ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืคืึธืจื–ืขืฆืŸ ื“ื™ ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ืึทืจื˜ื™ืงืœืขืŸ ืื•ื™ืฃ ื“ืขืจ ื˜ืขืžืข ืคื•ืŸ โ€‹โ€‹ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก ื•ื•ืคึผืŸ ืึทืงืกืขืก ืื™ืš ืงืขืŸ ื ื™ืฉื˜ ื”ืขืœืคึฟืŸ ืึธื‘ืขืจ ื˜ื™ื™ืœืŸ ืžื™ื™ืŸ ื˜ืฉื™ืงืึทื•ื•ืข ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ื“ืขืจืคืึทืจื•ื ื’ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ VPN ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ. ื ื ื™ื˜-ื ื™ื˜-ื ื™ื˜ื•ื•ื™ืึทืœ ืึทืจื‘ืขื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ื“ืขืจืœืื ื’ื˜ ื“ื•ืจืš ืื™ื™ืŸ ืงื•ื ื” (ืขืก ื–ืขื ืขืŸ ื™ื ื•ื•ืขื ื˜ืึธืจืก ืื™ืŸ ืจื•ืกื™ืฉืข ื“ืขืจืคืขืจ), ืึธื‘ืขืจ ื“ื™ ื˜ืฉืึทืœืึทื ื“ื–ืฉ ืื™ื– ื’ืขื•ื•ืขืŸ ืื ื’ืขื ื•ืžืขืŸ ืื•ืŸ ืงืจื™ื™ื™ื˜ื™ื•ื•ืœื™ ื™ืžืคึผืœืึทืžืขื ืึทื“. ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ื– ืึท ื˜ืฉื™ืงืึทื•ื•ืข ื‘ืึทื’ืจื™ืฃ ืžื™ื˜ ื“ื™ ืคืืœื’ืขื ื“ืข ืงืขืจืึทืงื˜ืขืจื™ืกื˜ื™ืงืก:

  1. ืขื˜ืœืขื›ืข ืกื™ื‘ื•ืช ืคื•ืŸ ืฉื•ืฅ ืงืขื’ืŸ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื•ื•ืึธืงื–ืึทืœ ืžื™ื˜ืœ (ืžื™ื˜ ืฉื˜ืจืขื ื’ ื‘ื™ื™ื ื“ื™ื ื’ ืฆื• ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ);
    • ืึทืกืกืขืกืก ื“ื™ ื”ืขืกืงืขื ืคื•ืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ 'ืก ืคึผื™ืกื™ ืžื™ื˜ ื“ื™ ืึทืกื™ื™ื ื“ UDID ืคื•ืŸ ื“ื™ ืขืจืœื•ื™ื‘ื˜ ืคึผื™ืกื™ ืื™ืŸ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ืึทื˜ืึทื‘ื™ื™ืก;
    • ืžื™ื˜ MFA ื ื™ืฆืŸ ื“ื™ PC UDID ืคึฟื•ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคึฟืึทืจ ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš Cisco DUO (ืื™ืจ ืงืขื ืขืŸ ืฆื•ื˜ืฉืขืคึผืขืŸ ืงื™ื™ืŸ ืกืึทืžืœ / ืจืึทื“ื™ื•ืก ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืื™ื™ื ืขืจ);
  2. ืžื•ืœื˜ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ:
    • ื‘ืึทื ื™ืฆืขืจ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืžื™ื˜ ืคืขืœื“ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืงืขื’ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื–ื™ื™;
    • ืœืึธื’ื™ืŸ (ืึทื ื˜ืฉื™ื™ื ื“ื–ืฉืึทื‘ืึทืœ, ื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ) ืื•ืŸ ืคึผืึทืจืึธืœ;
  3. ืึธืคึผืฉืึทืฆืŸ ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืงืึทื ืขืงื˜ื™ื ื’ ื‘ืึทืœืขื‘ืึธืก (ื”ืึทืœื˜ื  ื–ื™ืš)

ืœื™ื™ื–ื•ื ื’ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ื’ืขื ื™ืฆื˜:

  • Cisco ASA (VPN Gateway);
  • Cisco ISE (ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ / ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ / ืึทืงืึทื•ื ื˜ื™ื ื’, ืฉื˜ืึทื˜ ืขื•ื•ืึทืœื•ืึทื˜ื™ืึธืŸ, CA);
  • Cisco DUO (ืžื•ืœื˜ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ) (ืื™ืจ ืงืขื ืขืŸ ืฆื•ื˜ืฉืขืคึผืขืŸ ืงื™ื™ืŸ ืกืึทืžืœ / ืจืึทื“ื™ื•ืก ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืื™ื™ื ืขืจ);
  • Cisco AnyConnect (ืžื•ืœื˜ื™-ืฆื™ืœ ืึทื’ืขื ื˜ ืคึฟืึทืจ ื•ื•ืขืจืงืกื˜ื™ื™ืฉืึทื ื– ืื•ืŸ ืจื™ืจืขื•ื•ื“ื™ืง ืึทืก);

ืœืึธืžื™ืจ ืึธื ื”ื™ื™ื‘ืŸ ืžื™ื˜ ื“ื™ ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ืคื•ืŸ ื“ืขืจ ืงื•ื ื”:

  1. ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืžื•ื–ืŸ, ื“ื•ืจืš ื–ื™ื™ืŸ ืœืึธื’ื™ืŸ / ืคึผืึทืจืึธืœ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืงืขื ืขืŸ ืฆื• ืึธืคึผืœืึธื“ื™ืจืŸ ื“ื™ AnyConnect ืงืœื™ืขื ื˜ ืคึฟื•ืŸ ื“ื™ VPN ื’ื™ื™ื˜ื•ื•ื™ื™; ืึทืœืข ื ื™ื™ื˜ื™ืง AnyConnect ืžืึทื“ื–ืฉื•ืœื– ืžื•ื–ืŸ ื–ื™ื™ืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืก ืคึผืึธืœื™ื˜ื™ืง;
  2. ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื–ืึธืœ ืงืขื ืขืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ (ืคึฟืึทืจ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืกื™ื ืขืจื™ืึธื•ื–, ื“ืขืจ ื”ื•ื™ืคึผื˜ ืกืฆืขื ืึทืจ ืื™ื– ืžืึทื ื•ืึทืœ ื™ืฉื•ืึทื ืก ืื•ืŸ ื•ืคึผืœืึธืึทื“ื™ื ื’ ืื•ื™ืฃ ืึท ืคึผื™ืกื™), ืึธื‘ืขืจ ืื™ืš ื™ืžืคึผืœืึทืžืขื ืึทื“ ืึธื˜ืึทืžืึทื˜ื™ืง ืึทืจื•ื™ืกื’ืขื‘ืŸ ืคึฟืึทืจ ื“ืขืžืึทื ืกื˜ืจื™ื™ืฉืึทืŸ (ืขืก ืื™ื– ืงื™ื™ื ืžืึธืœ ืฆื• ืฉืคึผืขื˜ ืฆื• ื‘ืึทื–ื™ื™ึทื˜ื™ืงืŸ ืขืก).
  3. ื™ืงืขืจื“ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžื•ื–ืŸ ื ืขืžืขืŸ ืึธืจื˜ ืื™ืŸ ืขื˜ืœืขื›ืข ืกื˜ืึทื’ืขืก, ืขืจืฉื˜ืขืจ ืขืก ืื™ื– ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžื™ื˜ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ื“ื™ ื ื™ื™ื˜ื™ืง ืคืขืœื“ืขืจ ืื•ืŸ ื–ื™ื™ืขืจ ื•ื•ืึทืœื•ืขืก, ื“ืขืจื ืึธืš ืœืึธื’ื™ืŸ / ืคึผืึทืจืึธืœ, ื ืึธืจ ื“ืึธืก ืžืึธืœ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคืขืœื“ ืžื•ื–ืŸ ื–ื™ื™ืŸ ื™ื ืกืขืจื˜ืึทื“ ืื™ืŸ ื“ื™ ืœืึธื’ื™ืŸ ืคึฟืขื ืฆื˜ืขืจ. ื˜ืขืžืข ื ืึธืžืขืŸ (CN) ืึธืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ึทื˜ ืฆื• ืจืขื“ืึทื’ื™ืจืŸ.
  4. ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึทื›ืŸ ื–ื™ื›ืขืจ ืึทื– ื“ื™ ืžื™ื˜ืœ ืคื•ืŸ ื•ื•ืึธืก ืื™ืจ ืœืึธื’ื™ื ื’ ืื™ืŸ ืื™ื– ื“ื™ ืคึฟื™ืจืžืข ืœืึทืคึผื˜ืึทืคึผ ืืจื•ื™ืก ืฆื• ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืคึฟืึทืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก, ืื•ืŸ ื ื™ืฉื˜ ืขืคึผืขืก ืึทื ื“ืขืจืฉ. (ืขื˜ืœืขื›ืข ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ื’ืขืžืื›ื˜ ืฆื• ื‘ืึทืคืจื™ื“ื™ืงืŸ ื“ืขื ืคืึธื“ืขืจื•ื ื’)
  5. ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืงืึทื ืขืงื˜ื™ื ื’ ืžื™ื˜ืœ (ืื™ืŸ ื“ืขื ื‘ื™ื ืข ืคึผื™ืกื™) ื–ืึธืœ ื–ื™ื™ืŸ ืึทืกืกืขืกืกืขื“ ืžื™ื˜ ืึท ื˜ืฉืขืง ืคื•ืŸ ืึท ื’ืึทื ืฅ ื›ืขืคื˜ื™ ื˜ื™ืฉ ืคื•ืŸ ืงื•ื ื” ื‘ืื“ืขืจืคืขื ื™ืฉืŸ (ืกืึทืžืขืจื™ื™ื–ื™ื ื’):
    • ื˜ืขืงืขืก ืื•ืŸ ื–ื™ื™ืขืจ ืคึผืจืึธืคึผืขืจื˜ื™ืขืก;
    • ืจืขื’ื™ืกื˜ืจื™ ืื™ื™ื ืกืŸ;
    • ืึทืก ืคึผืึทื˜ืฉืึทื– ืคื•ืŸ ื“ื™ ืฆื•ื’ืขืฉื˜ืขืœื˜ ืจืฉื™ืžื” (ืฉืคึผืขื˜ืขืจ SCCM ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ);
    • ืึทื•ื•ืึทื™ืœืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ืึทื ื˜ื™-ื•ื•ื™ืจื•ืก ืคื•ืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืคืึทื‘ืจื™ืงืึทื ื˜ ืื•ืŸ ื“ื™ ืฉื™ื™ื›ื•ืช ืคื•ืŸ ืกื™ื’ื ืึทื˜ืฉืขืจื–;
    • ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ ืคื•ืŸ ื–ื™ื›ืขืจ ื‘ืึทื“ื™ื ื•ื ื’ืก;
    • ืึทื•ื•ืึทื™ืœืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ื–ื™ื›ืขืจ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืžื’ื™ืœื”;

ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ืžื™ื˜, ืื™ืš ืคึฟืึธืจืฉืœืึธื’ืŸ ืื™ืจ ื‘ืืฉื˜ื™ืžื˜ ืงื•ืง ืื™ืŸ ื“ื™ ื•ื•ื™ื“ืขื ื“ืขืžืึทื ืกื˜ืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืจื™ื–ืึทืœื˜ื™ื ื’ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื™ืึธื•ื˜ื•ื‘ืข (5 ืžื™ื ื•ื˜).

ืื™ืฆื˜ ืื™ืš ืคืึธืจืฉืœืึธื’ืŸ ืฆื• ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื“ืขื˜ืึทื™ืœืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืงืึทื•ื•ืขืจื“ ืื™ืŸ ื“ื™ ื•ื•ื™ื“ืขื ืงืœืขืžืขืจืœ.

ืœืึธืžื™ืจ ืฆื•ื’ืจื™ื™ื˜ืŸ ื“ื™ AnyConnect ืคึผืจืึธืคื™ืœ:

ืื™ืš ื”ืึธื‘ ืคืจื™ืขืจ ื’ืขื’ืขื‘ืŸ ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืคึผืจืึธืคื™ืœ (ืื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืคื•ืŸ ืึท ืžืขื ื™ื• ื ื•ืžืขืจ ืื™ืŸ ASDM) ืื™ืŸ ืžื™ื™ืŸ ืึทืจื˜ื™ืงืœ ื•ื•ืขื’ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงืœืึทืกื˜ืขืจ. ืื™ืฆื˜ ืื™ืš ื•ื•ืึธืœื˜ ื•ื•ื™ ืฆื• ื‘ืืžืขืจืงืŸ ื“ื™ ืึธืคึผืฆื™ืขืก ื•ื•ืึธืก ืžื™ืจ ื“ืึทืจืคึฟืŸ:

ืื™ืŸ ื“ืขื ืคึผืจืึธืคื™ืœ, ืžื™ืจ ื•ื•ืขืœืŸ ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ VPN ื’ื™ื™ื˜ื•ื•ื™ื™ ืื•ืŸ ื“ื™ ืคึผืจืึธืคื™ืœ ื ืึธืžืขืŸ ืคึฟืึทืจ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ื“ื™ ืกื•ืฃ ืงืœื™ืขื ื˜:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืœืึธืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ ืึธื˜ืึทืžืึทื˜ื™ืง ื™ืฉื•ืึทื ืก ืคื•ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคื•ืŸ ื“ื™ ืคึผืจืึธืคื™ืœ ื–ื™ื™ึทื˜, ื™ื ื“ืึทืงื™ื™ื˜ื™ื ื’, ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื•ืŸ, ืงืขืจืึทืงื˜ืขืจื™ืกื˜ื™ืงืœื™, ื•ืคืžืขืจืงื–ืึทืžืงื™ื™ื˜ ืฆื• ื“ื™ ืคืขืœื“ ืื™ื ื™ืฆื™ืืœืŸ (ืื™ืš), ื•ื•ื• ืึท ืกืคึผืขืฆื™ืคื™ืฉ ื•ื•ืขืจื˜ ืื™ื– ืžืึทื ื™ื•ืึทืœื™ ืืจื™ื™ืŸ UIDID ืคึผืจื•ื‘ื™ืจืŸ ืžืึทืฉื™ืŸ (ืื™ื™ื ื™ืงืœืขืš ืžื™ื˜ืœ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ื•ื•ืึธืก ืื™ื– ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ื“ื™ Cisco AnyConnect ืงืœื™ืขื ื˜).

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ื“ืึธ ืื™ืš ื•ื•ื™ืœืŸ ืฆื• ืžืึทื›ืŸ ืึท ืœื™ืจื™ืงืึทืœ ื“ื™ื’ืจืขืฉืึทืŸ, ื•ื•ื™ื™ึทืœ ื“ืขืจ ืึทืจื˜ื™ืงืœ ื‘ืืฉืจื™ื™ื‘ื˜ ื“ืขื ื‘ืึทื’ืจื™ืฃ; ืคึฟืึทืจ ื“ืขืžืึทื ืกื˜ืจื™ื™ืฉืึทืŸ ืฆื•ื•ืขืงืŸ, ื“ื™ UDID ืคึฟืึทืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ืืจื™ื™ืŸ ืื™ืŸ ื“ื™ ืื™ื ื™ืฆื™ืืœืŸ ืคืขืœื“ ืคื•ืŸ ื“ื™ AnyConnect ืคึผืจืึธืคื™ืœ. ืคื•ืŸ ืงื•ืจืก, ืื™ืŸ ืคืึทืงื˜ื™ืฉ ืœืขื‘ืŸ, ืื•ื™ื‘ ืื™ืจ ื˜ืึธืŸ ื“ืึธืก, ืึทืœืข ืงืœื™ื™ืึทื ืฅ ื‘ืึทืงื•ืžืขืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืžื™ื˜ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ UDID ืื™ืŸ ื“ืขื ืคืขืœื“ ืื•ืŸ ื’ืึธืจื ื™ืฉื˜ ื•ื•ืขื˜ ืึทืจื‘ืขื˜ืŸ ืคึฟืึทืจ ื–ื™ื™, ื•ื•ื™ื™ึทืœ ื–ื™ื™ ื“ืึทืจืคึฟืŸ ื“ื™ UDID ืคื•ืŸ ื–ื™ื™ืขืจ ืกืคึผืขืฆื™ืคื™ืฉ ืคึผื™ืกื™. ืึทื ื™ืงืึธื ื ืขืงื˜, ืœื™ื™ื“ืขืจ, ื˜ื•ื˜ ื ื™ืฉื˜ ื ืึธืš ื™ื ืกื˜ืจื•ืžืขื ื˜ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ ื“ื™ UDID ืคืขืœื“ ืื™ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื‘ืขื˜ืŸ ืคึผืจืึธืคื™ืœ ื“ื•ืจืš ืึท ืกื•ื•ื™ื•ื•ืข ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง, ื•ื•ื™ ืขืก ื˜ื•ื˜, ืœืžืฉืœ, ืžื™ื˜ ืึท ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง. %USER%.

ืขืก ืื™ื– ื›ื“ืื™ ืฆื• ื‘ืืžืขืจืงืŸ ืึทื– ื“ืขืจ ืงื•ื ื” (ืคื•ืŸ ื“ืขื ืกืฆืขื ืึทืจ) ื˜ื›ื™ืœืขืก ืคึผืœืึทื ื– ืฆื• ื™ื ื“ื™ืคึผืขื ื“ืึทื ื˜ืœื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืžื™ื˜ ืึท ื’ืขื’ืขื‘ืŸ UDID ืื™ืŸ ืžืึทื ื•ืึทืœ ืžืึธื“ืข ืฆื• ืึทื–ืึท ืคึผืจืึธื˜ืขืงื˜ืขื“ ืคึผื™ืกื™, ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ืึท ืคึผืจืึธื‘ืœืขื ืคึฟืึทืจ ืื™ื. ืึธื‘ืขืจ, ืคึฟืึทืจ ืจื•ื‘ึฟ ืคื•ืŸ ืื•ื ื“ื– ืžื™ืจ ื•ื•ืขืœืŸ ืึธื˜ืึทืžื™ื™ืฉืึทืŸ (ื ื•, ื“ืึธืก ืื™ื– ืืžืช ืคึฟืึทืจ ืžื™ืจ =)).

ืื•ืŸ ื“ืึธืก ืื™ื– ื•ื•ืึธืก ืื™ืš ืงืขื ืขืŸ ืคืึธืจืฉืœืึธื’ืŸ ืื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืคื•ืŸ ืึธื˜ืึทืžื™ื™ืฉืึทืŸ. ืื•ื™ื‘ AnyConnect ืื™ื– ื ืึธืš ื ื™ืฉื˜ ื‘ื™ื›ื•ืœืช ืฆื• ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ื•ืจืš ื“ื™ื ืึทืžื™ืงืึทืœืœื™ ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื“ื™ UDID, ืขืก ืื™ื– ืืŸ ืื ื“ืขืจ ื•ื•ืขื’ ื•ื•ืึธืก ื•ื•ืขื˜ ื“ืึทืจืคืŸ ืึท ื‘ื™ืกืœ ืฉืขืคืขืจื™ืฉ ื’ืขื“ืึทื ืง ืื•ืŸ ื‘ืขืจื™ื™ืฉ ื”ืขื ื˜ - ืื™ืš ื•ื•ืขืœ ื–ืึธื’ืŸ ืื™ืจ ื“ืขื ื‘ืึทื’ืจื™ืฃ. ืขืจืฉื˜ืขืจ, ืœืึธืžื™ืจ ื–ืขืŸ ื•ื•ื™ ื“ื™ UDID ืื™ื– ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืื•ื™ืฃ ืคืึทืจืฉื™ื“ืขื ืข ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ ื“ื•ืจืš ื“ื™ AnyConnect ืึทื’ืขื ื˜:

  • ืคึฟืขื ืฆื˜ืขืจ - SHA-256 ื”ืึทืฉ ืคื•ืŸ ื“ื™ ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ DigitalProductID ืื•ืŸ Machine SID ืจืขื’ื™ืกื˜ืจื™ ืฉืœื™ืกืœ
  • ืึธืกืงืก โ€” SHA-256 hash PlatformUUID
  • ืœื™ื ื•ืงืก - SHA-256 ื”ืึทืฉ ืคื•ืŸ ื“ื™ UUID ืคื•ืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ืฆืขื˜ื™ื™ืœื•ื ื’.
  • ืขืคึผืœ ื™ืึธืก โ€” SHA-256 hash PlatformUUID
  • ืึทื ื“ืจื•ื™ื“ โ€“ ื–ืขืŸ ื“ืึธืงื•ืžืขื ื˜ ืื•ื™ืฃ ืจื•ื ื’

ืึทืงืงืึธืจื“ื™ื ื’ืœื™, ืžื™ืจ ืžืึทื›ืŸ ืึท ืฉืจื™ืคื˜ ืคึฟืึทืจ ืื•ื ื“ื–ืขืจ ืคึฟื™ืจืžืข Windows ืึทืก, ืžื™ื˜ ื“ืขื ืฉืจื™ืคื˜ ืžื™ืจ ืœืึธื•ืงืึทืœื™ ืจืขื›ืขื ืขืŸ ื“ื™ UDID ื ื™ืฆืŸ ื‘ืึทื•ื•ื•ืกื˜ ื™ื ืคึผื•ืฅ ืื•ืŸ ืคืึธืจืขื ืึท ื‘ืงืฉื” ืฆื• ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื“ื•ืจืš ืึทืจื™ื™ึทืŸ ื“ืขื UDID ืื™ืŸ ื“ื™ ืคืืจืœืื ื’ื˜ ืคืขืœื“, ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ืื™ืจ ืงืขื ื˜ ืื•ื™ืš ื ื•ืฆืŸ ืึท ืžืึทืฉื™ืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืืจื•ื™ืก ื“ื•ืจืš AD (ื“ื•ืจืš ืึทื“ื™ื ื’ ื˜ืึธืคึผืœ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื ื™ืฆืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ื“ื™ ืกื›ืขืžืข ืงื™ื™ืคืœ ืกืขืจื˜ื™ืคื™ืงืึทื˜).

ืœืึธืžื™ืจ ืฆื•ื’ืจื™ื™ื˜ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืื•ื™ืฃ ื“ื™ Cisco ASA ื–ื™ื™ึทื˜:

ืœืึธืžื™ืจ ืžืึทื›ืŸ ืึท TrustPoint ืคึฟืึทืจ ื“ื™ ISE CA ืกืขืจื•ื•ืขืจ, ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ืขืจ ื•ื•ืึธืก ื•ื•ืขื˜ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืฆื• ืงืœื™ื™ืึทื ืฅ. ืื™ืš ื•ื•ืขืœ ื ื™ืฉื˜ ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื“ื™ ืฉืœื™ืกืœ-ืงื™ื™ื˜ ืึทืจื™ื™ึทื ืคื™ืจ ืคึผืจืึธืฆืขื“ื•ืจ; ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืื™ื– ื“ื™ืกืงืจื™ื™ื‘ื“ ืื™ืŸ ืžื™ื™ืŸ ืึทืจื˜ื™ืงืœ ืื•ื™ืฃ ืกืขื˜ืึทืคึผ VPN ืžืึทืกืข-ื‘ืึทืœืึทื ืกื™ื ื’ ืงืœืึทืกื˜ืขืจ.

crypto ca trustpoint ISE-CA
 enrollment terminal
 crl configure

ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ื“ื•ืจืš ื˜ื•ื ืขืœ-ื’ืจื•ืคึผืข ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื›ึผืœืœื™ื ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ ื“ื™ ืคืขืœื“ืขืจ ืื™ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื•ื•ืึธืก ืื™ื– ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ื“ื™ AnyConnect ืคึผืจืึธืคื™ืœ ืžื™ืจ ื’ืขืžืื›ื˜ ืื™ืŸ ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ื‘ื™ื ืข ืื™ื– ืื•ื™ืš ืงืึทื ืคื™ื’ื™ืขืจื“ ื“ืึธ. ื‘ื™ื˜ืข ื˜ืึธืŸ ืึทื– ืื™ืš ื ื•ืฆืŸ ื“ื™ ื•ื•ืขืจื˜ SECUREBANK-RA, ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื•ืกืขืจืก ืžื™ื˜ ืึท ืืจื•ื™ืก ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ืึท ื˜ื•ื ืขืœ ื’ืจื•ืคึผืข ื–ื™ื›ืขืจ-BANK-VPN, ื‘ื™ื˜ืข ื˜ืึธืŸ ืึทื– ืื™ืš ื”ืึธื‘ืŸ ื“ืขื ืคืขืœื“ ืื™ืŸ ื“ื™ AnyConnect ืคึผืจืึธืคื™ืœ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื‘ืขื˜ืŸ ื–ื™ื™ึทืœ.

tunnel-group-map enable rules
!
crypto ca certificate map OU-Map 6
 subject-name attr ou eq securebank-ra
!
webvpn
 anyconnect profiles SECUREBANK disk0:/securebank.xml
 certificate-group-map OU-Map 6 SECURE-BANK-VPN
!

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืกืขืจื•ื•ืขืจืก. ืื™ืŸ ืžื™ื™ืŸ ืคืึทืœ, ื“ืึธืก ืื™ื– ISE ืคึฟืึทืจ ื“ืขืจ ืขืจืฉื˜ืขืจ ื‘ื™ื ืข ืคื•ืŸ โ€‹โ€‹ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ DUO (Radius Proxy) ื•ื•ื™ MFA.

! CISCO ISE
aaa-server ISE protocol radius
 authorize-only
 interim-accounting-update periodic 24
 dynamic-authorization
aaa-server ISE (inside) host 192.168.99.134
 key *****
!
! DUO RADIUS PROXY
aaa-server DUO protocol radius
aaa-server DUO (inside) host 192.168.99.136
 timeout 60
 key *****
 authentication-port 1812
 accounting-port 1813
 no mschapv2-capable
!

ืžื™ืจ ืฉืึทืคึฟืŸ ื’ืจื•ืคึผืข ืคึผืึทืœืึทืกื™ื– ืื•ืŸ ื˜ื•ื ืขืœ ื’ืจื•ืคึผืขืก ืื•ืŸ ื–ื™ื™ืขืจ ืึทื’ื–ื™ืœื™ืขืจื™ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ:

ื˜ื•ื ืขืœ ื’ืจื•ืคึผืข DefaultWEBVPNGroup ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื‘ืคึฟืจื˜ ืฆื• ืึธืคึผืœืึธื“ื™ืจืŸ ื“ื™ AnyConnect VPN ืงืœื™ืขื ื˜ ืื•ืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื ื™ืฆืŸ ื“ื™ SCEP-Proxy ืคื•ื ืงืฆื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื“ื™ ASA; ืคึฟืึทืจ ื“ืขื ืžื™ืจ ื”ืึธื‘ืŸ ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืึธืคึผืฆื™ืขืก ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“ ื‘ื™ื™ื“ืข ืื•ื™ืฃ ื“ื™ ื˜ื•ื ืขืœ ื’ืจื•ืคึผืข ื–ื™ืš ืื•ืŸ ืื•ื™ืฃ ื“ื™ ืคึฟืึทืจื‘ื•ื ื“ืŸ ื’ืจื•ืคึผืข ืคึผืึธืœื™ื˜ื™ืง AC-Download, ืื•ืŸ ืื•ื™ืฃ ื“ื™ ืœืึธื•ื“ื™ื“ AnyConnect ืคึผืจืึธืคื™ืœ (ืคืขืœื“ืขืจ ืคึฟืึทืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ, ืืื–"ื• ื•). ืื•ื™ืš ืื™ืŸ ื“ืขื ื’ืจื•ืคึผืข ืคึผืึธืœื™ื˜ื™ืง ืžื™ืจ ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ื ื•ื™ื˜ ืฆื• ืึธืคึผืœืึธื“ื™ืจืŸ ISE ืคึผืึธืกื˜ื•ืจืข ืžืึธื“ื•ืœืข.

ื˜ื•ื ืขืœ ื’ืจื•ืคึผืข ื–ื™ื›ืขืจ-BANK-VPN ื“ืขืจ ืงืœื™ืขื ื˜ ื•ื•ืขื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื ื•ืฆืŸ ื•ื•ืขืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžื™ื˜ ื“ื™ ืืจื•ื™ืก ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืื™ืŸ ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ื‘ื™ื ืข, ื•ื•ื™ื™ึทืœ, ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ ื“ื™ ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืžืึทืคึผืข, ื“ื™ ืงืฉืจ ื•ื•ืขื˜ ืคืึทืœืŸ ืกืคึผืึทืกื™ืคื™ืงืœื™ ืื•ื™ืฃ ื“ืขื ื˜ื•ื ืขืœ ื’ืจื•ืคึผืข. ืื™ืš ื•ื•ืขื˜ ื–ืึธื’ืŸ ืื™ืจ ื•ื•ืขื’ืŸ ื˜ืฉื™ืงืึทื•ื•ืข ืึธืคึผืฆื™ืขืก ื“ืึธ:

  • ืฆื•ื•ื™ื™ื˜ื™ืง-ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ-ืกืขืจื•ื•ืขืจ-ื’ืจื•ืคึผืข ื“ื•ืึธ # ืฉื˜ืขืœืŸ ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื“ื™ DUO ืกืขืจื•ื•ืขืจ (ืจืึทื“ื™ื•ืก ืคึผืจืึธืงืกื™)
  • ื ืืžืขืŸ-ืคื•ืŸ-CertificateCN # ืคึฟืึทืจ ืขืจืฉื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืžื™ืจ ื ื•ืฆืŸ ื“ื™ CN ืคืขืœื“ ืคื•ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ื™ืจืฉืขื ืขืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืœืึธื’ื™ืŸ
  • ืฆื•ื•ื™ื™ื˜ื™ืง ื ืืžืขืŸ-ืคื•ืŸ-Certificate I # ืคึฟืึทืจ ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื“ื™ DUO ืกืขืจื•ื•ืขืจ, ืžื™ืจ ื ื•ืฆืŸ ื“ื™ ื™ืงืกื˜ืจืึทืงื˜ื™ื“ ื ืืžืขืŸ ืื•ืŸ ื“ื™ ืื™ื ื™ืฆื™ืืœืŸ (ืื™ืš) ืคืขืœื“ืขืจ ืคื•ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ.
  • ืคืึทืจ-ืคื™ืœืŸ-ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืงืœื™ืขื ื˜ # ืžืึทื›ืŸ ื“ื™ ื ืืžืขืŸ ืคืึทืจ-ืึธื ื’ืขืคื™ืœื˜ ืื™ืŸ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืขื ืฆื˜ืขืจ ืึธืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื˜ื•ื™ืฉืŸ
  • ืฆื•ื•ื™ื™ื˜ื™ืง-ืคืึทืจ-ืคื™ืœืŸ-ื‘ืึทื ื™ืฆืขืจ ืงืœื™ืขื ื˜ ื‘ืึทื”ืึทืœื˜ืŸ ื ื•ืฆืŸ-ืคึผืจืึธืกื˜ ืคึผืึทืจืึธืœ ืฉื˜ื•ืคึผืŸ # ืžื™ืจ ื‘ืึทื”ืึทืœื˜ืŸ ื“ื™ ืœืึธื’ื™ืŸ / ืคึผืึทืจืึธืœ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ืคึฟืขื ืฆื˜ืขืจ ืคึฟืึทืจ ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ DUO ืื•ืŸ ื ื•ืฆืŸ ื“ื™ ืึธื ื–ืึธื’ ืื•ืคึฟืŸ (ืกืžืก / ืฉื˜ื•ืคึผืŸ / ื˜ืขืœืขืคืึธืŸ) - ื“ืึธืง ืฆื• ื‘ืขื˜ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ื™ ืคึผืึทืจืึธืœ ืคืขืœื“ ื“ืึธ

!
access-list posture-redirect extended permit tcp any host 72.163.1.80 
access-list posture-redirect extended deny ip any any
!
access-list VPN-Filter extended permit ip any any
!
ip local pool vpn-pool 192.168.100.33-192.168.100.63 mask 255.255.255.224
!
group-policy SECURE-BANK-VPN internal
group-policy SECURE-BANK-VPN attributes
 dns-server value 192.168.99.155 192.168.99.130
 vpn-filter value VPN-Filter
 vpn-tunnel-protocol ssl-client 
 split-tunnel-policy tunnelall
 default-domain value ashes.cc
 address-pools value vpn-pool
 webvpn
  anyconnect ssl dtls enable
  anyconnect mtu 1300
  anyconnect keep-installer installed
  anyconnect ssl keepalive 20
  anyconnect ssl rekey time none
  anyconnect ssl rekey method ssl
  anyconnect dpd-interval client 30
  anyconnect dpd-interval gateway 30
  anyconnect ssl compression lzs
  anyconnect dtls compression lzs
  anyconnect modules value iseposture
  anyconnect profiles value SECUREBANK type user
!
group-policy AC-DOWNLOAD internal
group-policy AC-DOWNLOAD attributes
 dns-server value 192.168.99.155 192.168.99.130
 vpn-filter value VPN-Filter
 vpn-tunnel-protocol ssl-client 
 split-tunnel-policy tunnelall
 default-domain value ashes.cc
 address-pools value vpn-pool
 scep-forwarding-url value http://ise.ashes.cc:9090/auth/caservice/pkiclient.exe
 webvpn
  anyconnect ssl dtls enable
  anyconnect mtu 1300
  anyconnect keep-installer installed
  anyconnect ssl keepalive 20
  anyconnect ssl rekey time none
  anyconnect ssl rekey method ssl
  anyconnect dpd-interval client 30
  anyconnect dpd-interval gateway 30
  anyconnect ssl compression lzs
  anyconnect dtls compression lzs
  anyconnect modules value iseposture
  anyconnect profiles value SECUREBANK type user
!
tunnel-group DefaultWEBVPNGroup general-attributes
 address-pool vpn-pool
 authentication-server-group ISE
 accounting-server-group ISE
 default-group-policy AC-DOWNLOAD
 scep-enrollment enable
tunnel-group DefaultWEBVPNGroup webvpn-attributes
 authentication aaa certificate
!
tunnel-group SECURE-BANK-VPN type remote-access
tunnel-group SECURE-BANK-VPN general-attributes
 address-pool vpn-pool
 authentication-server-group ISE
 secondary-authentication-server-group DUO
 accounting-server-group ISE
 default-group-policy SECURE-BANK-VPN
 username-from-certificate CN
 secondary-username-from-certificate I
tunnel-group SECURE-BANK-VPN webvpn-attributes
 authentication aaa certificate
 pre-fill-username client
 secondary-pre-fill-username client hide use-common-password push
 group-alias SECURE-BANK-VPN enable
 dns-group ASHES-DNS
!

ื•ื•ื™ื™ึทื˜ืขืจ ืžื™ืจ ืžืึทืš ืื•ื™ืฃ ืฆื• ISE:

ืžื™ืจ ืงืึทื ืคื™ื’ื™ืขืจ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ (ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ AD/LDAP/ODBC, ืืื–"ื• ื•), ืคึฟืึทืจ ืคึผืึทืฉื˜ืขืก, ืื™ืš ื‘ืืฉืืคืŸ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ ISE ื–ื™ืš ืื•ืŸ ืึทืกื™ื™ื ื“ ืขืก ืื™ืŸ ื“ืขื ืคืขืœื“ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ UDID PC ืคื•ืŸ ื•ื•ืึธืก ืขืจ ืื™ื– ืขืจืœื•ื™ื‘ื˜ ืฆื• ืงืœืึธืฅ ืื™ืŸ ื“ื•ืจืš VPN. ืื•ื™ื‘ ืื™ืš ื ื•ืฆืŸ ื”ื™ื’ืข ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ISE, ืื™ืš ื•ื•ืขื˜ ื–ื™ื™ืŸ ืœื™ืžื™ื˜ืขื“ ืฆื• ื‘ืœื•ื™ื– ืื™ื™ืŸ ืžื™ื˜ืœ, ื•ื•ื™ื™ึทืœ ืขืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืคื™ืœืข ืคืขืœื“ืขืจ, ืึธื‘ืขืจ ืื™ืŸ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ืึทื˜ืึทื‘ื™ื™ืกื™ื– ืื™ืš ื•ื•ืขื˜ ื ื™ืฉื˜ ื”ืึธื‘ืŸ ืึทื–ืึท ืจื™ืกื˜ืจื™ืงืฉืึทื ื–.

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ื–ืืœ ืก ืงื•ืง ืื™ืŸ ื“ื™ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืคึผืึธืœื™ื˜ื™ืง, ืขืก ืื™ื– ืฆืขื˜ื™ื™ืœื˜ ืื™ืŸ ืคื™ืจ ืงืึทื ืขืงืฉืึทืŸ ืกื˜ืึทื’ืขืก:

  • Stage 1 - ืคึผืึธืœื™ื˜ื™ืง ืคึฟืึทืจ ื“ืึทื•ื ืœืึธื•ื“ื™ื ื’ ื“ื™ AnyConnect ืึทื’ืขื ื˜ ืื•ืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ
  • Stage 2 - ืขืจืฉื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืึธืœื™ื˜ื™ืง ืœืึธื’ื™ืŸ (ืคึฟื•ืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ) / ืคึผืึทืจืึธืœ + ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืžื™ื˜ UDID ื•ื•ืึทืœืึทื“ื™ื™ืฉืึทืŸ
  • Stage 3 - ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš Cisco DUO (MFA) ื ื™ืฆืŸ UDID ื•ื•ื™ ื ืืžืขืŸ + ืฉื˜ืึทื˜ ืึทืกืกืขืกืกืžืขื ื˜
  • Stage 4 - ืœืขืฆื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืื™ื– ืื™ืŸ ื“ื™ ืฉื˜ืึทื˜:
    • ื’ืขื”ืึธืจื›ื™ืง;
    • UDID ื•ื•ืึทืœืึทื“ื™ื™ืฉืึทืŸ (ืคึฟื•ืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ + ืœืึธื’ื™ืŸ ื‘ื™ื™ื ื“ื™ื ื’),
    • ืกื™ืกืงืึธ ื“ื•ืึธ ืžืคืึท;
    • ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš ืœืึธื’ื™ืŸ;
    • ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ;

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืœืึธืžื™ืจ ืงื•ืงืŸ ืื•ื™ืฃ ืึท ื˜ืฉื™ืงืึทื•ื•ืข ืฆื•ืฉื˜ืึทื ื“ UUID_VALIDATED, ืขืก ื ืึธืจ ืงื•ืงื˜ ื•ื•ื™ ื“ืขืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ื™ื ื’ ื‘ืึทื ื™ืฆืขืจ ืึทืงืฉืœื™ ื’ืขืงื•ืžืขืŸ ืคึฟื•ืŸ ืึท ืคึผื™ืกื™ ืžื™ื˜ ืึท ืขืจืœื•ื™ื‘ื˜ UDID ืคึฟืึทืจื‘ื•ื ื“ืŸ ืื™ืŸ ื“ืขื ืคืขืœื“ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ ื—ืฉื‘ื•ืŸ, ื“ื™ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืงื•ืงืŸ ื•ื•ื™ ื“ืึธืก:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ื“ืขืจ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืคึผืจืึธืคื™ืœ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืกื˜ืึทื’ืขืก 1,2,3 ืื™ื– ื•ื•ื™ ื’ื™ื™ื˜:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืื™ืจ ืงืขื ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืคึผื•ื ืงื˜ ื•ื•ื™ ื“ื™ UDID ืคึฟื•ืŸ ื“ื™ AnyConnect ืงืœื™ืขื ื˜ ืงื•ืžื˜ ืฆื• ืื•ื ื“ื– ื“ื•ืจืš ืงื•ืงืŸ ืื™ืŸ ื“ื™ ืงืœื™ืขื ื˜ ืกืขืกื™ืข ื“ืขื˜ืึทื™ืœืก ืื™ืŸ ISE. ืื™ืŸ ื“ืขื˜ืึทืœ ืžื™ืจ ื•ื•ืขืœืŸ ื–ืขืŸ ืึทื– AnyConnect ื“ื•ืจืš ื“ื™ ืžืขืงืึทื ื™ื–ืึทื ืึทืกื™ื“ืขืงืก ืกืขื ื“ื– ื ื™ื˜ ื‘ืœื•ื™ื– ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืคึผืœืึทื˜ืคืึธืจืžืข, ืึธื‘ืขืจ ืื•ื™ืš ื“ื™ UDID ืคื•ืŸ ื“ื™ ืžื™ื˜ืœ ื•ื•ื™ ืกื™ืกืงืึธ-ืึทื•ื•-ืคึผืึทื™ืจ:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ื–ืืœ ืก ื‘ืึทืฆืึธืœืŸ ื•ืคืžืขืจืงื–ืึทืžืงื™ื™ึทื˜ ืฆื• ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืืจื•ื™ืก ืฆื• ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื“ื™ ืคืขืœื“ ืื™ื ื™ืฆื™ืืœืŸ (ืื™ืš), ื•ื•ืึธืก ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื ืขืžืขืŸ ืขืก ื•ื•ื™ ืึท ืœืึธื’ื™ืŸ ืคึฟืึทืจ ืฆื•ื•ื™ื™ื˜ื™ืง ืžืคืึท ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ Cisco DUO:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืื•ื™ืฃ ื“ื™ DUO Radius Proxy ื–ื™ื™ึทื˜ ืื™ืŸ ื“ื™ ืงืœืึธืฅ ืžื™ืจ ืงืขื ืขืŸ ืงืœืืจ ื–ืขืŸ ื•ื•ื™ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื‘ืขื˜ืŸ ืื™ื– ื’ืขืžืื›ื˜, ืขืก ืงื•ืžื˜ ืžื™ื˜ UDID ื•ื•ื™ ื“ื™ ื ืืžืขืŸ:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืคึฟื•ืŸ ื“ื™ DUO ื˜ื•ื™ืขืจ ืžื™ืจ ื–ืขืŸ ืึท ื’ืขืจืึธื˜ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื’ืขืฉืขืขื ื™ืฉ:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ืื•ืŸ ืื™ืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืคึผืจืึธืคึผืขืจื˜ื™ืขืก ืื™ืš ื”ืึธื‘ืŸ ืขืก ืฉื˜ืขืœืŸ ืขืœื™ืึทืก, ื•ื•ืึธืก ืื™ืš ื’ืขื•ื•ื™ื™ื ื˜ ืคึฟืึทืจ ืœืึธื’ื™ืŸ, ืื™ืŸ ืงืขืจ, ื“ืึธืก ืื™ื– ื“ื™ UDID ืคื•ืŸ ื“ื™ ืคึผื™ืกื™ ืขืจืœื•ื™ื‘ื˜ ืคึฟืึทืจ ืœืึธื’ื™ืŸ:

ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ื”ืขื›ืกื˜ ื–ื™ื›ืขืจ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืžื™ืจ ื”ืึธื‘ืŸ:

  • ืžื•ืœื˜ื™-ืคืึทืงื˜ืึธืจ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ืžื™ื˜ืœ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ;
  • ืฉื•ืฅ ืงืขื’ืŸ ืกืคึผืึธืึธืคื™ื ื’ ืคื•ืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ 'ืก ืžื™ื˜ืœ;
  • ืึทืกืกืขืกืก ื“ื™ ืฆื•ืฉื˜ืึทื ื“ ืคื•ืŸ ื“ื™ ืžื™ื˜ืœ;
  • ืคึผืึธื˜ืขื ืฆื™ืขืœ ืคึฟืึทืจ ื’ืขื•ื•ืืงืกืŸ ืงืึธื ื˜ืจืึธืœ ืžื™ื˜ ืคืขืœื“ ืžืึทืฉื™ืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ, ืขื˜ืง;
  • ืคื•ืœืฉื˜ืขื ื“ื™ืง ืฉื•ืฅ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ื•ื•ืขืจืงืคึผืœื™ื™ืก ืžื™ื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ื™ืคึผืœื•ื™ื“ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžืึทื“ื–ืฉื•ืœื–;

ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืฆื• Cisco VPN ืกืขืจื™ืข ืึทืจื˜ื™ืงืœืขืŸ:

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’