¡m¤À¨É¡nSSL VPN (¤) ¦æ°Ê¥¥xªº«áÄ~¤è®×MotionPro | |
Array SSL VPNªº¦æ°Ê¸Ë¸mAPP - DesktopDirect ¦]¬Y¨Ç¦]¯À©ó2014/7/1¤U¬[¡F
2014/7/1«á¡A¨Ï¥ÎªÌµLªk©óAPP¥«¶°¤U¸üDD¡A¥u¯à³z¹L¦Û¦æ¬[¯¸ªº¤è¦¡¨Ó¤U¸ü¦w¸ËDD¡C
Array´£¥Xªº«áÄ~¦æ°Ê¤è®×¬°MotionPro¡A¤@Ó¤£¦P©ó¥H©¹DDªº¦æ°Ê¥¥x¡C
MotionPro¬O¤@ÓVitual Site¡A¸òÄݩ󡧸귽¡¨ªºDD¤j¤£¬Û¦P¡C
MotionPro¦b»·ºÝ®à±ªº°t¸m¤W¡A¸ò¤@¯ëVirutal Site¤@¼Ë¡A¥i¥H°ïÅ|¸ê·½¡A·íµM¤]¥]¬A¤FDD¡C
¥¿¦]¬°MotionPro¬O¤@ÓVirtul Site¡A¤£¬O°õ¦æ»·ºÝ®à±ªºAPP¡A
©Ò¥H¦bMotionPro¤W°õ¦æ»·ºÝ®à±¸ê·½®É¡AÁÙn¦A¦w¸Ë·L³nªºRD Client APP¤~¦æ¡C
³z¹LVPN tunnelªº«Ø¥ß«á¡A¦æ°Ê¸Ë¸m¨Ï¥ÎªÌªºRD Client¤~¥i¥H³z¹L¦¹³q¹D³s½u¨ì»·ºÝ¥D¾÷¡C
¦bµwÅé¸ê·½¤W¡AMotionPro¤w¸g¤£¦A¤ä´© Array SPX ¤F¡C
¦ÓArray AG¥Î¤á¡A¥²»Ý§â¶´Å骩¤É¯Å¨ì 9.3.0.79 ¥H¤W¤~¤ä´©MotionPro¡C
¦¹¥~¦æ°Ê¥Î¤áªºOSª©¥»¤]¦³¹ïÀ³n¨D¡A
Andorid¥¥xn 4.0 ¥H¤W¡AiOS¥¥x«h¬O 6.0 ¥H¤W³£¥i¦w¸Ë¨Ï¥ÎMotionPro¡C
¦Ó°£¤F³]©wªº³s±µ°ðn¶}©ñ¥H¥~¡A
¹ïÀ³iOS¦æ°Ê¸Ë¸m®É¡AÁÙn¦A¥[¶}UDP 500¡A4500³o¨âÓport¤~¯àÅýVPN Tunnel¶¶§Q«Ø°_¨Ó¡I
³o¬O¶¶¤l¦bºGµhªº´ú¸Õ¨â¤Ñ«á¤~§ä¨ìªº°ÝÃDÂI...
MotionPro¥¥xªºµo§G³]©w
¦]¬°MotionPro¬O¤@ºØVirtual Site¡A©Ò¥H¦b«Ø¸m¤W¤@¼Ë¬O¨ì Base System / VIRUTAL SITE / Virtual Site / Virtual Site ¤¤«Ø¥ß¡C
nª`·Nªº¬O Virtual Site Type n¿ï MotionPro ³á¡I
«Ø¥ß§¹¦¨¡A¶i¤JMotionProªºVirtual Siteº¶¡A¥i¥H¬Ý¨ì³s¨ì MotionPro Pilot ªº³sµ²¡C
MotionPro Pilot´N¸òDD Pilot¤@¼Ë¡A¦³µÛ¬Û¦üªº¿W¥ß³]©w¶±¡F
¦ý¤S¸òDD¦b¤º®e¤W§¹¥þ¤£¦P¡A¬O¨âºØ¤£¦PªºªF¦è¡C
MotionPro Pilot
¶i¤JMotionPro Pilot«á¡A²Ä¤@Ó¥\¯à¶ÅÒ¬OSystem Monitor¡A¥Î¨ÓºÞ²z¦æ°Ê¸Ë¸m¡C
¨Ï¥ÎªÌªº³]©w¡B¸ê·½°t¸mµ¥¬O¦b²Ä¤GÓ¶ÅÒSite Settings¤¤¶i¦æ¡C
§ÚÌ¥ý¦b AAA ¤¤¶i¦æ¨Ï¥ÎªÌ»P¸s²Õªº³]©w¡C
¨Ï¥ÎªÌªº¨Ó·½¡A¶¶¤l¥H±`¥ÎªºAD¬°¨Ò¡A¿ï¾ÜÅçÃҤ覡¬° LDAP¡AµM«á«ö¤U + ¸¹¡A·s¼W¤@ÓAD²ÕºA¡C
±µµÛ¦bADVANCED LDAP CONFIGURATIONS¤¤¡A³]©w LDAP Attribute Group ¬° memberOf¡A
Search Filter ¬° sAMAccountName=<USER>¡C
³o³¡¥÷«Ü«n³á¡I
¦]¬°¥¦¨M©w¤FAD¤¤¸s²Õªº§PÂ_¨Ì¾Ú¡A©Ò¥H¤@©wn¥´¥¿½T¡C
¦b DEVICEID ¤¤¡A¥i¤Ä¿ï Auto Approve¡AÅý¦æ°Ê¸Ë¸m¥i¥H¦Û°Ê³Qapprove¡C
·íµMY±z¤£§Æ±æ¦æ°Ê¸Ë¸m¦Û°Ê³Qapprove¡A§Æ±æ³z¹LºÞ²zûªº¬d®Ö«á¦A¤©¥H©ñ¦æªº¸Ü¡A
´N¤£n¤Ä³oӿﶵ¡C
Authorization»PGroup Mapping
ÅçÃÒªº¨Ó·½«ü©w¦n¨Ã³]©w§¹¦¨«á¡A±µµÛ´Nn¹ï»{ÃÒ¹Lªº±b¸¹¶i¦æ±ÂÅv¡C
³oÃä¬Ý¨ìªºUser«üªº¬O¥»¦aUser¡A
¦Ó§Ú̪º¨Ï¥ÎªÌ¨Ó·½¬OAD¡A©Ò¥H´N¤£¥Î³]©wUser¤F¡C
¦ýMotionPro¸ê·½ªº°tµo¬O¨Ì¾ÚUser©ÎGroup¡A
¥B¥~³¡¨Ï¥ÎªÌ¨Ó·½¥u¯à¥HGroup Mappingªº¤è¦¡¨Ó¶i¦æ¡A
©Ò¥H§Ú̫إߤ@Ó¥»¾÷ªºGroup¡A¨ä¥Î³~¬Oµ¹AD¤WªºGroup¨Ó°µMapping¡A¥H°t¸m¹ïÀ³¸ê·½¡C
¥»¾÷Group«Ø¥ß«á¡A«ö¤UGroup Mapping¨Ó°µADªº¸s²Õ¹ïÀ³¡C
¥»¾÷¸s²ÕµLºÃªº´N¬O§ÚÌè¤~«Ø¥ßªº¨º¤@Ó¡A
¦ýAD¸s²Õ¤S¬O°Ñ¦Ò¦ÛAD¤¤ªº¤°»ò©O¡H
µª®×´N¬O§ÚÌè¤~«ØAD²ÕºA®É¡A©Ò¶ñªº memberOf¡C
§Ú̳s¶iAD¤¤ªºADSI½s¿è¾¹¡A¥ô¿ï¤@ӨϥΪ̱b¸¹¡A¬d¬Ý¨ä¤º®e¡C
Åã¥Ü¡§¤Ï¦V³sµ²¡¨ÄÝ©Ê¡A
§ÚÌ¥i¥H¬Ý¨ì¨Ï¥ÎªÌ©ÒÄݪº¸s²Õ´N¦b³oùØ¡C
¦b°µGroup Mapping®É¡A¥un¬O¥X²{¦b memberOf ¤¤ªº¸s²Õ¦WºÙ´N¥i¥H®³¨Ó°µ¬°MappingªºGroup¦WºÙ¡C
¨Ò¦p¶¶¤l«Ø¥ßªºAD¸s²Õ VPN¡C
³oÃä´£¿ô¤j®a¤@Ó¶¶¤lµo²{ªºª¬ªp¡A
¨º´N¬OAD¹w³]ªº¸s²Õ Domain Users ¤£¦b memberOf ²M³æ¤§¤¤¡A
©Ò¥H Domain Users µLªk¥Î¨Ó°µ¬°Group Mapping¡I
¸ê·½°t¸m
MotionPro¥i°t¸mªº¸ê·½¥]¬Aºô¶¤ÎL7ªºapplications¡C
³oùضȥH²³æªººô¶¸ê·½°µÓ¥Ü½d¡C
³]©w¦nªº¸ê·½°O±on°t¸mµ¹Group¡C
¨ä¥¦
MotionPro³]©w¨ì³oÃä°ò¥»¤W´Nºâ§¹¦¨Åo¡C
µ¥µ¥¡I¡H
¨º»·ºÝ®à±©O¡H»·ºÝ®à±ªº¸ê·½°t¸mÁÙ¨S¤À¨É°Ú¡I
¼K¡A¤£n§Ñ¤FMotionPro¬O¤@ÓVirtual Site¡A
¦ÓVirtual Siteªº»·ºÝ®à±¸ê·½¬O³z¹LDD¤¤ªº±b¸¹/¸s²Õ¨Ó¤ñ¹ïªº¡C
¥un±zµn¤JMotionProªº±b¸¹¦bDDªº±b¸¹/¸s²Õ²M³æ¤¤¡A´N·|¥D°Ê°t¸mDD¤¤ªº»·ºÝ±¸ê·½¡C
¸ò¤@¯ëVirtual Siteªº®t§O¦b©ó¤@¯ëVirtual Site»Ýn¦b SITE CONFIGURATION / Portal / DesktopDirect ±Ò¥ÎDDªº¾ã¦X¥\¯à¡F
¦ÓMotionPro°µ¬°DDªº«áÄ~¦æ°Ê¤è®×¡ADDªº¾ã¦X¤w¤º«Ø¦b¨ä¤¤¡A¨Ï¥ÎªÌ¨Ã¤£»Ýn¯S§O¥h¾ã¦X¥¦¡C
¡ô¤@¯ëVirtual Site»Ýn¤â°Ê±Ò¥ÎDDªº¾ã¦X¡C
¦¹¥~¦b¹w³]ªº±¡ªp¤U¡A¥¦·|¦Û¤v«Ø¥ß¤@Ó0.0.0.0/0ªºVPN tunnel¡A¨Ñ¨Ï¥ÎªÌ³s½u¨Ï¥Î¸ê·½¡C
³o³¡¥÷¬O¦Û°Ê«Ø¥ßªº¡A¤£¥Î¯S§OºÞ¥¦¡C
¥t¥~¥¦¸òDD¤£¦P¡A°õ¦æ»·ºÝ®à±®É¡A¤£¬O¥ÑDD¨Ó°õ¦æ¡F
¦Ó¬O¥ÑRD Client¨Ó°õ¦æ¡A©Ò¥HµLªk¸òDD¤@¼Ë¶i¦æSSO¡C
³»¦h¬O¦bRD Clien³Q©I¥s°õ¦æ®É¡A¨Ï¥ÎªÌ¥i¥H¤â°Ê¤Ä¿ï¡§°O¿ý±K½X¡¨¨Ó¹F¦¨¤U¦¸µn¤J®É¡A§K¿é¤J±K½Xªº¥\¯à¡C
³Ì«á¡AY¬O¨S¦³¤Ä¿ï¦æ°Ê¸Ë¸m¦Û°ÊApproveªº¸Ü¡A
½Ð°O±o¨ì System Monitor ¶ÅÒ¤¤¶i¦æºÞ²z¡C
¨S¦³Approve¹Lªº¦æ°Ê¸Ë¸m¥i¬OµLªk¥¿±`¨Ï¥Îªº³á¡I
|
|
♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã
If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!
|