ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ ืื™ืš ื•ื•ืึธืœื˜ ื•ื•ื™ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืฉืจื™ื˜-ื“ื•ืจืš-ืฉืจื™ื˜ ื™ื ืกื˜ืจืึทืงืฉืึทื ื– ืื•ื™ืฃ ื•ื•ื™ ืื™ืจ ืงืขื ืขืŸ ื’ืขืฉื•ื•ื™ื ื“ ืฆืขื•ื•ื™ืงืœืขืŸ ื“ื™ ืžืขืจืกื˜ ืกืงืึทืœืึทื‘ืœืข ืกื›ืขืžืข ืื™ืŸ ื“ืขื ืžืึธืžืขื ื˜ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก ื•ื•ืคึผืŸ ืฆื•ื˜ืจื™ื˜ ื‘ืื–ื™ืจื˜ AnyConnect ืื•ืŸ Cisco ASA - VPN ืžืึทืกืข ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ.

ื”ืงื“ืžื”: ืคื™ืœืข ืงืึธืžืคึผืึทื ื™ืขืก ืึทืจื•ื ื“ื™ ื•ื•ืขืœื˜, ืจืขื›ื˜ ืฆื• ื“ืขืจ ืงืจืึทื ื˜ ืกื™ื˜ื•ืึทืฆื™ืข ืžื™ื˜ COVID-19, ืžืึทื›ืŸ ื”ืฉืชื“ืœื•ืช ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื–ื™ื™ืขืจ ืขืžืคึผืœื•ื™ื™ื– ืฆื• ื•ื•ื™ื™ึทื˜ ืึทืจื‘ืขื˜. ืจืขื›ื˜ ืฆื• ื“ืขืจ ื•ื•ื™ื™ื“ืกืคึผืจืขื“ ื™ื‘ืขืจื’ืึทื ื’ ืฆื• ื•ื•ื™ื™ึทื˜ ืึทืจื‘ืขื˜, ื“ื™ ืžืึทืกืข ืื•ื™ืฃ ื™ื’ื–ื™ืกื˜ื™ื ื’ VPN ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืคื•ืŸ ืงืึธืžืคึผืึทื ื™ืขืก ื™ื ืงืจื™ืกื™ื– ืงืจื™ื˜ื™ืงืึทืœื™ ืื•ืŸ ืึท ื–ื™ื™ืขืจ ืฉื ืขืœ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื•ื•ืึธื’ ื–ื™ื™ ืื™ื– ืคืืจืœืื ื’ื˜. ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื”ืึทื ื˜, ืคื™ืœืข ืงืึธืžืคึผืึทื ื™ืขืก ื–ืขื ืขืŸ ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืฆื• ื›ื™ื™ืกื˜ืึทืœื™ ื‘ืขืœ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืึทืจื‘ืขื˜ ืคึฟื•ืŸ ืงืจืึทืฆืŸ.

ืฆื• ื”ืขืœืคึฟืŸ ื’ืขืฉืขืคื˜ืŸ ื’ืขืฉื•ื•ื™ื ื“ ื™ื ืกื˜ืจื•ืžืขื ื˜ ื‘ืึทืงื•ื•ืขื, ื–ื™ื›ืขืจ ืื•ืŸ ืกืงืึทืœืึทื‘ืœืข ื•ื•ืคึผืŸ ืึทืงืกืขืก ืคึฟืึทืจ ืขืžืคึผืœื•ื™ื™ื–, Cisco ื’ื™ื˜ ืึทืจื•ื™ืฃ ืฆื• 13-ื•ื•ืึธืš ืœื™ื™ืกืึทื ืกื™ื– ืคึฟืึทืจ ื“ื™ ืฉื˜ืจื™ืš-ืจื™ื™ึทืš AnyConnect SSL-VPN ืงืœื™ืขื ื˜. ืื™ืจ ืงืขื ื˜ ืื•ื™ืš ื ืขืžืขืŸ ASAv ืคึฟืึทืจ ื˜ืขืกื˜ื™ื ื’ (ื•ื•ื™ืจื˜ื•ืึทืœ ืึทืกืึท ืคึฟืึทืจ VMWare / Hyper-V / KVM ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจื– ืื•ืŸ AWS / Azure ื•ื•ืึธืœืงืŸ ืคึผืœืึทื˜ืคืึธืจืžืก) ืคึฟื•ืŸ ืึธื˜ืขืจื™ื™ื–ื“ ืคึผืึทืจื˜ื ืขืจืก ืึธื“ืขืจ ื“ื•ืจืš ืงืึธื ื˜ืึทืงื˜ ืกื™ืกืงืึธ ืคืืจืฉื˜ื™ื™ืขืจืก ืืจื‘ืขื˜ืŸ ืžื™ื˜ ืื™ืจ.

ื“ืขืจ ืคึผืจืึธืฆืขื“ื•ืจ ืคึฟืึทืจ ืืจื•ื™ืกื’ืขื‘ืŸ AnyConnect COVID-19 ืœื™ื™ืกืึทื ืกื™ื– ืื™ื– ื“ื™ืกืงืจื™ื™ื‘ื“ ื“ืึธ.

ืื™ืš ื”ืึธื‘ืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืฉืจื™ื˜-ื“ื•ืจืš-ืฉืจื™ื˜ ื™ื ืกื˜ืจืึทืงืฉืึทื ื– ืคึฟืึทืจ ืึท ืคึผืฉื•ื˜ ืึธืคึผืฆื™ืข ืคึฟืึทืจ ื“ื™ืคึผืœื•ื™ื™ื ื’ ืึท ื•ื•ืคึผืŸ ืœืึธื•ื“-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ ื•ื•ื™ ื“ื™ ืžืขืจืกื˜ ืกืงืึทืœืึทื‘ืœืข ื•ื•ืคึผืŸ ื˜ืขื›ื ืึธืœืึธื’ื™ืข.

ื“ืขืจ ื‘ื™ื™ืฉืคึผื™ืœ ืื•ื ื˜ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืึทื ืฅ ืคึผืฉื•ื˜ ืื™ืŸ ื“ื™ ืคื•ื ื˜ ืคื•ืŸ ืžื™ื™ื ื•ื ื’ ืคื•ืŸ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืึทืœื’ืขืจื™ื“ืึทืžื– ื’ืขื ื™ืฆื˜, ืึธื‘ืขืจ ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึท ื’ื•ื˜ ืึธืคึผืฆื™ืข ืคึฟืึทืจ ืึท ืฉื ืขืœ ืึธื ื”ื™ื™ื‘ (ื•ื•ืึธืก ืื™ื– ืขืคึผืขืก ื•ื•ืึธืก ืคื™ืœืข ืžืขื ื˜ืฉืŸ ืคืขืœืŸ ืื™ืฆื˜) ืžื™ื˜ ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ื˜ื™ืฃ ืึทื“ืึทืคึผื˜ื™ื™ืฉืึทืŸ ืฆื• ื“ื™ื™ืŸ ื‘ืื“ืขืจืคืขื ื™ืฉืŸ ื‘ืขืฉืึทืก ื“ื™ ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ืคึผืจืึธืฆืขืก.

ืงื•ืจืฅ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข: VPN ืœืึธื•ื“ ื‘ืึทืœืึทื ืกื™ื ื’ ืงืœืึทืกื˜ืขืจ ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืื™ื– ื ื™ืฉื˜ ืึท ืคื™ื™ืœืึธื•ื•ืขืจ ืึธื“ืขืจ ืึท ืงืœืึทืกื˜ืขืจื™ื ื’ ืคึฟื•ื ืงืฆื™ืข ืื™ืŸ ื–ื™ื™ืŸ ื’ืขื‘ื•ื™ืจืŸ ื–ื™ื ืขืŸ; ื“ื™ ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ื’ืึธืจ ืคืึทืจืฉื™ื“ืขื ืข ASA ืžืึธื“ืขืœืก (ืžื™ื˜ ื–ื™ื›ืขืจ ืจื™ืกื˜ืจื™ืงืฉืึทื ื–) ืื™ืŸ ืกื“ืจ ืฆื• ืžืึทืกืข ื•ื•ืึธื’ ืจื™ืžืึธื•ื˜ ืึทืงืกืขืก VPN ืงืึทื ืขืงืฉืึทื ื–. ืขืก ืื™ื– ืงื™ื™ืŸ ืกื™ื ื’ืงืจืึทื ืึทื–ื™ื™ืฉืึทืŸ ืคื•ืŸ ืกืขืฉืึทื ื– ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ืฆื•ื•ื™ืฉืŸ ื“ื™ ื ืึธื•ื“ื– ืคื•ืŸ ืึทื–ืึท ืึท ืงื ื•ื™ืœ, ืึธื‘ืขืจ ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืžืึทืกืข ื•ื•ืคึผืŸ ืงืึทื ืขืงืฉืึทื ื– ืื•ืŸ ืขื ืฉื•ืจ ืฉื•ืœื“ ื˜ืึธืœืขืจืึทื ืฅ ืคื•ืŸ VPN ืงืึทื ืขืงืฉืึทื ื– ื‘ื™ื– ืœืคึผื—ื•ืช ืื™ื™ืŸ ืึทืงื˜ื™ื•ื• ื ืึธื“ืข ื‘ืœื™ื™ื‘ื˜ ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ. ื“ื™ ืžืึทืกืข ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ ืื™ื– ื‘ืึทืœืึทื ืกื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ื™ืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื•ื•ืขืจืงืœืึธื•ื“ ืคื•ืŸ ื“ื™ ื ืึธื•ื“ื– ื“ื•ืจืš ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื•ื•ืคึผืŸ ืกืขืฉืึทื ื–.

ืคึฟืึทืจ ืฉื•ืœื“ ื˜ืึธืœืขืจืึทื ืฅ ืคื•ืŸ ืกืคึผืขืฆื™ืคื™ืฉ ืงื ื•ื™ืœ ื ืึธื•ื“ื– (ืื•ื™ื‘ ืคืืจืœืื ื’ื˜), ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืึท ืคื™ืœืขืจ, ืึทื–ื•ื™ ื“ื™ ืึทืงื˜ื™ื•ื• ืงืฉืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคึผืจืึทืกืขืกื˜ ื“ื•ืจืš ื“ื™ ืขืจืฉื˜ื™ืง ื ืึธื“ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืคื™ืœืขืจ. ื“ืขืจ ื˜ืขืงืขืึธื•ื•ืขืจ ืื™ื– ื ื™ื˜ ืึท ื ื•ื™ื˜ื™ืง ืฆื•ืฉื˜ืึทื ื“ ืคึฟืึทืจ ื™ื ืฉื•ืจื™ื ื’ ืฉื•ืœื“ ื˜ืึธืœืขืจืึทื ืฅ ืื™ืŸ ื“ื™ ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ; ืื™ืŸ ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืคื•ืŸ ืึท ื ืึธื“ืข ื“ื•ืจื›ืคืึทืœ, ื“ืขืจ ืงื ื•ื™ืœ ื–ื™ืš ื•ื•ืขื˜ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืกืขืกื™ืข ืฆื• ืืŸ ืื ื“ืขืจ ืœืขื‘ืŸ ื ืึธื“ืข, ืึธื‘ืขืจ ืึธืŸ ืžื™ื™ื ื˜ื™ื™ื ื™ื ื’ ื“ื™ ืงืฉืจ ืกื˜ืึทื˜ื•ืก, ื•ื•ืึธืก ืื™ื– ืคึผื•ื ืงื˜ ื•ื•ืึธืก ื“ื™ ืคื™ืœืขืจ ื’ื™ื˜. ื“ืขืจื™ื‘ืขืจ, ื“ื™ ืฆื•ื•ื™ื™ ื˜ืขืงื ืึทืœืึทื“ื–ืฉื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ืงืึทืžื‘ื™ื™ื ื“ ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง.

ื VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ ืงืขื ืขืŸ ืึทื ื˜ื”ืึทืœื˜ืŸ ืžืขืจ ื•ื•ื™ ืฆื•ื•ื™ื™ ื ืึธื•ื“ื–.

VPN ืœืึธื“ืŸ-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ ืื™ื– ื’ืขืฉื˜ื™ืฆื˜ ืื•ื™ืฃ ASA 5512-X ืื•ืŸ ื”ืขื›ืขืจ.

ื–ื™ื ื˜ ื™ืขื“ืขืจ ASA ืื™ืŸ ื“ื™ VPN ืœืึธื“ืŸ-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ ืื™ื– ืึท ืคืจื™ื™ึท ืึทืคึผืึทืจืึทื˜ ืื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืคื•ืŸ ืกืขื˜ื˜ื™ื ื’ืก, ืžื™ืจ ื“ื•ืจื›ืคื™ืจืŸ ืึทืœืข ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืกื˜ืขืคึผืก ื™ื ื“ื™ื•ื•ื™ื“ื–ืฉื•ืึทืœื™ ืื•ื™ืฃ ื™ืขื“ืขืจ ื™ื—ื™ื“ ืžื™ื˜ืœ.

ื“ืขื˜ืึทื™ืœืก ืคื•ืŸ ื“ื™ ื˜ืขื›ื ืึธืœืึธื’ื™ืข ื“ืึธ

ื“ื™ ืœืึทื“ื–ืฉื™ืงืึทืœ ื˜ืึธืคึผืึธืœืึธื’ื™ ืคื•ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ ืื™ื–:

ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

ืขืจืฉื˜ ื“ื™ืคึผืœื•ื™ืžืึทื ื˜:

  1. ืžื™ืจ ืฆืขื•ื•ื™ืงืœืขืŸ ืึทืกืึทื•ื• ื™ื ืกื˜ืึทื ืกื™ื– ืคื•ืŸ ื“ื™ ื˜ืขืžืคึผืœืึทื˜ืขืก ื•ื•ืึธืก ืžื™ืจ ื“ืึทืจืคึฟืŸ (ASAv5/10/30/50) ืคึฟื•ืŸ ื“ื™ ื‘ื™ืœื“.

  2. ืžื™ืจ ื‘ืึทืฉื˜ื™ืžืขืŸ INSIDE / OUTSIDE ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืฆื• ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื•ื•ืœืึทืŸ (ืึทืจื•ื™ืก ืื™ืŸ ื–ื™ื™ึทืŸ ืื™ื™ื’ืŸ ื•ื•ืœืึทืŸ, INSIDE ืื™ืŸ ื–ื™ื™ืŸ ืื™ื™ื’ืŸ, ืึธื‘ืขืจ ืคึผืจืึธืกื˜ ืื™ืŸ ื“ื™ ืงื ื•ื™ืœ, ื–ืขืŸ ื˜ืึทืคึผืึทืœืึทื“ื–ืฉื™), ืขืก ืื™ื– ื•ื•ื™ื›ื˜ื™ืง ืึทื– ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืคื•ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื˜ื™ืคึผ ื–ืขื ืขืŸ ืœื™ื’ืŸ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืœ 2 ืึธืคึผืฉื ื™ื˜.

  3. ืœื™ืกืขื ืกืขืก:

    • ืื™ืŸ ื“ืขืจ ืฆื™ื™ื˜ ืคื•ืŸ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’, ASAv ื•ื•ืขื˜ ื ื™ืฉื˜ ื”ืึธื‘ืŸ ืงื™ื™ืŸ ืœื™ื™ืกืึทื ืกื™ื– ืื•ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืœื™ืžื™ื˜ืขื“ ืฆื• 100 ืงื‘ื™ื˜ / ืกืขืง.
    • ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ืึท ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืึท ืกื™ืžืขืŸ ืื™ืŸ ื“ื™ื™ืŸ ืกืžืึทืจื˜ ืึทืงืึทื•ื ื˜ ื—ืฉื‘ื•ืŸ: https://software.cisco.com/ -> ืกืžืึทืจื˜ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืœื™ืกืขื ืกื™ื ื’
    • ืื™ืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ื•ื•ืึธืก ืึธืคึผืขื ืก, ื’ื™ื˜ ื“ื™ ืงื ืขืคึผืœ ื ื™ื• ื˜ืึธืงืขืŸ

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืžืึทื›ืŸ ื–ื™ื›ืขืจ ืึทื– ื“ื™ ืคืขืœื“ ืื™ืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ื•ื•ืึธืก ืึธืคึผืขื ืก ืื™ื– ืึทืงื˜ื™ื•ื• ืื•ืŸ ื“ื™ ื˜ืฉืขืงืงื‘ืึธืงืก ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืœืึธื–ืŸ ืึทืจื•ื™ืกืคื™ืจืŸ-ืงืึทื ื˜ืจืึธื•ืœื“ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™... ืึธืŸ ื“ืขื ืึทืงื˜ื™ื•ื• ืคืขืœื“, ืื™ืจ ื•ื•ืขื˜ ื ื™ืฉื˜ ืงืขื ืขืŸ ืฆื• ื ื•ืฆืŸ ืฉื˜ืึทืจืง ืขื ืงืจื™ืคึผืฉืึทืŸ ืคืึทื ื’ืงืฉืึทื ื– ืื•ืŸ, ืึทืงืึธืจื“ื™ื ื’ืœื™, VPN. ืื•ื™ื‘ ื“ืึธืก ืคืขืœื“ ืื™ื– ื ื™ืฉื˜ ืึทืงื˜ื™ื•ื•, ื‘ื™ื˜ืข ืงืึธื ื˜ืึทืงื˜ ื“ื™ื™ืŸ ื—ืฉื‘ื•ืŸ ืžืึทื ืฉืึทืคึฟื˜ ืฆื• ื‘ืขื˜ืŸ ืึทืงื˜ืึทื•ื•ื™ื™ืฉืึทืŸ.

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ื ืึธืš ื“ืจื™ื ื’ืœืขืš ื“ืขื ืงื ืขืคึผืœ ืฉืึทืคึฟืŸ ื˜ืึธืงืขืŸ, ืึท ืกื™ืžืขืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื‘ืืฉืืคืŸ ื•ื•ืึธืก ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ืฆื• ืงืจื™ื’ืŸ ืึท ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืคึฟืึทืจ ASAv, ืงืึธืคึผื™ืข ืขืก:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืœืึธืžื™ืจ ืื™ื‘ืขืจื—ื–ืจืŸ ืกื˜ืขืคึผืก C,D,E ืคึฟืึทืจ ื™ืขื“ืขืจ ื“ื™ืคึผืœื•ื™ื“ ืึทืกืึทื•ื•.
    • ืฆื• ืžืึทื›ืŸ ืขืก ื’ืจื™ื ื’ืขืจ ืฆื• ื ืึธื›ืžืึทื›ืŸ ื“ื™ ืกื™ืžืขืŸ, ืœืึธื–ืŸ ืื•ื ื“ื– ื˜ืขืžืคึผืขืจืขืจืึทืœื™ ื’ืขื‘ืŸ ื˜ืขืœื ืขื˜. ืœืึธืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ื™ืขื“ืขืจ ASA (ื“ื™ ื‘ื™ื™ืฉืคึผื™ืœ ืื•ื ื˜ืŸ ื™ืœืึทืกื˜ืจื™ื™ืฅ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืื•ื™ืฃ ASA-1). ื˜ืขืœื ืขื˜ ืคึฟื•ืŸ ืึทืจื•ื™ืก ื˜ื•ื˜ ื ื™ืฉื˜ ืึทืจื‘ืขื˜ืŸ, ืื•ื™ื‘ ืื™ืจ ื˜ืึทืงืข ื“ืึทืจืคึฟืŸ ืขืก, ื˜ื•ื™ืฉืŸ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื“ืจื’ื” ืฆื• 100 ืฆื• ืึทืจื•ื™ืก, ืื•ืŸ ื˜ื•ื™ืฉืŸ ืขืก ืฆื•ืจื™ืง.

    !
    ciscoasa(config)# int gi0/0
    ciscoasa(config)# nameif outside
    ciscoasa(config)# ip address 192.168.31.30 255.255.255.0
    ciscoasa(config)# no shut
    !
    ciscoasa(config)# int gi0/1
    ciscoasa(config)# nameif inside
    ciscoasa(config)# ip address 192.168.255.2 255.255.255.0
    ciscoasa(config)# no shut
    !
    ciscoasa(config)# telnet 0 0 inside
    ciscoasa(config)# username admin password cisco priv 15
    ciscoasa(config)# ena password cisco
    ciscoasa(config)# aaa authentication telnet console LOCAL
    !
    ciscoasa(config)# route outside 0 0 192.168.31.1
    !
    ciscoasa(config)# wr
    !

    • ืฆื• ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ืึท ืกื™ืžืขืŸ ืื™ืŸ ื“ื™ ืกืžืึทืจื˜ ืึทืงืึทื•ื ื˜ ื•ื•ืึธืœืงืŸ, ืื™ืจ ืžื•ื–ืŸ ืฆื•ืฉื˜ืขืœืŸ ืื™ื ื˜ืขืจื ืขื˜ ืึทืงืกืขืก ืฆื• ASA, ืคืจื˜ื™ื ื“ืึธ.

    ืื™ืŸ ืงื•ืจืฅ, ASA ืื™ื– ื“ืืจืฃ:

    • ืื™ื ื˜ืขืจื ืขื˜ ืึทืงืกืขืก ื“ื•ืจืš ื”ื˜ื˜ืคึผืก;
    • ืฆื™ื™ื˜ ืกื™ื ื’ืงืจืึทื ืึทื–ื™ื™ืฉืึทืŸ (ืžืขืจ ืจื™ื›ื˜ื™ืง ื“ื•ืจืš NTP);
    • ืจืขื’ื™ืกื˜ืจื™ืจื˜ ื“ื ืก ืกืขืจื•ื•ืขืจ;
      • ืžื™ืจ ื’ื™ื™ืŸ ื“ื•ืจืš ื˜ืขืœื ืขื˜ ืฆื• ืื•ื ื“ื–ืขืจ ASA ืื•ืŸ ืžืึทื›ืŸ ืกืขื˜ื˜ื™ื ื’ืก ืฆื• ืึทืงื˜ืึทื•ื•ื™ื™ื˜ ื“ื™ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ื“ื•ืจืš Smart-Account.

    !
    ciscoasa(config)# clock set 19:21:00 Mar 18 2020
    ciscoasa(config)# clock timezone MSK 3
    ciscoasa(config)# ntp server 192.168.99.136
    !
    ciscoasa(config)# dns domain-lookup outside
    ciscoasa(config)# DNS server-group DefaultDNS
    ciscoasa(config-dns-server-group)# name-server 192.168.99.132 
    !
    ! ะŸั€ะพะฒะตั€ะธะผ ั€ะฐะฑะพั‚ัƒ DNS:
    !
    ciscoasa(config-dns-server-group)# ping ya.ru
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 87.250.250.242, timeout is 2 seconds:
    !!!!!
    !
    ! ะŸั€ะพะฒะตั€ะธะผ ัะธะฝั…ั€ะพะฝะธะทะฐั†ะธัŽ NTP:
    !
    ciscoasa(config)# show ntp associations 
      address         ref clock     st  when  poll reach  delay  offset    disp
    *~192.168.99.136   91.189.94.4       3    63    64    1    36.7    1.85    17.5
    * master (synced), # master (unsynced), + selected, - candidate, ~ configured
    !
    ! ะฃัั‚ะฐะฝะพะฒะธะผ ะบะพะฝั„ะธะณัƒั€ะฐั†ะธัŽ ะฝะฐัˆะตะน ASAv ะดะปั Smart-Licensing (ะฒ ัะพะพั‚ะฒะตั‚ัั‚ะฒะธะธ ั ะ’ะฐัˆะธะผ ะฟั€ะพั„ะธะปะตะผ, ะฒ ะผะพะตะผ ัะปัƒั‡ะฐะต 100ะœ ะดะปั ะฟั€ะธะผะตั€ะฐ)
    !
    ciscoasa(config)# license smart
    ciscoasa(config-smart-lic)# feature tier standard
    ciscoasa(config-smart-lic)# throughput level 100M
    !
    ! ะ’ ัะปัƒั‡ะฐะต ะฝะตะพะฑั…ะพะดะธะผะพัั‚ะธ ะผะพะถะฝะพ ะฝะฐัั‚ั€ะพะธั‚ัŒ ะดะพัั‚ัƒะฟ ะฒ ะ˜ะฝั‚ะตั€ะฝะตั‚ ั‡ะตั€ะตะท ะฟั€ะพะบัะธ ะธัะฟะพะปัŒะทัƒะนั‚ะต ัะปะตะดัƒัŽั‰ะธะน ะฑะปะพะบ ะบะพะผะฐะฝะด:
    !call-home
    !  http-proxy ip_address port port
    !
    ! ะ”ะฐะปะตะต ะผั‹ ะฒัั‚ะฐะฒะปัะตะผ ัะบะพะฟะธั€ะพะฒะฐะฝะฝั‹ะน ะธะท ะฟะพั€ั‚ะฐะปะฐ Smart-Account ั‚ะพะบะตะฝ (<token>) ะธ ั€ะตะณะธัั‚ั€ะธั€ัƒะตะผ ะปะธั†ะตะฝะทะธัŽ
    !
    ciscoasa(config)# end
    ciscoasa# license smart register idtoken <token>

    • ืžื™ืจ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืึทื– ื“ืขืจ ืžื™ื˜ืœ ื”ืื˜ ื”ืฆืœื—ื” ืจืขื’ื™ืกื˜ืจื™ืจื˜ ืึท ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืื•ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ื‘ื ื™ืžืฆื:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

  4. ืงืึทื ืคื™ื’ื™ืขืจ ื™ืงืขืจื“ื™ืง SSL-VPN ืื•ื™ืฃ ื™ืขื“ืขืจ ื’ื™ื™ื˜ื•ื•ื™ื™

    • ื“ืขืจื ืึธืš, ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ืึทืงืกืขืก ื“ื•ืจืš SSH ืื•ืŸ ASDM:

    ciscoasa(config)# ssh ver 2
    ciscoasa(config)# aaa authentication ssh console LOCAL
    ciscoasa(config)# aaa authentication http console LOCAL
    ciscoasa(config)# hostname vpn-demo-1
    vpn-demo-1(config)# domain-name ashes.cc
    vpn-demo-1(config)# cry key gen rsa general-keys modulus 4096 
    vpn-demo-1(config)# ssh 0 0 inside  
    vpn-demo-1(config)# http 0 0 inside
    !
    ! ะŸะพะดะฝะธะผะตะผ ัะตั€ะฒะตั€ HTTPS ะดะปั ASDM ะฝะฐ ะฟะพั€ั‚ัƒ 445 ั‡ั‚ะพะฑั‹ ะฝะต ะฟะตั€ะตัะตะบะฐั‚ัŒัั ั SSL-VPN ะฟะพั€ั‚ะฐะปะพะผ
    !
    vpn-demo-1(config)# http server enable 445 
    !

    • ืคึฟืึทืจ ASDM ืฆื• ืึทืจื‘ืขื˜ืŸ, ืื™ืจ ืžื•ื–ืŸ ืขืจืฉื˜ืขืจ ืืจืืคืงืืคื™ืข ืขืก ืคึฟื•ืŸ cisco.com, ืื™ืŸ ืžื™ื™ืŸ ืคืึทืœ, ื“ืึธืก ืื™ื– ื“ื™ ืคืืœื’ืขื ื“ืข ื˜ืขืงืข:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืคึฟืึทืจ ื“ื™ AnyConnect ืงืœื™ืขื ื˜ ืฆื• ืึทืจื‘ืขื˜ืŸ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืึธืคึผืœืึธื“ื™ืจืŸ ืึท ื‘ื™ืœื“ ืฆื• ื™ืขื“ืขืจ ASA ืคึฟืึทืจ ื™ืขื“ืขืจ ืงืœื™ืขื ื˜ ื“ืขืกืงื˜ืึทืคึผ ืึทืก ื’ืขื•ื•ื™ื™ื ื˜ (ืคึผืœืึทื ื ืขื“ ืฆื• ื ื•ืฆืŸ ืœื™ื ื•ืงืก / Windows / MAC), ืื™ืจ ื“ืึทืจืคึฟืŸ ืึท ื˜ืขืงืข ืžื™ื˜ ื”ืขืึทื“ืขื ื“ ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ืคึผืึทืงืงืึทื’ืข ืื™ืŸ ื“ืขื ื˜ื™ื˜ืœ:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ื“ื™ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ื˜ืขืงืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื•ืคึผืœืึธืึทื“ืขื“, ืœืžืฉืœ, ืฆื• ืึท ืคื˜ืคึผ ืกืขืจื•ื•ืขืจ ืื•ืŸ ื•ืคึผืœืึธืึทื“ืขื“ ืฆื• ื™ืขื“ืขืจ ื™ื—ื™ื“ ืึทืกืึท:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ASDM ืื•ืŸ ื–ื™ืš-ื’ืขื—ืชืžืขื˜ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคึฟืึทืจ SSL-VPN (ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ื ื•ืฆืŸ ืึท ื˜ืจืึทืกื˜ื™ื“ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ืŸ ืคึผืจืึธื“ื•ืงืฆื™ืข). ื“ื™ ื’ืขื’ืจื™ื ื“ืขื˜ FQDN ืคื•ืŸ ื“ื™ ืงื ื•ื™ืœ ื•ื•ื™ืจื˜ื•ืึทืœ ืึทื“ืจืขืก (vpn-demo.ashes.cc), ืื•ืŸ ื™ืขื“ืขืจ FQDN ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืึทื“ืจืขืก ืคื•ืŸ ื™ืขื“ืขืจ ืงื ื•ื™ืœ ื ืึธื“ืข ืžื•ื–ืŸ ื–ื™ื™ืŸ ืจื™ื–ืึทืœื•ื•ื“ ืื™ืŸ ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื“ื ืก ื–ืึธื ืข ืฆื• ื“ื™ IP ืึทื“ืจืขืก ืคื•ืŸ ื“ื™ OUTSIDE ืฆื•ื‘ื™ื ื“ (ืึธื“ืขืจ ืฆื• ื“ื™ ืžืึทืคึผื˜ ืึทื“ืจืขืก ืื•ื™ื‘ ื•ื“ืคึผ / 443 ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืื™ื– ื’ืขื ื™ืฆื˜ (DTLS) ืื•ืŸ tcp/443 (TLS)). ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื‘ืื“ืขืจืคืขื ื™ืฉืŸ ืคึฟืึทืจ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ ืึธืคึผื˜ื™ื™ืœื•ื ื’ ืกืขืจื˜ื™ืคื™ืงืึทื˜ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ื“ืึทืงื™ื•ืžืขื ื˜ื™ื™ืฉืึทืŸ.

    !
    vpn-demo-1(config)# crypto ca trustpoint SELF
    vpn-demo-1(config-ca-trustpoint)# enrollment self
    vpn-demo-1(config-ca-trustpoint)# fqdn vpn-demo.ashes.cc
    vpn-demo-1(config-ca-trustpoint)# subject-name cn=*.ashes.cc, ou=ashes-lab, o=ashes, c=ru
    vpn-demo-1(config-ca-trustpoint)# serial-number             
    vpn-demo-1(config-ca-trustpoint)# crl configure
    vpn-demo-1(config-ca-crl)# cry ca enroll SELF
    % The fully-qualified domain name in the certificate will be: vpn-demo.ashes.cc
    Generate Self-Signed Certificate? [yes/no]: yes
    vpn-demo-1(config)# 
    !
    vpn-demo-1(config)# sh cry ca certificates 
    Certificate
    Status: Available
    Certificate Serial Number: 4d43725e
    Certificate Usage: General Purpose
    Public Key Type: RSA (4096 bits)
    Signature Algorithm: SHA256 with RSA Encryption
    Issuer Name: 
    serialNumber=9A439T02F95
    hostname=vpn-demo.ashes.cc
    cn=*.ashes.cc
    ou=ashes-lab
    o=ashes
    c=ru
    Subject Name:
    serialNumber=9A439T02F95
    hostname=vpn-demo.ashes.cc
    cn=*.ashes.cc
    ou=ashes-lab
    o=ashes
    c=ru
    Validity Date: 
    start date: 00:16:17 MSK Mar 19 2020
    end   date: 00:16:17 MSK Mar 17 2030
    Storage: config
    Associated Trustpoints: SELF 
    
    CA Certificate
    Status: Available
    Certificate Serial Number: 0509
    Certificate Usage: General Purpose
    Public Key Type: RSA (4096 bits)
    Signature Algorithm: SHA1 with RSA Encryption
    Issuer Name: 
    cn=QuoVadis Root CA 2
    o=QuoVadis Limited
    c=BM
    Subject Name: 
    cn=QuoVadis Root CA 2
    o=QuoVadis Limited
    c=BM
    Validity Date: 
    start date: 21:27:00 MSK Nov 24 2006
    end   date: 21:23:33 MSK Nov 24 2031
    Storage: config
    Associated Trustpoints: _SmartCallHome_ServerCA               

    • ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ASDM, ื˜ืึธืŸ ื ื™ื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ืคึผืึธืจื˜, ืœืžืฉืœ:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืœืึธืžื™ืจ ื“ื•ืจื›ืคื™ืจืŸ ื™ืงืขืจื“ื™ืง ื˜ื•ื ืขืœ ืกืขื˜ื˜ื™ื ื’ืก:
    • ืžื™ืจ ื•ื•ืขืœืŸ ืžืึทื›ืŸ ื“ื™ ืคึฟื™ืจืžืข ื ืขืฅ ืฆื•ื˜ืจื™ื˜ืœืขืš ื“ื•ืจืš ืึท ื˜ื•ื ืขืœ ืื•ืŸ ืคืึทืจื‘ื™ื ื“ืŸ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื’ืœื™ื™ึทืš (ื ื™ืฉื˜ ื“ื™ ืžืขืจืกื˜ ื–ื™ื›ืขืจ ืื•ืคึฟืŸ ืื™ืŸ ื“ืขืจ ืึทื•ื•ืขืง ืคื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื™ื˜ืœืขืŸ ืื•ื™ืฃ ื“ื™ ืงืึทื ืขืงื˜ื™ื ื’ ื‘ืึทืœืขื‘ืึธืก, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ื“ื•ืจื›ื ืขืžืขืŸ ื“ื•ืจืš ืึท ื™ื ืคืขืงื˜ืึทื“ ื‘ืึทืœืขื‘ืึธืก ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืคึฟื™ืจืžืข ื“ืึทื˜ืŸ, ืึธืคึผืฆื™ืข. ืฉืคึผืึทืœื˜ืŸ-ื˜ื•ื ืขืœ-ืคึผืึธืœื™ื˜ื™ืง ื˜ื•ื ืขืœืึทืœืœ ื•ื•ืขื˜ ืœืึธื–ืŸ ืึทืœืข ื‘ืึทืœืขื‘ืึธืก ืคืึทืจืงืขืจ ืื™ืŸ ื“ืขื ื˜ื•ื ืขืœ. ื“ืืš ืฉืคึผืึทืœื˜ืŸ-ื˜ื•ื ืขืœ ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ื‘ืึทืคืจื™ื™ึทืขืŸ ื“ื™ VPN ื’ื™ื™ื˜ื•ื•ื™ื™ ืื•ืŸ ื ื™ืฉื˜ ืคึผืจืึทืกืขืกื™ื ื’ ื‘ืึทืœืขื‘ืึธืก ืื™ื ื˜ืขืจื ืขื˜ ืคืึทืจืงืขืจ)
    • ืžื™ืจ ื•ื•ืขืœืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืžื—ื ื•ืช ืื™ืŸ ื“ืขื ื˜ื•ื ืขืœ ืžื™ื˜ ืึทื“ืจืขืกืขืก ืคึฟื•ืŸ ื“ื™ ืกื•ื‘ื ืขื˜ 192.168.20.0/24 (ืึท ื‘ืขืงืŸ ืคื•ืŸ 10 ืฆื• 30 ืึทื“ืจืขืกืขืก (ืคึฟืึทืจ ื ืึธื“ืข #1)). ื™ืขื“ืขืจ ื ืึธื“ืข ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ ืžื•ื–ืŸ ื”ืึธื‘ืŸ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข VPN ื‘ืขืงืŸ.
    • ืœืึธืžื™ืจ ื“ื•ืจื›ืคื™ืจืŸ ื™ืงืขืจื“ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžื™ื˜ ืึท ืœืึธื•ืงืึทืœื™ ื‘ืืฉืืคืŸ ื‘ืึทื ื™ืฆืขืจ ืื•ื™ืฃ ื“ื™ ASA (ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ืจืขืงืึทืžืขื ื“ื™ื“, ื“ืึธืก ืื™ื– ื“ื™ ืกื™ืžืคึผืœืึทืกื˜ ืื•ืคึฟืŸ), ืขืก ืื™ื– ื‘ืขืกืขืจ ืฆื• ื˜ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš LDAP/RADIUS, ืึธื“ืขืจ ื‘ืขืกืขืจ ื ืึธืš, ื‘ื•ื ื“ ืžื•ืœื˜ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ (MFA)ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ ืกื™ืกืงืึธ ื“ื•ืึธ.

    !
    vpn-demo-1(config)# ip local pool vpn-pool 192.168.20.10-192.168.20.30 mask 255.255.255.0
    !
    vpn-demo-1(config)# access-list split-tunnel standard permit 192.168.0.0 255.255.0.0
    !
    vpn-demo-1(config)# group-policy SSL-VPN-GROUP-POLICY internal
    vpn-demo-1(config)# group-policy SSL-VPN-GROUP-POLICY attributes
    vpn-demo-1(config-group-policy)# vpn-tunnel-protocol ssl-client 
    vpn-demo-1(config-group-policy)# split-tunnel-policy tunnelspecified
    vpn-demo-1(config-group-policy)# split-tunnel-network-list value split-tunnel
    vpn-demo-1(config-group-policy)# dns-server value 192.168.99.132
    vpn-demo-1(config-group-policy)# default-domain value ashes.cc
    vpn-demo-1(config)# tunnel-group DefaultWEBVPNGroup general-attributes
    vpn-demo-1(config-tunnel-general)#  default-group-policy SSL-VPN-GROUP-POLICY
    vpn-demo-1(config-tunnel-general)#  address-pool vpn-pool
    !
    vpn-demo-1(config)# username dkazakov password cisco
    vpn-demo-1(config)# username dkazakov attributes
    vpn-demo-1(config-username)# service-type remote-access
    !
    vpn-demo-1(config)# ssl trust-point SELF
    vpn-demo-1(config)# webvpn
    vpn-demo-1(config-webvpn)#  enable outside
    vpn-demo-1(config-webvpn)#  anyconnect image disk0:/anyconnect-win-4.8.03036-webdeploy-k9.pkg
    vpn-demo-1(config-webvpn)#  anyconnect enable
    !

    • (ืึทืคึผืฉืึทื ืึทืœ): ืื™ืŸ ื“ื™ ืื•ื™ื‘ืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืžื™ืจ ื’ืขื•ื•ื™ื™ื ื˜ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืื•ื™ืฃ ื“ื™ ืคื™ื™ืจื•ื•ืึทืœ ืฆื• ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ ื•ื•ื™ื™ึทื˜ ื ื™ืฆืขืจืก, ื•ื•ืึธืก ืคื•ืŸ ืงื•ืจืก ืื™ื– ืคื•ืŸ ืงืœื™ื™ืŸ ื ื•ืฆืŸ ืึทื—ื•ืฅ ืื™ืŸ ื“ืขืจ ืœืึทื‘ืึธืจืึทื˜ืึธืจื™ืข. ืื™ืš ื•ื•ืขื˜ ื’ืขื‘ืŸ ืึท ื‘ื™ื™ึทืฉืคึผื™ืœ ืคื•ืŸ ื•ื•ื™ ืฆื• ื’ืขืฉื•ื•ื™ื ื“ ืึทื“ืึทืคึผื˜ ื“ื™ ืกืขื˜ืึทืคึผ ืคึฟืึทืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ืจืึทื“ื™ื•ืก ืกืขืจื•ื•ืขืจ, ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ Cisco Identity Services Engine:

    vpn-demo-1(config-aaa-server-group)# dynamic-authorization
    vpn-demo-1(config-aaa-server-group)# interim-accounting-update
    vpn-demo-1(config-aaa-server-group)# aaa-server RADIUS (outside) host 192.168.99.134
    vpn-demo-1(config-aaa-server-host)# key cisco
    vpn-demo-1(config-aaa-server-host)# exit
    vpn-demo-1(config)# tunnel-group DefaultWEBVPNGroup general-attributes
    vpn-demo-1(config-tunnel-general)# authentication-server-group  RADIUS 
    !

    ื“ื™ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ื”ืื˜ ืขืก ืžืขื’ืœืขืš ื ื™ืฉื˜ ื‘ืœื•ื™ื– ืฆื• ื’ืขืฉื•ื•ื™ื ื“ ื•ื™ืกืฉื˜ื™ืžืขืŸ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืจืึธืฆืขื“ื•ืจ ืžื™ื˜ ื“ื™ AD Directory ื“ื™ื ืกื˜, ืึธื‘ืขืจ ืื•ื™ืš ืฆื• ื•ื™ืกื˜ื™ื™ืœืŸ ืฆื™ ื“ื™ ืงืึธื ื ืขืงื˜ืขื“ ืงืึธืžืคึผื™ื•ื˜ืขืจ ื’ืขื”ืขืจื˜ ืฆื• AD, ืคึฟืึทืจืฉื˜ื™ื™ืŸ ืฆื™ ืขืก ืื™ื– ืึท ืคึฟื™ืจืžืข ืžื™ื˜ืœ ืึธื“ืขืจ ืึท ืคืขืจื–ืขื ืœืขื›ืข ืžื™ื˜ืœ, ืื•ืŸ ืึทืกืกืขืกืก ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืงืึธื ื ืขืงื˜ืขื“. ืžื™ื˜ืœ.

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืœืึธืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ื˜ืจืึทื ืกืคึผืึทืจืขื ื˜ NAT ืึทื–ื•ื™ ืึทื– ืคืึทืจืงืขืจ ืฆื•ื•ื™ืฉืŸ ื“ื™ ืงืœื™ืขื ื˜ ืื•ืŸ ื ืขืฅ ืจืขืกื•ืจืกืŸ ืคื•ืŸ ื“ื™ ืคึฟื™ืจืžืข ื ืขืฅ ืื™ื– ื ื™ืฉื˜ ื™ื ื˜ืขืจืคื™ืจื“ ืžื™ื˜:

    vpn-demo-1(config-network-object)#  subnet 192.168.20.0 255.255.255.0
    !
    vpn-demo-1(config)# nat (inside,outside) source static any any destination static vpn-users vpn-users no-proxy-arp

    • (ืึธืคึผื˜ื™ืึธื ืึทืœ): ืฆื• ื•ื™ืกืฉื˜ืขืœืŸ ืื•ื ื“ื–ืขืจ ืงืœื™ื™ืึทื ืฅ ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจืš ASA (ื•ื•ืขืŸ ื ื™ืฆืŸ tunnelall ืึธืคึผืฆื™ืขืก) ื ื™ืฆืŸ PAT, ืื•ืŸ ืื•ื™ืš ืึทืจื•ื™ืกื’ืึทื ื’ ื“ื•ืจืš ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ OUTSIDE ืฆื•ื‘ื™ื ื“ ืคึฟื•ืŸ ื•ื•ื• ื–ื™ื™ ื–ืขื ืขืŸ ืงืึธื ื ืขืงื˜ืขื“, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึทื›ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืกืขื˜ื˜ื™ื ื’ืก

    vpn-demo-1(config-network-object)# nat (outside,outside) source dynamic vpn-users interface
    vpn-demo-1(config)# nat (inside,outside) source dynamic any interface
    vpn-demo-1(config)# same-security-traffic permit intra-interface 
    !

    • ืขืก ืื™ื– ื’ืึธืจ ื•ื•ื™ื›ื˜ื™ืง ื•ื•ืขืŸ ื ื™ืฆืŸ ืึท ืงื ื•ื™ืœ ืฆื• ื’ืขื‘ืŸ ื“ื™ ื™ื ืขืจืœืขืš ื ืขืฅ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื•ื•ืึธืก ASA ืฆื• ืžืึทืจืฉืจื•ื˜ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืคืึทืจืงืขืจ ืฆื• ื•ืกืขืจืก; ืคึฟืึทืจ ื“ืขื ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ืจื™ื“ื™ืกื˜ืจื™ื‘ื™ื•ื˜ื™ื ื’ ื“ื™ ืจื•ืฅ / 32 ืึทื“ืจืขืกืขืก ืืจื•ื™ืก ืฆื• ืงืœื™ื™ืึทื ืฅ.
      ืื™ืŸ ื“ืขืจ ืžืึธืžืขื ื˜, ืžื™ืจ ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื ืึธืš ืงืึทื ืคื™ื’ื™ืขืจื“ ื“ื™ ืงื ื•ื™ืœ, ืึธื‘ืขืจ ืžื™ืจ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืืจื‘ืขื˜ืŸ VPN ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืฆื• ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ื™ื ื“ื™ื•ื•ื™ื“ื–ืฉื•ืึทืœื™ ืคืึทืจื‘ื™ื ื“ืŸ ื“ื•ืจืš FQDN ืึธื“ืขืจ IP.

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ืžื™ืจ ื–ืขืŸ ื“ื™ ืงืึธื ื ืขืงื˜ืขื“ ืงืœื™ืขื ื˜ ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืคื•ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ASA:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ืึทื–ื•ื™ ืึทื– ืื•ื ื“ื–ืขืจ ื’ืึทื ืฅ ื•ื•ืคึผืŸ ืงื ื•ื™ืœ ืื•ืŸ ื“ื™ ื’ืื ืฆืข ืคึฟื™ืจืžืข ื ืขืฅ ื•ื•ื™ืกืŸ ื“ื™ ืžืึทืจืฉืจื•ื˜ ืฆื• ืื•ื ื“ื–ืขืจ ืงืœื™ืขื ื˜, ืžื™ืจ ื•ื•ืขืœืŸ ืจื™ื“ื™ืกื˜ืจื™ื‘ื™ื•ื˜ ื“ืขื ืงืœื™ืขื ื˜ ืคึผืจืขืคื™ืงืก ืื™ืŸ ืึท ื“ื™ื ืึทืžื™ืฉ ืจื•ื˜ื™ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœ, ืœืžืฉืœ OSPF:

    !
    vpn-demo-1(config)# route-map RMAP-VPN-REDISTRIBUTE permit 1
    vpn-demo-1(config-route-map)#  match ip address VPN-REDISTRIBUTE
    !
    vpn-demo-1(config)# router ospf 1
    vpn-demo-1(config-router)#  network 192.168.255.0 255.255.255.0 area 0
    vpn-demo-1(config-router)#  log-adj-changes
    vpn-demo-1(config-router)#  redistribute static metric 5000 subnets route-map RMAP-VPN-REDISTRIBUTE

    ืื™ืฆื˜ ืžื™ืจ ื”ืึธื‘ืŸ ืึท ืžืึทืจืฉืจื•ื˜ ืฆื• ื“ืขื ืงืœื™ืขื ื˜ ืคึฟื•ืŸ ื“ื™ ืจื’ืข ASA-2 ื’ื™ื™ื˜ื•ื•ื™ื™ ืื•ืŸ ื™ื•ื–ืขืจื– ืงืึธื ื ืขืงื˜ืขื“ ืฆื• ืคืึทืจืฉื™ื“ืขื ืข VPN ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ ืงืขื ืขืŸ, ืœืžืฉืœ, ื™ื‘ืขืจื’ืขื‘ืŸ ื’ืœื™ื™ึทืš ื“ื•ืจืš ืึท ืคึฟื™ืจืžืข ืกืึธืคื˜ืคืึธื ืข, ืคึผื•ื ืงื˜ ื•ื•ื™ ื“ื™ ืฆื•ืจื™ืงืงืขืจ ืคืึทืจืงืขืจ ืคื•ืŸ ื“ื™ ืจืขืกื•ืจืกืŸ ื’ืขื‘ืขื˜ืŸ ื“ื•ืจืš ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื•ื•ืขื˜ ืึธื ืงื•ืžืขืŸ. ืื™ืŸ ื“ื™ ื’ืขื‘ืขื˜ืŸ VPN ื’ื™ื™ื˜ื•ื•ื™ื™:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

  5. ืœืึธืžื™ืจ ืคืึธืจื–ืขืฆืŸ ืฆื• ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ.

    ื“ื™ ืึทื“ืจืขืก 192.168.31.40 ื•ื•ืขื˜ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ื•ื•ื™ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ IP (ื•ื•ื™ืคึผ - ืึทืœืข VPN ืงืœื™ื™ืึทื ืฅ ื•ื•ืขืœืŸ ื˜ื›ื™ืœืขืก ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืขืก), ืคึฟื•ืŸ ื“ืขื ืึทื“ืจืขืก, ื“ืขืจ ืงืœืึทืกื˜ืขืจ ื”ืืจ ื•ื•ืขื˜ ืจื™ื“ืขืจืขืงื˜ ืฆื• ืึท ื•ื•ื™ื™ื ื™ืงืขืจ ืœืึธื•ื“ื™ื“ ืงื ื•ื™ืœ ื ืึธื“ืข. ื“ื• ื–ืืœืกื˜ ื ื™ืฉื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ืจืขื’ื™ืกื˜ืจื™ืจืŸ ืคืึธืจื•ื™ืก ืื•ืŸ ืคืึทืจืงืขืจื˜ ื“ื ืก ืจืขืงืึธืจื“ืก ื‘ื™ื™ื“ืข ืคึฟืึทืจ ื™ืขื“ืขืจ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืึทื“ืจืขืก / FQDN ืคื•ืŸ ื™ืขื“ืขืจ ืงื ื•ื™ืœ ื ืึธื“ืข, ืื•ืŸ ืคึฟืึทืจ ื•ื•ื™ืคึผ.

    vpn-demo-1(config)# vpn load-balancing
    vpn-demo-1(config-load-balancing)# interface lbpublic outside
    vpn-demo-1(config-load-balancing)# interface lbprivate inside
    vpn-demo-1(config-load-balancing)# priority 10
    vpn-demo-1(config-load-balancing)# cluster ip address 192.168.31.40
    vpn-demo-1(config-load-balancing)# cluster port 4000
    vpn-demo-1(config-load-balancing)# redirect-fqdn enable
    vpn-demo-1(config-load-balancing)# cluster key cisco
    vpn-demo-1(config-load-balancing)# cluster encryption
    vpn-demo-1(config-load-balancing)# cluster port 9023
    vpn-demo-1(config-load-balancing)# participate
    vpn-demo-1(config-load-balancing)#

    • ืžื™ืจ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืงื ื•ื™ืœ ืžื™ื˜ ืฆื•ื•ื™ื™ ืงืึธื ื ืขืงื˜ืขื“ ืงืœื™ื™ืึทื ืฅ:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    • ืœืึธื–ืŸ ืื•ื ื“ื– ืžืึทื›ืŸ ื“ื™ ืงื•ื ื” ื“ืขืจืคืึทืจื•ื ื’ ืžืขืจ ื‘ืึทืงื•ื•ืขื ืžื™ื˜ ืึทืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ AnyConnect ืคึผืจืึธืคื™ืœ ื“ื•ืจืš ASDM.

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ืžื™ืจ ื ืขืžืขืŸ ื“ืขื ืคึผืจืึธืคื™ืœ ืื•ื™ืฃ ืึท ื‘ืึทืงื•ื•ืขื ื•ื•ืขื’ ืื•ืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืื•ื ื“ื–ืขืจ ื’ืจื•ืคึผืข ืคึผืึธืœื™ื˜ื™ืง ืžื™ื˜ ืื™ื:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ื ืึธืš ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืงืœื™ืขื ื˜ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’, ื“ืขื ืคึผืจืึธืคื™ืœ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ืื•ืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื™ืŸ ื“ื™ AnyConnect ืงืœื™ืขื ื˜, ืึทื–ื•ื™ ืื•ื™ื‘ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ, ืื™ืจ ื ืึธืจ ื“ืึทืจืคึฟืŸ ืฆื• ืกืขืœืขืงื˜ื™ืจืŸ ืขืก ืคึฟื•ืŸ ื“ืขืจ ืจืฉื™ืžื”:

    ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึทืŸ ASA VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงื ื•ื™ืœ

    ื–ื™ื ื˜ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ASDM ืžื™ืจ ื‘ืืฉืืคืŸ ื“ืขื ืคึผืจืึธืคื™ืœ ืื•ื™ืฃ ื‘ืœื•ื™ื– ืื™ื™ืŸ ืึทืกืึท, ื˜ืึธืŸ ื ื™ื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ืื™ื‘ืขืจื—ื–ืจืŸ ื“ื™ ืกื˜ืขืคึผืก ืื•ื™ืฃ ื“ื™ ืจื•ืขืŸ ืึทืกืึทืก ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ.

ืžืกืงื ื: ืื–ื•ื™, ืžื™ืจ ื’ืขืฉื•ื•ื™ื ื“ ื“ื™ืคึผืœื•ื™ื“ ืึท ืงื ื•ื™ืœ ืคื•ืŸ ืขื˜ืœืขื›ืข VPN ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืžื™ื˜ ืึธื˜ืึทืžืึทื˜ื™ืง ืžืึทืกืข ื‘ืึทืœืึทื ืกื™ื ื’. ืขืก ืื™ื– ื’ืจื™ื ื’ ืฆื• ืœื™ื™ื’ืŸ ื ื™ื™ึทืข ื ืึธื•ื“ื– ืฆื• ื“ืขื ืงื ื•ื™ืœ, ืึทื˜ืฉื™ื•ื•ื™ื ื’ ืคึผืฉื•ื˜ ื”ืึธืจื™ื–ืึธื ื˜ืึทืœ ืกืงื™ื™ืœื™ื ื’ ื“ื•ืจืš ื“ื™ืคึผืœื•ื™ื™ื ื’ ื ื™ื™ึท ืึทืกืึทื•ื• ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ืึธื“ืขืจ ื ื™ืฆืŸ ื™ื™ึทื–ื ื•ื•ืึทืจื’ ืึทืกืึทืก. ื“ืขืจ ืฉื˜ืจื™ืš-ืจื™ื™ึทืš AnyConnect ืงืœื™ืขื ื˜ ืงืขื ืขืŸ ืฉื˜ืืจืง ืคืึทืจื‘ืขืกืขืจืŸ ื“ื™ื™ืŸ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืงืฉืจ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืžื™ื˜ ื“ื™ ื”ืึทืœื˜ื  ื–ื™ืš (ืฉื˜ืึทื˜ ืึทืกืขืกืžืึทื ืฅ), ืจื•ื‘ึฟ ื™ืคืขืงื˜ื™ื•ื•ืœื™ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ ืึท ืกืขื ื˜ืจืึทืœื™ื™ื–ื“ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ ืื•ืŸ ืึทืงืึทื•ื ื˜ื™ื ื’ ืกื™ืกื˜ืขื ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ื‘ืึทื“ื™ื ื•ื ื’ืก ืžืึธื˜ืึธืจ.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’