Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Array > ¡m¤À¨É¡nSSL VPN (¤@) Virtual Site»PRoleªº«Ø¥ß «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nSSL VPN (¤@) Virtual Site»PRoleªº«Ø¥ß¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

ArrayªºSSL VPN¬[ºc¦p¤U¡C



¦b¨Ï¥ÎªÌ³z¹L¼Ð·ÇªºSSL¥[±K¨ó©w³s¤JArray AG appliance®É¡A
¥i¨Ì·Ó¨Ï¥ÎªÌªº¤£¦P¡Aµ¹¤©¤£¦Pªº¸ê·½¡C

³o¨Ç¥i¤À°t¸ê·½¥]¬A¡Aºô¯¸³sµ²¡BVPN Tunnel¡B»·ºÝ®à­±¦s¨ú»P»·ºÝ®à­±À³¥Îµ{¦¡µ¥¡C
¦b¸ê·½ªº¤À°t¤W´N¹³¿n¤ì¤@¹³¡A¥i¨Ì·Ó¸s²Õ©Î­Ó¤H¦U¦Û¤£¦Pªº»Ý¨D¨Ó²Õ¦X«Ø¥ß¡A
¦Ó©Ò¿×ªºWeb Portal´N¬O´£¨Ñ³o¨Ç¸ê·½²Õ¦Xªº¤@­Ó¤J¤f¡C

¦bArray AG¤W´£¨Ñ¤F256­Ó¦U¦Û¿W¥ßªºµêÀÀ¥­¥x¨Ó¶i¦æ§G¸pWeb Portal¡C


¬°¤°»ò­n¿ï¾ÜArrayªºAG°µ¬°SSl VPNªº§G¸p©O¡H

  1. ±M§QSpeed Core§Þ³N¡A¤£»ÝASIC´¹¤ù¡A³t«×§Ö¡C
  2. ¤ä´©¦h¼h¡B¦hºØÅçÃÒ¡A¥]§tlocalDB¡BAD¡BLDAP¡BRADIUS¡B¾ÌÃÒµ¥¦hºØ¥D¬yªºÅçÃҤ覡¡F¤ä´©¤F¥«­±¤W90%¥H¤WªºÅçÃҤ覡¡C
  3. µêÀÀ¤Æ§Þ³N(Web Portal)¡A¦U¦Û¿W¥ßªºÀô¹Ò¡A¤è«KºÞ²z¡C
  4. ¦P¤@­Óµn¤J±b¸¹¡A¤£¦P®É¶¡¡A¤£¦Pªº¦aÂI»PÅçÃÒ¤èªk¥i¥H¹ïÀ³¨ì¤£¦Prole¡A¦Ó¦³µÛ¤£¦Pªº¨Ï¥Î¸ê·½¡A³]©w¼u©Ê¤S¦w¥þ¡C
  5. ¤£¦Prole¡A¥i³]©w¤£¦P¸ô¥Ñ¾É¦V¡A³z¹L¤£¦PªºGatewayÀW¼e¥~¥X¡C


¦bÁA¸Ñ¤FArray AGªº¬[ºc»P¯S©Ê«á¡A§G¸pAG®É¥i¥Ñ¥H¤U´X­Ó­«ÂI¨Ó¶i¦æ¡C
  1. «Ø¥ßVirtual Site¡A³o¬O©Ò¦³¸ê·½¿n¥»°ïÅ|ªº°_ÂI¡C
  2. ³]©wAuthentication¡AAuthorization»PAccounting¡A§YAAA¡C
  3. ³]©w¨¤¦ârole»Ppolicy¡C
  4. ¤À°t¸ê·½¡C



AG¦b²Ä¤@¦¸µn¤J¨Ï¥Î¤W¡A»P APV ¬Û¦P¡C
³z¹Lconsole½u³s¤J¡A³]©w¦nWebUI IP»Pport¨Ã±Ò¥Î«á¡A´N¥i¥H³z¹LWeb¨Óµn¤J¡C
µn¤JAG«áªº²Ä¤@µe­± Home Åã¥Ü¸ê°T¦p¤U¡C

±ÂÅv±Ò¥Î«á¡A§Ú­Ì´N¥i¥H³v¤@¨Ó«Ø¸mSSL VPN¤F¡ã

¤§«á°µ¥ô¦óÅܧó¡A³£¸òAPV¤@¼Ë­n°O±oÀx¦s¡A³o¼Ë©Ò¦³ªºÅܧó¤~¤£·|ÀHµÛ­«¶}¾÷¦Ó®ø¥¢¡I



«Ø¥ßVirtual Site
«Ø¸mAGªº²Ä¤@¨B¬O«Ø¥ß¤@­ÓVirtual Site¡C
¦³¤FVirtual Site«á¡AAAA»P¸ê·½ªº¤À°t¤~¯à¤@¨B¤@¨Bªº¨Ì»Ý¨D¨Ó°ïÅ|¦b¦¹µêÀÀ¥­¥x¤§¤W¡C

¦bVIRTUAL SITES / Virtual Sites / Virtusl Sites­¶ÅÒ¤¤§Ú­Ì³z¹L ADD ¨Ó«Ø¥ß²Ä¤@­ÓVirtual Site¡C


©óVirtual Site¤¤¶ñ¦n¯¸¥x¸ê°T¤Î¹ïÀ³ªºSSL¾ÌÃÒ¸ê°T«á¡A«ö¤U SAVE §Y¥i·s¼W¦¹Virtual Site¡C


Virtual Site«Ø¥ß§¹¦¨¡A¥X²{¦b²M³æ¤§¤¤¡C


¦b«Ø¥ßVirtual Site®É¡A·|µo²{¥¦¦@¦³4ºØÃþ«¬¡C

³Ì°ò¥»ªº¬Oexclusive¡A¦Óshared/alias¬O¦¨¹ï¨Ï¥ÎªºÃþ«¬¡AMotionPro«h¬O«Ø¥ßµ¹Pad/Phoneµ¥¦æ°Ê¸Ë¸mªºµêÀÀ¥­¥x¡C

«Ø¥ß¦n²Ä¤@­ÓVirtual Site«á¡A§Ú­Ì¤w¸g¥i¥H¥Î³]©wªºIP¡A³z¹Lhttps¨Ó¥´¶}ºô­¶Web Portal¡C

¤£¹L¦]¬°§Ú­ÌÁÙ¥¼«Ø¥ß¦¹Virtual SiteªºAAA¡A©Ò¥H·|¥X²{¦p¤W¡§¥¼«ü©w¦øªA¾¹¤èªk¡¨ªº°T®§¡C
³o¬O§Ú­Ì²Ä¤G¨BÆJ§Y±N¶i¦æªº«Ø¸m¤u§@¡C

­n¤Á´«¨ìVirtual Site¨Ó¶i¦æAAA¤Î¸ê·½°t¸m¡A§Ú­Ì­n³z¹L¥ª¤W¤èªº¤U©Ô¦¡¿ï³æ¨Ó¶i¦æ¡C


¤Á´«¨ì·s«ØªºVirtual Site«á¡A§Ú­Ì¥i¥H¬Ý¨ì¦¹¥­¥xªº¬ÛÃö¸ê°T¡C
¤§«áªºAAA¤Î¸ê·½°t¸m¤]³£¬O¦b¦¹¥­¥x¤U¨Ó¶i¦æ¡C


¦b«Ø¸mVirtual Site®É¡A¯¸¥xªºIP°t¸m·|¦b¾Þ§@Àô¹Ò¤¤¤À°t¨Ã¥ß§Y¥Í®Ä¡C

¦]¦¹¦b³W¹ºVirtual SiteªºIP®É¡A½Ð¤£­n¸ò¨ä¥¦Virtual Site©Î²{¹êÀô¹Ò¤¤ªºIP¬Û½Ä¬ð¡I
­YÀô¹Ò¤¤IP¼Æ¶q¤£¨¬ªº¸Ü¡A¤]¥i¥H¥ÎIP¥[¤Wport¨ÓÅܤƨϥΡC


AAA
¥Ñ©óAGªº¨C­ÓVirtual Site³£¬O¿W¥ßªº¡A¦]¦¹¨C­ÓSiteªºAAA»P¸ê·½¤À°tµ¥¡A¦ÛµM³£¬O¦b­Ó§OªºSite¤¤¨Ó¶i¦æ¡C
¤Á´«¨ìVirtual SiteºÞ²z­¶­±«á¡A
¦bSITE CONFIGURATION / AAA / Server­¶ÅÒ¤¤§Ú­Ì¥i¥H«Ø¥ßAAAªº¦øªA¾¹¸ê°T¡C

§Ú­Ì¤]¥i¥H¬Ý¨ìAG¦@¤ä´©¤FLDAP(AD)¡ARADIUS¡AClient¾ÌÃÒ¡ALocalDB¡ASMS»PSMXµ¥Ãþ«¬ªºÅçÃҤ覡¡C

§Ú­Ì¥HAG¥»¨­ªºÅçÃÒLocalDB¬°¨Ò¡A¥Ü½d¦p¦ó¥ÎLocalDB¨Ó°µAuthentication»PAuthorization¡C

¤Ä¿ï Enable LocalDB Server «á«ö¤UÀx¦s¡A§Y¥i±Ò¥Î¥»¾÷ÅçÃÒ¡ã

µM«á¨ìMethod­¶ÅÒùØ¡A·s¼W¤@­ÓAAA¤èªk¡C


«ü©w³o­ÓVirtual SiteªºÅçÃÒ»P±ÂÅv¤èªk¬°LocalDB¡C

¦b§Ú­Ì±Ò¥Î¥»¾÷ªºLocalDBÅçÃÒ«á¡AAG·|¬°¦¹Virtual Site«Ø¥ß¤@­Ó»PVirtual Site¦WºÙ¬Û¦Pªº¸ê®Æ®w¡C
¥H¥»¨Ò¬°¨Ò¡A¦¹¸ê®Æ®w¦WºÙ§Y¬° vSite_1¡C
¦bAuthentication»PAuthorization¤¤¬Ý¨ìªº¦WºÙ vSite_1 §Y¬°¦¹LocalDBªº¦WºÙ¡C

·íµM­Y§Ú­Ì¦³»Ý­n¡A¤]¥i¥H¥[¤JLDAP(AD)¡BRADIUSµ¥ÅçÃҤ覡¨Ó°t¦X¡C

³]©w§¹¦¨«á¡AMethod²M³æ¤¤·|¥X²{³o¤@µ§¡C



³]©wRole
Virtual Site¤¤³]©w¦n¤FAAA¤§«á¡A±µµÛ§Ú­Ì¨Ó³]©wRole¡C
¦bUSER POLICIES / Role / Role­¶ÅÒ¤¤¡A¿é¤JRole Name»P´y­z«á¡A«ö¤U Add a Role ¨Ó·s¼W¤@­Ó¨¤¦â¡C




µM«á¦bRole Qualification­¶ÅÒ¤¤«ö¤U ADD ¨Ó·s¼W¤@­Ó Qualification¡C


©óQualification¤¤¿ï¾ÜRole¨Ã³]©w±ø¥ó¡C
¦b³oÃä§Ú­Ì³]©w±ø¥ó¬°¸g¹LLocalDBªº±ÂÅv(Auth Method IS LocalDB)«áªºRole¬°­è¤~«Ø¥ßªºRole_Default¡C
«ö¤U Select «ö¶s¨Ó¿ï¾ÜÅçÃÒ¨Ó·½Method¡C


±µµÛ·|¥X²{©Ò¦³¥i¥Îªº Method ¥H¨Ñ³]©w¡A¥Ñ§Ú­Ì¦b Method ¤¤¥u³]©w¤F¤@­ÓLocalDBªºAAA¡A©Ò¥H³oÃä¥u¦³¤@µ§¤èªk¥i¨Ñ¿ï¾Ü¡C

¿ï¾Ü­n¨Ï¥Îªº¤èªk«á¡A«ö¤U OK¡C

Content¥X²{¤F§Ú­Ì­nªºLocalDB«á¡A«ö¤U Add «ö¶s¡A§â¥¦¥[¤J¡C


QualificationªºÄæ¦ì¬Ò¤w¶ñ§´¡A«ö¤U Save ¶i¦æÀx¦s¡C

³o¤@¾ã­Óªº³]©w·N«ä¬O¡§¸g¹LLocalDB±ÂÅv«áªº¨Ï¥ÎªÌ¡A¨äRole¬°Role_Default¡A¥i¨Ï¥Î°t¸mRole_Defaultªº¸ê·½¡¨¡C

Àx¦s«áQualification²M³æ¤¤·|¥X²{³o¤@µ§¡C


¨ì³oÃä¦A³z³]©wªºIP¨Ó¥´¶}VPNºô­¶®É¡A§Ú­Ì·|µo²{µn¤J­¶­±Web Portal¤w¸g¥X²{±b¸¹/±K½X¥i¨Ñµn¤J¤F¡C

¦ý¬O§Ú­Ì¦bLocalDBÁÙ¨S¦³«Ø¥ß¥ô¦ó±b¸¹¡A©Ò¥H¥Ø«e¬OµLªkµn¤Jªº¡C

­n¦b¥»¾÷ªºLocalDB«Ø±b¸¹¡A§Ú­Ì­n¨ìLOCAL DATABASE¤¤ªºLocal Accounts¨Ó¶i¦æ¡A
«ö¤U Add ¨Ó·s«Ø¤@­ÓLocalDBªº±b¸¹¡C


¿é¤J±z±ý«Ø¥ßªº±b¸¹/±K½X«á¡A«ö¤U Save «Ø¥ß±b¸¹¡C


Àx¦s«á¡A§Ú­Ì´N¥i¥H¦b²M³æ¤¤¬Ý¨ì­è¤~«Ø¥ßªº±b¸¹¡C


¦^¨ìVPNµn¤Jºô­¶Web Portal¡A¿é¤J±b¸¹/±K½X¡C


§Ú­Ì·|µo²{±b¸¹²{¦b¤w¸g¥i¥H´£¨Ñµn¤J¤F¡ã

ÁöµMµn¤J«áªº¨¤¦â¬ORole_Default¡A¦ý¦]¬°ÁÙ¨S¦³°t¸mRole_Defaultªº¥ô¦ó¸ê·½¡A
©Ò¥H¥X²{ªº­¶­±¬OªÅ¥Õªº¡A¬Ý¤£¨ì¥ô¦ó¸ê·½¡A
¤£¹L¤§«á¸ê·½«Ø¥ß«á¡A°O±o­n«ö¤WÂsÄý¾¹¤W¤èªºJava°õ¦æ±ÂÅv¡A
±ÂÅvµ¹Java«á¡A°t¸mªº¸ê·½¤~¯à¥¿±`¨Ï¥Î³á¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2014-07-27, 19:33 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
³z¹LLDAPÅýActive Directory¨Ï¥ÎªÌ°µ¬°±b±K¨Ó·½¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bAG¤¤­Y±ý³z¹L¬J¦³¤§Active Directory°µ¬°±b¸¹/±K½X¨Ó·½¡A
ÅýAD¤Wªº¨Ï¥ÎªÌ¯à°÷µn¤JAG¡A§Ú­Ì¥i¥H³z¹LLDAP¨Ó¹F¦¨¡C

¦bSITE CONFIGURATION / AAA / Server / LDAP­¶ÅÒ¤¤¡A
§Ú­Ì¥i¥H«Ø¥ß­n¨Ï¥ÎªºLDAP¸ê·½¡C


«Ø¥ß¦nLDAP Server¦WºÙ«á¡A¦b¸Óµ§¸ê®Æ³sÂI¨â¤U¡A¥i¶i¤J½s¿è¸Ô²Ó³]©w¡C


¦bLDAPªº¸Ô²Ó³]©w¤¤¡ASearch Filter­n¥´ sAMAccountName=<USER>¡A
Group Attribute­n¥´ memberOf¡AµM«á«ö¤UAPPLY CHANGES¡C
ª`·N¡A³o¨Ç¦r¦ê¦³¤j¤p¼gªº®t§O¡I

µM«á¦A«ö¤UAdd LDAP Server«ö¶s¡A¨Ó·s¼WAD¥D¾÷ªº¬ÛÃö¸ê°T¡C


AD¥D¾÷¬ÛÃö¸ê°T¿é¤J§¹¦¨«á¡A«ö¤USaveÀx¦s¡C


³o¼ËADªºLDAP²ÕºA´N³]©w¦n¤F¡C



µM«á¦bSITE CONFIGURATION / AAA / Method¤¤¡A§Ú­Ì­n«Ø¥ß³z¹LLDAPÅçÃҤαÂÅvªº¤èªk¡C


±NAuthentication¤ÎAuthorization§¡«ü¦V­è¤~«Ø¥ßªºLDAP¡C





LDAP«Ø¥ß§¹¦¨«á¡A¦A¨Ó¤À°t¥i¨Ï¥Î¦¹µêÀÀ¥­¥xªº¨¤¦âµ¹LDAP¡C
¦bUSER POLICIES / Role¤¤¡A·s«Ø¤@­Ó¨¤¦â¡C




µM«á¦bUSER POLICIES / Role Qualification¤¤¡A«Ø¥ß¦¹¨¤¦â¹ïÀ³ªºÅçÃÒ¤èªk¡C




ÅçÃÒ¤èªk·íµM¬O«ü¦V§Ú­Ì­è¤~«Ø¥ßªºLDAPÅçÃÒ¤èªkÅo¡ã


«ö¤UAdd«ö¶s¡A§âLDAPÅçÃÒ¤èªk¥[¤J¡C


³]©w§¹¦¨«á¡A«ö¤USaveÀx¦s¡C




¥H¬J¦³¤§AD°µ¬°±b¸¹/±K½X¨Ó·½¡A
ÅýAD¤Wªº¨Ï¥ÎªÌ¯à°÷µn¤JAGªº³]©w¨ì³oÃä´N§¹¦¨Åo¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2014-09-17, 18:26 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR