data:image/s3,"s3://crabby-images/710dc/710dc4cbd466249d5c723f5db1fc55434dcc6104" alt=""
需求:企业总部部署山石防火墙做为互联网出口网关,内部服务器(10.1.1.0/24)为员工提供远程办公服务;
为提升信息系统安全级别,远程办公人员需使用SSL VPN访问内部服务器。
防火墙关键配置:
fwa# show configuration
aaa-server “itbj.net” type local
user “ssluser1“
password “123456“
exit
user-group “inherit“
member user “ssluser1“
exit
exit
zone “untrust”
type wan
exit
zone “sslvpn“
vrouter “trust-vr”
exit
hostname “fwa”
scvpn pool “sslpool“
address 10.1.88.1 10.1.88.100 netmask 255.255.255.0
exit
tunnel scvpn “inherittimes“
ssl-protocol any
pool “sslpool“
split-tunnel-route 10.1.88.0/24
split-tunnel-route 10.1.1.0/24
aaa-server “itbj.net“
interface ethernet0/1
exit
interface ethernet0/0
zone “trust”
ip address 10.1.1.254 255.255.255.0
manage ssh
manage ping
manage snmp
exit
interface ethernet0/1
zone “untrust”
ip address 20.0.0.1 255.255.255.0
manage ping
exit
interface tunnel30
zone “sslvpn“
ip address 10.1.88.254 255.255.255.252
manage ping
tunnel scvpn “inherittimes“
reverse-route prefer
exit
ip vrouter “trust-vr”
snatrule id 1 from “10.1.1.0/24” to “Any” service “Any” eif ethernet0/1 trans-to eif-ip mode dynamicport
ip route 0.0.0.0/0 20.0.0.100
exit
rule id 1
action permit
src-zone “trust”
dst-zone “untrust”
src-addr “Any”
dst-addr “Any”
service “Any”
exit
rule id 31
action permit
src-zone “sslvpn“
dst-zone “trust”
src-addr “Any”
dst-ip 10.1.1.0/24
service “Any”
user-group “itbj.net” “inherit“
exit
End
使用、验证
一、安装SCVPN客户端
1、web浏览器地址栏输入https://20.0.0.1:4433 ,访问ssl vpn网关用户认证登录页面,输入用户名、密码后点击登录按钮;
data:image/s3,"s3://crabby-images/30831/30831d4b6beea8bfbab194ba3a7dc90921c559f7" alt=""
2、登录成功后点击下载按钮,web页面将重定向至hillstone(山石)官网自动执行下载;
data:image/s3,"s3://crabby-images/e7c5e/e7c5e135c0d51ab16f4dd2e9b59e4e8794f6e750" alt=""
3、下载完成后执行SCVPN客户端安装。
data:image/s3,"s3://crabby-images/33fef/33fef0fa5fffc3ad53c15f2fb863add7125ba20e" alt=""
二、开打SCVPN客户程序,输入SSL VPN网关地址,端口号默认为4433, 输入用户名、密码后点击登录
data:image/s3,"s3://crabby-images/b865e/b865ebbedb2dfc399951a1b7381b3d25a0b7074c" alt=""
data:image/s3,"s3://crabby-images/f4faa/f4faafa70d0945a6811c8a486378585eb38b0869" alt=""
data:image/s3,"s3://crabby-images/e181a/e181aa60dfd2e553d92708bdc2772c78919e2cef" alt=""
三、测试验证
使用ping 和 tracert 验证至总部内网服务器连通性和路径
data:image/s3,"s3://crabby-images/2f5a1/2f5a139dda97eb181b54acc3f772e8b1626d216d" alt=""
在总部防火墙上使用 show scvpn client inherittimes 查看SSL VPN用户登录状态信息
data:image/s3,"s3://crabby-images/c9902/c99026a428fd94232fcaa533aedeb28b47731664" alt=""