{"id":3187,"date":"2012-12-13T03:37:46","date_gmt":"2012-12-13T03:37:46","guid":{"rendered":"http:\/\/blog.pmail.idv.tw\/?p=3187"},"modified":"2012-12-13T03:37:46","modified_gmt":"2012-12-13T03:37:46","slug":"fortigate-60b-ssl-vpn-%e8%a8%ad%e5%ae%9a","status":"publish","type":"post","link":"https:\/\/blog.pmail.idv.tw\/?p=3187","title":{"rendered":"Fortigate 60B SSL VPN \u8a2d\u5b9a"},"content":{"rendered":"<p>OS \u7248\u672c\u70ba v4.0,build0513,120130 (MR3 Patch 5)<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl1.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl1\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl1\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl1_thumb.jpg\" width=\"244\" height=\"16\"><\/a><\/p>\n<p><!--more--><\/p>\n<p>\u5efa\u7acb\u6b65\u9a5f<\/p>\n<p>1. <strong>\u5efa\u7acb\u4f7f\u7528\u8005<\/strong><\/p>\n<p><strong>\u5728web console \uff0c \u4f7f\u7528\u8005\u8a8d\u8b49 \u5efa\u7acbsslvpn user<\/strong><\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ss2.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ss2\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ss2\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ss2_thumb.jpg\" width=\"244\" height=\"145\"><\/a><\/p>\n<p>2.\u5efa\u7acbSSL vpn \u7fa4\u7d44<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl3.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl3\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl3\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl3_thumb.jpg\" width=\"224\" height=\"165\"><\/a><\/p>\n<p>\u5c07\u4e0a\u500b\u6b65\u9a5f\u5efa\u7acb\u597d\u7684user \u52a0\u5165\u7fa4\u7d44<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl4.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl4\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl4\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl4_thumb.jpg\" width=\"244\" height=\"122\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>3. <strong>\u5efa\u7acb VPN \u7528\u6236 ip \u7bc4\u570d<\/strong><\/p>\n<p><strong><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl8.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl8\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl8\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl8_thumb.jpg\" width=\"244\" height=\"24\"><\/a><\/strong><\/p>\n<p><strong><\/strong>&nbsp;<\/p>\n<p>4.\u8a2d\u5b9avpn<\/p>\n<p>\u9810\u8a2d\u6b64\u7248\u672c \u76f4\u63a5\u555f\u7528ssl vpn \u6240\u4ee5\u5728\u5716\u5f62\u4ecb\u9762\u4e0a\u770b\u4e0d\u5230enable ssl-vpn \u9078\u9805<\/p>\n<p>\u5728 VPN &#8212;&gt; SSL &#8212;&gt; SSL \u8a2d\u5b9a<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl5.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl5\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl5\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl5_thumb.jpg\" width=\"231\" height=\"243\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>5.\u4f7f\u7528\u8005\u767b\u5165\u4ecb\u9762\u8a2d\u5b9a<\/p>\n<p>\u56e0\u70ba\u6211\u4f7f\u7528ssl vpn \u76ee\u7684\u662f\u70ba\u4e86\u8b93\u5728\u5c0d\u5cb8\u7684\u670b\u53cb\u53ef\u4ee5\u9806\u5229\u7528\u6211\u9019\u4e00\u53f060B \u4e0a\u7db2<\/p>\n<p>\u6240\u4ee5\u4f7f\u7528\u8005\u4ecb\u9762\u6211\u662f\u8a2d\u5b9a\u986f\u793a [Tunnel Mode]<\/p>\n<p>\u4e14\u4e0d\u52fe\u9078 [\u5206\u96e2\u901a\u9053\u6a21\u5f0f]&nbsp; <\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl31.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl31\" style=\"border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px\" border=\"0\" alt=\"ssl31\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl31_thumb.jpg\" width=\"244\" height=\"104\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>6. \u8a2d\u5b9afirewall policy<\/p>\n<p>WAN \u81f3 Internal&nbsp; <\/p>\n<p>\u63a1\u53d6\u884c\u52d5\u7684\u9078\u9805\u52d9\u5fc5\u8981\u9078 SSL-VPN, \u7528\u6236\u7fa4\u7d44\u8981\u52a0\u5165\u525b\u525b\u65b0\u589e\u7684SSLVPN \u7fa4\u7d44)<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl11.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl11\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl11\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl11_thumb.jpg\" width=\"244\" height=\"157\"><\/a>&nbsp; <a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl12.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl12\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl12\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl12_thumb.jpg\" width=\"244\" height=\"128\"><\/a><\/p>\n<p>Internal&nbsp; TO ssl.root \u5167\u7db2\u4e92\u901a<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl13.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl13\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl13\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl13_thumb.jpg\" width=\"244\" height=\"16\"><\/a><\/p>\n<p>ssl.root TO Internal \u5167\u7db2\u4e92\u901a<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl15.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl15\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl15\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl15_thumb.jpg\" width=\"244\" height=\"16\"><\/a><\/p>\n<p>ssl.root \u81f3 TOWAN (\u555f\u7528 NAT)<\/p>\n<p><a href=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl16.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" title=\"ssl16\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"ssl16\" src=\"https:\/\/blog.pmail.idv.tw\/wp-content\/uploads\/2012\/12\/ssl16_thumb.jpg\" width=\"244\" height=\"182\"><\/a><\/p>\n<div class=\"21cd169d3c0f71e95b84db320302cb4a\" data-index=\"1\" style=\"float: right; margin:10px 0 10px 10px;\">\n<script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-8711325745898650\"\r\n     crossorigin=\"anonymous\"><\/script>\n<\/div>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>OS \u7248\u672c\u70ba v4.0,build0513,120130 (MR3 Patch  &hellip; <a href=\"https:\/\/blog.pmail.idv.tw\/?p=3187\">\u95b1\u8b80\u5168\u6587 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[56],"tags":[],"class_list":["post-3187","post","type-post","status-publish","format-standard","hentry","category-fg"],"_links":{"self":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/3187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3187"}],"version-history":[{"count":0,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/3187\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}