Hnub no peb yuav saib cov kev xaiv VPN teeb tsa uas NSX Edge muab rau peb.
Feem ntau, peb tuaj yeem faib cov thev naus laus zis VPN ua ob hom tseem ceeb:
Qhov chaw-rau-site VPN. Kev siv ntau tshaj plaws ntawm IPSec yog los tsim qhov chaw ruaj ntseg, piv txwv li, nruab nrab ntawm lub chaw ua haujlwm loj thiab lub network ntawm qhov chaw nyob deb lossis hauv huab.
Chaw taws teeb Access VPN. Siv los txuas ib tus neeg siv rau lub koom haum ntiag tug network siv VPN tus neeg siv software.
NSX Edge tso cai rau peb ua ob qho tib si.
Peb yuav ua qhov teeb tsa siv lub rooj zaum sim nrog ob lub NSX Ntug, Linux server nrog lub daemon ntsia raccoon thiab lub khoos phis tawj Windows los sim Chaw Taws Teeb VPN.
Txhua yam yog npaj txhij, qhov chaw-rau-site IPsec VPN tau teeb tsa thiab ua haujlwm.
Hauv qhov piv txwv no, peb siv PSK los txheeb xyuas cov phooj ywg, tab sis daim ntawv pov thawj authentication kuj yog ib qho kev xaiv. Ua li no, mus rau lub Ntiaj Teb Configuration tab, qhib daim ntawv pov thawj authentication thiab xaiv daim ntawv pov thawj nws tus kheej.
Tsis tas li ntawd, koj yuav tsum tau hloov txoj kev authentication hauv qhov chaw teeb tsa.
Kuv nco ntsoov tias tus naj npawb ntawm IPsec tunnels nyob ntawm qhov loj ntawm Edge Gateway (nyeem txog qhov no hauv peb thawj tsab xov xwm).
SSL VPN
SSL VPN-Plus yog ib qho ntawm cov kev xaiv chaw taws teeb nkag VPN. Nws tso cai rau ib tus neeg siv cov chaw taws teeb tswj kom ruaj ntseg txuas mus rau ntiag tug network tom qab NSX Edge rooj vag. Ib qhov encrypted nyob rau hauv rooj plaub ntawm SSL VPN-ntxiv yog tsim los ntawm tus neeg siv khoom (Windows, Linux, Mac) thiab NSX Edge.
Cia peb pib teeb tsa. Hauv Edge Gateway cov kev pabcuam tswj vaj huam sib luag, mus rau SSL VPN-Plus tab, tom qab ntawd mus rau Chaw Xa Khoom. Peb xaiv qhov chaw nyob thiab chaw nres nkoj uas tus neeg rau zaub mov yuav mloog rau kev sib txuas tuaj, pab kom nkag mus thiab xaiv qhov tsim nyog encryption algorithms.
Ntawm no koj tuaj yeem hloov daim ntawv pov thawj uas lub server yuav siv.
Tom qab txhua yam npaj txhij, qhib lub server thiab tsis txhob hnov ββββqab txuag cov chaw.
Tom ntej no, peb yuav tsum tau teeb tsa lub pas dej ntawm qhov chaw nyob uas peb yuav muab rau cov neeg siv khoom thaum txuas. Lub network no yog cais los ntawm ib qho subnet uas twb muaj lawm hauv koj qhov NSX ib puag ncig thiab tsis tas yuav tsum tau teeb tsa ntawm lwm cov khoom siv ntawm lub cev sib txuas uas tsis yog cov kev taw qhia rau nws.
Mus rau IP Pools tab thiab nyem +.
Xaiv qhov chaw nyob, subnet mask thiab lub rooj vag. Ntawm no koj tuaj yeem hloov qhov chaw rau DNS thiab WINS servers.
Lub pas dej ua ke.
Tam sim no cia peb ntxiv cov tes hauj lwm uas cov neeg siv txuas rau VPN yuav nkag mus rau. Cia peb mus rau Private Networks tab thiab nyem +.
Sau rau hauv:
Network - lub network hauv zos uas cov neeg siv nyob deb yuav nkag tau.
Xa tsheb khiav, nws muaj ob txoj kev xaiv:
- hla lub qhov - xa tsheb mus rau lub network los ntawm lub qhov,
- bypass qhov - xa tsheb mus rau lub network ncaj qha hla lub qhov.
Qhib TCP Optimization - khij lub npov no yog tias koj tau xaiv qhov kev xaiv dhau qhov. Thaum optimization yog enabled, koj tuaj yeem qhia cov lej chaw nres nkoj uas koj xav kom ua kom zoo tshaj tsheb. Tsheb thauj mus los rau cov chaw nres nkoj uas tseem tshuav ntawm lub network tshwj xeeb yuav tsis ua kom zoo dua. Yog tias tus lej chaw nres nkoj tsis tau teev tseg, kev khiav tsheb rau txhua qhov chaw nres nkoj tau zoo. Nyeem ntxiv txog qhov no no.
Tom ntej no, mus rau qhov kev lees paub tab thiab nyem +. Rau authentication peb yuav siv lub zos server ntawm NSX Edge nws tus kheej.
Ntawm no peb tuaj yeem xaiv cov cai tsim cov passwords tshiab thiab teeb tsa cov kev xaiv rau thaiv cov neeg siv nyiaj (piv txwv li, tus lej ntawm kev rov ua dua yog tias tus password nkag tsis raug).
Txij li thaum peb tab tom siv cov ntawv pov thawj hauv zos, peb yuav tsum tsim cov neeg siv.
Ntxiv nrog rau tej yam yooj yim xws li lub npe thiab tus password, ntawm no koj tuaj yeem, piv txwv li, txwv tsis pub tus neeg siv hloov tus password lossis, hloov pauv, yuam nws hloov tus password rau lwm zaus nws nkag mus.
Tom qab tag nrho cov tsim nyog cov neeg siv tau ntxiv lawm, mus rau lub Installation Packages tab, nyem + thiab tsim lub installer nws tus kheej, uas tus neeg ua hauj lwm tej thaj chaw deb yuav download tau rau installation.
Nyem +. Peb xaiv qhov chaw nyob thiab chaw nres nkoj ntawm cov neeg rau zaub mov uas tus neeg siv yuav txuas, thiab cov platforms uas peb xav tau los tsim cov pob teeb tsa.
Hauv qab no hauv lub qhov rai no koj tuaj yeem qhia meej cov neeg siv khoom teeb tsa rau Windows. Xaiv:
pib tus neeg siv khoom ntawm lub logon - tus neeg siv khoom VPN yuav raug ntxiv rau kev pib ntawm lub tshuab tej thaj chaw deb;
tsim duab icon - yuav tsim ib tus neeg siv VPN icon ntawm lub desktop;
server kev ruaj ntseg daim ntawv pov thawj validation β yuav validate tus neeg rau zaub mov daim ntawv pov thawj raws li kev twb kev txuas.
Kev teeb tsa server tiav.
Tam sim no cia peb rub tawm cov pob teeb tsa uas peb tau tsim hauv cov kauj ruam kawg mus rau cov chaw taws teeb PC. Thaum teeb tsa lub server, peb teev nws qhov chaw nyob sab nraud (185.148.83.16) thiab chaw nres nkoj (445). Nws yog rau qhov chaw nyob no uas peb yuav tsum mus rau hauv lub web browser. Hauv kuv qhov xwm txheej nws yog 185.148.83.16: 445.
Hauv qhov rai tso cai, koj yuav tsum nkag mus rau cov ntaub ntawv pov thawj ntawm tus neeg siv peb tau tsim ua ntej.
Tom qab kev tso cai, peb pom ib daim ntawv teev cov pob khoom tsim muaj rau rub tawm. Peb tau tsim ib qho xwb - peb yuav rub tawm nws.
Tshawb xyuas VPN tus neeg siv txheeb cais ntawm lub computer hauv zos.
Hauv Windows hais kom ua kab (ipconfig / tag nrho) peb pom tias ib qho ntxiv virtual adapter tau tshwm sim thiab muaj kev sib txuas nrog cov chaw taws teeb network, txhua yam ua haujlwm:
Thiab thaum kawg, kos los ntawm Edge Gateway console.
L2VPN
L2VPN yuav xav tau thaum koj xav tau los ua ke ntau thaj chaw
faib network rau hauv ib qho chaw tshaj tawm.
Qhov no tuaj yeem pab tau, piv txwv li, thaum tsiv lub tshuab virtual: thaum VM txav mus rau lwm qhov chaw nyob, lub tshuab yuav khaws nws qhov chaw nyob IP thiab yuav tsis poob kev sib txuas nrog lwm lub tshuab nyob hauv tib lub npe L2 nrog nws.
Hauv peb qhov chaw sim, peb yuav txuas ob qhov chaw rau ib leeg, cia peb hu lawv A thiab B, raws li peb muaj ob lub NSX thiab ob qhov sib txawv tsim kev sib txuas, khi rau sib txawv Edges. Tshuab A muaj qhov chaw nyob 10.10.10.250/24, tshuab B muaj qhov chaw nyob 10.10.10.2/24.
Hauv vCloud Tus Thawj Coj, mus rau Kev Tswj tab, mus rau VDC peb xav tau, mus rau Org VDC Networks tab thiab ntxiv ob lub network tshiab.
Peb xaiv hom kev xa tawm network thiab khi lub network no rau peb NSX. Kos lub Create as subinterface checkbox.
Yog li ntawd, peb yuav tsum muaj ob lub network. Hauv peb qhov piv txwv, lawv hu ua network-a thiab network-b nrog tib lub rooj vag teeb tsa thiab tib lub npog ntsej muag.
Tam sim no cia peb mus rau qhov chaw ntawm thawj NSX. Qhov no yuav yog NSX uas Network A txuas nrog. Nws yuav ua raws li lub server.
Rov qab mus rau NSx Edge interface / Mus rau VPN tab -> L2VPN. Peb pab L2VPN, xaiv tus neeg rau zaub mov kev khiav hauj lwm hom, thiab nyob rau hauv lub neeg rau zaub mov Ntiaj teb no chaw teev cov sab nraud IP chaw nyob ntawm NSX uas qhov chaw nres nkoj rau lub qhov yuav mloog. Los ntawm lub neej ntawd, lub qhov (socket) yuav qhib rau ntawm qhov chaw nres nkoj 443, tab sis qhov no tuaj yeem hloov pauv. Tsis txhob hnov ββββqab xaiv qhov chaw encryption rau lub qhov av yav tom ntej.
Mus rau Server Sites tab thiab ntxiv ib tus phooj ywg.
Peb tig rau tus phooj ywg, teeb lub npe, piav qhia, yog tias tsim nyog, teeb tsa tus username thiab password. Peb yuav xav tau cov ntaub ntawv no tom qab thaum teeb tsa tus neeg siv khoom.
Hauv Egress Optimization Gateway Chaw Nyob peb tau teeb tsa qhov chaw nyob qhov rooj. Qhov no yog qhov tsim nyog kom tsis txhob muaj qhov tsis sib haum xeeb ntawm IP chaw nyob, vim tias lub rooj vag ntawm peb cov tes hauj lwm muaj tib qhov chaw nyob. Tom qab ntawd nias lub pob SELECT SUB-INTERFACES.
Ntawm no peb xaiv qhov xav tau subinterface. Txuag cov chaw.