Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Sophos XG > ¡m¤À¨É¡nBridge Mode¤â°Ê³]©w «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nBridge Mode¤â°Ê³]©w¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Bridge Mode¾ô±µ¼Ò¦¡¡A¤SºÙTransparent Mode¡A
¤@¯ë¥Î©óµLªk¨ú¥N²{¦³¨¾¤õÀð¡A¦ý¤S·Q¥[±j¬Y°Ï°ì¦w¥þ©Êªº¤@ºØ°µªk¡A
Bridge Mode¤]¬OPoC®É±`¥Îªº¤@ºØ´ú¸Õ¬[ºc¡C



±NBridge Mode¨¾¤õÀð³]©w¦b¬Y°Ï°ì³s¥~ªº³q¹D¡A
³z¹L¨¾¤õÀð¤Wªº¦w¥þ¼Ò²Õ¨Ó¤ÀªR¡B±½´y¬y³q¨ä¤Wªº«Ê¥]¡AÂÇ¥H¹F¨ì¥[±j¦w¥þ©Êªº®ÄªG¡C
¹ê»Ú³¡¸p®É¡A¥i¿ïÁÊ Hardware bypass¼Ò²Õ¡A¥HÁקKBridge Mode¨¾¤õÀ𦺾÷©ÎÂ_¹q®É¡A
Bridge Mode¨¾¤õÀ𦨬°ºô¸ô¤¤ªº»Ùê¡C


¦b¤£³z¹LWizardªº±¡ªp¤U¡A¤â°Ê«Ø¥ßBridge Modeªº¤è¦¡¦p¤U¡C

  1. ¦b CONFIGURE > Network ¤¤«ö¤U Add Bridge «Ø¥ß¾ô±µ°t¹ïºô¥d¡C



  2. ¦bBridge Interface²ÕºA¤¤¡A¿ï¾Ü¨â±i¥¼¨Ï¥Îªººô¥d¡A¨Ã³]¸m¨ä©ÒÄÝZone¡A¨Ò¦pLAN»PWAN¡A
    µM«á³]©w¨äIP»P¸Óºô¬qªºGateway IP¬ÛÃö¸ê°T¡C


    ¡ôPoC®É¡A½Ð¤£­n¤Ä¿ï¡§Enable routing on this bridge pair¡¨¿ï¶µ¡I

  3. §¹¦¨«á¡A¦bNetwork¤¤´N¥i¬Ý¨ì¦¹·s¼Wªº¾ô±µ¤¶­±¡C
    ÂIÀ»¥¦¡A¥i®i¶}¨ä¾ô±µºô¥d¦¨­û¡C



  4. µM«á³]©wºô¥d¦¨­û¶¡ªº¨¾¤õÀð³W«h¡C
    ¥Ñ©ó¶¶¤lªº½d¨Ò¤¤¡A¨â±iºô¥d¦¨­û¤À§OÄÝ©óLAN»PWAN¡A
    ©Ò¥H¶¶¤l«Ø¥ß¤FLAN to WAN»PWAN to LANÂù¦V¶}©ñ³W«h¡C



    ¦b³o¨â±ø³W«h¤¤¡A¦]¬°³£¬O¤º³¡¶Ç¾É¡A¤£»Ý­nNAT¡A©Ò¥H¶¶¤l¨ú®ø¤FNAT»PRoutingªº¬ÛÃö³]©w¡I

  5. ³Ì«á¡A¦p¤@¶}©l©Ò­z¡A³¡¸pBridge Mode¬O¬°¤F¥[±j¬Y°Ï°ì¦w¥þ©Êªº¤@ºØ°µªk¡A¨º»ò­«ÂI¦ÛµM¬O¦b¡§¦w¥þ©Ê¡¨³o³¡¤À¡F
    ¤£µM¦b§¹¥þ³z³qªº±¡§Î¤U¡A¤£°µ¥ô¦ó¦w¥þ©Ê¼Ò²Õªº®M¥Î¡ABridge Mode¥u¬O¼W¥[¤F¤@­Ó³]³Æ¬G»Ù­·ÀIªº¸`ÂI¡C

    ¦b¾ô±µÂI¤º¹ï¥~¡A¥~¹ï¤ºªºÂù¦V´ú¸ÕºZ³qµL»~«á¡A§Ú­Ì´N¥i¥H¦bÂù¦Vªº¨¾¤õÀð³W«h¤¤¡A¥[¤J¾A¦Xªº¼Ò²Õ¨Ó®M¥Î¡C
    ¥H¹F¦w¥þ¨¾Å@ªº¥Øªº¡I



    Bridge Modeªº³]©w¨ì¦¹§¹¦¨¡ã


¥t¥~¡ABridge Mode¦b³¡¸p®ÉµLªk¾A¥Î©ó¥H¤U³õ´º¡AÀô¹Ò³W¹º®É½Ð¯d·N¡C
  • Dynamic DNS
  • Multicast Routing
  • DHCP Client
  • IPsec VPN
  • VLAN
  • Virtual Host
  • PPPoE
  • Bridge (a Bridged Interface cannot be a member of Bridge)


¦¹¥~¡A¦bBridge Mode¤U¶¶¤l´ú¸Õ¹L¥H¤UªºSophosÀ³¥Î³õ´º¬OOKªº¡A¤@¨Ö¤À¨Éµ¹¤j®a¡C
  • Email Protect (Legacy Mode)¡C
  • RED¡A»ÝMapping¥~³¡IPªºTCP/UDP 3400,3410µ¹XG¡C
  • Wifi Protection¡A»Ý¦bRouter¤¤³]¤@µ§Host route 1.2.3.4«ü¦VXG¡C


°Ñ¦Ò¸ê®Æ
Deploy Sophos Firewall in Bridge Mode
https://community.sophos.com/kb/en-us/123276



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2016-11-30, 10:52 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nEnable routing on this bridge pair¬O¤°»ò¡H¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bBridge Mode³]©w¤¤¡A¦³¤@­Ó¡§Enable routing on this bridge pair¡¨ªº¿ï¶µ¥i¨Ñ¤Ä¿ï¡A
³o­Ó¿ï¶µªº¥\¯à¬O¤°»ò¡H



¦bCommunity¤W´£°ÝÃD«á¡A±o¨ì¦p¤UªºµªÂСC



²³æ¨Ó»¡¡A¦b±Ò¥Îroutingªº±¡ªp¤U¡A¾ô±µÂI¦]¬°¦³¶i¦ærouting¡A
©Ò¥H±q¾ô±µ¹ïPort 4¤W¨Óªº¬y¶q©¹¥Øªº192.168.1.100°e®É¡A
·|¦b¾ô±µÂI°µrouting¤U¨®¡Aª½±µ©¹Port 3 (192.168.1.0/24ºô¬q)ªº192.168.1.100¥D¾÷¡F
¦Ó¦^µ{®É¡A192.168.1.100¥D¾÷ªºgateway«ü¦VPort 3¡A©Ò¥H·|±qPort 3¤W¨®¡A¶i¦ærouting«á©¹Port 4°e¡C
§¹¦¨¹ïºÙªº¨Ó¦^¥æ¬y¡C



¦Ó¦b¤£±Ò¥Îroutingªº±¡ªp¡A
±q¾ô±µ¹ïPort 4¤W¨Óªº¬y¶q©¹¥Øªº192.168.1.100°e®É¡A·|ª½±µ°e¨ìPort 5¡A
µM«á¦b¥~³¡routing§¹¡A¶Ç°e¨ì192.168.1.100¥D¾÷¡F
¦Ó¦^µ{®É¡A192.168.1.100¥D¾÷ªºgateway«ü¦VPort 3¡A©Ò¥H·|±qPort 3¤W¨®¡A¶i¦ærouting«á©¹Port 4°e¡C
§Î¦¨¤£¹ïºÙªº¨Ó¦^¥æ¬y¡C

¥H¤W¬OXG¤W¦³Mix Mode (Bridge Mode»PGateway Mode¨Ã¦s)ªº±¡ªp¤U¤~·|µo¥Íªº±¡¹Ò¡A
¦b¤@¯ë³æ¯Â2 Port²Õ¦¨Bridge Modeªº±¡ªp¤U¡A¶¶¤l¤£«Øij¤Ä¿ï¡§Enable routing on this bridge pair¡¨¡A
¦]¬°¶¶¤l´¿¸g¹J¨ì¹L¤Ä¿ï¦¹¿ï¶µ«á¡A³y¦¨LANµLªk³z¹LWAN³s¥~ªº±¡ªpµo¥Í¡I
¨ú®ø¦¹¿ï¶µ«á¡A¤@¤ÁÅܪº¥¿±`¡ALAN¤]¥i¥H¶¶§Q³s¥~¤F...

³z¹LBridge Mode¶i¦æPoC®É¡A«Øij¤£­n¤Ä¿ï¦¹¿ï¶µ¡A¥H§K¥X²{¹w´Á¤§¥~ªºª¬ªp¡I
¥H¤W¤À¨Éµ¹¤j®a¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2016-11-30, 12:05 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nBridge Modeªº½Õ¾ã³]©w¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

XG¹w³]³¡¸p¤è¦¡¬OGateway Mode¡A
¦b§ï¦¨Bridge Mode«á¡A¦³¨Ç¨t²Î°Ñ¼Æ»Ý¶i¦æ½Õ¾ã¡A
¨Ï¥Î®É¤~¤£·|¥X²{¤@¨Ç©Ç©Ç¡B¤£¦X²zªº²{¶H¡C

³o¨Ç­ì¼t«Øijªº½Õ¾ã«ü¥O¦p¤U¡C

set http_proxy add_via_header off
¬O§_¼W¥[HTTP headerùتºvia¸ê°T.¹w³]­Èon,½Ð³]©w¬°off.

set advanced-firewall tcp-est-idle-timeout 2700
TCP³s½u¶¢¸mªºÂ_¶}®É¶¡,¥i±µ¨ü­È2700-432000,¹w³]­È10800,½Ð§ï¨ì³Ì¤pªº2700,¥H¥[³ttime,release¤w«Ø¥ßªºsession.

set advanced-firewall midstream-connection-pickup on
¬O§_±Ò¥Îmidstream-connection-pickup¾÷¨î,¹w³]­Èoff,½Ð§ï¬°on.

set advanced-firewall tcp-seq-checking off
ÀˬdTCP«Ê¥]¤¤ªºSYN»PACK¸¹½X,¹w³]­Èon,½Ð§ï¬°off.

set advanced-firewall tcp-selective-acknowledgement off
TCP¨ó©w¤¤ªºreceiver¦^À³sender¤w¦¬¨ì¸ê®Æ¤ù¬qªº¤@­Ó½T»{¾÷¨î.¹w³]­Èon,½Ð§ï¬°off.

set advanced-firewall strict-policy off
¬O§_®M¥ÎÄY®æªº¬Fµ¦¾÷¨î.¹w³]­Èon,½Ð§ï¬°off.

sys auth cta unauth-traffic drop-period 2
¥¼»{ÃÒ¬y¶q³Q©Úµ´ªº®É¶¡°Ï¶¡,¹w³]­È120¬í,«Øij½Õ¾ã¬°2¬í.

set service-param HTTPS invalid-certificate allow
HTTPS¨ó©w¤¤,«Dªk¾ÌÃÒ¬O§_¤¹³\.¹w³]­Èallow,½Ð½T»{¬O§_¬°allow.


¥t¥~¡AÁÙ¦³Webùتºpharming protectionºô§}¶ù±µ«OÅ@¤]­n¨ú®ø¤Ä¿ï¡C



¶¶¤l¦b«È¤áºÝÀô¹Ò¹J¨ì³o¼Ëªº±¡§Î¡A¦bXG¥HBridge Modeªº¤è¦¡¤¶±µ«á¡A
­ì¥»¥i¥H¹ï¥~´£¨ÑªA°ÈªºHTTPS¯¸¥x³£µLªk¦b¥~ºô³s¤J¤F¡I
¦ýHTTPªºªA°È«o¤£¨ü¼vÅT¡H

¥²»Ý°±¥Îpharming protection¡A´£¨Ñ¥~ºôªºHTTPS³s½u¤~«ì´_¥¿±`¡A
³¡¸p®É¡A½Ðª`·N¦¹ÂI¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2017-05-17, 22:55 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nBridge Mode¤U©Ò¦³ºô­¶³£¥´¤£¶}¡H¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦P¨Æ¦b¨Ï¥Îbridge mode°µPoC®É¹J¨ì¤F¤@­Ó©_©Çªº°ÝÃD¡A
·í±Ò¥ÎWeb Filter®É¡A©Ò¦³ºô­¶³£¥´¤£¶}¡A
§Y«K¬O¿ï¾ÜAllow All¤]¤@¼Ë¡I

¦ý§ï¬°none®É¡A©Ò¦³ºô­¶«o³£¥i¥H¥¿±`¶}±Ò¤F¡I
³o¬O«ç»ò¦^¨Æ¡H


­ì¨Ó¦³¨S¦³±Ò¥Îweb filter¦b«Ê¥]ªº³B²z¤W¦³«Ü¤jªº¤£¦P¡A
·í¿ï¾Ü¬°none®É¡AXG¤£¶i¦æ¹LÂo¡A«Ê¥]ª½±µ¸g¥Ñ¾ô±µ°t¹ï°e¨ì¥t¥~¤@ºÝ¡C

¦ý¿ï¾Ü¨ä¥¦web filter®É¡AXG·|¥Hproxyªº¬[ºc¨Ó³B²z«Ê¥]¡A
«Ê¥]·|¥ý°±¯d¦bXG¤W¡AµM«á¥ÑXG¤ñ¹ïpattern¡A§P©w³o­Ó«Ê¥]¸Ó¾×¡AÁÙ¬O©ñ¡H

³o®É­YXG¥»¨­µLªk§ó·spattern¡A¨º»ò¦bÀˬd®É´N·|¥X¤F°ÝÃD¡AµLªk§PÂ_¸Ó¾×ÁÙ¬O¸Ó©ñ¡H
µM«á´N³y¦¨¤F±Ò¥Îweb filter«á¡A©Ò¦³ºô­¶µLªk¶}±Òªºª¬ªp¡I

¦P¨Æªº³o­Ó®×¨Ò¡A¬O¦]¬°Àô¹Ò¤¤¦³¨â­Órouting³]³Æ-¬J¦³¨¾¤õÀð»PCore Switch¡A¦ÓXG´N§¨¦b¨â­Ó³]³Æ¤§¶¡¡C
¦b³o­Ó®×¨Ò¤¤¡AXGªºgateway«ü¦V¬J¦³¨¾¤õÀð»PCore Switch³£¥i¥H³s¥~¡A©Ò¥H¤]¨S¦³·Q¨ì·|¬Ogatewayªº°ÝÃD¡C

ª½¨ì«á¨Óµo²{ÁöµMgateway«ü¦V¬J¦³¨¾¤õÀð¥i¥H³q¡A
¦ýXGªºlicense sync»Ppattern update³£·|¥¢±Ñ¡A¤~µo²{¬O³o­Ó°ÝÃD¡C
¦b±Ngateway§ï«ü¦VCore Switch«á¡A°ÝÃDÁ`ºâ¶¶§Q±Æ°£¡C

¦Ü©óÀô¹Ò¤¤ªºgateway¨s³º¬O­n«ü¦V¬J¦³¨¾¤õÀðÁÙ¬OCore Switch¡H
³o­n¬ÝÀô¹Ò¬[ºc¦Ó©w¡C
¤£¹L¤@­Ó²³æªº´ú¸Õ¤èªk´N¬O¥h¸Õlicense sync»Ppattern update¡A
¦¨¥\¤F¡A´N¬O¹ïªº¡F¿ù¤F¡A´N§ï¦¨¥t¤@­Ó§a¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-12-25, 15:35 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR