<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sophos Firewall Firmware V22 &#8211; VACIF</title>
	<atom:link href="https://vacif.com/tag/sophos-firewall-firmware-v22/feed/" rel="self" type="application/rss+xml" />
	<link>https://vacif.com</link>
	<description>Đầu tư cho giá trị</description>
	<lastBuildDate>Thu, 07 May 2026 10:20:53 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://vacif.com/wp-content/uploads/2024/06/cropped-icon-32x32.png</url>
	<title>Sophos Firewall Firmware V22 &#8211; VACIF</title>
	<link>https://vacif.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>[Mới Nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình IPsec VPN Remote Access Trên Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ipsec-vpn-remote-access-tren-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ipsec-vpn-remote-access-tren-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 07 May 2026 10:16:58 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[IPsec VPN Remote Access]]></category>
		<category><![CDATA[Sophos endpoint]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29881</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình IPsec Remote Access VPN trên Sophos Firewall thông qua Sophos Connect Client, giúp người dùng từ xa có thể truy cập an toàn vào hệ thống mạng nội bộ của doanh nghiệp. Bên cạnh đó, bài viết cũng phân tích sự khác biệt giữa hai mô hình triển [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o user VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o user VPN&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 2: T\u1ea1o IPsec Profile&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 2: T\u1ea1o IPsec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;Phase 1 (Thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i ban \u0111\u1ea7u)&quot;,&quot;text&quot;:&quot;Phase 1 (Thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i ban \u0111\u1ea7u)&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;Phase 2 (Truy\u1ec1n d\u1eef li\u1ec7u VPN)&quot;,&quot;text&quot;:&quot;Phase 2 (Truy\u1ec1n d\u1eef li\u1ec7u VPN)&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh IPsec Remote Access&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh IPsec Remote Access&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho VPN&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 5: C\u00e0i Sophos Connect v\u00e0 export file c\u1ea5u h\u00ecnh \u0111\u1ec3 k\u1ebft n\u1ed1i&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 5: C\u00e0i Sophos Connect v\u00e0 export file c\u1ea5u h\u00ecnh \u0111\u1ec3 k\u1ebft n\u1ed1i&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o user VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-1-t\u1ea1o-user-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 2: T\u1ea1o IPsec Profile&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-2-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;Phase 1 (Thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i ban \u0111\u1ea7u)&quot;,&quot;value&quot;:&quot;phase-1-thi\u1ebft-l\u1eadp-k\u1ebft-n\u1ed1i-ban-\u0111\u1ea7u&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;Phase 2 (Truy\u1ec1n d\u1eef li\u1ec7u VPN)&quot;,&quot;value&quot;:&quot;phase-2-truy\u1ec1n-d\u1eef-li\u1ec7u-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh IPsec Remote Access&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-3-c\u1ea5u-h\u00ecnh-ipsec-remote-access&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-4-t\u1ea1o-firewall-rule-cho-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 5: C\u00e0i Sophos Connect v\u00e0 export file c\u1ea5u h\u00ecnh \u0111\u1ec3 k\u1ebft n\u1ed1i&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-5-c\u00e0i-sophos-connect-v\u00e0-export-file-c\u1ea5u-h\u00ecnh-\u0111\u1ec3-k\u1ebft-n\u1ed1i&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình<strong> IPsec Remote Access VPN trên Sophos Firewall</strong> thông qua <strong>Sophos Connect Client</strong>, giúp người dùng từ xa có thể truy cập an toàn vào hệ thống mạng nội bộ của doanh nghiệp.</p>



<p>Bên cạnh đó, bài viết cũng phân tích sự khác biệt giữa hai mô hình triển khai phổ biến:</p>



<ul class="wp-block-list">
<li><strong>Firewall quay PPPoE trực tiếp </strong>(khuyến nghị – đảm bảo IPsec hoạt động ổn định)</li>



<li><strong>Firewall đặt sau modem NAT </strong>(dễ phát sinh lỗi kết nối IPsec)</li>
</ul>



<p>Qua đó, giúp người đọc hiểu rõ nguyên nhân và lựa chọn mô hình triển khai phù hợp trong thực tế.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="2560" height="1243" src="https://vacif.com/wp-content/uploads/2026/05/image-109-scaled.png" alt="" class="wp-image-29883" srcset="https://vacif.com/wp-content/uploads/2026/05/image-109-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-109-300x146.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-109-1024x497.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-109-768x373.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-109-1536x746.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-109-2048x994.png 2048w" sizes="(max-width: 2560px) 100vw, 2560px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-tyrna"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-tyrna "><div class="eb-advance-heading-wrapper eb-advance-heading-tyrna button-1 undefined" data-id="eb-advance-heading-tyrna"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Trong thực tế, doanh nghiệp thường có nhu cầu cho phép nhân viên truy cập vào hệ thống nội bộ khi làm việc từ xa (tại nhà, quán cà phê hoặc khi đi công tác). Tuy nhiên, việc mở trực tiếp các dịch vụ nội bộ ra Internet tiềm ẩn nhiều rủi ro về bảo mật.</p>



<p>Vì vậy, giải pháp được đặt ra là triển khai VPN để tạo một kênh kết nối an toàn giữa người dùng bên ngoài và hệ thống mạng nội bộ.</p>



<p><strong>Yêu cầu:</strong></p>



<ul class="wp-block-list">
<li>Triển khai IPsec Remote Access VPN trên Sophos Firewall sử dụng Sophos Connect Client</li>



<li>Đảm bảo dữ liệu trao đổi được mã hóa, an toàn khi đi qua Internet</li>



<li>Người dùng sau khi kết nối VPN có thể truy cập vào các tài nguyên nội bộ như:
<ul class="wp-block-list">
<li>Server nội bộ</li>



<li>File chia sẻ (SMB)</li>



<li>Remote Desktop (RDP)</li>
</ul>
</li>



<li>Hạn chế truy cập, chỉ cho phép vào các mạng cần thiết (ví dụ: VLAN quản trị)</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x6cmy"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x6cmy "><div class="eb-advance-heading-wrapper eb-advance-heading-x6cmy button-1 undefined" data-id="eb-advance-heading-x6cmy"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<ol class="wp-block-list">
<li>Tạo user VPN</li>



<li>Tạo IPsec Profile</li>



<li>Cấu hình IPsec Remote Access</li>



<li>Tạo Firewall Rule cho VPN</li>



<li>Cài Sophos Connect và export file cấu hình để kết nối</li>
</ol>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hb5rp"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hb5rp "><div class="eb-advance-heading-wrapper eb-advance-heading-hb5rp button-1 undefined" data-id="eb-advance-heading-hb5rp"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">Bước 1: Tạo user VPN</span></h2></div></div></div>



<p>Authentication → Users → Add</p>



<figure class="wp-block-image size-full"><img decoding="async" width="2255" height="1062" src="https://vacif.com/wp-content/uploads/2026/05/Picture13.png" alt="" class="wp-image-29885" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture13.png 2255w, https://vacif.com/wp-content/uploads/2026/05/Picture13-300x141.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture13-1024x482.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture13-768x362.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture13-1536x723.png 1536w, https://vacif.com/wp-content/uploads/2026/05/Picture13-2048x965.png 2048w" sizes="(max-width: 2255px) 100vw, 2255px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a5bow"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a5bow "><div class="eb-advance-heading-wrapper eb-advance-heading-a5bow button-1 undefined" data-id="eb-advance-heading-a5bow"><h2 class="eb-ah-title"><span class="first-title">Bước 2: Tạo IPsec Profile</span></h2></div></div></div>



<p>Profiles → IPsec profiles → Add</p>



<p><strong>IPsec Profile</strong> dùng để định nghĩa các thông số bảo mật và cách thức thiết lập kết nối VPN giữa client và firewall. Để đảm bảo tương thích với Sophos Connect, profile nên cấu hình tương tự profile mặc định <strong>DefaultRemoteAccess.</strong></p>



<figure class="wp-block-image size-full"><img decoding="async" width="2255" height="1070" src="https://vacif.com/wp-content/uploads/2026/05/Picture14.png" alt="" class="wp-image-29886" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture14.png 2255w, https://vacif.com/wp-content/uploads/2026/05/Picture14-300x142.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture14-1024x486.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture14-768x364.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture14-1536x729.png 1536w, https://vacif.com/wp-content/uploads/2026/05/Picture14-2048x972.png 2048w" sizes="(max-width: 2255px) 100vw, 2255px" /></figure>



<p><strong>Thông tin chung</strong></p>



<ul class="wp-block-list">
<li><strong>Name: </strong>IPsec VPN Remote Access.</li>



<li><strong>Description: </strong>Description.</li>



<li><strong>Key exchange: </strong>IKEv1 &#8211; Chuẩn kết nối cũ.</li>



<li><strong>Authentication mode:</strong> Main mode &#8211; đảm bảo quá trình xác thực an toàn hơn.</li>



<li><strong>Key negotiation tries:</strong> 0 &#8211; cho phép thử kết nối không giới hạn nếu lần đầu thất bại.</li>



<li><strong>Re-key connection:</strong> Enable &nbsp;&#8211; tự động gia hạn kết nối khi sắp hết hạn.</li>



<li><strong>Use strict profile: </strong>Disable &#8211; cho phép linh hoạt khi thương lượng thuật toán giữa client và firewall.</li>



<li><strong>Pass data in compressed format:</strong> Disable &#8211; không cần thiết trong hầu hết trường hợp</li>



<li><strong>SHA2 with 96-bit truncation:</strong> Disable &#8211; giữ nguyên độ bảo mật đầy đủ của SHA2.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1769" height="839" src="https://vacif.com/wp-content/uploads/2026/05/Picture15.png" alt="" class="wp-image-29887" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture15.png 1769w, https://vacif.com/wp-content/uploads/2026/05/Picture15-300x142.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture15-1024x486.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture15-768x364.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture15-1536x728.png 1536w" sizes="auto, (max-width: 1769px) 100vw, 1769px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-z5slf"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-z5slf "><div class="eb-advance-heading-wrapper eb-advance-heading-z5slf button-1 undefined" data-id="eb-advance-heading-z5slf"><h2 class="eb-ah-title"><span class="first-title">Phase 1 (Thiết lập kết nối ban đầu)</span></h2></div></div></div>



<p>Đây là giai đoạn hai bên tạo kênh bảo mật để trao đổi khóa và xác thực lẫn nhau.</p>



<ul class="wp-block-list">
<li><strong>Key life: </strong>18000 seconds (thời gian tồn tại của phiên kết nối ban đầu)</li>



<li><strong>DH group: </strong>(giữ mặc định hệ thống – đảm bảo tương thích)</li>



<li><strong>Re-key margin: </strong>360 seconds (bắt đầu gia hạn trước khi hết hạn)</li>



<li><strong>Randomize re-keying margin: </strong>100% (tránh nhiều kết nối gia hạn cùng lúc)</li>
</ul>



<p><strong>Thuật toán:</strong></p>



<ul class="wp-block-list">
<li><strong>Encryption: </strong>AES256, AES256, AES128</li>



<li><strong>Authentication: </strong>SHA2-256, SHA1, SHA1</li>
</ul>



<p>Việc cấu hình nhiều thuật toán giúp firewall và client có thể “thương lượng” và chọn ra thuật toán phù hợp nhất để kết nối thành công.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2456" height="890" src="https://vacif.com/wp-content/uploads/2026/05/image-111.png" alt="" class="wp-image-29888" srcset="https://vacif.com/wp-content/uploads/2026/05/image-111.png 2456w, https://vacif.com/wp-content/uploads/2026/05/image-111-300x109.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-111-1024x371.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-111-768x278.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-111-1536x557.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-111-2048x742.png 2048w" sizes="auto, (max-width: 2456px) 100vw, 2456px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yjq7u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yjq7u "><div class="eb-advance-heading-wrapper eb-advance-heading-yjq7u button-1 undefined" data-id="eb-advance-heading-yjq7u"><h2 class="eb-ah-title"><span class="first-title">Phase 2 (Truyền dữ liệu VPN)</span></h2></div></div></div>



<p>Sau khi Phase 1 thành công, Phase 2 sẽ tạo kênh để truyền dữ liệu thực tế.</p>



<ul class="wp-block-list">
<li><strong>PFS group:</strong> Same as Phase 1 (tăng cường bảo mật cho mỗi phiên dữ liệu)</li>



<li><strong>Key life: </strong>3600 seconds (thời gian sử dụng khóa cho việc truyền dữ liệu)</li>
</ul>



<p><strong>Thuật toán:</strong></p>



<ul class="wp-block-list">
<li><strong>Encryption</strong>: AES256, AES256, AES128</li>



<li><strong>Authentication:</strong> SHA2-256, SHA1, SHA1</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2169" height="876" src="https://vacif.com/wp-content/uploads/2026/05/image-112.png" alt="" class="wp-image-29889" srcset="https://vacif.com/wp-content/uploads/2026/05/image-112.png 2169w, https://vacif.com/wp-content/uploads/2026/05/image-112-300x121.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-112-1024x414.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-112-768x310.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-112-1536x620.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-112-2048x827.png 2048w" sizes="auto, (max-width: 2169px) 100vw, 2169px" /></figure>



<p><strong>Dead Peer Detection (DPD)</strong></p>



<p>DPD giúp firewall kiểm tra xem client còn kết nối hay không.</p>



<ul class="wp-block-list">
<li><strong>Dead Peer Detection:</strong> Enable.</li>



<li><strong>Check peer after every: </strong>60 seconds &#8211; kiểm tra định kỳ.</li>



<li><strong>Wait for response up to:</strong> 240 seconds &nbsp;&#8211; thời gian chờ phản hồi.</li>



<li><strong>When peer unreachable:</strong> Disconnect &#8211; ngắt kết nối nếu không phản hồi.</li>
</ul>



<p>Nhấn <strong>Save</strong> để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0cghh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0cghh "><div class="eb-advance-heading-wrapper eb-advance-heading-0cghh button-1 undefined" data-id="eb-advance-heading-0cghh"><h2 class="eb-ah-title"><span class="first-title">Bước 3: Cấu hình IPsec Remote Access</span></h2></div></div></div>



<p><strong>Truy cập:</strong></p>



<p>Remote Access VPN → IPsec</p>



<p>Đây là bước cấu hình để bật tính năng IPsec Remote Access trên firewall và liên kết với profile đã tạo ở bước trước.</p>



<p><strong>General settings:</strong></p>



<ul class="wp-block-list">
<li><strong>IPsec remote access: </strong>Enable &#8211; Bật tính năng IPsec Remote Access trên firewall</li>



<li><strong>Interface:</strong> Port2 – 115.70.xxx.xxx &#8211; Cổng WAN nhận kết nối từ Internet</li>



<li><strong>IPsec profile:</strong> IPsec VPN Remote Access &#8211; Sử dụng profile đã tạo ở bước 1</li>
</ul>



<p><strong>Authentication:</strong></p>



<ul class="wp-block-list">
<li><strong>Authentication type:</strong> Preshared key &#8211; Xác thực bằng khóa bí mật dùng chung giữa client và firewall</li>



<li><strong>Preshared key:</strong> Client phải nhập đúng key này mới kết nối được</li>
</ul>



<p><strong>Identification:</strong></p>



<ul class="wp-block-list">
<li><strong>Local ID:</strong> Default</li>



<li><strong>Remote ID: </strong>Default</li>
</ul>



<p>Dùng để định danh 2 đầu VPN, trong lab có thể để mặc định</p>



<p><strong>Allowed users and groups:</strong></p>



<ul class="wp-block-list">
<li><strong>Allowed users and groups: </strong>it&nbsp; &#8211; Chỉ user thuộc group it mới được phép kết nối VPN</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2207" height="1146" src="https://vacif.com/wp-content/uploads/2026/05/Picture16.png" alt="" class="wp-image-29891" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture16.png 2207w, https://vacif.com/wp-content/uploads/2026/05/Picture16-300x156.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture16-1024x532.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture16-768x399.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture16-1536x798.png 1536w, https://vacif.com/wp-content/uploads/2026/05/Picture16-2048x1063.png 2048w" sizes="auto, (max-width: 2207px) 100vw, 2207px" /></figure>



<p><strong>Client information:</strong></p>



<ul class="wp-block-list">
<li><strong>Name: </strong>it &#8211; Tên cấu hình VPN (hiển thị khi export file cho client)</li>



<li><strong>Assign IP from: </strong>11.11.11.1 – 11.11.11.10 -&gt; Dải IP cấp cho user khi kết nối VPN</li>



<li><strong>DNS server 1 / 2:</strong> Có thể thêm DNS nội bộ nếu cần resolve domain nội bộ</li>
</ul>



<p><strong>Idle timeout:</strong></p>



<ul class="wp-block-list">
<li><strong>Disconnect when tunnel is idle:</strong> Tự ngắt VPN nếu không có hoạt động</li>



<li><strong>Idle session time interval: </strong>(120–21600s) &#8211; Thời gian chờ trước khi ngắt</li>
</ul>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-ns83o"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-ns83o "><figure class="eb-advanced-image-wrapper eb-advanced-image-ns83o no-effect" data-id="eb-advanced-image-ns83o"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture17.png" alt=""/></div></div></figure></div></div>



<p><strong>Advanced settings:</strong></p>



<ul class="wp-block-list">
<li><strong>Use as default gateway:</strong>
<ul class="wp-block-list">
<li><strong>Nếu bật:</strong> toàn bộ traffic client đi qua VPN</li>



<li><strong>Nếu tắt:</strong> chỉ đi các mạng nội bộ (split tunnel)</li>
</ul>
</li>



<li><strong>Permitted network resources (IPv4): </strong>VLAN_10_MGMT &#8211; Chỉ cho phép truy cập vào mạng nội bộ VLAN_10_MGMT</li>



<li><strong>Send Security Heartbeat through tunnel: </strong>Dùng cho Sophos endpoint</li>



<li><strong>Allow users to save username and password: </strong>Enable &#8211; Cho phép client lưu thông tin đăng nhập</li>



<li><strong>Prompt users for 2FA token: </strong>Dùng nếu có xác thực 2 lớp</li>



<li><strong>Run AD logon script after connecting: </strong>Tùy chọn</li>



<li><strong>Hostname or DNS suffix to monitor: </strong>Tùy chọn</li>



<li><strong>Connect tunnel automatically: </strong>Dùng để auto connect VPN khi truy cập domain</li>



<li><strong>DNS suffix</strong>: Dùng cho môi trường domain nội bộ</li>
</ul>



<p>Nhấn <strong>Apply</strong> để lưu cấu hình và nhấn <strong>Export Connection</strong> để lấy file đăng nhập.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1824" height="868" src="https://vacif.com/wp-content/uploads/2026/05/Picture18.png" alt="" class="wp-image-29893" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture18.png 1824w, https://vacif.com/wp-content/uploads/2026/05/Picture18-300x143.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture18-1024x487.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture18-768x365.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture18-1536x731.png 1536w" sizes="auto, (max-width: 1824px) 100vw, 1824px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ih251"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ih251 "><div class="eb-advance-heading-wrapper eb-advance-heading-ih251 button-1 undefined" data-id="eb-advance-heading-ih251"><h2 class="eb-ah-title"><span class="first-title">Bước 4: Tạo Firewall Rule cho VPN</span></h2></div></div></div>



<p><strong>Truy cập:</strong></p>



<p>Rules and Policies → Firewall Rules → Add</p>



<p>Firewall Rule dùng để cho phép traffic từ VPN đi vào mạng nội bộ và ngược lại. Nếu không có rule này, dù VPN kết nối thành công thì user vẫn không truy cập được tài nguyên bên trong.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="525" src="https://vacif.com/wp-content/uploads/2026/05/image-114-scaled.png" alt="" class="wp-image-29895" srcset="https://vacif.com/wp-content/uploads/2026/05/image-114-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-114-300x62.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-114-1024x210.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-114-768x158.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-114-1536x315.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-114-2048x420.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p><strong>Thông tin chung:</strong></p>



<ul class="wp-block-list">
<li><strong>Rule name:</strong> IPsec VPN Remote Access</li>



<li><strong>Action:</strong> Accept &#8211; cho phép lưu lượng đi qua</li>



<li><strong>Log firewall traffic: </strong>Enable &#8211; ghi log để dễ kiểm tra khi cần</li>



<li><strong>Description:</strong> (tùy chọn)</li>



<li><strong>Rule group:</strong> None</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="575" src="https://vacif.com/wp-content/uploads/2026/05/image-115-scaled.png" alt="" class="wp-image-29896" srcset="https://vacif.com/wp-content/uploads/2026/05/image-115-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-115-300x67.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-115-1024x230.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-115-768x172.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-115-1536x345.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-115-2048x460.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p><strong>Source zones: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>LAN</li>



<li>VPN</li>
</ul>



<p>Cho phép traffic từ cả mạng nội bộ và user VPN</p>



<p><strong>Source networks and devices: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>11 (dải IP VPN: 11.11.11.1 – 11.11.11.10) là IP được cấp cho client VPN</li>



<li>VLAN_10_MGMT là mạng nội bộ</li>
</ul>



<p><strong>Destination zones: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>LAN</li>



<li>VPN</li>
</ul>



<p>Cho phép truy cập hai chiều</p>



<p><strong>Destination networks: </strong><strong></strong></p>



<ul class="wp-block-list">
<li>11 &#8211; cho phép chiều ngược lại (LAN có thể phản hồi lại VPN client)</li>



<li>VLAN_10_MGMT &nbsp;&#8211; là mạng nội bộ mà user VPN được phép truy cập</li>
</ul>



<p>Nhấn<strong> Save / Apply</strong> để lưu rule</p>



<p></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dfwgb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dfwgb "><div class="eb-advance-heading-wrapper eb-advance-heading-dfwgb button-1 undefined" data-id="eb-advance-heading-dfwgb"><h2 class="eb-ah-title"><span class="first-title">Bước 5: Cài Sophos Connect và export file cấu hình để kết nối</span></h2></div></div></div>



<p>Sau khi hoàn tất cấu hình trên firewall, cần export file cấu hình VPN và cài đặt Sophos Connect trên máy người dùng để thực hiện kết nối.</p>



<p>Khi export cấu hình IPsec VPN từ Sophos Firewall, hệ thống có thể cung cấp hai loại file với mục đích sử dụng khác nhau:</p>



<ul class="wp-block-list">
<li><strong>File .scx: </strong>Đây là file cấu hình dành cho người dùng cuối, được sử dụng để import vào Sophos Connect Client nhằm thiết lập kết nối VPN. File này chứa đầy đủ thông tin cần thiết như địa chỉ gateway, cấu hình IPsec và các tham số kết nối.</li>



<li><strong>File .tgb: </strong>Đây là file backup cấu hình, được sử dụng cho mục đích sao lưu và khôi phục trên firewall. File này không dùng cho client và không thể import vào Sophos Connect.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1141" src="https://vacif.com/wp-content/uploads/2026/05/image-116-scaled.png" alt="" class="wp-image-29897" srcset="https://vacif.com/wp-content/uploads/2026/05/image-116-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-116-300x134.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-116-1024x456.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-116-768x342.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-116-1536x684.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-116-2048x913.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1575" height="1371" src="https://vacif.com/wp-content/uploads/2026/05/image-117.png" alt="" class="wp-image-29898" srcset="https://vacif.com/wp-content/uploads/2026/05/image-117.png 1575w, https://vacif.com/wp-content/uploads/2026/05/image-117-300x261.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-117-1024x891.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-117-768x669.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-117-1536x1337.png 1536w" sizes="auto, (max-width: 1575px) 100vw, 1575px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2345" height="1394" src="https://vacif.com/wp-content/uploads/2026/05/image-118.png" alt="" class="wp-image-29899" srcset="https://vacif.com/wp-content/uploads/2026/05/image-118.png 2345w, https://vacif.com/wp-content/uploads/2026/05/image-118-300x178.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-118-1024x609.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-118-768x457.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-118-1536x913.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-118-2048x1217.png 2048w" sizes="auto, (max-width: 2345px) 100vw, 2345px" /></figure>



<p>Ngoài ra, bạn có thể truy cập mục <strong>Current Activities</strong> để theo dõi các phiên VPN đang hoạt động, bao gồm thông tin người dùng đang đăng nhập và loại client đang sử dụng.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="591" src="https://vacif.com/wp-content/uploads/2026/05/image-119-scaled.png" alt="" class="wp-image-29900" srcset="https://vacif.com/wp-content/uploads/2026/05/image-119-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-119-300x69.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-119-1024x236.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-119-768x177.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-119-1536x354.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-119-2048x473.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ipsec-vpn-remote-access-tren-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình SSL VPN Client To Site Với Client Windows Và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ssl-vpn-client-to-site-voi-client-windows-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ssl-vpn-client-to-site-voi-client-windows-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 07 May 2026 08:39:15 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Client Windows]]></category>
		<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[SSL VPN Client To Site]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29849</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình SSL VPN Client-to-Site trên Sophos Firewall firmware v22, cho phép người dùng từ xa (remote user) sử dụng máy Windows kết nối an toàn vào mạng nội bộ doanh nghiệp thông qua Internet. Sau khi hoàn thành, người dùng có thể: Doanh nghiệp cần: Yêu cầu: Tổng quan [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i &quot;,&quot;text&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i &quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u &quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u &quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o User v\u00e0 Group&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o User v\u00e0 Group&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;T\u1ea1o Group&quot;,&quot;text&quot;:&quot;T\u1ea1o Group&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;T\u1ea1o User&quot;,&quot;text&quot;:&quot;T\u1ea1o User&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 2: C\u1ea5u h\u00ecnh SSL VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 2: C\u1ea5u h\u00ecnh SSL VPN&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh SSL VPN Global Settings&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh SSL VPN Global Settings&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho ph\u00e9p truy c\u1eadp t\u1eeb VPN v\u00e0o v\u00f9ng LAN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho ph\u00e9p truy c\u1eadp t\u1eeb VPN v\u00e0o v\u00f9ng LAN&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 5: T\u1ea3i VPN Client v\u00e0 file c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 5: T\u1ea3i VPN Client v\u00e0 file c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 6: C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m Sophos Connect&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 6: C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m Sophos Connect&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 7: Import c\u1ea5u h\u00ecnh VPN v\u00e0o Sophos Connect&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 7: Import c\u1ea5u h\u00ecnh VPN v\u00e0o Sophos Connect&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;B\u01b0\u1edbc 8: Test k\u1ebft n\u1ed1i SSL VPN&quot;,&quot;text&quot;:&quot;B\u01b0\u1edbc 8: Test k\u1ebft n\u1ed1i SSL VPN&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i &quot;,&quot;value&quot;:&quot;i-m\u1ee5c-\u0111\u00edch-b\u00e0i&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u &quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;B\u01b0\u1edbc 1: T\u1ea1o User v\u00e0 Group&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-1-t\u1ea1o-user-v\u00e0-group&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;T\u1ea1o Group&quot;,&quot;value&quot;:&quot;t\u1ea1o-group&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;T\u1ea1o User&quot;,&quot;value&quot;:&quot;t\u1ea1o-user&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 2: C\u1ea5u h\u00ecnh SSL VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-2-c\u1ea5u-h\u00ecnh-ssl-vpn&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 3: C\u1ea5u h\u00ecnh SSL VPN Global Settings&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-3-c\u1ea5u-h\u00ecnh-ssl-vpn-global-settings&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 4: T\u1ea1o Firewall Rule cho ph\u00e9p truy c\u1eadp t\u1eeb VPN v\u00e0o v\u00f9ng LAN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-4-t\u1ea1o-firewall-rule-cho-ph\u00e9p-truy-c\u1eadp-t\u1eeb-vpn-v\u00e0o-v\u00f9ng-lan&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 5: T\u1ea3i VPN Client v\u00e0 file c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-5-t\u1ea3i-vpn-client-v\u00e0-file-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 6: C\u00e0i \u0111\u1eb7t ph\u1ea7n m\u1ec1m Sophos Connect&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-6-c\u00e0i-\u0111\u1eb7t-ph\u1ea7n-m\u1ec1m-sophos-connect&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 7: Import c\u1ea5u h\u00ecnh VPN v\u00e0o Sophos Connect&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-7-import-c\u1ea5u-h\u00ecnh-vpn-v\u00e0o-sophos-connect&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;B\u01b0\u1edbc 8: Test k\u1ebft n\u1ed1i SSL VPN&quot;,&quot;value&quot;:&quot;b\u01b0\u1edbc-8-test-k\u1ebft-n\u1ed1i-ssl-vpn&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Mục đích bài </a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu </a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Mục đích bài </span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình <strong>SSL VPN Client-to-Site</strong> trên Sophos Firewall firmware v22, cho phép người dùng từ xa (remote user) sử dụng máy Windows kết nối an toàn vào mạng nội bộ doanh nghiệp thông qua Internet.</p>



<p>Sau khi hoàn thành, người dùng có thể:</p>



<ul class="wp-block-list">
<li>Truy cập tài nguyên nội bộ (Server, NAS, RDP, Web nội bộ…)</li>



<li>Mã hóa kết nối đảm bảo an toàn dữ liệu</li>



<li>Xác thực bằng tài khoản người dùng trên Sophos Firewall</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="422" src="https://vacif.com/wp-content/uploads/2026/05/image-94-1024x422.png" alt="" class="wp-image-29853" srcset="https://vacif.com/wp-content/uploads/2026/05/image-94-1024x422.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-94-300x124.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-94-768x316.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-94-1536x633.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-94-2048x843.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dpdzc"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dpdzc "><div class="eb-advance-heading-wrapper eb-advance-heading-dpdzc button-1 undefined" data-id="eb-advance-heading-dpdzc"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu </span></h2></div></div></div>



<p>Doanh nghiệp cần:</p>



<ul class="wp-block-list">
<li>Nhân viên truy cập từ xa (WFH)</li>



<li>Kết nối vào LAN nội bộ</li>



<li>Đảm bảo bảo mật và kiểm soát truy cập</li>
</ul>



<p>Yêu cầu:</p>



<ul class="wp-block-list">
<li>Chỉ user hợp lệ mới được VPN</li>



<li>Truy cập server nội bộ (RDP, File Server)</li>



<li>Có thể mở rộng MFA sau này</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qtw7f"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qtw7f "><div class="eb-advance-heading-wrapper eb-advance-heading-qtw7f button-1 undefined" data-id="eb-advance-heading-qtw7f"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<p>Tổng quan các bước:</p>



<ol class="wp-block-list">
<li>Tạo User và Group</li>



<li>Cấu hình SSL VPN Profile</li>



<li>Cấu hình SSL VPN Global Settings</li>



<li>Tạo Firewall Rule cho phép truy cập từ VPN vào vùng LAN</li>



<li>Tải VPN Client và file cấu hình</li>



<li>Cài đặt phần mềm Sophos Connect</li>



<li>Import cấu hình VPN vào Sophos Connect</li>



<li>Test kết nối SSL VPN</li>
</ol>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-3sz4j"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-3sz4j "><div class="eb-advance-heading-wrapper eb-advance-heading-3sz4j button-1 undefined" data-id="eb-advance-heading-3sz4j"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">Bước 1: Tạo User và Group</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-3o54l"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-3o54l "><div class="eb-advance-heading-wrapper eb-advance-heading-3o54l button-1 undefined" data-id="eb-advance-heading-3o54l"><h2 class="eb-ah-title"><span class="first-title">Tạo Group</span></h2></div></div></div>



<p>Authentication → Groups → Add</p>



<ul class="wp-block-list">
<li>Group Name: VACIF GROUP</li>



<li>Surfing quota: Unlimited Internet Access</li>



<li>Access time: Allowed all the time</li>
</ul>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-g6bpo"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-g6bpo "><figure class="eb-advanced-image-wrapper eb-advanced-image-g6bpo no-effect" data-id="eb-advanced-image-g6bpo"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture1-2-scaled.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0i5mh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0i5mh "><div class="eb-advance-heading-wrapper eb-advance-heading-0i5mh button-1 undefined" data-id="eb-advance-heading-0i5mh"><h2 class="eb-ah-title"><span class="first-title">Tạo User</span></h2></div></div></div>



<p>Authentication → Users → Add</p>



<ul class="wp-block-list">
<li>Username: VACIF</li>



<li>Password: ****</li>



<li>Group: VACIF GROUP</li>
</ul>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-lqq0z"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-lqq0z "><figure class="eb-advanced-image-wrapper eb-advanced-image-lqq0z no-effect" data-id="eb-advanced-image-lqq0z"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture3.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ahlmg"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ahlmg "><div class="eb-advance-heading-wrapper eb-advance-heading-ahlmg button-1 undefined" data-id="eb-advance-heading-ahlmg"><h2 class="eb-ah-title"><span class="first-title">Bước 2: Cấu hình SSL VPN</span></h2></div></div></div>



<p>VPN → Remote Access VPN → SSL VPN → Add → Configure manually</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-65sev"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-65sev "><figure class="eb-advanced-image-wrapper eb-advanced-image-65sev no-effect" data-id="eb-advanced-image-65sev"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture4-scaled.png" alt=""/></div></div></figure></div></div>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="565" src="https://vacif.com/wp-content/uploads/2026/05/image-98-1024x565.png" alt="" class="wp-image-29860" srcset="https://vacif.com/wp-content/uploads/2026/05/image-98-1024x565.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-98-300x166.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-98-768x424.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-98-1536x847.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-98-2048x1130.png 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>Thực hiện cấu hình các thông số sau:</strong></p>



<ul class="wp-block-list">
<li><strong>Name:</strong> Đặt tên cho cấu hình SSL VPN (ví dụ: SSLVPN-IT)</li>



<li><strong>Policy members: </strong>Chọn user hoặc group đã tạo trước đó (ví dụ: vpnuser01 hoặc SSLVPN-Users)</li>



<li><strong>Use as default gateway:</strong>
<ul class="wp-block-list">
<li><strong>Bật</strong> khi muốn toàn bộ lưu lượng của VPN Client đi qua Sophos Firewall (Full Tunnel)</li>



<li><strong>Không bật </strong>khi chỉ định tuyến lưu lượng truy cập vào mạng nội bộ qua VPN (Split Tunnel)</li>
</ul>
</li>



<li><strong>Permitted network resources (IPv4)</strong>: Chọn các dải mạng nội bộ (LAN) mà người dùng VPN được phép truy cập (ví dụ: 10.10.10.0/24)</li>



<li><strong>Disconnect idle clients: </strong>Tự động ngắt kết nối VPN khi người dùng không có hoạt động trong một khoảng thời gian nhất định</li>
</ul>



<p>→ Nhấn <strong>Apply </strong>để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-lii7j"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-lii7j "><figure class="eb-advanced-image-wrapper eb-advanced-image-lii7j no-effect" data-id="eb-advanced-image-lii7j"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture5.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-886cg"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-886cg "><div class="eb-advance-heading-wrapper eb-advance-heading-886cg button-1 undefined" data-id="eb-advance-heading-886cg"><h2 class="eb-ah-title"><span class="first-title">Bước 3: Cấu hình SSL VPN Global Settings</span></h2></div></div></div>



<p>VPN → Remote Access VPN → SSL VPN → Global Settings</p>



<ul class="wp-block-list">
<li><strong>Protocol: </strong>Chọn UDP để tối ưu hiệu suất và giảm độ trễ khi kết nối VPN</li>



<li><strong>SSL server certificate: </strong>Giữ nguyên ApplianceCertificate (chứng chỉ mặc định của thiết bị)</li>



<li><strong>Override hostname:</strong> Nhập địa chỉ IP WAN hoặc tên miền mà người dùng VPN sẽ sử dụng để kết nối (ví dụ: 123.20.173.178 hoặc vpn.company.com)</li>



<li><strong>Port:</strong> Giữ mặc định <strong>8443</strong> hoặc thay đổi nếu có yêu cầu riêng (Ở đây mình đặt 10443)</li>



<li><strong>Assign IPv4 addresses: </strong>Khai báo dải IP cấp phát cho VPN Client <em>(ví dụ: </em><em>10.121.10.0/24</em><em>)</em></li>



<li><strong>IPv4 DNS: </strong>Cấu hình DNS để client có thể phân giải tên miền khi kết nối VPN <em>(ví dụ: </em><em>8.8.8.8</em><em>, </em><em>1.1.1.1</em><em> hoặc DNS nội bộ)</em></li>



<li><strong>Disconnect dead peer after: </strong>Thiết lập thời gian (giây) để tự động ngắt kết nối khi client không phản hồi</li>



<li><strong>Disconnect idle peer after: </strong>Thiết lập thời gian ngắt kết nối khi người dùng không có hoạt động Có thể để trống &#8211; nên để trống nếu không giới hạn</li>
</ul>



<p>→ Nhấn <strong>Apply </strong>để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-qainb"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-qainb "><figure class="eb-advanced-image-wrapper eb-advanced-image-qainb no-effect" data-id="eb-advanced-image-qainb"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture6.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-k7b8x"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-k7b8x "><div class="eb-advance-heading-wrapper eb-advance-heading-k7b8x button-1 undefined" data-id="eb-advance-heading-k7b8x"><h2 class="eb-ah-title"><span class="first-title">Bước 4: Tạo Firewall Rule cho phép truy cập từ VPN vào vùng LAN</span></h2></div></div></div>



<p>Rules and Policies → Firewall Rules</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-ybbxr"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-ybbxr "><figure class="eb-advanced-image-wrapper eb-advanced-image-ybbxr no-effect" data-id="eb-advanced-image-ybbxr"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture7-scaled.png" alt=""/></div></div></figure></div></div>



<p><strong>Thực hiện cấu hình các thông số sau:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><tbody><tr><td><strong>Mục cấu hình</strong></td><td><strong>Giá trị đề xuất</strong></td></tr><tr><td>Rule Name</td><td>VACIF RULE VPN</td></tr><tr><td>Action</td><td>Accept</td></tr><tr><td>Log firewal traffic</td><td>On</td></tr><tr><td>Source zone</td><td>VPN</td></tr><tr><td>Source networks and devices</td><td>Any</td></tr><tr><td>During scheduled time</td><td>All the time</td></tr><tr><td>Destination zones</td><td>LAN</td></tr><tr><td>Destination networks</td><td>Lớp mạng local bạn muốn truy cập</td></tr><tr><td>Services</td><td>Any</td></tr></tbody></table></figure>



<p>→ Nhấn <strong>Save </strong>để lưu cấu hình</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-idgle"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-idgle "><figure class="eb-advanced-image-wrapper eb-advanced-image-idgle no-effect" data-id="eb-advanced-image-idgle"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture9.png" alt=""/></div></div></figure></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0z6tv"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0z6tv "><div class="eb-advance-heading-wrapper eb-advance-heading-0z6tv button-1 undefined" data-id="eb-advance-heading-0z6tv"><h2 class="eb-ah-title"><span class="first-title">Bước 5: Tải VPN Client và file cấu hình</span></h2></div></div></div>



<p>Để biết được port VPN là bao nhiêu thì bạn cần phải vào:</p>



<p>Administrator → Admin and user settings</p>



<div class="wp-block-essential-blocks-advanced-image  root-eb-advanced-image-jyd90"><div class="eb-parent-wrapper eb-parent-eb-advanced-image-jyd90 "><figure class="eb-advanced-image-wrapper eb-advanced-image-jyd90 no-effect" data-id="eb-advanced-image-jyd90"><div class="eb-image-wrapper"><div class="eb-image-wrapper-inner eb-img-style-square"><img decoding="async" src="https://vacif.com/wp-content/uploads/2026/05/Picture10-scaled.png" alt=""/></div></div></figure></div></div>



<ul class="wp-block-list">
<li>Tiếp theo, truy cập <strong>VPN Portal</strong> bằng trình duyệt: https://&lt;WAN-IP hoặc tên miền&gt;:8443</li>



<li>Đăng nhập bằng tài khoản VPN mà bạn đã tạo trước đó.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1477" src="https://vacif.com/wp-content/uploads/2026/05/image-100-scaled.png" alt="" class="wp-image-29868" srcset="https://vacif.com/wp-content/uploads/2026/05/image-100-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-100-300x173.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-100-1024x591.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-100-768x443.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-100-1536x886.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-100-2048x1181.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>



<p>Tại giao diện Portal:</p>



<ul class="wp-block-list">
<li>Nhấn <strong>Download for Windows</strong> trong mục <strong>Sophos Connect client</strong> để tải phần mềm</li>



<li>Nhấn <strong>Download for Windows, macOS, Linux</strong> trong mục <strong>VPN configuration</strong> để tải file cấu hình SSL VPN (.ovpn)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1643" height="851" src="https://vacif.com/wp-content/uploads/2026/05/Picture12.png" alt="" class="wp-image-29869" srcset="https://vacif.com/wp-content/uploads/2026/05/Picture12.png 1643w, https://vacif.com/wp-content/uploads/2026/05/Picture12-300x155.png 300w, https://vacif.com/wp-content/uploads/2026/05/Picture12-1024x530.png 1024w, https://vacif.com/wp-content/uploads/2026/05/Picture12-768x398.png 768w, https://vacif.com/wp-content/uploads/2026/05/Picture12-1536x796.png 1536w" sizes="auto, (max-width: 1643px) 100vw, 1643px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dfep1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dfep1 "><div class="eb-advance-heading-wrapper eb-advance-heading-dfep1 button-1 undefined" data-id="eb-advance-heading-dfep1"><h2 class="eb-ah-title"><span class="first-title">Bước 6: Cài đặt phần mềm Sophos Connect</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chạy file cài đặt: SophosConnect_&lt;version&gt;.exe</li>



<li>Tại màn hình cài đặt: Tick chọn “I accept the Sophos End User License Agreement and acknowledge the Sophos Privacy Policy”</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="556" src="https://vacif.com/wp-content/uploads/2026/05/image-101.png" alt="" class="wp-image-29870" srcset="https://vacif.com/wp-content/uploads/2026/05/image-101.png 975w, https://vacif.com/wp-content/uploads/2026/05/image-101-300x171.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-101-768x438.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iasma"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iasma "><div class="eb-advance-heading-wrapper eb-advance-heading-iasma button-1 undefined" data-id="eb-advance-heading-iasma"><h2 class="eb-ah-title"><span class="first-title">Bước 7: Import cấu hình VPN vào Sophos Connect</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Mở phần mềm <strong>Sophos Connect</strong></li>



<li>Tại giao diện chính: Nhấn <strong>Import connection </strong></li>



<li>Chọn file cấu hình đã tải: sslvpn-vacif-client-config.ovpn</li>



<li>Sau khi import thành công: Kết nối VPN sẽ hiển thị trong danh sách</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="744" height="422" src="https://vacif.com/wp-content/uploads/2026/05/image-102.png" alt="" class="wp-image-29871" srcset="https://vacif.com/wp-content/uploads/2026/05/image-102.png 744w, https://vacif.com/wp-content/uploads/2026/05/image-102-300x170.png 300w" sizes="auto, (max-width: 744px) 100vw, 744px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="967" height="726" src="https://vacif.com/wp-content/uploads/2026/05/image-103.png" alt="" class="wp-image-29872" srcset="https://vacif.com/wp-content/uploads/2026/05/image-103.png 967w, https://vacif.com/wp-content/uploads/2026/05/image-103-300x225.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-103-768x577.png 768w" sizes="auto, (max-width: 967px) 100vw, 967px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="726" height="764" src="https://vacif.com/wp-content/uploads/2026/05/image-104.png" alt="" class="wp-image-29873" srcset="https://vacif.com/wp-content/uploads/2026/05/image-104.png 726w, https://vacif.com/wp-content/uploads/2026/05/image-104-285x300.png 285w" sizes="auto, (max-width: 726px) 100vw, 726px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="881" height="890" src="https://vacif.com/wp-content/uploads/2026/05/image-105.png" alt="" class="wp-image-29874" srcset="https://vacif.com/wp-content/uploads/2026/05/image-105.png 881w, https://vacif.com/wp-content/uploads/2026/05/image-105-297x300.png 297w, https://vacif.com/wp-content/uploads/2026/05/image-105-768x776.png 768w" sizes="auto, (max-width: 881px) 100vw, 881px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0mezb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0mezb "><div class="eb-advance-heading-wrapper eb-advance-heading-0mezb button-1 undefined" data-id="eb-advance-heading-0mezb"><h2 class="eb-ah-title"><span class="first-title">Bước 8: Test kết nối SSL VPN</span></h2></div></div></div>



<p>Lúc này bạn có thể truy cập vào trong lớp mạng LAN nội bộ đã cấu hình. Ngoài ra bạn có thể vào mục Current activities để kiểm tra xem user nào đang đăng nhập SSL VPN.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2272" height="1402" src="https://vacif.com/wp-content/uploads/2026/05/image-107.png" alt="" class="wp-image-29876" srcset="https://vacif.com/wp-content/uploads/2026/05/image-107.png 2272w, https://vacif.com/wp-content/uploads/2026/05/image-107-300x185.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-107-1024x632.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-107-768x474.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-107-1536x948.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-107-2048x1264.png 2048w" sizes="auto, (max-width: 2272px) 100vw, 2272px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="2560" height="1198" src="https://vacif.com/wp-content/uploads/2026/05/image-108-scaled.png" alt="" class="wp-image-29877" srcset="https://vacif.com/wp-content/uploads/2026/05/image-108-scaled.png 2560w, https://vacif.com/wp-content/uploads/2026/05/image-108-300x140.png 300w, https://vacif.com/wp-content/uploads/2026/05/image-108-1024x479.png 1024w, https://vacif.com/wp-content/uploads/2026/05/image-108-768x359.png 768w, https://vacif.com/wp-content/uploads/2026/05/image-108-1536x719.png 1536w, https://vacif.com/wp-content/uploads/2026/05/image-108-2048x958.png 2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-ssl-vpn-client-to-site-voi-client-windows-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site To Site Giữa 2 Thiết Bị Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 08:07:55 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Cấu Hình VPN Site To Site]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29071</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình IPsec Site-to-Site VPN giữa hai thiết bị Sophos Firewall XGS sử dụng firmware v22, nhằm xây dựng kết nối bảo mật giữa hai hệ thống mạng đặt tại hai địa điểm khác nhau. Mục tiêu của bài lab: Môi trường triển khai: Doanh nghiệp có hai site sử [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;text&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;text&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-chi-ti\u1ebft-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-2-thi\u1ebft-b\u1ecb-sophos-firewall-firmware-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;value&quot;:&quot;1-c\u1ea5u-h\u00ecnh-tr\u00ean-sophos-firewall-1&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;value&quot;:&quot;2-c\u1ea5u-h\u00ecnh-tr\u00ean-sophos-firewall-2&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu </a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn chi tiết cấu hình VPN site to site giữa 2 thiết bị Sophos Firewall Firmware V22</a><li><a href="#eb-table-content-5">1. Cấu hình trên Sophos Firewall 1</a><li><a href="#eb-table-content-6">2. Cấu hình trên Sophos Firewall 2</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình IPsec Site-to-Site VPN giữa hai thiết bị Sophos Firewall XGS sử dụng firmware v22, nhằm xây dựng kết nối bảo mật giữa hai hệ thống mạng đặt tại hai địa điểm khác nhau.</p>



<p><strong>Mục tiêu của bài lab:</strong></p>



<ul class="wp-block-list">
<li>Thiết lập thành công đường hầm IPsec giữa hai firewall.</li>



<li>Cho phép hai mạng LAN tại hai site truy cập và trao đổi dữ liệu với nhau.</li>



<li>Đảm bảo toàn bộ lưu lượng truyền qua Internet được mã hóa an toàn.</li>



<li>Kiểm tra và xác minh trạng thái hoạt động của VPN Tunnel.</li>



<li>Hiểu rõ cơ chế hoạt động của Phase 1 (IKE SA) và Phase 2 (IPsec SA) trong quá trình thiết lập VPN.</li>
</ul>



<p><strong>Môi trường triển khai:</strong></p>



<ul class="wp-block-list">
<li>02 Sophos Firewall XGS (Virtual Appliance).</li>



<li>Cài đặt trên nền tảng ảo hóa Proxmox VE.</li>



<li>Hai đầu sử dụng IP WAN tĩnh, được cấp từ firewall/router thật để mô phỏng môi trường thực tế.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="903" src="https://vacif.com/wp-content/uploads/2026/03/image-13.png" alt="" class="wp-image-29072" srcset="https://vacif.com/wp-content/uploads/2026/03/image-13.png 975w, https://vacif.com/wp-content/uploads/2026/03/image-13-300x278.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-13-768x711.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Doanh nghiệp có hai site sử dụng hai thiết bị Sophos Firewall XGS kết nối ra Internet qua router Viettel với IP WAN lần lượt là <strong>123.123.123.11 và 123.123.123.15.</strong> Mỗi site có một mạng LAN riêng là <strong>100.100.100.0/24 và 200.200.200.0/24.</strong> Hiện tại hai mạng này không thể truy cập lẫn nhau qua Internet. Yêu cầu đặt ra là cho phép hai mạng LAN giao tiếp an toàn và ổn định. Giải pháp là triển khai VPN Site-to-Site IPsec để mã hóa và kết nối hai hệ thống qua Internet.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-p2o1y"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-p2o1y "><div class="eb-advance-heading-wrapper eb-advance-heading-p2o1y button-1 undefined" data-id="eb-advance-heading-p2o1y"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu </span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chuẩn bị thông tin cấu hình</li>



<li>Tạo các Network Object (Host/Subnet)</li>



<li>Cấu hình IPsec Site-to-Site VPN</li>



<li>Tạo Firewall Rule cho phép lưu lượng LAN <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2194.png" alt="↔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> VPN</li>



<li>Kiểm tra trạng thái hoạt động của VPN</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8kdbt"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8kdbt "><div class="eb-advance-heading-wrapper eb-advance-heading-8kdbt button-1 undefined" data-id="eb-advance-heading-8kdbt"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn chi tiết cấu hình VPN site to site giữa 2 thiết bị Sophos Firewall Firmware V22</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Cấu hình trên Sophos Firewall 1</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-unl1v"><div class="eb-parent-wrapper eb-parent-eb-text-unl1v "><div class="eb-text-wrapper eb-text-unl1v" data-id="eb-text-unl1v"><p class="eb-text"><strong>Bước 1:  </strong>Kiểm tra cấu hình interface, Ở Sophos Firewall 1, Có cổng WAN IP là 123.123.123.11, LAN là 100.100.100.1/24</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="780" src="https://vacif.com/wp-content/uploads/2026/03/image-15.png" alt="" class="wp-image-29074" srcset="https://vacif.com/wp-content/uploads/2026/03/image-15.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-15-300x250.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-15-768x640.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-lmfk5"><div class="eb-parent-wrapper eb-parent-eb-text-lmfk5 "><div class="eb-text-wrapper eb-text-lmfk5" data-id="eb-text-lmfk5"><p class="eb-text"><strong>Bước 2:</strong> Thêm Local và Remote LAN Network</p></div></div></div>



<p>Đến phần <strong>Hosts and services &gt; IP Host &gt; Add </strong>để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="727" src="https://vacif.com/wp-content/uploads/2026/03/image-14.png" alt="" class="wp-image-29073" srcset="https://vacif.com/wp-content/uploads/2026/03/image-14.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-14-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-14-768x597.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="728" src="https://vacif.com/wp-content/uploads/2026/03/image-19.png" alt="" class="wp-image-29079" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-19-768x597.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4keta"><div class="eb-parent-wrapper eb-parent-eb-text-4keta "><div class="eb-text-wrapper eb-text-4keta" data-id="eb-text-4keta"><p class="eb-text"><strong>Bước 3: </strong>Vào mục <strong>Administrator > Device Access > WAN: </strong>tick chọn <strong>IPsec</strong></p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-20.png" alt="" class="wp-image-29078" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-uouu5"><div class="eb-parent-wrapper eb-parent-eb-text-uouu5 "><div class="eb-text-wrapper eb-text-uouu5" data-id="eb-text-uouu5"><p class="eb-text"><strong>Bước 4: </strong>Tạo IPsec Connection</p></div></div></div>



<p>Vào mục <strong>Site to site &gt; IPsec &gt; Add</strong></p>



<ul class="wp-block-list">
<li><strong>IP Version: IPv4 </strong>-&gt; Tunnel sử dụng địa chỉ IPv4 để thiết lập IKE và truyền dữ liệu ESP.</li>



<li><strong>Connection Type: Policy-based</strong> -&gt; Chỉ những subnet khai báo ở Local subnet và Remote subnet mới được phép đi qua tunnel.</li>



<li><strong>Gateway Type: Respond only </strong>-&gt; Firewall này không chủ động kết nối, chỉ phản hồi khi bên kia gọi.</li>



<li><strong>Profile: IKEv2</strong> → Chuẩn VPN mới, ổn định và bảo mật hơn IKEv1.</li>



<li><strong>Authentication: Preshared Key (PSK) </strong>→ Hai firewall dùng chung một mật khẩu bí mật</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-16.png" alt="" class="wp-image-29076" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<ul class="wp-block-list">
<li><strong>Listening interface: 123.123.123.11</strong> -&gt; Đây là IP WAN của firewall này, firewall sẽ chờ kết nối VPN tại IP này.</li>



<li><strong>Gateway address: 123.123.123.15</strong> -&gt; Đây là IP WAN của firewall bên kia, VPN sẽ kết nối đến IP này.</li>



<li><strong>Local Subnet: LOCAL_VLAN_100 </strong>-&gt; Mạng nội bộ phía mình được phép đi qua VPN.</li>



<li><strong>Remote Subnet: VPN_VLAN_200 </strong>-&gt; Mạng nội bộ phía bên kia.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="729" src="https://vacif.com/wp-content/uploads/2026/03/image-18.png" alt="" class="wp-image-29077" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x234.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-18-768x598.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-17.png" alt="" class="wp-image-29075" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-17-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-iljad"><div class="eb-parent-wrapper eb-parent-eb-text-iljad "><div class="eb-text-wrapper eb-text-iljad" data-id="eb-text-iljad"><p class="eb-text"><strong>Bước 5:</strong> Tạo Firewall Rule</p></div></div></div>



<ul class="wp-block-list">
<li><strong>Rule name: VPN_SF_TO_SF1</strong></li>



<li><strong>Action: Accep</strong>t -&gt; Cho phép lưu lượng đi qua</li>



<li><strong>Log firewall traffic: Tick chọn</strong> -&gt; Ghi log để kiểm tra khi cần</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="741" src="https://vacif.com/wp-content/uploads/2026/03/image-21.png" alt="" class="wp-image-29080" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x238.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x608.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<ul class="wp-block-list">
<li><strong>Source zones: LAN, VPN </strong>-&gt; Nghĩa là lưu lượng có thể xuất phát từ mạng nội bộ, hoặc từ phía VPN bên kia</li>



<li><strong>Source networks: LOCAL_VLAN_100, VPN_VLAN_200 </strong>-&gt;chỉ những mạng này mới được phép sử dụng rule</li>



<li><strong>Destination zones: LAN, VPN </strong>-&gt; Cho phép truy cập hai chiều giữa LAN và VPN</li>



<li><strong>Destination networks: LOCAL_VLAN_100, VPN_VLAN_200</strong></li>



<li><strong>Services: Any</strong> -> Cho phép tất cả dịch vụ (ping, RDP, SMB, HTTP&#8230;)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="692" src="https://vacif.com/wp-content/uploads/2026/03/image-31.png" alt="" class="wp-image-29093" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.png 975w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x213.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x545.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-8iylg"><div class="eb-parent-wrapper eb-parent-eb-text-8iylg "><div class="eb-text-wrapper eb-text-8iylg" data-id="eb-text-8iylg"><p class="eb-text"><strong>Bước 6: </strong>Kiểm tra trạng thái VPN</p></div></div></div>



<p>&nbsp;Vào mục <strong>Site to site VPN -&gt; IPsec -&gt; </strong>Tick chọn <strong>Active</strong> và Connection để bật cấu hình.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="736" src="https://vacif.com/wp-content/uploads/2026/03/image-22.png" alt="" class="wp-image-29081" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x236.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x604.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8jx05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8jx05 "><div class="eb-advance-heading-wrapper eb-advance-heading-8jx05 button-1 undefined" data-id="eb-advance-heading-8jx05"><h2 class="eb-ah-title"><span class="first-title">2. Cấu hình trên Sophos Firewall 2</span></h2></div></div></div>



<p>Vào <strong>Hosts and services &gt; IP Host &gt; Add</strong> để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="782" src="https://vacif.com/wp-content/uploads/2026/03/image-24.png" alt="" class="wp-image-29083" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x251.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x642.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="726" src="https://vacif.com/wp-content/uploads/2026/03/image-23.png" alt="" class="wp-image-29082" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x596.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-hch3o"><div class="eb-parent-wrapper eb-parent-eb-text-hch3o "><div class="eb-text-wrapper eb-text-hch3o" data-id="eb-text-hch3o"><p class="eb-text"><strong>Bước 1: </strong>Tạo kết nối IPsec VPN đến Firewall 1</p></div></div></div>



<p>Đến phần <strong>Site-to-Site VPN &gt; IPsec</strong> và chọn <strong>Add</strong>. Tạo kết nối với thông số bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="730" src="https://vacif.com/wp-content/uploads/2026/03/image-25.png" alt="" class="wp-image-29086" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x234.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x599.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="734" src="https://vacif.com/wp-content/uploads/2026/03/image-27.png" alt="" class="wp-image-29084" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x602.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-patfl"><div class="eb-parent-wrapper eb-parent-eb-text-patfl "><div class="eb-text-wrapper eb-text-patfl" data-id="eb-text-patfl"><p class="eb-text"><strong>Bước 2: </strong>Tạo Firewall Rules cho Firewall 2</p></div></div></div>



<p>Đến phần <strong>Rules and Policies -&gt; Firewall rules</strong> chọn <strong>Add</strong> như hình bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="733" src="https://vacif.com/wp-content/uploads/2026/03/image-29.png" alt="" class="wp-image-29088" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-tglf7"><div class="eb-parent-wrapper eb-parent-eb-text-tglf7 "><div class="eb-text-wrapper eb-text-tglf7" data-id="eb-text-tglf7"><p class="eb-text"><strong>Bước 3: </strong>Kiểm tra trạng thái VPN</p></div></div></div>



<ul class="wp-block-list">
<li>Vào mục<strong> Site to site -&gt; IPsec -&gt;</strong> Tick chọn <strong>Active</strong> và <strong>Connection </strong>để bắt đầu kết nối.</li>



<li>Từ máy tính đang ở trong <strong>LAN 100.100.100.0/24 </strong>ping đến máy tính trong<strong> LAN 200.200.200.0/24</strong> <strong>-&gt; ping thành công.</strong></li>



<li>Ngược lại, từ máy tính đang ở trong <strong>LAN 200.200.200.0/24</strong> ping đến máy tính trong <strong>LAN 100.100.100.0/24</strong> &#8211;<strong>&gt; ping thành công.</strong></li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="733" src="https://vacif.com/wp-content/uploads/2026/03/image-28.png" alt="" class="wp-image-29087" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-28-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-28-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="756" src="https://vacif.com/wp-content/uploads/2026/03/image-30.png" alt="" class="wp-image-29089" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x242.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x620.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="537" src="https://vacif.com/wp-content/uploads/2026/03/image-26.png" alt="" class="wp-image-29085" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x172.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x441.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site to Site Giữa Firewall Fortinet và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 04 Mar 2026 05:41:35 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Fortinet Firewall]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29017</guid>

					<description><![CDATA[Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet. Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;text&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;text&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;text&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;text&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;text&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;text&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;text&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;text&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;text&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;text&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;text&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;link&quot;:&quot;eb-table-content-15&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-firewall-fortinet-v\u00e0-sophos-firewall-firmware-v22-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;value&quot;:&quot;1-tr\u00ean-thi\u1ebft-b\u1ecb-fortinet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;value&quot;:&quot;11-t\u1ea1o-vpn-tunnels&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;value&quot;:&quot;12-t\u1ea1o-static-route&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;value&quot;:&quot;13-t\u1ea1o-firewall-policy&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;value&quot;:&quot;2-tr\u00ean-thi\u1ebft-b\u1ecb-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;value&quot;:&quot;21-t\u1ea1o-subnet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;value&quot;:&quot;22-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;value&quot;:&quot;23-t\u1ea1o-ipsec-connection&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;value&quot;:&quot;24-t\u1ea1o-firewall-rule-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;value&quot;:&quot;3-ki\u1ec3m-tra-k\u1ebft-qu\u1ea3&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;value&quot;:&quot;ghi-ch\u00fa-l\u01b0u-\u00fd-tri\u1ec3n-khai&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet.</p>



<p>Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy cập lẫn nhau:</p>



<ul class="wp-block-list">
<li>172.16.16.0/24 – Site A</li>



<li>10.10.10.0/24 – Site B</li>



<li>192.168.20.0/24 – Site B</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="366" src="https://vacif.com/wp-content/uploads/2026/03/image-8.png" alt="" class="wp-image-29019" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x325.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-mm8bi"><div class="eb-parent-wrapper eb-parent-eb-text-mm8bi "><div class="eb-text-wrapper eb-text-mm8bi" data-id="eb-text-mm8bi"><p class="eb-text">Giải thích sơ đồ mạng:</p></div></div></div>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site A – Fortinet Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào cổng WAN của thiết bị Fortinet</li>



<li>IP WAN: 192.168.1.2</li>



<li>Mạng LAN nội bộ: 172.16.16.0/24</li>



<li>LAN được cấu hình trên interface LAN của Fortinet</li>
</ul>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site B – Sophos Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào interface a (WAN) của Sophos Firewall</li>



<li>IP WAN: 192.168.1.3</li>



<li>Mạng LAN nội bộ gồm 2 lớp mạng: 10.10.10.0/24, 192.168.20.0/24</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-w4aye"><div class="eb-parent-wrapper eb-parent-eb-text-w4aye "><div class="eb-text-wrapper eb-text-w4aye" data-id="eb-text-w4aye"><p class="eb-text">Lưu ý sơ đồ:</p></div></div></div>



<ul class="wp-block-list">
<li>Kết nối VPN sử dụng IPSec Site-to-Site</li>



<li>Xác thực bằng Pre-shared Key</li>



<li>Sử dụng IKEv2</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-jmoxo"><div class="eb-parent-wrapper eb-parent-eb-text-jmoxo "><div class="eb-text-wrapper eb-text-jmoxo" data-id="eb-text-jmoxo"><p class="eb-text">Chúng ta sẽ thực hiện cấu hình IPSec VPN Site-to-Site giữa:</p></div></div></div>



<ul class="wp-block-list">
<li>Fortinet (192.168.1.2)</li>



<li>Sophos (192.168.1.3)</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-oylnm"><div class="eb-parent-wrapper eb-parent-eb-text-oylnm "><div class="eb-text-wrapper eb-text-oylnm" data-id="eb-text-oylnm"><p class="eb-text">Mục tiêu:</p></div></div></div>



<p>Mạng LAN 172.16.16.0/24 (Fortinet) ⬄ Mạng LAN 10.10.10.0/24 và 192.168.20.0/24 (Sophos) có thể kết nối qua lại trực tiếp.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yq4nn"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yq4nn "><div class="eb-advance-heading-wrapper eb-advance-heading-yq4nn button-1 undefined" data-id="eb-advance-heading-yq4nn"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-queb7"><div class="eb-parent-wrapper eb-parent-eb-text-queb7 "><div class="eb-text-wrapper eb-text-queb7" data-id="eb-text-queb7"><p class="eb-text">Trên thiết bị Fortinet:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo VPN Tunnels</li>



<li>Tạo Static Route</li>



<li>Tạo Firewall Policy</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-vlwq4"><div class="eb-parent-wrapper eb-parent-eb-text-vlwq4 "><div class="eb-text-wrapper eb-text-vlwq4" data-id="eb-text-vlwq4"><p class="eb-text">Trên thiết bị Sophos:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo subnet</li>



<li>Tạo IPSec Profile</li>



<li>Tạo IPSec Connection</li>



<li>Tạo Firewall Rule</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-76g77"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-76g77 "><div class="eb-advance-heading-wrapper eb-advance-heading-76g77 button-1 undefined" data-id="eb-advance-heading-76g77"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Trên thiết bị Fortinet:</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wc297"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wc297 "><div class="eb-advance-heading-wrapper eb-advance-heading-wc297 button-1 undefined" data-id="eb-advance-heading-wc297"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Tạo VPN Tunnels</span></h2></div></div></div>



<p>Vào VPN → IPsec Tunnels → Create New → Custom</p>



<div class="wp-block-essential-blocks-text  root-eb-text-i1ir1"><div class="eb-parent-wrapper eb-parent-eb-text-i1ir1 "><div class="eb-text-wrapper eb-text-i1ir1" data-id="eb-text-i1ir1"><p class="eb-text">Bảng VPN Create Wizard</p></div></div></div>



<p>Name: S2S-LAB</p>



<p>Template Type: Custom</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg" alt="" class="wp-image-29020" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>Dùng Custom để chủ động cấu hình Phase 1 / Phase 2</p>



<div class="wp-block-essential-blocks-text  root-eb-text-xvm9r"><div class="eb-parent-wrapper eb-parent-eb-text-xvm9r "><div class="eb-text-wrapper eb-text-xvm9r" data-id="eb-text-xvm9r"><p class="eb-text">Bảng Network</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="746" height="709" src="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg" alt="" class="wp-image-29021" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg 746w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x285.jpg 300w" sizes="auto, (max-width: 746px) 100vw, 746px" /></figure>



<figure class="wp-block-table is-style-regular"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>IP Version</td><td>IPv4</td></tr><tr><td>Remote Gateway</td><td>Static IP Address</td></tr><tr><td>IP Address</td><td>192.168.1.3 (WAN Sophos)</td></tr><tr><td>Interface</td><td>WAN</td></tr><tr><td>Local Gateway</td><td>Không bật</td></tr><tr><td>Mode Config</td><td>Bỏ chọn</td></tr><tr><td>NAT Traversal</td><td>Disable</td></tr><tr><td>Dead Peer Detection</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-h7m6p"><div class="eb-parent-wrapper eb-parent-eb-text-h7m6p "><div class="eb-text-wrapper eb-text-h7m6p" data-id="eb-text-h7m6p"><p class="eb-text">&#8211; Disable NAT-T vì không NAT giữa 2 WAN<br>&#8211; Disable DPD để tránh reset tunnel trong lab</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-8oxg9"><div class="eb-parent-wrapper eb-parent-eb-text-8oxg9 "><div class="eb-text-wrapper eb-text-8oxg9" data-id="eb-text-8oxg9"><p class="eb-text">Bảng Authentication</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="735" height="331" src="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg" alt="" class="wp-image-29022" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg 735w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x135.jpg 300w" sizes="auto, (max-width: 735px) 100vw, 735px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Method</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>(ví dụ) FortiSophos@123</td></tr><tr><td>IKE Version</td><td>2</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-2qql7"><div class="eb-parent-wrapper eb-parent-eb-text-2qql7 "><div class="eb-text-wrapper eb-text-2qql7" data-id="eb-text-2qql7"><p class="eb-text">&#8211; PSK phải giống 100% bên Sophos</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-11jdu"><div class="eb-parent-wrapper eb-parent-eb-text-11jdu "><div class="eb-text-wrapper eb-text-11jdu" data-id="eb-text-11jdu"><p class="eb-text">Phase 1 Proposal</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="757" height="376" src="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg" alt="" class="wp-image-29023" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg 757w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x149.jpg 300w" sizes="auto, (max-width: 757px) 100vw, 757px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>28800</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6r9aw"><div class="eb-parent-wrapper eb-parent-eb-text-6r9aw "><div class="eb-text-wrapper eb-text-6r9aw" data-id="eb-text-6r9aw"><p class="eb-text">Phase 2 Selectors</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="578" height="714" src="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg" alt="" class="wp-image-29032" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg 578w, https://vacif.com/wp-content/uploads/2026/03/image-28-243x300.jpg 243w" sizes="auto, (max-width: 578px) 100vw, 578px" /></figure>



<p><strong>Selector 1</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 10.10.10.0/24</li>
</ul>



<p><strong>Selector 2</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 192.168.20.0/24</li>
</ul>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>43200</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4mf91"><div class="eb-parent-wrapper eb-parent-eb-text-4mf91 "><div class="eb-text-wrapper eb-text-4mf91" data-id="eb-text-4mf91"><p class="eb-text">&#8211; Mỗi subnet Sophos cần 1 Phase 2<br>&#8211; Nếu gộp → tunnel UP nhưng không có traffic</p></div></div></div>



<p>Nhấn OK để tạo VPN Tunnel.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ljz9a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ljz9a "><div class="eb-advance-heading-wrapper eb-advance-heading-ljz9a button-1 undefined" data-id="eb-advance-heading-ljz9a"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Tạo Static Route</span></h2></div></div></div>



<p>Vào Network → Static Routes → Create New</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg" alt="" class="wp-image-29027" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-i0llt"><div class="eb-parent-wrapper eb-parent-eb-text-i0llt "><div class="eb-text-wrapper eb-text-i0llt" data-id="eb-text-i0llt"><p class="eb-text">Route 1</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>10.10.10.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-t16sq"><div class="eb-parent-wrapper eb-parent-eb-text-t16sq "><div class="eb-text-wrapper eb-text-t16sq" data-id="eb-text-t16sq"><p class="eb-text">Route 2</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg" alt="" class="wp-image-29026" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>192.168.20.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-175x1"><div class="eb-parent-wrapper eb-parent-eb-text-175x1 "><div class="eb-text-wrapper eb-text-175x1" data-id="eb-text-175x1"><p class="eb-text">&#8211; Nếu thiếu static route → ping không bao giờ đi vào VPN</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-siaef"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-siaef "><div class="eb-advance-heading-wrapper eb-advance-heading-siaef button-1 undefined" data-id="eb-advance-heading-siaef"><h2 class="eb-ah-title"><span class="first-title"><a>1.3</a> &#8211; Tạo Firewall Policy</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-k0mcg"><div class="eb-parent-wrapper eb-parent-eb-text-k0mcg "><div class="eb-text-wrapper eb-text-k0mcg" data-id="eb-text-k0mcg"><p class="eb-text">Policy 1 – LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg" alt="" class="wp-image-29030" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>LAN</td></tr><tr><td>Outgoing Interface</td><td>S2S-LAB</td></tr><tr><td>Source</td><td>172.16.16.0/24</td></tr><tr><td>Destination</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr><tr><td>NAT</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-04oaf"><div class="eb-parent-wrapper eb-parent-eb-text-04oaf "><div class="eb-text-wrapper eb-text-04oaf" data-id="eb-text-04oaf"><p class="eb-text">Policy 2 – VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg" alt="" class="wp-image-29031" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>S2S-LAB</td></tr><tr><td>Outgoing Interface</td><td>LAN</td></tr><tr><td>Source</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination</td><td>172.16.16.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-i77g3"><div class="eb-parent-wrapper eb-parent-eb-text-i77g3 "><div class="eb-text-wrapper eb-text-i77g3" data-id="eb-text-i77g3"><p class="eb-text">&#8211; Policy VPN phải nằm trên policy Internet</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qh3q2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qh3q2 "><div class="eb-advance-heading-wrapper eb-advance-heading-qh3q2 button-1 undefined" data-id="eb-advance-heading-qh3q2"><h2 class="eb-ah-title"><span class="first-title"><a>2. </a>Trên thiết bị Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a7f6u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a7f6u "><div class="eb-advance-heading-wrapper eb-advance-heading-a7f6u button-1 undefined" data-id="eb-advance-heading-a7f6u"><h2 class="eb-ah-title"><span class="first-title">2.1 &#8211; Tạo subnet</span></h2></div></div></div>



<p>Vào Hosts and Services → Add</p>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tên</strong></th><th><strong>Loại</strong></th><th><strong>Thông số</strong></th></tr></thead><tbody><tr><td>LAN_SOPHOS_10</td><td>Network</td><td>IP: 10.10.10.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_SOPHOS_20</td><td>Network</td><td>IP: 192.168.20.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_FORTI</td><td>Network</td><td>IP: 172.16.16.0 / Subnet: 255.255.255.0</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bkx0m"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bkx0m "><div class="eb-advance-heading-wrapper eb-advance-heading-bkx0m button-1 undefined" data-id="eb-advance-heading-bkx0m"><h2 class="eb-ah-title"><span class="first-title">2.2 &#8211; Tạo IPSec Profile</span></h2></div></div></div>



<p>Vào SYSTEM &gt; Profiles → IPsec Profiles → Add</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg" alt="" class="wp-image-29024" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>Fortinet-Vacif</td></tr><tr><td>IKE Version</td><td>IKEv2</td></tr><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>DH Group</td><td>14</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x0jn2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x0jn2 "><div class="eb-advance-heading-wrapper eb-advance-heading-x0jn2 button-1 undefined" data-id="eb-advance-heading-x0jn2"><h2 class="eb-ah-title"><span class="first-title">2.3 &#8211; Tạo IPSec Connection</span></h2></div></div></div>



<p>Vào CONFIGURE → Site-to-site VPN → &nbsp;IPsec → Add</p>



<div class="wp-block-essential-blocks-text  root-eb-text-b8zwg"><div class="eb-parent-wrapper eb-parent-eb-text-b8zwg "><div class="eb-text-wrapper eb-text-b8zwg" data-id="eb-text-b8zwg"><p class="eb-text">General Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg" alt="" class="wp-image-29025" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>VPN_SOPHOS_VACIF</td></tr><tr><td>Connection Type</td><td>Policy-based</td></tr><tr><td>Gateway Type</td><td>Initiate the connection</td></tr><tr><td>Create firewall rule</td><td>Không chọn (tạo thủ công)</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-86g8b"><div class="eb-parent-wrapper eb-parent-eb-text-86g8b "><div class="eb-text-wrapper eb-text-86g8b" data-id="eb-text-86g8b"><p class="eb-text">Authentication</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Profile</td><td>Fortinet Vacif ( tạo ở bước trên )</td></tr><tr><td>Authentication Type&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>FortiSophos@123</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6opfg"><div class="eb-parent-wrapper eb-parent-eb-text-6opfg "><div class="eb-text-wrapper eb-text-6opfg" data-id="eb-text-6opfg"><p class="eb-text">Gateway Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg" alt="" class="wp-image-29033" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<ul class="wp-block-list">
<li>Listening interface: Port 2 – 192.168.1.3</li>



<li>Gateway address: 192.168.1.2 (WAN Fortinet)</li>



<li>Local Subnet: 10.10.10.0/24 , 192.168.20.0/24</li>



<li>Remote Subnet: 172.16.16.0/24</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2dz5o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2dz5o "><div class="eb-advance-heading-wrapper eb-advance-heading-2dz5o button-1 undefined" data-id="eb-advance-heading-2dz5o"><h2 class="eb-ah-title"><span class="first-title"><a>2.4</a> &#8211; Tạo Firewall Rule Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-069m1"><div class="eb-parent-wrapper eb-parent-eb-text-069m1 "><div class="eb-text-wrapper eb-text-069m1" data-id="eb-text-069m1"><p class="eb-text">LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg" alt="" class="wp-image-29028" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>LAN</td></tr><tr><td>Destination Zone</td><td>VPN</td></tr><tr><td>Source Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination Network</td><td>172.16.16.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-0pm0n"><div class="eb-parent-wrapper eb-parent-eb-text-0pm0n "><div class="eb-text-wrapper eb-text-0pm0n" data-id="eb-text-0pm0n"><p class="eb-text">VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg" alt="" class="wp-image-29029" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>VPN</td></tr><tr><td>Destination Zone</td><td>LAN</td></tr><tr><td>Source Network</td><td>172.16.16.0/24</td></tr><tr><td>Destination Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeg05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeg05 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeg05 button-1 undefined" data-id="eb-advance-heading-qeg05"><h2 class="eb-ah-title"><span class="first-title"><a>3</a>. Kiểm tra kết quả</span></h2></div></div></div>



<p><strong>Sophos:</strong> VPN → IPsec Connections → Status: <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f7e2.png" alt="🟢" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Connected</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg" alt="" class="wp-image-29034" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Fortinet:</strong> Monitor → IPsec Monitor → Tunnel: UP (Có Incoming / Outgoing Data)</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg" alt="" class="wp-image-29035" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Test:</strong></p>



<ul class="wp-block-list">
<li>172.16.16.x → 10.10.10.x</li>



<li>172.16.16.x → 192.168.20.x</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg" alt="" class="wp-image-29036" srcset="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-32-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-32-768x404.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iq8fr"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iq8fr "><div class="eb-advance-heading-wrapper eb-advance-heading-iq8fr button-1 undefined" data-id="eb-advance-heading-iq8fr"><h2 class="eb-ah-title"><span class="first-title">* Ghi chú &amp; Lưu ý triển khai</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đảm bảo thời gian hệ thống đồng bộ (NTP) để tránh lỗi IKEv2 do lệch thời gian.</li>



<li>PSK, thuật toán mã hóa và nhóm DH phải trùng khớp 2 đầu – sai khác sẽ khiến Phase 1/2 thất bại.</li>



<li>Tắt NAT trên policy đi vào VPN; bật NAT sẽ làm sai nguồn và gói tin không match selector.</li>



<li>Mỗi cặp Local/Remote subnet cần 1 selector (Phase 2). Không gộp nhiều subnet nếu thiết bị không hỗ trợ.</li>



<li>Nếu tunnel UP nhưng không ping được, kiểm tra: Static Route, Policy thứ tự, và bảng ARP/Route trên hai đầu.</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
