifirewall.com/wp-content/uploads/11-26-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/11-26-768x209.png 768w, https://thegioifirewall.com/wp-content/uploads/11-26-1536x419.png 1536w, https://thegioifirewall.com/wp-content/uploads/11-26-2048x558.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.4.Thêm 2 firewall rule cho phép lưu lượng VPN</strong></h4>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>Rules and policies &gt; Add Firewall Rule &gt; New firewall rule</strong>. Tạo 2&nbsp;<strong>firewall rule</strong>&nbsp;như hình sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="555" src="https://thegioifirewall.com/wp-content/uploads/9-30-1024x555.png" alt="" class="wp-image-11690" srcset="https://thegioifirewall.com/wp-content/uploads/9-30-1024x555.png 1024w, https://thegioifirewall.com/wp-content/uploads/9-30-300x163.png 300w, https://thegioifirewall.com/wp-content/uploads/9-30-768x416.png 768w, https://thegioifirewall.com/wp-content/uploads/9-30-1536x833.png 1536w, https://thegioifirewall.com/wp-content/uploads/9-30.png 2046w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="553" src="https://thegioifirewall.com/wp-content/uploads/32-4-1024x553.png" alt="" class="wp-image-11692" srcset="https://thegioifirewall.com/wp-content/uploads/32-4-1024x553.png 1024w, https://thegioifirewall.com/wp-content/uploads/32-4-300x162.png 300w, https://thegioifirewall.com/wp-content/uploads/32-4-768x415.png 768w, https://thegioifirewall.com/wp-content/uploads/32-4-1536x830.png 1536w, https://thegioifirewall.com/wp-content/uploads/32-4-2048x1107.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.5. Mở 2 dịch vụ HTTPS và PING cho VPN zone.</strong></h4>



<p class="wp-block-paragraph">Để có thể thực hiện ping giữa các host của 2 thiết bị SF1 và SF1 thông qua IPSec VPN, chúng ta cần mở 2 dịch vụ HTTPS và PING trên VPN zone.</p>



<p class="wp-block-paragraph">Để mở vào Administration &gt; Device Access.</p>



<p class="wp-block-paragraph">Tích chọn dịch vụ HTTPS và PING cho VPN zone và nhấn Apply để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="413" src="https://thegioifirewall.com/wp-content/uploads/20-12-1024x413.png" alt="" class="wp-image-11693" srcset="https://thegioifirewall.com/wp-content/uploads/20-12-1024x413.png 1024w, https://thegioifirewall.com/wp-content/uploads/20-12-300x121.png 300w, https://thegioifirewall.com/wp-content/uploads/20-12-768x310.png 768w, https://thegioifirewall.com/wp-content/uploads/20-12-1536x619.png 1536w, https://thegioifirewall.com/wp-content/uploads/20-12-2048x826.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading"><strong>5.2.Cấu hình trên Sophos Firewall 2</strong></h3>



<h4 class="wp-block-heading"><strong>5.2.1.Tạo profile cho lớp mạng local và remote LAN</strong></h4>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>Hosts and Services &gt; IP Host</strong>&nbsp;và nhấn&nbsp;<strong>Add</strong>&nbsp;để tạo local LAN với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: SF1_LAN.</li><li>IP version*: IPv4.</li><li>Type*: Network</li><li>IP address*: 10.145.41.0 – Subnet /24[255.255.255.0].</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/1-37-1024x272.png" alt="" class="wp-image-11679" srcset="https://thegioifirewall.com/wp-content/uploads/1-37-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/1-37-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/1-37-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/1-37-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/1-37-2048x544.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>Hosts and Services &gt; IP Host</strong>&nbsp;và nhấn&nbsp;<strong>Add</strong>&nbsp;để tạo remote LAN với các thông số sau:</p>



<ul class="wp-block-list"><li>Name*: SF2_LAN.</li><li>IP version*: IPv4.</li><li>Type*: Network</li><li>IP address*: 10.146.41.0 – Subnet /24[255.255.255.0].</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/2-32-1024x272.png" alt="" class="wp-image-11680" srcset="https://thegioifirewall.com/wp-content/uploads/2-32-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/2-32-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/2-32-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/2-32-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/2-32-2048x544.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.2.Tạo kết nối IPsec VPN đến ISP 1</strong></h4>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>VPN &gt; IPsec Connection</strong>&nbsp;và nhấn&nbsp;<strong>Add</strong>. Tạo kết nối IPsec VPN bằng các thông số dưới đây.</p>



<p class="wp-block-paragraph">Cấu hình General settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: SF2_to_SF1_ISP1.</li><li>IP version: chọn IPv4.</li><li>Connection type: chọn Site-to-site.</li><li>Gateway type: Initiate the connection.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="272" src="https://thegioifirewall.com/wp-content/uploads/12-24-1024x272.png" alt="" class="wp-image-11694" srcset="https://thegioifirewall.com/wp-content/uploads/12-24-1024x272.png 1024w, https://thegioifirewall.com/wp-content/uploads/12-24-300x80.png 300w, https://thegioifirewall.com/wp-content/uploads/12-24-768x204.png 768w, https://thegioifirewall.com/wp-content/uploads/12-24-1536x408.png 1536w, https://thegioifirewall.com/wp-content/uploads/12-24-2048x544.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Encryption với các thông số sau:</p>



<ul class="wp-block-list"><li>Policy: chọn IKEv2</li><li>Authentication type: chọn Preshared key</li><li>Nhập mật khẩu vào 2 ô Preshared key và Repeat preshared key (nhập giống mật khẩu đã nhập trên SF1).</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="280" src="https://thegioifirewall.com/wp-content/uploads/13-21-1024x280.png" alt="" class="wp-image-11695" srcset="https://thegioifirewall.com/wp-content/uploads/13-21-1024x280.png 1024w, https://thegioifirewall.com/wp-content/uploads/13-21-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/13-21-768x210.png 768w, https://thegioifirewall.com/wp-content/uploads/13-21-1536x420.png 1536w, https://thegioifirewall.com/wp-content/uploads/13-21-2048x560.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Gateway settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Listening interface: chọn <strong>Port2 – 192.168.2.119</strong>.</li><li>Gateway address: nhập IP WAN (ISP 1) của SF1 là 192.168.2.103.</li><li>Local subnet: chọn profile SF2_LAN.</li><li>Remote subnet: chọn profile SF1_LAN.</li><li>Nhấn Save để lưu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="456" src="https://thegioifirewall.com/wp-content/uploads/14-20-1024x456.png" alt="" class="wp-image-11696" srcset="https://thegioifirewall.com/wp-content/uploads/14-20-1024x456.png 1024w, https://thegioifirewall.com/wp-content/uploads/14-20-300x134.png 300w, https://thegioifirewall.com/wp-content/uploads/14-20-768x342.png 768w, https://thegioifirewall.com/wp-content/uploads/14-20-1536x684.png 1536w, https://thegioifirewall.com/wp-content/uploads/14-20-2048x912.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.3.Tạo kết nối IPSec VPN đến ISP 2.</strong></h4>



<p class="wp-block-paragraph">Tạo 1 kết nối IPsec khác sử dụng các thông tin dưới đây.</p>



<p class="wp-block-paragraph">Cấu hình General settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Name: SF2_to_SF1_ISP2.</li><li>IP version: chọn IPv4.</li><li>Connection type: chọn Site-to-site.</li><li>Gateway type: chọn Initiate the connection.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="268" src="https://thegioifirewall.com/wp-content/uploads/15-19-1024x268.png" alt="" class="wp-image-11697" srcset="https://thegioifirewall.com/wp-content/uploads/15-19-1024x268.png 1024w, https://thegioifirewall.com/wp-content/uploads/15-19-300x78.png 300w, https://thegioifirewall.com/wp-content/uploads/15-19-768x201.png 768w, https://thegioifirewall.com/wp-content/uploads/15-19-1536x402.png 1536w, https://thegioifirewall.com/wp-content/uploads/15-19-2048x535.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Encryption với các thông số sau:</p>



<ul class="wp-block-list"><li>Policy: chọn IKEv2.</li><li>Authentication type: chọn Preshared key.</li><li>Nhập mật khẩu vào 2 ô Preshared key và Repeat preshared key (nhập giống như bên SF1).</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="281" src="https://thegioifirewall.com/wp-content/uploads/16-19-1024x281.png" alt="" class="wp-image-11698" srcset="https://thegioifirewall.com/wp-content/uploads/16-19-1024x281.png 1024w, https://thegioifirewall.com/wp-content/uploads/16-19-300x82.png 300w, https://thegioifirewall.com/wp-content/uploads/16-19-768x211.png 768w, https://thegioifirewall.com/wp-content/uploads/16-19-1536x422.png 1536w, https://thegioifirewall.com/wp-content/uploads/16-19-2048x562.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Cấu hình Gateway settings với các thông số sau:</p>



<ul class="wp-block-list"><li>Listening interface: chọn Port3 – 192.168.2.119.</li><li>Gateway address: nhập IP WAN của SF1 (ISP 2) là 192.168.2.117.</li><li>Local subnet: chọn profile SF2_LAN.</li><li>Remote subnet: chọn profile SF1_LAN.</li><li>Nhấn Save.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="458" src="https://thegioifirewall.com/wp-content/uploads/17-17-1024x458.png" alt="" class="wp-image-11699" srcset="https://thegioifirewall.com/wp-content/uploads/17-17-1024x458.png 1024w, https://thegioifirewall.com/wp-content/uploads/17-17-300x134.png 300w, https://thegioifirewall.com/wp-content/uploads/17-17-768x343.png 768w, https://thegioifirewall.com/wp-content/uploads/17-17-1536x686.png 1536w, https://thegioifirewall.com/wp-content/uploads/17-17-2048x915.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Hai kết nối IPsec VPN vừa tạo sẽ hiển thị như sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="283" src="https://thegioifirewall.com/wp-content/uploads/22-7-1024x283.png" alt="" class="wp-image-11700" srcset="https://thegioifirewall.com/wp-content/uploads/22-7-1024x283.png 1024w, https://thegioifirewall.com/wp-content/uploads/22-7-300x83.png 300w, https://thegioifirewall.com/wp-content/uploads/22-7-768x212.png 768w, https://thegioifirewall.com/wp-content/uploads/22-7-1536x424.png 1536w, https://thegioifirewall.com/wp-content/uploads/22-7-2048x565.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.4.Cấu hình Failover cho các kết nối IPSec VPN.</strong></h4>



<p class="wp-block-paragraph">Phía dưới phần&nbsp;<strong>Failover Group</strong>&nbsp;nhấn&nbsp;<strong>Add</strong>.</p>



<p class="wp-block-paragraph">Cấu hình&nbsp;<strong>Failover</strong>&nbsp;theo các thông số như hình sau và nhấn&nbsp;<strong>Save</strong>.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="405" src="https://thegioifirewall.com/wp-content/uploads/23-7-1024x405.png" alt="" class="wp-image-11701" srcset="https://thegioifirewall.com/wp-content/uploads/23-7-1024x405.png 1024w, https://thegioifirewall.com/wp-content/uploads/23-7-300x119.png 300w, https://thegioifirewall.com/wp-content/uploads/23-7-768x304.png 768w, https://thegioifirewall.com/wp-content/uploads/23-7-1536x608.png 1536w, https://thegioifirewall.com/wp-content/uploads/23-7-2048x810.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Màn hình sau đây sẽ được hiển thị cho phần&nbsp;<strong>Failover Group</strong>.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="495" src="https://thegioifirewall.com/wp-content/uploads/24-10-1024x495.png" alt="" class="wp-image-11703" srcset="https://thegioifirewall.com/wp-content/uploads/24-10-1024x495.png 1024w, https://thegioifirewall.com/wp-content/uploads/24-10-300x145.png 300w, https://thegioifirewall.com/wp-content/uploads/24-10-768x371.png 768w, https://thegioifirewall.com/wp-content/uploads/24-10-1536x742.png 1536w, https://thegioifirewall.com/wp-content/uploads/24-10-2048x990.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Nhấp vào biểu tượng vòng tròn màu đỏ bên dưới Status của Failover Group đã được tạo để kích hoạt và thiết lập kết nối chính.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="496" src="https://thegioifirewall.com/wp-content/uploads/25-9-1024x496.png" alt="" class="wp-image-11704" srcset="https://thegioifirewall.com/wp-content/uploads/25-9-1024x496.png 1024w, https://thegioifirewall.com/wp-content/uploads/25-9-300x145.png 300w, https://thegioifirewall.com/wp-content/uploads/25-9-768x372.png 768w, https://thegioifirewall.com/wp-content/uploads/25-9-1536x744.png 1536w, https://thegioifirewall.com/wp-content/uploads/25-9-2048x991.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.2.5.Thêm 2 firewall rule cho phép lưu lượng VPN</strong></h4>



<p class="wp-block-paragraph">Nhấn&nbsp;<strong>Rules and policies &gt; Add Firewall Rule &gt; New firewall rule</strong>. Tạo 2&nbsp;<strong>firewall rule</strong>&nbsp;như hình sau.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="556" src="https://thegioifirewall.com/wp-content/uploads/18-16-1024x556.png" alt="" class="wp-image-11705" srcset="https://thegioifirewall.com/wp-content/uploads/18-16-1024x556.png 1024w, https://thegioifirewall.com/wp-content/uploads/18-16-300x163.png 300w, https://thegioifirewall.com/wp-content/uploads/18-16-768x417.png 768w, https://thegioifirewall.com/wp-content/uploads/18-16-1536x834.png 1536w, https://thegioifirewall.com/wp-content/uploads/18-16-2048x1112.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="555" src="https://thegioifirewall.com/wp-content/uploads/19-15-1024x555.png" alt="" class="wp-image-11706" srcset="https://thegioifirewall.com/wp-content/uploads/19-15-1024x555.png 1024w, https://thegioifirewall.com/wp-content/uploads/19-15-300x163.png 300w, https://thegioifirewall.com/wp-content/uploads/19-15-768x417.png 768w, https://thegioifirewall.com/wp-content/uploads/19-15-1536x833.png 1536w, https://thegioifirewall.com/wp-content/uploads/19-15-2048x1111.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading"><strong>5.1.5. Mở 2 dịch vụ HTTPS và PING cho VPN zone.</strong></h4>



<p class="wp-block-paragraph">Để có thể thực hiện ping giữa các host của 2 thiết bị SF1 và SF1 thông qua IPSec VPN, chúng ta cần mở 2 dịch vụ HTTPS và PING trên VPN zone.</p>



<p class="wp-block-paragraph">Để mở vào Administration &gt; Device Access.</p>



<p class="wp-block-paragraph">Tích chọn dịch vụ HTTPS và PING cho VPN zone và nhấn Apply để lưu.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="413" src="https://thegioifirewall.com/wp-content/uploads/21-11-1024x413.png" alt="" class="wp-image-11707" srcset="https://thegioifirewall.com/wp-content/uploads/21-11-1024x413.png 1024w, https://thegioifirewall.com/wp-content/uploads/21-11-300x121.png 300w, https://thegioifirewall.com/wp-content/uploads/21-11-768x309.png 768w, https://thegioifirewall.com/wp-content/uploads/21-11-1536x619.png 1536w, https://thegioifirewall.com/wp-content/uploads/21-11-2048x825.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading"><strong>5.3.Kiểm tra kết quả.</strong></h2>



<p class="wp-block-paragraph">Sử dụng một máy thuộc lớp LAN của SF1 có IP 10.145.41.11 và ping đến 1 máy thuộc lớp LAN của SF2 có IP 10.146.41.100 và kết quả là ping thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="560" src="https://thegioifirewall.com/wp-content/uploads/29-6-1024x560.png" alt="" class="wp-image-11709" srcset="https://thegioifirewall.com/wp-content/uploads/29-6-1024x560.png 1024w, https://thegioifirewall.com/wp-content/uploads/29-6-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/29-6-768x420.png 768w, https://thegioifirewall.com/wp-content/uploads/29-6-1536x840.png 1536w, https://thegioifirewall.com/wp-content/uploads/29-6-2048x1120.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Thực hiện ping ngược lại từ máy có IP 10.146.41.100 đến máy có IP 10.145.41.11 và kết quả là ping thành công.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="560" src="https://thegioifirewall.com/wp-content/uploads/28-9-1024x560.png" alt="" class="wp-image-11708" srcset="https://thegioifirewall.com/wp-content/uploads/28-9-1024x560.png 1024w, https://thegioifirewall.com/wp-content/uploads/28-9-300x164.png 300w, https://thegioifirewall.com/wp-content/uploads/28-9-768x420.png 768w, https://thegioifirewall.com/wp-content/uploads/28-9-1536x840.png 1536w, https://thegioifirewall.com/wp-content/uploads/28-9-2048x1120.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Truy cập danh sách firewall rule trên cả SF1 và SF2 để xác minh rằng các firewall rule VPN cho phép lưu lượng truy cập vào và ra.</p>



<p class="wp-block-paragraph">Trên SF1.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="104" src="https://thegioifirewall.com/wp-content/uploads/27-8-1024x104.png" alt="" class="wp-image-11711" srcset="https://thegioifirewall.com/wp-content/uploads/27-8-1024x104.png 1024w, https://thegioifirewall.com/wp-content/uploads/27-8-300x30.png 300w, https://thegioifirewall.com/wp-content/uploads/27-8-768x78.png 768w, https://thegioifirewall.com/wp-content/uploads/27-8-1536x156.png 1536w, https://thegioifirewall.com/wp-content/uploads/27-8-2048x207.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Trên SF2.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="105" src="https://thegioifirewall.com/wp-content/uploads/26-8-1024x105.png" alt="" class="wp-image-11710" srcset="https://thegioifirewall.com/wp-content/uploads/26-8-1024x105.png 1024w, https://thegioifirewall.com/wp-content/uploads/26-8-300x31.png 300w, https://thegioifirewall.com/wp-content/uploads/26-8-768x78.png 768w, https://thegioifirewall.com/wp-content/uploads/26-8-1536x157.png 1536w, https://thegioifirewall.com/wp-content/uploads/26-8-2048x209.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Chuyển đến&nbsp;<strong>Report &gt; VPN</strong>&nbsp;và xác minh việc lưu lượng IPsec.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="507" src="https://thegioifirewall.com/wp-content/uploads/30-7-1024x507.png" alt="" class="wp-image-11712" srcset="https://thegioifirewall.com/wp-content/uploads/30-7-1024x507.png 1024w, https://thegioifirewall.com/wp-content/uploads/30-7-300x149.png 300w, https://thegioifirewall.com/wp-content/uploads/30-7-768x380.png 768w, https://thegioifirewall.com/wp-content/uploads/30-7-1536x761.png 1536w, https://thegioifirewall.com/wp-content/uploads/30-7-2048x1014.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Bất cứ khi nào liên kết VPN Internet ISP 1 không hoạt động, kết nối IPsec sẽ chuyển sang liên kết VPN Internet ISP 2.</p>



<p class="wp-block-paragraph">Chúng ta sẽ thử ngắt kết nối VPN của đường ISP1 và chúng ta thấy rằng kết nối VPN của đường ISP 2 sẽ tự động thay thế.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="478" src="https://thegioifirewall.com/wp-content/uploads/31-8-1024x478.png" alt="" class="wp-image-11713" srcset="https://thegioifirewall.com/wp-content/uploads/31-8-1024x478.png 1024w, https://thegioifirewall.com/wp-content/uploads/31-8-300x140.png 300w, https://thegioifirewall.com/wp-content/uploads/31-8-768x359.png 768w, https://thegioifirewall.com/wp-content/uploads/31-8-1536x717.png 1536w, https://thegioifirewall.com/wp-content/uploads/31-8-2048x956.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/sophos-xgs-huong-dan-cau-hinh-failover-cho-nhieu-duong-ipsec-vpn-bang-sd-wan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
