資源描述:
《sonicwall防火墻跨節(jié)點vpn路由配置》由會員上傳分享,免費在線閱讀,更多相關內(nèi)容在工程資料-天天文庫。
1、Sonicwall防火墻跨節(jié)點VPN路由配置指引:(兩個或多個分店VPN節(jié)點互通配置)例如:分店A與分店B需要互通版本要求:Firewallrequirements?SonicOS2.0.1.3Enhancedorlater?SonicOS2.0.1.3Enhaneedorlater?SOHO3firmware6.4.x.xorlater集團主防火墻配置:1>登陸集團主防火墻Network->AddressObjectspageclickAddGroup..?button2、建立Jtgroup_A分店Group并添加集團及分店A網(wǎng)段3、建立Jtgroup_B分店Group并
2、添加集團及分店B網(wǎng)段4、找到分店AVPN配置條目——EDIT——NETWORK——LocalNetworks配置Chooselocalnetworkfromlist項,修改為Jtgroup_BLocalNetworks5、找到分店BVPN配置條目——EDIT——NETWORK——配置Chooselocalnetworkfromlist項,修改為Jtgroup_A分店A防火墻配置:1>登陸分店A防火墻NetworkAddressObjectspage,clickAdd..?button2、添加分丿占B店網(wǎng)段,網(wǎng)絡類型設置為Network,ZoneAssignment:設置為V
3、PN例:B分店_192.168.X.03、Network9AddressObjectspageclickEDITGroup..?button編輯JTGROUP組,將剛建立的分店B網(wǎng)段添加至該組。分店B防火墻配置:1>登陸分店B防火墻Network9AddressObjectspage,clickAdd..?button2、添加分店A店網(wǎng)段,網(wǎng)絡類型設置為Network,ZoneAssignment:設置為VPN例:A分店_192.168.X.O3、Network->AddressObjectspageclickEDITGroup...button編輯JTGROUP組,將剛建
4、立的分店B網(wǎng)段添加至該組。TZ170ConfigurationNetworkConfiauration1.GotoNetworkInterfacespage.ClicktheConfigureiconsofLANandWAN2.SetupLANIP=172.16.2.254mask=255.255.255.03.SetupWANIP=1.1.1.2mask=255.255.255.248,gateway=1.1.1.7AddressObjectsConfiauration4.WeneedtodefineremoteLANobjectsforVPNuse5.GotoNetwo
5、rkTAddressObjectspage,clickAdd..?button6.AddthefollowingnetworksforheadquartersBeijingandbranchShanghaiName:Type:Network:BeijingJ72.16.1.0Networkv172.16.1.0VPNvCancel255.255.255.0Netmask:ZoneAssignment芻EditAddressObject-MicrosoftInternetExplorer口兇1.ClickOKbuttonforeachaddressobjecttofinish
6、VSC40一uo-lnqnoM2O?LLSN<1QloEQQrolueNJQdsdxalauJow-cOSOJEW?dnojytsaHoSS2JPPpp<>l.2o<06edsloarqossa).lpp<個M』o/VQa)N0100?6一e匸quellspuw6u-=①g①pnou一01dno」6ss①」ppeue①leal。」x①n?8S6U-AAO--OJ①一
7、i①」匸uoo‘qel(5」eue0£1u-?寸
8、Luollnqpp<倍一oo6edS6ES①S個Nd>0100?COL6u二0801souunlNd>」0J(uoleoossvAluno①s)VSL①匸匸①p0?」x①ncyiLuo一le」nD匸uooNd>15.IntheGeneraltab,configurethefollowings16.IntheProposalstab,configurethefollowings3VPMPolicy-MicrosoftInternetExplorerProposalsAdvancedGeneralNetworkIKE(