Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Sophos XG > ¡m¤À¨É¡nXG»PFortiGate IPsec¦ê±µ «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nXG»PFortiGate IPsec¦ê±µ¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¥H«e´N¼g¹LCyberoam»PFortiGateªº¦ê±µ¡A
¦ÓXG¸òCyberoam¦bIPsec¤W®t¤£¦h¡A©Ò¥H³o½gªº­«ÂI¨ä¹ê¬O¡§¤£¦Pª©¥»ªºFortiGate IPsec³]©w¡¨¡C

­Y±zªºForti IPsec³]©w»P¥»½g°O¿ý¤£¦P¡A¨º»ò©Î³\¥i¥H°Ñ¦Ò³o¤@½g - Cyberoam»PFortiGate VPN¦ê±µ¡C

³]©wÀô¹Ò¦p¤U¡C


³]©wIPsecªº¤@­Ó­«ÂI¬O¨âºÝªºPhase 1 & 2¥[¸Ñ±K¤Îºtºâªk­n¤@­P¡AµM«á¨Ï¥Î¬Û¦PªºPreshared Key¡A
´x´¤¤F³o¼Ëªº±ø¥ó¡A°ò¥»¤WIPsec´N§¹¦¨¤F¤@¥b¡ã

  • FortiGateºÝªº³]©w
    ¦bFortiGateªºIPsec Tunnel¤¤·s¼W¤@­Ó³s½u¡C



    µM«á¦b¼ÒªO¤¤¿ï¾Ü¡§¦Û©w¸qVPNÀG¹D(µL¼ÒªO)¡¨³oºØÃþ«¬¨Ó¦Û¦æ©w¸qVPN¤º®e¡C



    ¦b·s«ØªºIPsec¤º®e¤¤¡A¥J²Ó³]©w¦nPhase 1 & 2¥[¸Ñ±K»Pºtºâªk¡A¨Ã°O¦í¨Ï¥ÎªºPreshared Key¡A
    ³o¨Ç³]©w¤º®e·|¦bSophos XG¤¤ªºIPsec¥t«Øprofile¨Ó¹ïÀ³¡C
    Phase 2ªº¤º®e³]©w§¹¦¨«á¡A½Ð¥ý«ö¤U¤Ä¤Ä¶i¦æÀx¦s¡C



    Phase 2Àx¦s«á¦A«ö¤@¦¸¡§½T»{¡¨´N§¹¦¨¤FIPsecªº²ÕºA«Ø¥ß¡C



    §¹¦¨«á¥i¥H¬Ý¨ì¸Ó²ÕºA¶µ¥Ø¥X²{¦bÀG¹D¼Ò¦¡¤¤¡C



    IPsec²ÕºA«Ø¥ß«á¡A±µµÛ­n«Ø¤@±ø¨¾¤õÀð³W«h¨Ó©ñ¦æIPsecªº«Ê¥]¡C



    ¦¹¨¾¤õÀð³W«hªº­«ÂI¦b©ó°Ê§@¿ï¾Ü¡§IPsec¡¨¡A¿ï¤F¡§IPsec¡¨«á´N¦³¹ïÀ³ªºVPNÀG¹D¤º®e¥X²{¡A
    µM«á¦A¿ï¾Ü­è­è«Ø¥ßªºIPsec²ÕºA¡C



    ¦¹³W«h«Ø¦n«á¡A¹w³]¬O¦b³Ì¤U¤è¡A§Ú­Ì¥i¥H§â¥¦½Õ¾ã¨ì¹w³]ªºinternal-wan³W«h¤§«e¡C



    §¹¦¨«á¡A¨¾¤õÀð³W«hªº±Æ¦C¶¶§ÇÀ³¸ÓÅã¥Ü¦p¤U¡C



    ¦Ü©óIPsec Tunnelªº±Ò¥Î/Â_¶}¥i¦bºÊµø¾¹¤¤ªºIPsecºÊµø¾¹ùضi¦æ¡C



    ¨ì³oÃäFortiGate¤Wªº³]©w¤w¸g§¹¦¨¡C
    ­n¯S§Oª`·Nªº¬O¡A¦bFortiGate¤¤IPsec tunnelªº«Ø¥ß»P¨¾¤õÀð©ñ¦æ³W«h¦³ª½±µªºÃö«Y¡A
    No policy = no tunnel
    ¦pªG¥¼«Ø¥ß¨¾¤õÀð³W«h¡A°ò¥»¤W³oIPsec VPN tunel¬O¤£·|°_¨Óªº¡A
    ¶¶¤l¦b³o³¡¤À¦Y¹LÁ«¡A³]©w®É­nª`·N³oÂI¡C

  • Sophos XGºÝªº³]©w
    XG¤Wªº³]©w«O¦³Cyberoamªº¯S¦â-²³æ¦n¥Î¡C
    ¥ý¦b CONFIGURE > VPN > IPsec Profiles ¤¤·s¼W¤@­Óprofile¨Ó¹ïÀ³¡C



    ¦bprofile¤º®e¤¤¡A½Ð±NFortiºÝ³]©wªºPhase 1 & 2¥[¸Ñ±K/ºtºâªk»PDH Group§Û¼g¹L¨Ó¡C



    µM«á¦b CONFIGURE > VPN > IPsec Connections ·s¼W¤@­ÓIPsec³s½u³q¹D¡C



    ¦¹IPsec³s½uªºPolicy·íµM­n¿ï¾Ü­è¤~·s«ØªºIPsec Profile¡A
    µM«á¶ñ¤J¤@­PªºPreshared Key»P¨âºÝªºIP¤Îºô¬q¸ê°T¡C



    §¹¦¨«á¡A«ö¤UConnection«ö¶s¡C



    ¥Ñ©óFortiºÝ¤w¥ý³]©w¦n¡A­Y¨âºÝ³]©w¥¿½T¡AIPsec TunnelÀ³¸Ó¥i¥H¶¶§Q³s³q¤F¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2017-02-23, 10:32 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡n»PInterface Mode Forti¦ê±µ¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¬Q¤Ñ¦]¤u§@»Ý¨D¡A±µÄ²¤F¥t¤@­Óª©¥»ªºForti¡A
¦Ó³o­Óª©¥»ªºIPsec VPN¸ò¤§«e´ú¸Õ¹LFortiµy¦³¤£¦P¡A¤w¸g¦³©Ò¿×Interface Modeªº¿ï¶µ¡C
¥H¤U¬°Interface Mode³]©w¤ß±o¡A¤À¨Éµ¹¤j®a¡C

  1. ­º¥ý¡A¦bIPsec²ÕºA¤¤¡A¦h¤F¤@­Ó¡§Enable IPsec Interface Mode¡¨ªº¿ï¶µ ¡A
    ±Ò¥Î³o¿ï¶µ«á¡AIPsec VPN´N§Î¦PForti¤Wªº¤@­Ó¤¶­±¡A¤]´N¬O©Ò¿×ªºInterface Mode¡A
    ³o¸ò­ì¥»ªºTunnel Mode¦b³]©w¤W¬O¤£¦Pªº¡C

    ¥Ñ©óTunnel Mode¦b¤W¤@½g¤w¹ê§@¹L¡A©Ò¥H³o½g±N·|¥HInterface Mode¨Ó¶i¦æ³s½u³]©w¡C
    ¦Ó¨Æ¹ê¤W¡ATunnel Mode»PInterface Mode¦bIPsec VPNªº²ÕºA³]©w¤W°£¤F³o­Ó¤Á´«¿ï¶µ¥~¡A¨ä¾l¬Û¦P¡A
    ©Ò¥H²ÕºA³]½Ð½Ð°Ñ¦Ò¤W¤@½g¡C

  2. ¥t¥~¡A¦b³o­Óª©¥»ªºForti¤¤¡AÁÙ¦h¤F¤@­Ó¡§¼Ò¦¡°t¸m¡¨ªº¿ï¶µ¡C


    ³o­Ó¿ï¶µ½Ð¤Å¤Ä¿ï¡I
    ¶¶¤l¤£²M·¡³o­Ó¥\¯àªº¹ê»Ú·N¸q¡A¦ý¤Ä¿ï«á¡A±N³y¦¨Phase2²ÕºA¤¤¡§ªñ/»·ºÝ²ÕºA¡¨µLªk°t¸m¡I¡H
    ·íµMIPsec VPN¤]´NµLªk¦¨¥\¦ê±µ¤F...
    ¦]¦¹³]©w®É¡A½Ð¤£­n¤Ä¿ï¦¹¿ï¶µ¡I

  3. ¦b«Ø¥ßInterface Mode²ÕºAªºIPsec VPN«á¡A¨¾¤õÀð¤W¸Ó«Ø¥ßªºPolicy rule¤]¦³¨Ç¤£¦P¡C
    ­ì¥»Tunnel Mode¬O­n¦b¡§°Ê§@¡¨¤W¿ï¾Ü¡§IPsec¡¨«á¡A¦A¬D¿ï­n¥ÎªºIPsec Tunnel¡C

    ¦bÅܬ°Interface Mode«á¡A¥Ñ©óIPsec VPN§Î¦PForti¤Wªº¤@­Ó¤¶­±¡A
    ©Ò¥H­nÅܦ¨­n«Ø¥ßInternal to Interface Mode IPsec VPN¶¡ªºÂù¦V©ñ¦æ³W«h¡C



  4. ³]©w¦nÂù¦Vpolicy«á¡AInterface Mode»ÝÃB¥~³]©wStatic Route¨Ó«ü©w¸ô¥Ñ¾É¦V¡C
    ¦]¬°IPsec VPN§Î¦PForti¤Wªº¤@­Ó¤¶­±¡A¨Ã¤£¹³Tunnel Mode·|¦Û°Ê¸j©w¹ïÀ³¸ô¥Ñ¡A
    ¦]¦¹¡A»Ý­n¼W¥[Âù¦Vstatic route¡A«Ê¥]¤~¯à¦¨¥\°e¨ì¹ïºÝ¡C



  5. ³Ì«á¡A¶¶¤lµo²{¤ÓµuªºPreshared Key·|³y¦¨³s½u¤Wªº¥¢±Ñ¡I
    XG¤W¼´¨ìªºlog¦p¤U¡C
    Oakley Transform [OAKLEY_DES_CBC (64), OAKLEY_MD5, OAKLEY_GROUP_MODP1536] refused due to insecure key_len and enc. alg. not listed in "ike" string

    ¦b±NPreshared Key§ï¬°12½Xªø«×¡A¥B¨ã½ÆÂø©Êªº¦r¦ê«á¡AXGÁ`ºâ¯à°÷»PForti¦¨¥\¦ê±µ¤F¡ã

¥H¤W¬°Interface Mode»PTunnel Modeªº®t²§¡A¤À¨Éµ¹¤j®a¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2018-01-30, 09:54 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR