<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sophos Firewall Firmware V22 &#8211; VACIF</title>
	<atom:link href="https://vacif.com/tag/sophos-firewall-firmware-v22/feed/" rel="self" type="application/rss+xml" />
	<link>https://vacif.com</link>
	<description>Đầu tư cho giá trị</description>
	<lastBuildDate>Fri, 06 Mar 2026 09:25:49 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://vacif.com/wp-content/uploads/2024/06/cropped-icon-32x32.png</url>
	<title>Sophos Firewall Firmware V22 &#8211; VACIF</title>
	<link>https://vacif.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site To Site Giữa 2 Thiết Bị Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 08:07:55 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Cấu Hình VPN Site To Site]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29071</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình IPsec Site-to-Site VPN giữa hai thiết bị Sophos Firewall XGS sử dụng firmware v22, nhằm xây dựng kết nối bảo mật giữa hai hệ thống mạng đặt tại hai địa điểm khác nhau. Mục tiêu của bài lab: Môi trường triển khai: Doanh nghiệp có hai site sử [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;text&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;text&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-chi-ti\u1ebft-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-2-thi\u1ebft-b\u1ecb-sophos-firewall-firmware-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;value&quot;:&quot;1-c\u1ea5u-h\u00ecnh-tr\u00ean-sophos-firewall-1&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;value&quot;:&quot;2-c\u1ea5u-h\u00ecnh-tr\u00ean-sophos-firewall-2&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu </a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn chi tiết cấu hình VPN site to site giữa 2 thiết bị Sophos Firewall Firmware V22</a><li><a href="#eb-table-content-5">1. Cấu hình trên Sophos Firewall 1</a><li><a href="#eb-table-content-6">2. Cấu hình trên Sophos Firewall 2</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình IPsec Site-to-Site VPN giữa hai thiết bị Sophos Firewall XGS sử dụng firmware v22, nhằm xây dựng kết nối bảo mật giữa hai hệ thống mạng đặt tại hai địa điểm khác nhau.</p>



<p><strong>Mục tiêu của bài lab:</strong></p>



<ul class="wp-block-list">
<li>Thiết lập thành công đường hầm IPsec giữa hai firewall.</li>



<li>Cho phép hai mạng LAN tại hai site truy cập và trao đổi dữ liệu với nhau.</li>



<li>Đảm bảo toàn bộ lưu lượng truyền qua Internet được mã hóa an toàn.</li>



<li>Kiểm tra và xác minh trạng thái hoạt động của VPN Tunnel.</li>



<li>Hiểu rõ cơ chế hoạt động của Phase 1 (IKE SA) và Phase 2 (IPsec SA) trong quá trình thiết lập VPN.</li>
</ul>



<p><strong>Môi trường triển khai:</strong></p>



<ul class="wp-block-list">
<li>02 Sophos Firewall XGS (Virtual Appliance).</li>



<li>Cài đặt trên nền tảng ảo hóa Proxmox VE.</li>



<li>Hai đầu sử dụng IP WAN tĩnh, được cấp từ firewall/router thật để mô phỏng môi trường thực tế.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="975" height="903" src="https://vacif.com/wp-content/uploads/2026/03/image-13.png" alt="" class="wp-image-29072" srcset="https://vacif.com/wp-content/uploads/2026/03/image-13.png 975w, https://vacif.com/wp-content/uploads/2026/03/image-13-300x278.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-13-768x711.png 768w" sizes="(max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Doanh nghiệp có hai site sử dụng hai thiết bị Sophos Firewall XGS kết nối ra Internet qua router Viettel với IP WAN lần lượt là <strong>123.123.123.11 và 123.123.123.15.</strong> Mỗi site có một mạng LAN riêng là <strong>100.100.100.0/24 và 200.200.200.0/24.</strong> Hiện tại hai mạng này không thể truy cập lẫn nhau qua Internet. Yêu cầu đặt ra là cho phép hai mạng LAN giao tiếp an toàn và ổn định. Giải pháp là triển khai VPN Site-to-Site IPsec để mã hóa và kết nối hai hệ thống qua Internet.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-p2o1y"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-p2o1y "><div class="eb-advance-heading-wrapper eb-advance-heading-p2o1y button-1 undefined" data-id="eb-advance-heading-p2o1y"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu </span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chuẩn bị thông tin cấu hình</li>



<li>Tạo các Network Object (Host/Subnet)</li>



<li>Cấu hình IPsec Site-to-Site VPN</li>



<li>Tạo Firewall Rule cho phép lưu lượng LAN <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2194.png" alt="↔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> VPN</li>



<li>Kiểm tra trạng thái hoạt động của VPN</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8kdbt"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8kdbt "><div class="eb-advance-heading-wrapper eb-advance-heading-8kdbt button-1 undefined" data-id="eb-advance-heading-8kdbt"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn chi tiết cấu hình VPN site to site giữa 2 thiết bị Sophos Firewall Firmware V22</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Cấu hình trên Sophos Firewall 1</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-unl1v"><div class="eb-parent-wrapper eb-parent-eb-text-unl1v "><div class="eb-text-wrapper eb-text-unl1v" data-id="eb-text-unl1v"><p class="eb-text"><strong>Bước 1:  </strong>Kiểm tra cấu hình interface, Ở Sophos Firewall 1, Có cổng WAN IP là 123.123.123.11, LAN là 100.100.100.1/24</p></div></div></div>



<figure class="wp-block-image size-full"><img decoding="async" width="936" height="780" src="https://vacif.com/wp-content/uploads/2026/03/image-15.png" alt="" class="wp-image-29074" srcset="https://vacif.com/wp-content/uploads/2026/03/image-15.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-15-300x250.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-15-768x640.png 768w" sizes="(max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-lmfk5"><div class="eb-parent-wrapper eb-parent-eb-text-lmfk5 "><div class="eb-text-wrapper eb-text-lmfk5" data-id="eb-text-lmfk5"><p class="eb-text"><strong>Bước 2:</strong> Thêm Local và Remote LAN Network</p></div></div></div>



<p>Đến phần <strong>Hosts and services &gt; IP Host &gt; Add </strong>để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="936" height="727" src="https://vacif.com/wp-content/uploads/2026/03/image-14.png" alt="" class="wp-image-29073" srcset="https://vacif.com/wp-content/uploads/2026/03/image-14.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-14-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-14-768x597.png 768w" sizes="(max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="728" src="https://vacif.com/wp-content/uploads/2026/03/image-19.png" alt="" class="wp-image-29079" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-19-768x597.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4keta"><div class="eb-parent-wrapper eb-parent-eb-text-4keta "><div class="eb-text-wrapper eb-text-4keta" data-id="eb-text-4keta"><p class="eb-text"><strong>Bước 3: </strong>Vào mục <strong>Administrator > Device Access > WAN: </strong>tick chọn <strong>IPsec</strong></p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-20.png" alt="" class="wp-image-29078" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-uouu5"><div class="eb-parent-wrapper eb-parent-eb-text-uouu5 "><div class="eb-text-wrapper eb-text-uouu5" data-id="eb-text-uouu5"><p class="eb-text"><strong>Bước 4: </strong>Tạo IPsec Connection</p></div></div></div>



<p>Vào mục <strong>Site to site &gt; IPsec &gt; Add</strong></p>



<ul class="wp-block-list">
<li><strong>IP Version: IPv4 </strong>-&gt; Tunnel sử dụng địa chỉ IPv4 để thiết lập IKE và truyền dữ liệu ESP.</li>



<li><strong>Connection Type: Policy-based</strong> -&gt; Chỉ những subnet khai báo ở Local subnet và Remote subnet mới được phép đi qua tunnel.</li>



<li><strong>Gateway Type: Respond only </strong>-&gt; Firewall này không chủ động kết nối, chỉ phản hồi khi bên kia gọi.</li>



<li><strong>Profile: IKEv2</strong> → Chuẩn VPN mới, ổn định và bảo mật hơn IKEv1.</li>



<li><strong>Authentication: Preshared Key (PSK) </strong>→ Hai firewall dùng chung một mật khẩu bí mật</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-16.png" alt="" class="wp-image-29076" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<ul class="wp-block-list">
<li><strong>Listening interface: 123.123.123.11</strong> -&gt; Đây là IP WAN của firewall này, firewall sẽ chờ kết nối VPN tại IP này.</li>



<li><strong>Gateway address: 123.123.123.15</strong> -&gt; Đây là IP WAN của firewall bên kia, VPN sẽ kết nối đến IP này.</li>



<li><strong>Local Subnet: LOCAL_VLAN_100 </strong>-&gt; Mạng nội bộ phía mình được phép đi qua VPN.</li>



<li><strong>Remote Subnet: VPN_VLAN_200 </strong>-&gt; Mạng nội bộ phía bên kia.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="729" src="https://vacif.com/wp-content/uploads/2026/03/image-18.png" alt="" class="wp-image-29077" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x234.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-18-768x598.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-17.png" alt="" class="wp-image-29075" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-17-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-iljad"><div class="eb-parent-wrapper eb-parent-eb-text-iljad "><div class="eb-text-wrapper eb-text-iljad" data-id="eb-text-iljad"><p class="eb-text"><strong>Bước 5:</strong> Tạo Firewall Rule</p></div></div></div>



<ul class="wp-block-list">
<li><strong>Rule name: VPN_SF_TO_SF1</strong></li>



<li><strong>Action: Accep</strong>t -&gt; Cho phép lưu lượng đi qua</li>



<li><strong>Log firewall traffic: Tick chọn</strong> -&gt; Ghi log để kiểm tra khi cần</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="741" src="https://vacif.com/wp-content/uploads/2026/03/image-21.png" alt="" class="wp-image-29080" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x238.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x608.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<ul class="wp-block-list">
<li><strong>Source zones: LAN, VPN </strong>-&gt; Nghĩa là lưu lượng có thể xuất phát từ mạng nội bộ, hoặc từ phía VPN bên kia</li>



<li><strong>Source networks: LOCAL_VLAN_100, VPN_VLAN_200 </strong>-&gt;chỉ những mạng này mới được phép sử dụng rule</li>



<li><strong>Destination zones: LAN, VPN </strong>-&gt; Cho phép truy cập hai chiều giữa LAN và VPN</li>



<li><strong>Destination networks: LOCAL_VLAN_100, VPN_VLAN_200</strong></li>



<li><strong>Services: Any</strong> -> Cho phép tất cả dịch vụ (ping, RDP, SMB, HTTP&#8230;)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="692" src="https://vacif.com/wp-content/uploads/2026/03/image-31.png" alt="" class="wp-image-29093" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.png 975w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x213.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x545.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-8iylg"><div class="eb-parent-wrapper eb-parent-eb-text-8iylg "><div class="eb-text-wrapper eb-text-8iylg" data-id="eb-text-8iylg"><p class="eb-text"><strong>Bước 6: </strong>Kiểm tra trạng thái VPN</p></div></div></div>



<p>&nbsp;Vào mục <strong>Site to site VPN -&gt; IPsec -&gt; </strong>Tick chọn <strong>Active</strong> và Connection để bật cấu hình.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="736" src="https://vacif.com/wp-content/uploads/2026/03/image-22.png" alt="" class="wp-image-29081" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x236.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x604.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8jx05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8jx05 "><div class="eb-advance-heading-wrapper eb-advance-heading-8jx05 button-1 undefined" data-id="eb-advance-heading-8jx05"><h2 class="eb-ah-title"><span class="first-title">2. Cấu hình trên Sophos Firewall 2</span></h2></div></div></div>



<p>Vào <strong>Hosts and services &gt; IP Host &gt; Add</strong> để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="782" src="https://vacif.com/wp-content/uploads/2026/03/image-24.png" alt="" class="wp-image-29083" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x251.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x642.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="726" src="https://vacif.com/wp-content/uploads/2026/03/image-23.png" alt="" class="wp-image-29082" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x596.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-hch3o"><div class="eb-parent-wrapper eb-parent-eb-text-hch3o "><div class="eb-text-wrapper eb-text-hch3o" data-id="eb-text-hch3o"><p class="eb-text"><strong>Bước 1: </strong>Tạo kết nối IPsec VPN đến Firewall 1</p></div></div></div>



<p>Đến phần <strong>Site-to-Site VPN &gt; IPsec</strong> và chọn <strong>Add</strong>. Tạo kết nối với thông số bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="730" src="https://vacif.com/wp-content/uploads/2026/03/image-25.png" alt="" class="wp-image-29086" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x234.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x599.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="734" src="https://vacif.com/wp-content/uploads/2026/03/image-27.png" alt="" class="wp-image-29084" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x602.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-patfl"><div class="eb-parent-wrapper eb-parent-eb-text-patfl "><div class="eb-text-wrapper eb-text-patfl" data-id="eb-text-patfl"><p class="eb-text"><strong>Bước 2: </strong>Tạo Firewall Rules cho Firewall 2</p></div></div></div>



<p>Đến phần <strong>Rules and Policies -&gt; Firewall rules</strong> chọn <strong>Add</strong> như hình bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="733" src="https://vacif.com/wp-content/uploads/2026/03/image-29.png" alt="" class="wp-image-29088" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-tglf7"><div class="eb-parent-wrapper eb-parent-eb-text-tglf7 "><div class="eb-text-wrapper eb-text-tglf7" data-id="eb-text-tglf7"><p class="eb-text"><strong>Bước 3: </strong>Kiểm tra trạng thái VPN</p></div></div></div>



<ul class="wp-block-list">
<li>Vào mục<strong> Site to site -&gt; IPsec -&gt;</strong> Tick chọn <strong>Active</strong> và <strong>Connection </strong>để bắt đầu kết nối.</li>



<li>Từ máy tính đang ở trong <strong>LAN 100.100.100.0/24 </strong>ping đến máy tính trong<strong> LAN 200.200.200.0/24</strong> <strong>-&gt; ping thành công.</strong></li>



<li>Ngược lại, từ máy tính đang ở trong <strong>LAN 200.200.200.0/24</strong> ping đến máy tính trong <strong>LAN 100.100.100.0/24</strong> &#8211;<strong>&gt; ping thành công.</strong></li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="733" src="https://vacif.com/wp-content/uploads/2026/03/image-28.png" alt="" class="wp-image-29087" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-28-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-28-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="756" src="https://vacif.com/wp-content/uploads/2026/03/image-30.png" alt="" class="wp-image-29089" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x242.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x620.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="537" src="https://vacif.com/wp-content/uploads/2026/03/image-26.png" alt="" class="wp-image-29085" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x172.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x441.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site to Site Giữa Firewall Fortinet và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 04 Mar 2026 05:41:35 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Fortinet Firewall]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29017</guid>

					<description><![CDATA[Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet. Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;text&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;text&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;text&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;text&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;text&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;text&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;text&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;text&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;text&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;text&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;text&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;link&quot;:&quot;eb-table-content-15&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-firewall-fortinet-v\u00e0-sophos-firewall-firmware-v22-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;value&quot;:&quot;1-tr\u00ean-thi\u1ebft-b\u1ecb-fortinet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;value&quot;:&quot;11-t\u1ea1o-vpn-tunnels&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;value&quot;:&quot;12-t\u1ea1o-static-route&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;value&quot;:&quot;13-t\u1ea1o-firewall-policy&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;value&quot;:&quot;2-tr\u00ean-thi\u1ebft-b\u1ecb-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;value&quot;:&quot;21-t\u1ea1o-subnet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;value&quot;:&quot;22-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;value&quot;:&quot;23-t\u1ea1o-ipsec-connection&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;value&quot;:&quot;24-t\u1ea1o-firewall-rule-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;value&quot;:&quot;3-ki\u1ec3m-tra-k\u1ebft-qu\u1ea3&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;value&quot;:&quot;ghi-ch\u00fa-l\u01b0u-\u00fd-tri\u1ec3n-khai&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet.</p>



<p>Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy cập lẫn nhau:</p>



<ul class="wp-block-list">
<li>172.16.16.0/24 – Site A</li>



<li>10.10.10.0/24 – Site B</li>



<li>192.168.20.0/24 – Site B</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="366" src="https://vacif.com/wp-content/uploads/2026/03/image-8.png" alt="" class="wp-image-29019" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x325.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-mm8bi"><div class="eb-parent-wrapper eb-parent-eb-text-mm8bi "><div class="eb-text-wrapper eb-text-mm8bi" data-id="eb-text-mm8bi"><p class="eb-text">Giải thích sơ đồ mạng:</p></div></div></div>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site A – Fortinet Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào cổng WAN của thiết bị Fortinet</li>



<li>IP WAN: 192.168.1.2</li>



<li>Mạng LAN nội bộ: 172.16.16.0/24</li>



<li>LAN được cấu hình trên interface LAN của Fortinet</li>
</ul>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site B – Sophos Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào interface a (WAN) của Sophos Firewall</li>



<li>IP WAN: 192.168.1.3</li>



<li>Mạng LAN nội bộ gồm 2 lớp mạng: 10.10.10.0/24, 192.168.20.0/24</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-w4aye"><div class="eb-parent-wrapper eb-parent-eb-text-w4aye "><div class="eb-text-wrapper eb-text-w4aye" data-id="eb-text-w4aye"><p class="eb-text">Lưu ý sơ đồ:</p></div></div></div>



<ul class="wp-block-list">
<li>Kết nối VPN sử dụng IPSec Site-to-Site</li>



<li>Xác thực bằng Pre-shared Key</li>



<li>Sử dụng IKEv2</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-jmoxo"><div class="eb-parent-wrapper eb-parent-eb-text-jmoxo "><div class="eb-text-wrapper eb-text-jmoxo" data-id="eb-text-jmoxo"><p class="eb-text">Chúng ta sẽ thực hiện cấu hình IPSec VPN Site-to-Site giữa:</p></div></div></div>



<ul class="wp-block-list">
<li>Fortinet (192.168.1.2)</li>



<li>Sophos (192.168.1.3)</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-oylnm"><div class="eb-parent-wrapper eb-parent-eb-text-oylnm "><div class="eb-text-wrapper eb-text-oylnm" data-id="eb-text-oylnm"><p class="eb-text">Mục tiêu:</p></div></div></div>



<p>Mạng LAN 172.16.16.0/24 (Fortinet) ⬄ Mạng LAN 10.10.10.0/24 và 192.168.20.0/24 (Sophos) có thể kết nối qua lại trực tiếp.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yq4nn"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yq4nn "><div class="eb-advance-heading-wrapper eb-advance-heading-yq4nn button-1 undefined" data-id="eb-advance-heading-yq4nn"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-queb7"><div class="eb-parent-wrapper eb-parent-eb-text-queb7 "><div class="eb-text-wrapper eb-text-queb7" data-id="eb-text-queb7"><p class="eb-text">Trên thiết bị Fortinet:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo VPN Tunnels</li>



<li>Tạo Static Route</li>



<li>Tạo Firewall Policy</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-vlwq4"><div class="eb-parent-wrapper eb-parent-eb-text-vlwq4 "><div class="eb-text-wrapper eb-text-vlwq4" data-id="eb-text-vlwq4"><p class="eb-text">Trên thiết bị Sophos:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo subnet</li>



<li>Tạo IPSec Profile</li>



<li>Tạo IPSec Connection</li>



<li>Tạo Firewall Rule</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-76g77"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-76g77 "><div class="eb-advance-heading-wrapper eb-advance-heading-76g77 button-1 undefined" data-id="eb-advance-heading-76g77"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Trên thiết bị Fortinet:</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wc297"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wc297 "><div class="eb-advance-heading-wrapper eb-advance-heading-wc297 button-1 undefined" data-id="eb-advance-heading-wc297"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Tạo VPN Tunnels</span></h2></div></div></div>



<p>Vào VPN → IPsec Tunnels → Create New → Custom</p>



<div class="wp-block-essential-blocks-text  root-eb-text-i1ir1"><div class="eb-parent-wrapper eb-parent-eb-text-i1ir1 "><div class="eb-text-wrapper eb-text-i1ir1" data-id="eb-text-i1ir1"><p class="eb-text">Bảng VPN Create Wizard</p></div></div></div>



<p>Name: S2S-LAB</p>



<p>Template Type: Custom</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg" alt="" class="wp-image-29020" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>Dùng Custom để chủ động cấu hình Phase 1 / Phase 2</p>



<div class="wp-block-essential-blocks-text  root-eb-text-xvm9r"><div class="eb-parent-wrapper eb-parent-eb-text-xvm9r "><div class="eb-text-wrapper eb-text-xvm9r" data-id="eb-text-xvm9r"><p class="eb-text">Bảng Network</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="746" height="709" src="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg" alt="" class="wp-image-29021" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg 746w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x285.jpg 300w" sizes="auto, (max-width: 746px) 100vw, 746px" /></figure>



<figure class="wp-block-table is-style-regular"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>IP Version</td><td>IPv4</td></tr><tr><td>Remote Gateway</td><td>Static IP Address</td></tr><tr><td>IP Address</td><td>192.168.1.3 (WAN Sophos)</td></tr><tr><td>Interface</td><td>WAN</td></tr><tr><td>Local Gateway</td><td>Không bật</td></tr><tr><td>Mode Config</td><td>Bỏ chọn</td></tr><tr><td>NAT Traversal</td><td>Disable</td></tr><tr><td>Dead Peer Detection</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-h7m6p"><div class="eb-parent-wrapper eb-parent-eb-text-h7m6p "><div class="eb-text-wrapper eb-text-h7m6p" data-id="eb-text-h7m6p"><p class="eb-text">&#8211; Disable NAT-T vì không NAT giữa 2 WAN<br>&#8211; Disable DPD để tránh reset tunnel trong lab</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-8oxg9"><div class="eb-parent-wrapper eb-parent-eb-text-8oxg9 "><div class="eb-text-wrapper eb-text-8oxg9" data-id="eb-text-8oxg9"><p class="eb-text">Bảng Authentication</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="735" height="331" src="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg" alt="" class="wp-image-29022" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg 735w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x135.jpg 300w" sizes="auto, (max-width: 735px) 100vw, 735px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Method</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>(ví dụ) FortiSophos@123</td></tr><tr><td>IKE Version</td><td>2</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-2qql7"><div class="eb-parent-wrapper eb-parent-eb-text-2qql7 "><div class="eb-text-wrapper eb-text-2qql7" data-id="eb-text-2qql7"><p class="eb-text">&#8211; PSK phải giống 100% bên Sophos</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-11jdu"><div class="eb-parent-wrapper eb-parent-eb-text-11jdu "><div class="eb-text-wrapper eb-text-11jdu" data-id="eb-text-11jdu"><p class="eb-text">Phase 1 Proposal</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="757" height="376" src="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg" alt="" class="wp-image-29023" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg 757w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x149.jpg 300w" sizes="auto, (max-width: 757px) 100vw, 757px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>28800</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6r9aw"><div class="eb-parent-wrapper eb-parent-eb-text-6r9aw "><div class="eb-text-wrapper eb-text-6r9aw" data-id="eb-text-6r9aw"><p class="eb-text">Phase 2 Selectors</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="578" height="714" src="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg" alt="" class="wp-image-29032" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg 578w, https://vacif.com/wp-content/uploads/2026/03/image-28-243x300.jpg 243w" sizes="auto, (max-width: 578px) 100vw, 578px" /></figure>



<p><strong>Selector 1</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 10.10.10.0/24</li>
</ul>



<p><strong>Selector 2</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 192.168.20.0/24</li>
</ul>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>43200</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4mf91"><div class="eb-parent-wrapper eb-parent-eb-text-4mf91 "><div class="eb-text-wrapper eb-text-4mf91" data-id="eb-text-4mf91"><p class="eb-text">&#8211; Mỗi subnet Sophos cần 1 Phase 2<br>&#8211; Nếu gộp → tunnel UP nhưng không có traffic</p></div></div></div>



<p>Nhấn OK để tạo VPN Tunnel.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ljz9a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ljz9a "><div class="eb-advance-heading-wrapper eb-advance-heading-ljz9a button-1 undefined" data-id="eb-advance-heading-ljz9a"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Tạo Static Route</span></h2></div></div></div>



<p>Vào Network → Static Routes → Create New</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg" alt="" class="wp-image-29027" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-i0llt"><div class="eb-parent-wrapper eb-parent-eb-text-i0llt "><div class="eb-text-wrapper eb-text-i0llt" data-id="eb-text-i0llt"><p class="eb-text">Route 1</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>10.10.10.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-t16sq"><div class="eb-parent-wrapper eb-parent-eb-text-t16sq "><div class="eb-text-wrapper eb-text-t16sq" data-id="eb-text-t16sq"><p class="eb-text">Route 2</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg" alt="" class="wp-image-29026" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>192.168.20.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-175x1"><div class="eb-parent-wrapper eb-parent-eb-text-175x1 "><div class="eb-text-wrapper eb-text-175x1" data-id="eb-text-175x1"><p class="eb-text">&#8211; Nếu thiếu static route → ping không bao giờ đi vào VPN</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-siaef"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-siaef "><div class="eb-advance-heading-wrapper eb-advance-heading-siaef button-1 undefined" data-id="eb-advance-heading-siaef"><h2 class="eb-ah-title"><span class="first-title"><a>1.3</a> &#8211; Tạo Firewall Policy</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-k0mcg"><div class="eb-parent-wrapper eb-parent-eb-text-k0mcg "><div class="eb-text-wrapper eb-text-k0mcg" data-id="eb-text-k0mcg"><p class="eb-text">Policy 1 – LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg" alt="" class="wp-image-29030" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>LAN</td></tr><tr><td>Outgoing Interface</td><td>S2S-LAB</td></tr><tr><td>Source</td><td>172.16.16.0/24</td></tr><tr><td>Destination</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr><tr><td>NAT</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-04oaf"><div class="eb-parent-wrapper eb-parent-eb-text-04oaf "><div class="eb-text-wrapper eb-text-04oaf" data-id="eb-text-04oaf"><p class="eb-text">Policy 2 – VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg" alt="" class="wp-image-29031" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>S2S-LAB</td></tr><tr><td>Outgoing Interface</td><td>LAN</td></tr><tr><td>Source</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination</td><td>172.16.16.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-i77g3"><div class="eb-parent-wrapper eb-parent-eb-text-i77g3 "><div class="eb-text-wrapper eb-text-i77g3" data-id="eb-text-i77g3"><p class="eb-text">&#8211; Policy VPN phải nằm trên policy Internet</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qh3q2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qh3q2 "><div class="eb-advance-heading-wrapper eb-advance-heading-qh3q2 button-1 undefined" data-id="eb-advance-heading-qh3q2"><h2 class="eb-ah-title"><span class="first-title"><a>2. </a>Trên thiết bị Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a7f6u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a7f6u "><div class="eb-advance-heading-wrapper eb-advance-heading-a7f6u button-1 undefined" data-id="eb-advance-heading-a7f6u"><h2 class="eb-ah-title"><span class="first-title">2.1 &#8211; Tạo subnet</span></h2></div></div></div>



<p>Vào Hosts and Services → Add</p>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tên</strong></th><th><strong>Loại</strong></th><th><strong>Thông số</strong></th></tr></thead><tbody><tr><td>LAN_SOPHOS_10</td><td>Network</td><td>IP: 10.10.10.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_SOPHOS_20</td><td>Network</td><td>IP: 192.168.20.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_FORTI</td><td>Network</td><td>IP: 172.16.16.0 / Subnet: 255.255.255.0</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bkx0m"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bkx0m "><div class="eb-advance-heading-wrapper eb-advance-heading-bkx0m button-1 undefined" data-id="eb-advance-heading-bkx0m"><h2 class="eb-ah-title"><span class="first-title">2.2 &#8211; Tạo IPSec Profile</span></h2></div></div></div>



<p>Vào SYSTEM &gt; Profiles → IPsec Profiles → Add</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg" alt="" class="wp-image-29024" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>Fortinet-Vacif</td></tr><tr><td>IKE Version</td><td>IKEv2</td></tr><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>DH Group</td><td>14</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x0jn2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x0jn2 "><div class="eb-advance-heading-wrapper eb-advance-heading-x0jn2 button-1 undefined" data-id="eb-advance-heading-x0jn2"><h2 class="eb-ah-title"><span class="first-title">2.3 &#8211; Tạo IPSec Connection</span></h2></div></div></div>



<p>Vào CONFIGURE → Site-to-site VPN → &nbsp;IPsec → Add</p>



<div class="wp-block-essential-blocks-text  root-eb-text-b8zwg"><div class="eb-parent-wrapper eb-parent-eb-text-b8zwg "><div class="eb-text-wrapper eb-text-b8zwg" data-id="eb-text-b8zwg"><p class="eb-text">General Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg" alt="" class="wp-image-29025" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>VPN_SOPHOS_VACIF</td></tr><tr><td>Connection Type</td><td>Policy-based</td></tr><tr><td>Gateway Type</td><td>Initiate the connection</td></tr><tr><td>Create firewall rule</td><td>Không chọn (tạo thủ công)</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-86g8b"><div class="eb-parent-wrapper eb-parent-eb-text-86g8b "><div class="eb-text-wrapper eb-text-86g8b" data-id="eb-text-86g8b"><p class="eb-text">Authentication</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Profile</td><td>Fortinet Vacif ( tạo ở bước trên )</td></tr><tr><td>Authentication Type&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>FortiSophos@123</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6opfg"><div class="eb-parent-wrapper eb-parent-eb-text-6opfg "><div class="eb-text-wrapper eb-text-6opfg" data-id="eb-text-6opfg"><p class="eb-text">Gateway Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg" alt="" class="wp-image-29033" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<ul class="wp-block-list">
<li>Listening interface: Port 2 – 192.168.1.3</li>



<li>Gateway address: 192.168.1.2 (WAN Fortinet)</li>



<li>Local Subnet: 10.10.10.0/24 , 192.168.20.0/24</li>



<li>Remote Subnet: 172.16.16.0/24</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2dz5o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2dz5o "><div class="eb-advance-heading-wrapper eb-advance-heading-2dz5o button-1 undefined" data-id="eb-advance-heading-2dz5o"><h2 class="eb-ah-title"><span class="first-title"><a>2.4</a> &#8211; Tạo Firewall Rule Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-069m1"><div class="eb-parent-wrapper eb-parent-eb-text-069m1 "><div class="eb-text-wrapper eb-text-069m1" data-id="eb-text-069m1"><p class="eb-text">LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg" alt="" class="wp-image-29028" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>LAN</td></tr><tr><td>Destination Zone</td><td>VPN</td></tr><tr><td>Source Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination Network</td><td>172.16.16.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-0pm0n"><div class="eb-parent-wrapper eb-parent-eb-text-0pm0n "><div class="eb-text-wrapper eb-text-0pm0n" data-id="eb-text-0pm0n"><p class="eb-text">VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg" alt="" class="wp-image-29029" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>VPN</td></tr><tr><td>Destination Zone</td><td>LAN</td></tr><tr><td>Source Network</td><td>172.16.16.0/24</td></tr><tr><td>Destination Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeg05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeg05 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeg05 button-1 undefined" data-id="eb-advance-heading-qeg05"><h2 class="eb-ah-title"><span class="first-title"><a>3</a>. Kiểm tra kết quả</span></h2></div></div></div>



<p><strong>Sophos:</strong> VPN → IPsec Connections → Status: <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f7e2.png" alt="🟢" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Connected</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg" alt="" class="wp-image-29034" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Fortinet:</strong> Monitor → IPsec Monitor → Tunnel: UP (Có Incoming / Outgoing Data)</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg" alt="" class="wp-image-29035" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Test:</strong></p>



<ul class="wp-block-list">
<li>172.16.16.x → 10.10.10.x</li>



<li>172.16.16.x → 192.168.20.x</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg" alt="" class="wp-image-29036" srcset="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-32-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-32-768x404.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iq8fr"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iq8fr "><div class="eb-advance-heading-wrapper eb-advance-heading-iq8fr button-1 undefined" data-id="eb-advance-heading-iq8fr"><h2 class="eb-ah-title"><span class="first-title">* Ghi chú &amp; Lưu ý triển khai</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đảm bảo thời gian hệ thống đồng bộ (NTP) để tránh lỗi IKEv2 do lệch thời gian.</li>



<li>PSK, thuật toán mã hóa và nhóm DH phải trùng khớp 2 đầu – sai khác sẽ khiến Phase 1/2 thất bại.</li>



<li>Tắt NAT trên policy đi vào VPN; bật NAT sẽ làm sai nguồn và gói tin không match selector.</li>



<li>Mỗi cặp Local/Remote subnet cần 1 selector (Phase 2). Không gộp nhiều subnet nếu thiết bị không hỗ trợ.</li>



<li>Nếu tunnel UP nhưng không ping được, kiểm tra: Static Route, Policy thứ tự, và bảng ARP/Route trên hai đầu.</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
