<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fortinet Firewall &#8211; VACIF</title>
	<atom:link href="https://vacif.com/tag/fortinet-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>https://vacif.com</link>
	<description>Đầu tư cho giá trị</description>
	<lastBuildDate>Fri, 06 Mar 2026 09:25:49 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://vacif.com/wp-content/uploads/2024/06/cropped-icon-32x32.png</url>
	<title>Fortinet Firewall &#8211; VACIF</title>
	<link>https://vacif.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site to Site Giữa Firewall Fortinet và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 04 Mar 2026 05:41:35 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Fortinet Firewall]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29017</guid>

					<description><![CDATA[Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet. Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;text&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;text&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;text&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;text&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;text&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;text&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;text&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;text&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;text&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;text&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;text&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;link&quot;:&quot;eb-table-content-15&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-firewall-fortinet-v\u00e0-sophos-firewall-firmware-v22-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;value&quot;:&quot;1-tr\u00ean-thi\u1ebft-b\u1ecb-fortinet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;value&quot;:&quot;11-t\u1ea1o-vpn-tunnels&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;value&quot;:&quot;12-t\u1ea1o-static-route&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;value&quot;:&quot;13-t\u1ea1o-firewall-policy&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;value&quot;:&quot;2-tr\u00ean-thi\u1ebft-b\u1ecb-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;value&quot;:&quot;21-t\u1ea1o-subnet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;value&quot;:&quot;22-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;value&quot;:&quot;23-t\u1ea1o-ipsec-connection&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;value&quot;:&quot;24-t\u1ea1o-firewall-rule-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;value&quot;:&quot;3-ki\u1ec3m-tra-k\u1ebft-qu\u1ea3&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;value&quot;:&quot;ghi-ch\u00fa-l\u01b0u-\u00fd-tri\u1ec3n-khai&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet.</p>



<p>Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy cập lẫn nhau:</p>



<ul class="wp-block-list">
<li>172.16.16.0/24 – Site A</li>



<li>10.10.10.0/24 – Site B</li>



<li>192.168.20.0/24 – Site B</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="864" height="366" src="https://vacif.com/wp-content/uploads/2026/03/image-8.png" alt="" class="wp-image-29019" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x325.png 768w" sizes="(max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-mm8bi"><div class="eb-parent-wrapper eb-parent-eb-text-mm8bi "><div class="eb-text-wrapper eb-text-mm8bi" data-id="eb-text-mm8bi"><p class="eb-text">Giải thích sơ đồ mạng:</p></div></div></div>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site A – Fortinet Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào cổng WAN của thiết bị Fortinet</li>



<li>IP WAN: 192.168.1.2</li>



<li>Mạng LAN nội bộ: 172.16.16.0/24</li>



<li>LAN được cấu hình trên interface LAN của Fortinet</li>
</ul>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site B – Sophos Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào interface a (WAN) của Sophos Firewall</li>



<li>IP WAN: 192.168.1.3</li>



<li>Mạng LAN nội bộ gồm 2 lớp mạng: 10.10.10.0/24, 192.168.20.0/24</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-w4aye"><div class="eb-parent-wrapper eb-parent-eb-text-w4aye "><div class="eb-text-wrapper eb-text-w4aye" data-id="eb-text-w4aye"><p class="eb-text">Lưu ý sơ đồ:</p></div></div></div>



<ul class="wp-block-list">
<li>Kết nối VPN sử dụng IPSec Site-to-Site</li>



<li>Xác thực bằng Pre-shared Key</li>



<li>Sử dụng IKEv2</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-jmoxo"><div class="eb-parent-wrapper eb-parent-eb-text-jmoxo "><div class="eb-text-wrapper eb-text-jmoxo" data-id="eb-text-jmoxo"><p class="eb-text">Chúng ta sẽ thực hiện cấu hình IPSec VPN Site-to-Site giữa:</p></div></div></div>



<ul class="wp-block-list">
<li>Fortinet (192.168.1.2)</li>



<li>Sophos (192.168.1.3)</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-oylnm"><div class="eb-parent-wrapper eb-parent-eb-text-oylnm "><div class="eb-text-wrapper eb-text-oylnm" data-id="eb-text-oylnm"><p class="eb-text">Mục tiêu:</p></div></div></div>



<p>Mạng LAN 172.16.16.0/24 (Fortinet) ⬄ Mạng LAN 10.10.10.0/24 và 192.168.20.0/24 (Sophos) có thể kết nối qua lại trực tiếp.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yq4nn"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yq4nn "><div class="eb-advance-heading-wrapper eb-advance-heading-yq4nn button-1 undefined" data-id="eb-advance-heading-yq4nn"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-queb7"><div class="eb-parent-wrapper eb-parent-eb-text-queb7 "><div class="eb-text-wrapper eb-text-queb7" data-id="eb-text-queb7"><p class="eb-text">Trên thiết bị Fortinet:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo VPN Tunnels</li>



<li>Tạo Static Route</li>



<li>Tạo Firewall Policy</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-vlwq4"><div class="eb-parent-wrapper eb-parent-eb-text-vlwq4 "><div class="eb-text-wrapper eb-text-vlwq4" data-id="eb-text-vlwq4"><p class="eb-text">Trên thiết bị Sophos:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo subnet</li>



<li>Tạo IPSec Profile</li>



<li>Tạo IPSec Connection</li>



<li>Tạo Firewall Rule</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-76g77"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-76g77 "><div class="eb-advance-heading-wrapper eb-advance-heading-76g77 button-1 undefined" data-id="eb-advance-heading-76g77"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Trên thiết bị Fortinet:</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wc297"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wc297 "><div class="eb-advance-heading-wrapper eb-advance-heading-wc297 button-1 undefined" data-id="eb-advance-heading-wc297"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Tạo VPN Tunnels</span></h2></div></div></div>



<p>Vào VPN → IPsec Tunnels → Create New → Custom</p>



<div class="wp-block-essential-blocks-text  root-eb-text-i1ir1"><div class="eb-parent-wrapper eb-parent-eb-text-i1ir1 "><div class="eb-text-wrapper eb-text-i1ir1" data-id="eb-text-i1ir1"><p class="eb-text">Bảng VPN Create Wizard</p></div></div></div>



<p>Name: S2S-LAB</p>



<p>Template Type: Custom</p>



<figure class="wp-block-image size-full"><img decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg" alt="" class="wp-image-29020" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x351.jpg 768w" sizes="(max-width: 864px) 100vw, 864px" /></figure>



<p>Dùng Custom để chủ động cấu hình Phase 1 / Phase 2</p>



<div class="wp-block-essential-blocks-text  root-eb-text-xvm9r"><div class="eb-parent-wrapper eb-parent-eb-text-xvm9r "><div class="eb-text-wrapper eb-text-xvm9r" data-id="eb-text-xvm9r"><p class="eb-text">Bảng Network</p></div></div></div>



<figure class="wp-block-image size-full"><img decoding="async" width="746" height="709" src="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg" alt="" class="wp-image-29021" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg 746w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x285.jpg 300w" sizes="(max-width: 746px) 100vw, 746px" /></figure>



<figure class="wp-block-table is-style-regular"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>IP Version</td><td>IPv4</td></tr><tr><td>Remote Gateway</td><td>Static IP Address</td></tr><tr><td>IP Address</td><td>192.168.1.3 (WAN Sophos)</td></tr><tr><td>Interface</td><td>WAN</td></tr><tr><td>Local Gateway</td><td>Không bật</td></tr><tr><td>Mode Config</td><td>Bỏ chọn</td></tr><tr><td>NAT Traversal</td><td>Disable</td></tr><tr><td>Dead Peer Detection</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-h7m6p"><div class="eb-parent-wrapper eb-parent-eb-text-h7m6p "><div class="eb-text-wrapper eb-text-h7m6p" data-id="eb-text-h7m6p"><p class="eb-text">&#8211; Disable NAT-T vì không NAT giữa 2 WAN<br>&#8211; Disable DPD để tránh reset tunnel trong lab</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-8oxg9"><div class="eb-parent-wrapper eb-parent-eb-text-8oxg9 "><div class="eb-text-wrapper eb-text-8oxg9" data-id="eb-text-8oxg9"><p class="eb-text">Bảng Authentication</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="735" height="331" src="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg" alt="" class="wp-image-29022" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg 735w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x135.jpg 300w" sizes="auto, (max-width: 735px) 100vw, 735px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Method</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>(ví dụ) FortiSophos@123</td></tr><tr><td>IKE Version</td><td>2</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-2qql7"><div class="eb-parent-wrapper eb-parent-eb-text-2qql7 "><div class="eb-text-wrapper eb-text-2qql7" data-id="eb-text-2qql7"><p class="eb-text">&#8211; PSK phải giống 100% bên Sophos</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-11jdu"><div class="eb-parent-wrapper eb-parent-eb-text-11jdu "><div class="eb-text-wrapper eb-text-11jdu" data-id="eb-text-11jdu"><p class="eb-text">Phase 1 Proposal</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="757" height="376" src="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg" alt="" class="wp-image-29023" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg 757w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x149.jpg 300w" sizes="auto, (max-width: 757px) 100vw, 757px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>28800</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6r9aw"><div class="eb-parent-wrapper eb-parent-eb-text-6r9aw "><div class="eb-text-wrapper eb-text-6r9aw" data-id="eb-text-6r9aw"><p class="eb-text">Phase 2 Selectors</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="578" height="714" src="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg" alt="" class="wp-image-29032" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg 578w, https://vacif.com/wp-content/uploads/2026/03/image-28-243x300.jpg 243w" sizes="auto, (max-width: 578px) 100vw, 578px" /></figure>



<p><strong>Selector 1</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 10.10.10.0/24</li>
</ul>



<p><strong>Selector 2</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 192.168.20.0/24</li>
</ul>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>43200</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4mf91"><div class="eb-parent-wrapper eb-parent-eb-text-4mf91 "><div class="eb-text-wrapper eb-text-4mf91" data-id="eb-text-4mf91"><p class="eb-text">&#8211; Mỗi subnet Sophos cần 1 Phase 2<br>&#8211; Nếu gộp → tunnel UP nhưng không có traffic</p></div></div></div>



<p>Nhấn OK để tạo VPN Tunnel.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ljz9a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ljz9a "><div class="eb-advance-heading-wrapper eb-advance-heading-ljz9a button-1 undefined" data-id="eb-advance-heading-ljz9a"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Tạo Static Route</span></h2></div></div></div>



<p>Vào Network → Static Routes → Create New</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg" alt="" class="wp-image-29027" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-i0llt"><div class="eb-parent-wrapper eb-parent-eb-text-i0llt "><div class="eb-text-wrapper eb-text-i0llt" data-id="eb-text-i0llt"><p class="eb-text">Route 1</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>10.10.10.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-t16sq"><div class="eb-parent-wrapper eb-parent-eb-text-t16sq "><div class="eb-text-wrapper eb-text-t16sq" data-id="eb-text-t16sq"><p class="eb-text">Route 2</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg" alt="" class="wp-image-29026" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>192.168.20.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-175x1"><div class="eb-parent-wrapper eb-parent-eb-text-175x1 "><div class="eb-text-wrapper eb-text-175x1" data-id="eb-text-175x1"><p class="eb-text">&#8211; Nếu thiếu static route → ping không bao giờ đi vào VPN</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-siaef"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-siaef "><div class="eb-advance-heading-wrapper eb-advance-heading-siaef button-1 undefined" data-id="eb-advance-heading-siaef"><h2 class="eb-ah-title"><span class="first-title"><a>1.3</a> &#8211; Tạo Firewall Policy</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-k0mcg"><div class="eb-parent-wrapper eb-parent-eb-text-k0mcg "><div class="eb-text-wrapper eb-text-k0mcg" data-id="eb-text-k0mcg"><p class="eb-text">Policy 1 – LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg" alt="" class="wp-image-29030" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>LAN</td></tr><tr><td>Outgoing Interface</td><td>S2S-LAB</td></tr><tr><td>Source</td><td>172.16.16.0/24</td></tr><tr><td>Destination</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr><tr><td>NAT</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-04oaf"><div class="eb-parent-wrapper eb-parent-eb-text-04oaf "><div class="eb-text-wrapper eb-text-04oaf" data-id="eb-text-04oaf"><p class="eb-text">Policy 2 – VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg" alt="" class="wp-image-29031" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>S2S-LAB</td></tr><tr><td>Outgoing Interface</td><td>LAN</td></tr><tr><td>Source</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination</td><td>172.16.16.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-i77g3"><div class="eb-parent-wrapper eb-parent-eb-text-i77g3 "><div class="eb-text-wrapper eb-text-i77g3" data-id="eb-text-i77g3"><p class="eb-text">&#8211; Policy VPN phải nằm trên policy Internet</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qh3q2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qh3q2 "><div class="eb-advance-heading-wrapper eb-advance-heading-qh3q2 button-1 undefined" data-id="eb-advance-heading-qh3q2"><h2 class="eb-ah-title"><span class="first-title"><a>2. </a>Trên thiết bị Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a7f6u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a7f6u "><div class="eb-advance-heading-wrapper eb-advance-heading-a7f6u button-1 undefined" data-id="eb-advance-heading-a7f6u"><h2 class="eb-ah-title"><span class="first-title">2.1 &#8211; Tạo subnet</span></h2></div></div></div>



<p>Vào Hosts and Services → Add</p>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tên</strong></th><th><strong>Loại</strong></th><th><strong>Thông số</strong></th></tr></thead><tbody><tr><td>LAN_SOPHOS_10</td><td>Network</td><td>IP: 10.10.10.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_SOPHOS_20</td><td>Network</td><td>IP: 192.168.20.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_FORTI</td><td>Network</td><td>IP: 172.16.16.0 / Subnet: 255.255.255.0</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bkx0m"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bkx0m "><div class="eb-advance-heading-wrapper eb-advance-heading-bkx0m button-1 undefined" data-id="eb-advance-heading-bkx0m"><h2 class="eb-ah-title"><span class="first-title">2.2 &#8211; Tạo IPSec Profile</span></h2></div></div></div>



<p>Vào SYSTEM &gt; Profiles → IPsec Profiles → Add</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg" alt="" class="wp-image-29024" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>Fortinet-Vacif</td></tr><tr><td>IKE Version</td><td>IKEv2</td></tr><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>DH Group</td><td>14</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x0jn2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x0jn2 "><div class="eb-advance-heading-wrapper eb-advance-heading-x0jn2 button-1 undefined" data-id="eb-advance-heading-x0jn2"><h2 class="eb-ah-title"><span class="first-title">2.3 &#8211; Tạo IPSec Connection</span></h2></div></div></div>



<p>Vào CONFIGURE → Site-to-site VPN → &nbsp;IPsec → Add</p>



<div class="wp-block-essential-blocks-text  root-eb-text-b8zwg"><div class="eb-parent-wrapper eb-parent-eb-text-b8zwg "><div class="eb-text-wrapper eb-text-b8zwg" data-id="eb-text-b8zwg"><p class="eb-text">General Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg" alt="" class="wp-image-29025" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>VPN_SOPHOS_VACIF</td></tr><tr><td>Connection Type</td><td>Policy-based</td></tr><tr><td>Gateway Type</td><td>Initiate the connection</td></tr><tr><td>Create firewall rule</td><td>Không chọn (tạo thủ công)</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-86g8b"><div class="eb-parent-wrapper eb-parent-eb-text-86g8b "><div class="eb-text-wrapper eb-text-86g8b" data-id="eb-text-86g8b"><p class="eb-text">Authentication</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Profile</td><td>Fortinet Vacif ( tạo ở bước trên )</td></tr><tr><td>Authentication Type&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>FortiSophos@123</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6opfg"><div class="eb-parent-wrapper eb-parent-eb-text-6opfg "><div class="eb-text-wrapper eb-text-6opfg" data-id="eb-text-6opfg"><p class="eb-text">Gateway Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg" alt="" class="wp-image-29033" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<ul class="wp-block-list">
<li>Listening interface: Port 2 – 192.168.1.3</li>



<li>Gateway address: 192.168.1.2 (WAN Fortinet)</li>



<li>Local Subnet: 10.10.10.0/24 , 192.168.20.0/24</li>



<li>Remote Subnet: 172.16.16.0/24</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2dz5o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2dz5o "><div class="eb-advance-heading-wrapper eb-advance-heading-2dz5o button-1 undefined" data-id="eb-advance-heading-2dz5o"><h2 class="eb-ah-title"><span class="first-title"><a>2.4</a> &#8211; Tạo Firewall Rule Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-069m1"><div class="eb-parent-wrapper eb-parent-eb-text-069m1 "><div class="eb-text-wrapper eb-text-069m1" data-id="eb-text-069m1"><p class="eb-text">LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg" alt="" class="wp-image-29028" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>LAN</td></tr><tr><td>Destination Zone</td><td>VPN</td></tr><tr><td>Source Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination Network</td><td>172.16.16.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-0pm0n"><div class="eb-parent-wrapper eb-parent-eb-text-0pm0n "><div class="eb-text-wrapper eb-text-0pm0n" data-id="eb-text-0pm0n"><p class="eb-text">VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg" alt="" class="wp-image-29029" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>VPN</td></tr><tr><td>Destination Zone</td><td>LAN</td></tr><tr><td>Source Network</td><td>172.16.16.0/24</td></tr><tr><td>Destination Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeg05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeg05 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeg05 button-1 undefined" data-id="eb-advance-heading-qeg05"><h2 class="eb-ah-title"><span class="first-title"><a>3</a>. Kiểm tra kết quả</span></h2></div></div></div>



<p><strong>Sophos:</strong> VPN → IPsec Connections → Status: <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f7e2.png" alt="🟢" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Connected</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg" alt="" class="wp-image-29034" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Fortinet:</strong> Monitor → IPsec Monitor → Tunnel: UP (Có Incoming / Outgoing Data)</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg" alt="" class="wp-image-29035" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Test:</strong></p>



<ul class="wp-block-list">
<li>172.16.16.x → 10.10.10.x</li>



<li>172.16.16.x → 192.168.20.x</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg" alt="" class="wp-image-29036" srcset="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-32-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-32-768x404.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iq8fr"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iq8fr "><div class="eb-advance-heading-wrapper eb-advance-heading-iq8fr button-1 undefined" data-id="eb-advance-heading-iq8fr"><h2 class="eb-ah-title"><span class="first-title">* Ghi chú &amp; Lưu ý triển khai</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đảm bảo thời gian hệ thống đồng bộ (NTP) để tránh lỗi IKEv2 do lệch thời gian.</li>



<li>PSK, thuật toán mã hóa và nhóm DH phải trùng khớp 2 đầu – sai khác sẽ khiến Phase 1/2 thất bại.</li>



<li>Tắt NAT trên policy đi vào VPN; bật NAT sẽ làm sai nguồn và gói tin không match selector.</li>



<li>Mỗi cặp Local/Remote subnet cần 1 selector (Phase 2). Không gộp nhiều subnet nếu thiết bị không hỗ trợ.</li>



<li>Nếu tunnel UP nhưng không ping được, kiểm tra: Static Route, Policy thứ tự, và bảng ARP/Route trên hai đầu.</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng Dẫn Cấu Hình VPN FAILOVER MPLS Giữa Sophos &#038; Fortigate Firewall</title>
		<link>https://vacif.com/huong-dan-cau-hinh-vpn-failover-mpls-giua-sophos-va-fortigate-firewall/</link>
					<comments>https://vacif.com/huong-dan-cau-hinh-vpn-failover-mpls-giua-sophos-va-fortigate-firewall/#respond</comments>
		
		<dc:creator><![CDATA[Nick Doan]]></dc:creator>
		<pubDate>Tue, 25 Mar 2025 07:30:13 +0000</pubDate>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Fortinet Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=21781</guid>

					<description><![CDATA[Cấu hình VPN Failover MPLS là giải pháp đảm bảo kết nối liên tục giữa các chi nhánh và trung tâm dữ liệu thông qua cả đường truyền MPLS và VPN (Internet). Khi đường MPLS gặp sự cố, VPN sẽ tự động kích hoạt để duy trì kết nối. Link tham khảo: https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-site-to-site-giua-sophos-va-fortinet-voi-ip-wan-la-ip-tinh/ Đăng nhập [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2y1c5"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2y1c5 "><div class="eb-advance-heading-wrapper eb-advance-heading-2y1c5 button-1 undefined" data-id="eb-advance-heading-2y1c5"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quát</span></h2></div></div></div>



<p><strong>Cấu hình VPN Failover MPLS</strong> là giải pháp đảm bảo kết nối liên tục giữa các chi nhánh và trung tâm dữ liệu thông qua cả đường truyền MPLS và VPN (Internet). Khi đường MPLS gặp sự cố, VPN sẽ tự động kích hoạt để duy trì kết nối.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-unq0z"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-unq0z "><div class="eb-advance-heading-wrapper eb-advance-heading-unq0z button-1 undefined" data-id="eb-advance-heading-unq0z"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ</span></h2></div></div></div>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="975" height="630" src="https://vacif.com/wp-content/uploads/2025/03/image-7.png" alt="" class="wp-image-21793" srcset="https://vacif.com/wp-content/uploads/2025/03/image-7.png 975w, https://vacif.com/wp-content/uploads/2025/03/image-7-600x388.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-7-300x194.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-7-768x496.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
</div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-h6ccz"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-h6ccz "><div class="eb-advance-heading-wrapper eb-advance-heading-h6ccz button-1 undefined" data-id="eb-advance-heading-h6ccz"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Mô hình hoạt động</span></h2></div></div></div>



<ul class="wp-block-list">
<li><strong>Primary Link (MPLS)</strong>: Kết nối chính giữa các chi nhánh với trung tâm dữ liệu thông qua MPLS.</li>



<li><strong>Backup Link (VPN &#8211; Internet)</strong>: Khi đường MPLS bị lỗi, VPN Site-to-Site qua Internet sẽ tự động thay thế.</li>



<li><strong>Failover Detection</strong>: Sử dụng tính năng theo dõi (health check) để giám sát trạng thái đường truyền, nếu phát hiện mất kết nối, tự động chuyển sang VPN.</li>



<li><strong>Load Balancing</strong>: Một số giải pháp có thể triển khai cả hai đường truyền cùng lúc để cân bằng tải.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-da9n3"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-da9n3 "><div class="eb-advance-heading-wrapper eb-advance-heading-da9n3 button-1 undefined" data-id="eb-advance-heading-da9n3"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-jztlz"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-jztlz "><div class="eb-advance-heading-wrapper eb-advance-heading-jztlz button-1 undefined" data-id="eb-advance-heading-jztlz"><h2 class="eb-ah-title"><span class="first-title">4.1 &#8211; <strong>Cấu hình VPN Site-to-Site giữa 2 chi nhánh</strong></span></h2></div></div></div>



<p>Link tham khảo: <a href="https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-site-to-site-giua-sophos-va-fortinet-voi-ip-wan-la-ip-tinh/">https://thegioifirewall.com/huong-dan-cau-hinh-ipsec-vpn-site-to-site-giua-sophos-va-fortinet-voi-ip-wan-la-ip-tinh/</a></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-1yr68"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-1yr68 "><div class="eb-advance-heading-wrapper eb-advance-heading-1yr68 button-1 undefined" data-id="eb-advance-heading-1yr68"><h2 class="eb-ah-title"><span class="first-title">4.2 &#8211; <strong>Cấu hình đường IPSec là đường backup cho đường MPLS</strong></span></h2></div></div></div>



<ul class="wp-block-list"></ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="942" height="500" src="https://vacif.com/wp-content/uploads/2025/03/image-8.png" alt="" class="wp-image-21794" srcset="https://vacif.com/wp-content/uploads/2025/03/image-8.png 942w, https://vacif.com/wp-content/uploads/2025/03/image-8-600x318.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-8-300x159.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-8-768x408.png 768w" sizes="auto, (max-width: 942px) 100vw, 942px" /></figure>
</div>


<ul class="wp-block-list">
<li>Chạy câu lệnh để xét đường IPSec backup cho đường MPLS.</li>



<li><strong>SYNTAX:</strong> <em>system link_failover add primarylink &lt;MPLSPort&gt; backuplink vpn tunnel &lt;VPNLink&gt; monitor PING host &lt;RemoteIP&gt;</em><em></em></li>



<li>Dưới dây là hình ảnh show kết quả cấu hình đường link Failover của MPLS.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="960" height="280" src="https://vacif.com/wp-content/uploads/2025/03/image-9.png" alt="" class="wp-image-21795" srcset="https://vacif.com/wp-content/uploads/2025/03/image-9.png 960w, https://vacif.com/wp-content/uploads/2025/03/image-9-600x175.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-9-300x88.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-9-768x224.png 768w" sizes="auto, (max-width: 960px) 100vw, 960px" /></figure>
</div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-uo0fe"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-uo0fe "><div class="eb-advance-heading-wrapper eb-advance-heading-uo0fe button-1 undefined" data-id="eb-advance-heading-uo0fe"><h2 class="eb-ah-title"><span class="first-title">4.3 &#8211; Cấu hình Static route để traffic đi trực tiếp qua đường MPLS</span></h2></div></div></div>



<p><ul><li>Đăng nhập vào <strong>sophos web admin.</strong></li></ul></p>



<ul class="wp-block-list">
<li>Đi tới <strong>Routing</strong> &gt;<strong> Static routes</strong> và add unicast routes IPv4.</li>
</ul>



<ul class="wp-block-list"></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="992" height="246" src="https://vacif.com/wp-content/uploads/2025/03/image-10.png" alt="" class="wp-image-21796" srcset="https://vacif.com/wp-content/uploads/2025/03/image-10.png 992w, https://vacif.com/wp-content/uploads/2025/03/image-10-600x149.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-10-300x74.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-10-768x190.png 768w" sizes="auto, (max-width: 992px) 100vw, 992px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-orx7t"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-orx7t "><div class="eb-advance-heading-wrapper eb-advance-heading-orx7t button-1 undefined" data-id="eb-advance-heading-orx7t"><h2 class="eb-ah-title"><span class="first-title">4.4 &#8211; Cấu hình thứ tự ưu tiên đường đi cho Static route</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đăng nhập vào console sophos CLI.Chọn option <strong>4. Device Console.</strong></li>



<li>Chạy câu lệnh để xét đường ưu tiên đường static route.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-9sepq"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-9sepq "><div class="eb-advance-heading-wrapper eb-advance-heading-9sepq button-1 undefined" data-id="eb-advance-heading-9sepq"><h2 class="eb-ah-title"><span class="first-title"><strong>** <strong>NOTE:</strong><em> </em>Thứ tự route mặc định trên firewall Sophos là Static route, SD_WAN route, VPN route.</strong></span></h2></div></div></div>



<ul class="wp-block-list">
<li><strong>SYNTAX:</strong><em> </em><em>system route_precedence set static sdwan_policyroute vpn</em></li>
</ul>



<ul class="wp-block-list">
<li><strong>Cấu hình Failover: </strong>Chuyển đổi tự động giữa MPLS và VPN khi có sự cố.Đăng nhập vào sophos web admin.Đi tới <strong>Routing</strong> &gt;<strong> SD_WAN profiles</strong> và add SD_WAN profiles mới.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="903" height="581" src="https://vacif.com/wp-content/uploads/2025/03/image-11.png" alt="" class="wp-image-21797" srcset="https://vacif.com/wp-content/uploads/2025/03/image-11.png 903w, https://vacif.com/wp-content/uploads/2025/03/image-11-600x386.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-11-300x193.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-11-768x494.png 768w" sizes="auto, (max-width: 903px) 100vw, 903px" /></figure>
</div>


<ul class="wp-block-list">
<li>Chuyển sang tab <strong>SD_WAN routes</strong>, tạo 1 SD_WAN route và chọn <strong>SD_WAN profiles</strong> vừa mới tạo.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="942" height="439" src="https://vacif.com/wp-content/uploads/2025/03/image-12.png" alt="" class="wp-image-21798" srcset="https://vacif.com/wp-content/uploads/2025/03/image-12.png 942w, https://vacif.com/wp-content/uploads/2025/03/image-12-600x280.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-12-300x140.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-12-768x358.png 768w" sizes="auto, (max-width: 942px) 100vw, 942px" /></figure>
</div>


<ul class="wp-block-list">
<li>Kiểm tra kết quả.</li>



<li>Ở đây mình đang có 2 đường WAN, 1 là đường MPLS và đường còn lại là đường viettel.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="883" height="291" src="https://vacif.com/wp-content/uploads/2025/03/image-13.png" alt="" class="wp-image-21799" srcset="https://vacif.com/wp-content/uploads/2025/03/image-13.png 883w, https://vacif.com/wp-content/uploads/2025/03/image-13-600x198.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-13-300x99.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-13-768x253.png 768w" sizes="auto, (max-width: 883px) 100vw, 883px" /></figure>
</div>


<ul class="wp-block-list">
<li>Ở tab <strong>SD_WAN profiles</strong> ta thấy đang chạy link MPLS</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="874" height="236" src="https://vacif.com/wp-content/uploads/2025/03/image-14.png" alt="" class="wp-image-21800" srcset="https://vacif.com/wp-content/uploads/2025/03/image-14.png 874w, https://vacif.com/wp-content/uploads/2025/03/image-14-600x162.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-14-300x81.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-14-768x207.png 768w" sizes="auto, (max-width: 874px) 100vw, 874px" /></figure>
</div>


<ul class="wp-block-list">
<li>Kết quả ping/tracert cho thấy rằng traffic đang đi qua đường MPLS.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="952" height="648" src="https://vacif.com/wp-content/uploads/2025/03/image-15.png" alt="" class="wp-image-21801" srcset="https://vacif.com/wp-content/uploads/2025/03/image-15.png 952w, https://vacif.com/wp-content/uploads/2025/03/image-15-600x408.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-15-300x204.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-15-768x523.png 768w" sizes="auto, (max-width: 952px) 100vw, 952px" /></figure>
</div>


<ul class="wp-block-list">
<li>Tiến hành off link MPLS.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="889" height="194" src="https://vacif.com/wp-content/uploads/2025/03/image-16.png" alt="" class="wp-image-21802" srcset="https://vacif.com/wp-content/uploads/2025/03/image-16.png 889w, https://vacif.com/wp-content/uploads/2025/03/image-16-600x131.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-16-300x65.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-16-768x168.png 768w" sizes="auto, (max-width: 889px) 100vw, 889px" /></figure>
</div>


<ul class="wp-block-list">
<li>Sẽ tự động chuyển qua đường viettel.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="855" height="199" src="https://vacif.com/wp-content/uploads/2025/03/image-17.png" alt="" class="wp-image-21803" srcset="https://vacif.com/wp-content/uploads/2025/03/image-17.png 855w, https://vacif.com/wp-content/uploads/2025/03/image-17-600x140.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-17-300x70.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-17-768x179.png 768w" sizes="auto, (max-width: 855px) 100vw, 855px" /></figure>
</div>


<ul class="wp-block-list">
<li>Kết quả ping thấy rằng traffic đang đi qua đường VPN.</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="924" height="333" src="https://vacif.com/wp-content/uploads/2025/03/image-18.png" alt="" class="wp-image-21804" srcset="https://vacif.com/wp-content/uploads/2025/03/image-18.png 924w, https://vacif.com/wp-content/uploads/2025/03/image-18-600x216.png 600w, https://vacif.com/wp-content/uploads/2025/03/image-18-300x108.png 300w, https://vacif.com/wp-content/uploads/2025/03/image-18-768x277.png 768w" sizes="auto, (max-width: 924px) 100vw, 924px" /></figure>
</div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-omljh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-omljh "><div class="eb-advance-heading-wrapper eb-advance-heading-omljh button-1 undefined" data-id="eb-advance-heading-omljh"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Kết luận</span></h2></div></div></div>



<p><strong>Cấu hình VPN Failover MPLS giúp:</strong></p>



<ul class="wp-block-list">
<li>Đảm bảo kết nối liên tục giữa các chi nhánh và trung tâm dữ liệu</li>



<li>Giảm thiểu gián đoạn dịch vụ khi MPLS gặp sự cố.</li>



<li>Tối ưu chi phí khi kết hợp MPLS và Internet thay vì chỉ sử dụng MPLS.</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/huong-dan-cau-hinh-vpn-failover-mpls-giua-sophos-va-fortigate-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
