<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tường lửa Palo Alto : Hướng dẫn cấu hình Site-to-Site VPN &#8211; Thegioifirewall</title>
	<atom:link href="https://thegioifirewall.com/tag/tuong-lua-palo-alto-huong-dan-cau-hinh-site-to-site-vpn/feed/" rel="self" type="application/rss+xml" />
	<link>https://thegioifirewall.com</link>
	<description>Tường lửa bảo vệ doanh nghiệp, trung tâm thông tin và giá cả</description>
	<lastBuildDate>Mon, 13 Apr 2020 01:59:35 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://thegioifirewall.com/wp-content/uploads/vacif_icon-150x150.png</url>
	<title>Tường lửa Palo Alto : Hướng dẫn cấu hình Site-to-Site VPN &#8211; Thegioifirewall</title>
	<link>https://thegioifirewall.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Tường lửa Palo Alto : Hướng dẫn cấu hình Site-to-Site VPN</title>
		<link>https://thegioifirewall.com/tuong-lua-palo-alto-huong-dan-cau-hinh-site-to-site-vpn/</link>
					<comments>https://thegioifirewall.com/tuong-lua-palo-alto-huong-dan-cau-hinh-site-to-site-vpn/#respond</comments>
		
		<dc:creator><![CDATA[TrungNghia]]></dc:creator>
		<pubDate>Thu, 09 Apr 2020 03:20:30 +0000</pubDate>
				<category><![CDATA[Hướng dẫn cấu hình Firewall Palo Alto]]></category>
		<category><![CDATA[Tường lửa Palo Alto : Hướng dẫn cấu hình Site-to-Site VPN]]></category>
		<guid isPermaLink="false">http://www.thegioifirewall.com/?p=4552</guid>

					<description><![CDATA[1.Giới Thiệu Bài viết này sẽ hướng dẫn người dùng tường lửa Palo Alto về các cấu hình cơ bản với Site-to-Site VPN. Bài viết này sẽ hướng dẫn các cấu hình sau : Tạo và định cấu hình tunnel interface để sử dụng trong kết nối VPN Site-to-Site. Định cấu hình IKE Gateway và [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h3 class="wp-block-heading">1.Giới Thiệu</h3>



<p class="wp-block-paragraph">Bài viết này sẽ hướng dẫn người dùng tường lửa Palo Alto về các cấu hình cơ bản với Site-to-Site VPN.</p>



<p class="wp-block-paragraph">Bài viết này sẽ hướng dẫn các cấu hình sau :</p>



<ul class="wp-block-list"><li>Tạo và định cấu hình tunnel interface để sử dụng trong kết nối VPN Site-to-Site.</li><li>Định cấu hình IKE Gateway và IKE Crypto Profile.</li><li>Cấu hình IPSec Crypto Profile và IPsec tunnel.</li><li>Kiểm tra kết nối.</li></ul>



<h3 class="wp-block-heading">2. Hướng dẫn cấu hình</h3>



<p class="wp-block-paragraph">Chúng ta có sơ đồ mạng như sau</p>



<div class="wp-block-image"><figure class="aligncenter"><img fetchpriority="high" decoding="async" width="1024" height="495" src="https://thegioifirewall.com/wp-content/uploads/diagram-12-1024x495.jpg" alt="" class="wp-image-4615" srcset="https://thegioifirewall.com/wp-content/uploads/diagram-12-1024x495.jpg 1024w, https://thegioifirewall.com/wp-content/uploads/diagram-12-300x145.jpg 300w, https://thegioifirewall.com/wp-content/uploads/diagram-12-768x371.jpg 768w, https://thegioifirewall.com/wp-content/uploads/diagram-12.jpg 1224w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<h4 class="wp-block-heading">2.1 Cấu hình Tunnel Interface</h4>



<p class="wp-block-paragraph">Vào Network &gt; Interfaces &gt; click Add và cấu hình tunnel interface theo thông số sau :</p>



<ul class="wp-block-list"><li>Interface Name : trong textbox phía bên phải của tunnel, nhập 12</li><li>Comment : Tunnel to DMZ</li><li>Virtual Router : lab-vr</li><li>Security Zone : Tạo và gán 1 layer3 zone tên là VPN</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" width="693" height="297" src="https://thegioifirewall.com/wp-content/uploads/1-61.jpg" alt="" class="wp-image-4554" srcset="https://thegioifirewall.com/wp-content/uploads/1-61.jpg 693w, https://thegioifirewall.com/wp-content/uploads/1-61-300x129.jpg 300w" sizes="(max-width: 693px) 100vw, 693px" /></figure></div>



<p class="wp-block-paragraph">Ở tab IPv4 cấu hình theo thông số sau :</p>



<ul class="wp-block-list"><li>IP : 172.16.2.10/24</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img decoding="async" width="695" height="367" src="https://thegioifirewall.com/wp-content/uploads/2-53.jpg" alt="" class="wp-image-4555" srcset="https://thegioifirewall.com/wp-content/uploads/2-53.jpg 695w, https://thegioifirewall.com/wp-content/uploads/2-53-300x158.jpg 300w" sizes="(max-width: 695px) 100vw, 695px" /></figure></div>



<p class="wp-block-paragraph">Ở Advanced tab cấu hình các thông số sau :</p>



<ul class="wp-block-list"><li>Management Profile : ping</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="696" height="295" src="https://thegioifirewall.com/wp-content/uploads/3-54.jpg" alt="" class="wp-image-4556" srcset="https://thegioifirewall.com/wp-content/uploads/3-54.jpg 696w, https://thegioifirewall.com/wp-content/uploads/3-54-300x127.jpg 300w" sizes="auto, (max-width: 696px) 100vw, 696px" /></figure></div>



<p class="wp-block-paragraph">Bấm OK để lưu.</p>



<h4 class="wp-block-heading">2.2 Cấu hình IKE Gateway</h4>



<p class="wp-block-paragraph">Vào Network &gt; Network Profiles &gt; IKE Gateways &gt; Click Add&gt;</p>



<p class="wp-block-paragraph">Cấu hình theo các thông số như sau :</p>



<ul class="wp-block-list"><li>Name : dmz-ike-gateway</li><li>Version : IKEv1 only mode</li><li>Interface : ethernet1/3</li><li>Local IP Address : 192.168.50.1/24</li><li>Peer IP Address Type : IP</li><li>Peer IP Address : 192.168.50.10</li><li>Pre-shared Key : paloalto</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="595" height="455" src="https://thegioifirewall.com/wp-content/uploads/4-45.jpg" alt="" class="wp-image-4557" srcset="https://thegioifirewall.com/wp-content/uploads/4-45.jpg 595w, https://thegioifirewall.com/wp-content/uploads/4-45-300x229.jpg 300w" sizes="auto, (max-width: 595px) 100vw, 595px" /></figure></div>



<p class="wp-block-paragraph">Chuyển qua Advanced Options tab.</p>



<p class="wp-block-paragraph">Ở IKEv1 subtab cấu hình như sau :</p>



<ul class="wp-block-list"><li>Select IKE Crypto Profile</li><li>Name : AES256-DH2-SHA2</li><li>DH Group : Add Group 2</li><li>Authentication : add sha256</li><li>Encryption : Add aes-256-cbc</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="791" height="382" src="https://thegioifirewall.com/wp-content/uploads/5-39.jpg" alt="" class="wp-image-4558" srcset="https://thegioifirewall.com/wp-content/uploads/5-39.jpg 791w, https://thegioifirewall.com/wp-content/uploads/5-39-300x145.jpg 300w, https://thegioifirewall.com/wp-content/uploads/5-39-768x371.jpg 768w" sizes="auto, (max-width: 791px) 100vw, 791px" /></figure></div>



<p class="wp-block-paragraph">Bấm OK 2 lần để lưu.</p>



<h4 class="wp-block-heading">2.3 Tạo 1 IPSec Crypto Profile</h4>



<p class="wp-block-paragraph">Vào Network &gt; Network Profile &gt; IPSec Crypto &gt; bấm Add.</p>



<p class="wp-block-paragraph">Cấu hình theo các thông số sau :</p>



<ul class="wp-block-list"><li>Name : AES256-SHA256</li><li>IPSec Protocol :ESP</li><li>Encryption : Add aes-256-cbc</li><li>Authentication : Add sha256</li><li>Dh Group : chọn group 2</li></ul>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="797" height="413" src="https://thegioifirewall.com/wp-content/uploads/7-30.jpg" alt="" class="wp-image-4562" srcset="https://thegioifirewall.com/wp-content/uploads/7-30.jpg 797w, https://thegioifirewall.com/wp-content/uploads/7-30-300x155.jpg 300w, https://thegioifirewall.com/wp-content/uploads/7-30-768x398.jpg 768w" sizes="auto, (max-width: 797px) 100vw, 797px" /></figure>



<p class="wp-block-paragraph">Bấm OK để lưu.</p>



<h4 class="wp-block-heading">2.4 Cấu hình IPSec Tunnel</h4>



<p class="wp-block-paragraph">Vào Network &gt; IPSec Tunnels &gt; Click Add</p>



<p class="wp-block-paragraph">Ở tab General cấu hình theo thông số sau :</p>



<ul class="wp-block-list"><li>Name : dmz-tunnel</li><li>Tunnel Interface : tunnel.12</li><li>Type : Auto Key</li><li>IKE Gateway : dmz-ike-gateway</li><li>IPSec Crypto Profile : AES256-SHA256</li><li>Show Advanced Options : Select the check box</li><li>Tunnel Monitor : Select the check box</li><li>Destination IP : 172.16.2.11</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="793" height="477" src="https://thegioifirewall.com/wp-content/uploads/8-26.jpg" alt="" class="wp-image-4563" srcset="https://thegioifirewall.com/wp-content/uploads/8-26.jpg 793w, https://thegioifirewall.com/wp-content/uploads/8-26-300x180.jpg 300w, https://thegioifirewall.com/wp-content/uploads/8-26-768x462.jpg 768w" sizes="auto, (max-width: 793px) 100vw, 793px" /></figure></div>



<p class="wp-block-paragraph">Ở tab Proxy IDS, bấm Add và cấu hình theo thông số sau :</p>



<ul class="wp-block-list"><li>Proxy ID : dmz-tunnel-network</li><li>Local : 192.168.1.0/24</li><li>Remote : 172.16.2.0/24</li></ul>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="476" height="209" src="https://thegioifirewall.com/wp-content/uploads/9-23.jpg" alt="" class="wp-image-4564" srcset="https://thegioifirewall.com/wp-content/uploads/9-23.jpg 476w, https://thegioifirewall.com/wp-content/uploads/9-23-300x132.jpg 300w" sizes="auto, (max-width: 476px) 100vw, 476px" /></figure></div>



<p class="wp-block-paragraph">Bấm OK 2 lần để lưu.</p>



<p class="wp-block-paragraph">Bấm Commit để cam kết các thay đổi.</p>



<h4 class="wp-block-heading">2.5 Kiểm tra kết nối</h4>



<p class="wp-block-paragraph">Vào Network &gt; IPSec Tunnels.</p>



<p class="wp-block-paragraph">Lưu ý rằng cột Status trong VPN Tunnel có thể có màu đỏ. Nếu Status hiển thị màu đỏ, VPN Tunnel chưa được kết nối.</p>



<p class="wp-block-paragraph">Refresh lại Network &gt; IPSec Tunnels page. Cột Status lúc này hiển thị màu xanh lá cho biết VPN Tunnel đã được kết nối.</p>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="1024" height="77" src="https://thegioifirewall.com/wp-content/uploads/10-19-1024x77.jpg" alt="" class="wp-image-4565" srcset="https://thegioifirewall.com/wp-content/uploads/10-19-1024x77.jpg 1024w, https://thegioifirewall.com/wp-content/uploads/10-19-300x23.jpg 300w, https://thegioifirewall.com/wp-content/uploads/10-19-768x58.jpg 768w, https://thegioifirewall.com/wp-content/uploads/10-19.jpg 1159w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure></div>



<p class="wp-block-paragraph">Vào Monitor &gt; Logs &gt; System.</p>



<p class="wp-block-paragraph">Xem lại các mục nhật ký VPN.</p>



<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="748" height="434" src="https://thegioifirewall.com/wp-content/uploads/11-19.jpg" alt="" class="wp-image-4566" srcset="https://thegioifirewall.com/wp-content/uploads/11-19.jpg 748w, https://thegioifirewall.com/wp-content/uploads/11-19-300x174.jpg 300w" sizes="auto, (max-width: 748px) 100vw, 748px" /></figure></div>
]]></content:encoded>
					
					<wfw:commentRss>https://thegioifirewall.com/tuong-lua-palo-alto-huong-dan-cau-hinh-site-to-site-vpn/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
