<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Firewall &#8211; VACIF</title>
	<atom:link href="https://vacif.com/category/huong-dan-tai-lieu/bao-mat/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>https://vacif.com</link>
	<description>Đầu tư cho giá trị</description>
	<lastBuildDate>Thu, 14 May 2026 10:01:11 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://vacif.com/wp-content/uploads/2024/06/cropped-icon-32x32.png</url>
	<title>Firewall &#8211; VACIF</title>
	<link>https://vacif.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>[Mới Nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình Tính Năng Zero-Day Protection</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-tinh-nang-zero-day-protection/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-tinh-nang-zero-day-protection/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 14 May 2026 10:01:11 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=30029</guid>

					<description><![CDATA[Zero-day Protection được vận hành bởi SophosLabs Intelix, là một dịch vụ đám mây kết hợp machine learning, sandboxing và năng lực nghiên cứu mối đe dọa để phát hiện cả các mối nguy đã biết và chưa biết thông qua việc phân tích các tệp tải xuống đáng ngờ và file đính kèm email. [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Zero-day Protection l\u00e0 g\u00ec?&quot;,&quot;text&quot;:&quot;1. Zero-day Protection l\u00e0 g\u00ec?&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u00e1c th\u00e0nh ph\u1ea7n ch\u00ednh c\u1ee7a t\u00ednh n\u0103ng Zero-day Protecion&quot;,&quot;text&quot;:&quot;2. C\u00e1c th\u00e0nh ph\u1ea7n ch\u00ednh c\u1ee7a t\u00ednh n\u0103ng Zero-day Protecion&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.1 Machine Learning&quot;,&quot;text&quot;:&quot;2.1 Machine Learning&quot;,&quot;link&quot;:&quot;21-machine-learning&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.2 Ph\u00e2n t\u00edch Sandbox&quot;,&quot;text&quot;:&quot;2.2 Ph\u00e2n t\u00edch Sandbox&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;II - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u00e0i \u0111\u1eb7t SSL Certificate tr\u00ean m\u00e1y t\u00ednh c\u1ee7a ng\u01b0\u1eddi d\u00f9ng&quot;,&quot;text&quot;:&quot;1. C\u00e0i \u0111\u1eb7t SSL Certificate tr\u00ean m\u00e1y t\u00ednh c\u1ee7a ng\u01b0\u1eddi d\u00f9ng&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u1ea5u h\u00ecnh rule Zero-day Protection&quot;,&quot;text&quot;:&quot;2. C\u1ea5u h\u00ecnh rule Zero-day Protection&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. C\u1ea5u h\u00ecnh rule SSL Inspection&quot;,&quot;text&quot;:&quot;3. C\u1ea5u h\u00ecnh rule SSL Inspection&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4. Ki\u1ec3m tra c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;4. Ki\u1ec3m tra c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4.1. Test block virus&quot;,&quot;text&quot;:&quot;4.1. Test block virus&quot;,&quot;link&quot;:&quot;41-test-block-virus&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4.2 Test t\u00ednh n\u0103ng Sandboxing&quot;,&quot;text&quot;:&quot;4.2 Test t\u00ednh n\u0103ng Sandboxing&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Zero-day Protection l\u00e0 g\u00ec?&quot;,&quot;value&quot;:&quot;1-zero-day-protection-l\u00e0-g\u00ec&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. C\u00e1c th\u00e0nh ph\u1ea7n ch\u00ednh c\u1ee7a t\u00ednh n\u0103ng Zero-day Protecion&quot;,&quot;value&quot;:&quot;2-c\u00e1c-th\u00e0nh-ph\u1ea7n-ch\u00ednh-c\u1ee7a-t\u00ednh-n\u0103ng-zero-day-protecion&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.1 Machine Learning&quot;,&quot;value&quot;:&quot;21-machine-learning&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.2 Ph\u00e2n t\u00edch Sandbox&quot;,&quot;value&quot;:&quot;22-ph\u00e2n-t\u00edch-sandbox&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;II - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;ii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u00e0i \u0111\u1eb7t SSL Certificate tr\u00ean m\u00e1y t\u00ednh c\u1ee7a ng\u01b0\u1eddi d\u00f9ng&quot;,&quot;value&quot;:&quot;1-c\u00e0i-\u0111\u1eb7t-ssl-certificate-tr\u00ean-m\u00e1y-t\u00ednh-c\u1ee7a-ng\u01b0\u1eddi-d\u00f9ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u1ea5u h\u00ecnh rule Zero-day Protection&quot;,&quot;value&quot;:&quot;2-c\u1ea5u-h\u00ecnh-rule-zero-day-protection&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;3. C\u1ea5u h\u00ecnh rule SSL Inspection&quot;,&quot;value&quot;:&quot;3-c\u1ea5u-h\u00ecnh-rule-ssl-inspection&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;4. Ki\u1ec3m tra c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;4-ki\u1ec3m-tra-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;4.1. Test block virus&quot;,&quot;value&quot;:&quot;41-test-block-virus&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;4.2 Test t\u00ednh n\u0103ng Sandboxing&quot;,&quot;value&quot;:&quot;42-test-t\u00ednh-n\u0103ng-sandboxing&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan bài viết</a><li><a href="#eb-table-content-5">II &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-6">III &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-7">1. Cài đặt SSL Certificate trên máy tính của người dùng</a><li><a href="#eb-table-content-8">2. Cấu hình rule Zero-day Protection</a><li><a href="#eb-table-content-9">3. Cấu hình rule SSL Inspection</a><li><a href="#eb-table-content-10">4. Kiểm tra cấu hình</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan bài viết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iar4g"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iar4g "><div class="eb-advance-heading-wrapper eb-advance-heading-iar4g button-1 undefined" data-id="eb-advance-heading-iar4g"><h2 class="eb-ah-title"><span class="first-title">1. Zero-day Protection là gì?</span></h2></div></div></div>



<p><strong>Zero-day Protection </strong>được vận hành bởi <strong>SophosLabs Intelix</strong>, là một dịch vụ đám mây kết hợp <strong>machine learning</strong>, <strong>sandboxing</strong> và năng lực nghiên cứu mối đe dọa để phát hiện cả các mối nguy đã biết và chưa biết thông qua việc phân tích các tệp tải xuống đáng ngờ và file đính kèm email.</p>



<p><strong>Sophos Firewall</strong> sẽ gửi các tệp mới đến <strong>SophosLabs Intelix</strong> để thực hiện phân tích bảo vệ zero-day khi các tệp này đi vào mạng của bạn. Intelix sử dụng nhiều lớp phân tích để xác định mức độ rủi ro mà từng tệp có thể gây ra cho hệ thống mạng. Ngoài việc chặn các tệp nguy hiểm, tính năng zero-day protection còn cung cấp các báo cáo phân tích chi tiết giúp bạn hiểu rõ mức độ rủi ro của từng tệp.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-la6ko"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-la6ko "><div class="eb-advance-heading-wrapper eb-advance-heading-la6ko button-1 undefined" data-id="eb-advance-heading-la6ko"><h2 class="eb-ah-title"><span class="first-title">2. Các thành phần chính của tính năng Zero-day Protecion</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dh7sf"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dh7sf "><div class="eb-advance-heading-wrapper eb-advance-heading-dh7sf button-1 undefined" data-id="eb-advance-heading-dh7sf"><h2 class="eb-ah-title"><span class="first-title">2.1 Machine Learning</span></h2></div></div></div>



<p>SophosLabs Intelix sử dụng nhiều mô hình machine learning để phân tích đặc điểm, tính năng, mã di truyền (genetics) và uy tín toàn cầu của tệp. Hệ thống sẽ so sánh các tệp mới với hàng triệu tệp đã được xác định là an toàn hoặc độc hại để đánh giá khả năng tệp mới có phải là mã độc hay không.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8ae3q"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8ae3q "><div class="eb-advance-heading-wrapper eb-advance-heading-8ae3q button-1 undefined" data-id="eb-advance-heading-8ae3q"><h2 class="eb-ah-title"><span class="first-title">2.2 Phân tích Sandbox</span></h2></div></div></div>



<p>Phân tích sandbox thực hiện cả phân tích động và phân tích tĩnh đối với các tệp mới đi vào mạng của bạn. Quá trình này bao gồm:</p>



<ul class="wp-block-list">
<li>Phân tích bằng deep learning</li>



<li>Phát hiện khai thác lỗ hổng (exploit detection)</li>



<li>Công nghệ <strong>CryptoGuard</strong> để phát hiện ransomware đang mã hóa dữ liệu theo thời gian thực</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-91mg7"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-91mg7 "><div class="eb-advance-heading-wrapper eb-advance-heading-91mg7 button-1 undefined" data-id="eb-advance-heading-91mg7"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>PC/laptop người dùng trong mạng sẽ thực hiện download các tệp đáng ngờ trên trình duyệt Chrome, khi đó Sophos firewall đã cấu hình tính năng Zero-day sẽ thực hiệnscan file download từ trình duyệt Chrome với protocol HTTP/HTTPS, với các tệp đáng ngờ sẽ có action là block download.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4kkae"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4kkae "><div class="eb-advance-heading-wrapper eb-advance-heading-4kkae button-1 undefined" data-id="eb-advance-heading-4kkae"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-aw5t0"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-aw5t0 "><div class="eb-advance-heading-wrapper eb-advance-heading-aw5t0 button-1 undefined" data-id="eb-advance-heading-aw5t0"><h2 class="eb-ah-title"><span class="first-title">1. Cài đặt SSL Certificate trên máy tính của người dùng</span></h2></div></div></div>



<p>Kiểm tra cài đặt Zero-day Protection vào mục Zero-day Protection > Protection Settings > Data Center Location chọn Let Sophos Decide.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="2560" height="826" src="https://vacif.com/wp-content/uploads/2026/05/image-190-scaled.png" alt="" class="wp-image-30030" srcset="https://vacif.com/wp-content/uploads/2026/05/image-190-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-190-300x97.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-190-1024x330.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-190-768x248.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-190-1536x495.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-190-2048x660.png 2048w" sizes="(max-width: 2560px) 100vw, 2560px" /></figure>



<p>Di chuyển xuống mục Certificate > Certificate Authorities > chọn download Security Appliance SSL_CA.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="2560" height="662" src="https://vacif.com/wp-content/uploads/2026/05/image-191-scaled.png" alt="" class="wp-image-30031" srcset="https://vacif.com/wp-content/uploads/2026/05/image-191-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-191-300x78.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-191-1024x265.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-191-768x199.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-191-1536x397.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-191-2048x530.png 2048w" sizes="(max-width: 2560px) 100vw, 2560px" /></figure>



<p>Di chuyển qua máy tính của người dùng, add Certificates, chọn All tasks > Import</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1988" height="1141" src="https://vacif.com/wp-content/uploads/2026/05/image-192.png" alt="" class="wp-image-30032" srcset="https://vacif.com/wp-content/uploads/2026/05/image-192.png 1988w, https://vacif.com/wp-content/uploads/2026/05/image-192-300x172.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-192-1024x588.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-192-768x441.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-192-1536x882.png 1536w" sizes="(max-width: 1988px) 100vw, 1988px" /></figure>



<p>Chọn Browse, click chọn Certificates SSL_CA vừa tải xuống ở bước trên. Click Next</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="1026" height="1007" src="https://vacif.com/wp-content/uploads/2026/05/image-193.png" alt="" class="wp-image-30033" style="aspect-ratio:1.01887686446942;width:457px;height:auto" srcset="https://vacif.com/wp-content/uploads/2026/05/image-193.png 1026w, https://vacif.com/wp-content/uploads/2026/05/image-193-300x294.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-193-1024x1005.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-193-768x754.png 768w" sizes="auto, (max-width: 1026px) 100vw, 1026px" /></figure>



<p>Chọn Place all certificates in following store. Chọn Trust root Certificates Authorities. Click Next</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="1083" height="1045" src="https://vacif.com/wp-content/uploads/2026/05/image-194.png" alt="" class="wp-image-30034" style="aspect-ratio:1.0363780074028377;width:473px;height:auto" srcset="https://vacif.com/wp-content/uploads/2026/05/image-194.png 1083w, https://vacif.com/wp-content/uploads/2026/05/image-194-300x289.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-194-1024x988.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-194-768x741.png 768w" sizes="auto, (max-width: 1083px) 100vw, 1083px" /></figure>



<p>Chọn Finish. Import thành công.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="559" src="https://vacif.com/wp-content/uploads/2026/05/image-195.png" alt="" class="wp-image-30035" srcset="https://vacif.com/wp-content/uploads/2026/05/image-195.png 975w, https://vacif.com/wp-content/uploads/2026/05/image-195-300x172.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-195-768x440.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="561" src="https://vacif.com/wp-content/uploads/2026/05/image-196.png" alt="" class="wp-image-30036" srcset="https://vacif.com/wp-content/uploads/2026/05/image-196.png 975w, https://vacif.com/wp-content/uploads/2026/05/image-196-300x173.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-196-768x442.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hlffp"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hlffp "><div class="eb-advance-heading-wrapper eb-advance-heading-hlffp button-1 undefined" data-id="eb-advance-heading-hlffp"><h2 class="eb-ah-title"><span class="first-title">2. Cấu hình rule Zero-day Protection</span></h2></div></div></div>



<p>Truy cập&nbsp;Rule and policies&nbsp;&gt;&nbsp;Firewall rules&nbsp;&gt;&nbsp;Add firewall rule&nbsp;&gt;&nbsp;New firewall rule.</p>



<ul class="wp-block-list">
<li>Rule Name: Điền tên bạn muốn</li>



<li>Action: chọn Accept</li>



<li>Tích chọn Log firewall traffic để xem log match với rule này</li>



<li>Source zone: LAN</li>



<li>Source networks and devices: Test_VM (IP:123.123.123.203/24)</li>



<li>Destination Zones: WAN</li>



<li>Destination networks: Any</li>



<li>Services: Any</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2092" height="928" src="https://vacif.com/wp-content/uploads/2026/05/image-201.png" alt="" class="wp-image-30041" srcset="https://vacif.com/wp-content/uploads/2026/05/image-201.png 2092w, https://vacif.com/wp-content/uploads/2026/05/image-201-300x133.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-201-1024x454.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-201-768x341.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-201-1536x681.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-201-2048x908.png 2048w" sizes="auto, (max-width: 2092px) 100vw, 2092px" /></figure>



<p>Trong Web Policy chọn&nbsp;<strong>Scan HTTP and Decrypted HTTPS và Use Zero-day Protection</strong>&nbsp;để sử dụng tính năng này.</p>



<p>Nhấn&nbsp;<strong>Save&nbsp;</strong>để lưu</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1030" src="https://vacif.com/wp-content/uploads/2026/05/image-202-scaled.png" alt="" class="wp-image-30042" srcset="https://vacif.com/wp-content/uploads/2026/05/image-202-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-202-300x121.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-202-1024x412.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-202-768x309.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-202-1536x618.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-202-2048x824.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-7vdmn"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-7vdmn "><div class="eb-advance-heading-wrapper eb-advance-heading-7vdmn button-1 undefined" data-id="eb-advance-heading-7vdmn"><h2 class="eb-ah-title"><span class="first-title">3. Cấu hình rule SSL Inspection</span></h2></div></div></div>



<p>Di chuyển đến tab Rules and policies. > Chọn tab SSL/TLS inspection rules > Click Add</p>



<ul class="wp-block-list">
<li>Name: Đặt tên policy bạn muốn</li>



<li>Source zones: LAN.</li>



<li>Source networks and devices: chọn Test VM.</li>



<li>Destination zones: WAN.</li>



<li>Action: Chọn Decrypt.</li>



<li>Profile: chọn Maximum compatibility.</li>
</ul>



<p>Nhấn Save.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1188" src="https://vacif.com/wp-content/uploads/2026/05/image-200-scaled.png" alt="" class="wp-image-30040" srcset="https://vacif.com/wp-content/uploads/2026/05/image-200-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-200-300x139.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-200-1024x475.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-200-768x356.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-200-1536x713.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-200-2048x951.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p>Đối với trình duyệt Chrome thường dùng kho chứng chỉ riêng nên nếu muốn scan http/https 1 cách hiệu quả phải add thêm chứng chỉ SSL_CA của Sophos.</p>



<p>Mở trình duyệt, vào Settings (Cài đặt).Tìm kiếm từ khóa &#8220;Quản lý chứng chỉ&#8221;. Click chọn &#8220;Chứng chỉ được nhập từ windows&#8221; chọn tab Trust root Certification Authorities &gt; Import.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1924" height="922" src="https://vacif.com/wp-content/uploads/2026/05/image-203.png" alt="" class="wp-image-30043" srcset="https://vacif.com/wp-content/uploads/2026/05/image-203.png 1924w, https://vacif.com/wp-content/uploads/2026/05/image-203-300x144.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-203-1024x491.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-203-768x368.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-203-1536x736.png 1536w" sizes="auto, (max-width: 1924px) 100vw, 1924px" /></figure>



<p>Click Browse > chọn SSL_CA.pem của Sophos > click Next.</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="1163" height="1134" src="https://vacif.com/wp-content/uploads/2026/05/image-204.png" alt="" class="wp-image-30044" style="aspect-ratio:1.0255828150635278;width:488px;height:auto" srcset="https://vacif.com/wp-content/uploads/2026/05/image-204.png 1163w, https://vacif.com/wp-content/uploads/2026/05/image-204-300x293.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-204-1024x998.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-204-768x749.png 768w" sizes="auto, (max-width: 1163px) 100vw, 1163px" /></figure>



<p>Import thành công. Click OK.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1947" height="991" src="https://vacif.com/wp-content/uploads/2026/05/image-205.png" alt="" class="wp-image-30045" srcset="https://vacif.com/wp-content/uploads/2026/05/image-205.png 1947w, https://vacif.com/wp-content/uploads/2026/05/image-205-300x153.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-205-1024x521.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-205-768x391.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-205-1536x782.png 1536w" sizes="auto, (max-width: 1947px) 100vw, 1947px" /></figure>



<p>Kiểm tra chứng chỉ SSL_CA đã được add vào trình duyệt.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1535" height="966" src="https://vacif.com/wp-content/uploads/2026/05/image-206.png" alt="" class="wp-image-30046" srcset="https://vacif.com/wp-content/uploads/2026/05/image-206.png 1535w, https://vacif.com/wp-content/uploads/2026/05/image-206-300x189.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-206-1024x644.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-206-768x483.png 768w" sizes="auto, (max-width: 1535px) 100vw, 1535px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dr5di"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dr5di "><div class="eb-advance-heading-wrapper eb-advance-heading-dr5di button-1 undefined" data-id="eb-advance-heading-dr5di"><h2 class="eb-ah-title"><span class="first-title">4. Kiểm tra cấu hình</span></h2></div></div></div>



<p>Truy cập vào trang Sophostest của Sophos, kiểm tra trang web đang sử dụng chứng chỉ SSL_CA.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2063" height="1460" src="https://vacif.com/wp-content/uploads/2026/05/image-207.png" alt="" class="wp-image-30047" srcset="https://vacif.com/wp-content/uploads/2026/05/image-207.png 2063w, https://vacif.com/wp-content/uploads/2026/05/image-207-300x212.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-207-1024x725.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-207-768x544.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-207-1536x1087.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-207-2048x1449.png 2048w" sizes="auto, (max-width: 2063px) 100vw, 2063px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-6nx4k"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-6nx4k "><div class="eb-advance-heading-wrapper eb-advance-heading-6nx4k button-1 undefined" data-id="eb-advance-heading-6nx4k"><h2 class="eb-ah-title"><span class="first-title">4.1. Test block virus</span></h2></div></div></div>



<p>Click chọn Anti-virus Eicar > Download</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1618" height="970" src="https://vacif.com/wp-content/uploads/2026/05/image-208.png" alt="" class="wp-image-30048" srcset="https://vacif.com/wp-content/uploads/2026/05/image-208.png 1618w, https://vacif.com/wp-content/uploads/2026/05/image-208-300x180.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-208-1024x614.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-208-768x460.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-208-1536x921.png 1536w" sizes="auto, (max-width: 1618px) 100vw, 1618px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1386" height="940" src="https://vacif.com/wp-content/uploads/2026/05/image-209.png" alt="" class="wp-image-30049" srcset="https://vacif.com/wp-content/uploads/2026/05/image-209.png 1386w, https://vacif.com/wp-content/uploads/2026/05/image-209-300x203.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-209-1024x694.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-209-768x521.png 768w" sizes="auto, (max-width: 1386px) 100vw, 1386px" /></figure>



<p>Trình duyệt báo lỗi không thể truy cập</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1680" height="1011" src="https://vacif.com/wp-content/uploads/2026/05/image-210.png" alt="" class="wp-image-30050" srcset="https://vacif.com/wp-content/uploads/2026/05/image-210.png 1680w, https://vacif.com/wp-content/uploads/2026/05/image-210-300x181.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-210-1024x616.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-210-768x462.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-210-1536x924.png 1536w" sizes="auto, (max-width: 1680px) 100vw, 1680px" /></figure>



<p>Kiểm tra log Malware trên Sophos firewall báo đã block file tải xuống với protocol Https.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="555" src="https://vacif.com/wp-content/uploads/2026/05/image-211-scaled.png" alt="" class="wp-image-30051" srcset="https://vacif.com/wp-content/uploads/2026/05/image-211-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-211-300x65.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-211-1024x222.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-211-768x166.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-211-1536x333.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-211-2048x444.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-nivmm"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-nivmm "><div class="eb-advance-heading-wrapper eb-advance-heading-nivmm button-1 undefined" data-id="eb-advance-heading-nivmm"><h2 class="eb-ah-title"><span class="first-title">4.2 Test tính năng Sandboxing</span></h2></div></div></div>



<p>Truy cập Sophostest > chọn Intelix Potentially Unwanted Application (PUA) Reputation EXE file > Download.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1481" height="1058" src="https://vacif.com/wp-content/uploads/2026/05/image-212.png" alt="" class="wp-image-30052" srcset="https://vacif.com/wp-content/uploads/2026/05/image-212.png 1481w, https://vacif.com/wp-content/uploads/2026/05/image-212-300x214.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-212-1024x732.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-212-768x549.png 768w" sizes="auto, (max-width: 1481px) 100vw, 1481px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1137" height="843" src="https://vacif.com/wp-content/uploads/2026/05/image-213.png" alt="" class="wp-image-30053" srcset="https://vacif.com/wp-content/uploads/2026/05/image-213.png 1137w, https://vacif.com/wp-content/uploads/2026/05/image-213-300x222.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-213-1024x759.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-213-768x569.png 768w" sizes="auto, (max-width: 1137px) 100vw, 1137px" /></figure>



<p>Trình duyệt báo lỗi truy cập</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1264" height="772" src="https://vacif.com/wp-content/uploads/2026/05/image-214.png" alt="" class="wp-image-30054" srcset="https://vacif.com/wp-content/uploads/2026/05/image-214.png 1264w, https://vacif.com/wp-content/uploads/2026/05/image-214-300x183.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-214-1024x625.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-214-768x469.png 768w" sizes="auto, (max-width: 1264px) 100vw, 1264px" /></figure>



<p>Kiểm tra log Zero-day Protection đã block file tải xuống.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="706" src="https://vacif.com/wp-content/uploads/2026/05/image-215-scaled.png" alt="" class="wp-image-30055" srcset="https://vacif.com/wp-content/uploads/2026/05/image-215-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-215-300x83.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-215-1024x282.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-215-768x212.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-215-1536x423.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-215-2048x565.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p>Bạn có thể truy cập bào tab Zero-day protection > Download and attachments để có các thông tin rõ ràng hơn về các file đã tải xuống.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2165" height="827" src="https://vacif.com/wp-content/uploads/2026/05/image-216.png" alt="" class="wp-image-30056" srcset="https://vacif.com/wp-content/uploads/2026/05/image-216.png 2165w, https://vacif.com/wp-content/uploads/2026/05/image-216-300x115.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-216-1024x391.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-216-768x293.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-216-1536x587.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-216-2048x782.png 2048w" sizes="auto, (max-width: 2165px) 100vw, 2165px" /></figure>



<p>Click chọn icon 3 chấm > View report về 1 file cụ thể</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1936" height="903" src="https://vacif.com/wp-content/uploads/2026/05/image-217.png" alt="" class="wp-image-30057" srcset="https://vacif.com/wp-content/uploads/2026/05/image-217.png 1936w, https://vacif.com/wp-content/uploads/2026/05/image-217-300x140.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-217-1024x478.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-217-768x358.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-217-1536x716.png 1536w" sizes="auto, (max-width: 1936px) 100vw, 1936px" /></figure>



<p>Vậy, bạn đã hoàn thành cấu hình tính năng Zero-Day Protection trên Sophos Firewall</p>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-tinh-nang-zero-day-protection/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] Sophos Firewall: [Sophos Firewall XGS] Hướng Dẫn Cấu Hình SD-RED 60 Mode Standard/ Unified</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-sophos-firewall-xgs-huong-dan-cau-hinh-sd-red-60-mode-standard-unified/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-sophos-firewall-xgs-huong-dan-cau-hinh-sd-red-60-mode-standard-unified/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 14 May 2026 09:01:34 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=30014</guid>

					<description><![CDATA[SD-RED 60 ở chế độ Standard/Unified cho phép kết nối chi nhánh hoặc văn phòng từ xa về Sophos Firewall XGS thông qua một đường hầm bảo mật qua Internet. Toàn bộ mạng phía sau thiết bị RED sẽ được xem như một phần của mạng LAN nội bộ, do firewall trung tâm quản lý [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - M\u00f4 h\u00ecnh&quot;,&quot;text&quot;:&quot;II - M\u00f4 h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - C\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - C\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u1ea5u h\u00ecnh RED&quot;,&quot;text&quot;:&quot;1. C\u1ea5u h\u00ecnh RED&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u1ea5u h\u00ecnh Zone&quot;,&quot;text&quot;:&quot;2. C\u1ea5u h\u00ecnh Zone&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. C\u1ea5u h\u00ecnh Interface&quot;,&quot;text&quot;:&quot;3. C\u1ea5u h\u00ecnh Interface&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4. C\u1ea5u h\u00ecnh ch\u00ednh s\u00e1ch&quot;,&quot;text&quot;:&quot;4. C\u1ea5u h\u00ecnh ch\u00ednh s\u00e1ch&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - K\u1ebft lu\u1eadn&quot;,&quot;text&quot;:&quot;IV - K\u1ebft lu\u1eadn&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - M\u00f4 h\u00ecnh&quot;,&quot;value&quot;:&quot;ii-m\u00f4-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - C\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u1ea5u h\u00ecnh RED&quot;,&quot;value&quot;:&quot;1-c\u1ea5u-h\u00ecnh-red&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u1ea5u h\u00ecnh Zone&quot;,&quot;value&quot;:&quot;2-c\u1ea5u-h\u00ecnh-zone&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;3. C\u1ea5u h\u00ecnh Interface&quot;,&quot;value&quot;:&quot;3-c\u1ea5u-h\u00ecnh-interface&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;4. C\u1ea5u h\u00ecnh ch\u00ednh s\u00e1ch&quot;,&quot;value&quot;:&quot;4-c\u1ea5u-h\u00ecnh-ch\u00ednh-s\u00e1ch&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - K\u1ebft lu\u1eadn&quot;,&quot;value&quot;:&quot;iv-k\u1ebft-lu\u1eadn&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan bài viết</a><li><a href="#eb-table-content-1">II &#8211; Mô hình</a><li><a href="#eb-table-content-2">III &#8211; Cấu hình</a><li><a href="#eb-table-content-3">1. Cấu hình RED</a><li><a href="#eb-table-content-4">2. Cấu hình Zone</a><li><a href="#eb-table-content-5">3. Cấu hình Interface</a><li><a href="#eb-table-content-6">4. Cấu hình chính sách</a><li><a href="#eb-table-content-7">IV &#8211; Kết luận</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan bài viết</span></h2></div></div></div>



<p>SD-RED 60 ở chế độ <strong>Standard/Unified</strong> cho phép kết nối chi nhánh hoặc văn phòng từ xa về <strong>Sophos Firewall XGS</strong> thông qua một đường hầm bảo mật qua Internet. Toàn bộ mạng phía sau thiết bị RED sẽ được xem như một phần của mạng LAN nội bộ, do firewall trung tâm quản lý hoàn toàn, bao gồm DHCP, gateway và các chính sách bảo mật. Chế độ này giúp quản trị tập trung, kiểm soát truy cập và lọc lưu lượng hiệu quả, rất phù hợp cho mô hình nhiều site hoặc branch office.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4vlua"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4vlua "><div class="eb-advance-heading-wrapper eb-advance-heading-4vlua button-1 undefined" data-id="eb-advance-heading-4vlua"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Mô hình</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1294" src="https://vacif.com/wp-content/uploads/2026/05/image-178-scaled.png" alt="" class="wp-image-30015" srcset="https://vacif.com/wp-content/uploads/2026/05/image-178-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-178-300x152.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-178-1024x518.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-178-768x388.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-178-1536x777.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-178-2048x1036.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-e9bqr"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-e9bqr "><div class="eb-advance-heading-wrapper eb-advance-heading-e9bqr button-1 undefined" data-id="eb-advance-heading-e9bqr"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iar4g"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iar4g "><div class="eb-advance-heading-wrapper eb-advance-heading-iar4g button-1 undefined" data-id="eb-advance-heading-iar4g"><h2 class="eb-ah-title"><span class="first-title">1. Cấu hình RED</span></h2></div></div></div>



<p>Truy cập vào Sophos Firewall. Đến phần <strong>System services</strong> -> <strong>RED</strong>. Bật <strong>RED status</strong> trên Head Office Firewall lên.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1613" height="744" src="https://vacif.com/wp-content/uploads/2026/05/image-179.png" alt="" class="wp-image-30016" srcset="https://vacif.com/wp-content/uploads/2026/05/image-179.png 1613w, https://vacif.com/wp-content/uploads/2026/05/image-179-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-179-1024x472.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-179-768x354.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-179-1536x708.png 1536w" sizes="auto, (max-width: 1613px) 100vw, 1613px" /></figure>



<p>Đăng kí Sophos Firewall với RED provisioning Server sau khi bật <strong>RED status</strong>. Lưu ý: chỉ làm 1 lần suy nhất.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2071" height="1185" src="https://vacif.com/wp-content/uploads/2026/05/image-180.png" alt="" class="wp-image-30017" srcset="https://vacif.com/wp-content/uploads/2026/05/image-180.png 2071w, https://vacif.com/wp-content/uploads/2026/05/image-180-300x172.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-180-1024x586.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-180-768x439.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-180-1536x879.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-180-2048x1172.png 2048w" sizes="auto, (max-width: 2071px) 100vw, 2071px" /></figure>



<p>Sau khi đăng kí xong thì sẽ có giao diện như sau.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1808" height="877" src="https://vacif.com/wp-content/uploads/2026/05/image-181.png" alt="" class="wp-image-30018" srcset="https://vacif.com/wp-content/uploads/2026/05/image-181.png 1808w, https://vacif.com/wp-content/uploads/2026/05/image-181-300x146.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-181-1024x497.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-181-768x373.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-181-1536x745.png 1536w" sizes="auto, (max-width: 1808px) 100vw, 1808px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-xane5"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-xane5 "><div class="eb-advance-heading-wrapper eb-advance-heading-xane5 button-1 undefined" data-id="eb-advance-heading-xane5"><h2 class="eb-ah-title"><span class="first-title">2. Cấu hình Zone</span></h2></div></div></div>



<p>Vào <strong>Network</strong> -&gt; <strong>Zones</strong>. Nhấn <strong>Add.</strong></p>



<p>Bật dịch vụ mạng và các dịch vụ khác phục vụ cho việc cấu hình và troubleshoot.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2196" height="1197" src="https://vacif.com/wp-content/uploads/2026/05/image-182.png" alt="" class="wp-image-30019" srcset="https://vacif.com/wp-content/uploads/2026/05/image-182.png 2196w, https://vacif.com/wp-content/uploads/2026/05/image-182-300x164.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-182-1024x558.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-182-768x419.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-182-1536x837.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-182-2048x1116.png 2048w" sizes="auto, (max-width: 2196px) 100vw, 2196px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-fi64f"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-fi64f "><div class="eb-advance-heading-wrapper eb-advance-heading-fi64f button-1 undefined" data-id="eb-advance-heading-fi64f"><h2 class="eb-ah-title"><span class="first-title">3. Cấu hình Interface</span></h2></div></div></div>



<p>Đến phần <strong>Network</strong> -> <strong>Interfaces</strong>. Nhấn <strong>Add interface</strong>, và chọn <strong>Add RED</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1118" src="https://vacif.com/wp-content/uploads/2026/05/image-183-scaled.png" alt="" class="wp-image-30020" srcset="https://vacif.com/wp-content/uploads/2026/05/image-183-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-183-300x131.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-183-1024x447.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-183-768x335.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-183-1536x671.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-183-2048x894.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<ul class="wp-block-list">
<li><strong>Branch name: </strong>Đặt tên</li>



<li><strong>Type: </strong>Dòng thiết bị</li>



<li><strong>RED ID: </strong>S/N thiết bị (nằm dưới thiết bị RED)</li>



<li><strong>Unlock code:</strong> nhập đoạn mã mà firewall sẽ gửi qua email đã nhập ở bước đăng kí RED</li>



<li><strong>Firewall/Hostname:</strong> IP WAN firewall</li>



<li><strong>2<sup>nd</sup> Firewall/Hostname: </strong>IP WAN remote (phía SD-RED)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1411" height="830" src="https://vacif.com/wp-content/uploads/2026/05/image-184.png" alt="" class="wp-image-30021" srcset="https://vacif.com/wp-content/uploads/2026/05/image-184.png 1411w, https://vacif.com/wp-content/uploads/2026/05/image-184-300x176.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-184-1024x602.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-184-768x452.png 768w" sizes="auto, (max-width: 1411px) 100vw, 1411px" /></figure>



<p>Cấu hình cho SD-RED và remote LAN nhận DHCP.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1863" height="658" src="https://vacif.com/wp-content/uploads/2026/05/image-185.png" alt="" class="wp-image-30022" srcset="https://vacif.com/wp-content/uploads/2026/05/image-185.png 1863w, https://vacif.com/wp-content/uploads/2026/05/image-185-300x106.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-185-1024x362.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-185-768x271.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-185-1536x543.png 1536w" sizes="auto, (max-width: 1863px) 100vw, 1863px" /></figure>



<p>Cấu hình mode <strong>Standard/unified</strong>.</p>



<ul class="wp-block-list">
<li><strong>RED IP: </strong>nhập IP cùng subnet với subnet mà Firewall cấp cho remote LAN</li>



<li><strong>RED netmask: </strong>lớp mạng</li>



<li><strong>Zone:</strong> RED_Device</li>



<li><strong>RED DHCP range:</strong> IP range cho remote network (phía sau thiết bị RED)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2552" height="1361" src="https://vacif.com/wp-content/uploads/2026/05/image-186.png" alt="" class="wp-image-30023" srcset="https://vacif.com/wp-content/uploads/2026/05/image-186.png 2552w, https://vacif.com/wp-content/uploads/2026/05/image-186-300x160.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-186-1024x546.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-186-768x410.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-186-1536x819.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-186-2048x1092.png 2048w" sizes="auto, (max-width: 2552px) 100vw, 2552px" /></figure>



<p>Kết quả</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="482" src="https://vacif.com/wp-content/uploads/2026/05/image-187-scaled.png" alt="" class="wp-image-30024" srcset="https://vacif.com/wp-content/uploads/2026/05/image-187-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-187-300x56.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-187-1024x193.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-187-768x145.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-187-1536x289.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-187-2048x386.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-t87x3"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-t87x3 "><div class="eb-advance-heading-wrapper eb-advance-heading-t87x3 button-1 undefined" data-id="eb-advance-heading-t87x3"><h2 class="eb-ah-title"><span class="first-title">4. Cấu hình chính sách</span></h2></div></div></div>



<p>Tạo Firewall rule cho phép remote LAN(phía sau thiết bị RED) truy cập Internet và try cập vào LAN Office.</p>



<p>Trong <strong>PROTECT</strong>, chọn <strong>Rule and policies</strong> -&gt; <strong>Add firewall rule</strong> -&gt; chọn <strong>New firewall rule</strong>.</p>



<p>Đặt tên và chọn action.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1702" height="610" src="https://vacif.com/wp-content/uploads/2026/05/image-188.png" alt="" class="wp-image-30025" srcset="https://vacif.com/wp-content/uploads/2026/05/image-188.png 1702w, https://vacif.com/wp-content/uploads/2026/05/image-188-300x108.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-188-1024x367.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-188-768x275.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-188-1536x551.png 1536w" sizes="auto, (max-width: 1702px) 100vw, 1702px" /></figure>



<p>Chọn <strong>Source zone</strong> là <strong>RED_Device</strong> và <strong>Destination zone</strong> là <strong>LAN/WAN</strong> để <strong>remote LAN</strong> có thể truy cập Internet và access vào LAN.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2124" height="768" src="https://vacif.com/wp-content/uploads/2026/05/image-189.png" alt="" class="wp-image-30026" srcset="https://vacif.com/wp-content/uploads/2026/05/image-189.png 2124w, https://vacif.com/wp-content/uploads/2026/05/image-189-300x108.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-189-1024x370.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-189-768x278.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-189-1536x555.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-189-2048x741.png 2048w" sizes="auto, (max-width: 2124px) 100vw, 2124px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-91mg7"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-91mg7 "><div class="eb-advance-heading-wrapper eb-advance-heading-91mg7 button-1 undefined" data-id="eb-advance-heading-91mg7"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Kết luận</span></h2></div></div></div>



<p>Qua bài viết này, chúng ta đã cùng đi qua toàn bộ quy trình triển khai <strong>SD-RED 60 ở chế độ Standard/Unified trên Sophos Firewall XGS</strong>, từ mô hình kết nối cho đến các bước cấu hình thực tế. Đây là một giải pháp tối ưu cho doanh nghiệp có nhiều chi nhánh, giúp mở rộng mạng nội bộ một cách an toàn, linh hoạt và dễ quản trị tập trung. Hy vọng bài viết sẽ giúp anh em kỹ sư có thêm góc nhìn thực tế và tự tin hơn khi triển khai RED trong các dự án thực chiến.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-sophos-firewall-xgs-huong-dan-cau-hinh-sd-red-60-mode-standard-unified/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình IPsec VPN Remote Access Trên Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ipsec-vpn-remote-access-tren-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ipsec-vpn-remote-access-tren-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 07 May 2026 10:16:58 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[IPsec VPN Remote Access]]></category>
		<category><![CDATA[Sophos endpoint]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29881</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình IPsec Remote Access VPN trên Sophos Firewall thông qua Sophos Connect Client, giúp người dùng từ xa có thể truy cập an toàn vào hệ thống mạng nội bộ của doanh nghiệp. Bên cạnh đó, bài viết cũng phân tích sự khác biệt giữa hai mô hình triển [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o user VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o user VPN&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 2: T\u1ea1o IPsec Profile&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 2: T\u1ea1o IPsec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;Phase 1 (Thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i ban \u0111\u1ea7u)&quot;,&quot;text&quot;:&quot;Phase 1 (Thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i ban \u0111\u1ea7u)&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;Phase 2 (Truy\u1ec1n d\u1eef li\u1ec7u VPN)&quot;,&quot;text&quot;:&quot;Phase 2 (Truy\u1ec1n d\u1eef li\u1ec7u VPN)&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh IPsec Remote Access&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh IPsec Remote Access&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho VPN&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 5: C\u00e0i Sophos Connect v\u00e0 export file c\u1ea5u h\u00ecnh \u0111\u1ec3 k\u1ebft n\u1ed1i&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 5: C\u00e0i Sophos Connect v\u00e0 export file c\u1ea5u h\u00ecnh \u0111\u1ec3 k\u1ebft n\u1ed1i&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o user VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-1-t\u1ea1o-user-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 2: T\u1ea1o IPsec Profile&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-2-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;Phase 1 (Thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i ban \u0111\u1ea7u)&quot;,&quot;value&quot;:&quot;phase-1-thi\u1ebft-l\u1eadp-k\u1ebft-n\u1ed1i-ban-\u0111\u1ea7u&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;Phase 2 (Truy\u1ec1n d\u1eef li\u1ec7u VPN)&quot;,&quot;value&quot;:&quot;phase-2-truy\u1ec1n-d\u1eef-li\u1ec7u-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh IPsec Remote Access&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-3-c\u1ea5u-h\u00ecnh-ipsec-remote-access&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-4-t\u1ea1o-firewall-rule-cho-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 5: C\u00e0i Sophos Connect v\u00e0 export file c\u1ea5u h\u00ecnh \u0111\u1ec3 k\u1ebft n\u1ed1i&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-5-c\u00e0i-sophos-connect-v\u00e0-export-file-c\u1ea5u-h\u00ecnh-\u0111\u1ec3-k\u1ebft-n\u1ed1i&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình<strong> IPsec Remote Access VPN trên Sophos Firewall</strong> thông qua <strong>Sophos Connect Client</strong>, giúp người dùng từ xa có thể truy cập an toàn vào hệ thống mạng nội bộ của doanh nghiệp.</p>



<p>Bên cạnh đó, bài viết cũng phân tích sự khác biệt giữa hai mô hình triển khai phổ biến:</p>



<ul class="wp-block-list">
<li><strong>Firewall quay PPPoE trực tiếp </strong>(khuyến nghị – đảm bảo IPsec hoạt động ổn định)</li>



<li><strong>Firewall đặt sau modem NAT </strong>(dễ phát sinh lỗi kết nối IPsec)</li>
</ul>



<p>Qua đó, giúp người đọc hiểu rõ nguyên nhân và lựa chọn mô hình triển khai phù hợp trong thực tế.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1243" src="https://vacif.com/wp-content/uploads/2026/05/image-109-scaled.png" alt="" class="wp-image-29883" srcset="https://vacif.com/wp-content/uploads/2026/05/image-109-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-109-300x146.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-109-1024x497.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-109-768x373.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-109-1536x746.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-109-2048x994.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-tyrna"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-tyrna "><div class="eb-advance-heading-wrapper eb-advance-heading-tyrna button-1 undefined" data-id="eb-advance-heading-tyrna"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Trong thực tế, doanh nghiệp thường có nhu cầu cho phép nhân viên truy cập vào hệ thống nội bộ khi làm việc từ xa (tại nhà, quán cà phê hoặc khi đi công tác). Tuy nhiên, việc mở trực tiếp các dịch vụ nội bộ ra Internet tiềm ẩn nhiều rủi ro về bảo mật.</p>



<p>Vì vậy, giải pháp được đặt ra là triển khai VPN để tạo một kênh kết nối an toàn giữa người dùng bên ngoài và hệ thống mạng nội bộ.</p>



<p><strong>Yêu cầu:</strong></p>



<ul class="wp-block-list">
<li>Triển khai IPsec Remote Access VPN trên Sophos Firewall sử dụng Sophos Connect Client</li>



<li>Đảm bảo dữ liệu trao đổi được mã hóa, an toàn khi đi qua Internet</li>



<li>Người dùng sau khi kết nối VPN có thể truy cập vào các tài nguyên nội bộ như:
<ul class="wp-block-list">
<li>Server nội bộ</li>



<li>File chia sẻ (SMB)</li>



<li>Remote Desktop (RDP)</li>
</ul>
</li>



<li>Hạn chế truy cập, chỉ cho phép vào các mạng cần thiết (ví dụ: VLAN quản trị)</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x6cmy"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x6cmy "><div class="eb-advance-heading-wrapper eb-advance-heading-x6cmy button-1 undefined" data-id="eb-advance-heading-x6cmy"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<ol class="wp-block-list">
<li>Tạo user VPN</li>



<li>Tạo IPsec Profile</li>



<li>Cấu hình IPsec Remote Access</li>



<li>Tạo Firewall Rule cho VPN</li>



<li>Cài Sophos Connect và export file cấu hình để kết nối</li>
</ol>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hb5rp"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hb5rp "><div class="eb-advance-heading-wrapper eb-advance-heading-hb5rp button-1 undefined" data-id="eb-advance-heading-hb5rp"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">Bước 1: Tạo user VPN</span></h2></div></div></div>



<p>Authentication → Users → Add</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2255" height="1062" src="https://vacif.com/wp-content/uploads/2026/05/Picture13.png" alt="" class="wp-image-29885" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture13.png 2255w, https://vacif.com/wp-content/uploads/2026/05/Picture13-300x141.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture13-1024x482.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture13-768x362.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture13-1536x723.png 1536w, https://vacif.com/wp-content/uploads/2026/05/Picture13-2048x965.png 2048w" sizes="auto, (max-width: 2255px) 100vw, 2255px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a5bow"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a5bow "><div class="eb-advance-heading-wrapper eb-advance-heading-a5bow button-1 undefined" data-id="eb-advance-heading-a5bow"><h2 class="eb-ah-title"><span class="first-title">Bước 2: Tạo IPsec Profile</span></h2></div></div></div>



<p>Profiles → IPsec profiles → Add</p>



<p><strong>IPsec Profile</strong> dùng để định nghĩa các thông số bảo mật và cách thức thiết lập kết nối VPN giữa client và firewall. Để đảm bảo tương thích với Sophos Connect, profile nên cấu hình tương tự profile mặc định <strong>DefaultRemoteAccess.</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2255" height="1070" src="https://vacif.com/wp-content/uploads/2026/05/Picture14.png" alt="" class="wp-image-29886" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture14.png 2255w, https://vacif.com/wp-content/uploads/2026/05/Picture14-300x142.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture14-1024x486.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture14-768x364.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture14-1536x729.png 1536w, https://vacif.com/wp-content/uploads/2026/05/Picture14-2048x972.png 2048w" sizes="auto, (max-width: 2255px) 100vw, 2255px" /></figure>



<p><strong>Thông tin chung</strong></p>



<ul class="wp-block-list">
<li><strong>Name: </strong>IPsec VPN Remote Access.</li>



<li><strong>Description: </strong>Description.</li>



<li><strong>Key exchange: </strong>IKEv1 &#8211; Chuẩn kết nối cũ.</li>



<li><strong>Authentication mode:</strong> Main mode &#8211; đảm bảo quá trình xác thực an toàn hơn.</li>



<li><strong>Key negotiation tries:</strong> 0 &#8211; cho phép thử kết nối không giới hạn nếu lần đầu thất bại.</li>



<li><strong>Re-key connection:</strong> Enable &nbsp;&#8211; tự động gia hạn kết nối khi sắp hết hạn.</li>



<li><strong>Use strict profile: </strong>Disable &#8211; cho phép linh hoạt khi thương lượng thuật toán giữa client và firewall.</li>



<li><strong>Pass data in compressed format:</strong> Disable &#8211; không cần thiết trong hầu hết trường hợp</li>



<li><strong>SHA2 with 96-bit truncation:</strong> Disable &#8211; giữ nguyên độ bảo mật đầy đủ của SHA2.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1769" height="839" src="https://vacif.com/wp-content/uploads/2026/05/Picture15.png" alt="" class="wp-image-29887" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture15.png 1769w, https://vacif.com/wp-content/uploads/2026/05/Picture15-300x142.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture15-1024x486.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture15-768x364.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture15-1536x728.png 1536w" sizes="auto, (max-width: 1769px) 100vw, 1769px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-z5slf"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-z5slf "><div class="eb-advance-heading-wrapper eb-advance-heading-z5slf button-1 undefined" data-id="eb-advance-heading-z5slf"><h2 class="eb-ah-title"><span class="first-title">Phase 1 (Thiết lập kết nối ban đầu)</span></h2></div></div></div>



<p>Đây là giai đoạn hai bên tạo kênh bảo mật để trao đổi khóa và xác thực lẫn nhau.</p>



<ul class="wp-block-list">
<li><strong>Key life: </strong>18000 seconds (thời gian tồn tại của phiên kết nối ban đầu)</li>



<li><strong>DH group: </strong>(giữ mặc định hệ thống – đảm bảo tương thích)</li>



<li><strong>Re-key margin: </strong>360 seconds (bắt đầu gia hạn trước khi hết hạn)</li>



<li><strong>Randomize re-keying margin: </strong>100% (tránh nhiều kết nối gia hạn cùng lúc)</li>
</ul>



<p><strong>Thuật toán:</strong></p>



<ul class="wp-block-list">
<li><strong>Encryption: </strong>AES256, AES256, AES128</li>



<li><strong>Authentication: </strong>SHA2-256, SHA1, SHA1</li>
</ul>



<p>Việc cấu hình nhiều thuật toán giúp firewall và client có thể “thương lượng” và chọn ra thuật toán phù hợp nhất để kết nối thành công.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2456" height="890" src="https://vacif.com/wp-content/uploads/2026/05/image-111.png" alt="" class="wp-image-29888" srcset="https://vacif.com/wp-content/uploads/2026/05/image-111.png 2456w, https://vacif.com/wp-content/uploads/2026/05/image-111-300x109.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-111-1024x371.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-111-768x278.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-111-1536x557.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-111-2048x742.png 2048w" sizes="auto, (max-width: 2456px) 100vw, 2456px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yjq7u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yjq7u "><div class="eb-advance-heading-wrapper eb-advance-heading-yjq7u button-1 undefined" data-id="eb-advance-heading-yjq7u"><h2 class="eb-ah-title"><span class="first-title">Phase 2 (Truyền dữ liệu VPN)</span></h2></div></div></div>



<p>Sau khi Phase 1 thành công, Phase 2 sẽ tạo kênh để truyền dữ liệu thực tế.</p>



<ul class="wp-block-list">
<li><strong>PFS group:</strong> Same as Phase 1 (tăng cường bảo mật cho mỗi phiên dữ liệu)</li>



<li><strong>Key life: </strong>3600 seconds (thời gian sử dụng khóa cho việc truyền dữ liệu)</li>
</ul>



<p><strong>Thuật toán:</strong></p>



<ul class="wp-block-list">
<li><strong>Encryption</strong>: AES256, AES256, AES128</li>



<li><strong>Authentication:</strong> SHA2-256, SHA1, SHA1</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2169" height="876" src="https://vacif.com/wp-content/uploads/2026/05/image-112.png" alt="" class="wp-image-29889" srcset="https://vacif.com/wp-content/uploads/2026/05/image-112.png 2169w, https://vacif.com/wp-content/uploads/2026/05/image-112-300x121.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-112-1024x414.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-112-768x310.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-112-1536x620.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-112-2048x827.png 2048w" sizes="auto, (max-width: 2169px) 100vw, 2169px" /></figure>



<p><strong>Dead Peer Detection (DPD)</strong></p>



<p>DPD giúp firewall kiểm tra xem client còn kết nối hay không.</p>



<ul class="wp-block-list">
<li><strong>Dead Peer Detection:</strong> Enable.</li>



<li><strong>Check peer after every: </strong>60 seconds &#8211; kiểm tra định kỳ.</li>



<li><strong>Wait for response up to:</strong> 240 seconds &nbsp;&#8211; thời gian chờ phản hồi.</li>



<li><strong>When peer unreachable:</strong> Disconnect &#8211; ngắt kết nối nếu không phản hồi.</li>
</ul>



<p>Nhấn <strong>Save</strong> để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0cghh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0cghh "><div class="eb-advance-heading-wrapper eb-advance-heading-0cghh button-1 undefined" data-id="eb-advance-heading-0cghh"><h2 class="eb-ah-title"><span class="first-title">Bước 3: Cấu hình IPsec Remote Access</span></h2></div></div></div>



<p><strong>Truy cập:</strong></p>



<p>Remote Access VPN → IPsec</p>



<p>Đây là bước cấu hình để bật tính năng IPsec Remote Access trên firewall và liên kết với profile đã tạo ở bước trước.</p>



<p><strong>General settings:</strong></p>



<ul class="wp-block-list">
<li><strong>IPsec remote access: </strong>Enable &#8211; Bật tính năng IPsec Remote Access trên firewall</li>



<li><strong>Interface:</strong> Port2 – 115.70.xxx.xxx &#8211; Cổng WAN nhận kết nối từ Internet</li>



<li><strong>IPsec profile:</strong> IPsec VPN Remote Access &#8211; Sử dụng profile đã tạo ở bước 1</li>
</ul>



<p><strong>Authentication:</strong></p>



<ul class="wp-block-list">
<li><strong>Authentication type:</strong> Preshared key &#8211; Xác thực bằng khóa bí mật dùng chung giữa client và firewall</li>



<li><strong>Preshared key:</strong> Client phải nhập đúng key này mới kết nối được</li>
</ul>



<p><strong>Identification:</strong></p>



<ul class="wp-block-list">
<li><strong>Local ID:</strong> Default</li>



<li><strong>Remote ID: </strong>Default</li>
</ul>



<p>Dùng để định danh 2 đầu VPN, trong lab có thể để mặc định</p>



<p><strong>Allowed users and groups:</strong></p>



<ul class="wp-block-list">
<li><strong>Allowed users and groups: </strong>it&nbsp; &#8211; Chỉ user thuộc group it mới được phép kết nối VPN</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2207" height="1146" src="https://vacif.com/wp-content/uploads/2026/05/Picture16.png" alt="" class="wp-image-29891" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture16.png 2207w, https://vacif.com/wp-content/uploads/2026/05/Picture16-300x156.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture16-1024x532.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture16-768x399.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture16-1536x798.png 1536w, https://vacif.com/wp-content/uploads/2026/05/Picture16-2048x1063.png 2048w" sizes="auto, (max-width: 2207px) 100vw, 2207px" /></figure>



<p><strong>Client information:</strong></p>



<ul class="wp-block-list">
<li><strong>Name: </strong>it &#8211; Tên cấu hình VPN (hiển thị khi export file cho client)</li>



<li><strong>Assign IP from: </strong>11.11.11.1 – 11.11.11.10 -&gt; Dải IP cấp cho user khi kết nối VPN</li>



<li><strong>DNS server 1 / 2:</strong> Có thể thêm DNS nội bộ nếu cần resolve domain nội bộ</li>
</ul>



<p><strong>Idle timeout:</strong></p>



<ul class="wp-block-list">
<li><strong>Disconnect when tunnel is idle:</strong> Tự ngắt VPN nếu không có hoạt động</li>



<li><strong>Idle session time interval: </strong>(120–21600s) &#8211; Thời gian chờ trước khi ngắt</li>
</ul>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-ns83o"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-ns83o "><figure class="eb-advanced-image-wrapper eb-advanced-image-ns83o no-effect" data-id="eb-advanced-image-ns83o"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture17.png" alt=""/></div></div></figure></div></div>



<p><strong>Advanced settings:</strong></p>



<ul class="wp-block-list">
<li><strong>Use as default gateway:</strong>
<ul class="wp-block-list">
<li><strong>Nếu bật:</strong> toàn bộ traffic client đi qua VPN</li>



<li><strong>Nếu tắt:</strong> chỉ đi các mạng nội bộ (split tunnel)</li>
</ul>
</li>



<li><strong>Permitted network resources (IPv4): </strong>VLAN_10_MGMT &#8211; Chỉ cho phép truy cập vào mạng nội bộ VLAN_10_MGMT</li>



<li><strong>Send Security Heartbeat through tunnel: </strong>Dùng cho Sophos endpoint</li>



<li><strong>Allow users to save username and password: </strong>Enable &#8211; Cho phép client lưu thông tin đăng nhập</li>



<li><strong>Prompt users for 2FA token: </strong>Dùng nếu có xác thực 2 lớp</li>



<li><strong>Run AD logon script after connecting: </strong>Tùy chọn</li>



<li><strong>Hostname or DNS suffix to monitor: </strong>Tùy chọn</li>



<li><strong>Connect tunnel automatically: </strong>Dùng để auto connect VPN khi truy cập domain</li>



<li><strong>DNS suffix</strong>: Dùng cho môi trường domain nội bộ</li>
</ul>



<p>Nhấn <strong>Apply</strong> để lưu cấu hình và nhấn <strong>Export Connection</strong> để lấy file đăng nhập.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1824" height="868" src="https://vacif.com/wp-content/uploads/2026/05/Picture18.png" alt="" class="wp-image-29893" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture18.png 1824w, https://vacif.com/wp-content/uploads/2026/05/Picture18-300x143.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture18-1024x487.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture18-768x365.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture18-1536x731.png 1536w" sizes="auto, (max-width: 1824px) 100vw, 1824px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ih251"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ih251 "><div class="eb-advance-heading-wrapper eb-advance-heading-ih251 button-1 undefined" data-id="eb-advance-heading-ih251"><h2 class="eb-ah-title"><span class="first-title">Bước 4: Tạo Firewall Rule cho VPN</span></h2></div></div></div>



<p><strong>Truy cập:</strong></p>



<p>Rules and Policies → Firewall Rules → Add</p>



<p>Firewall Rule dùng để cho phép traffic từ VPN đi vào mạng nội bộ và ngược lại. Nếu không có rule này, dù VPN kết nối thành công thì user vẫn không truy cập được tài nguyên bên trong.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="525" src="https://vacif.com/wp-content/uploads/2026/05/image-114-scaled.png" alt="" class="wp-image-29895" srcset="https://vacif.com/wp-content/uploads/2026/05/image-114-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-114-300x62.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-114-1024x210.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-114-768x158.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-114-1536x315.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-114-2048x420.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p><strong>Thông tin chung:</strong></p>



<ul class="wp-block-list">
<li><strong>Rule name:</strong> IPsec VPN Remote Access</li>



<li><strong>Action:</strong> Accept &#8211; cho phép lưu lượng đi qua</li>



<li><strong>Log firewall traffic: </strong>Enable &#8211; ghi log để dễ kiểm tra khi cần</li>



<li><strong>Description:</strong> (tùy chọn)</li>



<li><strong>Rule group:</strong> None</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="575" src="https://vacif.com/wp-content/uploads/2026/05/image-115-scaled.png" alt="" class="wp-image-29896" srcset="https://vacif.com/wp-content/uploads/2026/05/image-115-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-115-300x67.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-115-1024x230.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-115-768x172.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-115-1536x345.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-115-2048x460.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p><strong>Source zones: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>LAN</li>



<li>VPN</li>
</ul>



<p>Cho phép traffic từ cả mạng nội bộ và user VPN</p>



<p><strong>Source networks and devices: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>11 (dải IP VPN: 11.11.11.1 – 11.11.11.10) là IP được cấp cho client VPN</li>



<li>VLAN_10_MGMT là mạng nội bộ</li>
</ul>



<p><strong>Destination zones: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>LAN</li>



<li>VPN</li>
</ul>



<p>Cho phép truy cập hai chiều</p>



<p><strong>Destination networks: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>11 &#8211; cho phép chiều ngược lại (LAN có thể phản hồi lại VPN client)</li>



<li>VLAN_10_MGMT &nbsp;&#8211; là mạng nội bộ mà user VPN được phép truy cập</li>
</ul>



<p>Nhấn<strong> Save / Apply</strong> để lưu rule</p>



<p></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dfwgb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dfwgb "><div class="eb-advance-heading-wrapper eb-advance-heading-dfwgb button-1 undefined" data-id="eb-advance-heading-dfwgb"><h2 class="eb-ah-title"><span class="first-title">Bước 5: Cài Sophos Connect và export file cấu hình để kết nối</span></h2></div></div></div>



<p>Sau khi hoàn tất cấu hình trên firewall, cần export file cấu hình VPN và cài đặt Sophos Connect trên máy người dùng để thực hiện kết nối.</p>



<p>Khi export cấu hình IPsec VPN từ Sophos Firewall, hệ thống có thể cung cấp hai loại file với mục đích sử dụng khác nhau:</p>



<ul class="wp-block-list">
<li><strong>File .scx: </strong>Đây là file cấu hình dành cho người dùng cuối, được sử dụng để import vào Sophos Connect Client nhằm thiết lập kết nối VPN. File này chứa đầy đủ thông tin cần thiết như địa chỉ gateway, cấu hình IPsec và các tham số kết nối.</li>



<li><strong>File .tgb: </strong>Đây là file backup cấu hình, được sử dụng cho mục đích sao lưu và khôi phục trên firewall. File này không dùng cho client và không thể import vào Sophos Connect.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1141" src="https://vacif.com/wp-content/uploads/2026/05/image-116-scaled.png" alt="" class="wp-image-29897" srcset="https://vacif.com/wp-content/uploads/2026/05/image-116-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-116-300x134.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-116-1024x456.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-116-768x342.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-116-1536x684.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-116-2048x913.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1575" height="1371" src="https://vacif.com/wp-content/uploads/2026/05/image-117.png" alt="" class="wp-image-29898" srcset="https://vacif.com/wp-content/uploads/2026/05/image-117.png 1575w, https://vacif.com/wp-content/uploads/2026/05/image-117-300x261.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-117-1024x891.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-117-768x669.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-117-1536x1337.png 1536w" sizes="auto, (max-width: 1575px) 100vw, 1575px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2345" height="1394" src="https://vacif.com/wp-content/uploads/2026/05/image-118.png" alt="" class="wp-image-29899" srcset="https://vacif.com/wp-content/uploads/2026/05/image-118.png 2345w, https://vacif.com/wp-content/uploads/2026/05/image-118-300x178.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-118-1024x609.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-118-768x457.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-118-1536x913.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-118-2048x1217.png 2048w" sizes="auto, (max-width: 2345px) 100vw, 2345px" /></figure>



<p>Ngoài ra, bạn có thể truy cập mục <strong>Current Activities</strong> để theo dõi các phiên VPN đang hoạt động, bao gồm thông tin người dùng đang đăng nhập và loại client đang sử dụng.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="591" src="https://vacif.com/wp-content/uploads/2026/05/image-119-scaled.png" alt="" class="wp-image-29900" srcset="https://vacif.com/wp-content/uploads/2026/05/image-119-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-119-300x69.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-119-1024x236.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-119-768x177.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-119-1536x354.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-119-2048x473.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ipsec-vpn-remote-access-tren-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình SSL VPN Client To Site Với Client Windows Và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ssl-vpn-client-to-site-voi-client-windows-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ssl-vpn-client-to-site-voi-client-windows-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 07 May 2026 08:39:15 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Client Windows]]></category>
		<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[SSL VPN Client To Site]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29849</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình SSL VPN Client-to-Site trên Sophos Firewall firmware v22, cho phép người dùng từ xa (remote user) sử dụng máy Windows kết nối an toàn vào mạng nội bộ doanh nghiệp thông qua Internet. Sau khi hoàn thành, người dùng có thể: Doanh nghiệp cần: Yêu cầu: Tổng quan [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i &quot;,&quot;text&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i &quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u &quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u &quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o User v\u00e0 Group&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o User v\u00e0 Group&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;T\u1ea1o Group&quot;,&quot;text&quot;:&quot;T\u1ea1o Group&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;T\u1ea1o User&quot;,&quot;text&quot;:&quot;T\u1ea1o User&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 2: C\u1ea5u h\u00ecnh SSL VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 2: C\u1ea5u h\u00ecnh SSL VPN&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh SSL VPN Global Settings&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh SSL VPN Global Settings&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho ph\u00e9p truy c\u1eadp t\u1eeb VPN v\u00e0o v\u00f9ng LAN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho ph\u00e9p truy c\u1eadp t\u1eeb VPN v\u00e0o v\u00f9ng LAN&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 5: T\u1ea3i VPN Client v\u00e0 file c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 5: T\u1ea3i VPN Client v\u00e0 file c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 6: C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m Sophos Connect&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 6: C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m Sophos Connect&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 7: Import c\u1ea5u h\u00ecnh VPN v\u00e0o Sophos Connect&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 7: Import c\u1ea5u h\u00ecnh VPN v\u00e0o Sophos Connect&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 8: Test k\u1ebft n\u1ed1i SSL VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 8: Test k\u1ebft n\u1ed1i SSL VPN&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i &quot;,&quot;value&quot;:&quot;i-m\u1ee5c-\u0111\u00edch-b\u00e0i&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u &quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o User v\u00e0 Group&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-1-t\u1ea1o-user-v\u00e0-group&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;T\u1ea1o Group&quot;,&quot;value&quot;:&quot;t\u1ea1o-group&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;T\u1ea1o User&quot;,&quot;value&quot;:&quot;t\u1ea1o-user&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 2: C\u1ea5u h\u00ecnh SSL VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-2-c\u1ea5u-h\u00ecnh-ssl-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh SSL VPN Global Settings&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-3-c\u1ea5u-h\u00ecnh-ssl-vpn-global-settings&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho ph\u00e9p truy c\u1eadp t\u1eeb VPN v\u00e0o v\u00f9ng LAN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-4-t\u1ea1o-firewall-rule-cho-ph\u00e9p-truy-c\u1eadp-t\u1eeb-vpn-v\u00e0o-v\u00f9ng-lan&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 5: T\u1ea3i VPN Client v\u00e0 file c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-5-t\u1ea3i-vpn-client-v\u00e0-file-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 6: C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m Sophos Connect&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-6-c\u00e0i-\u0111\u1eb7t-ph\u1ea7n-m\u1ec1m-sophos-connect&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 7: Import c\u1ea5u h\u00ecnh VPN v\u00e0o Sophos Connect&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-7-import-c\u1ea5u-h\u00ecnh-vpn-v\u00e0o-sophos-connect&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 8: Test k\u1ebft n\u1ed1i SSL VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-8-test-k\u1ebft-n\u1ed1i-ssl-vpn&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Mục đích bài </a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu </a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Mục đích bài </span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình <strong>SSL VPN Client-to-Site</strong> trên Sophos Firewall firmware v22, cho phép người dùng từ xa (remote user) sử dụng máy Windows kết nối an toàn vào mạng nội bộ doanh nghiệp thông qua Internet.</p>



<p>Sau khi hoàn thành, người dùng có thể:</p>



<ul class="wp-block-list">
<li>Truy cập tài nguyên nội bộ (Server, NAS, RDP, Web nội bộ…)</li>



<li>Mã hóa kết nối đảm bảo an toàn dữ liệu</li>



<li>Xác thực bằng tài khoản người dùng trên Sophos Firewall</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="422" src="https://vacif.com/wp-content/uploads/2026/05/image-94-1024x422.png" alt="" class="wp-image-29853" srcset="https://vacif.com/wp-content/uploads/2026/05/image-94-1024x422.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-94-300x124.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-94-768x316.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-94-1536x633.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-94-2048x843.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dpdzc"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dpdzc "><div class="eb-advance-heading-wrapper eb-advance-heading-dpdzc button-1 undefined" data-id="eb-advance-heading-dpdzc"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu </span></h2></div></div></div>



<p>Doanh nghiệp cần:</p>



<ul class="wp-block-list">
<li>Nhân viên truy cập từ xa (WFH)</li>



<li>Kết nối vào LAN nội bộ</li>



<li>Đảm bảo bảo mật và kiểm soát truy cập</li>
</ul>



<p>Yêu cầu:</p>



<ul class="wp-block-list">
<li>Chỉ user hợp lệ mới được VPN</li>



<li>Truy cập server nội bộ (RDP, File Server)</li>



<li>Có thể mở rộng MFA sau này</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qtw7f"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qtw7f "><div class="eb-advance-heading-wrapper eb-advance-heading-qtw7f button-1 undefined" data-id="eb-advance-heading-qtw7f"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<p>Tổng quan các bước:</p>



<ol class="wp-block-list">
<li>Tạo User và Group</li>



<li>Cấu hình SSL VPN Profile</li>



<li>Cấu hình SSL VPN Global Settings</li>



<li>Tạo Firewall Rule cho phép truy cập từ VPN vào vùng LAN</li>



<li>Tải VPN Client và file cấu hình</li>



<li>Cài đặt phần mềm Sophos Connect</li>



<li>Import cấu hình VPN vào Sophos Connect</li>



<li>Test kết nối SSL VPN</li>
</ol>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-3sz4j"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-3sz4j "><div class="eb-advance-heading-wrapper eb-advance-heading-3sz4j button-1 undefined" data-id="eb-advance-heading-3sz4j"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">Bước 1: Tạo User và Group</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-3o54l"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-3o54l "><div class="eb-advance-heading-wrapper eb-advance-heading-3o54l button-1 undefined" data-id="eb-advance-heading-3o54l"><h2 class="eb-ah-title"><span class="first-title">Tạo Group</span></h2></div></div></div>



<p>Authentication → Groups → Add</p>



<ul class="wp-block-list">
<li>Group Name: VACIF GROUP</li>



<li>Surfing quota: Unlimited Internet Access</li>



<li>Access time: Allowed all the time</li>
</ul>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-g6bpo"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-g6bpo "><figure class="eb-advanced-image-wrapper eb-advanced-image-g6bpo no-effect" data-id="eb-advanced-image-g6bpo"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture1-2-scaled.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0i5mh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0i5mh "><div class="eb-advance-heading-wrapper eb-advance-heading-0i5mh button-1 undefined" data-id="eb-advance-heading-0i5mh"><h2 class="eb-ah-title"><span class="first-title">Tạo User</span></h2></div></div></div>



<p>Authentication → Users → Add</p>



<ul class="wp-block-list">
<li>Username: VACIF</li>



<li>Password: ****</li>



<li>Group: VACIF GROUP</li>
</ul>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-lqq0z"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-lqq0z "><figure class="eb-advanced-image-wrapper eb-advanced-image-lqq0z no-effect" data-id="eb-advanced-image-lqq0z"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture3.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ahlmg"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ahlmg "><div class="eb-advance-heading-wrapper eb-advance-heading-ahlmg button-1 undefined" data-id="eb-advance-heading-ahlmg"><h2 class="eb-ah-title"><span class="first-title">Bước 2: Cấu hình SSL VPN</span></h2></div></div></div>



<p>VPN → Remote Access VPN → SSL VPN → Add → Configure manually</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-65sev"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-65sev "><figure class="eb-advanced-image-wrapper eb-advanced-image-65sev no-effect" data-id="eb-advanced-image-65sev"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture4-scaled.png" alt=""/></div></div></figure></div></div>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="565" src="https://vacif.com/wp-content/uploads/2026/05/image-98-1024x565.png" alt="" class="wp-image-29860" srcset="https://vacif.com/wp-content/uploads/2026/05/image-98-1024x565.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-98-300x166.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-98-768x424.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-98-1536x847.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-98-2048x1130.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>Thực hiện cấu hình các thông số sau:</strong></p>



<ul class="wp-block-list">
<li><strong>Name:</strong> Đặt tên cho cấu hình SSL VPN (ví dụ: SSLVPN-IT)</li>



<li><strong>Policy members: </strong>Chọn user hoặc group đã tạo trước đó (ví dụ: vpnuser01 hoặc SSLVPN-Users)</li>



<li><strong>Use as default gateway:</strong>
<ul class="wp-block-list">
<li><strong>Bật</strong> khi muốn toàn bộ lưu lượng của VPN Client đi qua Sophos Firewall (Full Tunnel)</li>



<li><strong>Không bật </strong>khi chỉ định tuyến lưu lượng truy cập vào mạng nội bộ qua VPN (Split Tunnel)</li>
</ul>
</li>



<li><strong>Permitted network resources (IPv4)</strong>: Chọn các dải mạng nội bộ (LAN) mà người dùng VPN được phép truy cập (ví dụ: 10.10.10.0/24)</li>



<li><strong>Disconnect idle clients: </strong>Tự động ngắt kết nối VPN khi người dùng không có hoạt động trong một khoảng thời gian nhất định</li>
</ul>



<p>→ Nhấn <strong>Apply </strong>để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-lii7j"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-lii7j "><figure class="eb-advanced-image-wrapper eb-advanced-image-lii7j no-effect" data-id="eb-advanced-image-lii7j"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture5.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-886cg"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-886cg "><div class="eb-advance-heading-wrapper eb-advance-heading-886cg button-1 undefined" data-id="eb-advance-heading-886cg"><h2 class="eb-ah-title"><span class="first-title">Bước 3: Cấu hình SSL VPN Global Settings</span></h2></div></div></div>



<p>VPN → Remote Access VPN → SSL VPN → Global Settings</p>



<ul class="wp-block-list">
<li><strong>Protocol: </strong>Chọn UDP để tối ưu hiệu suất và giảm độ trễ khi kết nối VPN</li>



<li><strong>SSL server certificate: </strong>Giữ nguyên ApplianceCertificate (chứng chỉ mặc định của thiết bị)</li>



<li><strong>Override hostname:</strong> Nhập địa chỉ IP WAN hoặc tên miền mà người dùng VPN sẽ sử dụng để kết nối (ví dụ: 123.20.173.178 hoặc vpn.company.com)</li>



<li><strong>Port:</strong> Giữ mặc định <strong>8443</strong> hoặc thay đổi nếu có yêu cầu riêng (Ở đây mình đặt 10443)</li>



<li><strong>Assign IPv4 addresses: </strong>Khai báo dải IP cấp phát cho VPN Client <em>(ví dụ: </em><em>10.121.10.0/24</em><em>)</em></li>



<li><strong>IPv4 DNS: </strong>Cấu hình DNS để client có thể phân giải tên miền khi kết nối VPN <em>(ví dụ: </em><em>8.8.8.8</em><em>, </em><em>1.1.1.1</em><em> hoặc DNS nội bộ)</em></li>



<li><strong>Disconnect dead peer after: </strong>Thiết lập thời gian (giây) để tự động ngắt kết nối khi client không phản hồi</li>



<li><strong>Disconnect idle peer after: </strong>Thiết lập thời gian ngắt kết nối khi người dùng không có hoạt động Có thể để trống &#8211; nên để trống nếu không giới hạn</li>
</ul>



<p>→ Nhấn <strong>Apply </strong>để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-qainb"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-qainb "><figure class="eb-advanced-image-wrapper eb-advanced-image-qainb no-effect" data-id="eb-advanced-image-qainb"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture6.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-k7b8x"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-k7b8x "><div class="eb-advance-heading-wrapper eb-advance-heading-k7b8x button-1 undefined" data-id="eb-advance-heading-k7b8x"><h2 class="eb-ah-title"><span class="first-title">Bước 4: Tạo Firewall Rule cho phép truy cập từ VPN vào vùng LAN</span></h2></div></div></div>



<p>Rules and Policies → Firewall Rules</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-ybbxr"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-ybbxr "><figure class="eb-advanced-image-wrapper eb-advanced-image-ybbxr no-effect" data-id="eb-advanced-image-ybbxr"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture7-scaled.png" alt=""/></div></div></figure></div></div>



<p><strong>Thực hiện cấu hình các thông số sau:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><tbody><tr><td><strong>Mục cấu hình</strong></td><td><strong>Giá trị đề xuất</strong></td></tr><tr><td>Rule Name</td><td>VACIF RULE VPN</td></tr><tr><td>Action</td><td>Accept</td></tr><tr><td>Log firewal traffic</td><td>On</td></tr><tr><td>Source zone</td><td>VPN</td></tr><tr><td>Source networks and devices</td><td>Any</td></tr><tr><td>During scheduled time</td><td>All the time</td></tr><tr><td>Destination zones</td><td>LAN</td></tr><tr><td>Destination networks</td><td>Lớp mạng local bạn muốn truy cập</td></tr><tr><td>Services</td><td>Any</td></tr></tbody></table></figure>



<p>→ Nhấn <strong>Save </strong>để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-idgle"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-idgle "><figure class="eb-advanced-image-wrapper eb-advanced-image-idgle no-effect" data-id="eb-advanced-image-idgle"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture9.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0z6tv"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0z6tv "><div class="eb-advance-heading-wrapper eb-advance-heading-0z6tv button-1 undefined" data-id="eb-advance-heading-0z6tv"><h2 class="eb-ah-title"><span class="first-title">Bước 5: Tải VPN Client và file cấu hình</span></h2></div></div></div>



<p>Để biết được port VPN là bao nhiêu thì bạn cần phải vào:</p>



<p>Administrator → Admin and user settings</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-jyd90"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-jyd90 "><figure class="eb-advanced-image-wrapper eb-advanced-image-jyd90 no-effect" data-id="eb-advanced-image-jyd90"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture10-scaled.png" alt=""/></div></div></figure></div></div>



<ul class="wp-block-list">
<li>Tiếp theo, truy cập <strong>VPN Portal</strong> bằng trình duyệt: https://&lt;WAN-IP hoặc tên miền&gt;:8443</li>



<li>Đăng nhập bằng tài khoản VPN mà bạn đã tạo trước đó.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1477" src="https://vacif.com/wp-content/uploads/2026/05/image-100-scaled.png" alt="" class="wp-image-29868" srcset="https://vacif.com/wp-content/uploads/2026/05/image-100-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-100-300x173.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-100-1024x591.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-100-768x443.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-100-1536x886.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-100-2048x1181.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p>Tại giao diện Portal:</p>



<ul class="wp-block-list">
<li>Nhấn <strong>Download for Windows</strong> trong mục <strong>Sophos Connect client</strong> để tải phần mềm</li>



<li>Nhấn <strong>Download for Windows, macOS, Linux</strong> trong mục <strong>VPN configuration</strong> để tải file cấu hình SSL VPN (.ovpn)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1643" height="851" src="https://vacif.com/wp-content/uploads/2026/05/Picture12.png" alt="" class="wp-image-29869" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture12.png 1643w, https://vacif.com/wp-content/uploads/2026/05/Picture12-300x155.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture12-1024x530.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture12-768x398.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture12-1536x796.png 1536w" sizes="auto, (max-width: 1643px) 100vw, 1643px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dfep1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dfep1 "><div class="eb-advance-heading-wrapper eb-advance-heading-dfep1 button-1 undefined" data-id="eb-advance-heading-dfep1"><h2 class="eb-ah-title"><span class="first-title">Bước 6: Cài đặt phần mềm Sophos Connect</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chạy file cài đặt: SophosConnect_&lt;version&gt;.exe</li>



<li>Tại màn hình cài đặt: Tick chọn “I accept the Sophos End User License Agreement and acknowledge the Sophos Privacy Policy”</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="556" src="https://vacif.com/wp-content/uploads/2026/05/image-101.png" alt="" class="wp-image-29870" srcset="https://vacif.com/wp-content/uploads/2026/05/image-101.png 975w, https://vacif.com/wp-content/uploads/2026/05/image-101-300x171.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-101-768x438.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iasma"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iasma "><div class="eb-advance-heading-wrapper eb-advance-heading-iasma button-1 undefined" data-id="eb-advance-heading-iasma"><h2 class="eb-ah-title"><span class="first-title">Bước 7: Import cấu hình VPN vào Sophos Connect</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Mở phần mềm <strong>Sophos Connect</strong></li>



<li>Tại giao diện chính: Nhấn <strong>Import connection </strong></li>



<li>Chọn file cấu hình đã tải: sslvpn-vacif-client-config.ovpn</li>



<li>Sau khi import thành công: Kết nối VPN sẽ hiển thị trong danh sách</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="744" height="422" src="https://vacif.com/wp-content/uploads/2026/05/image-102.png" alt="" class="wp-image-29871" srcset="https://vacif.com/wp-content/uploads/2026/05/image-102.png 744w, https://vacif.com/wp-content/uploads/2026/05/image-102-300x170.png 300w" sizes="auto, (max-width: 744px) 100vw, 744px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="967" height="726" src="https://vacif.com/wp-content/uploads/2026/05/image-103.png" alt="" class="wp-image-29872" srcset="https://vacif.com/wp-content/uploads/2026/05/image-103.png 967w, https://vacif.com/wp-content/uploads/2026/05/image-103-300x225.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-103-768x577.png 768w" sizes="auto, (max-width: 967px) 100vw, 967px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="726" height="764" src="https://vacif.com/wp-content/uploads/2026/05/image-104.png" alt="" class="wp-image-29873" srcset="https://vacif.com/wp-content/uploads/2026/05/image-104.png 726w, https://vacif.com/wp-content/uploads/2026/05/image-104-285x300.png 285w" sizes="auto, (max-width: 726px) 100vw, 726px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="881" height="890" src="https://vacif.com/wp-content/uploads/2026/05/image-105.png" alt="" class="wp-image-29874" srcset="https://vacif.com/wp-content/uploads/2026/05/image-105.png 881w, https://vacif.com/wp-content/uploads/2026/05/image-105-297x300.png 297w, https://vacif.com/wp-content/uploads/2026/05/image-105-768x776.png 768w" sizes="auto, (max-width: 881px) 100vw, 881px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0mezb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0mezb "><div class="eb-advance-heading-wrapper eb-advance-heading-0mezb button-1 undefined" data-id="eb-advance-heading-0mezb"><h2 class="eb-ah-title"><span class="first-title">Bước 8: Test kết nối SSL VPN</span></h2></div></div></div>



<p>Lúc này bạn có thể truy cập vào trong lớp mạng LAN nội bộ đã cấu hình. Ngoài ra bạn có thể vào mục Current activities để kiểm tra xem user nào đang đăng nhập SSL VPN.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2272" height="1402" src="https://vacif.com/wp-content/uploads/2026/05/image-107.png" alt="" class="wp-image-29876" srcset="https://vacif.com/wp-content/uploads/2026/05/image-107.png 2272w, https://vacif.com/wp-content/uploads/2026/05/image-107-300x185.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-107-1024x632.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-107-768x474.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-107-1536x948.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-107-2048x1264.png 2048w" sizes="auto, (max-width: 2272px) 100vw, 2272px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1198" src="https://vacif.com/wp-content/uploads/2026/05/image-108-scaled.png" alt="" class="wp-image-29877" srcset="https://vacif.com/wp-content/uploads/2026/05/image-108-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-108-300x140.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-108-1024x479.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-108-768x359.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-108-1536x719.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-108-2048x958.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ssl-vpn-client-to-site-voi-client-windows-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] Hướng Dẫn Cài Đặt Tường Tửa Sophos Firewall Ảo Bằng File KVM và Dùng Lệnh CLI Trên proxmox</title>
		<link>https://vacif.com/moi-nhat-2026-huong-dan-cai-dat-tuong-tua-sophos-firewall-ao-bang-file-kvm-va-dung-lenh-cli-tren-proxmox/</link>
					<comments>https://vacif.com/moi-nhat-2026-huong-dan-cai-dat-tuong-tua-sophos-firewall-ao-bang-file-kvm-va-dung-lenh-cli-tren-proxmox/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 25 Mar 2026 09:46:19 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Ảo Hóa]]></category>
		<category><![CDATA[CLI]]></category>
		<category><![CDATA[Proxmox VE]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29268</guid>

					<description><![CDATA[Nếu bạn đã quen với việc triển khai Sophos Firewall trên các nền tảng ảo hóa như VMware Workstation hoặc ESXi, thì Proxmox VE là một lựa chọn đáng để thử khi xây dựng hệ thống lab hoặc hạ tầng ảo hóa chi phí thấp. Proxmox VE là nền tảng ảo hóa mã nguồn mở [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u00e0i \u0111\u1eb7t t\u01b0\u1eddng l\u1eeda Sophos Firewall \u1ea3o b\u1eb1ng file KVM v\u00e0 d\u00f9ng l\u1ec7nh CLI tr\u00ean Proxmox&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u00e0i \u0111\u1eb7t t\u01b0\u1eddng l\u1eeda Sophos Firewall \u1ea3o b\u1eb1ng file KVM v\u00e0 d\u00f9ng l\u1ec7nh CLI tr\u00ean Proxmox&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. T\u1ea3i file Sophos Firewall KVM Image&quot;,&quot;text&quot;:&quot;1. T\u1ea3i file Sophos Firewall KVM Image&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Upload file image l\u00ean server Proxmox&quot;,&quot;text&quot;:&quot;2. Upload file image l\u00ean server Proxmox&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. T\u1ea1o m\u00e1y \u1ea3o Sophos Firewall b\u1eb1ng CLI&quot;,&quot;text&quot;:&quot;3. T\u1ea1o m\u00e1y \u1ea3o Sophos Firewall b\u1eb1ng CLI&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4. Import disk image v\u00e0o m\u00e1y \u1ea3o &quot;,&quot;text&quot;:&quot;4. Import disk image v\u00e0o m\u00e1y \u1ea3o &quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;5. C\u1ea5u h\u00ecnh boot disk&quot;,&quot;text&quot;:&quot;5. C\u1ea5u h\u00ecnh boot disk&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;6. Kh\u1edfi \u0111\u1ed9ng Sophos Firewall&quot;,&quot;text&quot;:&quot;6. Kh\u1edfi \u0111\u1ed9ng Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;7. Truy c\u1eadp giao di\u1ec7n Web Admin&quot;,&quot;text&quot;:&quot;7. Truy c\u1eadp giao di\u1ec7n Web Admin&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-m\u1ee5c-\u0111\u00edch-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u00e0i \u0111\u1eb7t t\u01b0\u1eddng l\u1eeda Sophos Firewall \u1ea3o b\u1eb1ng file KVM v\u00e0 d\u00f9ng l\u1ec7nh CLI tr\u00ean Proxmox&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u00e0i-\u0111\u1eb7t-t\u01b0\u1eddng-l\u1eeda-sophos-firewall-\u1ea3o-b\u1eb1ng-file-kvm-v\u00e0-d\u00f9ng-l\u1ec7nh-cli-tr\u00ean-proxmox&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. T\u1ea3i file Sophos Firewall KVM Image&quot;,&quot;value&quot;:&quot;1-t\u1ea3i-file-sophos-firewall-kvm-image&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Upload file image l\u00ean server Proxmox&quot;,&quot;value&quot;:&quot;2-upload-file-image-l\u00ean-server-proxmox&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. T\u1ea1o m\u00e1y \u1ea3o Sophos Firewall b\u1eb1ng CLI&quot;,&quot;value&quot;:&quot;3-t\u1ea1o-m\u00e1y-\u1ea3o-sophos-firewall-b\u1eb1ng-cli&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;4. Import disk image v\u00e0o m\u00e1y \u1ea3o &quot;,&quot;value&quot;:&quot;4-import-disk-image-v\u00e0o-m\u00e1y-\u1ea3o&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;5. C\u1ea5u h\u00ecnh boot disk&quot;,&quot;value&quot;:&quot;5-c\u1ea5u-h\u00ecnh-boot-disk&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;6. Kh\u1edfi \u0111\u1ed9ng Sophos Firewall&quot;,&quot;value&quot;:&quot;6-kh\u1edfi-\u0111\u1ed9ng-sophos-firewall&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;7. Truy c\u1eadp giao di\u1ec7n Web Admin&quot;,&quot;value&quot;:&quot;7-truy-c\u1eadp-giao-di\u1ec7n-web-admin&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Mục đích bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cài đặt tường lửa Sophos Firewall ảo bằng file KVM và dùng lệnh CLI trên Proxmox</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Mục đích bài viết</span></h2></div></div></div>



<p>Nếu bạn đã quen với việc triển khai <strong>Sophos Firewall</strong> trên các nền tảng ảo hóa như VMware Workstation hoặc ESXi, thì <strong>Proxmox VE </strong>là một lựa chọn đáng để thử khi xây dựng hệ thống lab hoặc hạ tầng ảo hóa chi phí thấp.</p>



<p><strong>Proxmox VE là nền tảng ảo hóa mã nguồn mở hỗ trợ hai công nghệ chính:</strong></p>



<ul class="wp-block-list">
<li>KVM (Kernel-based Virtual Machine) để chạy máy ảo</li>



<li>LXC (Linux Containers) để chạy container</li>
</ul>



<p><strong>Với các ưu điểm như:</strong></p>



<ul class="wp-block-list">
<li>Miễn phí và mã nguồn mở</li>



<li>Cộng đồng sử dụng lớn</li>



<li>Quản lý VM thông qua Web GUI</li>



<li>Hỗ trợ snapshot, backup và clustering</li>
</ul>



<p><strong>Proxmox ngày càng được nhiều doanh nghiệp vừa và nhỏ lựa chọn. Trong bài viết này, chúng ta sẽ thực hiện:</strong></p>



<ul class="wp-block-list">
<li>Triển khai Sophos Firewall Virtual trên Proxmox VE</li>



<li>Sử dụng file KVM image của Sophos</li>



<li>Tạo máy ảo bằng lệnh CLI trên Proxmox</li>



<li>Import disk image vào VM</li>



<li>Khởi động Sophos Firewall và thực hiện cấu hình ban đầu</li>
</ul>



<p>Sau khi hoàn thành bài lab, Sophos Firewall sẽ hoạt động như một tường lửa ảo trong hệ thống Proxmox.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4yuyy"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4yuyy "><div class="eb-advance-heading-wrapper eb-advance-heading-4yuyy button-1 undefined" data-id="eb-advance-heading-4yuyy"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="939" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-37.png" alt="" class="wp-image-29269" srcset="https://vacif.com/wp-content/uploads/2026/03/image-37.png 939w, https://vacif.com/wp-content/uploads/2026/03/image-37-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-37-768x325.png 768w" sizes="auto, (max-width: 939px) 100vw, 939px" /></figure>



<p>Trong mô hình này:</p>



<ul class="wp-block-list">
<li>Proxmox VE đóng vai trò là <strong>hypervisor</strong> để chạy máy ảo.</li>



<li>Sophos Firewall được cài đặt dưới dạng <strong>Virtual Machine</strong>.</li>



<li>Máy Windows Client dùng để: 
<ul class="wp-block-list">
<li>Truy cập giao diện quản trị firewall</li>



<li>Kiểm tra trạng thái hoạt động của hệ thống.</li>
</ul>
</li>
</ul>



<p>Quản trị viên truy cập vào giao diện quản trị của Sophos Firewall thông qua trình duyệt web với địa chỉ: <strong>https://10.10.10.200:4444</strong></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-6oz1o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-6oz1o "><div class="eb-advance-heading-wrapper eb-advance-heading-6oz1o button-1 undefined" data-id="eb-advance-heading-6oz1o"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Trong bài lab này, chúng ta thực hiện triển khai Sophos Firewall dưới dạng máy ảo trên Proxmox VE với mục đích xây dựng môi trường thử nghiệm.</p>



<p><strong>Các yêu cầu của hệ thống như sau:</strong></p>



<ul class="wp-block-list">
<li>Cài đặt Sophos Firewall Virtual trên Proxmox.</li>



<li>Cấu hình địa chỉ IP cho firewall là<strong> 10.10.10.200/24.</strong></li>



<li>Máy Windows Client có địa chỉ <strong>10.10.10.116/24.</strong></li>



<li>Máy Windows có thể truy cập vào giao diện quản trị của Sophos Firewall thông qua trình duyệt web.</li>
</ul>



<p><strong>Sau khi hoàn thành cấu hình:</strong></p>



<ul class="wp-block-list">
<li>Quản trị viên có thể đăng nhập vào giao diện Web Admin</li>



<li>Thực hiện các cấu hình bảo mật, firewall rule và quản lý hệ thống.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-47r7n"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-47r7n "><div class="eb-advance-heading-wrapper eb-advance-heading-47r7n button-1 undefined" data-id="eb-advance-heading-47r7n"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<p><strong>Quá trình triển khai Sophos Firewall Virtual trên Proxmox gồm các bước chính sau:</strong></p>



<ol class="wp-block-list">
<li>Tải file <strong>&#8220;Sophos Firewall KVM Image&#8221;</strong></li>



<li>Upload file image lên server Proxmox</li>



<li>Tạo máy ảo Sophos Firewall bằng CLI</li>



<li>Import disk image vào máy ảo</li>



<li>Cấu hình boot disk</li>



<li>Khởi động Sophos Firewall</li>



<li>Truy cập giao diện Web Admin</li>
</ol>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-k9cwb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-k9cwb "><div class="eb-advance-heading-wrapper eb-advance-heading-k9cwb button-1 undefined" data-id="eb-advance-heading-k9cwb"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cài đặt tường lửa Sophos Firewall ảo bằng file KVM và dùng lệnh CLI trên Proxmox</span></h2></div></div></div>



<p><strong>Trước khi bắt tay vào dựng Sophos Firewall trên Proxmox, bạn cần chuẩn bị:</strong></p>



<ul class="wp-block-list">
<li>Máy chủ/PC đã cài Proxmox VE (khuyến nghị bản 7.x hoặc mới hơn).</li>



<li>File KVM Sophos Firewall (SFOS): tải từ trang chủ Sophos (bản Home hoặc Trial).</li>



<li>Tài nguyên tối thiểu cho VM: CPU: 2, coreRAM: 4 GB</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Tải file Sophos Firewall KVM Image</span></h2></div></div></div>



<p>Trước tiên, chúng ta cần chuẩn bị file KVM cài đặt Sophos Firewall. Truy cập trang chính thức của Sophos tại: <strong>https://www.sophos.com/en-us/support/downloads/firewall-installers.</strong> Tại đây, chọn và tải về phiên bản dành cho KVM (tương thích với Proxmox).</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="753" height="403" src="https://vacif.com/wp-content/uploads/2026/03/image-39.png" alt="" class="wp-image-29270" srcset="https://vacif.com/wp-content/uploads/2026/03/image-39.png 753w, https://vacif.com/wp-content/uploads/2026/03/image-39-300x161.png 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></figure>



<p>Sau khi tải và giải nén ta được 2 file như sau:</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="502" height="43" src="https://vacif.com/wp-content/uploads/2026/03/image-38.png" alt="" class="wp-image-29271" srcset="https://vacif.com/wp-content/uploads/2026/03/image-38.png 502w, https://vacif.com/wp-content/uploads/2026/03/image-38-300x26.png 300w" sizes="auto, (max-width: 502px) 100vw, 502px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="309" height="119" src="https://vacif.com/wp-content/uploads/2026/03/image-40.png" alt="" class="wp-image-29272" srcset="https://vacif.com/wp-content/uploads/2026/03/image-40.png 309w, https://vacif.com/wp-content/uploads/2026/03/image-40-300x116.png 300w" sizes="auto, (max-width: 309px) 100vw, 309px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-7cjjp"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-7cjjp "><div class="eb-advance-heading-wrapper eb-advance-heading-7cjjp button-1 undefined" data-id="eb-advance-heading-7cjjp"><h2 class="eb-ah-title"><span class="first-title">2. Upload file image lên server Proxmox</span></h2></div></div></div>



<p>Tạo máy ảo Sophos Firewall trên Proxmox -&gt; Đăng nhập vào Proxmox Web UI -&gt; chọn <strong>Create VM</strong> để bắt đầu tạo máy ảo mới -&gt; Nhập <strong>VM ID</strong> và T<strong>ên máy ảo (Name).</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="274" src="https://vacif.com/wp-content/uploads/2026/03/image-43.png" alt="" class="wp-image-29275" srcset="https://vacif.com/wp-content/uploads/2026/03/image-43.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-43-300x109.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="553" src="https://vacif.com/wp-content/uploads/2026/03/image-42.png" alt="" class="wp-image-29273" srcset="https://vacif.com/wp-content/uploads/2026/03/image-42.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-42-300x221.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p>Tick chọn <strong>Do not use any media -&gt;</strong>Type: <strong>linux -&gt;</strong>Version: <strong>6.x &#8211; 2.6 Kernel</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="273" src="https://vacif.com/wp-content/uploads/2026/03/image-41.png" alt="" class="wp-image-29274" srcset="https://vacif.com/wp-content/uploads/2026/03/image-41.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-41-300x109.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p>Sockets: <strong>2</strong></p>



<p>Cores: <strong>2</strong></p>



<p>Type: <strong>host</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="183" src="https://vacif.com/wp-content/uploads/2026/03/image-44.png" alt="" class="wp-image-29278" srcset="https://vacif.com/wp-content/uploads/2026/03/image-44.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-44-300x73.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p></p>



<p>Memory(MB): 4096 và click next</p>



<p></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="160" src="https://vacif.com/wp-content/uploads/2026/03/image-46.png" alt="" class="wp-image-29279" srcset="https://vacif.com/wp-content/uploads/2026/03/image-46.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-46-300x64.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p></p>



<p>Chọn card mạng <strong>bridge </strong>và click<strong>next -></strong> chắc chắn ràng không có gì sai xót sau khi tạo xong, nhấn <strong>finish.</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="265" src="https://vacif.com/wp-content/uploads/2026/03/image-45.png" alt="" class="wp-image-29277" srcset="https://vacif.com/wp-content/uploads/2026/03/image-45.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-45-300x106.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p>Sử dụng công cụ WinSCP để tiến hành copy file KVM Sophos đã tải về vào thư mục của VM theo đường dẫn: <strong>/mnt/pve/disk-pve1/images/2027/</strong></p>



<p>Trong đó:</p>



<ul class="wp-block-list">
<li><strong>disk-pve1</strong> là tên storage trên Proxmox.</li>



<li><strong>2027 là VM ID</strong> mà bạn đã tạo ở bước trước.</li>
</ul>



<p><strong>** Lưu ý: </strong>Thư mục có dạng<strong>/mnt/pve/&lt;storage-name>/images/&lt;VMID>/</strong>. Bạn cần thay đúng <strong>&lt;storage-name></strong> và <strong>&lt;VMID></strong> theo môi trường của mình.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="939" height="824" src="https://vacif.com/wp-content/uploads/2026/03/image-48.png" alt="" class="wp-image-29281" srcset="https://vacif.com/wp-content/uploads/2026/03/image-48.png 939w, https://vacif.com/wp-content/uploads/2026/03/image-48-300x263.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-48-768x674.png 768w" sizes="auto, (max-width: 939px) 100vw, 939px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="940" height="215" src="https://vacif.com/wp-content/uploads/2026/03/image-49.png" alt="" class="wp-image-29282" srcset="https://vacif.com/wp-content/uploads/2026/03/image-49.png 940w, https://vacif.com/wp-content/uploads/2026/03/image-49-300x69.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-49-768x176.png 768w" sizes="auto, (max-width: 940px) 100vw, 940px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-m2738"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-m2738 "><div class="eb-advance-heading-wrapper eb-advance-heading-m2738 button-1 undefined" data-id="eb-advance-heading-m2738"><h2 class="eb-ah-title"><span class="first-title">3. Tạo máy ảo Sophos Firewall bằng CLI</span></h2></div></div></div>



<p>Mở <strong>Shell </strong>trong giao diện Proxmox.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="751" height="95" src="https://vacif.com/wp-content/uploads/2026/03/image-50.png" alt="" class="wp-image-29283" srcset="https://vacif.com/wp-content/uploads/2026/03/image-50.png 751w, https://vacif.com/wp-content/uploads/2026/03/image-50-300x38.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /></figure>



<p>Truy cập thư mục lưu trữ:</p>



<ul class="wp-block-list">
<li><strong>cd /mnt/pve</strong></li>



<li><strong>ls</strong></li>
</ul>



<p>→ Lệnh ls sẽ liệt kê tất cả các storage có trong Proxmox.</p>



<p>Di chuyển vào storage bạn đã dùng để lưu file KVM, ví dụ:</p>



<ul class="wp-block-list">
<li><strong>cd /mnt/pve/disk1-pve1/images/</strong></li>



<li><strong>Ls</strong></li>
</ul>



<p>Tại đây sẽ hiển thị danh sách các thư mục tương ứng với VM ID. Trong ví dụ này, máy Sophos Firewall được gán VM ID = 1027:</p>



<ul class="wp-block-list">
<li><strong>cd 1027</strong></li>



<li><strong>ls</strong></li>
</ul>



<p>→ Bạn sẽ thấy toàn bộ các file (bao gồm ISO và disk image) của VM Sophos Firewall.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="412" src="https://vacif.com/wp-content/uploads/2026/03/image-51.png" alt="" class="wp-image-29284" srcset="https://vacif.com/wp-content/uploads/2026/03/image-51.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-51-300x164.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-kb9wj"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-kb9wj "><div class="eb-advance-heading-wrapper eb-advance-heading-kb9wj button-1 undefined" data-id="eb-advance-heading-kb9wj"><h2 class="eb-ah-title"><span class="first-title">4. Import disk image vào máy ảo </span></h2></div></div></div>



<p>Mở file cấu hình của VM bằng trình soạn thảo nano:</p>



<ul class="wp-block-list">
<li> <strong>nano /etc/pve/qemu-server/1027.conf</strong></li>
</ul>



<p>Thêm hoặc chỉnh sửa 2 dòng sau để khai báo ổ đĩa cho Sophos Firewall:</p>



<ul class="wp-block-list">
<li><strong>scsi0: disk1-pve1:1027/PRIMARY-DISK.qcow2,size=32G</strong></li>



<li><strong>scsi1: disk1-pve1:1027/AUXILIARY-DISK.qcow2,size=80G</strong></li>
</ul>



<p>→ scsi0: Ổ cứng chính (32GB).</p>



<p>→ scsi1: Ổ phụ (80GB).</p>



<p><strong>Lưu file cấu hình:</strong></p>



<ul class="wp-block-list">
<li>Nhấn <strong>Ctrl + O → Enter</strong> để lưu.</li>



<li>Nhấn <strong>Ctrl + X</strong> để thoát khỏi nano.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="751" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-52.png" alt="" class="wp-image-29285" srcset="https://vacif.com/wp-content/uploads/2026/03/image-52.png 751w, https://vacif.com/wp-content/uploads/2026/03/image-52-300x181.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-o2e58"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-o2e58 "><div class="eb-advance-heading-wrapper eb-advance-heading-o2e58 button-1 undefined" data-id="eb-advance-heading-o2e58"><h2 class="eb-ah-title"><span class="first-title">5. Cấu hình boot disk</span></h2></div></div></div>



<p>Tick chọn như hình bên dưới</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="319" src="https://vacif.com/wp-content/uploads/2026/03/image-53.png" alt="" class="wp-image-29286" srcset="https://vacif.com/wp-content/uploads/2026/03/image-53.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-53-300x127.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-zapov"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-zapov "><div class="eb-advance-heading-wrapper eb-advance-heading-zapov button-1 undefined" data-id="eb-advance-heading-zapov"><h2 class="eb-ah-title"><span class="first-title">6. Khởi động Sophos Firewall</span></h2></div></div></div>



<p>Sau khi hoàn tất, nhấn <strong>Start</strong> để khởi động node Sophos Firewall.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="751" height="348" src="https://vacif.com/wp-content/uploads/2026/03/image-54.png" alt="" class="wp-image-29287" srcset="https://vacif.com/wp-content/uploads/2026/03/image-54.png 751w, https://vacif.com/wp-content/uploads/2026/03/image-54-300x139.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dom1g"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dom1g "><div class="eb-advance-heading-wrapper eb-advance-heading-dom1g button-1 undefined" data-id="eb-advance-heading-dom1g"><h2 class="eb-ah-title"><span class="first-title">7. Truy cập giao diện Web Admin</span></h2></div></div></div>



<p>Truy cập Console của VM để theo dõi quá trình boot. Nếu thấy giao diện cài đặt của Sophos xuất hiện và hệ thống chạy ổn định, nghĩa là bạn đã triển khai thành công.</p>



<p>Như vậy, chúng ta đã chạy Sophos Firewall ảo trong Proxmox thành công. Từ đây, bạn có thể tiếp tục:</p>



<ul class="wp-block-list">
<li>Truy cập WebAdmin</li>



<li>Thực hiện các bước cấu hình cơ bản (IP LAN/WAN, NAT, Firewall Rule).</li>



<li>Mở rộng lab với VPN, IPS, WAF, hoặc thử nghiệm các tính năng bảo mật khác.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="753" height="495" src="https://vacif.com/wp-content/uploads/2026/03/image-55.png" alt="" class="wp-image-29288" srcset="https://vacif.com/wp-content/uploads/2026/03/image-55.png 753w, https://vacif.com/wp-content/uploads/2026/03/image-55-300x197.png 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-huong-dan-cai-dat-tuong-tua-sophos-firewall-ao-bang-file-kvm-va-dung-lenh-cli-tren-proxmox/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site to Site Giữa Firewall Fortinet và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 04 Mar 2026 05:41:35 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Fortinet Firewall]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29017</guid>

					<description><![CDATA[Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet. Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;text&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;text&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;text&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;text&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;text&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;text&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;text&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;text&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;text&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;text&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;text&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;link&quot;:&quot;eb-table-content-15&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-firewall-fortinet-v\u00e0-sophos-firewall-firmware-v22-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;value&quot;:&quot;1-tr\u00ean-thi\u1ebft-b\u1ecb-fortinet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;value&quot;:&quot;11-t\u1ea1o-vpn-tunnels&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;value&quot;:&quot;12-t\u1ea1o-static-route&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;value&quot;:&quot;13-t\u1ea1o-firewall-policy&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;value&quot;:&quot;2-tr\u00ean-thi\u1ebft-b\u1ecb-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;value&quot;:&quot;21-t\u1ea1o-subnet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;value&quot;:&quot;22-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;value&quot;:&quot;23-t\u1ea1o-ipsec-connection&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;value&quot;:&quot;24-t\u1ea1o-firewall-rule-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;value&quot;:&quot;3-ki\u1ec3m-tra-k\u1ebft-qu\u1ea3&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;value&quot;:&quot;ghi-ch\u00fa-l\u01b0u-\u00fd-tri\u1ec3n-khai&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet.</p>



<p>Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy cập lẫn nhau:</p>



<ul class="wp-block-list">
<li>172.16.16.0/24 – Site A</li>



<li>10.10.10.0/24 – Site B</li>



<li>192.168.20.0/24 – Site B</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="366" src="https://vacif.com/wp-content/uploads/2026/03/image-8.png" alt="" class="wp-image-29019" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x325.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-mm8bi"><div class="eb-parent-wrapper eb-parent-eb-text-mm8bi "><div class="eb-text-wrapper eb-text-mm8bi" data-id="eb-text-mm8bi"><p class="eb-text">Giải thích sơ đồ mạng:</p></div></div></div>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site A – Fortinet Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào cổng WAN của thiết bị Fortinet</li>



<li>IP WAN: 192.168.1.2</li>



<li>Mạng LAN nội bộ: 172.16.16.0/24</li>



<li>LAN được cấu hình trên interface LAN của Fortinet</li>
</ul>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site B – Sophos Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào interface a (WAN) của Sophos Firewall</li>



<li>IP WAN: 192.168.1.3</li>



<li>Mạng LAN nội bộ gồm 2 lớp mạng: 10.10.10.0/24, 192.168.20.0/24</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-w4aye"><div class="eb-parent-wrapper eb-parent-eb-text-w4aye "><div class="eb-text-wrapper eb-text-w4aye" data-id="eb-text-w4aye"><p class="eb-text">Lưu ý sơ đồ:</p></div></div></div>



<ul class="wp-block-list">
<li>Kết nối VPN sử dụng IPSec Site-to-Site</li>



<li>Xác thực bằng Pre-shared Key</li>



<li>Sử dụng IKEv2</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-jmoxo"><div class="eb-parent-wrapper eb-parent-eb-text-jmoxo "><div class="eb-text-wrapper eb-text-jmoxo" data-id="eb-text-jmoxo"><p class="eb-text">Chúng ta sẽ thực hiện cấu hình IPSec VPN Site-to-Site giữa:</p></div></div></div>



<ul class="wp-block-list">
<li>Fortinet (192.168.1.2)</li>



<li>Sophos (192.168.1.3)</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-oylnm"><div class="eb-parent-wrapper eb-parent-eb-text-oylnm "><div class="eb-text-wrapper eb-text-oylnm" data-id="eb-text-oylnm"><p class="eb-text">Mục tiêu:</p></div></div></div>



<p>Mạng LAN 172.16.16.0/24 (Fortinet) ⬄ Mạng LAN 10.10.10.0/24 và 192.168.20.0/24 (Sophos) có thể kết nối qua lại trực tiếp.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yq4nn"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yq4nn "><div class="eb-advance-heading-wrapper eb-advance-heading-yq4nn button-1 undefined" data-id="eb-advance-heading-yq4nn"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-queb7"><div class="eb-parent-wrapper eb-parent-eb-text-queb7 "><div class="eb-text-wrapper eb-text-queb7" data-id="eb-text-queb7"><p class="eb-text">Trên thiết bị Fortinet:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo VPN Tunnels</li>



<li>Tạo Static Route</li>



<li>Tạo Firewall Policy</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-vlwq4"><div class="eb-parent-wrapper eb-parent-eb-text-vlwq4 "><div class="eb-text-wrapper eb-text-vlwq4" data-id="eb-text-vlwq4"><p class="eb-text">Trên thiết bị Sophos:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo subnet</li>



<li>Tạo IPSec Profile</li>



<li>Tạo IPSec Connection</li>



<li>Tạo Firewall Rule</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-76g77"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-76g77 "><div class="eb-advance-heading-wrapper eb-advance-heading-76g77 button-1 undefined" data-id="eb-advance-heading-76g77"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Trên thiết bị Fortinet:</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wc297"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wc297 "><div class="eb-advance-heading-wrapper eb-advance-heading-wc297 button-1 undefined" data-id="eb-advance-heading-wc297"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Tạo VPN Tunnels</span></h2></div></div></div>



<p>Vào VPN → IPsec Tunnels → Create New → Custom</p>



<div class="wp-block-essential-blocks-text  root-eb-text-i1ir1"><div class="eb-parent-wrapper eb-parent-eb-text-i1ir1 "><div class="eb-text-wrapper eb-text-i1ir1" data-id="eb-text-i1ir1"><p class="eb-text">Bảng VPN Create Wizard</p></div></div></div>



<p>Name: S2S-LAB</p>



<p>Template Type: Custom</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg" alt="" class="wp-image-29020" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>Dùng Custom để chủ động cấu hình Phase 1 / Phase 2</p>



<div class="wp-block-essential-blocks-text  root-eb-text-xvm9r"><div class="eb-parent-wrapper eb-parent-eb-text-xvm9r "><div class="eb-text-wrapper eb-text-xvm9r" data-id="eb-text-xvm9r"><p class="eb-text">Bảng Network</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="746" height="709" src="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg" alt="" class="wp-image-29021" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg 746w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x285.jpg 300w" sizes="auto, (max-width: 746px) 100vw, 746px" /></figure>



<figure class="wp-block-table is-style-regular"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>IP Version</td><td>IPv4</td></tr><tr><td>Remote Gateway</td><td>Static IP Address</td></tr><tr><td>IP Address</td><td>192.168.1.3 (WAN Sophos)</td></tr><tr><td>Interface</td><td>WAN</td></tr><tr><td>Local Gateway</td><td>Không bật</td></tr><tr><td>Mode Config</td><td>Bỏ chọn</td></tr><tr><td>NAT Traversal</td><td>Disable</td></tr><tr><td>Dead Peer Detection</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-h7m6p"><div class="eb-parent-wrapper eb-parent-eb-text-h7m6p "><div class="eb-text-wrapper eb-text-h7m6p" data-id="eb-text-h7m6p"><p class="eb-text">&#8211; Disable NAT-T vì không NAT giữa 2 WAN<br>&#8211; Disable DPD để tránh reset tunnel trong lab</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-8oxg9"><div class="eb-parent-wrapper eb-parent-eb-text-8oxg9 "><div class="eb-text-wrapper eb-text-8oxg9" data-id="eb-text-8oxg9"><p class="eb-text">Bảng Authentication</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="735" height="331" src="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg" alt="" class="wp-image-29022" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg 735w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x135.jpg 300w" sizes="auto, (max-width: 735px) 100vw, 735px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Method</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>(ví dụ) FortiSophos@123</td></tr><tr><td>IKE Version</td><td>2</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-2qql7"><div class="eb-parent-wrapper eb-parent-eb-text-2qql7 "><div class="eb-text-wrapper eb-text-2qql7" data-id="eb-text-2qql7"><p class="eb-text">&#8211; PSK phải giống 100% bên Sophos</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-11jdu"><div class="eb-parent-wrapper eb-parent-eb-text-11jdu "><div class="eb-text-wrapper eb-text-11jdu" data-id="eb-text-11jdu"><p class="eb-text">Phase 1 Proposal</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="757" height="376" src="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg" alt="" class="wp-image-29023" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg 757w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x149.jpg 300w" sizes="auto, (max-width: 757px) 100vw, 757px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>28800</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6r9aw"><div class="eb-parent-wrapper eb-parent-eb-text-6r9aw "><div class="eb-text-wrapper eb-text-6r9aw" data-id="eb-text-6r9aw"><p class="eb-text">Phase 2 Selectors</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="578" height="714" src="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg" alt="" class="wp-image-29032" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg 578w, https://vacif.com/wp-content/uploads/2026/03/image-28-243x300.jpg 243w" sizes="auto, (max-width: 578px) 100vw, 578px" /></figure>



<p><strong>Selector 1</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 10.10.10.0/24</li>
</ul>



<p><strong>Selector 2</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 192.168.20.0/24</li>
</ul>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>43200</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4mf91"><div class="eb-parent-wrapper eb-parent-eb-text-4mf91 "><div class="eb-text-wrapper eb-text-4mf91" data-id="eb-text-4mf91"><p class="eb-text">&#8211; Mỗi subnet Sophos cần 1 Phase 2<br>&#8211; Nếu gộp → tunnel UP nhưng không có traffic</p></div></div></div>



<p>Nhấn OK để tạo VPN Tunnel.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ljz9a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ljz9a "><div class="eb-advance-heading-wrapper eb-advance-heading-ljz9a button-1 undefined" data-id="eb-advance-heading-ljz9a"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Tạo Static Route</span></h2></div></div></div>



<p>Vào Network → Static Routes → Create New</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg" alt="" class="wp-image-29027" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-i0llt"><div class="eb-parent-wrapper eb-parent-eb-text-i0llt "><div class="eb-text-wrapper eb-text-i0llt" data-id="eb-text-i0llt"><p class="eb-text">Route 1</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>10.10.10.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-t16sq"><div class="eb-parent-wrapper eb-parent-eb-text-t16sq "><div class="eb-text-wrapper eb-text-t16sq" data-id="eb-text-t16sq"><p class="eb-text">Route 2</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg" alt="" class="wp-image-29026" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>192.168.20.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-175x1"><div class="eb-parent-wrapper eb-parent-eb-text-175x1 "><div class="eb-text-wrapper eb-text-175x1" data-id="eb-text-175x1"><p class="eb-text">&#8211; Nếu thiếu static route → ping không bao giờ đi vào VPN</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-siaef"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-siaef "><div class="eb-advance-heading-wrapper eb-advance-heading-siaef button-1 undefined" data-id="eb-advance-heading-siaef"><h2 class="eb-ah-title"><span class="first-title"><a>1.3</a> &#8211; Tạo Firewall Policy</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-k0mcg"><div class="eb-parent-wrapper eb-parent-eb-text-k0mcg "><div class="eb-text-wrapper eb-text-k0mcg" data-id="eb-text-k0mcg"><p class="eb-text">Policy 1 – LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg" alt="" class="wp-image-29030" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>LAN</td></tr><tr><td>Outgoing Interface</td><td>S2S-LAB</td></tr><tr><td>Source</td><td>172.16.16.0/24</td></tr><tr><td>Destination</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr><tr><td>NAT</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-04oaf"><div class="eb-parent-wrapper eb-parent-eb-text-04oaf "><div class="eb-text-wrapper eb-text-04oaf" data-id="eb-text-04oaf"><p class="eb-text">Policy 2 – VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg" alt="" class="wp-image-29031" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>S2S-LAB</td></tr><tr><td>Outgoing Interface</td><td>LAN</td></tr><tr><td>Source</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination</td><td>172.16.16.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-i77g3"><div class="eb-parent-wrapper eb-parent-eb-text-i77g3 "><div class="eb-text-wrapper eb-text-i77g3" data-id="eb-text-i77g3"><p class="eb-text">&#8211; Policy VPN phải nằm trên policy Internet</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qh3q2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qh3q2 "><div class="eb-advance-heading-wrapper eb-advance-heading-qh3q2 button-1 undefined" data-id="eb-advance-heading-qh3q2"><h2 class="eb-ah-title"><span class="first-title"><a>2. </a>Trên thiết bị Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a7f6u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a7f6u "><div class="eb-advance-heading-wrapper eb-advance-heading-a7f6u button-1 undefined" data-id="eb-advance-heading-a7f6u"><h2 class="eb-ah-title"><span class="first-title">2.1 &#8211; Tạo subnet</span></h2></div></div></div>



<p>Vào Hosts and Services → Add</p>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tên</strong></th><th><strong>Loại</strong></th><th><strong>Thông số</strong></th></tr></thead><tbody><tr><td>LAN_SOPHOS_10</td><td>Network</td><td>IP: 10.10.10.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_SOPHOS_20</td><td>Network</td><td>IP: 192.168.20.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_FORTI</td><td>Network</td><td>IP: 172.16.16.0 / Subnet: 255.255.255.0</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bkx0m"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bkx0m "><div class="eb-advance-heading-wrapper eb-advance-heading-bkx0m button-1 undefined" data-id="eb-advance-heading-bkx0m"><h2 class="eb-ah-title"><span class="first-title">2.2 &#8211; Tạo IPSec Profile</span></h2></div></div></div>



<p>Vào SYSTEM &gt; Profiles → IPsec Profiles → Add</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg" alt="" class="wp-image-29024" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>Fortinet-Vacif</td></tr><tr><td>IKE Version</td><td>IKEv2</td></tr><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>DH Group</td><td>14</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x0jn2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x0jn2 "><div class="eb-advance-heading-wrapper eb-advance-heading-x0jn2 button-1 undefined" data-id="eb-advance-heading-x0jn2"><h2 class="eb-ah-title"><span class="first-title">2.3 &#8211; Tạo IPSec Connection</span></h2></div></div></div>



<p>Vào CONFIGURE → Site-to-site VPN → &nbsp;IPsec → Add</p>



<div class="wp-block-essential-blocks-text  root-eb-text-b8zwg"><div class="eb-parent-wrapper eb-parent-eb-text-b8zwg "><div class="eb-text-wrapper eb-text-b8zwg" data-id="eb-text-b8zwg"><p class="eb-text">General Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg" alt="" class="wp-image-29025" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>VPN_SOPHOS_VACIF</td></tr><tr><td>Connection Type</td><td>Policy-based</td></tr><tr><td>Gateway Type</td><td>Initiate the connection</td></tr><tr><td>Create firewall rule</td><td>Không chọn (tạo thủ công)</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-86g8b"><div class="eb-parent-wrapper eb-parent-eb-text-86g8b "><div class="eb-text-wrapper eb-text-86g8b" data-id="eb-text-86g8b"><p class="eb-text">Authentication</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Profile</td><td>Fortinet Vacif ( tạo ở bước trên )</td></tr><tr><td>Authentication Type&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>FortiSophos@123</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6opfg"><div class="eb-parent-wrapper eb-parent-eb-text-6opfg "><div class="eb-text-wrapper eb-text-6opfg" data-id="eb-text-6opfg"><p class="eb-text">Gateway Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg" alt="" class="wp-image-29033" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<ul class="wp-block-list">
<li>Listening interface: Port 2 – 192.168.1.3</li>



<li>Gateway address: 192.168.1.2 (WAN Fortinet)</li>



<li>Local Subnet: 10.10.10.0/24 , 192.168.20.0/24</li>



<li>Remote Subnet: 172.16.16.0/24</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2dz5o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2dz5o "><div class="eb-advance-heading-wrapper eb-advance-heading-2dz5o button-1 undefined" data-id="eb-advance-heading-2dz5o"><h2 class="eb-ah-title"><span class="first-title"><a>2.4</a> &#8211; Tạo Firewall Rule Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-069m1"><div class="eb-parent-wrapper eb-parent-eb-text-069m1 "><div class="eb-text-wrapper eb-text-069m1" data-id="eb-text-069m1"><p class="eb-text">LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg" alt="" class="wp-image-29028" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>LAN</td></tr><tr><td>Destination Zone</td><td>VPN</td></tr><tr><td>Source Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination Network</td><td>172.16.16.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-0pm0n"><div class="eb-parent-wrapper eb-parent-eb-text-0pm0n "><div class="eb-text-wrapper eb-text-0pm0n" data-id="eb-text-0pm0n"><p class="eb-text">VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg" alt="" class="wp-image-29029" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>VPN</td></tr><tr><td>Destination Zone</td><td>LAN</td></tr><tr><td>Source Network</td><td>172.16.16.0/24</td></tr><tr><td>Destination Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeg05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeg05 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeg05 button-1 undefined" data-id="eb-advance-heading-qeg05"><h2 class="eb-ah-title"><span class="first-title"><a>3</a>. Kiểm tra kết quả</span></h2></div></div></div>



<p><strong>Sophos:</strong> VPN → IPsec Connections → Status: <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f7e2.png" alt="🟢" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Connected</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg" alt="" class="wp-image-29034" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Fortinet:</strong> Monitor → IPsec Monitor → Tunnel: UP (Có Incoming / Outgoing Data)</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg" alt="" class="wp-image-29035" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Test:</strong></p>



<ul class="wp-block-list">
<li>172.16.16.x → 10.10.10.x</li>



<li>172.16.16.x → 192.168.20.x</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg" alt="" class="wp-image-29036" srcset="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-32-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-32-768x404.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iq8fr"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iq8fr "><div class="eb-advance-heading-wrapper eb-advance-heading-iq8fr button-1 undefined" data-id="eb-advance-heading-iq8fr"><h2 class="eb-ah-title"><span class="first-title">* Ghi chú &amp; Lưu ý triển khai</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đảm bảo thời gian hệ thống đồng bộ (NTP) để tránh lỗi IKEv2 do lệch thời gian.</li>



<li>PSK, thuật toán mã hóa và nhóm DH phải trùng khớp 2 đầu – sai khác sẽ khiến Phase 1/2 thất bại.</li>



<li>Tắt NAT trên policy đi vào VPN; bật NAT sẽ làm sai nguồn và gói tin không match selector.</li>



<li>Mỗi cặp Local/Remote subnet cần 1 selector (Phase 2). Không gộp nhiều subnet nếu thiết bị không hỗ trợ.</li>



<li>Nếu tunnel UP nhưng không ping được, kiểm tra: Static Route, Policy thứ tự, và bảng ARP/Route trên hai đầu.</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Theo Dõi &#038; Xuất Report Từ Sophos Firewall V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-theo-doi-xuat-report-tu-sophos-firewall-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-theo-doi-xuat-report-tu-sophos-firewall-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Tue, 03 Mar 2026 09:20:47 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[log and report]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[sophos firewall v22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=28977</guid>

					<description><![CDATA[Bài viết này nhằm: Qua đó, giúp hệ thống được giám sát hiệu quả và vận hành an toàn hơn. Xem thông tin về lưu lượng mạng đi qua firewall và các mối đe dọa bảo mật Các loại Dashboard chính: Xem thông tin về việc sử dụng ứng dụng và Internet trên hệ thống [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="974" height="287" src="https://vacif.com/wp-content/uploads/2026/03/image.png" alt="" class="wp-image-28978" srcset="https://vacif.com/wp-content/uploads/2026/03/image.png 974w, https://vacif.com/wp-content/uploads/2026/03/image-300x88.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-768x226.png 768w" sizes="auto, (max-width: 974px) 100vw, 974px" /></figure>


<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22 &quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22 &quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22&quot;,&quot;text&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng Report &amp; Log c\u1ee7a Sophos Firewall&quot;,&quot;text&quot;:&quot;1. Gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng Report &amp; Log c\u1ee7a Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - Dashboards&quot;,&quot;text&quot;:&quot;1.1 - Dashboards&quot;,&quot;link&quot;:&quot;11-dashboards&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - Application &amp; Webs&quot;,&quot;text&quot;:&quot;1.2 - Application &amp; Webs&quot;,&quot;link&quot;:&quot;12-application-webs&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - Networks &amp; Threat&quot;,&quot;text&quot;:&quot;1.3 - Networks &amp; Threat&quot;,&quot;link&quot;:&quot;13-networks-threat&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.4 - VPN&quot;,&quot;text&quot;:&quot;1.4 - VPN&quot;,&quot;link&quot;:&quot;14-vpn&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.5 - Email&quot;,&quot;text&quot;:&quot;1.5 - Email&quot;,&quot;link&quot;:&quot;15-email&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.6 - Compliance&quot;,&quot;text&quot;:&quot;1.6 - Compliance&quot;,&quot;link&quot;:&quot;16-compliance&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.7 - Custom&quot;,&quot;text&quot;:&quot;1.7 - Custom&quot;,&quot;link&quot;:&quot;17-custom&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.8 - Log Viewer&quot;,&quot;text&quot;:&quot;1.8 - Log Viewer&quot;,&quot;link&quot;:&quot;18-log-viewer&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u00e1ch xu\u1ea5t Report tr\u00ean Sophos Firewall&quot;,&quot;text&quot;:&quot;2. C\u00e1ch xu\u1ea5t Report tr\u00ean Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22 &quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-theo-d\u00f5i-v\u00e0-xu\u1ea5t-report-t\u1eeb-sophos-firewall-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22&quot;,&quot;value&quot;:&quot;ii-chi-ti\u1ebft-v\u1ec1-theo-d\u00f5i-v\u00e0-xu\u1ea5t-report-t\u1eeb-sophos-firewall-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng Report &amp; Log c\u1ee7a Sophos Firewall&quot;,&quot;value&quot;:&quot;1-gi\u1edbi-thi\u1ec7u-t\u00ednh-n\u0103ng-report-log-c\u1ee7a-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.1 - Dashboards&quot;,&quot;value&quot;:&quot;11-dashboards&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.2 - Application &amp; Webs&quot;,&quot;value&quot;:&quot;12-application-webs&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.3 - Networks &amp; Threat&quot;,&quot;value&quot;:&quot;13-networks-threat&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.4 - VPN&quot;,&quot;value&quot;:&quot;14-vpn&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.5 - Email&quot;,&quot;value&quot;:&quot;15-email&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.6 - Compliance&quot;,&quot;value&quot;:&quot;16-compliance&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.7 - Custom&quot;,&quot;value&quot;:&quot;17-custom&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.8 - Log Viewer&quot;,&quot;value&quot;:&quot;18-log-viewer&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u00e1ch xu\u1ea5t Report tr\u00ean Sophos Firewall&quot;,&quot;value&quot;:&quot;2-c\u00e1ch-xu\u1ea5t-report-tr\u00ean-sophos-firewall&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về theo dõi và xuất report từ Sophos Firewall V22 </a><li><a href="#eb-table-content-1">II &#8211; Chi tiết về theo dõi và xuất report từ Sophos Firewall V22</a><li><a href="#eb-table-content-2">1. Giới thiệu tính năng Report &amp; Log của Sophos Firewall</a><li><a href="#11-dashboards">1.1 &#8211; Dashboards</a><li><a href="#12-application-webs">1.2 &#8211; Application &amp; Webs</a><li><a href="#13-networks-threat">1.3 &#8211; Networks &amp; Threat</a><li><a href="#14-vpn">1.4 &#8211; VPN</a><li><a href="#15-email">1.5 &#8211; Email</a><li><a href="#16-compliance">1.6 &#8211; Compliance</a><li><a href="#17-custom">1.7 &#8211; Custom</a><li><a href="#18-log-viewer">1.8 &#8211; Log Viewer</a><li><a href="#eb-table-content-11">2. Cách xuất Report trên Sophos Firewall</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về theo dõi và xuất report từ Sophos Firewall V22 </span></h2></div></div></div>



<p>Bài viết này nhằm:</p>



<ul class="wp-block-list">
<li>Hướng dẫn cách xem và lọc log trên Sophos Firewall.</li>



<li>Hướng dẫn đọc và xuất report phục vụ vận hành và báo cáo.</li>



<li>Giúp quản trị viên nhanh chóng phát hiện sự cố và mối đe dọa bảo mật.</li>
</ul>



<p>Qua đó, giúp hệ thống được giám sát hiệu quả và vận hành an toàn hơn.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Chi tiết về theo dõi và xuất report từ Sophos Firewall V22</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Giới thiệu tính năng Report &amp; Log của Sophos Firewall</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-lo7kj"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-lo7kj "><div class="eb-advance-heading-wrapper eb-advance-heading-lo7kj button-1 undefined" data-id="eb-advance-heading-lo7kj"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Dashboards</span></h2></div></div></div>



<p>Xem thông tin về lưu lượng mạng đi qua firewall và các mối đe dọa bảo mật<strong></strong><strong></strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="974" height="463" src="https://vacif.com/wp-content/uploads/2026/03/image-1.png" alt="" class="wp-image-28979" srcset="https://vacif.com/wp-content/uploads/2026/03/image-1.png 974w, https://vacif.com/wp-content/uploads/2026/03/image-1-300x143.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-1-768x365.png 768w" sizes="auto, (max-width: 974px) 100vw, 974px" /></figure>



<p><strong>Các loại Dashboard chính:</strong></p>



<ul class="wp-block-list">
<li><strong>Traffic dashboard</strong>: Phân loại theo lưu lượng mạng</li>



<li><strong>Security dashboard</strong>:&nbsp; Hoạt động bị chặn và các mối đe dọa: Malware, IPS, Spam, nguồn tấn công.</li>



<li><strong>Executive report</strong>: Thông tin tổng hợp cho người quản lý: Traffic &amp; Threat nổi bật.</li>



<li><strong>User threat quotient (UTQ):</strong> Xếp hạng người dùng dựa trên điểm rủi ro bảo mật.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-z9r4w"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-z9r4w "><div class="eb-advance-heading-wrapper eb-advance-heading-z9r4w button-1 undefined" data-id="eb-advance-heading-z9r4w"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Application &amp; Webs</span></h2></div></div></div>



<p>Xem thông tin về việc sử dụng ứng dụng và Internet trên hệ thống mạng của bạn.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="445" src="https://vacif.com/wp-content/uploads/2026/03/image-3.jpg" alt="" class="wp-image-28981" srcset="https://vacif.com/wp-content/uploads/2026/03/image-3.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-3-300x143.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-3-768x366.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p><strong>Application risk meter</strong> là cách thức mà Firewall sẽ tính điểm dựa trên mức độ rủi ro và số lần truy cập (hits) của từng ứng dụng. Chỉ số rủi ro ứng dụng được xác định dựa trên điểm trung bình của toàn bộ lưu lượng ứng dụng</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="273" height="75" src="https://vacif.com/wp-content/uploads/2026/03/image-2.png" alt="" class="wp-image-28982" style="aspect-ratio:3.6400133824021412;width:336px;height:auto"/></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>User app risks &amp; usage</strong>: Thống kê việc sử dụng các ứng dụng và mức độ rủi ro tương ứng.</li>



<li><strong>Cloud applications usage</strong>: Thống kê việc sử dụng các ứng dụng đám mây</li>



<li><strong>Blocked user apps</strong>: Các lần truy cập ứng dụng bị chặn.</li>



<li><strong>Synchronized applications</strong>: Các ứng dụng được phân loại và đồng bộ từ endpoint lên firewall.</li>



<li><strong>Web risks &amp; usage</strong>: Hoạt động truy cập web trong mạng và các rủi ro liên quan.</li>



<li><strong>Blocked web attempts</strong>: Các lần truy cập web bị chặn</li>



<li><strong>Search engine</strong>: Thống kê hành vi tìm kiếm của người dùn</li>



<li><strong>Web content</strong>: Các kết quả khớp của bộ lọc nội dung và các thông tin liên quan.</li>



<li><strong>Web server usage</strong>: Lưu lượng Application, Web, Internet và FTP.</li>



<li><strong>Web server protection</strong>: Trạng thái bảo mật của các Web Server, bao gồm các cuộc tấn công và nguồn tấn công.</li>



<li><strong>User data transfer</strong>: User traffic</li>



<li><strong>FTP usage</strong>: FTP activity</li>



<li><strong>FTP protection</strong>: Malicious FTP activity</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-01ner"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-01ner "><div class="eb-advance-heading-wrapper eb-advance-heading-01ner button-1 undefined" data-id="eb-advance-heading-01ner"><h2 class="eb-ah-title"><span class="first-title">1.3 &#8211; Networks &amp; Threat</span></h2></div></div></div>



<p>Xem thông tin về việc sử dụng mạng và các mối đe dọa liên quan.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="443" src="https://vacif.com/wp-content/uploads/2026/03/image-4.jpg" alt="" class="wp-image-28983" srcset="https://vacif.com/wp-content/uploads/2026/03/image-4.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-4-300x142.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-4-768x364.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Intrusion attacks</strong>: Các lượt tấn công</li>



<li><strong>Active threat response</strong>: Threat events và các máy bị xâm nhập được phát hiện bởi MDR (Managed Detection and Response) và Sophos X-Ops</li>



<li><strong>Wireless</strong>: Access point và SSID được sử dụng</li>



<li><strong>Security Heartbeat</strong>: Tình trạng sức khỏe của máy trạm trong mạng dựa trên kết nối giữa máy trạm và Firewall.</li>



<li><strong>Zero-day protection</strong>: Bảo vệ nâng cao trước các cuộc tấn công mới.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2x5jk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2x5jk "><div class="eb-advance-heading-wrapper eb-advance-heading-2x5jk button-1 undefined" data-id="eb-advance-heading-2x5jk"><h2 class="eb-ah-title"><span class="first-title">1.4 &#8211; VPN</span></h2></div></div></div>



<p>Xem thông tin về remote user (người dùng kết nối từ xa) vào hệ thống mạng của bạn thông qua IPSEC VPN, SSL VPN và Clientless access</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="450" src="https://vacif.com/wp-content/uploads/2026/03/image-5.jpg" alt="" class="wp-image-28984" srcset="https://vacif.com/wp-content/uploads/2026/03/image-5.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-5-300x144.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-5-768x370.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>VPN</strong>: Lưu lượng phát sinh từ remote users qua IPsec, L2TP hoặc PPTP</li>



<li><strong>SSL VPN</strong>: Lưu lượng phát sinh từ remote users thông qua SSL VPN Client.</li>



<li><strong>Clientless Access</strong>: Lưu lượng phát sinh từ remote users thông qua trình duyệt web.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dlae4"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dlae4 "><div class="eb-advance-heading-wrapper eb-advance-heading-dlae4 button-1 undefined" data-id="eb-advance-heading-dlae4"><h2 class="eb-ah-title"><span class="first-title">1.5 &#8211; Email</span></h2></div></div></div>



<p>Xem thông tin về email traffic (lưu lượng email) trong hệ thống mạng</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="445" src="https://vacif.com/wp-content/uploads/2026/03/image-6.jpg" alt="" class="wp-image-28985" srcset="https://vacif.com/wp-content/uploads/2026/03/image-6.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-6-300x143.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-6-768x365.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Email Usage</strong>: Email traffic trong hệ thống mạng của mình</li>



<li><strong>Email Protection</strong>: Email Traffic bị Virus và Spam trong hệ thống mạng của mình</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-kgyit"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-kgyit "><div class="eb-advance-heading-wrapper eb-advance-heading-kgyit button-1 undefined" data-id="eb-advance-heading-kgyit"><h2 class="eb-ah-title"><span class="first-title">1.6 &#8211; Compliance</span></h2></div></div></div>



<p>Xem thông tin về việc tuân thủ các quy định/quy chuẩn:</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="446" src="https://vacif.com/wp-content/uploads/2026/03/image-7.jpg" alt="" class="wp-image-28986" srcset="https://vacif.com/wp-content/uploads/2026/03/image-7.jpg 934w, https://vacif.com/wp-content/uploads/2026/03/image-7-300x143.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-7-768x367.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></figure>



<p>Các nhóm Quy chuẩn có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>HIPAA</strong>: Security Report tuân thủ chuẩn HIPAA</li>



<li><strong>GLBA:</strong> Security Report tuân thủ chuẩn GLBA</li>



<li><strong>SOX</strong>: Security Report tuân thủ chuẩn SOX</li>



<li><strong>FISMA</strong>: Security Report tuân thủ chuẩn FISMA</li>



<li><strong>PCI</strong>: Security Report tuân thủ chuẩn PCI</li>



<li><strong>NERC CIP v3</strong>: Security Report tuân thủ chuẩn NERC CIP v3</li>



<li><strong>CIPA</strong>: Security Report tuân thủ chuẩn CIPA</li>



<li><strong>Events</strong>: Network Event và các mức độ nghiêm trọng tương ứng</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4fdmh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4fdmh "><div class="eb-advance-heading-wrapper eb-advance-heading-4fdmh button-1 undefined" data-id="eb-advance-heading-4fdmh"><h2 class="eb-ah-title"><span class="first-title">1.7 &#8211; Custom</span></h2></div></div></div>



<p>Tạo báo cáo bao gồm các tiêu chí được chỉ định.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="443" src="https://vacif.com/wp-content/uploads/2026/03/image-8.jpg" alt="" class="wp-image-28987" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x142.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x364.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Các loại <strong>Report</strong> có thể tạo trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Web Report</strong>: Tìm kiếm hoạt động duyệt web hoặc virus. Có thể lọc theo user, domain và các tiêu chí khác</li>



<li><strong>Mail Report</strong>: Tìm kiếm lưu lượng Email, Spam và Virus. Có thể lọc theo protocol, user và các tiêu chí khác.</li>



<li><strong>FTP Report</strong>: Tìm kiếm hoạt động FTP và Virus. Có thể lọc theo kiểu truyền, user, file hoặc source IP</li>



<li><strong>User Report</strong>: Thống kê mức độ sử dụng: ứng dụng rủi ro cao, website không hiệu quả, virus phát hiện. Có thể lọc theo username, source host.</li>



<li><strong>Web Server Report</strong>: Tìm kiếm hoạt động Web Server (time, user, URI) và cả các sự kiện bảo vệ Web Server.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wsam0"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wsam0 "><div class="eb-advance-heading-wrapper eb-advance-heading-wsam0 button-1 undefined" data-id="eb-advance-heading-wsam0"><h2 class="eb-ah-title"><span class="first-title">1.8 &#8211; Log Viewer</span></h2></div></div></div>



<p>Log Viewer hiển thị event logs và được tự động cập nhật khi có event mới (Real-time).</p>



<p>Để truy cập, ở góc phải phía trên Sophos Firewall, nhấn Log viewer</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="130" src="https://vacif.com/wp-content/uploads/2026/03/image-10.jpg" alt="" class="wp-image-28990" srcset="https://vacif.com/wp-content/uploads/2026/03/image-10.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-10-300x42.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-10-768x107.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Cửa sổ Log Viewer mới sẽ xuất hiện, và quản trị viên có thể xem log Realtime ở đây</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="552" src="https://vacif.com/wp-content/uploads/2026/03/image-9.jpg" alt="" class="wp-image-28989" srcset="https://vacif.com/wp-content/uploads/2026/03/image-9.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-9-300x177.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-9-768x453.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Quản trị viên có thể tùy chọn các loại log cụ thể để giám sát như sau:</p>



<ul class="wp-block-list">
<li>Admin</li>



<li>Active Threat Response</li>



<li>Application filter</li>



<li>Authentication</li>



<li>Email</li>



<li>Firewall</li>



<li>IPS</li>



<li>Malware</li>



<li>Security Heartbeat</li>



<li>SSL/TLS inspection</li>



<li>SD-WAN</li>



<li>System</li>



<li>VPN</li>



<li>Web content policy</li>



<li>Web filter</li>



<li>Web server protection</li>



<li>Zero-day protection</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="200" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-3.png" alt="" class="wp-image-28988" srcset="https://vacif.com/wp-content/uploads/2026/03/image-3.png 200w, https://vacif.com/wp-content/uploads/2026/03/image-3-151x300.png 151w" sizes="auto, (max-width: 200px) 100vw, 200px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-mw44a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-mw44a "><div class="eb-advance-heading-wrapper eb-advance-heading-mw44a button-1 undefined" data-id="eb-advance-heading-mw44a"><h2 class="eb-ah-title"><span class="first-title">2. Cách xuất Report trên Sophos Firewall</span></h2></div></div></div>



<p>Trong quá trình quản trị hệ thống, người quản trị cần các file báo cáo tổng hợp phản ánh tình trạng sử dụng hệ thống và các mối đe dọa tiêu biểu. Vì vậy, trong bài hướng dẫn này sẽ lựa chọn <strong>Executive report</strong> để thực hiện việc xuất báo cáo.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="490" src="https://vacif.com/wp-content/uploads/2026/03/image-12.jpg" alt="" class="wp-image-28992" srcset="https://vacif.com/wp-content/uploads/2026/03/image-12.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-12-300x157.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-12-768x402.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>&nbsp;Để xuất Report báo cáo theo lịch trình, chọn <strong>Show Reports Settings</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="483" src="https://vacif.com/wp-content/uploads/2026/03/image-11.jpg" alt="" class="wp-image-28991" srcset="https://vacif.com/wp-content/uploads/2026/03/image-11.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-11-300x155.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-11-768x396.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Chọn <strong>Report Scheduling</strong>, nhấn <strong>Add</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="491" src="https://vacif.com/wp-content/uploads/2026/03/image-13.jpg" alt="" class="wp-image-28993" srcset="https://vacif.com/wp-content/uploads/2026/03/image-13.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-13-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-13-768x403.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Nhập thông tin sau:</p>



<ul class="wp-block-list">
<li><strong>Name:</strong> Đặt tên lịch report.</li>



<li><strong>Description:</strong> Mô tả (không bắt buộc).</li>



<li><strong>To email address:</strong> Địa chỉ email nhận report (có thể nhập nhiều email)</li>



<li><strong>Report type: </strong>Chọn loại report (VD: Report group)</li>



<li><strong>Report group:</strong> Chọn nhóm report phù hợp (VD: Executive Report)</li>



<li><strong>Email frequency: </strong>Chọn Daily hoặc Weekly và mốc thời gian gửi report qua email.</li>
</ul>



<p>Sau khi nhập hoàn tất, nhấn <strong>Save</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="425" src="https://vacif.com/wp-content/uploads/2026/03/image-15.jpg" alt="" class="wp-image-28995" srcset="https://vacif.com/wp-content/uploads/2026/03/image-15.jpg 934w, https://vacif.com/wp-content/uploads/2026/03/image-15-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-15-768x349.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></figure>



<p>Đúng lịch trình cấu hình, Sophos sẽ gửi email bảng báo cáo report về email.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="794" height="473" src="https://vacif.com/wp-content/uploads/2026/03/image-14.jpg" alt="" class="wp-image-28994" srcset="https://vacif.com/wp-content/uploads/2026/03/image-14.jpg 794w, https://vacif.com/wp-content/uploads/2026/03/image-14-300x179.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-14-768x458.jpg 768w" sizes="auto, (max-width: 794px) 100vw, 794px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-theo-doi-xuat-report-tu-sophos-firewall-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] Hướng Dẫn Activate &#038; Renew License Sophos Firewall</title>
		<link>https://vacif.com/moi-nhat-2026-huong-dan-activate-renew-license-sophos-firewall/</link>
					<comments>https://vacif.com/moi-nhat-2026-huong-dan-activate-renew-license-sophos-firewall/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Tue, 03 Mar 2026 04:54:12 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[activate license]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[renew license]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=28952</guid>

					<description><![CDATA[Nếu chưa có tài khoản Sophos Central, tham khảo: https://thegioifirewall.com/sophos-central-huong-dan-tao-tai-khoan-sophos-central-trial/ Đăng nhập Sophos Central bằng tài khoản Super Admin. &#8211; Vào Account → Licensing Firewall licenses &#8211; Chọn&#160;Firewall&#160;licenses&#160; &#8211;&#160;Chọn&#160;Claim&#160;firewall&#160; &#8211;&#160;Nhập&#160;Serial Number&#160;thiết&#160;bị&#160; Sau khi claim thành công, thiết bị sẽ hiển thị trong danh sách quản lý. &#8211; Chọn thiết bị → Apply subscriptions &#8211; Nhập License Key [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 Activate v\u00e0 Renew License Sophos Firewall &quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 Activate v\u00e0 Renew License Sophos Firewall &quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - H\u01b0\u1edbng d\u1eabn Activate License Sophos Firewall &quot;,&quot;text&quot;:&quot;II - H\u01b0\u1edbng d\u1eabn Activate License Sophos Firewall &quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. T\u1ea1o t\u00e0i kho\u1ea3n Sophos Central&quot;,&quot;text&quot;:&quot;1. T\u1ea1o t\u00e0i kho\u1ea3n Sophos Central&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Claim thi\u1ebft b\u1ecb Sophos Firewall&quot;,&quot;text&quot;:&quot;2. Claim thi\u1ebft b\u1ecb Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Apply License cho thi\u1ebft b\u1ecb&quot;,&quot;text&quot;:&quot;3. Apply License cho thi\u1ebft b\u1ecb&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4. \u0110\u1ed3ng b\u1ed9 License v\u1ec1 Firewall&quot;,&quot;text&quot;:&quot;4. \u0110\u1ed3ng b\u1ed9 License v\u1ec1 Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - L\u01b0u \u00fd khi Renew License Sophos Firewall &quot;,&quot;text&quot;:&quot;III - L\u01b0u \u00fd khi Renew License Sophos Firewall &quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 license khi renew:&quot;,&quot;text&quot;:&quot;1. C\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 license khi renew:&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng nh\u1eadn \u0111\u01b0\u1ee3c License Key:&quot;,&quot;text&quot;:&quot;2. Tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng nh\u1eadn \u0111\u01b0\u1ee3c License Key:&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 Activate v\u00e0 Renew License Sophos Firewall &quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-activate-v\u00e0-renew-license-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - H\u01b0\u1edbng d\u1eabn Activate License Sophos Firewall &quot;,&quot;value&quot;:&quot;ii-h\u01b0\u1edbng-d\u1eabn-activate-license-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. T\u1ea1o t\u00e0i kho\u1ea3n Sophos Central&quot;,&quot;value&quot;:&quot;1-t\u1ea1o-t\u00e0i-kho\u1ea3n-sophos-central&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. Claim thi\u1ebft b\u1ecb Sophos Firewall&quot;,&quot;value&quot;:&quot;2-claim-thi\u1ebft-b\u1ecb-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;3. Apply License cho thi\u1ebft b\u1ecb&quot;,&quot;value&quot;:&quot;3-apply-license-cho-thi\u1ebft-b\u1ecb&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;4. \u0110\u1ed3ng b\u1ed9 License v\u1ec1 Firewall&quot;,&quot;value&quot;:&quot;4-\u0111\u1ed3ng-b\u1ed9-license-v\u1ec1-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - L\u01b0u \u00fd khi Renew License Sophos Firewall &quot;,&quot;value&quot;:&quot;iii-l\u01b0u-\u00fd-khi-renew-license-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 license khi renew:&quot;,&quot;value&quot;:&quot;1-c\u01a1-ch\u1ebf-\u0111\u1ed3ng-b\u1ed9-license-khi-renew&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. Tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng nh\u1eadn \u0111\u01b0\u1ee3c License Key:&quot;,&quot;value&quot;:&quot;2-tr\u01b0\u1eddng-h\u1ee3p-kh\u00f4ng-nh\u1eadn-\u0111\u01b0\u1ee3c-license-key&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về Activate và Renew License Sophos Firewall </a><li><a href="#eb-table-content-1">II &#8211; Hướng dẫn Activate License Sophos Firewall </a><li><a href="#eb-table-content-2">1. Tạo tài khoản Sophos Central</a><li><a href="#eb-table-content-3">2. Claim thiết bị Sophos Firewall</a><li><a href="#eb-table-content-4">3. Apply License cho thiết bị</a><li><a href="#eb-table-content-5">4. Đồng bộ License về Firewall</a><li><a href="#eb-table-content-6">III &#8211; Lưu ý khi Renew License Sophos Firewall </a><li><a href="#eb-table-content-7">1. Cơ chế đồng bộ license khi renew:</a><li><a href="#eb-table-content-8">2. Trường hợp không nhận được License Key:</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về Activate và Renew License Sophos Firewall </span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-3m3jy"><div class="eb-parent-wrapper eb-parent-eb-text-3m3jy "><div class="eb-text-wrapper eb-text-3m3jy" data-id="eb-text-3m3jy"><p class="eb-text">Bài viết hướng dẫn cách activate và renew license Sophos Firewall thông qua Sophos Central.<br>Sophos Central là nền tảng quản lý tập trung cho phép quản lý thiết bị, license và đồng bộ trạng thái license từ cloud về firewall.</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-v3lxg"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-v3lxg "><div class="eb-advance-heading-wrapper eb-advance-heading-v3lxg button-1 undefined" data-id="eb-advance-heading-v3lxg"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Hướng dẫn Activate License Sophos Firewall </span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Tạo tài khoản Sophos Central</span></h2></div></div></div>



<p>Nếu chưa có tài khoản Sophos Central, tham khảo: <a href="https://thegioifirewall.com/sophos-central-huong-dan-tao-tai-khoan-sophos-central-trial/"><em><strong>https://thegioifirewall.com/sophos-central-huong-dan-tao-tai-khoan-sophos-central-trial/</strong></em></a></p>



<p>Đăng nhập Sophos Central bằng tài khoản Super Admin.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-3wm20"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-3wm20 "><div class="eb-advance-heading-wrapper eb-advance-heading-3wm20 button-1 undefined" data-id="eb-advance-heading-3wm20"><h2 class="eb-ah-title"><span class="first-title">2. Claim thiết bị Sophos Firewall</span></h2></div></div></div>



<p>&#8211; Vào Account → Licensing Firewall licenses</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-4.png" alt="" class="wp-image-29011" srcset="https://vacif.com/wp-content/uploads/2026/03/image-4.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-4-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-4-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>&#8211; Chọn&nbsp;Firewall&nbsp;licenses&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-5.png" alt="" class="wp-image-29013" srcset="https://vacif.com/wp-content/uploads/2026/03/image-5.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-5-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-5-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>&#8211;&nbsp;Chọn&nbsp;Claim&nbsp;firewall&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-6.png" alt="" class="wp-image-29014" srcset="https://vacif.com/wp-content/uploads/2026/03/image-6.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-6-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-6-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>&#8211;&nbsp;Nhập&nbsp;Serial Number&nbsp;thiết&nbsp;bị&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-7.png" alt="" class="wp-image-29012" srcset="https://vacif.com/wp-content/uploads/2026/03/image-7.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-7-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-7-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>Sau khi claim thành công, thiết bị sẽ hiển thị trong danh sách quản lý.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-lrwd4"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-lrwd4 "><div class="eb-advance-heading-wrapper eb-advance-heading-lrwd4 button-1 undefined" data-id="eb-advance-heading-lrwd4"><h2 class="eb-ah-title"><span class="first-title">3. Apply License cho thiết bị</span></h2></div></div></div>



<p>&#8211; Chọn thiết bị → Apply subscriptions</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-2.jpg" alt="" class="wp-image-28961" srcset="https://vacif.com/wp-content/uploads/2026/03/image-2.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-2-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-2-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p>&#8211; Nhập License Key</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-1.jpg" alt="" class="wp-image-28960" srcset="https://vacif.com/wp-content/uploads/2026/03/image-1.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-1-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-1-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p>&#8211; Preview subscription → Apply license</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeqj6"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeqj6 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeqj6 button-1 undefined" data-id="eb-advance-heading-qeqj6"><h2 class="eb-ah-title"><span class="first-title">4. Đồng bộ License về Firewall</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-y512i"><div class="eb-parent-wrapper eb-parent-eb-text-y512i "><div class="eb-text-wrapper eb-text-y512i" data-id="eb-text-y512i"><p class="eb-text">&#8211; Vào Sophos Firewall → Administrator → Device access<br>&#8211; Nhấn Synchronize<br><br><img loading="lazy" decoding="async" width="575" height="265" src="data:image/png;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwgHBgoICAgLCgoLDhgQDg0NDh0VFhEYIx8lJCIfIiEmKzcvJik0KSEiMEExNDk7Pj4+JS5ESUM8SDc9Pjv/2wBDAQoLCw4NDhwQEBw7KCIoOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozv/wAARCAGNA18DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwDkvFWu3+q69ema6lMMc7pFEHIRFBIGB07Vh1Y1H/kKXn/XxJ/6Ea0fCC6W3ivTxrWwWJk/eeZ93ODt3e27GaYGLvX+8PzoJA5JAr2GeDxU9xMNN0zwhcxhmMMcSKWZO3GeuKwZJYvCHgrT9Wi0uzl1bV7iUyyXUAcQgE5RVPT0/OgR57kYzkY9aQMp6MD+Neu6Rp+m61deFPEn9mWtvNeyzQXcEcYEUhCPhtvTqv61bsdP1W71C/t/E/hrSbXQxHKftKwojqAflIIJOcUAeMZB4zRkHuK9Fv8AwlPrngbw3JpYsYmWKXzJJpFiaQE/KScc9K3tQ0LS7bxHqGp3Wn286aRo0UyWwQeW8nz8kDg/d/WgDxsMD0IP0oLKOrAfjXomkXkPjzRNcttS0uwgurK0Nza3NpAI2QjPyn1HH61uGOQ2dj/wiMHhaTTzbJzeYMxfvuz3oA8gBB6HNKqs5woJPoK3fGaarH4gaPWLG1s7pYlGy0QLGy84YY69/wAqxUyIXx1YhaqC5mTJ2QfZ5v8Anm1I0UiLuZCB609rWQMVUbsde1Nxtgb1L4/KtXTSvdNf16EKd9mn/XqR19BfDP8A5J9pf+7J/wCjGr59r6C+Gf8AyT7S/wDdk/8ARjVganU0VQ1fV7fRbRbi4SRwzhAsYy3Qkn6AAk+wq8CGAKnIIyCO9IYtFVpb6KK9trQhme5DlGXGBtAJz+dWe+O/pQAUU1mwjMqlyoPyqRkn0+tNt5Gmto5ZIWgZkDNG5GU9jjjigCSiobqZ4LcyxW73LAjEcZGWycZGTjjrUpIBGSOenvQAtFQ/a4ftv2PcfP8AK83bj+HOM5+tTd8d/SgAooHPQg84qmuorPaR3NnDJco8vl4TAK/NtZjnHAINAFyikOBjkc9PeloAKKQHIyOQe9LQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUVyUHxK0Ca7FuwuYVyR5siAKMfQ57V0EWq2stvZXALLHfDMRfAx8pbn04FbToVYfFGxnGrTn8LLtFUU1ixfYGnVDJIyIGPUq23PHbI4NSrqFm7BVuY2YhSADz82Qv54P5Vm4SXQrmj3LNFVZ9RtLW5FvPL5b+UZcsDgKDg8/jTlv7RrM3gnXyF6v6dsY65z260csrXsPmXcsUVVj1KxlQyJdRlQMk56c4/nxUL61ZxLFvfEkrBVjU7jy+0dOOv8jTUJPoLmj3NCiqZ1bTwrt9qQhGCnGTyemB36Hp6GrasrqGUhlYZBHcVLi1uhpp7C0VDcXKW3lbwx82VY1x6npTXv7SO6Fq9wizMMhCf8+ho5WwuixRVWDUrK5jlkhuUdIV3SEZ+Uc8/Tg0PqNrHLsMyYClnbcMKMA8/gafJK9rC5lvctUVUXVLF0Di6jwSBycHJbaBg988Uv9p2PmrF9qTe2cDPpnv8Agfyo5Jdg5o9y1RUVvcw3cCz28gkjb7rDoaS7uo7K1e4lyUTGce5A/rSs726jurXJqKpPq1lHJMrzACHaCw5BLAkAY69DSPrNhEWEtwsYVtoY8h/lDZGO2GHNVyS7C549y9RSAggEEEHkEd6jubqG0i82eQImcZwTz9BUpN6DvYloqjLrNhFPHCbhWZz/AA8hRtLZJ6dBn8RSf23p7KxiuUkZUZtoOM4GTyeOnP05qvZz7C549y/RVeG/tLi4e3inV5UzuQdsHB/I9ajTV9Ne+Nil/btdAlTAJBvyOoxS5Jdg5l3LMn3R9aoQtPcmVbi08gK37pt4bevvjoeOnuKvyfd/GqsF1Hc7/Lz8hwcipKPmnUf+Qpef9fEn/oRp2my2UGoQy6javdWik+ZCj7C4x2PbnFN1H/kKXn/XxJ/6Ear0xHa6d4q8IaNepqGmeE7hLyHJheS9JVSRjJH41XtvGtteaS+leJdKOo24uHuIXhl8qSFmJJA9sk/nXJUUAdunxDhg1fR2tNJNtpOkB/KtFly7llILFj35/U1yV9fzXt1cStNN5c0rOI2kJABJOKq0UAbeta/Fq3hzRdJW2aNtLjdGkZgRJuI6Dt0rcl+I7f8ACQ/2hFp2+zmsUsrq0mf/AFqjPII6dT+tcRRQB10vi/StP0W+0/w1okmnyagnlz3E9wZGCf3V/M/nUcereBFjQS+Ert3CgMftpG4965WigDa8V+Iz4m1dbwWwtYYoVghhDbiqL0ye55rMVJDAhjUk7i3Hb0qCirhJRvcmSbJ1S5TO1WGTk4pkg2IkZ6jJI9M1HRTc1ayv9/8AwBKLvdhX0F8M/wDkn2l/7sn/AKMavn2voL4Z/wDJPtL/AN2T/wBGNWZZJqE8134lZI9Mlv7extzG6xuigSSDnO4jPyY/76qpFdTv4ZttNuvMt3hvo7G7BfDCPPy5YH+JSgyD3NdVBawWxlMMYQzSGSQj+Jj1J/IVHLptlP8AafNtkf7WoWcMMiQAYGR7UXCxjNp1jpvi7SY7KNLffFOWgj4U4C/Nj17Z71lRadbDwfZ6gqMt4bhF+0hyJArTbSobrjaSMV1NromnWUyTwW2Jkztkd2dgCMEZYk49qlGmWQskshbr9nRgyx5OAQ24H8+adxWMV7K20vXZ7exhW3hm0yR5I4+FZlYANj1wTzVWztIb+fw7DdKZYv7JZmjYna5/d/eHf8a6iS0t5bj7Q8QaXyjFuPXYTkj9BTItPtIHgeKBVa2i8mIjPyJxwP8AvkflSuOxzF5EtlpmuWVvmO3gu7cxRg8R7jGSB6DJJx71a1fTvM1G+vJrCLVrfYqlVmCzWmF5Cg8c/e4IPP0rcl02zmE4kt1YXLK0uSfnK42k/TA/KobvQtMv52nuLXdI4CyFXZRIB0DAEBvxp3FYy7K20678VW17FCsu/TEmjlkXLn5sBifXFVtLg0+y8JTalcRytLKJUkljY+aQZSoVWz8ozj0xXRyadZy3FvcNABLbDETKSu0enHUcDg8Uo06zWwawFuhtWDAxEZUgkk/qTSuOxzltZ/Y/EWnwf2XbadFdQzJLDHNvMyhQfnGAOPXk81DZ2lva+GbB7eFImk1VA5QY3YnIGfw4ro7XRNNs50uIbb99HnZI8jOwBGCMsSce1OTR9PQvttgA8wnK7jjzAchgM4BzzxTuKxl2unWWtX+qyapCtxLDcmBFc/6mMKpXb/dzknI5/KqFon9rN4eS+driMx3QJZv9cqkBS3rkAH3rob3RNN1CczXNtvkZdrMrsm9fRsEbh7GrH2O282CUQoHtlKQkDGwEAEAfQClcLGZosEdlq+rWNsvl20ZikjiH3ULKd20dgcZxW1USW0MdxLcJGFlm2+Y3dtvA/LNS0igooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACk68UtFAHF2/wAMNHivfPlubmePJJhfABznuOeK6RNGtVtLC1b95FYjCLIA27ClRn860KK3niKtT4pXMo0acPhRk/2BCoZIp3jikJEiKi4Zd5cAf3cFiOO1Oh0C2hvRdCR2Ikd9hxg7ug+i84+prUoqPaz7lezj2M2bRLZ1VID9mRUK7I1GM7gwP1BUH3ol01xp80aSmW4eUT+YcL84IIPQgYwOK0qKPaS7hyRMOHQZnhLXF2ySyM5lCBW3AvvAzjg/T1qf+wkBwl1IsbMjSJtB3lXLDnt1xWrRTdab6iVOJjL4ciSBoUnwMBUJiUlVGcDPXPPXjp9a1oY/Jgji3tJsULvc5ZsDqfen0VMpyluVGCjsVr6zN5EirMYXjkWRXChsEexqpLoonZjPdPIkhVpU2hRI4GAc9R24HpWpRQpyitAcE9zL0iwurd7iS9YP5iRxqpIb5VB64AHemf8ACOW32QW7TSsBv+Y4yc4x/wB8hVA+la9FP2sr3QvZxtYyH8OwSogkmbcpclkQLuLDg49sAj3FC+HrdJFZZW2hFVgyAliq4DZ7HvWvRT9rPuL2cOxHBEILeKFSSI0CAnvgYqO9tEvrOS1kJCSYzgZ6EH+lWKKzu07l2VrGVP4ftpJmmhIgYsrKEjG0EKVPHfIao30Jlmj+zXJhQIyuQi5AKIuAMY6Ln2rZorRVZrqR7OPYZDEsEMcMeQkahVz6AYFV9Qsft8KR+c8QVtxwMhuCMEd+ufqKt0h+6cZzjtWak07ltJqxkL4djSFbdbyUQLzs2ry3l+XnP05x61NPosU6OrTSAOSTgD/nn5f8uaghuLmOMgNLjIDTMjN2P8J5BzjOOOaR72/mjmVcrIMqUSM/u/lBzu78nGK09pNvcjkj2L0OnRwTxyiRiUMpAIH/AC0IJ/LFSLYWi3z3620YunQI0wX5io7Zqm11fI4Qrkq5APlH9783T/Z471YsJ55vOE4OVbg7Co/DNQ5S7lJIsyfdH1rJ0jrcf7w/rWtJ90fWsnSOtx/vD+tSUfPF4nmazcoeA104/wDHzUHmp2gTHuW/xqzcf8h2f/r7f/0M1VhbZKjZAwwOSMgfhTEO81f+eEf5t/jSean/ADwj/Nv8auebaMxMrCRto6kkDk5AJGfSmF7RYBtCNIEOMr3wOv45oArean/PCP8ANv8AGjzU/wCeEf5t/jVrzrePfsERVlAVdh6ZH3vfrVOXZ5r+X9zcdv07UAO81P8AnhH+bf40ean/ADwj/Nv8ajooAk81P+eEf5t/jR5qf88I/wA2/wAajooAk81P+eEf5t/jR5qf88I/zb/Go6KAJPNT/nhH+bf404kqoZrVQp6E7sfzqIHBB681b3RyNKRPkyqcIwxg+/atqVOM07vUzqTcbWRXkC7UdV27wcgHjg1798M/+SfaX/uyf+jGrwF/9RD/AMC/nXv3wz/5J9pf+7J/6MasTQ6miiikMKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAM0gAXOABk5OO5paKACiiigBkn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB873zFNXunHVbmQj/AL7NQ7oP+ecg9g4/wqTUf+Qpef8AXxJ/6EaXTrCfVL+Gyt9glmOFMjhVHGSST0FMRFmD+5J/32P8KMwf3JP++x/hWtF4U1KSPezW8JEnlskkuChJABb0B3DH4+lQvoF1FZG9kntVtgdpk83PzbypXAGc8Zxjpg0AZ+YP7kn/AH2P8KMwf3JP++x/hWtZ+FNQvoY57eazMMg+SRpwoJ3EbcHndxnGOhHrUV94du9Ps7q6mmtWjtZkhkCS5bcyhgAMc8E/TBoAzswf3JP++x/hRmD+5J/32P8ACta58KalaW7z3D2sSLEJVDTDMi7Q2VHfAYD607/hEdRDlWnskPUFrkYZNyr5g/2fmHPoD6UAY+YP7kn/AH2P8KMwf3JP++x/hWpceFtSt1kY+Q/lH96BKAYgRkMwOMCpT4P1MMyebZFkcq4FwPlUEguf9jjOfQj1oAxswf3JP++x/hRmD+5J/wB9j/CrV9pU+nxl5ZYHHmCP91Ju5KK+fphhz65FUaAJMwf3JP8Avsf4UZg/uSf99j/Co6KAHyOGCqq7VUcAnJr3/wCGf/JPtL/3ZP8A0Y1eaD4R+KCAd1hgjP8Ax8H/AOJr1jwZpN1oXhOx0y88vz4A+/y23Ly5IwfoaBm5RRg0YPpSAKKMH0owfSgAoowfSjB9KACijB9KMH0oAKKMH0owfSgAoowfSjpQAUUmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRmgBsn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB866j/yFLz/r4k/9CNFjYT6ndraW6o0jhiA7BVwoJJJPA4Bo1H/kKXn/AF8Sf+hGn6XqDaXqCXawpMVV0MbkgMGUqeRz0JpiJpfDmpRbQtp5xcjYLf8Ae7wV3BlK5BXHeoE0nUZI0lj066ZHbajLAxDEdgcdeD+Vbdp42uLNI4Y9Ntfs8G0QRbm/dADAwSck9SSfU1bfxyv9ns625OozYWQnKxqo8zGPm5/1hxwDxzmgDmG0q/UOz6fcgRuI3Jhb5WPRTx15HHuKuHR9c/swrNbXEVlA7tslBVQ4UFuPUjFX08b3yxRD7LEZYYxCkvmOCEGzIwDySYx83UZOO1Obxzd7pHisLaNmJKkFjtJQKSR0YnANAGPc6fq8kskt3ZXjSRxqztJC2VQDCk5HTAx+FUNo9BXRHxdIFvUTToQl4p3o00jqGO7LYYn++cdMfnnnhxQAm0ego2r6D8qWigAwB2ooooAKUfeH1FJSj7w+ooA+mZLZ5pbeZbqWIRAHy0xtf13evHHt1q/H90VAn3F/3R/Kp4/uikM8N8R3VyviXU1W4mVRdSYAkIA+Y1m/bLr/AJ+p/wDv43+NXfEn/Izan/19Sf8AoRrMr7OlFezjp0R8xUk+d6k32y6/5+p/+/jf40fbLr/n6n/7+N/jUNaOkWA1D7bGI2kmjtTJCqnkuGUdO/BPFVLlirtCjzSdkyp9suv+fqf/AL+N/jR9suv+fqf/AL+N/jW/J4agNtFIZXjcxxiQIoKwMVBLSZbIGSenofpUs/hOxhZlOoTBi2xA0QGG2ucnJ+78nb1rH29L+kaeyqHN/bLr/n6n/wC/jf40fbLr/n6n/wC/jf41048J2aROXunCmNZA7KA/AYnC574xz+BqtP4Yto7C5uoruWTyojMuEXCgBCFfnhjv7ccUKvRbt+g3Sqowftl1/wA/U/8A38b/ABo+2XX/AD9T/wDfxv8AGoaK6OVdjDmfcm+2XX/P1P8A9/G/xr1zwCzSeD7V5GLsXkyzHJ+8a8dr2H4ff8ibaf8AXST/ANDNeXmiSoL1/wAzvwDbqv0OkwPQflRgeg/Kiqmq3Mlnp0k8bojKVAZxkLlgCT+dfPRV2kj2W7K5bwPQflRgeg/KsNNelWRbfyVunLsqyxtsWUBgAV69zzz2pf8AhIt+yRIMRuCo3vtG4MinJxwAWIJ9q19hPsR7WBt4HoPyowPQflWZa6z9q1FbMW4wV5kWQMM7d3HqvbPrVZPEqyO6JBGMPhXebahGGOSSOD8p4pexn2D2kO5uYHoPyowPQflWNL4g8tHZbdGxL5ar5w3DkjLjHyjjjrnIpr+I9vmj7IAyKrBWlGSDjJOARxnp19qPY1Owe1h3NvA9B+VGB6D8qZBKs9vHMv3ZEDDHuM0+stjQMDHQflRgeg/Kl7UlADZHjijaSRlREBZmbgADqab50HlxyeYmyUgRtnhs9MfWotQtDfWbWwlMSuy72UZO0HJA+uKyz4bkzGPtauseAjSR5dFBYgAg4H3ueOwrWEYNe87ESlJPRG27RxruYgDIHT1OKdgegrEXw0qbDDMsZUjcVTGQAnHX1Qn/AIFUsWi/ZbCe0jmRTNHGpJTjKgAkg+tDhT6S/ASlPqjWwPQUxHikLhGVijbWx2OM4/UViQ+GwYBi8DMBsWZF5UYcEA5/2x/3zVmHRpbezeJJIY5DcpcLsiIjUrt4xnODt/Whwpr7X4ApTfQ1cD0FGB6CsE+G5SMfbFGYlRjsPzkEHnJ4HHQetXtM0pdPd5Cyu7IqA4PygZyAT2yf0olGCV1L8AUpN6o0MD0H5UYHoPyoorI0DA9B+VGB6D8qKKADA9B+VGB6D8qKKADA9B+VGB6D8qzL+6u7a9ISdBCLWScp5WWymOM5759Krr4hkyC1nmPOCwl+Y/PsyFx1z2zWqpSaujN1Ip2Zt4HoPyowPQflVLStROp27TGDysEY+bcCCAf681drOUXF2ZaaaugwPQflRgeg/KiikMABnoPyowPQflSjqKSgAwPQflRgeg/Kufk8Q3Ftcuk8KsgnmEZQffRAePZgQM+xp/8Ab8z3KxLDCFyFysm7c3mbTtOOV569a29hMy9rA3cD0H5UYHoPyrAs9euPKiW5WJpZERyzSCNBld2M469MClk8Rs07RQwx7Vk2mRn6rh+nHXKdPej2E77B7WFjewPQflRgeg/KsSLxE0nlotsHeQqqgygHJKrlhj5RlsjrkCp5NbEVpZXDQALcnDZk/wBXzj0yefb8qTozXQaqwfU1MD0H5UYHoPyrn38SXDpugs0UZf8A1snXCMwHA4OV6e9Sxa/IWw1usgBBdlk4UEovy8fNy/tT9hU7C9rA28D0H5UYHoPyrC/4SYbN7WyBQVJInztDAnnjORjkc4zW7UTpyh8RcZxlsBA9B+VGB6D8qU0lQUGB6D8qMD0H5UUUAGB6D8qMD0H5VmarqEtlc26rLEkTDL5AZz8wHAyDjntk5xxWW/iHUfJWNYoRdMrOmVO2RfMVVxz7kH3wa2jRlJJoylVjF2Z0+B6D8qMD0H5VzR8Q31zORZx4ikdRCBDvcjY5ORkfxJj2FdFCZGgjaZQkpUF1U5AbHIH41M6cofEVGalsPwPQflRgeg/KiisywwPQflRgccD8qKX0oATA9B+VGB6D8qKKADA9B+VGB6D8qKxdQ1m5stQmh2IYAYUR9pJV3PIPsRnHuPerhBzdkTKSirs2sD0H5UYHoPyrnpvEtw1uZLe0jTIfBlk9EZh268cipI9dnibyZ4kllV9pIbbu5UAKMfMctk9OKv2EyPbQN3A9B+VGB6D8qy9N1xdSujbpbMmFLli3YYH/AKFuX/gNalZyg4O0i4yUldBgeg/KjA9B+VFFSUGBjoPyowPQflS9qSgAwPQflRgeg/KiigAwPQflRgeg/KuYg8T3fl27TQKxRHa5CKRu+UtHt9MgZPWrv/CQlTGHtAu9W/5bDkjOAOO+OpxW7w9RdDJVoM2sD0H5UYHoPyrD/wCEnjHk/wCj7y+Q6xuSyn5sAAgZ+6aRPEu6RI/siuxYAmOYMuCFPBxyfn6expewqdh+1h3N3A9B+VGB6D8qpabqQ1ATfuxG0L7Sofd9DnGPyzV2spRcXZlppq6DA9B+VIQPQUtB6UhkknT8aydI63H+8P61rSdPxrJ0jrcf7w/rSGfOuo/8hS8/6+JP/QjVerN+C2rXajqbmQD/AL7NSf2VMWwJI8FtoPzctnGOnr+FMRSoq19gkA+aSNWABdcnKA9CePp09RStp0q78Oj7JDH8oY5b06e/egCpRVpbAtMIluICx3DhjwR1HT9elVjwTg5HqO9ACUUUUAFFFFABRRRQAUo+8PqKSlH3h9RQB9Qp9xf90fyqeP7oqBPuL/uj+VTocKKQzwjxJ/yM2p/9fUn/AKEazK9V1D4aWeoajc3r6nOjXErSFRGuBk5xVf8A4VRY/wDQVuP+/a19LTzDDqCTfTszwp4Ks5NpHmVFem/8Kosf+grcf9+lo/4VRY/9BW4/79LV/wBpYbv+DJ+o1ux5lRXpv/CqLH/oK3H/AH6Wj/hVFj/0Fbj/AL9LR/aWG7/gw+o1+x5lVhL66jtHtEnZYHPzIOh/zgce1ei/8Kosf+grcf8AfpaP+FUWP/QVuP8Av0tDzHDPd/gNYKuun4nmVFem/wDCqLH/AKCtx/36Wj/hVFj/ANBW4/79LR/aWG7/AIMX1Gt2PMq9h+H3/Im2n/XST/0M1l/8Kosf+grcf9+lrqdC0VdC0qPT4rhpkjZmDuuDyc9q4cfi6VakowetzrwmGqUqnNJdC/QQGBDAMD1BGRS7G9R+VGxvUflXjHpjdifL8i/L93gfL9PSgopBBVSD1BFO2N6j8qNjeo/KgBoRQQwVQQMA45A9KTy48EeWmCckbRyfWn7G9R+VGxvUflRcBhjQ7sxqd33sqOfr60GOM5zGh3dcqOfrT9jeo/KjY3qPyouAlFLsb1H5UbG9R+VAB2pKXY3qPyo2N6j8qAEopdjeo/KjY3qPyoAzdQ0+6ur2Ga3uBCEQqSWPGc8hfX3z+dZreG7iSFRLJHI4Rl+eRiByh447lTn610mxvUflRsb1H5VrGtOKsjN0oy3MI6JeAPILwrLzsKO3ygh8gDp/Ev8A3zUVhpl+0kVwR9nWOfcIpJHOFwucA/Q9SOtdFsb1H5UbG9R+VP28rC9lESil2N6j8qNjeo/KsTUSil2N6j8qNjeo/KgBKKXY3qPyo2N6j8qAEopdjeo/KjY3qPyoAQgHqAfwpNq/3R+VO2N6j8qNjeo/KgBqqqjCqFGc4AxS0uxvUflRsb1H5UAJRS7G9R+VGxvUflQADqKSl2t6j8qNjeo/KgBu1f7o/KgRoAAEUBemFHH0p2xvUflRsb1H5UANKIRgopGc8qKTy4+f3acnJ+Ucmn7G9R+VGxvUflRcBuxASQignGTj06UFFOMop2nIyOn0p2xvUflRsb1H5UAN8tOfkXk5Pyjk+v1oCIvRFH0Ap2xvUflRsb1H5UAVoLC1ti5jhGXYMxYljkdOv1NWKXY3qPyo2N6j8qbbe4JJbAaSl2t6j8qNjeo/KkAlFLsb1H5UbG9R+VADSqsQWVSVOQSM4+lG1ePlHHTinbG9R+VGxvUflQA3ao/hA/Clpdjeo/KjY3qPyoASil2N6j8qNjeo/KgBKX0o2N6j8qNjeo/KgBKKXY3qPyo2N6j8qAEowD2B/Cl2N6j8qNjeo/KgBnlx8/u15OT8o5PrS7FJB2rkHIOOhp2xvUflRsb1H5UAIAB0AH0FFLsb1H5UbG9R+VACUUuxvUflRsb1H5UAHakpdjeo/KjY3qPyoASil2N6j8qNjeo/KgBu1f7o/KkEcYxiNBtGBhRwPan7G9R+VGxvUflRcBnlR4A8tBgYGFAwPb0qK3sra1QpDCAC275iWOemcn2qxsb1H5UbG9R+VO7FZDVVVztULk5OBjJpaXY3qPyo2N6j8qQxKD0pdjeo/KjYfUflQA+Tp+NZOkdbj/eH9a1nOR+NZOkdbj/eH9aQz52vyV1a7YdRcyEf99mlXUrtZnlErF3YFsknuePpyeKbqP8AyFLz/r4k/wDQjVvw7qEGla3Fe3G/y40kHydclGAwe3JHPbrTEVGvZGQrsQEhVZgPmYL0B/IflS/b5sOPly8hlyMjDH8cdu9dcNe8MXGpQ6lcK4lhIIDwM7vhIwu5s8srK53HrnNMOr+EZJoJDZQ8szSNLAxYMQ2S2Bhskgjrj0FAHJm9fzVkSKKNgWJ2r1LDBzVeum0u78LwnU/t0ZlSSVvsytb8hMHaRjO05xkZHHr0rRsdd8Kw6kl4LSC2eKfcrCzLL5QlJAC54cpt+b2oA4ilAJ6AnvwK6jSpvD0GgibVIYZnkuZg0axkzuuE2YbPyAEt168irw17wxBbXNvHESJgd32a3aJX+WUKAM8EB0BPc80AcTg4JwcDqccUldnHq3hVJbiOSKJ4ZHDQrHaNGiYEm3zBk7yNyZOOfeqGsXvhy40eWPT7eOC6+0bo/LhYZXJzlm6DHQD6Y70Ac3RRRQAUo+8PqKSlH3h9RQB9Qp9xf90fyqdPuCoE+4v+6P5VOn3BSGRG6txL5RmQODgqT39KlxWa1xAg1CCUhneVtsWMs2VGMCoZZLlJTHLOscqLGIyzsMnAyQoHzc5BpiubHSkUh1DKQVIyCO9UA8/2trTc+IS0pbnlSPlGfqT/AN81FFMpVPtdxLEfJjMW1iCxI5OP4jnjFAGrijFZfmzG/ZWmWOUT7VQu2SnptxggjvVu4Vn1CBAzhfLdtqsQCQVxmgCzikdljUs5CqOpNY8M900ZaOYNceU5kj3Mzbsf3SMKQf8AJokuFDSC0uJZEEAY5YnDbwD17+tAXNnGKOtZcr7ruaHzGlaQuoCSMCo2ngr6e49qLUjbGyPK8cVmrhUc8tk5+p7YoC5qHjrgCkVlYsFIJU4I9DWFJIZoJ08wtEIkkO2Vnwd3OT646gVbab98yyTOtr55BcORxsUqN3YE5oC5p4oxWZbh7maKN5ZjCUlKEOVLKGAUk/SpfOnOhpNubzCi7mA+YDPJ+uM0AXcqWK5G4DJHpS9PxrHeULJctZys8WIgzlyQq5bdhuT/AIZpy4aS3eSYPEtzhSkjEL8h43Hrz/PFAXNViFUsxAUDJJ7UKyvnawOOuO1Yxu5GZ2jdwXhlLKZCzKQOMjGFPsKldyPNLSiMGZc72KB/3Y4LDp/9aiwXNXFGKis5PNs4pMONy/xnJ/PvU1IYmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAMfoPrWVpHW4/3h/WtaToPrWTpHW4/wB4f1oA+ddR/wCQpef9fEn/AKEal0jTxqmoraGQxbo5H3AZ+6hbH44xUWo/8hS8/wCviT/0I1HBPNbSiW3keOQAjchwQCMH9CRTEdGnga8JlR9QsxKpCKqliDJ5ioVJxxguvPTmqqeEb2WVFju7NkcBll8wqmDIY88gfxKaoprmrxSNImo3KuxJZt55JIJP4lVP4Cki1vVreBbeLULiOJX3qgfgHOc4+vNAGu/gm9WKImeGNmlMJaVmVWcsFRVG3OWz3GKqXvha+sXtY5JbdpLmdLfYjnMbsqsobj0YdM1WHiHWhI0g1S63sCCfMPQ9f5D6YqJNWvhcQTSXLzGCZJlWRiRuUAKT+AA+lAGuvgjUJCpjvLF1kkEUbh2xI+XBUfL2MbZz6e9C+B9WlkVYZbSZWIAkSX5cnbtB44J3jA9j6Vm3XiDV7y5NxNqE5fzBIuHICMCSMemNx/M1E2r6k7OzX8+XkSRsPjLL908dx29KANceCb7JJvbHaT8hEjHfhdzYGOMLng46VJc+CLiOTy4LyBwJ3gEkhKiSQOUVVGCQTtPXjjrWLJrWqSsWfUJySSfv46rtPT/Z4+lSf8JDrW93/tS63OpVj5nUHk/r360AP1bQLrR4Y5Z5oJN7+WyxMSY22K+GyB/CwPGay6nnvbu6XbcXMsq7t2HbPO0Ln64AH0FQUAFKPvD6ikpR94fUUAfSk88sd7axq2EZRuHrWon3BWPdf8hGz/3VrYT7opDF3AfxD86Ny/3h+dOj/wBWKdQBHuX+8Pzo3D+8PzqSigCPcv8AeH50bl/vD86kooAiYqylSRhhg81DBbQwOZBI7uRt3SSbiB6CrdFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/AHh+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/wB4fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/AHh+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/wB4fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/AHh+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/wB4fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8PzoBB6EH8akpsnQfUUARyfdH1rJ0jrcf7w/rWtJ90fWsnSOtx/vD+tAHzrqP/ACFLz/r4k/8AQjVjQr6HTtZt7i5DNbZMdwFGSY2BVsD1wTVfUf8AkKXn/XxJ/wChGn6Vp8mrata6fFw9xIEzjO0dz+AyaYjsZfFvh28KLPZ8Nu3+ZDuRdnyQEr3/AHec8cE1ma/rGhahoyQ2kKrPGkccKC3KtCA7lvnJ+ZSpUAdqZdeCLuG9uYIrqLakmy3EwZXn/d+aMAAgfLnqeoxU9t4DmYzedexyCKTyv9HJ/wBYDhlJYDGODkAg5oA5Kiuht/Bl9c3zWMV5aNcRjEq/PiN+MITtxnnr061NP4NMdqJ01CEoqLJNM4YJErRq2MAEk5cDj17UAcxRXSSeBtRhdY5ruyjlLAOjSMNgLMoYnGMEoehz0rD1Cyl06/ms5uZIW2kgEZ/AgGgCvRRRQAUUUUAFKPvD6ikpR94fUUAfSF1/yEbP/dWtiP7orHuv+QjZ/wC6tbEf3RSGSR/6tfpSkgAknAHUmkj/ANWv0qO7hNxZzQjGZI2UbunIxQBLuUkDcMkZAz2oJAxk9elYa6NdxyCQSqxSPyVAcqTEGBC57EjOT9KV9L1J9n+kDzEB2ymVjs+QrjGOeT97rQBt5GcZ59KWs/TrOe2d3nfcWQKMtuK4LHGfTmtCgAooooAKKKKACiiigApjTRI6xvIiuwyqlgCfpT6w9V0m6u9SFxbxw4KBWeRs8DP8JB554II96ANeO6t5s+VPG+Bk7XBxTlljfbtkVt3TB61gt4dnTT7WGCZRKq+VOxUDMTABwNoGegxmpbPQ57W/gn8791HNM/lbhtRWzt2jHXnnmgDcooooAKKKKACiiigAooooAKT60tIeeBQAtFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUVkatrn9l6vpdm8O6K/d0eXP+qIxt49CSB+NVYvFsDX+pQSW8nlWc0cEJjUu9w7BshVHoVI/A0AdDRXP3/jCwttPe5gjnnkWB5TGsLZj25H7zj5fmBHPoatvr9qtm0oyZBI0AXBx5gQvjPpgdaANWisS18U2M72sMgkSWdYwzBCY0kdQwQt68/wAqtz6zawakunlZnmIVnMcRZYwxIUsR0BINAGhRWFf+KrO10xLyFWl8yJZ0UqRlC6oT9fm6d6efFWnqi/u7szF2Q2wt281SoDElfTBB988UAbVFZT+IrFLmSHbcMsQO+ZYWMasF3FS3rj/DrVUeLLQbZXinWGRIzEhgfzXLswXC46HHFAG/RXOXHjC3UlYLaY4t5JWeWNlEbIwUo4xkHJ/l61cfxPpsdxLC5mAi3gy+U3lsyAllVuhYAHj2NAGvRWfpetWureYIFmjeMKxSaIoxVvusAexwfyrQoAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACmSdB9RT6ZJ0H1FAEcn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB866j/wAhS8/6+JP/AEI1HDNNA5e3keN9pUshwdpGCPoRkVJqP/IUvP8Ar4k/9CNWNCvotN1m3ubhWa2BKTqoyWjYFXA98E0xEkGuaxFpZ02C4nW3B3MFzkIFxtz2TBPHvReeJda1C8kuZNQnDyEnZG5CqM5wB6V01x4y0W62rJayhJFdZ1EfDKuEhHXn5M596jtPE/h2B47j+z0imSd2zFahWC7m2lSMY+QhSPqfegDmV8Q6ym3bqt2NiBFxKeFHQfoKbHrmrRGIx6lcr5I2x4kPyjGMD8OK6Vdb8JG4T/iXRxw+SVyLQM6fd+Xk4LcN8xB69fTG1280i7srBdOhEU0SbZgsAjB4GMnqTkEnkjn8KAKK6vqaOJF1C5DjGD5h7En+bE/iar3FxNdTvPcSvLLIcs7nJJqOigAooooAKKKKAClH3h9RSUo+8PqKAPpC6/5CNn/urWxH90Vj3X/IRs/91a2I/uikMkj/ANWv0p1Nj/1a/SmXSSS2k0cLbJGQhWz0OOKAJaKxTa3iR/6HavaA9UWVclscE9sZ69zTpINUQvN57kjLbQwx95ugx/d20AbFFYSx6yYYinmfeVvnkUsPu5z7fe/w9HOmqQeWgmdmmKqckHaSDuPTjHBFAG3RWbeRah9oaS2dioACpvAB4bPbrnbVeK11Z1UTTSoA2OHAO3cc5684x3oA2qKy7GLVFuw13ITHsGQMEE4Hv1zntWpQAUUUUAFFFYOq2F7Lq8d1aQB2VVCySMCiYzz2YHntkHvQBvUVyZXX1lihzd7mVmQGVCQw2cuehXJbA64qRdP1y1t1jjknaMjc6RyqGDZfhSeg+4TQB1FFY+lR6smoTm/ZmiKLtbcNu7jO0Dt154/GtigAooooASloooAKKKKAEpaKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAzNX0OLV2UyyvHthkiG0cgvtww9wVBFUo/CcduqNbXskc8SxeVKUDYZA4LEd929s/WugooA5ybwiWt5Ug1SaGS6ieO7k8tSZtzFicfwnLHp2OPenyeFi9yWGoyrbGYz+R5a43mMoTu645zj1roKKAOct/B1rbahDdJKpEZjZg1ujOzIoUEORlQcAkDv0Iq3qOg/2hqtvetdmNYWVtgiXcNpz8r/eUHoRyCPStiigDmD4NZoTCdWn8tIfJtwIkBhXzFcc9z8gHNSXfhN72CUTakXnnk3zSNboQflCjaP4SAOCDnOetdHRQBh/8I5Ipnih1SdLS4DGSEorFnZNpJY84PXHr37VX1Pw3cSG0eyuWWWE20ZcgfKsRY7sHqfm6V0lFAHOS+EhLG2dQk82ZJVuJPLX975hBJA/hwVGPapJvC6zmWJr6QWjNLJFBsH7uSQMC27qQN7ED3rfooAo2elrZ3j3IlZi9vFBtI6BN3P47qvUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABTJOg+op9Mk6D6igCOT7o+tZOkdbj/eH9a1pPuj61k6R1uP94f1oA+ddR/5Cl5/18Sf+hGrOg6bHq+sRWM0rRRurszrjI2oW78Dp1NVtR/5Cl5/18Sf+hGm2kt1BcCayeZJ4wWDwkhlGOTkdsZzTEb0Pg83gE1vqVtFC7lYxKxkY4ZUJ3ICp+Z1HB7+1T2ngO7YxtdzqqPlWWPIeNsr1BHIwc+/rWHPfawMzXFzergqS8jMMZwy8n12gj1wD2ok1jWQI1l1C9A27ow0rDKnuPUcdfagCteQC2vbi3DFhDK0YJ74JGf0qGhpN7s7vuZiSWJySTSbh6j86AFopNwPcfnS0AFFFFABRRRQAUo+8PqKSlH3h9RQB9IXX/IRs/wDdWtiP7orHuv8AkI2f+6tbEf3RSGSR/wCrX6U6mx/6tfpTLozC0mNvzNsOz644oAlorFM91DHm0+1up6m4iLHdjhQODgnqeg7U559U8xCysqGTLBIskKGI2++Rg5oA2KKxbe+1KVlEsTRJv4byGJbheCO3VuenFOe8vodPswzMZ5CwkJgJbIBONo9wBmgDYorHju9WllZGgWLLqPuE7Bkc56HjPfim/btT2t+5bKs2GEDEMf4VHcA88npQBtUVRspb153FygCFSy4TG35iMZ78AGr1ABRRRQAUUVg6rLfxavG9stzKoVdsKZVCecknBUjpkNg+lAG9RXK/23rAeKMqSzBmT/RGBlIC/LjPygFiN1OW9122tlWQSMGG4ym2LtHy+FwD83Ree2aAOoorH0q+1K51CeK8gMaKisoEZCqeMjcep69OK2KACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKAM7V7qaJI4bYyCaQlv3abiAoz09CcD8ary6tJMEMDRxpuhyGPztuIzj+X51sbRu3YG7GM4pnkQllbyk3L0O0cUxGfY3011fJvePy3gLiNDyvzAfN7/wD16fZak11fPBhCmxmRlBHAbHfr+Qq8sUaMzJGqs3UhQCaFhiRi6RorN1IUAmgDNXVpBI6yCJcSKAAeil9uc5wf0qF9WmFxLIjw+XHGx2Mfv7XK/L7kCtf7PDhx5MeJPv8Ayj5vr60fZ4Pl/cx/Lyvyjj6UAZr6tLHLLGyxKQ2IwTxjcF3EjsM8jgiie/uAkiBoGCQPI7xsecEjA9D+eK0vIhy58pMv987R8319aVYYlXasaBcbcBRjHpQBky6pcKJghhG1njUclgQm4MfbihNRn8zyxJFvfbmSQnYPkDHA9/8AGtOK0ghd5EjXe7EsxGTz/SlNvAU8swxlP7u0YoAzodVnmeN/LjWJnjQqSd2WXOadPf3EN/LCHi2kxrHvGNm7OSfXp+eK0tiZzsXOc9O9I8MUmd8aNkYOVByPSgCmNQf+zhdsqYR8SEHI2hsFh7d6gOrT8N5cSqAr7GJ3OrMQNvvjH4nFaM1tHPbm3OVjYbSEOOPT6U4wxEoxjQlPukqPl+lAGW2sSeWvlrEZCrZUt90iQIM/nVjULyayiib92ScmRj0GB1AznH5496tiCEMzCJAWOWO0c0skUcoAkjVwDkbhnBoAyZNamV5ykCmOPeBk4OVGc9eh+lOn1Ce2llQshl+XjBKn5STgZ46etaZhiLlzEhdhgttGSPSleGKT/WRo/OfmUGgDPg1CR7O7u+DsQSIhPA/dq2M/U0JqUqXAhuPKHz7S4JAxs3Dr+VaIjQKVCKAeox1pGhicEPGjAkE5UHp0oAyo9Uu5/KMawKJDGvzZOCybs/SmQ6tcNKZCYihEOYs/NluDt/nWyI4xjCKMdOKb5EO5X8pNy/dO0ZH0oAyo9YuZVJWGNd5UJuP3cuFwecnr7elWr69ltiiKYQxjaRmkyFO3HA9zmrYhiVmYRICxyxCjk+9LJFHKAJI1cA5AYZwaAKtleS3XnSOqpEhAA53fdBOfzqnFrM0reWBCC5TbIwIUBgx5Gc/w8dM5rYCgZwAMnJx3qMW0AVkEEYVvvDYMH60AYv8Aat0bE4miV1AYuTy+ZCPl+gFW9Ru54Ll0DqIvI37RwxO4Dg/jWgbeE7cwxnb935Rx9Kc0cbkFkViOhIzigDJk1S7Xe4WDYqyOAc5wj7SPqf0qa21Kae/aEwgR7nUHOCNp69ec/TjitDy4zxsXoR09etIIoxIZBGocjBYDk/jQBljUbpXkjaS33ebIAz8BVXHB56nP5ZqxPqRgs7e7aPEUq5YHqpK5Ufnx+Iq20EL53wo245OVByfWknt0uAgkyVVg20HgkdM/jzQBnf2pcKxDxw5DGMxgncGCbs/T/wDXSrqss88UMHkkvsyxJIGVZj0/3f1rS8qPzPN8tfMxjdjnH1pEghj+5Ei85+VQKAKN9qU1teCGKEOAgdsnG7JxgHIx+tRf2nJLI8ZCgRTomVYjflsZHt2+oNajxRyMrPGrFTlSRnH0oEUYxiNeOnHSgDKj1O5mkhUvDGxmCyLjPylWIwc4PTqPypLfVLgpEdiNGPLVsklyWXPWtUW8KjasMYBbdgKOvr9aURxjoijp29OlAFDT9Rlu7gRv5JDQiUeWSSuT901HFq8hcLMIlJkVSAeFU7uc5wen/wBarttYQ20ryqXZ3GCWOeM5/wA96k+zwbWXyY9rnLDaPmPvQBkrq85dpg0RjEaN5ZPLZdl+X8hUh1aYPJGREr7wqZyQoLY3Eg4I/LnitPyIcqfJTKfdO0cfSjyIfn/cp+8+/wDKPm+vrQBm3F/ceXKA0JWODezxMeTuI4PbpUdzqtyqT+WYAQZVTGSylM8kenH6itcRRhdojULjGAvGPSo4rWCEuUjXc5JYkZJycn8KAM86jNHJJGrw7tzEvIx2cIpwPTO6pIdTmllRmjjSF5BHg53AmPfn09qumGAoEMMZUHIUqMU8qh6qpyc9O/SgBysGUMpBBGQR3psnQfUU5QFUKoAAGAB2psnQfUUhkcn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB866j/yFLz/r4k/9CNTaLqC6XrFteSRtJEjESxqeXjYFWX8QTUOo/wDIUvP+viT/ANCNSaRp0mr6va6fGcG4kClv7q9WP4AE0xHWHx5YzPGZtOdT8+6Tar7ccQkKSMlUyp5HXis7XPE1hqujC0itJEkUIsaNGgSHa7MSpHPIYLt6DFF94MazvnR75YrZplS2eSNmeVSqtn5AQMBu/GQafdeB5VLi0vI3SFpfOeTI2ojuvmYxwPkwevJHrQBbbxhopkkkXTW3vAqFmt49vBb5AueFIIyc9ulVG8W2Lz3kkmlJKvyfYUZEAh+Xa4bA5BGSOvODVdvCElvrun6XdX8A+2SNEzxAsYmHUEfiMGpZvBqhBNb6pEYEt1mnMkbho8xCToByCM4x+NAC674ostQsbi2sbPyHnZMyGBFPlguSmQSf4lGRj7tcvXVD4f6g12LUX1oX+62NxCPkAKeOM54Pfmqc/hlY9TezTUE2RWC3ksskbDaCFJUADJ+8MUAYNFdPJ4FvI7iSD7faNLGjEom5mLqcFAoGSfekbwRdIjyNqFsIodqzv5ch8pmCFRjGWz5i8jgc0AczRXTN4HvI5Fil1C0jlyPNU7v3YO/BzjByY2HHtVbVfCV5pGntd3NxACrf6nlXKliobBHqOnXFAGFSj7w+opKUfeH1FAH0hdf8hGz/AN1a2I/uise6/wCQjZ/7q1sR/dFIZJH/AKtfpTqbH/q1+lRXryRWNxJFnzFiYrgZ5A4oAnorCj1PUIXWGSBnJkx+9IDfw8ZGBk5JHt+NC6zdOWxHHuRNxHICkg8Nn0x7UAbtJgEg45HSsNtZvEBcRIyvtKBkK4ypPOT3IwP61M+qXqTxobZNsjsByRwG24ye/f8AzmgDXorHg1S6eC8nMYkMUaMkaKRgnOQc9SOM00apfuqlIIsdM4JB+/yMdvlH50AbVFYbaxcyu8ccJXChgQpyp44Pr19qnudUntpLaNYTK0iAuNpBOfT/AD+VAGrRXPNrF8Y5Spj5+44jbGdq/KPU5J6+n5Wv7UvBcRRtbpiTJ7jI3EY+oAyeO9AGvRWPb6xPK9srxIBK5VyoJ546c8jnrz+FR6trl1YagbeKBJF8nzB8rFiec9OgwPf8KANvapYNtG4DAOORS1zJ8UTtdukUcLRg/IuG3yruYZHbAAyc0yLxReSQI4hgYMAwdVfbIcA+Wv8At8/TigDqaK5a513VYlEzLDGksb7EEZypEgXOSeuOcdKhi8R6lBbzM+ycIy4kdCMZ7cBcn8u/XigDr6K5mbxNdRu4MUEY8wITIr/ufmx8/wBRyMU2PxBqapJcPbK0TnCIVYGM7FO7pyvJPrQB1FFc7b+I52vLeOeOJYXVy0qKx3AFvmHovA9ev0ySeIbpRL8tvHtl2fOr/uRlsF8DvgYx/eFAHRUVza6/qjMJPsUSRZyUZX3gDZkZ6Z+f9K6SgAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAoqKWXy8ADJNR/aW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390VOjb1DetADqKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKQmgBC2Kw/EXizSfDFsJtSudrP/q4UG6ST6D09zxUviPW4dA0W61OcblgTKpn77HhV/E4r5x1XVLzWtSm1C/mMtxMck9lHZQOwHpVRjcD0W9+NtyZCLDRYhH2NxMSx/Ben51NpvxszKF1TR9iE8yWsmSP+At1/Oua8LfDPWfE9kL8SxWNo/8Aq5JgWaT3Cjt7k1T8W+BNW8IbJrpo7i0kbatxDnAb0YHoau0dhHvOja9p2vWK3mm3S3EJODjgqfRh1BrQc5UfUV89+CR4p0vUo9V0fSb66tWIWdUiOyZO4yeCfQ172kkrxK3kuucHDDBH1qJKwyaT7o+tZOkdbj/eH9a1CWI+ZSB71l6R1uP94f1qQPnXUf8AkKXn/XxJ/wChGoo5ZIWLRSNGxUqSrYOCMEfQipdR/wCQpef9fEn/AKEar0xFmPUr+K3NtHfXCQsoQxrKwUqOgxnpyaJdSv5y5mvbiQyKUctKx3KTkg+oJ5xVaigCzJqV9LLDNJe3DyW+PJdpSTHjptPakfUL2TzN95O3mjD5kPzDGMH144+lV6KALq61qylSup3YKpsBE7cL6dage8upPv3MzfuvK5cn5P7v09qhooAuHWNUOT/aV3ny/Lz5zfd9OvSp7nxFrFzeJdNqE8cka7Y/KkKhBgDCgHjIArMooAsx6lfxOHjvrhGXABErZGM4/mfzPrRLqN9cQGCa8uJYmfzCjyEgt64Peq1FABSj7w+opKUfeH1FAH0hdf8AIRs/91a2I/uise6/5CNn/urWxH90Uhkkf+rX6U6mx/6tfpTqACoobeG33eTEse45baMZqWigAooooAKKKKACiiigAooooAKKKKAIzBEzu5jUs67GOOo54P5n86ciLGixooVVGFA6AU6igBrokiMkih0YYKsMgimW9tBaR+XbxJEhOdqjAzUtFADJIo5dvmIG2MGXI6EdDT6KKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooArXP3l+lQ1Nc/eX6VDTERiUZbPQdMd6VpCP4SOD17UvlJgDb0FBjU9ST+NAB5g9803zhxwcc5PpinGNSSSOowaTyl9z+PWgBVkVgT/d60glUjOD0JpwUAEZPPqab5S+/1zQACUEnIIGcA/hQJQQCFJz0FL5ag55+maTylHrn1zzQAGTnGCOQDkUnnDAwp5xinbF/XPWkWJQoBJJAHOaAASjHIJ9SB05pVkDHGCPTPejyl9/z60oQAjHbNAC1bh/1S1Uq3D/qloAkooopDCiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKY54p9MfpQB5j8Zrl00Gxt1J2TXWW99qkj+deOtypx1xXt/xW0uTUPCrTRKWeylE2B/d6N+hz+FeI1rDYTPpzwxdWt34W0yeyKmA2qBQO2FAI/AgirN5p9pq0DW19bpcW+5WMcgyCQcj9RXlPwk1/UIra80W1t7e5Ifz41mu/KIB4IUbTnkZP1r0PSNZ/tm51PSZxFbXdptDi2ufNwGHBzgYIwQRjioa1B7GxNdW9mYYnZUMrCOJB3PoBTYbzzb2a28iRRGAQ5Xhs1yniew1JtYs5IYri4hjRQjR/eDA889j05rr7ZmaBPMKmQAB9pzhu9bzpxhTjJO9/wADmp1ZzqSi1a34jpvuD61jaR1uP94f1rZm+4PrWNpHW4/3h/WuY6j53vgG1i6Vm2qbpwT6DeeastZoGl/0Jg0e7y03k+bggZ9Twc8cGqmo/wDIUvP+viT/ANCNLYWM+pXiWtts81gzAu4UAKCxJJ6YANMRe/s60ZlRSVk+dmQv2Cglc+oJ/HmmCzs3u3iBG1Av3WIOSRwSfXpx61HcaDqlu5Bs5JUAQiWAeYjBwCpDDg5yPzpH0HWI2RJNKvFaRtqAwN8xxnA49OaAJG09XjUrAVlYoTErMSoJIJIPI7VMun2TOFXDDd/CzE4y3X24HTn86rtoGsqsT/2bdHz9+wCMljtOGyOoweOaqx2N5NbvcRWkzwxtteRYyQp9CfyoAZOoSZlC7QO2CP0PNR1dk0bVYzKJNNu1MKB5Mwt8i+p46cH8jQdG1QFgdNugVj8xgYW4X16dOtAFKir0ejajJdx2htJIp5Y2kjSUbC6gEnGevANWofC2q3FrHcIkAWVA0aNOod8qXAC+u0E49KAMeitLUfD+p6SsrXsAjWJowSHBzvUspGOowp+hGKzaAClH3h9RSUo+8PqKAPpC6/5CNn/urWxH90Vj3X/IRs/91a2I/uikMkj/ANWv0p1Nj/1Y+lOoAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigBrxq/3hTPs8fv+dS0UARfZ4/f86Ps8fv+dS0UARfZ4/f86Ps8fv8AnUtFAEX2eP3/ADo+zx+/51LRQBF9nj9/zo+zx+/51LRQBF9nj9/zo+zx+/51LRQBF9nj9/zo+zx+/wCdS0UARfZ4/Q/nUgAAwOAKWigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAprCnUhoAoXcCyIysoZWBBBGQR6V4l4x+H13pFxJeaVC9xYMdxjQZeD2x3X3r3l0yKpzW27tTTsB8uhircMVZfQ4IrT8O67qPh7Wor7S2LT/daLBYTKeqkDk17veeGNLvn33Wm2s7f3nhBJ/GpLHw9p9gf9Esbe3PrHEFP51fOhWJ9E8SNqWnRXF9ps+nzuOYXwxHvx/XBrSS9tlB2KVBOThMZJqGKyUfw1O1uoUcdxWYxWuI5RtTOevIqGKCKHd5aBdxycVKYwoyKbQB8yaj/wAhS8/6+JP/AEI0/TNSn0m/S9tseaiuqk9tylc/UZzTNR/5Cl5/18Sf+hGrOgfZv7btvtcUEsOTlJ5AiE7TjJPHXGM8E9eKYjWHj3VMAtFC0gcPv3MMn5d2QDg7tg46DnFQR+Mr5YpIXtoJIZo/KlQlhuT95kZByP8AWnkegrbksvDEkNxFcXFiJWYEPCyx+SP3O4gAkFgC/AJUkHArMmsPDNp4itYzcyNbeZH5kRZZIyC+GzIrfKNuD0P4UAIvjzUBIXa1tyTkfKzqQNysoyD2Kjnqe9VtM8XX2k2s8Vvb27SzStIZ3BLZJUnPPPKjGfU1Z1LSvDsFmJVvDE5kUZhmW4JyX3rsyMBcLhs85q3pmneGIrC3u7i6iZniIljmnXc53Doozt49wfr1oAyX8UO0ckS6bbpG0nnRgSSny5cEF8lufvHg8dOOubcnju/mklaS0t3EqMGjdnKbiSS23OOp6dqTXtM0C102S40+cNc+edqJcLIgG9vlx1IChTu96vhvC0IaZVs/9KtpLsBohL9lbagWEISATu8w4z0xQBhX3ia7vdQsb4QxQz2WCjqSS5BzliTk+n0p914s1S4jvI43W1W8mEjiDK7VCbBGPRQtbbnwje2LywwW9nOttdSxxu33ySwRDzw4+VlHoSO1cSKANrU/FN/q1hLZXKQ+VJci4UqDmM4I2g5+7yTj1JrFoooAKUfeH1FJSj7w+ooA+kLr/kI2f+6tbCfcFY91/wAhGz/3VrYT7gpDF2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaZPPHbW8k8rbY41LscdABk1zv8AwsHw/wBrmUj1+zv/AIVMpxjuzelh61VN04N27Js6XaP8mjaP8muZ/wCFgeH/APn4l/8AAd/8KP8AhYHh/wD5+Jf/AAHf/Cp9rT/mRr9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/wo/4WB4f/AOfiX/wHf/Cj2tP+ZB9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/wo/4WB4f/AOfiX/wHf/Cj2tP+ZB9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/wo/4WB4f/AOfiX/wHf/Cj2tP+ZB9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/woPxB8PgZNzKB/wBcH/wo9rT/AJkH1DF/8+pfczpto/yaNo/yar2V9Bf26T277o3UMpx2NWa0ORpp2Ym0f5NG0f5NLRQITaP8mjaP8mlooATaP8mjaP8AJpaKAE2j/Jo2j/JpaKAG7R/k00xqf/11JRQBCYV9P1pREvp+tSUUANEaj/8AXShQO1OooAZJ938aiqWT7v41FQB8yaj/AMhS8/6+JP8A0I0/S9MutY1GLT7JVe4mzsVmCg4BJ5PsKZqP/IUvP+viT/0I0un30um3YuoVUuEdBuzjDKVP6GmInfQdVRFb7DM4MXmkIpYou5l+b0OVbj2pbnw7rFncvby6bceYhGdqFhyQByOOrAfU1pP451aW3MMqwufJWPzBuVshWXeSDyxDHPY06Hx5q1sZvJitkE773G0n5igQ4546Bsf3gKAMldC1dtm3S7o+YpZf3R5UdT9BkfnUeo6XeaVctBeQmNgxUN1Vsddp7itKbxbfTWE9oYLdRdRbLiQBt0pCqobrgHaoHHHWquua9deILpLq9jhEyLs3xgjK54B57c4oAzKKKKACiiigAooooAKUfeH1FJSj7w+ooA+kLr/kI2f+6tbCfcFY91/yEbP/AHVrYT7gpDK8F8Jry5t2TYYCMMT94Y5P4Go7bVYp7bz5FMYMrIigFmbHQ4Az05plxpskrOySqheU7j6xsAGH14pRZTQyiaHy2ZZXYIxIBVgOM44IwKegtSw1/aqkb+ZuEgJXapY4HU4A4xTba/inthMSFPlCVh12qc8/oahis7m3kE0ZieRwwkDEhQWbdkfT9ajXTrqG28qN4WL2whctkYIzyOOevSgC0L+LMu/hUZVUgEl8qCMAc96mjnilh85HGwZyTxjHXOelUX0yQneGVmV1ZV3MucJtIyORVm3tjFavHsjVnLEgEsMn1zyfegBUvreQZVyMlQNyEZ3dOo6H1plxqEUEiIecyeW2ASVO3cMDv2quthciIqGRApRo4vMZ1BU5PJ5APTHalNneGf7RmDzPP83Zk4xs24zjr70AWTqFsI1k8wkNnAVCW465GMjHele+to2VWk6gHIUkAHoSR0z71VewnKFsRGV5HckSMhQkADaw+nPHNSR295A7FJIpDKE8x3yCGAAJwOuce1AEhv4S5SNgzLKI2yGABJxjOOtC6laPnZIzcNjCNhiOoBxyeOlM+xSbNu5c/a/O/DdnH1qvZW1zLbW6SBEijkaQHnceWwMduvWgCzDqUMsaTEiONofNO/IYDPpjpT/7RtRGXMhUBghDIwYE9BjGeaqjTZ2hjVnjVo4VjBGSCVYEH6cVI1ncTXAuJTGj+ZGdqkkBVJPXHXmjQC3BPHcIXiYkA7SCCCD6EHpVcalA9zFDG24SbvnIIGAM5BPBH0qWGAxvcliCJpNwx2G0D+lUxp1xIkEErRCKCN4wyZ3MCu0HHagCaXVbWOB5hvcIA20IQWBOMjI5HvUxvbcSiIswYkDlDgE9ATjAPsao/wBmTNA6MsSv5WxX8x2ycg9+g4HrUk1ldT3Ad2QjzUkGZG+QDBKheh6Hn3o0DUlXUED4kKKgR3LgnA2ttx0qxDPHOpaPd8pwQylSD7g1SGnSANkxPlJF2uDg7n3DP4VYs4ZoUcStkFsom8vsGOm48mgCzRRRSGFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQBn69/wAgG+/695P/AEE1zHhHTorrSIHkySIV/lXT6/8A8gG+/wCveT/0E1ieCP8AkCQf9cV/lWf/AC8+R1/8wj/xL8maX9iW/oaP7Et/Q1pVk6vc3FvPvW4aO3ih3yeTsLoc/eZW5ZcDt71vCLk7HDJqKuSf2Jb+ho/sS39DUNxrskRnjW3VpbcM0gLkDblQh6fxbv0NO/tW7M7WohthcRtJvZ5CsZChTwcZyd4+mCav2UyfaRJP7Et/Q0f2Jb+hqsdYurdrh5I4pIRLMseG+YbE3gdMY4Iz1qX+17lJMSwQbY2iWUK53EydNoxzjI+vPpR7GYe0iSf2Jb+ho/sS39DVaPWbiYQeZEkfn+VInlSZ+Vn2kNkfypW1q5CFlghlEk/kwvFuZWIBLHHXAxgY6mj2Mw9pEsf2Jb+hrO8QaRBDoF/Io5W3cj/vk1uWVw13ZRXDxGJpFyUJztNUvEv/ACLeo/8AXtJ/6CawqKyaOrDWdaD81+ZT8GEjSIBn/lmv8hXSZNc14N/5BMP/AFyT+Qro3fYjMewoj8KCv/Fl6sdk0ZNV45nICHBfOMsMds0vmyFiPl+8AAD6iqMSfJoyag+0ErlVHpz645pBcMcnaDkjaPTIzQBYyaMmoTMRErbfmY4x6UgnJIBTBboM/nQBPk0ZNVvtDHHAHIPHcc/4U4znjAGSAR+NAE+TRk1WE7Nhjwvy4A6804Tsdo2rlsEc9M+tAE+TRk1AJ2JXKgA8E575xU1ADwc0tNWnUhjJPu/jUVSyfd/GoqAPmTUf+Qpef9fEn/oRq34daxTW4m1LyzbKkhbzVDLnY23g8E7sYB71U1H/AJCl5/18Sf8AoRptnay317BaQDMs8gjQH1JxTEdfcWPhC6kNwbqKOIhfMeKYRlTtTGIgP4iX3AfdI/NbfT/DNnE8bXNpLOG3GY3KvtUiYAAYwekWR6tmuen8NapDqElmsAnZJTEJI2Gxzs35BOONnzZ9KsXng3WrRQ32dLg+a0RWBw5Vg4Tp6Ekcj15xQBuWHh7wxqN55FmXnZJBH5Yuz86bkBk3beDhmwOhIri7qNYryeKM5SOVlUk54BIFaqeGfEMDOyWc0OBtZ1lVcggE4IPIwcnGRii68Javall+ziQx7xIUYbVKsVwGJwxO04A54oAxaK27bwjrNxGJTbiKIhCHZ1O4MwUYAPJBYZHWoh4W1tiNlg5U5IYsqgAc5bJ+UY55xxQBk0VJcW81pcSW9xG0c0TFHRuqkdRUdABRRRQAUo+8PqKSlH3h9RQB9IXX/IRs/wDdWthPuCse6/5CNn/urWwn3BSGOooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAz9f/5AN9/17yf+gmsTwR/yBIP+uK/yrodTtjeabcWyttMsTIDjpkYrhrPSvE2lILe11BFjQBV/0cHgVnK6ne1ztpck6Dg5qLvfW/Z9kzvM1DNaWtw6PPbxSsn3S6Biv0zXJ7fF/wD0E4//AAEWk2+L/wDoJR/+Ai01Uktov8P8yPq1N/8AL2P/AJN/8idWllAs1xKw817gjfvweB0X6Dn86dLaWs4Imt4ZAW3kOgPzdM/WuS2+L/8AoJR/+Ai0bfF//QSj/wDARaftZdn+H+YfVaf/AD9j/wCTf/InXmCBgQ0MZBJJBUdSMH8xxSNbW7TJM0ERljGEcoNyj2Ncjt8X/wDQSj/8BFo2+L/+glH/AOAi0e0l2f4f5h9Vp/8AP2P/AJN/8idf9ntwFHkx/KAF+UcAHIx+NQrpunpG8aWNsqPjcqxKA2Oma5bb4v8A+glH/wCAi0bfF/8A0Eo//ARaPay7P8P8w+q0v+fsf/Jv/kTsUVI0VI1VEUYVVGAB7Cs3xL/yLeo/9e0n/oJrA2+L/wDoJR/+Ai1Fd2niu8tJbabUUaOVCjgWoGQetRKcmmuV/h/ma0qNOFSMnVjZNfzf/Imv4N/5BMP/AFyT+QrpCAeozWP4Z0+XT9PSGbkqoXOPQVt4HpWkdEjkqtSqSa7sjZFb7yg59RRtXOdoz9KkwPSjA9KozIyikYKgjOcYo2If4F6Y6VJgelGB6UAR7VK7do2+mKAqjGFAx046VJgelGB6UARhEXoqj6Ck8uPGNi4+lS4HpRgelAEexQQdo46cUBFHRQOc8CpMD0owPSgCPYmQdoyOhxS0/A9KMD0oARadRRSAZJ938aiqWT7v41FQB8yaj/yFLz/r4k/9CNLp+oXGl3iXlowSeMMEcjO3IIyPfng9qTUf+Qpef9fEn/oRqzoLW6a3bNdJbvCCcrcttQnacZOCBzjGRjOM8UxFoeMNYMZWSSGdim3zZYgzj5Cm7d/e2nGfTFKfGGsfahcpJBFKNxBSEDlnDk/iyg/nWvdaZ4fmiutRmlDJDNFCTARFHIzhehUFcph9xXg8HAqaTTvBuPIWa2ysxcFbo7jmP5ULE4xuByQcZ7jNAHPS+KtUlZTuhQLv2qsfC7k2NjJPYfnT7jxbqV3E8NxFZSxOzP5b2wKq5JJcD+9lm/OtZLLwWJFiaUsrOAZGuzlAZGU9Bg7VCtnvVPQ9P8N3OlxSapdrBP8AaMSEz4LJkYAUdPcnj3GMUARN421l9gb7KQgG0eQMZDKwPXrlFPp7VDL4s1Wa3mhZrcC4TZO6wgNKMbRuPcgcCtCey8JieG3WTYbiVo5JvtW4Wv7tdrcZDLvJzyeBUs9r4Xmsf9Gmid4Q6qk115RCb3+fIXLNwpCnPDUAcve3c1/ezXlwQZp3LuVGBk+1QV2g0rwa10sa3a+WYSRLJdgKeVwzAcg/e+X9DXFngkZzz19aACiiigApR94fUUlKPvD6igD6Quv+QjZ/7q1sJ9wVj3X/ACEbP/dWthPuikMdRXDPrjCy1Wx+0SyagmrnZCd+4Reeg4I/hwfXFV5vFuuLpUtxHcRyXBmjW4iFmyf2cCzAgs3yt0A59c9CKAPQaK4Gy8TeJp3gupvJWHdBG9uLViH8xGJcN1ABAOAO+PSs9/HHiMaVFJH5buJXElybbERYIrLGpzyCSewbjGM0AenUVw1jreq3/jWwt7qdoAs06yaekLL5aCL5HZ/4gTyP/rGmv4t1WDWNRgkkRoLa5TOy1JWGHzlVix6htpJ5GO4OBQB3dFeap4q1h9Za6iumIlVVt7M2rkXQ+0yJhf7p2YJP0PSp4/F+sObmKe8jgRLoJLerZF47VDvx7kkqowwBGc85FAHodFcDda1rkiNeG4WSGC7iSJEtXiDfuN5kOTnGT908DvVO38Ta3qEdhN/awa1MsRnuIrIopaSJyYT9GC8+rjuKAPSqK83tvFevQWMap/r47Xiya1dm2C33icuTz8/y4/DrU1/4n8RaXGY57mKQxXC7pVsyHlVolcIq52kgsR1BOOOc0AehUVmRXTXGmXEhufMdZnRGgiZCpDYC4PUg8E9DUQvLqCKIyMRMZCJ12bju44UdNuD65/WgDYorHS7v0ifD+a0SSMwMfJIcgD8BzTZNTu0hQgq7bjghOJACBj68npTsK5tUVkm7vwxbcpXJbb5XYSbcZ+nNSXUd1LqbJAWVVjQh/MKqp3HPHRuBRYLmlRWQ99epGrsygsGZR5R+YhsBPy70xr69iYp5gY+ZJy6ejfKn5HNFgubVFZMl3cvHIftHlOsg3RiEkxrvA698jmkjvblXROnzfKhQky5cg89sDmiwXNeiqFlPdShhOQd0AkXCbdpORj9BVW01C4WKHzZPMjxH5shjIKEg5U++QOfeiwXNmisiO/vnVZdoK/KPL8sgtlSevbnFQre3hkaVHachVIVUKrnY5K4+uP0osFzdoqlp928yFZnVmLEIyjG4AAn24zUMVxcnVWkZJPs0jGFST8oI6HHXkhhn6UhmnRWPcTXdtc3EiyHDyhQzLwgCAgDtyTilfUNQWURiFc/KMhDjLgbfwBzn8KdhXNeis++vZre8hii5BK7gU+8C2Dg+3Wm3dzdQskjRmPCvwh3j+HBPT1NAGlRWfb3l5JZGX7OsjKH53YyQTjjHOcCq8+pXEdoHjmEznJ3CEgcDO3n39OaLBc2KKynub3ck2/C+cyiIR/eAU4BPucVJZXdzNazySFCyLlTtIwcZIIHofxosFzRorHXVJ1tyzfM2x9reXwzjGAMdep/yKRL27TzlWQOQZDh4z+6w3yknuDRYLmzRWVDfzyPGGk8sEDAaHJlOSDjB4xgfnmo2vLuJYZJJFVpUj3OYzhNxORj2osFzZorGW6u3kVnYsGEZSMIVDfOQWH1GDj3p8N7eztHGsi/OV3P5J/dkhiVweuMCiwXNaisqDUZ2uIxPhUaIMyrGfl+XJJ7j9fTrWoDkAjoaQxaKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKTavpS0UAN2r6CjavoKdRQA3avoKNq+gp1FADdq+go2r6CnUUAN2r6CjavoKdRQA3avoKNq+gp1FACYxS0UUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFADJPu/jUVSyfd/GoqAPmTUf8AkKXn/XxJ/wChGq9WNR/5Cl5/18Sf+hGq9MQu5toXcdoOQM8A0lFGD6UAFFFFABRRRQAUUUUAFFFFABSj7w+opKUfeH1FAH0hdf8AIRs/91a2E+4Kx7r/AJCNn/urWwn3RSGRJexu7qN4EZKs7LhQR1Gac15brKYmuEDhSxBYcAHBqmumOslyweHE5bkoSw3fjg/lTf7I/cpCJVKLGY/mTJI3Bhn3459aYtS+LqAkgXEZIXcfnHA9fpQt1A+dtxG21dxw4OB6/SqEuj+bLMfMXbIWYZBJUnGR1xjj0pZtIWUPiQIWZ24X1ZSAf++aA1NATIyK6yKyN91g3B+lNNzCp2mZN2CQu4ZOOvFVxYYsHt94V2YuHUHCtnIPJ9agbSGLRYuBsj2nBXkkZyevcnPNAGglxHIiusgKuMjJ9s/yoWeN4/NWZGjH8YYEfnWcdHdo/JNwBFjsnzZ2bOuenepksHSznhEqrJMcl1BIHAHcn0oAnlltJ4fKllieOdSu0uMODwR70kEtrEyWMDIDEmFjQ/cVcDHt2qomj4SQNKpZw3O0nGWDdzntU1rYNb3SymRGVFdVATDEMwPJ70AWftUGGP2iPCfe+cfL9fSmyXttEjs9zGAgBb5hwD0rPg0qQxx+c0a7CcKE6jzA3zc89B+dSSaS0m8eagXLlPk5yxB+Y55HFAF7z4SXHnJlBlhvHyj39KZ9uttwRZldioYKjA5BOM/nVM6QWaQmVeSWU7ScEsGIIzgjIqRtPkkfe0kQJA3BI8Dh93HP4UAWzcwAMTPHhDhjvHyn39KZPew28SSvJlZGCptIO4npiqkeklXjLyoViKhQExkA5+b1NTrYhbWGDeMRSb87evJOP1oAnNzAAzfaI8IdrHePlPoacZEGcuoxjOT0z0rPi0ko0ReRGEWwKBHjIUk8+/NS3No0+oQvgiNV/enI+bByo/A80AWlnickJMjENtOGB59PrQs0bvsWVGbGdoYE49aoR6XLGY3WaMPCFVP3eAQufvc9eansLH7ErZcOzKoJC46DFAEwuoCjOLiPan3jvGF+vpQt3A8rRLOjOuMqG9RkVROj4SIJKoaJVA+UgMQSecH3o/sgiB40mVCyptYKcqy9xz05oDUvtcwKoZp4wpxglxjnpSNdQrIIzKpctt2g5IOCefTpVBdG8kfuZUyCwUSJkBCMBcZ7f1NObRke1NuZWAMocsBhjhduKA1NAyqIjKCWULu+XnI9vWokvraRWcTrsXGXJwvPIGT3pVS4WFlMke/aAjBMAHHXGfWqZ0kpbmCGYbQ+9S4OVYg7iCD3Jz+dAFxby3csq3EZKvsI3D73pS/arfYZPtEWwHaW3jGfSqi6X+83PKGGWOQmDllCk/pmof7GkEBjE6AkBSQrfMApAzz79qA1NFrq3jYq9xErDqC4BFNuLyO2ZVkEhJUt8iFsAYyTj61UGjrs2mRScMMlPVAv9M1PLp8c8kLSsWWKMoVBK7s464PTjpQBN9rtwpb7REFGMkuBjPSk+2WwMgNxGDEQr5YDaT0qs2mkHfE8YbzGcB48rhhjBHtUR0dgFCTLhSCu5Tz8m05wfxoAvy3dvDuMs8a7F3sCwyB64oF3CeTKqgttUswG44zx69apjSysUsKyR+XIpGTHlgdu3g56cf0pJNKdzI3mx7pQyvmPIAYDO3nrxQBfWaN5GjWVGdfvKGBI+opq3ULlV8xVdiQqswDHB9PwqGCwEE6ShgSrSE/LydxB6+2KiXSgN2ZASzKQdvIw5b+uKALRvIAwHnKSW2na2cHBPPpwDTpbmGFC8kyKq9csPTNUhpbGBIXljCoNqlI8Ejay889fm/zmmtpczFpGniMjAqcxHbgqF6Z68UAXkuoZMbZlyyB9pbB2+pFR3F1apa/apXV4UYEOvzAHOM8fWqiaNtJBkR1Kn76k87NvrjFTrYP9i+zyTBiZA+ccABgcep6dTQBP9rgBcNMqhCAxY4HIyOaVbuB2dVnQmMkON3Q4yf0rPbRSGYxzjG/cisDhV27dvBzx2/KntpAaEw+YAnmKwwvONoVl69CB+tGgal5riJSA0yAscDLjk+lNN3biTy/OXdznB+7jrn0qiNGKx7VmUllZHZ0z8pIxjnggAD8KdJpAkSMCbaY5HkB29STkZHcfzoAvyzJDH5jnC5Azj1OB/Oolv7Z2KiTkSNEcjowGT+GO9K8UlzazRTbVL7lUrzgdj9e9UTogZSDcHmHYfl6vnl/x6YoAvfbbXeiefHlxlDuGG5xwald0jQvIyoo6sxwBWYdHc7v3sQMiMr/IT1IORk9eKuTQz3FqULrG+/IxyNoPAP1HcUAS/aISyr50e5xlRvGW+nrTUuoJZnijkV3RdzBTnHOPz4qnDo4ii2NKGOU+YLyNrFuPzqWysXtZN7SRtiJYlCpt4BOCeevNAEiX0DtIrb4vKALmVdoGenJqQ3MC53TxjC7jlx09fpVL+zbhoNkk8bOJRLvCMNze/PTHp0wKE0ny4/kdA4ZGXKHblex5zjmgNTRDKyB1YFSMhgeMVAt9avu23EeFYLu3DBJGQAe9QjTENo0LSNvZWUspIUbiT93OMc1BNpE0yy5uIlM2dwSMhR8oX1z2oA0w6MQA6knOMHrjrVePUbaQkbmQYJDSLtUgHBwT71HZWjQ3k8zAhM7YlOOM4LH8TTV0iJbfZndIWyXbJGN+7ABOB07UAWXvLWNHd7iMBFDN8w4B6Gn+fCWZfOj3Ku5huHA9T7VRl0kymQeagVi7L8nOW9T3A/w9Ka+jmR5GaVfnJYfKThjgkdcY4/KgNS4b61BCrMjsy7lCMDkZxkfjUhuIBvzPH+7OH+cfKff0qpJp0krK7SRK2MNsjwPvBuOfamJpJDxlpUKxEbQE5IDbvm9TQBoK6ugdWDKRkMDkEVBFfW8qNJuZECht8i7VKnoQTRawSW6tDlfKGSpA5yWJPHoMiqq6VKp3edECrKyosZCEjPJXPU57UAX/AD4d6p50e5/ujeMt9PWmR3ttLCZlnj2AZYlgNv19Kox6VKszKXQR4jJbZySGLELzwMmnjSSgiaORA8SqBlPlYgnqP+BUAX/Oi3qnmpucZVdwyR6iomvYVnMPzkhgrMEJVSegJ/L86rwaY0E8MizKAg+fC4LdeOuMc8dxUwtp0nkMU6pFK+9xsywPGQDnvj0oAlNzbhWYzxAIdrHePlPoab9stdzr9ojBTG7LDjPSqdvpHktGWkVxEy4+U5IGeuT15p0OleU0eZFZUKNjZ1Kgj+v6UaBqWzdQAgCVWO8JhTnDHsfSmteQrOYfnLKQGIQlVJGQCaqw6VIlwJnuA5DKfunnBJ9eOvapZrGSW8E4kRACOQmHx/dznkH3oAltr2G6IWPeCy71DoV3L6j1oN9biVIi5DvKYgMfxAZP6VBBpzbI0upElWKLykVFKjHGSeevApk+kCSSV45vK3IojG3PlsMfN+QH5UBqWY7+2lkjjVzukQyKCpGVFLb31vdLE0L7hMCU4x0659OtVv7JCyiVJ3V0Zdg/hCgbcEfQnn3p1tpf2a4hlWXIji2Mm3hmwBu9uBRoGpM9/bpEJGc7SWH3Tn5c7uPbBpo1O13ojM8bu4QK6EHJGR+dRy6YJJbl/Nws0bKq7fuMwwx/HA/WlbSrc+WuDtGd+4li+V29Sc8UaBqWVuImiaXeFRSQzNwBg4P60puIBjM8fK7h845Hr9Kqpp7rYJbmcPIkvmh2XhjuzyKYuk4ST94hd9pzs4BDlsY/u5PSgC0Ly2aVYhMhZlDL8w+YHPT16GnG4gCuxnjAjOHO8fKff0qsdOMhZ3eMOwT7keAMOW4qFNHKRlRIjEYCMQ2QASeeevPagC6Ly1LOouI8oQGG4cEjIoa8tVIBuI8s/ljDA/N6fWq8OmtHNHI8qybCrH5MEkIV+nvUUWkyxyiVrhXcMh5Q843e/H3u1AF9LmF9v7xVZl3hGYBseuKVZ4XQukqMi9WDAgfjWeujsqCPzl2cEnZ82Qu3rnpVmGwSJJkJBSWNUIC46LigCd54oxkuD823AIzn/JqKPULSZlWO4Ri4yvP3uSOPfIqpDovlnc1xvYhSSV6sGBZvxCgfhThpPyFTIpO0KpCdAH3f/Wo0DU0qKDRSGFFFFADJPu/jUVSyfd/GoqAPmW/ONWuj6XMnbP8AGatyahEJ9+8TAoxIKkqHzlCM8jnt0HSqeo/8hS8/6+JP/QjUuj2cF/qkNtdSvDC24u8a7iAAT6HHTrjjr2piJVvlEVuzXD+ZG6EhARwCd2R0z7jr3p0d/GFjZpW3LcGQ5LZI3AjjoenetSXwTO83+jTiJZObdJzuaRQqszb0yuMOMHjPoKf/AMIKwtpGOqRGQzeTARG4WRwZAynIyDmPg9OaAMW9u7WW0MVupUvMJmBXGGIOR9Bxis6umj8DXkkqx/brYNko42vkSYQ7Bx8xw45HvVSz0W1bTEuLv7c8s88sESWkQfy2jUElweTnPQY4BNAGJRXTt4Fuo5Nk2p2abdqyY3NsdmVQuAM9XXnp1pZ/BMkfkiPUY2eXyk2GFyfMcMSBgdAFJz7UAcvRW3r/AIcbQba1aS4E0k7uMp9zaFRlI+ofn6ViUAFFFFABSj7w+opKUfeH1FAH0hdf8hGz/wB1a2E+4Kx7r/kI2f8AurWwn3BSGZr6qY7+ZWBa3RWVcIeXUbj83T1GPamjVpYnla4SPy12geW2dpKkjnHOTx+VanlpgDYuAdwGO/rTVt4EUqkMaqSCQEAGR0piM+TWHidkMCkhT0c/eGMgnHv29KkXUZWlMPkxCRC3mbpcLgEDg4681cNvCXLmGMu3VtgyaGghcgvDGxB3DKg4PrQBQGruxO23ADNtjZmIGd235uOPwzSi9nbT/NLIjtcGIuOVQb9uferpt4CXJgjJk+/8g+b6+tOEUYjMQjQRnqm0Y/KgDPl1CS1PlKy3jgsSR8uAAODjjPPsKbPqtwscjRwxr9/yyzk/dYA5GPetD7NbmNY/s8WxTlV2DAP0pxijYEGNCDnIKjv1/OgDPn1WSGORzDGdruoXeSWCfePSllvZv7OuJ0PzrNsTCjOCwHfjPNXmt4HUK0MbKDkAoCAad5abSuxdpOSMcZoAzzeXEM0cO1ndwoAmKrgktydufSmLrJ2NK9vthHO7PQZxzx1zitMojMGKqWHQkc037PCC58mPL/f+QfN9fWgDNOtN9nMgt1DrwyMxzuAyw4Hbj86nsr2S5vChI8shiBjkfdx/6EatvBDIMPDGwzuwVB59acsaKcqiqfUDFAGNb6tcBd8m6TKD5WQKMl9oIxyR1z+HrVgatJn5rdVCBTIC/wA3LFflGOemeavmGIrtMSFcYwVGMelMWztlmEohQMAAvyjC4z09OpoApjVZG2BYEJl2mP8Aedi235uODTf7SuEb50jZt7oFVsA4dVGeM960VghUlliRSx3EhRyfWl8mLcW8pMk5J2jk/wCQPyoAzn1eRA2YI90f+sBkxn5yvy8c9M1bv5XihTypAheZELYBwCcHrRcWEFy6NIDhDnaMAHnNSC2hEPkmNWjznawyM5z396AM3+0LmO5VSyzRRM/msq8uo28jHcbjnHoaSG/uHWCZ51ETKmSiqeWP8Q6gHjBFaqxRoFCxqoUYACgYHpTfs0G5G8iPcgwh2D5fp6UAU57i7/tNoIN5CiM7QgK4JO7ceo4FMGrSeWshgjC7PMI8znbnAxxyf/rVphQGLAAMepxyaYYIW2ZiQ7PuZUfL9PSgDOTVZwVR4EdssW2E/d3lRjjrx3p51Gd1jeOOELJKqjdJltpbByMcGrpt4CQxhjJDbgSg4Pr9aX7PBlj5MeXOW+QfMfegDPi1VyqkxhlG0OWbDEsTjAxz/n0qzZXr3ORLGsZMaSLtfOQ2cD68VP5EO5X8mPcowp2jI+lBgiLI3lqDGcrgYxgED+ZoAzbrUbi3uLhSV8sSJHE2PusdpIP1BOPpTZL+5itzMLhXZ/OAj2j5Nu7B/QZz61rGONgQyKQxBOQOSOhpq28ClysMYL/eIQfN9fWgChDeXBsr2RmbdAp2GRArA7c8gdumKPt81vbRySKz7jlmlKjYMD+5nj/JrR8tDu+RfmGG46j3qMWlqFCi2hAByAIxwfWgClJqzI7x+Su/eFjG4nOTjJwOn0z6Uq6pM5XFsqj5A25+QWJAxx0yP1q6baA78wR/vPv/ACD5vr604RRqAFjQAYwAo7dKAMtdWmSAPIsbSNEj7ATjkMTjAz2708aq4G8opjaT7zHGxcKRnAP97r0q+bW3K7TbxFc5xsGP88mlNvA23MMZ2nIyg4NAalO7u7i3vyBtMSxrhS2MszbQSccAU+2vpLi58nykGwHzGD55BI+XjnpVto0fO9FbcMHIzkelIkccYASNUAGBtGMD0oGZy3dyftEjNIESYopCoFxvC8Hrn60f2vL+7/0UHeu/AYn5d2PTr+laWxMFdi4JyRjv601oIW27oY22HK5UfL9KBFBNZDT+SYdpztJLcAjO/wDIYP41DJrEzxkoqxsuc9SCCuR1ArW8uPO7y1zknO0dT1pq21ugwsEaj0CCgBLu4+zwl12ltwVQSeSTjHAJqlFq7yqkgtwI/k3/AD/MCxI4GOeRV4W8IiMXlqyEklWGcknJ/WnLDEoAWNFAxwFA6dKAKVpfTXMz7hGqfZ1lQK27GSevvxUVre3TWsDkeZLOQB5hVVHyk5G3Jxx3rRSGKIsY4kQt97aoGaSO2gi/1cEac5+VAKAM+LVpCxleNBbsVAJbBTMe705HXmgavMysFt03puLAuQMBQ3GRnoa0vKiAwI0x6bR9P5UiW8EYwkMaj0CAUAUm1UiKWfyVMSZAG/5yRjtjpzUM+rXC28u2FI5Y0ZmLtxgHHygjnr0OK0/Ih3F/Jj3MNpO0ZI9KT7LbbVX7PFtXlRsGBQBV1C4mgkUpKEjWMu+0KzDnqQeq9enNNm1YRpuWNWbLjBfH3WC/1zV2SGKUqZIkcr93coOKZLZ28wcPCmXxuYKATyDyfwoApNq0il18mLdErtJ+94O0jO3jnrSvqzrllgUqxZYwXwchgp3DHHWrhsrYyI/kJ8i7VXaMDnPA9c0/yId7P5Sbm+820ZP1oDUhtZ5pJbhJ/KUxyBFCE8/KD3+tWqZ5UfmeZ5ab853bRn86fSGFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAyT7v41FUsn3fxqKgD5k1H/AJCl5/18Sf8AoRpLH7Z9si/s/wA/7UDmPyM78+2OaXUf+Qpef9fEn/oRqxoepJpOqx3skJmVI5FMecbtyMvPtzzTEEmqaxZXcqXF3dxzGRZJop3YbmXBG9T16DrU8k/iLVWOol76cSyEq6MxG4H+H6FscdM1pQeM90MEd1b7CgkVnt41/dgoqRFA2SSmD1Pf1q4vjy0F7FL/AGfKIYVcRxqUG0mVX3D0OAQcdzQByq61qSFCup3SmJPLTE7fIv8AdHPA4H5VHDf3ltFLDBdzxRzj96iSECT6gda62DxppaS2pbTWSOKLYyJEmV4UEK2c4O0nPHXoec8bIytK7KpVWYkAnoM9KALD6nqEior31ywRQqgyscAEEAc9iAfwFH9qah+6/wBPuf3Lbo/3rfIeeRzx1P5mqtFAE1xe3V4Qbq5mnIJI8xy2M49foPyqGiigAooooAKUfeH1FJSj7w+ooA+kLr/kI2f+6tbCfcFY91/yEbP/AHVrYT7opDHUUxRlQSzfnS7f9pvzoAdRTdv+0350bf8Aab86AHUU3b/tN+dG3/ab86AHUU3b/tN+dG3/AGm/OgB1FN2/7TfnRt/2m/OgB1FN2/7TfnRt/wBpvzoAdRTdv+0350bf9pvzoAdRTdv+0350bf8Aab86AHUU3b/tN+dG3/ab86AHUU3b/tN+dG3/AGm/OgB1FN2/7TfnRt/2m/OgB1FN2/7TfnRt/wBpvzoAdRTdv+0350bf9pvzoAdRTdv+0350bf8Aab86AHUU3b/tN+dG3/ab86AHUU3b/tN+dG3/AGm/OgB1FN2/7TfnRt/2m/OgB1FN2/7TfnRt/wBpvzoAdRTdv+0350bf9pvzoAdRTdv+0350bf8Aab86AHUUxRlQdzdPWl2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6imAZz8zdfWl2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6imMMAnc350+gBkn3fxqKpZPu/jUVAHzJqP/IUvP8Ar4k/9CNWND01NW1VLKSUxK8cjb/QqjMM+3HPtVfUf+Qpef8AXxJ/6Eas22nyHy3hnkSRxgbAc8jGOPXOK3pUKlZtQV7GVSrClrNmufBUklrazQX8LmeAMuMuryYdiAwHC7U6nvxUi+BSI3MmqRqSIvKkELeU25irZb2x/jis9NP1OF5bJLq8jYIY5IBuBCrklSueg54+tOhXVZ7hfJ1W8eZlCLtlbJA5A69O9b/2fiP5fxX+Zj9co9/wY6z8H3l5rV1pazrG9uFPmPGwVt2Nv0zn/DNTHwTMkfmvqMPlxoGuCsTkxZRGAAx82Q46dOaqQwah5k91DqN0JCuZ5VchiM4+Y555xSJDfwlZ01K6jOSFkDsOQMHBz6YH0p/2fif5fxX+YfXKHf8ABll/CMkupava2lyD/Z0xjRHUl5cZOeOnA59KkufBD2Qd7nWLRESVIWYIzbZGYrg46DIJz6VTgstQlMyW97dMbggTbGb94T03c85561HPFd3K7LjUriZQANsjlhx06ntzR/Z+J/l/Ff5h9cod/wAGaT+B7iC0ka6uUhmt2JucKz+Su3O3aBlm5U8HoaYngi4aOB31K1j875sMGBCfNg4IBydh4OMZGe+KSJfRzecmqXSy7t28SNuzjGc5644+lKn9oRhQmrXShGLqBI3DHqevU5P5mj+z8T/L+K/zF9dofzfgzNv7OTT7+ezmz5kEhRsqV5HseRVetJ9OaV2kkuWd2OWZhkk+pOab/ZY/57H/AL5o/s/E/wAv4r/MPrtD+b8GZ9KPvD6ir/8AZY/57H/vmlGljI/fHr/do/s/E/y/iv8AMPrtD+b8GfQF1/yEbP8A3VrYj+6Kx7r/AJCVn/urWxH90VwHYQ3ORp8xW5FqRGxE5AIi4+8c8cdea4iy8b6qdJm1GeKCaVZUh+ygMgjTYWM5G0uwcDIABwPoa7p4Yri3MM0aSxOMMjrkMPQjvUN1pOm32ftmn2txkAHzYVbIHQcjtk/nQBydt401WW5dRa2E8Ul06xGOZvlhSFZSfu/MSDx0yT2qBPiTPJpjXH9lIkzbXhR3kxIhRn4wmSwC8nG3nOa7ZNPsY7n7THZ26T4A81YgG4GBz9OPpVc6BorQtCdIsTE7+YyG3Tazf3iMdaAOXfx5qMgM1ppVq0DBvLMt0wbKwLO2QFI+62B7+1WPEeuap52krpEl1Gb6zlnWK3t0mZnAQoG3cBfmOTxXTjTrELtFlbgc8CJe67T2/ujH04qUW8CvG4hjDRKUjYKMopxkD0HA/KgDkV8X6wJDbyafYJP9oa2DyXTInmRxh5Cx2nA5wBz69KpL8QtQ2yzDT4ZEuJoltIwz7kDQCU79qknjpgfoK7WfTNPuoXhuLG2mikfzHSSJWVn/ALxBHJ96bPpGl3W/7Rp1pN5gVX3wqdwX7oPHbt6UAcrN441C50q+vbCys4Fggbat1c4lEgiEn3APmXBxwcnGelM/4Ta/tjdxywW001uJJ5d9xsjEaJGWWM7csxL8A/nXXf2VppuBcf2fa+cI/KEnkru2YxtzjpjjFM/sXSTFHCdLszHE++NDAuEbAGQMcHAHPtQBj6P4qudS1lLWWwiitbh7hLeRZSZMxEA71IAGQ3YnpWVbeOb61hb7dBa3AeedYXjmwwVLgRnzFxhRhhg+3PWu1W0tkkEiW8SupZgwQAgt9459+/rUC6PpaNOyabaK1yCs5EC/vQeobjn8aAOZuPHd0t5cJb6fby29pI/nSG4IYoswiyoCkE85xntiqVz421Sa/t2g+z29pNgoiMJJCouY4jvBHynBbgZ6+ortY9J02GIxRafaxxkbSiwqBjOcYx68/WkXSNLW4kuF020E0rBpJBCoZiCCCTjk5AP1FAGN4U8WyeJJplfT2tkEazRPkkMhJGDkD5uO2Rz14rpar21hZWckslrZwQPM26Voowpc+px1qxQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABSUtJQBz/im91G0gsl064ERkdvNWMxeeyhc/uxIQrYOCR1x0rBi8d6jHa3E7CxvEzCLUgSRvKGh8xiUCsRwDx0HPOBXbXVhZajbLDfWkF1EMMEmjDgH1wajn0XSbrP2jS7OXKqp3wKeF+6OnQdqAOX0nxveXlzvure1jtLiYLDiUholNt53zZGD6Z9z6Va0PxlLq2q2tpLZQ28V1bLLE3nFmdjGHIGFxxnGCQeM4xW9JoukyqyyaZZurBVIaBSCF+6Onbt6U6HStOt7oXUNhbRThBGJUhUMFHAGQOlAFuiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKAMLxbqF3pnh6S5sZGjn+0RRhlVScNIqnG75c4J68Vn/APCT3mnXel6ZcRm4m1HdsluZY0ePax3bxHlemNuDyeOK6ae1t7y3e3uoIriFj80cqBlPPcGoY9G0uGEwxabaxRsACqQqBwcjt2JyPfmgDjv+E/vJILSSS1ghaZEulW3uPMBjKyfI+V+U5QdPz4NTXHjzULd7OBrCzM91FGzCOZ2ETShjHk7AOwzzk846V0uneHNI0uxSzttPgEagZLRKWcgY3MccnBPPuasPpWmyXMVy+n2rTwqFilMKlkA6AHHGKAOOsPGmqP5EUsdnJd3UEEi75/Lt0zE0jfNtyCQBxzznsKv6X41uNT1C126bHHYXMyQLIZj5qu0HnDK4xjGR19DW+dE0hrc2x0qyMDEExmBdpIzg4x2yfzqwLO1DBxbQhg4cEIMhgNoP1xxn04oA4/VvGt1Z6r8iWsVjbXU0EvmTYkkZIS/K7TtUnGCMnjpzVUfEPUAWuZNPgW3tYbk3EW9w7vH5eNuVBA/eDIIz1PYZ7SXSNMnumuptOtJLh12NK8KlmXGME4zjHFJHoukwxpHFplmiRliirAoCkjBI47jg+tAFTw1rc2uWEs1xafZpYJjCyjO1sAHI3AEDnuK2KgtLK1sIBBZ20NtCCSI4UCLk9TgVPQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFADX+6adTX+6adQAyT7v41FUsn3fxqKgD5k1H/kKXn/XxJ/6Ea3tDvoNPurW8mjEwgG9Y92MsB8ufbODWDqP/ACFLz/r4k/8AQjVzw3p0Gq67BZ3Ku0TrIxCEgnajMOgJ6gdATXXhsT7By0vc569D2ttbWO0XxjZnzZWtZIp5kPneVIpWVjHs+Ytk4HB69SaX/hNLV5WMtp5ke4lULJ8vzkr27KdtZdx4AWVppbW5NtEFjaMTrleQm7LHDDBfoyg8c1B/whUDaddTC4uo5beYLie28t2TBBwhPIB+YtnhQeK6PrsP+ff4mP1Wf8/4GwfF9o8jM9pnD5jzsOxdyHGMf7Df99Utz4xt3gkSCOZGxIIy0inBcIC3sflPr97rWRF8PZWZlmu5o284xKFtCf8Alo6B254T5NxPoaq2PheK88GXmqqjvdwyOVKyDYI0xuY8e54zk5GBjNH16H/Pv8f+AH1WX8/4HTt40sPlRLWURDYSN6Zfa+4K3qMEjP6VAfF9qkX7i1KS7cI2UxB9z5U4+78pPPOTWVZ+FNMv9EtJI5ZIZ3tRcTzMpbALSZCrux0jI/Wq8Xg60ls47garIpkhEoVrbgAxGUZO7+6p/HFJY2C/5d/j/wAAHhZP7f4EV5cRXF7PPGFjSWVnVMj5QSSBUO9f7y/nWnN8PHt2iD6mknmMVxFFkjClz1YfwbG/4H7Uf8IBGl21rJqx8xd7EJbZ+VZPLyBuyTnkjsK6FmzStyfj/wAAxeXJv4vwMzev95fzo3r/AHl/OsSeLyLiWHcr+W5XcvRsHGRTMU/7Xf8AJ+P/AABf2cv5vwN7ev8AeX86UMuR8y9fWsDFAHzD6ij+1n/J+P8AwA/s5fzfgfSN1/yErT6L/OtiP7orHuv+QjZ/7q1sR/dFeIeqKiAoDlvzp3lj+8351zfjHVb3SdNsZLK4FuZbgo7koOPLcgZcEDkDt7VjL8Qr9RJEbOFpI7RJC0m6La/7vduU9B85I6A46+gB3vlj+8350eWP7zfnXLaF4wutX15bBrBY4TCH3lir/cVt2087TuIHHasuDxJ4itdKtb+4WSeS5d9iShBGRzj7i7gM4688UAd75Y/vN+dHlj+8351xEvjrVoLm+i/seOb7HJ5TLG53bt2xTt64ZipB/unvUU/xA1Dy7XGmrA11vUI27euMpuGRg4dW454x0zQB3nlj+8350eWP7zfnWP4T1G81PSGuL5t0omZc7NvAxjitugBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWB3b86PLH95vzps1zb2+3z544t5wu9wufpmpaAGeWP7zfnR5Y/vN+dOVlcZVgwzjINI0iJjcwGSAMn16UAJ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5QHdvzo8sf3m/OiWWOFC8sixoOrMcClR1kQOjBlYZBByDQAnlj+8350eWP7zfnRJLHCheV1RB1ZjgChJopGKpIjMAGIDAnB6GgA8sf3m/Ojyx/eb86a11bqzq08YMYy4Lj5R7+lAubcsqieMsy7lG8ZI9R7UAO8sf3m/Ojyx/eb86IpY5k3xSLIp/iRgRT6AGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAInQBCct+dLSyf6s0lADJPu/jUVSyfd/GoqAPmTUf+Qpef9fEn/oRqOCKea4jitkkeZ22osYJYn0GKk1H/kKXn/XxJ/6Eam0bURpWpx3bRmVAro6q21trKVOD2ODxTEQ3kF9YTPa3qTwSHDNHKSM56Ejv9aEhvblTMizyjBy+Sc4xnnvwRx71v2fifT9O0+extbK5eNlCo9xIsjMNpBVhjCrk5AHQ+/NWT48Li58yG4YvcSSwL5i7YlbZgdOq7OMf3jQBz91/a2lxy2N009uJyDJGz8tsyBnntkjFU4zMYpPLMnloA0m0naOwJ/lXVTeNYLmOcPa3MMkpdjNDIm9gXdgjEqflw4B/3RVhvHlmI0ij0yby1jVWV5FO8K6OEbjlflI/4F0oA4oOw4DsO2AaNzf3m/OusvfGVreWmoW7WczfaogiMSinIBALEcnGenOcdq5KgByySKwZZHDA5BDEEUCWRWDrI4YdGDHP502igAooooAKUfeH1FJSj7w+ooA+kLr/AJCNn/urWxH90Vj3X/IRs/8AdWtiP7opDIrq6a0tUkWLzMnBJJAUc8nAPH4d6gGs2+0tLG6AyCPPBBOByCDyPmFW3t4rmFFlUkDkYYqR+IqI6VYkj/R1GMYAJA7f/Ej8qAK4122KA+VIJShbyyBnjJA/HBqRdVTyoi8ZErsFKeh+XPPtuFTDTrRW3LCAcEHDHBBz2/E0HTrMzed5I38c5Pt2/wCAj8qAIJNUEd7Pb+Wg8nbkljk5x2xjv60HW7MMoYSAldwynOOcce+DVxraFvM3Rg+YQX9yMY/kKYLG2WRHWIBkXaME9Oeo79TQBXOt2QjkkVmZY87sL74/oaltL9buWREQgIMhs/eGSP6Un9k2Hl+WLZQuAPlJHQEDp7Ej8aeljbxOjxp5ZU5+U4z16/maAKtxrIgWT9zl4i29S+AoBABzjvuB/Oo/7fVc+ZbkAIWDB8qxBIABx3wSD3rQaytnkkkaFS0oUOf723pRPZW10HE8KyBwA2e4ByPyNADL++Fiiu0ZdWyODjnBIH44xVaLWo5AGMLgEAYHzEt8uVx7FgKuGzheFYZVMqq+8bzk7gcg/nSLYWq42wKMOXGP7xO4n8wDQBVOu2fJDEqpO5iOgAbkevK4pya1aOQB5mdrMfl6Yzn69O2am/s2zww8gEMSSCSRznOB26n86P7NtDszETszty7HGc89evJ5oAltrhLqBZo87W6ZqWo4LeK2j8uFNq5JxnOSeSakoAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAztSsLi6u7SeBwPILbh5hTOcdwD6dKo3Wh38sUqRXi8ufKLMwKJg7eeeQzH8AORit+ipcUyHBMwpNI1EFlhuYlVmLkktwfn4wOx3jP0qODQLuL52nj8wqVDBjlV3lgAcDjB9q6GilyIPZo5i90e9gVI7bfMGICqHbEZwmWznrkN+f59PRRTUUhxilsFFFFUUFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAFW/t5LiFBFs3pKrgOSAcHOKz/7Gu/MDLdCPIY/uyQI2JYnaMcjkenStqigCglpMlgYVjhV92QA7ED3DHkHv0qOz0+axliZRG/7lIZCOOmTn37CtOigDKuNOuLi4mkIhA48gqxBU5BJPHUkDnnoOOtQDQZcorSqUxmTk/M2G9unzdiPpW5RQBS02zltIpPOk3ySPuODnHAHoPT0q7RRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAyT/VmkpZP9WaSgBkn3fxqKpZPu/jUVAHzLqQI1W8BGCLiT/wBCNVq7vx74QhsdTl1G3uiEu2MphMedrHrg56Z9q4Q8GmDCiiigQUUUUAFFFFABRRRQAUUUUAFKPvD6ikpR94fUUAfTMkVu00MkkgWRFXaNwGfT9avx/dFU2tLed7eeWFHlgGY3YcrkdquR/dFIY6NTsHzGnbT/AH2/Sub8X65eaDZ6ZcWZTEl6kcyMud8ZDZXPY9Oa5y9+IWq2dm8SxQSTLE5Ezj+LMhU4GBgBAMd85zQB6PtP99v0o2n++36VwkvxFuYLp7dtPicoCSwkIziXZ0wccc1UPxG1K6tdkNtBBKYZZDIMtjb5ZAAP/XTvnp70AejbT/fb9KNp/vt+lcpJruoapo+k3NrP/Z7300oYxoshVUjkYD5gR1QZOKwovibqC2iSSWNu7BwrEEjdiNXY+2d3HpjvQB6RtP8Afb9KNp/vt+lcBZ/EK/D20dzaQS+Y0m9lJQkb5AoHXGBHz1zntUFr8QdUvrqNfJhhj2IzCMckmSMcE5x8rkdPfjsAejbT/fb9KNp/vt+lect8UL0WiTf2bBlpDkbz93Yr4+vOM/jjtXo4OQDQAm0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igCORTsPzE0Usn+rNJQAyT7v41Akkcn3JFbjPynP8AnofyqeT7v41neTBZmX7PAkTTtvkZRjcfWmho/9k="></p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-he6fz"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-he6fz "><div class="eb-advance-heading-wrapper eb-advance-heading-he6fz button-1 undefined" data-id="eb-advance-heading-he6fz"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Lưu ý khi Renew License Sophos Firewall </span></h2></div></div></div>



<p>Đối với các lần gia hạn (renew) license trong tương lai, cần lưu ý</p>



<p>&#8211; License Number: chỉ dùng để tracking và support, không dùng để activate.</p>



<p>&#8211; License Key: bắt buộc để kích hoạt hoặc renew license.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0vyql"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0vyql "><div class="eb-advance-heading-wrapper eb-advance-heading-0vyql button-1 undefined" data-id="eb-advance-heading-0vyql"><h2 class="eb-ah-title"><span class="first-title">1. Cơ chế đồng bộ license khi renew:</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Trong hầu hết các trường hợp, nếu Sophos Firewall đã được liên kết đúng Sophos Central account, license sau khi renew sẽ tự động đồng bộ xuống thiết bị mà không cần thao tác thủ công.</li>



<li>Tuy nhiên, nếu license không tự đồng bộ và vẫn hiển thị trạng thái <strong>Expired</strong>, bạn có thể thực hiện các bước sau:
<ul class="wp-block-list">
<li>Kiểm tra license trong Sophos Central hoặc Sophos Partner Portal để xác định License Key tương ứng</li>



<li>Thực hiện apply License Key thủ công cho thiết bị Firewall (theo hướng dẫn ở Mục II.3)</li>
</ul>
</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-zrgo3"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-zrgo3 "><div class="eb-advance-heading-wrapper eb-advance-heading-zrgo3 button-1 undefined" data-id="eb-advance-heading-zrgo3"><h2 class="eb-ah-title"><span class="first-title">2. Trường hợp không nhận được License Key:</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Nếu email gia hạn không chứa License Key, khuyến nghị:
<ul class="wp-block-list">
<li>Kiểm tra lại thông tin license trong Sophos Portal</li>



<li>Hoặc liên hệ Sophos Support / Partner để xác nhận chính xác License Key trước khi apply</li>
</ul>
</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-huong-dan-activate-renew-license-sophos-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng Dẫn NAT Forwarding (Đổi Port) Sophos Firewall Version 21</title>
		<link>https://vacif.com/huong-dan-nat-forwarding-doi-port-sophos-firewall-version21/</link>
					<comments>https://vacif.com/huong-dan-nat-forwarding-doi-port-sophos-firewall-version21/#respond</comments>
		
		<dc:creator><![CDATA[Long Nguyen]]></dc:creator>
		<pubDate>Fri, 14 Nov 2025 03:20:57 +0000</pubDate>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=27950</guid>

					<description><![CDATA[Trong môi trường thực tế, đôi khi chúng ta không muốn (hoặc không thể) mở đúng port gốc của một dịch vụ ra ngoài Internet. Thay vào đó, chúng ta sẽ chuyển hướng port ngoài sang port nội bộ để: Kỹ thuật này gọi là NAT Forwarding, hay còn gọi là Port Forwarding hoặc PAT [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về NAT Forwarding</span></h2></div></div></div>



<p>Trong môi trường thực tế, đôi khi chúng ta không muốn (hoặc không thể) mở đúng port gốc của một dịch vụ ra ngoài Internet. Thay vào đó, chúng ta sẽ chuyển hướng port ngoài sang port nội bộ để:</p>



<ul class="wp-block-list">
<li><strong>Tăng bảo mật</strong>: tránh sử dụng những port phổ biến dễ bị quét (ví dụ: 3389 – RDP, 21 – FTP…)</li>



<li><strong>Giải quyết xung đột port</strong>: khi có nhiều dịch vụ trong mạng nội bộ cùng sử dụng một port giống nhau, nhưng cần ánh xạ ra ngoài bằng port khác nhau</li>



<li><strong>Giảm rủi ro tấn công tự động</strong>, đặc biệt là các loại botnet hay brute force</li>
</ul>



<p>Kỹ thuật này gọi là NAT Forwarding, hay còn gọi là Port Forwarding hoặc PAT – Port Address Translation. Trên Sophos Firewall, việc cấu hình NAT Forwarding cực kỳ linh hoạt, dễ dàng thông qua giao diện đồ họa.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-rjcs2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-rjcs2 "><div class="eb-advance-heading-wrapper eb-advance-heading-rjcs2 button-1 undefined" data-id="eb-advance-heading-rjcs2"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Yêu cầu:</span></h2></div></div></div>



<p>Doanh nghiệp có một máy chủ nội bộ sử dụng Remote Desktop Protocol (RDP) với port mặc định là 3389, nhưng vì lý do bảo mật, muốn người dùng bên ngoài truy cập bằng port 1606 thay vì 3389.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wacy1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wacy1 "><div class="eb-advance-heading-wrapper eb-advance-heading-wacy1 button-1 undefined" data-id="eb-advance-heading-wacy1"><h2 class="eb-ah-title"><span class="first-title">2. Thông tin tình huống cấu hình:</span></h2></div></div></div>



<ul class="wp-block-list">
<li>IP WAN của doanh nghiệp: 123.20.40.173</li>



<li>Máy chủ nội bộ cần truy cập: 192.168.206.104</li>



<li>Port dịch vụ nội bộ (gốc): 3389 (Remote Desktop)</li>



<li>Port truy cập từ ngoài Internet: 1606</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-aq9re"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-aq9re "><div class="eb-advance-heading-wrapper eb-advance-heading-aq9re button-1 undefined" data-id="eb-advance-heading-aq9re"><h2 class="eb-ah-title"><span class="first-title">3. Sơ đồ tình huống cấu hình:</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="440" src="https://vacif.com/wp-content/uploads/2025/11/image-90.png" alt="" class="wp-image-27959" srcset="https://vacif.com/wp-content/uploads/2025/11/image-90.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-90-300x135.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-90-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-urf9e"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-urf9e "><div class="eb-advance-heading-wrapper eb-advance-heading-urf9e button-1 undefined" data-id="eb-advance-heading-urf9e"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Hướng dẫn cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-uoku1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-uoku1 "><div class="eb-advance-heading-wrapper eb-advance-heading-uoku1 button-1 undefined" data-id="eb-advance-heading-uoku1"><h2 class="eb-ah-title"><span class="first-title">1. Thêm IP Host</span></h2></div></div></div>



<p>Để NAT port dịch vụ ra bên ngoài, trước hết các bạn cần định nghĩa IP của máy chủ nội bộ và dịch vụ cần mở. Các bạn click vào menu Host and services trên Dashboard, tại mục IP host các bạn click chọn Add.</p>



<p>Trong bảng thông tin này, các bạn cần điền:</p>



<ul class="wp-block-list">
<li><strong>Name</strong>: Đặt tên cho host cần mở port</li>



<li><strong>Type</strong>: chọn&nbsp;<strong>IP</strong></li>



<li><strong>IP address</strong>: Nhập IP nội bộ của host</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-91.png" alt="" class="wp-image-27960" srcset="https://vacif.com/wp-content/uploads/2025/11/image-91.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-91-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-91-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yvhlv"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yvhlv "><div class="eb-advance-heading-wrapper eb-advance-heading-yvhlv button-1 undefined" data-id="eb-advance-heading-yvhlv"><h2 class="eb-ah-title"><span class="first-title">2. Định nghĩa dịch vụ</span></h2></div></div></div>



<p>Tiếp theo, bạn cần định nghĩa các dịch vụ sẽ sử dụng</p>



<p>Vào Services và click chọn Add</p>



<ul class="wp-block-list">
<li><strong>Name</strong>: Remote_Desktop</li>



<li><strong>Type</strong>: TCP/UDP</li>



<li><strong>Destination Port</strong>: 3389</li>



<li>tab <strong>Source Port</strong>: Để mặc định (1:65535), trừ khi có yêu cầu cụ thể</li>
</ul>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-92.png" alt="" class="wp-image-27961" srcset="https://vacif.com/wp-content/uploads/2025/11/image-92.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-92-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-92-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Vào <strong>Services </strong>và click chọn <strong>Add</strong><strong></strong></p>



<ul class="wp-block-list">
<li><strong>Name</strong>: Forwarding_1606</li>



<li><strong>Type</strong>: TCP/UDP</li>



<li><strong>Destination Port</strong>: 1606</li>



<li>tab <strong>Source Port</strong>: Để mặc định (1:65535), trừ khi có yêu cầu cụ thể</li>
</ul>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="441" src="https://vacif.com/wp-content/uploads/2025/11/image-93.png" alt="" class="wp-image-27962" srcset="https://vacif.com/wp-content/uploads/2025/11/image-93.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-93-300x136.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-93-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0emgw"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0emgw "><div class="eb-advance-heading-wrapper eb-advance-heading-0emgw button-1 undefined" data-id="eb-advance-heading-0emgw"><h2 class="eb-ah-title"><span class="first-title">3. Tạo NAT Rule</span></h2></div></div></div>



<p>Tiến hành tạo NAT Policy để ánh xạ port từ IP WAN về máy chủ nội bộ.</p>



<p>Để tạo vào PROTECT > Rules and policies > NAT rules > Add NAT rule > New NAT rule.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-94.png" alt="" class="wp-image-27963" srcset="https://vacif.com/wp-content/uploads/2025/11/image-94.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-94-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-94-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-9iqr2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-9iqr2 "><div class="eb-advance-heading-wrapper eb-advance-heading-9iqr2 button-1 undefined" data-id="eb-advance-heading-9iqr2"><h2 class="eb-ah-title"><span class="first-title">Cấu hình các thông số như sau:</span></h2></div></div></div>



<figure class="wp-block-table"><table><tbody><tr><td>Rule status</td><td>ON</td></tr><tr><td>Rule name</td><td>VACIF_NAT_RDP</td></tr><tr><td>Rule position</td><td>Top</td></tr><tr><td>Original source</td><td>Any</td></tr><tr><td>Original destination</td><td>#Port1 (WAN interface)</td></tr><tr><td>Original service</td><td>Forwarding_1606</td></tr><tr><td>Translated source (SNAT)</td><td>Original</td></tr><tr><td>Translated destination (DNAT)</td><td>WINDOW_SERVER_2025 (IP Host nội bộ)</td></tr><tr><td>Translated service (PAT)</td><td>REMOTE_DESKTOP (Dịch vụ đã tạo)</td></tr><tr><td>Inbound interface</td><td>VNPT_Port1 (GATEWAY PORT1)</td></tr><tr><td>Outbound interface</td><td>Any</td></tr></tbody></table></figure>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu rule.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="441" src="https://vacif.com/wp-content/uploads/2025/11/image-95.png" alt="" class="wp-image-27964" srcset="https://vacif.com/wp-content/uploads/2025/11/image-95.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-95-300x136.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-95-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-rqhak"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-rqhak "><div class="eb-advance-heading-wrapper eb-advance-heading-rqhak button-1 undefined" data-id="eb-advance-heading-rqhak"><h2 class="eb-ah-title"><span class="first-title">4. Tạo Firewall Rule</span></h2></div></div></div>



<p><strong>Mặc định</strong>, Sophos Firewall sẽ <strong>chặn các lưu lượng truy cập từ Internet vào mạng nội bộ (LAN)</strong>.<br>Vì vậy, sau khi cấu hình NAT policy, bạn cần tạo thêm một <strong>Firewall Rule</strong> để cho phép lưu lượng sử dụng dịch vụ (VD: Remote Desktop) được đi vào.</p>



<p>Để tạo vào <strong>PROTECT &gt; Rules and policies &gt; Add firewall rule &gt; New firewall rule</strong><strong></strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-96.png" alt="" class="wp-image-27965" srcset="https://vacif.com/wp-content/uploads/2025/11/image-96.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-96-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-96-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Cấu hình các thông số như sau</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Rule name</strong></td><td>VACIF_NAT_RDP_RULE</td></tr><tr><td><strong>Rule pos</strong><strong>ition</strong></td><td>Top</td></tr><tr><td><strong>Source zones</strong></td><td>WAN</td></tr><tr><td><strong>Source network</strong></td><td>Any</td></tr><tr><td><strong>Destination zones</strong></td><td>LAN</td></tr><tr><td><strong>Destination network</strong></td><td>#Port1</td></tr><tr><td><strong>Service</strong></td><td>Forwarding_1606</td></tr><tr><td><strong>Action</strong></td><td>Accept</td></tr><tr><td><strong>Log traffic</strong></td><td>Tích chọn để giám sát</td></tr></tbody></table></figure>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu rule.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="441" src="https://vacif.com/wp-content/uploads/2025/11/image-97.png" alt="" class="wp-image-27966" srcset="https://vacif.com/wp-content/uploads/2025/11/image-97.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-97-300x136.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-97-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-1cnab"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-1cnab "><div class="eb-advance-heading-wrapper eb-advance-heading-1cnab button-1 undefined" data-id="eb-advance-heading-1cnab"><h2 class="eb-ah-title"><span class="first-title">5. Kiểm tra NAT Forwarding</span></h2></div></div></div>



<p>Sau khi cấu hình xong, bạn có thể kiểm tra xem port đã mở thành công chưa bằng cách:</p>



<ul class="wp-block-list">
<li>Truy cập trang:<br><a href="https://www.yougetsignal.com/tools/open-ports/">https://www.yougetsignal.com/tools/open-ports/</a></li>



<li>Nhập port <strong>1606</strong>, nhấn <strong>Check</strong>.<br>Nếu hiển thị <strong>&#8220;Port is open&#8221;</strong>, nghĩa là NAT thành công.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="636" src="https://vacif.com/wp-content/uploads/2025/11/image-98.png" alt="" class="wp-image-27967" srcset="https://vacif.com/wp-content/uploads/2025/11/image-98.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-98-300x196.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-98-768x501.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/huong-dan-nat-forwarding-doi-port-sophos-firewall-version21/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng Dẫn Cấu Hình QoS Ưu Tiên Microsoft Teams Trên Sophos Firewall</title>
		<link>https://vacif.com/huong-dan-cau-hinh-qos-uu-tien-microsoft-teams-tren-sophos-firewall/</link>
					<comments>https://vacif.com/huong-dan-cau-hinh-qos-uu-tien-microsoft-teams-tren-sophos-firewall/#respond</comments>
		
		<dc:creator><![CDATA[Long Nguyen]]></dc:creator>
		<pubDate>Thu, 21 Aug 2025 03:38:03 +0000</pubDate>
				<category><![CDATA[Case study]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://new.vacif.com/?p=26372</guid>

					<description><![CDATA[Microsoft Teams hiện đang là nền tảng phổ biến cho các cuộc họp trực tuyến (Meeting) và làm việc từ xa. Để đảm bảo chất lượng đường truyền cho các cuộc họp Teams, việc thiết lập QoS (Quality of Service) trên firewall là rất cần thiết. Trong bài viết này, chúng ta sẽ thực hiện [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-7iftb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-7iftb "><div class="eb-advance-heading-wrapper eb-advance-heading-7iftb button-1 undefined" data-id="eb-advance-heading-7iftb"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Giới thiệu</span></h2></div></div></div>



<p>Microsoft Teams hiện đang là nền tảng phổ biến cho các cuộc họp trực tuyến (Meeting) và làm việc từ xa. Để đảm bảo chất lượng đường truyền cho các cuộc họp Teams, việc thiết lập QoS (Quality of Service) trên firewall là rất cần thiết.</p>



<p>Trong bài viết này, chúng ta sẽ thực hiện cấu hình QoS ưu tiên lưu lượng Microsoft Teams trên thiết bị <strong>Sophos Firewall</strong>.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4es7f"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4es7f "><div class="eb-advance-heading-wrapper eb-advance-heading-4es7f button-1 undefined" data-id="eb-advance-heading-4es7f"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Yêu cầu thực hiện</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Thiết bị Sophos Firewall đã hoạt động bình thường.</li>



<li>Quyền truy cập quản trị Sophos Central hoặc trực tiếp trên Firewall.</li>



<li>Đường truyền internet ổn định.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-d44tw"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-d44tw "><div class="eb-advance-heading-wrapper eb-advance-heading-d44tw button-1 undefined" data-id="eb-advance-heading-d44tw"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Các bước thực hiện</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0y5uy"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0y5uy "><div class="eb-advance-heading-wrapper eb-advance-heading-0y5uy button-1 undefined" data-id="eb-advance-heading-0y5uy"><h2 class="eb-ah-title"><span class="first-title">Bước 1: Đăng nhập Firewall Sophos và tạo application Team</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đăng nhập vào Firewall Sophos.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-151.png" alt="" class="wp-image-26379" srcset="https://vacif.com/wp-content/uploads/2025/08/image-151.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-151-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-151-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-151-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Tiếp theo chọn Application-&gt;Application Filter -&gt; Add để tạo <strong>Microsoft Teams</strong> .</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-152.png" alt="" class="wp-image-26380" srcset="https://vacif.com/wp-content/uploads/2025/08/image-152.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-152-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-152-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Nhập name là: Mircrosoft Teams</li>
</ul>



<p>Nhấn add để vào Application filter policy rules</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-153.png" alt="" class="wp-image-26381" srcset="https://vacif.com/wp-content/uploads/2025/08/image-153.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-153-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-153-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Ở chỗ Category chọn: Conferencing -&gt; Select individual application -&gt; Mircrosoft Teams -&gt; Action chọn: Allow  -&gt; Schedule chọn: All the time -&gt; Save.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-154.png" alt="" class="wp-image-26382" srcset="https://vacif.com/wp-content/uploads/2025/08/image-154.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-154-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-154-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Xong phần thì nó sẽ hiện ra như thế này rồi mình nhấn Save.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-155.png" alt="" class="wp-image-26384" srcset="https://vacif.com/wp-content/uploads/2025/08/image-155.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-155-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-155-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-6nyg1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-6nyg1 "><div class="eb-advance-heading-wrapper eb-advance-heading-6nyg1 button-1 undefined" data-id="eb-advance-heading-6nyg1"><h2 class="eb-ah-title"><span class="first-title">Bước 2: Tạo Traffic Shaping Policy</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chọn vào System service-&gt;Traffic Shaping-&gt; Add</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-156.png" alt="" class="wp-image-26385" srcset="https://vacif.com/wp-content/uploads/2025/08/image-156.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-156-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-156-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Sau khi nhấn add-&gt;nhập những thông tin như này theo thứ tự ở trên hình ảnh</p>



<ul class="wp-block-list">
<li>Name : Team_QoS</li>



<li>Policy association: Rules</li>



<li>Rule Type: Guarantee</li>



<li>Limit upload/download separately: Enable</li>



<li>Priority: 0 – [ Real Time – e.g. VoIP] (highest)</li>



<li>Guarantee – limit upload: ( 400-500) KBps</li>



<li>Guarantee – limit download: (400-500) KBps</li>



<li>Bandwidth usage type: Individual</li>



<li>Save</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="468" src="https://vacif.com/wp-content/uploads/2025/08/image-157-1024x468.png" alt="" class="wp-image-26386" srcset="https://vacif.com/wp-content/uploads/2025/08/image-157-1024x468.png 1024w, https://vacif.com/wp-content/uploads/2025/08/image-157-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-157-768x351.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-157.png 1058w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>&nbsp;Sau khi nhập những bước trên xong thì chúng ta sẽ tạo 1 cái rule để Bước 1 và Bước 2 có thể chạy</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-d1y8k"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-d1y8k "><div class="eb-advance-heading-wrapper eb-advance-heading-d1y8k button-1 undefined" data-id="eb-advance-heading-d1y8k"><h2 class="eb-ah-title"><span class="first-title">Bước 3: Tạo Rule Policy để chạy QoS</span></h2></div></div></div>



<p>Muốn tạo được Rule Policy thì ta vào phần Protect-&gt;Rule and policies-&gt;Firewall rules-&gt; Add firewall rule-&gt;New firewall rules</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="424" src="https://vacif.com/wp-content/uploads/2025/08/image-158.png" alt="" class="wp-image-26387" srcset="https://vacif.com/wp-content/uploads/2025/08/image-158.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-158-300x130.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-158-768x334.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Sau khi nhấn New firewall rule thì firewall sẽ hiện ra trang edit firewall rule để mình điền thông rule</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="294" src="https://vacif.com/wp-content/uploads/2025/08/image-159.png" alt="" class="wp-image-26388" srcset="https://vacif.com/wp-content/uploads/2025/08/image-159.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-159-300x90.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-159-768x232.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Rule name: Allow_Teams_Meeting</li>



<li>Action: Accept</li>



<li>Tích vào Log firewall traffic</li>



<li>Rule group: None</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="349" src="https://vacif.com/wp-content/uploads/2025/08/image-160.png" alt="" class="wp-image-26389" srcset="https://vacif.com/wp-content/uploads/2025/08/image-160.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-160-300x107.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-160-768x275.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Source Zone: LAN</li>



<li>Source networks and devices: Khuyến khích chọn IP và subnet cố định, không nên để any ở mục này. Ở đây tôi sẽ để IP của máy mình.</li>



<li>Destination Zones: WAN</li>



<li>Destination networks: Any</li>



<li>Service: Any</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="779" height="193" src="https://vacif.com/wp-content/uploads/2025/08/image-23.jpg" alt="" class="wp-image-26375" srcset="https://vacif.com/wp-content/uploads/2025/08/image-23.jpg 779w, https://vacif.com/wp-content/uploads/2025/08/image-23-300x74.jpg 300w, https://vacif.com/wp-content/uploads/2025/08/image-23-768x190.jpg 768w" sizes="auto, (max-width: 779px) 100vw, 779px" /></figure>



<p>Kéo xuống dưới sẽ thấy phần Other security features trong phần này thì điền như sau:</p>



<ul class="wp-block-list">
<li>Identify and control applications (App control): Chọn Mircrosoft Teams mà nãy mình đã tạo ở Application (Bước 1).</li>



<li>Shape traffic: Chọn Teams-Qos mà nãy mình đã tạo ở Traffic Shaping Policy (Bước 2).</li>



<li>Tích vào Apply application-base traffic shaping policy</li>



<li>Cuối cùng là chọn Save.</li>
</ul>



<p>Khi xong hết những cấu hình ở trên thì tiếp theo mình sẽ vào bước test xem cấu hình của mình đã chạy hay chưa.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-f9157"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-f9157 "><div class="eb-advance-heading-wrapper eb-advance-heading-f9157 button-1 undefined" data-id="eb-advance-heading-f9157"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Kết quả</span></h2></div></div></div>



<p>Ở đây em sẽ test với mức băng thông mình đã quy định là 400KBps ở trên bước 2, mình sẽ vào Teams để download 1 file mà mình đã tạo.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-161.png" alt="" class="wp-image-26390" srcset="https://vacif.com/wp-content/uploads/2025/08/image-161.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-161-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-161-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-161-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-162.png" alt="" class="wp-image-26391" srcset="https://vacif.com/wp-content/uploads/2025/08/image-162.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-162-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-162-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-162-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Tiếp theo sẽ tang băng thông lên thành 4000KBps tức là 4MBps để xem băng thông.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-163.png" alt="" class="wp-image-26392" srcset="https://vacif.com/wp-content/uploads/2025/08/image-163.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-163-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-163-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-164.png" alt="" class="wp-image-26393" srcset="https://vacif.com/wp-content/uploads/2025/08/image-164.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-164-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-164-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-164-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-165.png" alt="" class="wp-image-26394" srcset="https://vacif.com/wp-content/uploads/2025/08/image-165.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-165-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-165-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-165-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Nếu mà kết quả như trên mình đã làm thành công với QoS rồi nhé. Chúc các bạn thành công nhé.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/huong-dan-cau-hinh-qos-uu-tien-microsoft-teams-tren-sophos-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
