我对防火墙配置一个SSLVPN,使用户能够远程来访问设备,怎么配置呢?流程是什么呢?具体是什么思路呢?
(0)
最佳答案
 
							
							
							配置如下,照着复制粘贴即可,需要把sslvp的外网IP改成自己的就行:
创建sslvpn虚拟接口,并配置sslvpn IP段:
interface SSLVPN-AC1
 ip address 172.16.100.1 255.255.255.0
 manage https inbound
 manage ping inbound
 manage ssh inbound
#
创建sslvpn安全域,并把sslvpn接口加入sslvpn安全域(创建专门的安全域可选)
security-zone name sslvpn
 import interface SSLVPN-AC1
#
配置地址sslvpn段对象组:
object-group ip address sslvpn
 0 network subnet 172.16.100.0 255.255.255.0
 object 0 description sslvpn
#
创建sslvpn分配的地址池:
sslvpn ip address-pool sslvpn 172.16.100.2 172.16.100.254
#
绑定出口IP和开启sslvpn服务
sslvpn gateway gw
 ip address 1.1.1.1 port 65534   //1.1.1.1为出接口IP
 service enable
#
sslvpn context gw
 gateway gw
 undo password-changing enable
 ip-tunnel interface SSLVPN-AC1
 ip-tunnel address-pool sslvpn mask 255.255.255.0
 web-access ip-client auto-activate
放行sslvpn访问的业务网段:
 ip-route-list list
  include 172.16.0.0 255.255.255.0
  include 172.16.248.0 255.255.252.0
  include 172.16.253.0 255.255.255.0
 policy-group group
  ip-tunnel access-route ip-route-list list
  ip-tunnel address-pool sslvpn mask 255.255.255.0
 default-policy-group group
 log user-login enable
 force-logout max-onlines enable
 service enable
#
放行安全域
security-policy ip
rule 1 name sslvpn-trust
  action pass
  logging enable
  counting enable
  profile 1_IPv4
  source-zone sslvpn
  destination-zone Trust
#
rule 2 name trust-sslvpn
  action pass
  logging enable
  counting enable
  source-zone Trust
  destination-zone sslvpn
#
创建sslvpn账号和密码:
local-user user01 class network
 password simple user01
 service-type sslvpn
 authorization-attribute user-role network-operator
 authorization-attribute sslvpn-policy-group group
#
(0)
暂无评论
 
	 
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论