Ò»¡¢×éÍøÐèÇó
ÈçÏÂͼËùʾ£ºNGFW×÷ΪÅÔ·ģʽ½ÓÔÚºËÐĽ»»»»úÉÏ£¬ÍâÍøPC²¦ÈëSSL-VPN£¬´Ó¶øÄÜ·ÃÎÊÄÚÍøµÄ·þÎñÆ÷×ÊÔ´192.168.1.3¡£
¶þ¡¢ÅäÖÃÒªµã
1¡¢ÅäÖýӿڵØÖ·¡¢¿ªÆôSSL-VPN
2¡¢ÅäÖÃĬÈÏ·ÓÉ
3¡¢ÅäÖÃÓû§Ãû¡¢Óû§×é
4¡¢ÅäÖÃSSL-VPN
5¡¢ÅäÖÃ×ÊÔ´¡¢×ÊÔ´×é
6¡¢ÅäÖð²È«²ßÂÔ
7¡¢ÔÚ·ÓÉÆ÷ÉÏÅäÖö˿ÚÓ³É䣬½«NGFWµÄtcp 10443¶Ë¿ÚÓ³Éä³öÀ´£¨Â·ÓÉÆ÷µÄÆäËûÅäÖÃÊ¡ÂÔ£©¡£
Èý¡¢ÅäÖò½Öè
1¡¢ÅäÖýӿڵØÖ·¡¢¿ªÆôSSL-VPN
ÅäÖÃge1½Ó¿ÚIPµØÖ·Îª192.168.1.200/24£¬¹´Ñ¡SSL-VPN¹¦ÄÜ¡£
2¡¢ÅäÖÃĬÈÏ·ÓÉ£¬Ö¸Ïò·ÓÉÄÚÍø¿ÚµÄIPµØÖ·192.168.1.1
3¡¢ÅäÖÃÓû§Ãû¡¢Óû§×é
ÅäÖÃÓû§×飺
Óû§×éÀàÐÍSSL-VPN£¬¿ªÆôSSL-VPNͨµÀ·þÎñ¼°¿ªÆô´úÀí·þÎñ£º
4¡¢ÅäÖÃSSL-VPN
¹´Ñ¡¡°ÆôÓÃSSL-VPN¡±
5¡¢ÅäÖÃ×ÊÔ´¡¢×ÊÔ´×é
±¾ÀýÒÔNBR2000×÷Ϊweb·þÎñÆ÷£¬·ÃÎÊNBR2000µÄwebÒ³ÃæURLµØÖ·Îª£º192.168.1.3£¨ÌîдIPµØÖ·¾Í¿ÉÒÔ£¬²»ÄÜдΪhttp://192.168.1.3£©£¬¶Ë¿ÚºÅΪ80
ÅäÖÃ×ÊÔ´×飺
н¨×ÊÔ´×éNBR2000,½«¸Õ²Å½¨ºÃµÄNBR2000×ÊÔ´Ìí¼Ó½øÀ´£º
6¡¢ÅäÖð²È«²ßÂÔ
ÏÈн¨ËùÐèµÄµØÖ·½Úµã£º
Ô´½Ó¿ÚºÍÄ¿µÄ½Ó¿Ú¾ùÑ¡Ôñge1£»
¶¯×÷Ñ¡Ôñ£ºSSL-VPN
ÀàÐÍÑ¡Ôñ:REMOTE-ACCESS
Ñ¡ÔñSSLÓû§×é
ÅäÖúóÐèÒª¹´Ñ¡ÆôÓãº
7¡¢ÅäÖ÷ÓÉÆ÷¶Ë¿ÚÓ³Éä
ip nat inside source static tcp 192.168.1.200 10443 192.168.33.32 10443 permit-inside
ËÄ¡¢Ñé֤Ч¹û
ÍâÍøPCÔÚä¯ÀÀÆ÷ÀïÊäÈ룺https://192.168.33.32:10443£¬ÈçÏÂͼËùʾ£º
ÊäÈëÓû§ÃûÃÜÂëºó£¬½øÈëÈçÏÂÒ³Ãæ£¬µã»÷web×ÊÔ´¼´¿É¿´µ½NBR2000µÄ×ÊÔ´£¬µã»÷¼´¿É½øÈëNBR2000µÄweb¹ÜÀíÒ³Ãæ¡£
ʹÓÃÆ»¹ûÊÖ»ú²âÊÔ£º
ÔÚÊÖ»úÀïÊäÈëhttps://192.168.33.32:10443