ZyXEL Communications 10 Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Redes ZyXEL Communications 10. ZyWALL SSL 10 Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 102
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
ZyWALL SSL 10 Support Notes
1
All contents copyright (c) 2006 ZyXEL Communications Corporation.
ZyWALL SSL 10
Integrated SSL-VPN Appliance
Support Notes
Revision 2.01
April. 2007
Vista de página 0
1 2 3 4 5 6 ... 101 102

Resumo do Conteúdo

Página 1 - ZyWALL SSL 10

ZyWALL SSL 10 Support Notes 1 All contents copyright (c) 2006 ZyXEL Communications Corporation. ZyWALL SSL 10 Integrated SSL-VPN Appliance

Página 2

ZyWALL SSL 10 Support Notes 10 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: However, if you have configured a port

Página 3

ZyWALL SSL 10 Support Notes 100 All contents copyright (c) 2006 ZyXEL Communications Corporation. single user profile where you can manage all

Página 4 - 1. Deployment

ZyWALL SSL 10 Support Notes 101 All contents copyright (c) 2006 ZyXEL Communications Corporation. D03. SSL VPN vs. PPTP VPN? Here we compare th

Página 5

ZyWALL SSL 10 Support Notes 102 All contents copyright (c) 2006 ZyXEL Communications Corporation. E2. What are the checking items of EPC on ZyW

Página 6

ZyWALL SSL 10 Support Notes 11 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL SSL 10 1) Access ZyWA

Página 7

ZyWALL SSL 10 Support Notes 12 All contents copyright (c) 2006 ZyXEL Communications Corporation. But if it’s not your first time to configure

Página 8

ZyWALL SSL 10 Support Notes 13 All contents copyright (c) 2006 ZyXEL Communications Corporation.

Página 9

ZyWALL SSL 10 Support Notes 14 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5) Then choose "Static" for the devi

Página 10 - ZyWALL SSL 10 Support Notes

ZyWALL SSL 10 Support Notes 15 All contents copyright (c) 2006 ZyXEL Communications Corporation. 7) Then configure the VPN network and the rem

Página 11

ZyWALL SSL 10 Support Notes 16 All contents copyright (c) 2006 ZyXEL Communications Corporation. 8) Then the system will remind you to rememb

Página 12

ZyWALL SSL 10 Support Notes 17 All contents copyright (c) 2006 ZyXEL Communications Corporation. 10) Enter the necessary information to regist

Página 13

ZyWALL SSL 10 Support Notes 18 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step1: Assume the PC_A is an Internet host whi

Página 14

ZyWALL SSL 10 Support Notes 19 All contents copyright (c) 2006 ZyXEL Communications Corporation. The user can open the application tool to ac

Página 15

ZyWALL SSL 10 Support Notes 2 All contents copyright (c) 2006 ZyXEL Communications Corporation. INDEX 1. Deployment...

Página 16

ZyWALL SSL 10 Support Notes 20 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1.2 NAT Mode 1.2.1 Deploy ZYWALL SSL 10 at

Página 17

ZyWALL SSL 10 Support Notes 21 All contents copyright (c) 2006 ZyXEL Communications Corporation. tunnel after user pass the SSL authentication.

Página 18

ZyWALL SSL 10 Support Notes 22 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note2: Please ensure you turn on JavaScript an

Página 19

ZyWALL SSL 10 Support Notes 23 All contents copyright (c) 2006 ZyXEL Communications Corporation. But if it’s not your first time to configure Z

Página 20 - 1.2 NAT Mode

ZyWALL SSL 10 Support Notes 24 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5) In this example, we choose “Static” for the

Página 21

ZyWALL SSL 10 Support Notes 25 All contents copyright (c) 2006 ZyXEL Communications Corporation. 7) In this example, we create one SSL VPN us

Página 22

ZyWALL SSL 10 Support Notes 26 All contents copyright (c) 2006 ZyXEL Communications Corporation. 8) Then configure the VPN network and the remo

Página 23

ZyWALL SSL 10 Support Notes 27 All contents copyright (c) 2006 ZyXEL Communications Corporation. 9) It will give you a summery for the ZyWALL S

Página 24

ZyWALL SSL 10 Support Notes 28 All contents copyright (c) 2006 ZyXEL Communications Corporation. 10) Enter the necessary information to registe

Página 25

ZyWALL SSL 10 Support Notes 29 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2. Integrated Application The authenticati

Página 26

ZyWALL SSL 10 Support Notes 3 All contents copyright (c) 2006 ZyXEL Communications Corporation. A10. Does ZyWALL support dynamic IP addressing?

Página 27

ZyWALL SSL 10 Support Notes 30 All contents copyright (c) 2006 ZyXEL Communications Corporation. There are different access resources avai

Página 28

ZyWALL SSL 10 Support Notes 31 All contents copyright (c) 2006 ZyXEL Communications Corporation. configuration page. There are two main block f

Página 29 - 2. Integrated Application

ZyWALL SSL 10 Support Notes 32 All contents copyright (c) 2006 ZyXEL Communications Corporation. Please switch to User/Group configuration page

Página 30 - 2.1 External Authentication

ZyWALL SSL 10 Support Notes 33 All contents copyright (c) 2006 ZyXEL Communications Corporation. Finally, adding the outsider group. We can ch

Página 31

ZyWALL SSL 10 Support Notes 34 All contents copyright (c) 2006 ZyXEL Communications Corporation. There are three SSL application type

Página 32

ZyWALL SSL 10 Support Notes 35 All contents copyright (c) 2006 ZyXEL Communications Corporation. Application: Select the Application from

Página 33 - 2.2 Objects Configuration

ZyWALL SSL 10 Support Notes 36 All contents copyright (c) 2006 ZyXEL Communications Corporation.

Página 34

ZyWALL SSL 10 Support Notes 37 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.2.2 VPN Network Object Please switch

Página 35

ZyWALL SSL 10 Support Notes 38 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.2.3 Endpoint Security Object End

Página 36

ZyWALL SSL 10 Support Notes 39 All contents copyright (c) 2006 ZyXEL Communications Corporation. Outsider Endpoint Security Policy:

Página 37

ZyWALL SSL 10 Support Notes 4 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1. Deployment SSL topology encapsulates the sen

Página 38

ZyWALL SSL 10 Support Notes 40 All contents copyright (c) 2006 ZyXEL Communications Corporation. Sales Endpoint Security Policy: Norma

Página 39

ZyWALL SSL 10 Support Notes 41 All contents copyright (c) 2006 ZyXEL Communications Corporation. RD Endpoint Security Policy: RD needs

Página 40

ZyWALL SSL 10 Support Notes 42 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.2.4 Private IP Pool Object Privat

Página 41

ZyWALL SSL 10 Support Notes 43 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.3 SSL Policy Configuration After perviou

Página 42

ZyWALL SSL 10 Support Notes 44 All contents copyright (c) 2006 ZyXEL Communications Corporation. They are only allowed to use the we

Página 43 - 2.3 SSL Policy Configuration

ZyWALL SSL 10 Support Notes 45 All contents copyright (c) 2006 ZyXEL Communications Corporation. They are only allowed to use the web applicati

Página 44

ZyWALL SSL 10 Support Notes 46 All contents copyright (c) 2006 ZyXEL Communications Corporation. private IP pool to connect with VPN network.

Página 45

ZyWALL SSL 10 Support Notes 47 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3. SSL VPN Solution In the chapter one,

Página 46

ZyWALL SSL 10 Support Notes 48 All contents copyright (c) 2006 ZyXEL Communications Corporation. Background Story: ZyCompany has a security c

Página 47 - 3. SSL VPN Solution

ZyWALL SSL 10 Support Notes 49 All contents copyright (c) 2006 ZyXEL Communications Corporation. To achieve this, we have to complete the follo

Página 48

ZyWALL SSL 10 Support Notes 5 All contents copyright (c) 2006 ZyXEL Communications Corporation. The network topology above is used to ill

Página 49

ZyWALL SSL 10 Support Notes 50 All contents copyright (c) 2006 ZyXEL Communications Corporation. However, if you found it’s “Reject” or “Drop

Página 50

ZyWALL SSL 10 Support Notes 51 All contents copyright (c) 2006 ZyXEL Communications Corporation. WAN IP address depending on server access sett

Página 51

ZyWALL SSL 10 Support Notes 52 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step4. Register and enable AV/IDP functions

Página 52

ZyWALL SSL 10 Support Notes 53 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1. In IDP->General, check the Enable Intr

Página 53

ZyWALL SSL 10 Support Notes 54 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: Remember to make sure the AV signature

Página 54

ZyWALL SSL 10 Support Notes 55 All contents copyright (c) 2006 ZyXEL Communications Corporation.

Página 55

ZyWALL SSL 10 Support Notes 56 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.2 Seamless Integrate SSL VPN into your exist

Página 56

ZyWALL SSL 10 Support Notes 57 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration information in this example:

Página 57

ZyWALL SSL 10 Support Notes 58 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL SSL10 Please refer to

Página 58

ZyWALL SSL 10 Support Notes 59 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1) Configure the static Public IP address to

Página 59

ZyWALL SSL 10 Support Notes 6 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration information in this example: Z

Página 60

ZyWALL SSL 10 Support Notes 60 All contents copyright (c) 2006 ZyXEL Communications Corporation. (PPPoE with dynamic IP assignment). 4) Con

Página 61

ZyWALL SSL 10 Support Notes 61 All contents copyright (c) 2006 ZyXEL Communications Corporation. Gateway). NAT routers sit on the border betwe

Página 62

ZyWALL SSL 10 Support Notes 62 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1) UDP 500 (IKE) must be forwarded to ZyWALL

Página 63

ZyWALL SSL 10 Support Notes 63 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5) On peer VPN gateway, use the public WAN IP

Página 64

ZyWALL SSL 10 Support Notes 64 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: However, if you have to configure the

Página 65

ZyWALL SSL 10 Support Notes 65 All contents copyright (c) 2006 ZyXEL Communications Corporation. Security Policy Configuration for SSL VPN tra

Página 66

ZyWALL SSL 10 Support Notes 66 All contents copyright (c) 2006 ZyXEL Communications Corporation. available in IDP/AV and AS General configurati

Página 67

ZyWALL SSL 10 Support Notes 67 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.3 Integration: SonicWALL+ZyWALL SSL10 We wou

Página 68

ZyWALL SSL 10 Support Notes 68 All contents copyright (c) 2006 ZyXEL Communications Corporation. y ZyWALL SSL10’s WAN ÅÆ SonicWALL’s OPT port

Página 69

ZyWALL SSL 10 Support Notes 69 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step3. Setup the port forwarding for SSL tr

Página 70

ZyWALL SSL 10 Support Notes 7 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2) Go to the GUI > Network > DMZ > P

Página 71

ZyWALL SSL 10 Support Notes 70 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step5. Access https://172.120.1.10 from an I

Página 72

ZyWALL SSL 10 Support Notes 71 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.4 Integration: Netscreen+ZyWALL SSL10 We wou

Página 73

ZyWALL SSL 10 Support Notes 72 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1) Connect the Ethernet cables as following y

Página 74

ZyWALL SSL 10 Support Notes 73 All contents copyright (c) 2006 ZyXEL Communications Corporation. 4) Configure it as following figure. So any in

Página 75

ZyWALL SSL 10 Support Notes 74 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3) Configure the destination NAT setting as fo

Página 76

ZyWALL SSL 10 Support Notes 75 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.5 Integration with NSA-2400 for file sharing

Página 77

ZyWALL SSL 10 Support Notes 76 All contents copyright (c) 2006 ZyXEL Communications Corporation. See the following step-by-step configuration.

Página 78

ZyWALL SSL 10 Support Notes 77 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: It’s better to path by click the Brows

Página 79

ZyWALL SSL 10 Support Notes 78 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL SSL10 Step1. Pleas

Página 80

ZyWALL SSL 10 Support Notes 79 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL UTM Step1. Create p

Página 81

ZyWALL SSL 10 Support Notes 8 All contents copyright (c) 2006 ZyXEL Communications Corporation. 4) Go to the GUI > Network > LAN, conf

Página 82

ZyWALL SSL 10 Support Notes 80 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step2. Make sure firewall rule allow SSL traf

Página 83

ZyWALL SSL 10 Support Notes 81 All contents copyright (c) 2006 ZyXEL Communications Corporation. UTM’s HTTPS management port number from port 4

Página 84

ZyWALL SSL 10 Support Notes 82 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step4. Allow NetBIOS between WAN and DMZ, D

Página 85

ZyWALL SSL 10 Support Notes 83 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2) Enter the information as below. Note the

Página 86

ZyWALL SSL 10 Support Notes 84 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3) You will enter the portal, continue to cl

Página 87

ZyWALL SSL 10 Support Notes 85 All contents copyright (c) 2006 ZyXEL Communications Corporation. 6) Enter the username and password, you will

Página 88

ZyWALL SSL 10 Support Notes 86 All contents copyright (c) 2006 ZyXEL Communications Corporation. 4. Best Practice: Stronger Password Security

Página 89

ZyWALL SSL 10 Support Notes 87 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: To use two-factor authentication, it’s r

Página 90

ZyWALL SSL 10 Support Notes 88 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step3. Setup AAA server 1) Go to GUI > Sy

Página 91

ZyWALL SSL 10 Support Notes 89 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on Authenex Server 1). Conne

Página 92

ZyWALL SSL 10 Support Notes 9 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step3. Check if UTM functions (ex. Firewall, An

Página 93

ZyWALL SSL 10 Support Notes 90 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2). Go to Server Configuration > Add NAS E

Página 94 - A. ZyWALL General FAQ

ZyWALL SSL 10 Support Notes 91 All contents copyright (c) 2006 ZyXEL Communications Corporation. Then edit the user and check the Assign only

Página 95

ZyWALL SSL 10 Support Notes 92 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5). Go to Manage A-Keys > Search A-Keys, se

Página 96

ZyWALL SSL 10 Support Notes 93 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2). After successful login, you could see the

Página 97

ZyWALL SSL 10 Support Notes 94 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5. FAQ A. ZyWALL General FAQ A01. How to acces

Página 98

ZyWALL SSL 10 Support Notes 95 All contents copyright (c) 2006 ZyXEL Communications Corporation. A05. Does the ZyWALL support PPPoE? Yes. The Z

Página 99 - B. Firmware Upgrade FAQ

ZyWALL SSL 10 Support Notes 96 All contents copyright (c) 2006 ZyXEL Communications Corporation. A09. What can we do with ZyWALL? Browse the

Página 100 - D. SSL VPN FAQ

ZyWALL SSL 10 Support Notes 97 All contents copyright (c) 2006 ZyXEL Communications Corporation. dynamic IP address. Suppose your company'

Página 101 - E. EPC(End Point Check) FAQ

ZyWALL SSL 10 Support Notes 98 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1. Check if the 'MAC address' is va

Página 102

ZyWALL SSL 10 Support Notes 99 All contents copyright (c) 2006 ZyXEL Communications Corporation. B. Firmware Upgrade FAQ B01. How to perform th

Comentários a estes Manuais

Sem comentários