ZyXEL Communications 10 Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Mise en réseau ZyXEL Communications 10. ZyWALL SSL 10 Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 102
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 0
ZyWALL SSL 10 Support Notes
1
All contents copyright (c) 2006 ZyXEL Communications Corporation.
ZyWALL SSL 10
Integrated SSL-VPN Appliance
Support Notes
Revision 2.01
April. 2007
Vue de la page 0
1 2 3 4 5 6 ... 101 102

Résumé du contenu

Page 1 - ZyWALL SSL 10

ZyWALL SSL 10 Support Notes 1 All contents copyright (c) 2006 ZyXEL Communications Corporation. ZyWALL SSL 10 Integrated SSL-VPN Appliance

Page 2

ZyWALL SSL 10 Support Notes 10 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: However, if you have configured a port

Page 3

ZyWALL SSL 10 Support Notes 100 All contents copyright (c) 2006 ZyXEL Communications Corporation. single user profile where you can manage all

Page 4 - 1. Deployment

ZyWALL SSL 10 Support Notes 101 All contents copyright (c) 2006 ZyXEL Communications Corporation. D03. SSL VPN vs. PPTP VPN? Here we compare th

Page 5

ZyWALL SSL 10 Support Notes 102 All contents copyright (c) 2006 ZyXEL Communications Corporation. E2. What are the checking items of EPC on ZyW

Page 6

ZyWALL SSL 10 Support Notes 11 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL SSL 10 1) Access ZyWA

Page 7

ZyWALL SSL 10 Support Notes 12 All contents copyright (c) 2006 ZyXEL Communications Corporation. But if it’s not your first time to configure

Page 8

ZyWALL SSL 10 Support Notes 13 All contents copyright (c) 2006 ZyXEL Communications Corporation.

Page 9

ZyWALL SSL 10 Support Notes 14 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5) Then choose "Static" for the devi

Page 10 - ZyWALL SSL 10 Support Notes

ZyWALL SSL 10 Support Notes 15 All contents copyright (c) 2006 ZyXEL Communications Corporation. 7) Then configure the VPN network and the rem

Page 11

ZyWALL SSL 10 Support Notes 16 All contents copyright (c) 2006 ZyXEL Communications Corporation. 8) Then the system will remind you to rememb

Page 12

ZyWALL SSL 10 Support Notes 17 All contents copyright (c) 2006 ZyXEL Communications Corporation. 10) Enter the necessary information to regist

Page 13

ZyWALL SSL 10 Support Notes 18 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step1: Assume the PC_A is an Internet host whi

Page 14

ZyWALL SSL 10 Support Notes 19 All contents copyright (c) 2006 ZyXEL Communications Corporation. The user can open the application tool to ac

Page 15

ZyWALL SSL 10 Support Notes 2 All contents copyright (c) 2006 ZyXEL Communications Corporation. INDEX 1. Deployment...

Page 16

ZyWALL SSL 10 Support Notes 20 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1.2 NAT Mode 1.2.1 Deploy ZYWALL SSL 10 at

Page 17

ZyWALL SSL 10 Support Notes 21 All contents copyright (c) 2006 ZyXEL Communications Corporation. tunnel after user pass the SSL authentication.

Page 18

ZyWALL SSL 10 Support Notes 22 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note2: Please ensure you turn on JavaScript an

Page 19

ZyWALL SSL 10 Support Notes 23 All contents copyright (c) 2006 ZyXEL Communications Corporation. But if it’s not your first time to configure Z

Page 20 - 1.2 NAT Mode

ZyWALL SSL 10 Support Notes 24 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5) In this example, we choose “Static” for the

Page 21

ZyWALL SSL 10 Support Notes 25 All contents copyright (c) 2006 ZyXEL Communications Corporation. 7) In this example, we create one SSL VPN us

Page 22

ZyWALL SSL 10 Support Notes 26 All contents copyright (c) 2006 ZyXEL Communications Corporation. 8) Then configure the VPN network and the remo

Page 23

ZyWALL SSL 10 Support Notes 27 All contents copyright (c) 2006 ZyXEL Communications Corporation. 9) It will give you a summery for the ZyWALL S

Page 24

ZyWALL SSL 10 Support Notes 28 All contents copyright (c) 2006 ZyXEL Communications Corporation. 10) Enter the necessary information to registe

Page 25

ZyWALL SSL 10 Support Notes 29 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2. Integrated Application The authenticati

Page 26

ZyWALL SSL 10 Support Notes 3 All contents copyright (c) 2006 ZyXEL Communications Corporation. A10. Does ZyWALL support dynamic IP addressing?

Page 27

ZyWALL SSL 10 Support Notes 30 All contents copyright (c) 2006 ZyXEL Communications Corporation. There are different access resources avai

Page 28

ZyWALL SSL 10 Support Notes 31 All contents copyright (c) 2006 ZyXEL Communications Corporation. configuration page. There are two main block f

Page 29 - 2. Integrated Application

ZyWALL SSL 10 Support Notes 32 All contents copyright (c) 2006 ZyXEL Communications Corporation. Please switch to User/Group configuration page

Page 30 - 2.1 External Authentication

ZyWALL SSL 10 Support Notes 33 All contents copyright (c) 2006 ZyXEL Communications Corporation. Finally, adding the outsider group. We can ch

Page 31

ZyWALL SSL 10 Support Notes 34 All contents copyright (c) 2006 ZyXEL Communications Corporation. There are three SSL application type

Page 32

ZyWALL SSL 10 Support Notes 35 All contents copyright (c) 2006 ZyXEL Communications Corporation. Application: Select the Application from

Page 33 - 2.2 Objects Configuration

ZyWALL SSL 10 Support Notes 36 All contents copyright (c) 2006 ZyXEL Communications Corporation.

Page 34

ZyWALL SSL 10 Support Notes 37 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.2.2 VPN Network Object Please switch

Page 35

ZyWALL SSL 10 Support Notes 38 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.2.3 Endpoint Security Object End

Page 36

ZyWALL SSL 10 Support Notes 39 All contents copyright (c) 2006 ZyXEL Communications Corporation. Outsider Endpoint Security Policy:

Page 37

ZyWALL SSL 10 Support Notes 4 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1. Deployment SSL topology encapsulates the sen

Page 38

ZyWALL SSL 10 Support Notes 40 All contents copyright (c) 2006 ZyXEL Communications Corporation. Sales Endpoint Security Policy: Norma

Page 39

ZyWALL SSL 10 Support Notes 41 All contents copyright (c) 2006 ZyXEL Communications Corporation. RD Endpoint Security Policy: RD needs

Page 40

ZyWALL SSL 10 Support Notes 42 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.2.4 Private IP Pool Object Privat

Page 41

ZyWALL SSL 10 Support Notes 43 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2.3 SSL Policy Configuration After perviou

Page 42

ZyWALL SSL 10 Support Notes 44 All contents copyright (c) 2006 ZyXEL Communications Corporation. They are only allowed to use the we

Page 43 - 2.3 SSL Policy Configuration

ZyWALL SSL 10 Support Notes 45 All contents copyright (c) 2006 ZyXEL Communications Corporation. They are only allowed to use the web applicati

Page 44

ZyWALL SSL 10 Support Notes 46 All contents copyright (c) 2006 ZyXEL Communications Corporation. private IP pool to connect with VPN network.

Page 45

ZyWALL SSL 10 Support Notes 47 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3. SSL VPN Solution In the chapter one,

Page 46

ZyWALL SSL 10 Support Notes 48 All contents copyright (c) 2006 ZyXEL Communications Corporation. Background Story: ZyCompany has a security c

Page 47 - 3. SSL VPN Solution

ZyWALL SSL 10 Support Notes 49 All contents copyright (c) 2006 ZyXEL Communications Corporation. To achieve this, we have to complete the follo

Page 48

ZyWALL SSL 10 Support Notes 5 All contents copyright (c) 2006 ZyXEL Communications Corporation. The network topology above is used to ill

Page 49

ZyWALL SSL 10 Support Notes 50 All contents copyright (c) 2006 ZyXEL Communications Corporation. However, if you found it’s “Reject” or “Drop

Page 50

ZyWALL SSL 10 Support Notes 51 All contents copyright (c) 2006 ZyXEL Communications Corporation. WAN IP address depending on server access sett

Page 51

ZyWALL SSL 10 Support Notes 52 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step4. Register and enable AV/IDP functions

Page 52

ZyWALL SSL 10 Support Notes 53 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1. In IDP->General, check the Enable Intr

Page 53

ZyWALL SSL 10 Support Notes 54 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: Remember to make sure the AV signature

Page 54

ZyWALL SSL 10 Support Notes 55 All contents copyright (c) 2006 ZyXEL Communications Corporation.

Page 55

ZyWALL SSL 10 Support Notes 56 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.2 Seamless Integrate SSL VPN into your exist

Page 56

ZyWALL SSL 10 Support Notes 57 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration information in this example:

Page 57

ZyWALL SSL 10 Support Notes 58 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL SSL10 Please refer to

Page 58

ZyWALL SSL 10 Support Notes 59 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1) Configure the static Public IP address to

Page 59

ZyWALL SSL 10 Support Notes 6 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration information in this example: Z

Page 60

ZyWALL SSL 10 Support Notes 60 All contents copyright (c) 2006 ZyXEL Communications Corporation. (PPPoE with dynamic IP assignment). 4) Con

Page 61

ZyWALL SSL 10 Support Notes 61 All contents copyright (c) 2006 ZyXEL Communications Corporation. Gateway). NAT routers sit on the border betwe

Page 62

ZyWALL SSL 10 Support Notes 62 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1) UDP 500 (IKE) must be forwarded to ZyWALL

Page 63

ZyWALL SSL 10 Support Notes 63 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5) On peer VPN gateway, use the public WAN IP

Page 64

ZyWALL SSL 10 Support Notes 64 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: However, if you have to configure the

Page 65

ZyWALL SSL 10 Support Notes 65 All contents copyright (c) 2006 ZyXEL Communications Corporation. Security Policy Configuration for SSL VPN tra

Page 66

ZyWALL SSL 10 Support Notes 66 All contents copyright (c) 2006 ZyXEL Communications Corporation. available in IDP/AV and AS General configurati

Page 67

ZyWALL SSL 10 Support Notes 67 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.3 Integration: SonicWALL+ZyWALL SSL10 We wou

Page 68

ZyWALL SSL 10 Support Notes 68 All contents copyright (c) 2006 ZyXEL Communications Corporation. y ZyWALL SSL10’s WAN ÅÆ SonicWALL’s OPT port

Page 69

ZyWALL SSL 10 Support Notes 69 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step3. Setup the port forwarding for SSL tr

Page 70

ZyWALL SSL 10 Support Notes 7 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2) Go to the GUI > Network > DMZ > P

Page 71

ZyWALL SSL 10 Support Notes 70 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step5. Access https://172.120.1.10 from an I

Page 72

ZyWALL SSL 10 Support Notes 71 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.4 Integration: Netscreen+ZyWALL SSL10 We wou

Page 73

ZyWALL SSL 10 Support Notes 72 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1) Connect the Ethernet cables as following y

Page 74

ZyWALL SSL 10 Support Notes 73 All contents copyright (c) 2006 ZyXEL Communications Corporation. 4) Configure it as following figure. So any in

Page 75

ZyWALL SSL 10 Support Notes 74 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3) Configure the destination NAT setting as fo

Page 76

ZyWALL SSL 10 Support Notes 75 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3.5 Integration with NSA-2400 for file sharing

Page 77

ZyWALL SSL 10 Support Notes 76 All contents copyright (c) 2006 ZyXEL Communications Corporation. See the following step-by-step configuration.

Page 78

ZyWALL SSL 10 Support Notes 77 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: It’s better to path by click the Brows

Page 79

ZyWALL SSL 10 Support Notes 78 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL SSL10 Step1. Pleas

Page 80

ZyWALL SSL 10 Support Notes 79 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on ZyWALL UTM Step1. Create p

Page 81

ZyWALL SSL 10 Support Notes 8 All contents copyright (c) 2006 ZyXEL Communications Corporation. 4) Go to the GUI > Network > LAN, conf

Page 82

ZyWALL SSL 10 Support Notes 80 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step2. Make sure firewall rule allow SSL traf

Page 83

ZyWALL SSL 10 Support Notes 81 All contents copyright (c) 2006 ZyXEL Communications Corporation. UTM’s HTTPS management port number from port 4

Page 84

ZyWALL SSL 10 Support Notes 82 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step4. Allow NetBIOS between WAN and DMZ, D

Page 85

ZyWALL SSL 10 Support Notes 83 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2) Enter the information as below. Note the

Page 86

ZyWALL SSL 10 Support Notes 84 All contents copyright (c) 2006 ZyXEL Communications Corporation. 3) You will enter the portal, continue to cl

Page 87

ZyWALL SSL 10 Support Notes 85 All contents copyright (c) 2006 ZyXEL Communications Corporation. 6) Enter the username and password, you will

Page 88

ZyWALL SSL 10 Support Notes 86 All contents copyright (c) 2006 ZyXEL Communications Corporation. 4. Best Practice: Stronger Password Security

Page 89

ZyWALL SSL 10 Support Notes 87 All contents copyright (c) 2006 ZyXEL Communications Corporation. Note: To use two-factor authentication, it’s r

Page 90

ZyWALL SSL 10 Support Notes 88 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step3. Setup AAA server 1) Go to GUI > Sy

Page 91

ZyWALL SSL 10 Support Notes 89 All contents copyright (c) 2006 ZyXEL Communications Corporation. Configuration on Authenex Server 1). Conne

Page 92

ZyWALL SSL 10 Support Notes 9 All contents copyright (c) 2006 ZyXEL Communications Corporation. Step3. Check if UTM functions (ex. Firewall, An

Page 93

ZyWALL SSL 10 Support Notes 90 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2). Go to Server Configuration > Add NAS E

Page 94 - A. ZyWALL General FAQ

ZyWALL SSL 10 Support Notes 91 All contents copyright (c) 2006 ZyXEL Communications Corporation. Then edit the user and check the Assign only

Page 95

ZyWALL SSL 10 Support Notes 92 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5). Go to Manage A-Keys > Search A-Keys, se

Page 96

ZyWALL SSL 10 Support Notes 93 All contents copyright (c) 2006 ZyXEL Communications Corporation. 2). After successful login, you could see the

Page 97

ZyWALL SSL 10 Support Notes 94 All contents copyright (c) 2006 ZyXEL Communications Corporation. 5. FAQ A. ZyWALL General FAQ A01. How to acces

Page 98

ZyWALL SSL 10 Support Notes 95 All contents copyright (c) 2006 ZyXEL Communications Corporation. A05. Does the ZyWALL support PPPoE? Yes. The Z

Page 99 - B. Firmware Upgrade FAQ

ZyWALL SSL 10 Support Notes 96 All contents copyright (c) 2006 ZyXEL Communications Corporation. A09. What can we do with ZyWALL? Browse the

Page 100 - D. SSL VPN FAQ

ZyWALL SSL 10 Support Notes 97 All contents copyright (c) 2006 ZyXEL Communications Corporation. dynamic IP address. Suppose your company'

Page 101 - E. EPC(End Point Check) FAQ

ZyWALL SSL 10 Support Notes 98 All contents copyright (c) 2006 ZyXEL Communications Corporation. 1. Check if the 'MAC address' is va

Page 102

ZyWALL SSL 10 Support Notes 99 All contents copyright (c) 2006 ZyXEL Communications Corporation. B. Firmware Upgrade FAQ B01. How to perform th

Commentaires sur ces manuels

Pas de commentaire