部署方案:如何“无缝”替换旧VPN?
你的目标很简单:用防火墙直接提供SSL VPN服务,替代内网那台性能不佳的单臂模式VPN。
确认防火墙已支持SSL VPN功能
替换策略与步骤
第一步:获取官方文档:开始前,先下载官方配置手册。可以参考官方VPN配置指南和SSL VPN管理员手册。
第二步:配置防火墙SSL VPN服务:参考下面“详细配置步骤”章节,在你的H3C防火墙上新建SSL VPN网关、地址池和用户。
第三步:停用旧VPN并测试:暂时停用旧的SSL VPN设备,从外网测试新配置的VPN能否正常拨入,并确保所有需要访问的内网资源都可达。
第四步:DNS与路由调整:确保防火墙上配置的DNS能正确解析内网资源。如果内网有多个网段,需在SSL VPN策略中添加相应的路由。
第五步:最终替换:确认新VPN服务稳定后,正式将旧的SSL VPN设备下线,并清理其在核心交换机上可能残留的路由或端口映射配置。
命令行配置示例:
<H3C> system-view
# 1. 配置SSL VPN网关,监听外网接口的10443端口
[H3C] sslvpn gateway SSLVPNGW
[H3C-sslvpn-gateway-SSLVPNGW] ip address GigabitEthernet1/0/0 port 10443
[H3C-sslvpn-gateway-SSLVPNGW] service enable
[H3C-sslvpn-gateway-SSLVPNGW] quit
# 2. 创建SSL VPN AC接口并配置地址池
[H3C] interface SSLVPN-AC 1
[H3C-SSLVPN-AC1] ip address 10.10.10.1 255.255.255.0
[H3C-SSLVPN-AC1] quit
[H3C] sslvpn ip address-pool SSLPOOL 10.10.10.2 10.10.10.254
# 3. 配置内网资源访问权限(允许访问192.168.10.0/24网段)
[H3C] acl advanced 3999
[H3C-acl-ipv4-adv-3999] rule permit ip destination 192.168.10.0 0.0.0.255
[H3C-acl-ipv4-adv-3999] quit
# 4. 配置SSL VPN访问实例
[H3C] sslvpn context SSLVPN
[H3C-sslvpn-context-SSLVPN] gateway SSLVPNGW
[H3C-sslvpn-context-SSLVPN] ip-tunnel interface SSLVPN-AC1
[H3C-sslvpn-context-SSLVPN] ip-tunnel address-pool SSLPOOL mask 255.255.255.0
[H3C-sslvpn-context-SSLVPN] ip-tunnel dns-server primary 114.114.114.114
[H3C-sslvpn-context-SSLVPN] ip-route-list NEIWANG
[H3C-sslvpn-context-SSLVPN-route-list-NEIWANG] include 192.168.10.0 255.255.255.0
[H3C-sslvpn-context-SSLVPN-route-list-NEIWANG] quit
[H3C-sslvpn-context-SSLVPN] policy-group SSLVPNZIYUAN
[H3C-sslvpn-context-SSLVPN-policy-group-SSLVPNZIYUAN] filter ip-tunnel acl 3999
[H3C-sslvpn-context-SSLVPN-policy-group-SSLVPNZIYUAN] quit
# 5. 创建用户并授权(例如用户名为vpnuser,密码为Pass@123)
[H3C] local-user vpnuser class network
[H3C-luser-network-vpnuser] password simple Pass@123
[H3C-luser-network-vpnuser] service-type sslvpn
[H3C-luser-network-vpnuser] authorization-attribute user-role network-operator
[H3C-luser-network-vpnuser] authorization-attribute sslvpn-policy-group SSLVPNZIYUAN
[H3C-luser-network-vpnuser] quit
暂无评论