{"id":20694,"date":"2024-10-17T14:54:33","date_gmt":"2024-10-17T07:54:33","guid":{"rendered":"https:\/\/thegioifirewall.com\/?p=20694"},"modified":"2025-03-24T07:27:21","modified_gmt":"2025-03-24T07:27:21","slug":"nhung-cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21","status":"publish","type":"post","link":"https:\/\/vacif.com\/en\/nhung-cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21\/","title":{"rendered":"Nh\u1eefng C\u1ea3i Ti\u1ebfn V\u1ec1 Kh\u1ea3 N\u0103ng M\u1edf R\u1ed9ng V\u00e0 Tr\u1ea3i Nghi\u1ec7m Ng\u01b0\u1eddi D\u00f9ng Trong Sophos Firewall Phi\u00ean B\u1ea3n 21"},"content":{"rendered":"\n<p>Sophos v\u1eeba gi\u1edbi thi\u1ec7u b\u1ea3n c\u1eadp nh\u1eadt l\u1edbn cho t\u01b0\u1eddng l\u1eeda c\u1ee7a h\u1ecd v\u1edbi phi\u00ean b\u1ea3n Sophos Firewall 21 (V21), mang \u0111\u1ebfn nhi\u1ec1u c\u1ea3i ti\u1ebfn v\u1ec1 kh\u1ea3 n\u0103ng m\u1edf r\u1ed9ng v\u00e0 tr\u1ea3i nghi\u1ec7m ng\u01b0\u1eddi d\u00f9ng (UX). Nh\u1eefng n\u00e2ng c\u1ea5p n\u00e0y bao g\u1ed3m c\u1ea3i ti\u1ebfn VPN, c\u1ea3i thi\u1ec7n qu\u1ea3n l\u00fd \u0111\u1ecbnh tuy\u1ebfn t\u0129nh v\u00e0 \u0111\u1ed9ng, c\u00f9ng v\u1edbi kh\u1ea3 n\u0103ng t\u00edch h\u1ee3p Google Workspace, nh\u1eb1m m\u1ee5c ti\u00eau n\u00e2ng cao hi\u1ec7u su\u1ea5t v\u00e0 t\u1ed1i \u01b0u h\u00f3a c\u00e1c t\u00e1c v\u1ee5 qu\u1ea3n tr\u1ecb. Trong b\u00e0i vi\u1ebft n\u00e0y, ch\u00fang ta s\u1ebd kh\u00e1m ph\u00e1 chi ti\u1ebft t\u1eebng t\u00ednh n\u0103ng m\u1edbi v\u00e0 c\u00e1ch ch\u00fang gi\u00fap t\u0103ng c\u01b0\u1eddng hi\u1ec7u su\u1ea5t ho\u1ea1t \u0111\u1ed9ng c\u1ee7a h\u1ec7 th\u1ed1ng.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>C\u1ea3i Thi\u1ec7n Tr\u1ea3i Nghi\u1ec7m Ng\u01b0\u1eddi D\u00f9ng (UX) VPN<\/strong><\/li>\n<\/ol>\n\n\n\n<p>M\u1ed9t trong nh\u1eefng c\u1ea3i ti\u1ebfn quan tr\u1ecdng nh\u1ea5t c\u1ee7a Sophos Firewall V21 l\u00e0 c\u00e1c c\u1ea3i ti\u1ebfn v\u1ec1 tr\u1ea3i nghi\u1ec7m ng\u01b0\u1eddi d\u00f9ng (UX) li\u00ean quan \u0111\u1ebfn VPN. Sophos \u0111\u00e3 gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng k\u00edch ho\u1ea1t v\u00e0 h\u1ee7y k\u00edch ho\u1ea1t h\u00e0ng lo\u1ea1t c\u00e1c k\u1ebft n\u1ed1i VPN, gi\u00fap vi\u1ec7c qu\u1ea3n l\u00fd tr\u1edf n\u00ean thu\u1eadn ti\u1ec7n h\u01a1n cho qu\u1ea3n tr\u1ecb vi\u00ean. \u0110i\u1ec1u n\u00e0y \u0111\u1eb7c bi\u1ec7t h\u1eefu \u00edch khi ph\u1ea3i x\u1eed l\u00fd nhi\u1ec1u k\u1ebft n\u1ed1i c\u00f9ng l\u00fac, gi\u1ea3m thi\u1ec3u th\u1eddi gian qu\u1ea3n l\u00fd v\u00e0 t\u0103ng hi\u1ec7u su\u1ea5t.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/uploads.thegioifirewall.com\/2024\/10\/cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21.png\" alt=\"\" class=\"wp-image-20710\"\/><\/figure>\n\n\n\n<p>Tr\u00ean trang qu\u1ea3n l\u00fd VPN, t\u00ednh n\u0103ng l\u1ecdc \u0111\u00e3 \u0111\u01b0\u1ee3c c\u1ea3i ti\u1ebfn, gi\u00fap ng\u01b0\u1eddi d\u00f9ng d\u1ec5 d\u00e0ng t\u00ecm ki\u1ebfm v\u00e0 truy c\u1eadp th\u00f4ng tin tr\u00ean nhi\u1ec1u trang kh\u00e1c nhau. Sophos c\u0169ng \u0111\u00e3 th\u00eam t\u00ednh n\u0103ng t\u00ecm ki\u1ebfm theo v\u0103n b\u1ea3n t\u1ef1 do v\u00e0 t\u00ecm ki\u1ebfm d\u1ef1a tr\u00ean gi\u00e1 tr\u1ecb v\u00e0o c\u1ea5u h\u00ecnh VPN. \u0110i\u1ec1u n\u00e0y cho ph\u00e9p ng\u01b0\u1eddi d\u00f9ng d\u1ec5 d\u00e0ng t\u00ecm ki\u1ebfm c\u00e1c m\u1ea1ng, subnet, ho\u1eb7c ng\u01b0\u1eddi d\u00f9ng cho c\u1ea3 VPN truy c\u1eadp t\u1eeb xa v\u00e0 VPN site-to-site (k\u1ebft n\u1ed1i gi\u1eefa c\u00e1c \u0111\u1ecba \u0111i\u1ec3m). V\u00ed d\u1ee5, khi th\u00eam m\u1ed9t m\u1ee5c m\u1edbi d\u01b0\u1edbi ph\u1ea7n Subnet Local, b\u1ea1n c\u00f3 th\u1ec3 t\u00ecm ki\u1ebfm ngay c\u00e1c t\u00f9y ch\u1ecdn ph\u00f9 h\u1ee3p v\u1edbi t\u1eeb kh\u00f3a &#8220;20.20&#8221;, gi\u00fap t\u00ecm ki\u1ebfm nhanh ch\u00f3ng c\u00e1c m\u1ea1ng v\u00e0 subnet.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/uploads.thegioifirewall.com\/2024\/10\/cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21-1.png\" alt=\"\u1ea2nh c\u00f3 ch\u1ee9a v\u0103n b\u1ea3n, ph\u1ea7n m\u1ec1m, Bi\u1ec3u t\u01b0\u1ee3ng m\u00e1y t\u00ednh, s\u1ed1\"\/><\/figure>\n\n\n\n<p>Ngo\u00e0i ra, Sophos \u0111\u00e3 th\u00eam b\u1ed9 l\u1ecdc cho c\u00e1c giao di\u1ec7n XFRM trong giao di\u1ec7n trang qu\u1ea3n l\u00fd VPN. \u0110i\u1ec1u n\u00e0y gi\u00fap \u0111\u01a1n gi\u1ea3n h\u00f3a vi\u1ec7c qu\u1ea3n l\u00fd v\u00e0 t\u00ecm ki\u1ebfm c\u00e1c giao di\u1ec7n ph\u00f9 h\u1ee3p v\u1edbi VPN d\u1ef1a tr\u00ean RB, gi\u1ea3i quy\u1ebft c\u00e1c th\u00e1ch th\u1ee9c khi x\u00e2y d\u1ef1ng VPN tr\u00ean c\u00e1c giao di\u1ec7n VLAN v\u00e0 WAN.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/uploads.thegioifirewall.com\/2024\/10\/cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21-2.png\" alt=\"\u1ea2nh c\u00f3 ch\u1ee9a v\u0103n b\u1ea3n, \u1ea3nh ch\u1ee5p m\u00e0n h\u00ecnh, ph\u1ea7n m\u1ec1m, Bi\u1ec3u t\u01b0\u1ee3ng m\u00e1y t\u00ednh\n\nM\u00f4 t\u1ea3 \u0111\u01b0\u1ee3c t\u1ea1o t\u1ef1 \u0111\u1ed9ng\"\/><\/figure>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>H\u1ed7 Tr\u1ee3 DHCP Relay Qua Giao Di\u1ec7n XFRM Tunnel<\/strong><\/li>\n<\/ol>\n\n\n\n<p>M\u1ed9t t\u00ednh n\u0103ng \u0111\u00e1ng ch\u00fa \u00fd kh\u00e1c trong Sophos Firewall V21 l\u00e0 h\u1ed7 tr\u1ee3 cho t\u00ednh n\u0103ng DHCP relay qua c\u00e1c giao di\u1ec7n XFRM tunnel. T\u00ednh n\u0103ng n\u00e0y cho ph\u00e9p c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean tri\u1ec3n khai DHCP relay cho c\u00e1c m\u00e1y ch\u1ee7 n\u1eb1m ph\u00eda sau c\u00e1c t\u01b0\u1eddng l\u1eeda t\u1eeb xa, m\u1ed9t \u0111i\u1ec1u tr\u01b0\u1edbc \u0111\u00e2y kh\u00f4ng th\u1ec3 th\u1ef1c hi\u1ec7n \u0111\u01b0\u1ee3c trong c\u00e1c tri\u1ec3n khai SD-WAN. Tr\u01b0\u1edbc khi c\u00f3 b\u1ea3n c\u1eadp nh\u1eadt n\u00e0y, c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean ph\u1ea3i d\u1ef1a v\u00e0o c\u00e1c VPN d\u1ef1a tr\u00ean ch\u00ednh s\u00e1ch \u0111\u1ec3 \u0111\u00e1p \u1ee9ng c\u00e1c tr\u01b0\u1eddng h\u1ee3p s\u1eed d\u1ee5ng nh\u1ea5t \u0111\u1ecbnh. Tuy nhi\u00ean, v\u1edbi Sophos Firewall V21, gi\u1edd \u0111\u00e2y DHCP relay c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c c\u1ea5u h\u00ecnh qua c\u00e1c giao di\u1ec7n XFRM tunnel, gi\u00fap c\u1ea3i thi\u1ec7n kh\u1ea3 n\u0103ng tri\u1ec3n khai v\u00e0 qu\u1ea3n l\u00fd DHCP trong c\u00e1c m\u1ea1ng ph\u1ee9c t\u1ea1p.<\/p>\n\n\n\n<p>L\u01b0u \u00fd r\u1eb1ng, trong b\u1ea3n ph\u00e1t h\u00e0nh n\u00e0y, Sophos Firewall h\u1ed7 tr\u1ee3 DHCP relay cho c\u00e1c m\u00e1y ch\u1ee7 n\u1eb1m ph\u00eda sau t\u01b0\u1eddng l\u1eeda. Tuy nhi\u00ean, c\u00e1c giao di\u1ec7n t\u01b0\u1eddng l\u1eeda \u0111\u01b0\u1ee3c c\u1ea5u h\u00ecnh nh\u01b0 c\u00e1c m\u00e1y ch\u1ee7 DHCP s\u1ebd kh\u00f4ng h\u1ed7 tr\u1ee3 cho c\u00e1c giao di\u1ec7n tunnel.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/uploads.thegioifirewall.com\/2024\/10\/cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21-3.png\" alt=\"\u1ea2nh c\u00f3 ch\u1ee9a v\u0103n b\u1ea3n, bi\u1ec3u \u0111\u1ed3, \u1ea3nh ch\u1ee5p m\u00e0n h\u00ecnh, b\u1ea3n \u0111\u1ed3\"\/><\/figure>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>T\u1ed1i \u01afu H\u00f3a Hi\u1ec7u Su\u1ea5t VPN IPsec<\/strong><\/li>\n<\/ol>\n\n\n\n<p>Sophos \u0111\u00e3 c\u1ea3i thi\u1ec7n hi\u1ec7u su\u1ea5t VPN IPsec cho c\u00e1c c\u1ed5ng v\u00e0o t\u1eeb xa d\u1ef1a tr\u00ean FQDN (Fully Qualified Domain Name) trong phi\u00ean b\u1ea3n V21. Tr\u01b0\u1edbc \u0111\u00e2y, c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean ph\u1ea3i c\u1ea5u h\u00ecnh c\u1ed5ng v\u00e0o t\u1eeb xa b\u1eb1ng c\u00e1ch s\u1eed d\u1ee5ng FQDN, nh\u01b0ng \u0111i\u1ec1u n\u00e0y kh\u00f4ng cho ph\u00e9p s\u1eed d\u1ee5ng c\u00e1c m\u1ee5c wildcard v\u00e0 th\u01b0\u1eddng g\u1eb7p v\u1ea5n \u0111\u1ec1 khi c\u00f3 \u0111\u1ed9 tr\u1ec5 DNS cao. Qu\u00e1 tr\u00ecnh ph\u00e2n gi\u1ea3i FQDN c\u00f3 th\u1ec3 khi\u1ebfn to\u00e0n b\u1ed9 k\u1ebft n\u1ed1i VPN b\u1ecb tr\u00ec tr\u1ec7, \u1ea3nh h\u01b0\u1edfng \u0111\u1ebfn c\u00e1c k\u1ebft n\u1ed1i kh\u00e1c.<\/p>\n\n\n\n<p>Gi\u1edd \u0111\u00e2y, c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean c\u00f3 th\u1ec3 ch\u1ecdn s\u1eed d\u1ee5ng \u0111\u1ecba ch\u1ec9 IP \u0111\u00e3 ph\u00e2n gi\u1ea3i thay v\u00ec d\u1ef1a v\u00e0o ph\u00e2n gi\u1ea3i FQDN trong d\u1ecbch v\u1ee5 VPN. T\u00f9y ch\u1ecdn n\u00e0y \u0111\u01b0\u1ee3c thi\u1ebft l\u1eadp trong giao di\u1ec7n d\u00f2ng l\u1ec7nh (CLI) v\u00e0 b\u1ecb t\u1eaft theo m\u1eb7c \u0111\u1ecbnh \u0111\u1ec3 tr\u00e1nh nh\u1eefng thay \u0111\u1ed5i kh\u00f4ng mong mu\u1ed1n trong qu\u00e1 tr\u00ecnh di chuy\u1ec3n. Tuy nhi\u00ean, n\u1ebfu \u0111\u01b0\u1ee3c k\u00edch ho\u1ea1t, h\u1ec7 th\u1ed1ng s\u1ebd th\u1ef1c hi\u1ec7n ph\u00e2n gi\u1ea3i l\u1ea1i IP c\u1ee9 m\u1ed7i 5 ph\u00fat \u0111\u1ec3 ph\u00e1t hi\u1ec7n b\u1ea5t k\u1ef3 thay \u0111\u1ed5i IP n\u00e0o li\u00ean quan \u0111\u1ebfn FQDN. N\u1ebfu c\u00f3 thay \u0111\u1ed5i v\u1ec1 IP, qu\u00e1 tr\u00ecnh kh\u00f4i ph\u1ee5c k\u1ebft n\u1ed1i c\u1ee5 th\u1ec3 c\u00f3 th\u1ec3 m\u1ea5t m\u1ed9t ch\u00fat th\u1eddi gian.<\/p>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>T\u0103ng T\u1ed1c \u0110\u1ed9 Kh\u00f4i Ph\u1ee5c Giao Di\u1ec7n V\u00e0 T\u1ed1c \u0110\u1ed9 Kh\u1edfi \u0110\u1ed9ng L\u1ea1i D\u1ecbch V\u1ee5<\/strong><\/li>\n<\/ol>\n\n\n\n<p>M\u1ed9t c\u1ea3i ti\u1ebfn quan tr\u1ecdng kh\u00e1c trong Sophos Firewall V21 l\u00e0 t\u1ed1c \u0111\u1ed9 kh\u00f4i ph\u1ee5c giao di\u1ec7n \u0111\u00e3 \u0111\u01b0\u1ee3c t\u0103ng l\u00ean \u0111\u1ebfn 20 l\u1ea7n trong c\u00e1c tr\u01b0\u1eddng h\u1ee3p kh\u1edfi \u0111\u1ed9ng l\u1ea1i d\u1ecbch v\u1ee5, reboot thi\u1ebft b\u1ecb, ho\u1eb7c x\u1ea3y ra s\u1ef1 c\u1ed1 chuy\u1ec3n \u0111\u1ed5i d\u1ef1 ph\u00f2ng (HA failover). Nh\u1eefng c\u1ea3i ti\u1ebfn n\u00e0y gi\u00fap gi\u1ea3m thi\u1ec3u th\u1eddi gian c\u1ea7n thi\u1ebft \u0111\u1ec3 kh\u00f4i ph\u1ee5c k\u1ebft n\u1ed1i m\u1ea1ng so v\u1edbi c\u00e1c phi\u00ean b\u1ea3n tr\u01b0\u1edbc, \u0111\u1eb7c bi\u1ec7t trong c\u00e1c m\u00f4i tr\u01b0\u1eddng SD-WAN v\u00e0 tri\u1ec3n khai VPN v\u1edbi quy m\u00f4 l\u1edbn.<\/p>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li><strong>T\u00edch H\u1ee3p Google Workspace<\/strong><\/li>\n<\/ol>\n\n\n\n<p>S\u1ef1 gia t\u0103ng c\u1ee7a Google Workspace trong m\u00f4i tr\u01b0\u1eddng doanh nghi\u1ec7p \u0111\u00e3 th\u00fac \u0111\u1ea9y Sophos h\u1ed7 tr\u1ee3 t\u00edch h\u1ee3p Google Workspace v\u1edbi t\u01b0\u1eddng l\u1eeda trong phi\u00ean b\u1ea3n V21. Phi\u00ean b\u1ea3n n\u00e0y h\u1ed7 tr\u1ee3 t\u00edch h\u1ee3p Google Workspace th\u00f4ng qua giao th\u1ee9c LDAP th\u00f4ng th\u01b0\u1eddng, gi\u00fap c\u00e1c doanh nghi\u1ec7p s\u1eed d\u1ee5ng Google Workspace d\u1ec5 d\u00e0ng k\u1ebft n\u1ed1i v\u1edbi h\u1ec7 th\u1ed1ng t\u01b0\u1eddng l\u1eeda c\u1ee7a h\u1ecd.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/uploads.thegioifirewall.com\/2024\/10\/cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21-4.png\" alt=\"\"\/><\/figure>\n\n\n\n<p>M\u1ed9t c\u1ea3i ti\u1ebfn \u0111\u1eb7c bi\u1ec7t l\u00e0 kh\u1ea3 n\u0103ng t\u00edch h\u1ee3p SSO (Single Sign-On) cho Google Chromebook v\u1edbi c\u00e1c m\u00e1y ch\u1ee7 ki\u1ec3u LDAP, m\u1ed9t t\u00ednh n\u0103ng tr\u01b0\u1edbc \u0111\u00e2y ch\u1ec9 gi\u1edbi h\u1ea1n cho Active Directory. \u0110i\u1ec1u n\u00e0y gi\u00fap tri\u1ec3n khai t\u00ednh n\u0103ng SSO cho Chromebook d\u1ec5 d\u00e0ng h\u01a1n th\u00f4ng qua Google LDAP.<\/p>\n\n\n\n<p>Sophos c\u0169ng l\u01b0u \u00fd r\u1eb1ng vi\u1ec7c t\u00edch h\u1ee3p Google Workspace kh\u00f4ng y\u00eau c\u1ea7u domain cho c\u00e1c y\u00eau c\u1ea7u AAA, v\u00ec v\u1eady ng\u01b0\u1eddi d\u00f9ng ch\u1ec9 c\u1ea7n cung c\u1ea5p t\u00ean \u0111\u0103ng nh\u1eadp m\u00e0 kh\u00f4ng c\u1ea7n domain. Ngo\u00e0i ra, b\u1ea1n c\u1ea7n \u0111\u1ea3m b\u1ea3o kh\u00f4ng ch\u1ecdn h\u1ed9p ki\u1ec3m &#8220;PEN-based DN&#8221; trong trang c\u1ea5u h\u00ecnh m\u00e1y ch\u1ee7.<\/p>\n\n\n\n<ol start=\"6\" class=\"wp-block-list\">\n<li><strong>C\u1ea3i Thi\u1ec7n Kh\u1ea3 N\u0103ng X\u1eed L\u00fd Y\u00eau C\u1ea7u SSO<\/strong><\/li>\n<\/ol>\n\n\n\n<p>Sophos Firewall V21 c\u0169ng mang l\u1ea1i nh\u1eefng c\u1ea3i ti\u1ebfn \u0111\u00e1ng k\u1ec3 trong vi\u1ec7c x\u1eed l\u00fd c\u00e1c y\u00eau c\u1ea7u SSO (Single Sign-On), gi\u00fap t\u01b0\u1eddng l\u1eeda c\u00f3 th\u1ec3 qu\u1ea3n l\u00fd h\u00e0ng ngh\u00ecn y\u00eau c\u1ea7u \u0111\u0103ng nh\u1eadp \u0111\u1ed3ng th\u1eddi m\u1ed9t c\u00e1ch hi\u1ec7u qu\u1ea3. Tr\u01b0\u1edbc \u0111\u00e2y, trong c\u00e1c tri\u1ec3n khai ph\u1ee9c t\u1ea1p s\u1eed d\u1ee5ng nhi\u1ec1u c\u01a1 ch\u1ebf SSO kh\u00e1c nhau nh\u01b0 STAS, RADIUS SSO, v\u00e0 SYNCHRON-ized user ID, h\u1ec7 th\u1ed1ng th\u01b0\u1eddng b\u1ecb qu\u00e1 t\u1ea3i khi t\u1ea5t c\u1ea3 c\u00e1c ph\u01b0\u01a1ng th\u1ee9c SSO c\u1ed1 g\u1eafng \u0111\u0103ng nh\u1eadp c\u00f9ng m\u1ed9t ng\u01b0\u1eddi d\u00f9ng c\u00f9ng l\u00fac, d\u1eabn \u0111\u1ebfn vi\u1ec7c x\u1eed l\u00fd y\u00eau c\u1ea7u AAA b\u1ecb \u1ea3nh h\u01b0\u1edfng.<\/p>\n\n\n\n<p>V\u1edbi Sophos V21, t\u01b0\u1eddng l\u1eeda c\u00f3 th\u1ec3 x\u1eed l\u00fd c\u00e1c y\u00eau c\u1ea7u nhanh g\u1ea5p 4 l\u1ea7n v\u00e0 t\u1ef1 \u0111\u1ed9ng lo\u1ea1i b\u1ecf c\u00e1c y\u00eau c\u1ea7u tr\u00f9ng l\u1eb7p t\u1eeb nhi\u1ec1u lo\u1ea1i kh\u00e1ch h\u00e0ng SSO kh\u00e1c nhau sau khi m\u1ed9t ng\u01b0\u1eddi d\u00f9ng \u0111\u00e3 \u0111\u01b0\u1ee3c x\u00e1c th\u1ef1c th\u00e0nh c\u00f4ng.<\/p>\n\n\n\n<ol start=\"7\" class=\"wp-block-list\">\n<li><strong>C\u1ea3i Ti\u1ebfn Qu\u1ea3n L\u00fd \u0110\u1ecbnh Tuy\u1ebfn T\u0129nh V\u00e0 \u0110\u1ed9ng<\/strong><\/li>\n<\/ol>\n\n\n\n<p>Qu\u1ea3n l\u00fd \u0111\u1ecbnh tuy\u1ebfn l\u00e0 m\u1ed9t ch\u1ee9c n\u0103ng quan tr\u1ecdng trong b\u1ea5t k\u1ef3 h\u1ec7 th\u1ed1ng t\u01b0\u1eddng l\u1eeda n\u00e0o, v\u00e0 Sophos Firewall V21 \u0111\u00e3 mang \u0111\u1ebfn nh\u1eefng c\u1ea3i ti\u1ebfn l\u1edbn trong qu\u1ea3n l\u00fd \u0111\u1ecbnh tuy\u1ebfn t\u0129nh v\u00e0 \u0111\u1ed9ng. Tr\u00ean trang qu\u1ea3n l\u00fd \u0111\u1ecbnh tuy\u1ebfn, Sophos \u0111\u00e3 gi\u1edbi thi\u1ec7u m\u1ed9t s\u1ed1 t\u00ednh n\u0103ng m\u1edbi quan tr\u1ecdng, bao g\u1ed3m kh\u1ea3 n\u0103ng b\u1eadt\/t\u1eaft c\u00e1c tuy\u1ebfn \u0111\u01b0\u1eddng t\u0129nh, gi\u00fap qu\u1ea3n tr\u1ecb vi\u00ean d\u1ec5 d\u00e0ng ki\u1ec3m so\u00e1t v\u00e0 kh\u1eafc ph\u1ee5c s\u1ef1 c\u1ed1 h\u01a1n.<\/p>\n\n\n\n<p>Ngo\u00e0i ra, Sophos \u0111\u00e3 th\u00eam t\u00ednh n\u0103ng &#8220;nh\u00e2n b\u1ea3n tuy\u1ebfn \u0111\u01b0\u1eddng&#8221; (clone route), cho ph\u00e9p qu\u1ea3n tr\u1ecb vi\u00ean t\u1ea1o c\u00e1c tuy\u1ebfn \u0111\u01b0\u1eddng gi\u1ed1ng nhau nhanh ch\u00f3ng, bao g\u1ed3m c\u1ea3 tr\u01b0\u1eddng m\u00f4 t\u1ea3 \u0111\u1ec3 theo d\u00f5i th\u00f4ng tin tuy\u1ebfn \u0111\u01b0\u1eddng. M\u1ed9t t\u00ednh n\u0103ng h\u1eefu \u00edch kh\u00e1c l\u00e0 &#8220;giao di\u1ec7n ki\u1ec3u black hole&#8221; (black hole type interface), gi\u00fap ch\u1eb7n c\u00e1c l\u01b0u l\u01b0\u1ee3ng kh\u00f4ng mong mu\u1ed1n m\u1ed9t c\u00e1ch d\u1ec5 d\u00e0ng. V\u1edbi t\u00ednh n\u0103ng Equal Cost Multipath (ECMP), Sophos Firewall V21 c\u00f2n h\u1ed7 tr\u1ee3 c\u00e2n b\u1eb1ng t\u1ea3i l\u01b0u l\u01b0\u1ee3ng qua nhi\u1ec1u tuy\u1ebfn \u0111\u01b0\u1eddng t\u0129nh, t\u0103ng c\u01b0\u1eddng kh\u1ea3 n\u0103ng x\u1eed l\u00fd l\u01b0u l\u01b0\u1ee3ng m\u1ea1ng.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/uploads.thegioifirewall.com\/2024\/10\/cai-tien-ve-kha-nang-mo-rong-va-trai-nghiem-nguoi-dung-trong-sophos-firewall-phien-ban-21-5.png\" alt=\"\"\/><\/figure>\n\n\n\n<p>Trong \u0111\u1ecbnh tuy\u1ebfn \u0111\u1ed9ng, phi\u00ean b\u1ea3n V21 gi\u1edd \u0111\u00e2y c\u00f3 th\u1ec3 ph\u00e2n ph\u1ed1i l\u1ea1i c\u00e1c tuy\u1ebfn BGP v\u00e0o OSPFv3, trong khi t\u1ea5t c\u1ea3 c\u00e1c c\u1ea5u h\u00ecnh n\u00e2ng cao kh\u00e1c v\u1eabn c\u00f3 s\u1eb5n th\u00f4ng qua CLI. Tr\u01b0\u1edbc \u0111\u00e2y, trong c\u00e1c t\u00ecnh hu\u1ed1ng chuy\u1ec3n \u0111\u1ed5i d\u1ef1 ph\u00f2ng (failover), \u0111\u1ecbnh tuy\u1ebfn \u0111\u1ed9ng th\u01b0\u1eddng b\u1ecb gi\u00e1n \u0111o\u1ea1n nhi\u1ec1u l\u1ea7n \u0111\u1ec3 kh\u00f4i ph\u1ee5c k\u1ebft n\u1ed1i gi\u1eefa c\u00e1c thi\u1ebft b\u1ecb SFOS. Tuy nhi\u00ean, v\u1edbi b\u1ea3n ph\u00e1t h\u00e0nh n\u00e0y, Sophos \u0111\u00e3 gi\u1ea3m thi\u1ec3u ho\u00e0n to\u00e0n t\u00e1c \u0111\u1ed9ng c\u1ee7a s\u1ef1 c\u1ed1 thi\u1ebft b\u1ecb ph\u1ee5 tr\u1ee3, ch\u1ec9 c\u00f2n m\u1ed9t l\u1ea7n gi\u00e1n \u0111o\u1ea1n d\u1ecbch v\u1ee5 trong tr\u01b0\u1eddng h\u1ee3p thi\u1ebft b\u1ecb ch\u00ednh g\u1eb7p s\u1ef1 c\u1ed1.<\/p>\n\n\n\n<p><strong>K\u1ebft Lu\u1eadn<\/strong><\/p>\n\n\n\n<p>Sophos Firewall V21 mang \u0111\u1ebfn h\u00e0ng lo\u1ea1t t\u00ednh n\u0103ng v\u00e0 c\u1ea3i ti\u1ebfn m\u1ea1nh m\u1ebd, gi\u00fap c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean h\u1ec7 th\u1ed1ng d\u1ec5 d\u00e0ng qu\u1ea3n l\u00fd c\u00e1c k\u1ebft n\u1ed1i m\u1ea1ng, VPN, v\u00e0 \u0111\u1ecbnh tuy\u1ebfn trong c\u00e1c m\u00f4i tr\u01b0\u1eddng ph\u1ee9c t\u1ea1p. C\u00e1c c\u1ea3i ti\u1ebfn n\u00e0y kh\u00f4ng ch\u1ec9 t\u0103ng c\u01b0\u1eddng t\u00ednh linh ho\u1ea1t v\u00e0 hi\u1ec7u su\u1ea5t m\u00e0 c\u00f2n gi\u00fap t\u1ed1i \u01b0u h\u00f3a qu\u00e1 tr\u00ecnh qu\u1ea3n tr\u1ecb v\u00e0 gi\u1ea3m thi\u1ec3u c\u00e1c v\u1ea5n \u0111\u1ec1 v\u1ec1 hi\u1ec7u su\u1ea5t m\u1ea1ng.<\/p>\n\n\n\n<p>\u0110\u1ec3 t\u00ecm hi\u1ec3u th\u00eam v\u1ec1 Sophos Firewall V21 v\u00e0 c\u00e1c t\u00ednh n\u0103ng m\u1edbi kh\u00e1c, b\u1ea1n c\u00f3 th\u1ec3 xem th\u00eam c\u00e1c t\u00e0i li\u1ec7u h\u01b0\u1edbng d\u1eabn v\u00e0 video demo t\u1eeb Sophos \u0111\u01b0\u1ee3c li\u00ean k\u1ebft trong ph\u1ea7n m\u00f4 t\u1ea3. \u0110\u1eebng qu\u00ean tham gia c\u1ed9ng \u0111\u1ed3ng Sophos tr\u00ean <a href=\"https:\/\/community.sophos.com\/\">community.sophos.com<\/a> \u0111\u1ec3 \u0111\u1eb7t c\u00e2u h\u1ecfi v\u00e0 th\u1ea3o lu\u1eadn th\u00eam v\u1edbi c\u00e1c chuy\u00ean gia. N\u1ebfu b\u1ea1n c\u1ea7n h\u1ed7 tr\u1ee3 chi ti\u1ebft h\u01a1n, b\u1ea1n c\u00f3 th\u1ec3 gh\u00e9 th\u0103m <a href=\"https:\/\/techvids.sophos.com\/\">techvids.sophos.com<\/a> \u0111\u1ec3 xem th\u00eam nhi\u1ec1u video h\u1eefu \u00edch v\u1ec1 c\u00e1c s\u1ea3n ph\u1ea9m kh\u00e1c c\u1ee7a Sophos.<\/p>\n\n\n\n<p>C\u1ea3m \u01a1n b\u1ea1n \u0111\u00e3 theo d\u00f5i b\u00e0i vi\u1ebft n\u00e0y v\u00e0 hy v\u1ecdng nh\u1eefng th\u00f4ng tin tr\u00ean s\u1ebd gi\u00fap b\u1ea1n hi\u1ec3u r\u00f5 h\u01a1n v\u1ec1 c\u00e1c c\u1ea3i ti\u1ebfn trong Sophos Firewall phi\u00ean b\u1ea3n 21, c\u0169ng nh\u01b0 c\u00e1ch nh\u1eefng t\u00ednh n\u0103ng n\u00e0y c\u00f3 th\u1ec3 t\u1ed1i \u01b0u h\u00f3a hi\u1ec7u su\u1ea5t ho\u1ea1t \u0111\u1ed9ng v\u00e0 qu\u1ea3n l\u00fd m\u1ea1ng c\u1ee7a b\u1ea1n. \u0110\u1eebng ng\u1ea7n ng\u1ea1i li\u00ean h\u1ec7 v\u1edbi \u0111\u1ed9i ng\u0169 h\u1ed7 tr\u1ee3 c\u1ee7a Sophos n\u1ebfu b\u1ea1n g\u1eb7p b\u1ea5t k\u1ef3 th\u1eafc m\u1eafc hay v\u1ea5n \u0111\u1ec1 n\u00e0o trong qu\u00e1 tr\u00ecnh s\u1eed d\u1ee5ng!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophos v\u1eeba gi\u1edbi thi\u1ec7u b\u1ea3n c\u1eadp nh\u1eadt l\u1edbn cho t\u01b0\u1eddng l\u1eeda c\u1ee7a h\u1ecd v\u1edbi phi\u00ean b\u1ea3n Sophos Firewall 21 (V21), mang \u0111\u1ebfn nhi\u1ec1u c\u1ea3i ti\u1ebfn v\u1ec1 kh\u1ea3 n\u0103ng m\u1edf r\u1ed9ng v\u00e0 tr\u1ea3i nghi\u1ec7m ng\u01b0\u1eddi d\u00f9ng (UX). Nh\u1eefng n\u00e2ng c\u1ea5p n\u00e0y bao g\u1ed3m c\u1ea3i ti\u1ebfn VPN, c\u1ea3i thi\u1ec7n qu\u1ea3n l\u00fd \u0111\u1ecbnh tuy\u1ebfn t\u0129nh v\u00e0 \u0111\u1ed9ng, c\u00f9ng [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":21149,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[80,10],"tags":[334],"class_list":["post-20694","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-huong-dan-tai-lieu","category-tin-tuc","tag-sophos-firewall","entry","has-media"],"_links":{"self":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts\/20694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/comments?post=20694"}],"version-history":[{"count":1,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts\/20694\/revisions"}],"predecessor-version":[{"id":21125,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts\/20694\/revisions\/21125"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/media\/21149"}],"wp:attachment":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/media?parent=20694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/categories?post=20694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/tags?post=20694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}