没有配置证书认证,提示:证书认证失败,请检查证书是否过期、配置是否正确。
#
interface SSLVPN-AC1
ip address 10.10.10.1 255.255.255.0
manage https inbound
manage ping inbound
manage ssh inbound
#
security-zone name "SSL VPN"
import interface SSLVPN-AC1
#
#
sslvpn ip address-pool 地址池 10.10.10.2 10.10.10.254
#
sslvpn gateway 2
ip address 1xx.1xx.xx.xx port 4433
service enable
#
sslvpn context SSLVPN1
gateway 1
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool 地址池 mask 255.255.255.0
ip-tunnel dns-server primary 223.5.5.5
ip-tunnel dns-server secondary 114.114.114.114
ip-tunnel log connection-close
ip-tunnel log packet-drop
ip-route-list 192.168.1.0
include 192.168.1.0 255.255.255.0
ip-route-list 缺省
include 0.0.0.0 0.0.0.0
policy-group 资源组1
filter ip-tunnel acl 3000
ip-tunnel access-route ip-route-list 192.168.1.0
ip-tunnel address-pool 地址池 mask 255.255.248.0
default-policy-group 资源组1
log user-login enable
log resource-access enable
force-logout max-onlines enable
service enable
#
#
security-policy ip
rule 3 name SSLVPN_SSLVPN1_20251026224229_IPv4
action pass
source-zone Untrust
destination-zone Local
destination-ip-host 1xx.1xx.xxx.1xx
service-port tcp destination eq 4433
rule 1 name SSLVPN_SSL_20250901155102_IPv4
action pass
logging enable
counting enable
source-zone Untrust
destination-zone Local
service-port tcp destination eq 4433
service-port tcp destination eq 4422
service-port tcp destination eq 14433
rule 0 name GuideSecPolicy
action pass
counting enable
source-zone Trust
destination-zone Untrust
destination-zone DMZ
rule 2 name "SSL VPN-TRUST"
action pass
logging enable
counting enable
source-zone "SSL VPN"
destination-zone Trust
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
没有指定证书