{"id":32126,"date":"2019-10-31T21:45:18","date_gmt":"2019-10-31T18:45:18","guid":{"rendered":"https:\/\/prohoster.info\/blog\/osobennosti-nastrojki-palo-alto-networks-ssl-vpn\/"},"modified":"2019-10-31T21:45:18","modified_gmt":"2019-10-31T18:45:18","slug":"osobennosti-nastrojki-palo-alto-networks-ssl-vpn","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/osobennosti-nastrojki-palo-alto-networks-ssl-vpn","title":{"rendered":"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/f1b7724dcec58c57688ca5020ebdbd96.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nPavar\u00ebsisht t\u00eb gjitha avantazheve t\u00eb firewalleve Palo Alto Networks, n\u00eb internetin rus nuk ka shum\u00eb materiale p\u00ebr konfigurimin e k\u00ebtyre pajisjeve, si dhe tekste q\u00eb p\u00ebrshkruajn\u00eb p\u00ebrvoj\u00ebn e tyre t\u00eb implementimit. Ne vendos\u00ebm t\u00eb p\u00ebrmbledhim materialet e grumbulluara nga ne gjat\u00eb pun\u00ebs me pajisjet e k\u00ebtij ofruesi dhe t\u00eb flasim p\u00ebr ve\u00e7orit\u00eb me t\u00eb cilat u p\u00ebrball\u00ebm gjat\u00eb realizimit t\u00eb projekteve t\u00eb ndryshme. <\/p>\n<p>P\u00ebr t\u00eb njohur Palo Alto Networks, n\u00eb k\u00ebt\u00eb artikull do t\u00eb shqyrtojm\u00eb konfigurimet e nevojshme p\u00ebr t\u00eb zgjidhur nj\u00eb nga detyrat m\u00eb t\u00eb zakonshme t\u00eb mbrojtjes s\u00eb rrjetit, - SSL VPN p\u00ebr akses t\u00eb larg\u00ebt. Gjithashtu do t\u00eb flasim p\u00ebr funksionalitetet ndihm\u00ebse p\u00ebr konfigurimin e p\u00ebrgjithsh\u00ebm t\u00eb firewalleve, identifikimin e p\u00ebrdoruesve, aplikacioneve dhe politikave t\u00eb siguris\u00eb. N\u00ebse tema do t\u00eb interesoj\u00eb lexuesit, m\u00eb von\u00eb do t\u00eb publikojm\u00eb materiale me analiza t\u00eb Site-to-Site <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/vpn\/\"   title=\"VPN\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"33\">VPN<\/a>, rrug\u00ebtimit dinamik dhe menaxhimit centralizuar p\u00ebrmes Panorama. <br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nFirewallet Palo Alto Networks p\u00ebrdorin nj\u00eb s\u00ebr\u00eb teknologjish inovative, duke p\u00ebrfshir\u00eb App-ID, User-ID, Content-ID. P\u00ebrdorimi i k\u00ebtij funksionaliteti siguron nj\u00eb nivel t\u00eb lart\u00eb sigurie. P\u00ebr shembull, p\u00ebrmes App-ID \u00ebsht\u00eb e mundur t\u00eb identifikosh trafikun e aplikacioneve n\u00eb baz\u00eb t\u00eb n\u00ebnshkrueseve, dekodimit dhe heuristik\u00ebs, pa marr\u00eb parasysh portin dhe protokollin e p\u00ebrdorur, p\u00ebrfshir\u00eb brenda tunelit SSL. User-ID lejon identifikimin e p\u00ebrdoruesve t\u00eb rrjetit p\u00ebrmes integrimit me LDAP. Content-ID ofron mund\u00ebsin\u00eb p\u00ebr t\u00eb skanuar trafikun dhe p\u00ebr t\u00eb identifikuar skedar\u00ebt dhe p\u00ebrmbajtjen e tyre. Mes funksioneve t\u00eb tjera t\u00eb firewalleve mund t\u00eb ve\u00e7ojm\u00eb mbrojtjen nga nd\u00ebrhyrjet, mbrojtjen nga dob\u00ebsit\u00eb dhe sulmet DoS, anti-spiunin e integruar, filtrimin e URL-ve, klasterizimin, menaxhimin centralizuar.<\/p>\n<p>P\u00ebr demonstrim, do t\u00eb p\u00ebrdorim nj\u00eb sken\u00eb t\u00eb izoluar, me nj\u00eb konfigurim identik me at\u00eb reale, p\u00ebrve\u00e7 emrave t\u00eb pajisjeve, emrit t\u00eb domain-it AD dhe adresave IP. N\u00eb realitet, gjith\u00e7ka \u00ebsht\u00eb m\u00eb e komplikuar - mund t\u00eb ket\u00eb shum\u00eb filiale. N\u00eb kufijt\u00eb e vendeve qendrore n\u00eb k\u00ebt\u00eb rast, do t\u00eb vendoset nj\u00eb klaster n\u00eb vend t\u00eb nj\u00eb firewalle, gjithashtu mund t\u00eb nevojitet rrug\u00ebtim dinamik.<\/p>\n<p>N\u00eb sken\u00eb p\u00ebrdoret <b>PAN-OS 7.1.9<\/b>. Si n\u00eb nj\u00eb konfigurim tipik shqyrtojm\u00eb rrjetin me nj\u00eb mur zjarri Palo Alto Networks n\u00eb kufi. Mur zjarri ofron akses t\u00eb larg\u00ebt SSL VPN n\u00eb selin\u00eb qendrore. Si nj\u00eb databaz\u00eb p\u00ebrdoruesish do t\u00eb p\u00ebrdoret domeni Active Directory (figura 1).<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/b3db829ea3d1361cb2106bc70cad8ef0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 1 \u2013 Skema strukturore e rrjetit<\/i><\/p>\n<p>Hapat e konfigurimit:<\/p>\n<ol>\n<li>Parakonfigurimi i pajisjes. Caktimi i emrit, <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/lir\/ipv4\/\"   title=\"Adresa IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"624\">Adresa IP<\/a> menaxhimi, rrug\u00ebve statike, llogarive t\u00eb administrator\u00ebve, profileve t\u00eb menaxhimit<\/li>\n<li>Instalimi i licencave, konfigurimi dhe instalimi i p\u00ebrdit\u00ebsimeve<\/li>\n<li>Konfigurimi i zona e siguris\u00eb, nd\u00ebrfaqeve rrjet\u00ebsore, politikave t\u00eb trafikimit, p\u00ebrkthimit t\u00eb adresave<\/li>\n<li>Konfigurimi i profilit t\u00eb autentifikimit LDAP dhe funksionit t\u00eb Identifikimit t\u00eb P\u00ebrdoruesve<\/li>\n<li>Konfigurimi i SSL VPN<\/li>\n<\/ol>\n<p><\/p>\n<h4>1. Parakonfigurimi<\/h4>\n<p>\nInstrumenti kryesor p\u00ebr konfigurimin e murit t\u00eb zjarrit Palo Alto Networks \u00ebsht\u00eb nd\u00ebrfaqja web, gjithashtu \u00ebsht\u00eb e mundur menaxhimi p\u00ebrmes CLI. Si parazgjedhje, nd\u00ebrfaqes s\u00eb menaxhimit i \u00ebsht\u00eb caktuar adresa IP 192.168.1.1\/24, login: admin, fjal\u00ebkalimi: admin. <\/p>\n<p>Adresa mund t\u00eb ndryshohet duke u lidhur n\u00eb nd\u00ebrfaqen web nga e nj\u00ebjta rrjet, ose p\u00ebrmes komand\u00ebs <b>set deviceconfig system ip-address  netmask<\/b>. Ajo ekzekutohet n\u00eb modalitetin e konfigurimit. P\u00ebr t\u00eb kaluar n\u00eb modalitetin e konfigurimit p\u00ebrdoret komandja <b>konfiguro.<\/b>. T\u00eb gjitha ndryshimet n\u00eb murin e zjarrit ndodhin vet\u00ebm pas konfirmimit t\u00eb konfigurimeve me komand\u00ebn <b>commit<\/b>, si n\u00eb modalitetin e komand\u00ebs ashtu edhe n\u00eb nd\u00ebrfaqen web.<\/p>\n<p>P\u00ebr t\u00eb ndryshuar konfigurimet n\u00eb nd\u00ebrfaqen web p\u00ebrdoret seksioni <b>Device -&gt; General Settings dhe Device -&gt; Management Interface Settings.<\/b> Emri, banner\u00ebt, zona time dhe konfigurime t\u00eb tjera mund t\u00eb caktohen n\u00eb seksionin General Settings (fig. 2).<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/6e46d795deed506a57fe1375ca90ad25.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 2 \u2013 Parametrat e nd\u00ebrfaqes s\u00eb menaxhimit<\/i><\/p>\n<p>N\u00eb rast se aplikohet nj\u00eb mur zjarri virtual n\u00eb mjedisin ESXi, n\u00eb seksionin General Settings duhet t\u00eb aktivizohet p\u00ebrdorimi i adres\u00ebs MAC t\u00eb caktuar nga hipervizori, ose t\u00eb konfigurohen n\u00eb hipervizor adresat MAC t\u00eb caktuara n\u00eb nd\u00ebrfaqet e murit t\u00eb zjarrit, ose t\u00eb ndryshohen parametrat e switch-ave virtual p\u00ebr t\u00eb lejuar ndryshime t\u00eb adresave MAC. N\u00eb t\u00eb kund\u00ebrt, trafiku nuk do t\u00eb kaloj\u00eb.<\/p>\n<p>Nd\u00ebrfaqja e menaxhimit konfigurohet ve\u00e7mas dhe nuk shfaqet n\u00eb list\u00ebn e nd\u00ebrfaqeve rrjet\u00ebsore. N\u00eb seksionin <b>Management Interface Settings<\/b> caktohet porti i parazgjedhur p\u00ebr nd\u00ebrfaqen e menaxhimit. Rrug\u00ebt e tjera statike konfigurohen n\u00eb seksionin e router\u00ebve virtual\u00eb, p\u00ebr k\u00ebt\u00eb do t\u00eb shkruhet m\u00eb posht\u00eb. <\/p>\n<p>P\u00ebr t\u00eb lejuar qasje n\u00eb pajisje p\u00ebrmes nd\u00ebrfaqeve t\u00eb tjera, duhet t\u00eb krijoni nj\u00eb profil menaxhimi <b>Profili i Menaxhimit<\/b> n\u00eb seksionin <b>Network -&gt; Profili i Rrjetit -&gt; Menaxhimi i Nd\u00ebrfaqes<\/b> dhe ta caktoni at\u00eb n\u00eb nd\u00ebrfaqen p\u00ebrkat\u00ebse. <\/p>\n<p>M\u00eb pas, duhet t\u00eb konfiguroni DNS dhe NTP n\u00eb seksionin <b>Device -&gt; Sh\u00ebrbimet<\/b> p\u00ebr t\u00eb marr\u00eb p\u00ebrdit\u00ebsime dhe p\u00ebr t\u00eb siguruar koh\u00ebn e sakt\u00eb (fig. 3). Nga e gjitha, gjith\u00eb trafiku i krijuar nga firewalle p\u00ebrdor si adres\u00eb IP burimi adres\u00ebn IP t\u00eb nd\u00ebrfaqes s\u00eb menaxhimit. Nj\u00eb nd\u00ebrfaqe tjet\u00ebr mund t\u00eb caktosh p\u00ebr \u00e7do sh\u00ebrbim t\u00eb ve\u00e7ant\u00eb n\u00eb seksionin <b>Konfigurimi i Rrug\u00ebve t\u00eb Sh\u00ebrbimeve<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/7f13e6631daf8924405216fa07f4e39b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 3 \u2013 Parametrat e sh\u00ebrbimeve DNS, NTP dhe rrug\u00ebt sistemore<\/i><\/p>\n<h4>2. Instalimi i licencave, konfigurimi dhe instalimi i p\u00ebrdit\u00ebsimeve<\/h4>\n<p>\nP\u00ebr funksionimin e plot\u00eb t\u00eb t\u00eb gjitha funksioneve t\u00eb firewalle duhet t\u00eb instaloni nj\u00eb licenc\u00eb. Mund t\u00eb p\u00ebrdorni nj\u00eb licenc\u00eb provuese, duke e k\u00ebrkuar at\u00eb nga partner\u00ebt e Palo Alto Networks. Periudha e saj \u00ebsht\u00eb 30 dit\u00eb. Licenca aktivizohet ose p\u00ebrmes nj\u00eb skedari ose me Kod Auth. Licencat konfigurohen n\u00eb seksionin <b>Device -&gt; Licencat<\/b> (fig. 4).<br \/>\nPasi t\u00eb keni instaluar licenc\u00ebn, duhet t\u00eb konfiguroni instalimin e p\u00ebrdit\u00ebsimeve n\u00eb seksionin <b>Device -&gt; P\u00ebrdit\u00ebsimet Dynamike<\/b>.<br \/>\nN\u00eb seksionin <b>Device -&gt; Softueri<\/b> mund t\u00eb shkarkoni dhe instaloni versione t\u00eb reja t\u00eb PAN-OS.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/0e3790b5f2234c563d2a46a47f37602f.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 4 \u2013 Paneli i Kontrollit t\u00eb Licencave<\/i><\/p>\n<h4>3. Konfigurimi i zonave t\u00eb siguris\u00eb, nd\u00ebrfaqeve t\u00eb rrjetit, politikave t\u00eb trafikut, p\u00ebrkthimit t\u00eb adresave<\/h4>\n<p>\nFirewallet e Palo Alto Networks aplikojn\u00eb logjik\u00ebn e zonave gjat\u00eb konfigurimit t\u00eb rregullave t\u00eb rrjetit. Nd\u00ebrfaqet e rrjetit caktohen n\u00eb nj\u00eb zon\u00eb t\u00eb caktuar, dhe ajo p\u00ebrdoret n\u00eb rregullat e trafikut. Ky qasje lejon q\u00eb n\u00eb t\u00eb ardhmen, gjat\u00eb ndryshimeve t\u00eb konfigurimeve t\u00eb nd\u00ebrfaqeve, t\u00eb mos ndryshosh rregullat e trafikut, por n\u00eb vend t\u00eb k\u00ebsaj t\u00eb rip\u00ebrcaktosh nd\u00ebrfaqet e nevojshme n\u00eb zonat p\u00ebrkat\u00ebse. N\u00eb parazgjedhje, trafiku brenda zon\u00ebs \u00ebsht\u00eb i lejuar, trafiku midis zonave \u00ebsht\u00eb i ndaluar, p\u00ebr k\u00ebt\u00eb p\u00ebrgjigjen rregullat e parazgjedhura <b>intrazone-default<\/b> dhe <b>interzone-default<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/16a1d20529e7ab3b31bde5a90a20dec0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 5 \u2013 Zonat e Siguris\u00eb<\/i><\/p>\n<p>N\u00eb k\u00ebt\u00eb shembull, nd\u00ebrfaqja n\u00eb rrjetin e brendsh\u00ebm \u00ebsht\u00eb caktuar n\u00eb zon\u00ebn <b>internal<\/b>, nd\u00ebrsa nd\u00ebrfaqja e orientuar drejt Internetit \u00ebsht\u00eb caktuar n\u00eb zon\u00ebn <b>external<\/b>. P\u00ebr SSL VPN, \u00ebsht\u00eb krijuar nj\u00eb nd\u00ebrfaqe tuneli, e caktuar n\u00eb zon\u00ebn <b>vpn <\/b>(fig. 5).<\/p>\n<p>Nd\u00ebrfaqet e rrjetit t\u00eb firewalleve Palo Alto Networks mund t\u00eb funksionojn\u00eb n\u00eb pes\u00eb m\u00ebnyra t\u00eb ndryshme:<\/p>\n<ul>\n<li><b>Tap <\/b>\u2013 p\u00ebrdoret p\u00ebr mbledhjen e trafikut me q\u00ebllim monitorimin dhe analizimin<\/li>\n<li><b>HA <\/b>\u2013 p\u00ebrdoret p\u00ebr funksionimin e klasterit<\/li>\n<li><b>Virtual Wire<\/b> \u2013 n\u00eb k\u00ebt\u00eb mod, Palo Alto Networks bashkon dy interfereca dhe kalon n\u00eb m\u00ebnyr\u00eb transparente trafikun midis tyre, pa ndryshuar adresat MAC dhe IP.<\/li>\n<li><b>Layer2<\/b> \u2013 moda e switch-it<\/li>\n<li><b>Layer3<\/b> \u2013 moda e router-it<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/692a1a767d50092b29e863da13895aa3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Fig 6 \u2013 Konfigurimi i mod\u00ebs s\u00eb funksionimit t\u00eb interferec\u00ebs<\/i><\/p>\n<p>N\u00eb k\u00ebt\u00eb shembull do t\u00eb p\u00ebrdoret moda Layer3 (fig. 6). N\u00eb parametrat e interferec\u00ebs s\u00eb rrjetit ceket adresa IP, moda e funksionimit dhe zona p\u00ebrkat\u00ebse e siguris\u00eb. P\u00ebrve\u00e7 mod\u00ebs s\u00eb funksionimit t\u00eb interferec\u00ebs, ajo duhet t\u00eb caktohet n\u00eb routerin virtual Virtual Router, q\u00eb \u00ebsht\u00eb ekuivalenti i instanc\u00ebs VRF n\u00eb Palo Alto Networks. Router\u00ebt virtual\u00eb jan\u00eb t\u00eb izoluar nga nj\u00ebri-tjetri dhe kan\u00eb tabelat e tyre t\u00eb routing-ut dhe konfigurimet e protokolleve t\u00eb rrjeteve.<\/p>\n<p>N\u00eb konfigurimet e routerit virtual ceken rrug\u00ebt statike dhe konfigurimet e protokolleve t\u00eb routing-ut. N\u00eb k\u00ebt\u00eb shembull \u00ebsht\u00eb krijuar vet\u00ebm rruga baze p\u00ebr qasje n\u00eb rrjetet e jashtme (fig. 7).<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/a9a51f51c84d5fd47762a4167c7b7e2c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Fig 7 \u2013 Konfigurimi i routerit virtual<\/i><\/p>\n<p>Hapi tjet\u00ebr i konfigurimit \u2013 politikat e trafikut, seksioni <b>Policies -&gt; Security<\/b>. Shembulli i konfigurimit shikohet n\u00eb fig. 8. Logjika e funksionimit t\u00eb rregullave \u00ebsht\u00eb e nj\u00ebjt\u00eb si p\u00ebr t\u00eb gjitha firewalle. Rregullat kontrollohen nga lart posht\u00eb, deri n\u00eb p\u00ebrputhjen e par\u00eb. P\u00ebrshkrimi i shkurt\u00ebr i rregullave:<\/p>\n<p>1. SSL VPN Access to Web Portal. Lejon qasjen n\u00eb portalin web p\u00ebr autentifikimin e lidhjeve t\u00eb larg\u00ebta.<br \/>\n2. VPN traffic \u2013 lejon trafikun midis lidhjeve t\u00eb larg\u00ebta dhe zyr\u00ebs kryesore.<br \/>\n3. Basic Internet \u2013 lejon aplikacione t\u00eb tilla si dns, ping, traceroute, ntp. Firewall-i lejon aplikacione bazuar n\u00eb n\u00ebnshkrime, dekodim dhe heuristik\u00eb dhe jo bazuar n\u00eb numrat e porteve dhe protokolleve, prandaj n\u00eb seksionin Service \u00ebsht\u00eb caktuar application-default. Porta\/protokolli i default p\u00ebr k\u00ebt\u00eb aplikacion.<br \/>\n4. Web Access \u2013 lejon qasje n\u00eb internet p\u00ebrmes protokolleve HTTP dhe HTTPS pa kontroll t\u00eb aplikacioneve.<br \/>\n5,6. Rregulla t\u00eb default p\u00ebr trafikun tjet\u00ebr.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/2aea65b9e482df4dcee3294a59203165.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Fig 8 \u2014 Shembulli i konfigurimit t\u00eb rregullave t\u00eb rrjetit<\/i><\/p>\n<p>P\u00ebr konfigurimin e NAT p\u00ebrdoret seksioni <b>Policies -&gt; NAT<\/b>. Shembulli i konfigurimit t\u00eb NAT shikohet n\u00eb fig. 9.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/c059a4f84b981f3205f1a4b33c5344b3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Fig 9 \u2013 Shembulli i konfigurimit t\u00eb NAT<\/i><\/p>\n<p>P\u00ebr \u00e7do trafik nga internal n\u00eb external mund t\u00eb ndryshohet adresa e burimit n\u00eb adres\u00ebn IP t\u00eb jashtme t\u00eb firewall-it dhe t\u00eb p\u00ebrdoret adresa dinamike e portit (PAT).<\/p>\n<p><b>4. Konfigurimi i profilit t\u00eb autentifikimit LDAP dhe funksionit t\u00eb Identifikimit t\u00eb P\u00ebrdoruesit<\/b><br \/>\nPara t\u00eb lidhni p\u00ebrdoruesit p\u00ebrmes SSL-VPN, duhet t\u00eb konfiguroni mekanizmin e autentikimit. N\u00eb k\u00ebt\u00eb shembull, autentikimi do t\u00eb b\u00ebhet n\u00eb kontrolluesin e domenit Active Directory p\u00ebrmes nd\u00ebrfaqes s\u00eb uebit Palo Alto Networks.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/3d766a14f1e01ba051c2aa171c209156.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 10 \u2013 Profili LDAP<\/i><\/p>\n<p>P\u00ebr t\u00eb funksionuar autentikimi, duhet t\u00eb konfigurohet <b>Profili LDAP<\/b> dhe <b>Profili i Autentikimit<\/b>. N\u00eb seksionin <b>Device -&gt; Server Profiles -&gt; LDAP<\/b> (fig. 10) duhet t\u00eb specifikoni adres\u00ebn IP dhe portin e kontrolluesit t\u00eb domenit, llojin LDAP dhe llogarin\u00eb e p\u00ebrdoruesit q\u00eb \u00ebsht\u00eb pjes\u00eb e grupeve <b>Server Operators<\/b>, <b>Event Log Readers<\/b>, <b>Distributed COM Users<\/b>. Pastaj n\u00eb seksionin <b>Device -&gt; Authentication Profile<\/b> krijoni nj\u00eb profil autentikimi (fig. 11), sh\u00ebnoni profilin q\u00eb krijuat m\u00eb par\u00eb <b>Profili LDAP<\/b> dhe n\u00eb tabin Advanced specifikoni grupin e p\u00ebrdoruesve (fig. 12), t\u00eb cil\u00ebve u lejohet aksesin e larg\u00ebt. \u00cbsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb theksohet n\u00eb profil parametrin <b>User Domain<\/b>, p\u00ebrndryshe autorizimi i bazuar n\u00eb grupe nuk do t\u00eb funksionoj\u00eb. N\u00eb fush\u00eb duhet t\u00eb jepet emri NetBIOS i domenit.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/465351361288da9fd2db00afc43c2ddf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 11 \u2013 Profili i autentikimit<\/i><\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/43983491298482daad6c39a5369137c1.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 12 \u2013 Zgjedhja e grupit AD<\/i><\/p>\n<p>Hapi i ardhsh\u00ebm \u2013 konfigurimi i <b>Device -&gt; User Identification<\/b>. K\u00ebtu duhet t\u00eb specifikoni adres\u00ebn IP t\u00eb kontrolluesit t\u00eb domenit, kredencialet p\u00ebr lidhje, si dhe t\u00eb konfiguroni parametrat <b>Enable Security Log<\/b>, <b>Enable Session<\/b>, <b>Enable Probing<\/b> (fig. 13). N\u00eb seksionin <b>Group Mapping<\/b> (fig. 14) duhet t\u00eb sh\u00ebnohen parametrat e identifikimit t\u00eb objekteve n\u00eb LDAP dhe lista e grupeve q\u00eb do t\u00eb p\u00ebrdoren p\u00ebr autorizim. Po ashtu si n\u00eb Profilin e Autentikimit, k\u00ebtu duhet t\u00eb caktoni parametrin User Domain.<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/ba466e3187bc01434c4afb9469434bc4.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 13 \u2013 Parametrat e User Mapping<\/i><\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/3c43d0156849e6f3f99b92818b76445e.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 14 \u2013 Parametrat e Group Mapping<\/i><\/p>\n<p>Hapi i fundit n\u00eb k\u00ebt\u00eb etap\u00eb do t\u00eb jet\u00eb krijimi i nj\u00eb zone VPN dhe nj\u00eb nd\u00ebrfaqe p\u00ebr k\u00ebt\u00eb zon\u00eb. N\u00eb nd\u00ebrfaqe duhet t\u00eb aktivizohet parametri <b>Enable User Identification<\/b> (fig. 15).<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/45d28b957c2d889cb51cd3fb1096896d.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 15 \u2013 Konfigurimi i zoneve VPN<\/i><\/p>\n<h4>5. Konfigurimi i SSL VPN<\/h4>\n<p>\nPara t'u lidhur me SSL VPN, p\u00ebrdoruesi i larg\u00ebt duhet t\u00eb hyj\u00eb n\u00eb portalin e internetit, t\u00eb kaloj\u00eb autentikimin dhe t\u00eb shkarkoj\u00eb klientin Global Protect. M\u00eb pas, ky klient do t\u00eb k\u00ebrkoj\u00eb kredencialet dhe do t\u00eb lidh\u00eb me rrjetin e korporat\u00ebs. Portali i internetit funksionon n\u00eb m\u00ebnyr\u00eb https dhe, p\u00ebr pasoj\u00eb, \u00ebsht\u00eb e nevojshme q\u00eb t\u00eb vendoset nj\u00eb certifikat\u00eb p\u00ebr t\u00eb. P\u00ebrdorni nj\u00eb certifikat\u00eb publike, n\u00ebse ka nj\u00eb mund\u00ebsi t\u00eb till\u00eb. K\u00ebshtu, p\u00ebrdoruesit nuk do t'i jepet nj\u00eb njoftim mbi pamjaftueshm\u00ebrin\u00eb e certifikat\u00ebs n\u00eb faqen e internetit. N\u00ebse nuk ka mund\u00ebsi p\u00ebr t\u00eb p\u00ebrdorur nj\u00eb certifikat\u00eb publike, at\u00ebher\u00eb \u00ebsht\u00eb e nevojshme q\u00eb t\u00eb l\u00ebshohet nj\u00eb certifikat\u00eb e vetme, e cila do t\u00eb aplikohet n\u00eb faqen e internetit p\u00ebr https. Ajo mund t\u00eb jet\u00eb e vet\u00eb-n\u00ebnshkruar ose e l\u00ebshuar p\u00ebrmes nj\u00eb qendre lokale t\u00eb certifikimit. Kompjuteri i larg\u00ebt duhet t\u00eb ket\u00eb certifikat\u00ebn rr\u00ebnj\u00eb ose t\u00eb vet\u00eb-n\u00ebnshkruar n\u00eb list\u00ebn e qendrave t\u00eb besuara rr\u00ebnj\u00ebsore, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb mos i jepet p\u00ebrdoruesit nj\u00eb gabim gjat\u00eb lidhjes me portalin e internetit. N\u00eb k\u00ebt\u00eb shembull do t\u00eb p\u00ebrdoret nj\u00eb certifikat\u00eb e l\u00ebshuar p\u00ebrmes sh\u00ebrbimeve t\u00eb certifikimit t\u00eb Active Directory.<\/p>\n<p>P\u00ebr t\u00eb l\u00ebshuar nj\u00eb certifikat\u00eb, \u00ebsht\u00eb e nevojshme t\u00eb krijohet nj\u00eb k\u00ebrkes\u00eb p\u00ebr certifikat\u00ebn n\u00eb seksionin<b> Device -&gt; Certificate Management -&gt; Certificates -&gt; Generate<\/b>. N\u00eb k\u00ebrkes\u00eb sh\u00ebnojm\u00eb emrin e certifikat\u00ebs dhe IP-n\u00eb ose FQDN-n\u00eb e portalit t\u00eb internetit (fig. 16). Pas krijimit t\u00eb k\u00ebrkes\u00ebs, shkarkojm\u00eb <b>.csr<\/b> skedarin dhe kopjojm\u00eb p\u00ebrmbajtjen e tij n\u00eb fush\u00ebn e k\u00ebrkes\u00ebs p\u00ebr certifikat\u00ebn n\u00eb formularin e internetit AD CS Web Enrollment. N\u00eb var\u00ebsi t\u00eb rregullimeve t\u00eb qendr\u00ebs s\u00eb certifikimit, k\u00ebrkesa p\u00ebr certifikat\u00ebn duhet t\u00eb miratohet dhe t\u00eb shkarkohet certifikata e l\u00ebshuar n\u00eb formatin <b>Base64 Encoded Certificate<\/b>. P\u00ebr m\u00eb tep\u00ebr, \u00ebsht\u00eb e nevojshme t\u00eb shkarkohet certifikata rr\u00ebnj\u00eb e qendr\u00ebs s\u00eb certifikimit. M\u00eb pas, \u00ebsht\u00eb e nevojshme t\u00eb importohen t\u00eb dyja certifikat\u00ebt n\u00eb zjarrin e rrjetit. Gjat\u00eb importimit t\u00eb certifikat\u00ebs p\u00ebr portalin e internetit, \u00ebsht\u00eb e nevojshme t\u00eb ve\u00e7oni k\u00ebrkes\u00ebn n\u00eb statusin pending dhe t\u00eb klikoni import. Emri i certifikat\u00ebs duhet t\u00eb p\u00ebrputhet me emrin q\u00eb u sh\u00ebnua m\u00eb par\u00eb n\u00eb k\u00ebrkes\u00eb. Emri i certifikat\u00ebs rr\u00ebnj\u00eb mund t\u00eb p\u00ebrcaktohet n\u00eb m\u00ebnyr\u00eb t\u00eb rast\u00ebsishme. Pas importimit t\u00eb certifikat\u00ebs, \u00ebsht\u00eb e nevojshme t\u00eb krijohet <b>SSL\/TLS Service Profile<\/b> n\u00eb seksionin <b>Device -&gt; Certificate Management<\/b>. N\u00eb profil vendosim certifikat\u00ebn e importuar m\u00eb par\u00eb. <\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/b3a7e2c99b0e4b7fdc63e12942dd03ba.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Figura 16 \u2013 K\u00ebrkesa p\u00ebr certifikat\u00ebn<\/i><\/p>\n<p>Hapi tjet\u00ebr \u2013 konfigurimi i objekteve <b>Global Protect Gateway<\/b> dhe <b>Global Protect Portal<\/b> n\u00eb seksionin <b>Network -&gt; Global Protect<\/b>. N\u00eb cil\u00ebsimet <b>Global Protect Gateway<\/b> sh\u00ebnojm\u00eb adres\u00ebn IP t\u00eb jashtme t\u00eb zjarrin t\u00eb rrjetit, si dhe t\u00eb krijuarat m\u00eb par\u00eb <b>SSL Profile<\/b>, <b>Profili i Autentikimit<\/b>, nd\u00ebrfaqja e tunelit dhe konfigurimet IP t\u00eb klientit. Duhet t\u00eb caktosh nj\u00eb pool adresash IP, nga e cila do t'i caktohet nj\u00eb adres\u00eb klientit, dhe Rruga e Qasjes \u2013 n\u00ebnrrjetet, t\u00eb cilave do t\u00eb ket\u00eb \u043c\u0430\u0440\u0448\u0440\u0443t klienti. N\u00ebse q\u00ebllimi \u00ebsht\u00eb q\u00eb t\u00eb kaloj\u00eb gjith\u00eb trafikun e p\u00ebrdoruesit p\u00ebrmes nj\u00eb firewalle, duhet t\u00eb p\u00ebrcaktosh n\u00ebnrrjetin 0.0.0.0\/0 (Fig. 17).<\/p>\n<p><img decoding=\"async\" alt=\"Ve\u00e7orit\u00eb e konfigurimit t\u00eb Palo Alto Networks: SSL VPN\" src=\"\/wp-content\/uploads\/2019\/04\/6594b57408f40ee13b669219c8bb6b45.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Fig 17 \u2013 Konfigurimi i pool-it t\u00eb adresave IP dhe rrug\u00ebve<\/i><\/p>\n<p>M\u00eb pas \u00ebsht\u00eb e nevojshme t\u00eb konfigurohet <b>Global Protect Portal<\/b>. P\u00ebrcaktojme adres\u00ebn IP t\u00eb firewall-it, <b>SSL Profile<\/b> dhe <b>Profili i Autentikimit<\/b> dhe list\u00ebn e adresave IP t\u00eb jashtme t\u00eb firewalleve, t\u00eb cilat do t\u00eb lidhen me klientin. N\u00ebse ka disa firewalle, mund t\u00eb caktohet nj\u00eb prioritet p\u00ebr \u00e7do nj\u00eb, sipas t\u00eb cilit p\u00ebrdoruesit do t\u00eb zgjedhin firewall-in p\u00ebr tu lidhur.<\/p>\n<p>N\u00eb seksionin <b>Device -&gt; GlobalProtect Client<\/b> duhet t\u00eb shkarkosh paket\u00ebn e klientit VPN nga serverat Palo Alto Networks dhe ta aktivizosh at\u00eb. P\u00ebr t'u lidhur, p\u00ebrdoruesi duhet t\u00eb hyj\u00eb n\u00eb uebfaqen e portalit, ku do t'i ofrohet mund\u00ebsia p\u00ebr t\u00eb shkarkuar <b>GlobalProtect Client<\/b>. Pasi t\u00eb shkarkohet dhe t\u00eb instalohet, do t\u00eb jet\u00eb e mundur t\u00eb jepen kreditit e tua dhe t\u00eb lidhen me rrjetin korporativ p\u00ebrmes SSL VPN.<\/p>\n<h4>P\u00ebrfundim<\/h4>\n<p>\nK\u00ebshtu, pjesa e konfigurimit t\u00eb Palo Alto Networks ka p\u00ebrfunduar. Shpresojm\u00eb q\u00eb informacioni ishte i dobish\u00ebm, dhe lexuesi pati nj\u00eb pasqyr\u00eb mbi teknologjit\u00eb e p\u00ebrdorura n\u00eb Palo Alto Networks. N\u00ebse keni pyetje n\u00eb lidhje me konfigurimin dhe d\u00ebshira p\u00ebr tema t\u00eb artikujve t\u00eb ardhsh\u00ebm - shkruani ato n\u00eb komentet, do t\u00eb jemi t\u00eb lumtur t'u p\u00ebrgjigjemi.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/crosstech\/blog\/443726\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0432\u0441\u0435 \u043f\u0440\u0435\u0438\u043c\u0443\u0449\u0435\u0441\u0442\u0432\u0430 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432 Palo Alto Networks, \u0432 \u0440\u0443\u043d\u0435\u0442\u0435 \u043d\u0435 \u0442\u0430\u043a \u043c\u043d\u043e\u0433\u043e \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u043e\u0432 \u043f\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 \u044d\u0442\u0438\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0442\u0435\u043a\u0441\u0442\u043e\u0432, \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u043e\u043f\u044b\u0442 \u0438\u0445 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u044f. \u041c\u044b \u0440\u0435\u0448\u0438\u043b\u0438 \u043e\u0431\u043e\u0431\u0449\u0438\u0442\u044c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043d\u0430\u043a\u043e\u043f\u043b\u0435\u043d\u043d\u044b\u0435 \u0443 \u043d\u0430\u0441 \u0437\u0430 \u0432\u0440\u0435\u043c\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u044d\u0442\u043e\u0433\u043e \u0432\u0435\u043d\u0434\u043e\u0440\u0430 \u0438 \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e\u0431 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u0445, \u0441 \u043a\u043e\u0442\u043e\u0440\u044b\u043c\u0438 \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0432 \u0445\u043e\u0434\u0435 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432. \u0414\u043b\u044f \u0437\u043d\u0430\u043a\u043e\u043c\u0441\u0442\u0432\u0430 \u0441 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23965,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-32126","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0432\u0441\u0435 \u043f\u0440\u0435\u0438\u043c\u0443\u0449\u0435\u0441\u0442\u0432\u0430 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/osobennosti-nastrojki-palo-alto-networks-ssl-vpn\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 Palo Alto Networks: SSL VPN | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0432\u0441\u0435 \u043f\u0440\u0435\u0438\u043c\u0443\u0449\u0435\u0441\u0442\u0432\u0430 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/osobennosti-nastrojki-palo-alto-networks-ssl-vpn\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:45:18+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:45:18+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Karakteristikat e konfigurimit t\u00eb Palo Alto Networks: SSL VPN | ProHoster","description":"Megjith\u00ebse t\u00eb gjitha avantazhet e firewalleve.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/osobennosti-nastrojki-palo-alto-networks-ssl-vpn","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 Palo Alto Networks: SSL VPN | ProHoster","og:description":"\u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0432\u0441\u0435 \u043f\u0440\u0435\u0438\u043c\u0443\u0449\u0435\u0441\u0442\u0432\u0430 \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/osobennosti-nastrojki-palo-alto-networks-ssl-vpn","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:45:18+00:00","article:modified_time":"2019-10-31T18:45:18+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32126","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 20:27:18","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:04:40","updated":"2026-02-08 20:27:18","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=32126"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32126\/revisions"}],"predecessor-version":[{"id":157815,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32126\/revisions\/157815"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/23965"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=32126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=32126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=32126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}