{"id":78242,"date":"2020-04-18T01:42:36","date_gmt":"2020-04-17T23:42:36","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa"},"modified":"2020-04-18T01:42:36","modified_gmt":"2020-04-17T23:42:36","slug":"realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa","title":{"rendered":"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Duke vazhduar serin\u00eb e artikujve mbi tem\u00ebn e organizimit <strong>VPN p\u00ebr Qasje t\u00eb Larg\u00ebt<\/strong> t\u00eb aksesit, nuk mund t\u00eb mos ndaj nj\u00eb p\u00ebrvoj\u00eb interesante n\u00eb implementimin <strong>e nj\u00eb konfiguracioni VPN t\u00eb mbrojtur fort<\/strong>. Nj\u00eb detyr\u00eb jo e thjesht\u00eb m\u00eb dha nj\u00eb klient (kan\u00eb imagjinat\u00eb n\u00eb fshatrat Ruse), por Challenge Accepted dhe u realizua kreativisht. Si rezultat, u krijua nj\u00eb koncept interesant me karakteristikat e m\u00ebposhtme:<\/p>\n<p><\/p>\n<ol>\n<li>Disa faktor\u00eb mbrojt\u00ebs nga z\u00ebvend\u00ebsimi i pajisjes p\u00ebrfundimtare (me lidhje t\u00eb fort\u00eb me p\u00ebrdoruesin);\n<ul>\n<li>Vler\u00ebsimi i p\u00ebrputhshm\u00ebris\u00eb s\u00eb PC-s\u00eb s\u00eb p\u00ebrdoruesit me UDID e caktuar t\u00eb PC-s\u00eb t\u00eb lejuar n\u00eb baz\u00ebn e autentifikimit; <\/li>\n<li>Me MFA, q\u00eb p\u00ebrdor UDID t\u00eb PC-s\u00eb nga certifikata p\u00ebr autentifikim t\u00eb dyt\u00eb p\u00ebrmes Cisco DUO <em>(Mund t\u00eb lidhni \u00e7do SAML\/RADIUS t\u00eb p\u00ebrputhsh\u00ebm)<\/em>; <\/li>\n<\/ul>\n<\/li>\n<li>Autentifikim shum\u00ebfaktor\u00ebsh: \n<ul>\n<li>Certifikata e p\u00ebrdoruesit me verifikimin e fushave dhe autentifikimin e dyt\u00eb p\u00ebrmes nj\u00eb prej tyre;<\/li>\n<li>Identifikimi (i pandryshuesh\u00ebm, i marra nga certifikata) dhe fjal\u00ebkalimi;<\/li>\n<\/ul>\n<\/li>\n<li>Vler\u00ebsimi i gjendjes s\u00eb hostit q\u00eb po lidhet (Posture)<\/li>\n<\/ol>\n<p><\/p>\n<p><strong>Komponent\u00ebt e p\u00ebrdorur t\u00eb zgjidhjes:<\/strong><\/p>\n<p><\/p>\n<ul>\n<li>Cisco ASA (Porta VPN);<\/li>\n<li>Cisco ISE (Autentifikim \/ Autorizim \/ Aktivitet, Vler\u00ebsimi i Gjendjes, CA);<\/li>\n<li>Cisco DUO (Autentifikimi shum\u00ebfaktor\u00ebsh) <em>(Mund t\u00eb lidhni \u00e7do SAML\/RADIUS t\u00eb p\u00ebrputhsh\u00ebm)<\/em>;<\/li>\n<li>Cisco AnyConnect (Agjenti multifunksional p\u00ebr stacionet e pun\u00ebs dhe sistemet operative mobile);<\/li>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p><strong>T\u00eb fillojm\u00eb me k\u00ebrkesat e klientit:<\/strong><\/p>\n<p><\/p>\n<ol>\n<li>P\u00ebrdoruesi duhet, me autentifikimin e tij Login\/Fjal\u00ebkalim, t\u00eb ket\u00eb mund\u00ebsin\u00eb t\u00eb shkarkoj\u00eb klientin AnyConnect nga VPN gateway, t\u00eb gjitha modul\u00ebt e nevojsh\u00ebm AnyConnect duhet t\u00eb instalohen automatikisht sipas politik\u00ebs s\u00eb p\u00ebrdoruesit;<\/li>\n<li>P\u00ebrdoruesi duhet t\u00eb ket\u00eb mund\u00ebsin\u00eb e rregjistrimit automatik t\u00eb certifikat\u00ebs (p\u00ebr nj\u00eb nga skenar\u00ebt, skenari kryesor \u00ebsht\u00eb regjistrimi manual dhe ngarkimi n\u00eb PC), un\u00eb realizova regjistrimin automatik p\u00ebr demonstrohen (t\u00eb heq\u00ebsh asnj\u00ebher\u00eb nuk \u00ebsht\u00eb von\u00eb).<\/li>\n<li>Autentifikimi kryesor duhet t\u00eb kaloj\u00eb n\u00eb disa etapa, s\u00eb pari b\u00ebhet autentifikimi i certifikat\u00ebs me analizimin e fushave dhe vlerave t\u00eb nevojshme, pastaj login\/fjal\u00ebkalim, vet\u00ebm q\u00eb k\u00ebt\u00eb her\u00eb n\u00eb dritaren e login duhet t\u00eb vendoset emri i p\u00ebrdoruesit, i p\u00ebrcaktuar n\u00eb fush\u00ebn e certifikat\u00ebs. <strong>Subjekti Emri (CN)<\/strong> pa mund\u00ebsi redaktimi.<\/li>\n<li>\u00cbsht\u00eb e nevojshme t\u00eb sigurohemi q\u00eb pajisja nga e cila b\u00ebhet hyrja t\u00eb jet\u00eb laptopi i dh\u00ebn\u00eb p\u00ebrdoruesit p\u00ebr qasje t\u00eb larg\u00ebt korporative, dhe jo di\u00e7ka tjet\u00ebr. (Jan\u00eb b\u00ebr\u00eb disa variante p\u00ebr t\u00eb p\u00ebrmbushur k\u00ebt\u00eb k\u00ebrkes\u00eb)<\/li>\n<li>Duhet t\u00eb b\u00ebhet nj\u00eb vler\u00ebsim i gjendjes s\u00eb pajisjes q\u00eb po lidhet (n\u00eb k\u00ebt\u00eb faz\u00eb PC) me kontrollin e nj\u00eb tabele t\u00eb sh\u00ebndosh\u00eb k\u00ebrkesash nga klienti (duke p\u00ebrmbledhur):\n<ul>\n<li>Skedar\u00ebt dhe pronat e tyre;<\/li>\n<li>Regjistrimet e regjistrit;<\/li>\n<li>Patch-et e OS nga lista e ofruar (n\u00eb vazhdim integrimi i SCCM);<\/li>\n<li>Prania e Antivirusit nga nj\u00eb prodhues i caktuar dhe aktualiteti i n\u00ebnshkrimeve;<\/li>\n<li>Aktiviteti i disa sh\u00ebrbimeve t\u00eb caktuara;<\/li>\n<li>Prania e disa programeve t\u00eb instaluara;<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p><\/p>\n<p>N\u00eb fillim, sugjeroj t\u00eb shikoni patjet\u00ebr demonstrat\u00ebn video t\u00eb realizimit t\u00eb fituar n\u00eb <strong>Youtube (5 minuta)<\/strong>.<\/p>\n<p>\n<center><div class=\"youtube-placeholder\" data-id=\"cBftD3KFK98\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/cBftD3KFK98\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<p>Tani propozoj t\u00eb shqyrtojm\u00eb detajet e realizimit q\u00eb nuk u p\u00ebrmend\u00ebn n\u00eb videon.<\/p>\n<p><\/p>\n<p><strong>Le t\u00eb p\u00ebrgatisim profilin AnyConnect:<\/strong><\/p>\n<p><\/p>\n<p>Shembulli i krijimit t\u00eb profilit (n\u00eb lidhje me menun\u00eb n\u00eb ASDM) e kam p\u00ebrmendur m\u00eb par\u00eb n\u00eb artikullin tim p\u00ebr konfigurimin <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cisco\/blog\/493098\/\">VPN Load-Balancing klasteri<\/a><\/noindex>. Tani dua t\u00eb theksoj ve\u00e7an\u00ebrisht ato opsione q\u00eb na nevojiten:<\/p>\n<p><\/p>\n<p>N\u00eb profil do t\u00eb tregojm\u00eb portin VPN dhe emrin e profilit p\u00ebr lidhen n\u00eb klientin p\u00ebrfundimtar:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/45ff3cb1f7b592e102bd6e256ae26043.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Do t\u00eb realizojm\u00eb cil\u00ebsimet p\u00ebr automatizimin e l\u00ebshimit t\u00eb certifikat\u00ebs nga profili, duke treguar, p\u00ebrkat\u00ebsisht, parametrat e certifikat\u00ebs dhe, si\u00e7 \u00ebsht\u00eb karakteristik, do t\u00eb kushtojm\u00eb v\u00ebmendje fush\u00ebs <strong>Initials (I)<\/strong>, ku manualisht \u00ebsht\u00eb futur nj\u00eb vler\u00eb specifike <strong>UDID<\/strong> i makin\u00ebs testuese (Identifikuesi Unik i Pajisjes, i gjeneruar nga klienti Cisco AnyConnect).<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/89d4edb4f1b166eda75916286998a4bf.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>K\u00ebtu d\u00ebshiroj t\u00eb b\u00ebj nj\u00eb sh\u00ebnim lirik, pasi ky artikull p\u00ebrshkruan konceptin, p\u00ebr q\u00ebllime demonstrative \u00ebsht\u00eb futur UDID p\u00ebr l\u00ebshimin e certifikat\u00ebs n\u00eb fush\u00ebn Initials t\u00eb profilit AnyConnect. Sigurisht, n\u00eb jet\u00eb reale, n\u00ebse e b\u00ebni k\u00ebt\u00eb, t\u00eb gjith\u00eb klient\u00ebt do t\u00eb marrin nj\u00eb certifikat me UDID t\u00eb nj\u00ebjt\u00eb n\u00eb k\u00ebt\u00eb fush\u00eb dhe asgj\u00eb nuk do t\u00eb funksionoj\u00eb p\u00ebr ta, pasi ata kan\u00eb nevoj\u00eb p\u00ebr UDID-n\u00eb e PC-s\u00eb s\u00eb tyre specifike. AnyConnect fatkeq\u00ebsisht ende nuk implementon z\u00ebvend\u00ebsimin n\u00eb profil p\u00ebr k\u00ebrkes\u00ebn e certifikat\u00ebs n\u00eb fush\u00ebn UDID p\u00ebrmes variablit t\u00eb ambientit, ashtu si\u00e7 e b\u00ebn, p\u00ebr shembull, me variablin <strong>%USER%<\/strong>.<\/p>\n<p><\/p>\n<p>Duhet theksuar se porosit\u00ebsi (i k\u00ebtij skenari) fillimisht planifikon t\u00eb l\u00ebshoj\u00eb vet\u00eb certifikatat me UDID t\u00eb caktuar n\u00eb m\u00ebnyr\u00eb manuale p\u00ebr k\u00ebto PC t\u00eb Mbrojtura, q\u00eb p\u00ebr t\u00eb nuk \u00ebsht\u00eb ndonj\u00eb problem. Megjithat\u00eb, p\u00ebr shumic\u00ebn e ne, d\u00ebshirojm\u00eb automatizim (p\u00ebr mua t\u00eb pakt\u00ebn =)). <\/p>\n<p><\/p>\n<p>Dhe ja \u00e7far\u00eb mund t'ju ofroj p\u00ebr automatizimin. N\u00ebse certifikata l\u00ebshohet automatikisht AnyConnect duke futur dinamikisht UDID, nuk \u00ebsht\u00eb gjith\u00e7ka e mundur, por ka nj\u00eb m\u00ebnyr\u00eb tjet\u00ebr q\u00eb k\u00ebrkon pak kreativitet dhe duar t\u00eb zhd\u00ebrvjellta \u2013 do t'ju tregoj konceptin. Fillimisht, le t\u00eb shqyrtojm\u00eb si krijohet UDID n\u00eb sisteme t\u00eb ndryshme operative nga agjenti AnyConnect: <\/p>\n<p><\/p>\n<ul>\n<li><strong>macOS<\/strong> \u2014 SHA-256 hash i kombinimit t\u00eb \u00e7el\u00ebsit t\u00eb regjistrit DigitalProductID dhe Machine SID<\/li>\n<li><strong>OSX<\/strong> \u2014 SHA-256 hash i PlatformUUID<\/li>\n<li><strong>OpenVPN<\/strong> \u2014 SHA-256 hash i UUID t\u00eb partisioneve kryesore.<\/li>\n<li><strong>Apple iOS<\/strong> \u2014 SHA-256 hash i PlatformUUID<\/li>\n<li><strong>Fare OS<\/strong> \u2013 Shih dokumentin p\u00ebr <noindex><a rel=\"nofollow\" href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/vpn_client\/anyconnect\/anyconnect40\/administration\/guide\/b_AnyConnect_Administrator_Guide_4-0\/b_AnyConnect_Administrator_Guide_4-0_chapter_01010.html#reference_C87ADD1C58F64EF8928D921323209AA6\">lidhjes<\/a><\/noindex><\/li>\n<\/ul>\n<p><\/p>\n<p>Dhe k\u00ebshtu, ne krijojm\u00eb nj\u00eb skript p\u00ebr sistemet tona operative Windows, n\u00ebp\u00ebrmjet k\u00ebtij skripti llogarisim lokalisht UDID sipas t\u00eb dh\u00ebnave t\u00eb njohura dhe krijojm\u00eb nj\u00eb k\u00ebrkes\u00eb p\u00ebr l\u00ebshimin e certifikat\u00ebs, duke futur n\u00eb fush\u00ebn e duhur k\u00ebt\u00eb UDID, e cila, p\u00ebr faktin, mund t\u00eb jet\u00eb edhe certifikata e makin\u00ebs, e l\u00ebshuar nga AD (duke shtuar n\u00eb skem\u00eb dyfish autentifikim me certifikat\u00ebn <strong>Multiple Certificate<\/strong>). <\/p>\n<p><\/p>\n<p><strong>T\u00eb p\u00ebrgatisim konfigurimet nga ana e Cisco ASA:<\/strong><\/p>\n<p><\/p>\n<p>T\u00eb krijojm\u00eb TrustPoint p\u00ebr serverin ISE CA, i cili do t\u00eb l\u00ebshoj\u00eb certifikata p\u00ebr klient\u00ebt. Procedur\u00ebn e importit t\u00eb Key-Chain nuk do ta shqyrtoj, shembulli \u00ebsht\u00eb i p\u00ebrshkruar n\u00eb artikullin tim p\u00ebr konfigurimin <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cisco\/blog\/493098\/\">VPN Load-Balancing klasteri<\/a><\/noindex>. <\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">crypto ca trustpoint ISE-CA\n enrollment terminal\n crl configure<\/code><\/pre>\n<p><\/p>\n<p>Konfigurojm\u00eb shp\u00ebrndarjen n\u00eb baze t\u00eb Tunnel-Group sipas rregullave n\u00eb p\u00ebrputhje me fushat n\u00eb certifikat\u00ebn, me t\u00eb cil\u00ebn b\u00ebhet autentifikimi. Po ashtu, k\u00ebtu konfiguroni profilin AnyConnect, i prodhuar nga ne n\u00eb faz\u00ebn e kaluar. V\u00ebrej se po p\u00ebrdor vler\u00ebn <strong>SECUREBANK-RA<\/strong>, p\u00ebr t\u00eb transferuar p\u00ebrdoruesit me certifikat\u00ebn e l\u00ebshuar n\u00eb grupin tunel. <strong>SECURE-BANK-VPN<\/strong>, kushtoj v\u00ebmendje se kjo fush\u00eb \u00ebsht\u00eb vendosur n\u00eb kolon\u00ebn e k\u00ebrkes\u00ebs p\u00ebr certifikat\u00ebn e profilit AnyConnect.<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">tunnel-group-map enable rules\n!\ncrypto ca certificate map OU-Map 6\n subject-name attr ou eq securebank-ra\n!\nwebvpn\n anyconnect profiles SECUREBANK disk0:\/securebank.xml\n certificate-group-map OU-Map 6 SECURE-BANK-VPN\n!<\/code><\/pre>\n<p><\/p>\n<p>Konfigurojm\u00eb server\u00ebt e autentikimit. N\u00eb rastin tim, ky \u00ebsht\u00eb ISE p\u00ebr faz\u00ebn e par\u00eb t\u00eb autentikimit dhe DUO (Radius Proxy) si MFA.<\/p>\n<p><\/p>\n<pre><code class=\"plaintext\">! CISCO ISE\naaa-server ISE protocol radius\n authorize-only\n interim-accounting-update periodic 24\n dynamic-authorization\naaa-server ISE (inside) host 192.168.99.134\n key *****\n!\n! DUO RADIUS PROXY\naaa-server DUO protocol radius\naaa-server DUO (inside) host 192.168.99.136\n timeout 60\n key *****\n authentication-port 1812\n accounting-port 1813\n no mschapv2-capable\n!<\/code><\/pre>\n<p><\/p>\n<p>Krijojm\u00eb politika grupore dhe grupe tunelesh, si dhe komponent\u00ebt e tyre ndihm\u00ebs:<\/p>\n<p><\/p>\n<p>Grupi tunel <strong>DefaultWEBVPNGroup<\/strong> do t\u00eb p\u00ebrdoret fillimisht p\u00ebr shkarkimin e klientit AnyConnect VPN dhe l\u00ebshimin e certifikat\u00ebs s\u00eb p\u00ebrdoruesit duke p\u00ebrdorur funksionin SCEP-Proxy t\u00eb ASA, p\u00ebr k\u00ebt\u00eb kemi aktivizuar opsionet p\u00ebrkat\u00ebse si n\u00eb grupin e tunelit ashtu edhe n\u00eb politik\u00ebn grupore t\u00eb asociuar. <strong>AC-Download<\/strong>, si dhe n\u00eb profilin e shkarkuar AnyConnect (fushat e l\u00ebshimit t\u00eb certifikat\u00ebs etj.). Gjithashtu n\u00eb k\u00ebt\u00eb politik\u00eb grupi p\u00ebrcaktojm\u00eb nevoj\u00ebn p\u00ebr shkarkimin <strong>ISE Posture Module<\/strong>.<\/p>\n<p><\/p>\n<p>Grupi tunel <strong>SECURE-BANK-VPN<\/strong> do t\u00eb p\u00ebrdoret automatikisht nga klienti gjat\u00eb autentifikimit me certifikat\u00ebn e l\u00ebshuar n\u00eb faz\u00ebn e m\u00ebparshme, pasi sipas Hart\u00ebs s\u00eb Certifikat\u00ebs, lidhja do t\u00eb bjer\u00eb pik\u00ebrisht n\u00eb k\u00ebt\u00eb grup tuneli. Do t\u00eb flas p\u00ebr opsionet interesante k\u00ebtu:<\/p>\n<p><\/p>\n<ul>\n<li><strong>secondary-authentication-server-group DUO<\/strong> # \u0417\u0430\u0434\u0430\u0435\u043c \u0432\u0442\u043e\u0440\u0438\u0447\u043d\u0443\u044e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 DUO (Radius Proxy)<\/li>\n<li><strong>username-from-certificate CN<\/strong> # \u0418\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u0434\u043b\u044f \u043f\u0435\u0440\u0432\u0438\u0447\u043d\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043f\u043e\u043b\u0435 CN \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0434\u043b\u044f \u043d\u0430\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u043b\u043e\u0433\u0438\u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f<\/li>\n<li><strong>secondary-username-from-certificate I<\/strong> # \u0414\u043b\u044f \u0432\u0442\u043e\u0440\u0438\u0447\u043d\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 DUO \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u043d\u043e\u0435 \u0438 \u043f\u043e\u043b\u044f Initials (I) \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430.<\/li>\n<li><strong>pre-fill-username client<\/strong> # \u0434\u0435\u043b\u0430\u0435\u043c \u043f\u0440\u0435\u0434\u0437\u0430\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u043c \u0438\u043c\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0432 \u043e\u043a\u043d\u0435 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0431\u0435\u0437 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f<\/li>\n<li><strong>secondary-pre-fill-username client hide use-common-password push<\/strong> # \u041f\u0440\u044f\u0447\u0435\u043c \u043e\u043a\u043d\u043e \u0432\u0432\u043e\u0434\u0430 \u043b\u043e\u0433\u0438\u043d\u0430\/\u043f\u0430\u0440\u043e\u043b\u044f \u0434\u043b\u044f \u0432\u0442\u043e\u0440\u0438\u0447\u043d\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 DUO \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u0434\u043b\u044f \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432\u043c\u0435\u0441\u0442\u043e \u043f\u043e\u043b\u044f \u043f\u0430\u0440\u043e\u043b\u044f \u043c\u0435\u0442\u043e\u0434 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u044f (sms\/push\/phone) \u2013 \u0434\u043e\u043a\u0430 <noindex><a rel=\"nofollow\" href=\"https:\/\/duo.com\/docs\/ciscoasa-radius\">k\u00ebtu<\/a><\/noindex><\/li>\n<\/ul>\n<p><\/p>\n<pre><code class=\"plaintext\">!\naccess-list posture-redirect extended permit tcp any host 72.163.1.80 \naccess-list posture-redirect extended deny ip any any\n!\naccess-list VPN-Filter extended permit ip any any\n!\nip local pool vpn-pool 192.168.100.33-192.168.100.63 mask 255.255.255.224\n!\ngroup-policy SECURE-BANK-VPN internal\ngroup-policy SECURE-BANK-VPN attributes\n dns-server value 192.168.99.155 192.168.99.130\n vpn-filter value VPN-Filter\n vpn-tunnel-protocol ssl-client \n split-tunnel-policy tunnelall\n default-domain value ashes.cc\n address-pools value vpn-pool\n webvpn\n  anyconnect ssl dtls enable\n  anyconnect mtu 1300\n  anyconnect keep-installer installed\n  anyconnect ssl keepalive 20\n  anyconnect ssl rekey time none\n  anyconnect ssl rekey method ssl\n  anyconnect dpd-interval client 30\n  anyconnect dpd-interval gateway 30\n  anyconnect ssl compression lzs\n  anyconnect dtls compression lzs\n  anyconnect modules value iseposture\n  anyconnect profiles value SECUREBANK type user\n!\ngroup-policy AC-DOWNLOAD internal\ngroup-policy AC-DOWNLOAD attributes\n dns-server value 192.168.99.155 192.168.99.130\n vpn-filter value VPN-Filter\n vpn-tunnel-protocol ssl-client \n split-tunnel-policy tunnelall\n default-domain value ashes.cc\n address-pools value vpn-pool\n scep-forwarding-url value http:\/\/ise.ashes.cc:9090\/auth\/caservice\/pkiclient.exe\n webvpn\n  anyconnect ssl dtls enable\n  anyconnect mtu 1300\n  anyconnect keep-installer installed\n  anyconnect ssl keepalive 20\n  anyconnect ssl rekey time none\n  anyconnect ssl rekey method ssl\n  anyconnect dpd-interval client 30\n  anyconnect dpd-interval gateway 30\n  anyconnect ssl compression lzs\n  anyconnect dtls compression lzs\n  anyconnect modules value iseposture\n  anyconnect profiles value SECUREBANK type user\n!\ntunnel-group DefaultWEBVPNGroup general-attributes\n address-pool vpn-pool\n authentication-server-group ISE\n accounting-server-group ISE\n default-group-policy AC-DOWNLOAD\n scep-enrollment enable\ntunnel-group DefaultWEBVPNGroup webvpn-attributes\n authentication aaa certificate\n!\ntunnel-group SECURE-BANK-VPN type remote-access\ntunnel-group SECURE-BANK-VPN general-attributes\n address-pool vpn-pool\n authentication-server-group ISE\n secondary-authentication-server-group DUO\n accounting-server-group ISE\n default-group-policy SECURE-BANK-VPN\n username-from-certificate CN\n secondary-username-from-certificate I\ntunnel-group SECURE-BANK-VPN webvpn-attributes\n authentication aaa certificate\n pre-fill-username client\n secondary-pre-fill-username client hide use-common-password push\n group-alias SECURE-BANK-VPN enable\n dns-group ASHES-DNS\n!<\/code><\/pre>\n<p><\/p>\n<p><strong>M\u00eb pas kalojm\u00eb n\u00eb ISE:<\/strong><\/p>\n<p><\/p>\n<p>Konfigurojm\u00eb nj\u00eb p\u00ebrdorues lokal (mund t\u00eb p\u00ebrdorim gjithashtu AD\/LDAP\/ODBC etj.), p\u00ebr thjesht\u00ebsi kam krijuar nj\u00eb p\u00ebrdorues lokal n\u00eb ISE dhe e kam caktuar n\u00eb fush\u00ebn <strong>description<\/strong> <strong>UDID i PC-s\u00eb<\/strong> nga i cili i lejohet hyrja p\u00ebrmes VPN. N\u00eb rastin e p\u00ebrdorimit t\u00eb autentikimit lokal n\u00eb ISE, do t\u00eb jem i kufizuar vet\u00ebm n\u00eb nj\u00eb pajisje, pasi nuk ka shum\u00eb fusha, por n\u00eb bazat e t\u00eb dh\u00ebnave t\u00eb jashtme p\u00ebr autentikim, ato kufizime nuk do t\u00eb ken\u00eb.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/ea73d4bab6c0872f7c3aef4ad1345b12.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>T\u00eb shohim politik\u00ebn e autorizimit, e cila ndahet n\u00eb kat\u00ebr faza t\u00eb lidhjes:<\/p>\n<p><\/p>\n<ul>\n<li><strong>Faza 1<\/strong> \u2014 Politika p\u00ebr shkarkimin e agentit AnyConnect dhe l\u00ebshimin e certifikat\u00ebs<\/li>\n<li><strong>Faza 2<\/strong> \u2014 Politika e autentikimit fillestar Login (nga certifikata)\/Fjal\u00ebkalimi + Certifikata me validimin e UDID<\/li>\n<li><strong>Faza 3<\/strong> \u2014 Autentikimi dyt\u00ebsor p\u00ebrmes Cisco DUO (MFA) me UDID si emri i p\u00ebrdoruesit + Vler\u00ebsimi i gjendjes<\/li>\n<li><strong>Faza 4<\/strong> \u2014 Autoriza finale n\u00eb gjendjen:\n<ul>\n<li>E pajtueshme;<\/li>\n<li>me validimin e UDID (nga certifikata + lidhja me login), <\/li>\n<li>Cisco DUO MFA;<\/li>\n<li>Autentikimi me login; <\/li>\n<li>Autentikimi me certifikat\u00eb;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/f0927091b896dc1e8b7fde35f9ff9211.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>T\u00eb shohim nj\u00eb kusht interesant <strong>UUID_VALIDATED<\/strong>, pik\u00ebrisht ajo e verifikon n\u00ebse p\u00ebrdoruesi q\u00eb po autentikohet ka ardhur nga nj\u00eb PC me UDID t\u00eb lejuar t\u00eb asociuar n\u00eb fush\u00ebn <strong>P\u00ebrshkrimi<\/strong> e llogaris\u00eb, duket si kushtet:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/73952c705b376246f8b2fb9de883302b.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Profilin e autorizimit, i p\u00ebrdorur n\u00eb fazat 1, 2, 3, duket si m\u00eb posht\u00eb:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/4b1eb6688a5a42d74b587424b02624e1.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>T\u00eb kontrollojm\u00eb si arrin UDID nga klienti AnyConnect duke par\u00eb detajet e sesionit t\u00eb klientit n\u00eb ISE. N\u00eb detajet do t\u00eb shohim se AnyConnect p\u00ebrmes mekanizmit <strong>ACIDEX<\/strong> d\u00ebrgon jo vet\u00ebm t\u00eb dh\u00ebnat n\u00eb lidhje me platform\u00ebn, por gjithashtu UDID e pajisjes si <strong>Cisco-AV-PAIR<\/strong>:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/34859d3b6a5edb448999eaec49c59669.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>T\u00eb v\u00ebm\u00eb re certifikat\u00ebn e shkruar p\u00ebr p\u00ebrdoruesin dhe fush\u00ebn <strong>Initials (I)<\/strong>, e cila p\u00ebrdoret p\u00ebr ta marr\u00eb at\u00eb si login p\u00ebr autentifikimin e dyt\u00eb MFA n\u00eb Cisco DUO:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/ac5928db33e5dbbb1bd7e2190da6d9fa.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>N\u00eb an\u00ebn e DUO Radius Proxy n\u00eb logun e shohim qart\u00eb si b\u00ebhet k\u00ebrkesa p\u00ebr autentifikim, ajo b\u00ebhet duke p\u00ebrdorur UDID si emrin e p\u00ebrdoruesit:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/791f5470115460dc4d920096e79dde0f.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Nga portali DUO shohim nj\u00eb ngjarje t\u00eb suksesshme autentifikimi:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/a31e31c57ad8b6e4ba021f3da7eedb7e.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Dhe n\u00eb pron\u00ebsit\u00eb e p\u00ebrdoruesit kam vendosur <strong>ALIAS<\/strong>, t\u00eb cilin e p\u00ebrdora p\u00ebr login, nga ana tjet\u00ebr kjo \u00ebsht\u00eb UDID e lejuar p\u00ebr loginin e PC:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Zbatimi i konceptit t\u00eb aksesit t\u00eb avancuar dhe t\u00eb mbrojtur n\u00eb distanc\u00eb.\" src=\"\/wp-content\/uploads\/2020\/04\/4035937749d1b85bad291aa4ec407352.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p><strong>Si rezultat mor\u00ebm:<\/strong><\/p>\n<p><\/p>\n<ul>\n<li>Autentifikimin e shum\u00ebfaktorit t\u00eb p\u00ebrdoruesit dhe pajisjes;<\/li>\n<li>Mbrojtja nga z\u00ebvend\u00ebsimi i pajisjes s\u00eb p\u00ebrdoruesit;<\/li>\n<li>Vler\u00ebsimi i gjendjes s\u00eb pajisjes;<\/li>\n<li>Potenciali p\u00ebr p\u00ebrmir\u00ebsimin e kontrollit me certifikat\u00ebn e makin\u00ebs s\u00eb domenit etj.;<\/li>\n<li>Mbrojtja gjith\u00ebp\u00ebrfshir\u00ebse e vendit t\u00eb pun\u00ebs t\u00eb larg\u00ebt me modula sigurie q\u00eb shp\u00ebrndahen automatikisht;<\/li>\n<\/ul>\n<p><\/p>\n<p>Linket e artikujve t\u00eb seris\u00eb Cisco VPN:<\/p>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cisco\/blog\/493098\/\">Implementimi i grupit t\u00eb Load-Balancing p\u00ebr ASA VPN<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cisco\/blog\/493774\/\">Optimizimi i sh\u00ebrbimeve n\u00eb re n\u00eb tunelin AnyConnect VPN mbi Cisco ASA<\/a><\/noindex><\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cisco\/blog\/497618\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044f \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u044c\u0435\u0439 \u043f\u043e \u0442\u0435\u043c\u0435 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 Remote-Access VPN \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0435 \u043c\u043e\u0433\u0443 \u043d\u0435 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u043e\u043f\u044b\u0442\u043e\u043c \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u0432\u044b\u0441\u043e\u043a\u043e\u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 VPN. \u0417\u0430\u0434\u0430\u0447\u0443 \u043d\u0435\u0442\u0440\u0438\u0432\u0438\u0430\u043b\u044c\u043d\u0443\u044e \u043f\u043e\u0434\u043a\u0438\u043d\u0443\u043b \u043e\u0434\u0438\u043d \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a (\u0435\u0441\u0442\u044c \u0432\u044b\u0434\u0443\u043c\u0449\u0438\u043a\u0438 \u0432 \u0420\u0443\u0441\u0441\u043a\u0438\u0445 \u0441\u0435\u043b\u0435\u043d\u0438\u044f\u0445), \u043d\u043e Challenge Accepted \u0438 \u0442\u0432\u043e\u0440\u0447\u0435\u0441\u043a\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u0439 \u043a\u043e\u043d\u0446\u0435\u043f\u0442 \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c\u0438 \u0445\u0430\u0440\u0430\u043a\u0442\u0435\u0440\u0438\u0441\u0442\u0438\u043a\u0430\u043c\u0438: \u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0444\u0430\u043a\u0442\u043e\u0440\u043e\u0432 \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u043e\u043a\u043e\u043d\u0435\u0447\u043d\u043e\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 (\u0441 \u0436\u0435\u0441\u0442\u043a\u043e\u0439 \u043f\u0440\u0438\u0432\u044f\u0437\u043a\u043e\u0439 \u043a \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e); [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":78243,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-78242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044f \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u044c\u0435\u0439 \u043f\u043e \u0442\u0435\u043c\u0435 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 Remote-Access VPN \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0435 \u043c\u043e\u0433\u0443 \u043d\u0435 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u043e\u043f\u044b\u0442\u043e\u043c \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u0432\u044b\u0441\u043e\u043a\u043e\u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 VPN.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043a\u043e\u043d\u0446\u0435\u043f\u0446\u0438\u0438 \u0432\u044b\u0441\u043e\u043a\u043e\u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0433\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044f \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u044c\u0435\u0439 \u043f\u043e \u0442\u0435\u043c\u0435 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 Remote-Access VPN \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0435 \u043c\u043e\u0433\u0443 \u043d\u0435 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u043e\u043f\u044b\u0442\u043e\u043c \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u0432\u044b\u0441\u043e\u043a\u043e\u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 VPN.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-04-17T23:42:36+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-04-17T23:42:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Realizimi i konceptit t\u00eb aksesit t\u00eb shkall\u00ebs s\u00eb lart\u00eb t\u00eb siguris\u00eb | ProHoster","description":"Duke vazhdoj serin\u00eb e artikujve mbi tem\u00ebn e organizimit t\u00eb aksesit VPN me Remote-Access, nuk mund t\u00eb mos ndaj nj\u00eb p\u00ebrvoj\u00eb interesante n\u00eb shp\u00ebrndarjen e nj\u00eb konfigurimi shum\u00eb t\u00eb sigurt VPN.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043a\u043e\u043d\u0446\u0435\u043f\u0446\u0438\u0438 \u0432\u044b\u0441\u043e\u043a\u043e\u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0433\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 | ProHoster","og:description":"\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044f \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u044c\u0435\u0439 \u043f\u043e \u0442\u0435\u043c\u0435 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 Remote-Access VPN \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0435 \u043c\u043e\u0433\u0443 \u043d\u0435 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u043e\u043f\u044b\u0442\u043e\u043c \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f \u0432\u044b\u0441\u043e\u043a\u043e\u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 VPN.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/realizacziya-konczepczii-vysokozashhishhennogo-udalennogo-dostupa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-04-17T23:42:36+00:00","article:modified_time":"2020-04-17T23:42:36+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"78242","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:02:45","updated":"2022-09-29 00:42:25","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/78242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=78242"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/78242\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/78243"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=78242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=78242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=78242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}