我对防火墙配置一个SSLVPN,使用户能够远程来访问设备,怎么配置呢?流程是什么呢?具体是什么思路呢?
(0)
最佳答案
配置如下,照着复制粘贴即可,需要把sslvp的外网IP改成自己的就行:
创建sslvpn虚拟接口,并配置sslvpn IP段:
interface SSLVPN-AC1
ip address 172.16.100.1 255.255.255.0
manage https inbound
manage ping inbound
manage ssh inbound
#
创建sslvpn安全域,并把sslvpn接口加入sslvpn安全域(创建专门的安全域可选)
security-zone name sslvpn
import interface SSLVPN-AC1
#
配置地址sslvpn段对象组:
object-group ip address sslvpn
0 network subnet 172.16.100.0 255.255.255.0
object 0 description sslvpn
#
创建sslvpn分配的地址池:
sslvpn ip address-pool sslvpn 172.16.100.2 172.16.100.254
#
绑定出口IP和开启sslvpn服务
sslvpn gateway gw
ip address 1.1.1.1 port 65534 //1.1.1.1为出接口IP
service enable
#
sslvpn context gw
gateway gw
undo password-changing enable
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool sslvpn mask 255.255.255.0
web-access ip-client auto-activate
放行sslvpn访问的业务网段:
ip-route-list list
include 172.16.0.0 255.255.255.0
include 172.16.248.0 255.255.252.0
include 172.16.253.0 255.255.255.0
policy-group group
ip-tunnel access-route ip-route-list list
ip-tunnel address-pool sslvpn mask 255.255.255.0
default-policy-group group
log user-login enable
force-logout max-onlines enable
service enable
#
放行安全域
security-policy ip
rule 1 name sslvpn-trust
action pass
logging enable
counting enable
profile 1_IPv4
source-zone sslvpn
destination-zone Trust
#
rule 2 name trust-sslvpn
action pass
logging enable
counting enable
source-zone Trust
destination-zone sslvpn
#
创建sslvpn账号和密码:
local-user user01 class network
password simple user01
service-type sslvpn
authorization-attribute user-role network-operator
authorization-attribute sslvpn-policy-group group
#
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论