<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sophos Firewall &#8211; VACIF</title>
	<atom:link href="https://vacif.com/tag/sophos-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>https://vacif.com</link>
	<description>Đầu tư cho giá trị</description>
	<lastBuildDate>Wed, 25 Mar 2026 09:51:46 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://vacif.com/wp-content/uploads/2024/06/cropped-icon-32x32.png</url>
	<title>Sophos Firewall &#8211; VACIF</title>
	<link>https://vacif.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>[Mới Nhất 2026] Hướng Dẫn Cài Đặt Tường Tửa Sophos Firewall Ảo Bằng File KVM và Dùng Lệnh CLI Trên proxmox</title>
		<link>https://vacif.com/moi-nhat-2026-huong-dan-cai-dat-tuong-tua-sophos-firewall-ao-bang-file-kvm-va-dung-lenh-cli-tren-proxmox/</link>
					<comments>https://vacif.com/moi-nhat-2026-huong-dan-cai-dat-tuong-tua-sophos-firewall-ao-bang-file-kvm-va-dung-lenh-cli-tren-proxmox/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 25 Mar 2026 09:46:19 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Ảo Hóa]]></category>
		<category><![CDATA[CLI]]></category>
		<category><![CDATA[Proxmox VE]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29268</guid>

					<description><![CDATA[Nếu bạn đã quen với việc triển khai Sophos Firewall trên các nền tảng ảo hóa như VMware Workstation hoặc ESXi, thì Proxmox VE là một lựa chọn đáng để thử khi xây dựng hệ thống lab hoặc hạ tầng ảo hóa chi phí thấp. Proxmox VE là nền tảng ảo hóa mã nguồn mở [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u00e0i \u0111\u1eb7t t\u01b0\u1eddng l\u1eeda Sophos Firewall \u1ea3o b\u1eb1ng file KVM v\u00e0 d\u00f9ng l\u1ec7nh CLI tr\u00ean Proxmox&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u00e0i \u0111\u1eb7t t\u01b0\u1eddng l\u1eeda Sophos Firewall \u1ea3o b\u1eb1ng file KVM v\u00e0 d\u00f9ng l\u1ec7nh CLI tr\u00ean Proxmox&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. T\u1ea3i file Sophos Firewall KVM Image&quot;,&quot;text&quot;:&quot;1. T\u1ea3i file Sophos Firewall KVM Image&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Upload file image l\u00ean server Proxmox&quot;,&quot;text&quot;:&quot;2. Upload file image l\u00ean server Proxmox&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. T\u1ea1o m\u00e1y \u1ea3o Sophos Firewall b\u1eb1ng CLI&quot;,&quot;text&quot;:&quot;3. T\u1ea1o m\u00e1y \u1ea3o Sophos Firewall b\u1eb1ng CLI&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4. Import disk image v\u00e0o m\u00e1y \u1ea3o &quot;,&quot;text&quot;:&quot;4. Import disk image v\u00e0o m\u00e1y \u1ea3o &quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;5. C\u1ea5u h\u00ecnh boot disk&quot;,&quot;text&quot;:&quot;5. C\u1ea5u h\u00ecnh boot disk&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;6. Kh\u1edfi \u0111\u1ed9ng Sophos Firewall&quot;,&quot;text&quot;:&quot;6. Kh\u1edfi \u0111\u1ed9ng Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;7. Truy c\u1eadp giao di\u1ec7n Web Admin&quot;,&quot;text&quot;:&quot;7. Truy c\u1eadp giao di\u1ec7n Web Admin&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - M\u1ee5c \u0111\u00edch b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-m\u1ee5c-\u0111\u00edch-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u00e0i \u0111\u1eb7t t\u01b0\u1eddng l\u1eeda Sophos Firewall \u1ea3o b\u1eb1ng file KVM v\u00e0 d\u00f9ng l\u1ec7nh CLI tr\u00ean Proxmox&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u00e0i-\u0111\u1eb7t-t\u01b0\u1eddng-l\u1eeda-sophos-firewall-\u1ea3o-b\u1eb1ng-file-kvm-v\u00e0-d\u00f9ng-l\u1ec7nh-cli-tr\u00ean-proxmox&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. T\u1ea3i file Sophos Firewall KVM Image&quot;,&quot;value&quot;:&quot;1-t\u1ea3i-file-sophos-firewall-kvm-image&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Upload file image l\u00ean server Proxmox&quot;,&quot;value&quot;:&quot;2-upload-file-image-l\u00ean-server-proxmox&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. T\u1ea1o m\u00e1y \u1ea3o Sophos Firewall b\u1eb1ng CLI&quot;,&quot;value&quot;:&quot;3-t\u1ea1o-m\u00e1y-\u1ea3o-sophos-firewall-b\u1eb1ng-cli&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;4. Import disk image v\u00e0o m\u00e1y \u1ea3o &quot;,&quot;value&quot;:&quot;4-import-disk-image-v\u00e0o-m\u00e1y-\u1ea3o&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;5. C\u1ea5u h\u00ecnh boot disk&quot;,&quot;value&quot;:&quot;5-c\u1ea5u-h\u00ecnh-boot-disk&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;6. Kh\u1edfi \u0111\u1ed9ng Sophos Firewall&quot;,&quot;value&quot;:&quot;6-kh\u1edfi-\u0111\u1ed9ng-sophos-firewall&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;7. Truy c\u1eadp giao di\u1ec7n Web Admin&quot;,&quot;value&quot;:&quot;7-truy-c\u1eadp-giao-di\u1ec7n-web-admin&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Mục đích bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cài đặt tường lửa Sophos Firewall ảo bằng file KVM và dùng lệnh CLI trên Proxmox</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Mục đích bài viết</span></h2></div></div></div>



<p>Nếu bạn đã quen với việc triển khai <strong>Sophos Firewall</strong> trên các nền tảng ảo hóa như VMware Workstation hoặc ESXi, thì <strong>Proxmox VE </strong>là một lựa chọn đáng để thử khi xây dựng hệ thống lab hoặc hạ tầng ảo hóa chi phí thấp.</p>



<p><strong>Proxmox VE là nền tảng ảo hóa mã nguồn mở hỗ trợ hai công nghệ chính:</strong></p>



<ul class="wp-block-list">
<li>KVM (Kernel-based Virtual Machine) để chạy máy ảo</li>



<li>LXC (Linux Containers) để chạy container</li>
</ul>



<p><strong>Với các ưu điểm như:</strong></p>



<ul class="wp-block-list">
<li>Miễn phí và mã nguồn mở</li>



<li>Cộng đồng sử dụng lớn</li>



<li>Quản lý VM thông qua Web GUI</li>



<li>Hỗ trợ snapshot, backup và clustering</li>
</ul>



<p><strong>Proxmox ngày càng được nhiều doanh nghiệp vừa và nhỏ lựa chọn. Trong bài viết này, chúng ta sẽ thực hiện:</strong></p>



<ul class="wp-block-list">
<li>Triển khai Sophos Firewall Virtual trên Proxmox VE</li>



<li>Sử dụng file KVM image của Sophos</li>



<li>Tạo máy ảo bằng lệnh CLI trên Proxmox</li>



<li>Import disk image vào VM</li>



<li>Khởi động Sophos Firewall và thực hiện cấu hình ban đầu</li>
</ul>



<p>Sau khi hoàn thành bài lab, Sophos Firewall sẽ hoạt động như một tường lửa ảo trong hệ thống Proxmox.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4yuyy"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4yuyy "><div class="eb-advance-heading-wrapper eb-advance-heading-4yuyy button-1 undefined" data-id="eb-advance-heading-4yuyy"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="939" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-37.png" alt="" class="wp-image-29269" srcset="https://vacif.com/wp-content/uploads/2026/03/image-37.png 939w, https://vacif.com/wp-content/uploads/2026/03/image-37-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-37-768x325.png 768w" sizes="(max-width: 939px) 100vw, 939px" /></figure>



<p>Trong mô hình này:</p>



<ul class="wp-block-list">
<li>Proxmox VE đóng vai trò là <strong>hypervisor</strong> để chạy máy ảo.</li>



<li>Sophos Firewall được cài đặt dưới dạng <strong>Virtual Machine</strong>.</li>



<li>Máy Windows Client dùng để: 
<ul class="wp-block-list">
<li>Truy cập giao diện quản trị firewall</li>



<li>Kiểm tra trạng thái hoạt động của hệ thống.</li>
</ul>
</li>
</ul>



<p>Quản trị viên truy cập vào giao diện quản trị của Sophos Firewall thông qua trình duyệt web với địa chỉ: <strong>https://10.10.10.200:4444</strong></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-6oz1o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-6oz1o "><div class="eb-advance-heading-wrapper eb-advance-heading-6oz1o button-1 undefined" data-id="eb-advance-heading-6oz1o"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Trong bài lab này, chúng ta thực hiện triển khai Sophos Firewall dưới dạng máy ảo trên Proxmox VE với mục đích xây dựng môi trường thử nghiệm.</p>



<p><strong>Các yêu cầu của hệ thống như sau:</strong></p>



<ul class="wp-block-list">
<li>Cài đặt Sophos Firewall Virtual trên Proxmox.</li>



<li>Cấu hình địa chỉ IP cho firewall là<strong> 10.10.10.200/24.</strong></li>



<li>Máy Windows Client có địa chỉ <strong>10.10.10.116/24.</strong></li>



<li>Máy Windows có thể truy cập vào giao diện quản trị của Sophos Firewall thông qua trình duyệt web.</li>
</ul>



<p><strong>Sau khi hoàn thành cấu hình:</strong></p>



<ul class="wp-block-list">
<li>Quản trị viên có thể đăng nhập vào giao diện Web Admin</li>



<li>Thực hiện các cấu hình bảo mật, firewall rule và quản lý hệ thống.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-47r7n"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-47r7n "><div class="eb-advance-heading-wrapper eb-advance-heading-47r7n button-1 undefined" data-id="eb-advance-heading-47r7n"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<p><strong>Quá trình triển khai Sophos Firewall Virtual trên Proxmox gồm các bước chính sau:</strong></p>



<ol class="wp-block-list">
<li>Tải file <strong>&#8220;Sophos Firewall KVM Image&#8221;</strong></li>



<li>Upload file image lên server Proxmox</li>



<li>Tạo máy ảo Sophos Firewall bằng CLI</li>



<li>Import disk image vào máy ảo</li>



<li>Cấu hình boot disk</li>



<li>Khởi động Sophos Firewall</li>



<li>Truy cập giao diện Web Admin</li>
</ol>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-k9cwb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-k9cwb "><div class="eb-advance-heading-wrapper eb-advance-heading-k9cwb button-1 undefined" data-id="eb-advance-heading-k9cwb"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cài đặt tường lửa Sophos Firewall ảo bằng file KVM và dùng lệnh CLI trên Proxmox</span></h2></div></div></div>



<p><strong>Trước khi bắt tay vào dựng Sophos Firewall trên Proxmox, bạn cần chuẩn bị:</strong></p>



<ul class="wp-block-list">
<li>Máy chủ/PC đã cài Proxmox VE (khuyến nghị bản 7.x hoặc mới hơn).</li>



<li>File KVM Sophos Firewall (SFOS): tải từ trang chủ Sophos (bản Home hoặc Trial).</li>



<li>Tài nguyên tối thiểu cho VM: CPU: 2, coreRAM: 4 GB</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Tải file Sophos Firewall KVM Image</span></h2></div></div></div>



<p>Trước tiên, chúng ta cần chuẩn bị file KVM cài đặt Sophos Firewall. Truy cập trang chính thức của Sophos tại: <strong>https://www.sophos.com/en-us/support/downloads/firewall-installers.</strong> Tại đây, chọn và tải về phiên bản dành cho KVM (tương thích với Proxmox).</p>



<figure class="wp-block-image size-full"><img decoding="async" width="753" height="403" src="https://vacif.com/wp-content/uploads/2026/03/image-39.png" alt="" class="wp-image-29270" srcset="https://vacif.com/wp-content/uploads/2026/03/image-39.png 753w, https://vacif.com/wp-content/uploads/2026/03/image-39-300x161.png 300w" sizes="(max-width: 753px) 100vw, 753px" /></figure>



<p>Sau khi tải và giải nén ta được 2 file như sau:</p>



<figure class="wp-block-image size-full"><img decoding="async" width="502" height="43" src="https://vacif.com/wp-content/uploads/2026/03/image-38.png" alt="" class="wp-image-29271" srcset="https://vacif.com/wp-content/uploads/2026/03/image-38.png 502w, https://vacif.com/wp-content/uploads/2026/03/image-38-300x26.png 300w" sizes="(max-width: 502px) 100vw, 502px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="309" height="119" src="https://vacif.com/wp-content/uploads/2026/03/image-40.png" alt="" class="wp-image-29272" srcset="https://vacif.com/wp-content/uploads/2026/03/image-40.png 309w, https://vacif.com/wp-content/uploads/2026/03/image-40-300x116.png 300w" sizes="auto, (max-width: 309px) 100vw, 309px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-7cjjp"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-7cjjp "><div class="eb-advance-heading-wrapper eb-advance-heading-7cjjp button-1 undefined" data-id="eb-advance-heading-7cjjp"><h2 class="eb-ah-title"><span class="first-title">2. Upload file image lên server Proxmox</span></h2></div></div></div>



<p>Tạo máy ảo Sophos Firewall trên Proxmox -&gt; Đăng nhập vào Proxmox Web UI -&gt; chọn <strong>Create VM</strong> để bắt đầu tạo máy ảo mới -&gt; Nhập <strong>VM ID</strong> và T<strong>ên máy ảo (Name).</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="274" src="https://vacif.com/wp-content/uploads/2026/03/image-43.png" alt="" class="wp-image-29275" srcset="https://vacif.com/wp-content/uploads/2026/03/image-43.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-43-300x109.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="553" src="https://vacif.com/wp-content/uploads/2026/03/image-42.png" alt="" class="wp-image-29273" srcset="https://vacif.com/wp-content/uploads/2026/03/image-42.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-42-300x221.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p>Tick chọn <strong>Do not use any media -&gt;</strong>Type: <strong>linux -&gt;</strong>Version: <strong>6.x &#8211; 2.6 Kernel</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="273" src="https://vacif.com/wp-content/uploads/2026/03/image-41.png" alt="" class="wp-image-29274" srcset="https://vacif.com/wp-content/uploads/2026/03/image-41.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-41-300x109.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p>Sockets: <strong>2</strong></p>



<p>Cores: <strong>2</strong></p>



<p>Type: <strong>host</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="183" src="https://vacif.com/wp-content/uploads/2026/03/image-44.png" alt="" class="wp-image-29278" srcset="https://vacif.com/wp-content/uploads/2026/03/image-44.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-44-300x73.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p></p>



<p>Memory(MB): 4096 và click next</p>



<p></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="160" src="https://vacif.com/wp-content/uploads/2026/03/image-46.png" alt="" class="wp-image-29279" srcset="https://vacif.com/wp-content/uploads/2026/03/image-46.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-46-300x64.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p></p>



<p>Chọn card mạng <strong>bridge </strong>và click<strong>next -></strong> chắc chắn ràng không có gì sai xót sau khi tạo xong, nhấn <strong>finish.</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="265" src="https://vacif.com/wp-content/uploads/2026/03/image-45.png" alt="" class="wp-image-29277" srcset="https://vacif.com/wp-content/uploads/2026/03/image-45.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-45-300x106.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<p>Sử dụng công cụ WinSCP để tiến hành copy file KVM Sophos đã tải về vào thư mục của VM theo đường dẫn: <strong>/mnt/pve/disk-pve1/images/2027/</strong></p>



<p>Trong đó:</p>



<ul class="wp-block-list">
<li><strong>disk-pve1</strong> là tên storage trên Proxmox.</li>



<li><strong>2027 là VM ID</strong> mà bạn đã tạo ở bước trước.</li>
</ul>



<p><strong>** Lưu ý: </strong>Thư mục có dạng<strong>/mnt/pve/&lt;storage-name>/images/&lt;VMID>/</strong>. Bạn cần thay đúng <strong>&lt;storage-name></strong> và <strong>&lt;VMID></strong> theo môi trường của mình.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="939" height="824" src="https://vacif.com/wp-content/uploads/2026/03/image-48.png" alt="" class="wp-image-29281" srcset="https://vacif.com/wp-content/uploads/2026/03/image-48.png 939w, https://vacif.com/wp-content/uploads/2026/03/image-48-300x263.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-48-768x674.png 768w" sizes="auto, (max-width: 939px) 100vw, 939px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="940" height="215" src="https://vacif.com/wp-content/uploads/2026/03/image-49.png" alt="" class="wp-image-29282" srcset="https://vacif.com/wp-content/uploads/2026/03/image-49.png 940w, https://vacif.com/wp-content/uploads/2026/03/image-49-300x69.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-49-768x176.png 768w" sizes="auto, (max-width: 940px) 100vw, 940px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-m2738"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-m2738 "><div class="eb-advance-heading-wrapper eb-advance-heading-m2738 button-1 undefined" data-id="eb-advance-heading-m2738"><h2 class="eb-ah-title"><span class="first-title">3. Tạo máy ảo Sophos Firewall bằng CLI</span></h2></div></div></div>



<p>Mở <strong>Shell </strong>trong giao diện Proxmox.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="751" height="95" src="https://vacif.com/wp-content/uploads/2026/03/image-50.png" alt="" class="wp-image-29283" srcset="https://vacif.com/wp-content/uploads/2026/03/image-50.png 751w, https://vacif.com/wp-content/uploads/2026/03/image-50-300x38.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /></figure>



<p>Truy cập thư mục lưu trữ:</p>



<ul class="wp-block-list">
<li><strong>cd /mnt/pve</strong></li>



<li><strong>ls</strong></li>
</ul>



<p>→ Lệnh ls sẽ liệt kê tất cả các storage có trong Proxmox.</p>



<p>Di chuyển vào storage bạn đã dùng để lưu file KVM, ví dụ:</p>



<ul class="wp-block-list">
<li><strong>cd /mnt/pve/disk1-pve1/images/</strong></li>



<li><strong>Ls</strong></li>
</ul>



<p>Tại đây sẽ hiển thị danh sách các thư mục tương ứng với VM ID. Trong ví dụ này, máy Sophos Firewall được gán VM ID = 1027:</p>



<ul class="wp-block-list">
<li><strong>cd 1027</strong></li>



<li><strong>ls</strong></li>
</ul>



<p>→ Bạn sẽ thấy toàn bộ các file (bao gồm ISO và disk image) của VM Sophos Firewall.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="412" src="https://vacif.com/wp-content/uploads/2026/03/image-51.png" alt="" class="wp-image-29284" srcset="https://vacif.com/wp-content/uploads/2026/03/image-51.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-51-300x164.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-kb9wj"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-kb9wj "><div class="eb-advance-heading-wrapper eb-advance-heading-kb9wj button-1 undefined" data-id="eb-advance-heading-kb9wj"><h2 class="eb-ah-title"><span class="first-title">4. Import disk image vào máy ảo </span></h2></div></div></div>



<p>Mở file cấu hình của VM bằng trình soạn thảo nano:</p>



<ul class="wp-block-list">
<li> <strong>nano /etc/pve/qemu-server/1027.conf</strong></li>
</ul>



<p>Thêm hoặc chỉnh sửa 2 dòng sau để khai báo ổ đĩa cho Sophos Firewall:</p>



<ul class="wp-block-list">
<li><strong>scsi0: disk1-pve1:1027/PRIMARY-DISK.qcow2,size=32G</strong></li>



<li><strong>scsi1: disk1-pve1:1027/AUXILIARY-DISK.qcow2,size=80G</strong></li>
</ul>



<p>→ scsi0: Ổ cứng chính (32GB).</p>



<p>→ scsi1: Ổ phụ (80GB).</p>



<p><strong>Lưu file cấu hình:</strong></p>



<ul class="wp-block-list">
<li>Nhấn <strong>Ctrl + O → Enter</strong> để lưu.</li>



<li>Nhấn <strong>Ctrl + X</strong> để thoát khỏi nano.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="751" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-52.png" alt="" class="wp-image-29285" srcset="https://vacif.com/wp-content/uploads/2026/03/image-52.png 751w, https://vacif.com/wp-content/uploads/2026/03/image-52-300x181.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-o2e58"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-o2e58 "><div class="eb-advance-heading-wrapper eb-advance-heading-o2e58 button-1 undefined" data-id="eb-advance-heading-o2e58"><h2 class="eb-ah-title"><span class="first-title">5. Cấu hình boot disk</span></h2></div></div></div>



<p>Tick chọn như hình bên dưới</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="752" height="319" src="https://vacif.com/wp-content/uploads/2026/03/image-53.png" alt="" class="wp-image-29286" srcset="https://vacif.com/wp-content/uploads/2026/03/image-53.png 752w, https://vacif.com/wp-content/uploads/2026/03/image-53-300x127.png 300w" sizes="auto, (max-width: 752px) 100vw, 752px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-zapov"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-zapov "><div class="eb-advance-heading-wrapper eb-advance-heading-zapov button-1 undefined" data-id="eb-advance-heading-zapov"><h2 class="eb-ah-title"><span class="first-title">6. Khởi động Sophos Firewall</span></h2></div></div></div>



<p>Sau khi hoàn tất, nhấn <strong>Start</strong> để khởi động node Sophos Firewall.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="751" height="348" src="https://vacif.com/wp-content/uploads/2026/03/image-54.png" alt="" class="wp-image-29287" srcset="https://vacif.com/wp-content/uploads/2026/03/image-54.png 751w, https://vacif.com/wp-content/uploads/2026/03/image-54-300x139.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dom1g"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dom1g "><div class="eb-advance-heading-wrapper eb-advance-heading-dom1g button-1 undefined" data-id="eb-advance-heading-dom1g"><h2 class="eb-ah-title"><span class="first-title">7. Truy cập giao diện Web Admin</span></h2></div></div></div>



<p>Truy cập Console của VM để theo dõi quá trình boot. Nếu thấy giao diện cài đặt của Sophos xuất hiện và hệ thống chạy ổn định, nghĩa là bạn đã triển khai thành công.</p>



<p>Như vậy, chúng ta đã chạy Sophos Firewall ảo trong Proxmox thành công. Từ đây, bạn có thể tiếp tục:</p>



<ul class="wp-block-list">
<li>Truy cập WebAdmin</li>



<li>Thực hiện các bước cấu hình cơ bản (IP LAN/WAN, NAT, Firewall Rule).</li>



<li>Mở rộng lab với VPN, IPS, WAF, hoặc thử nghiệm các tính năng bảo mật khác.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="753" height="495" src="https://vacif.com/wp-content/uploads/2026/03/image-55.png" alt="" class="wp-image-29288" srcset="https://vacif.com/wp-content/uploads/2026/03/image-55.png 753w, https://vacif.com/wp-content/uploads/2026/03/image-55-300x197.png 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-huong-dan-cai-dat-tuong-tua-sophos-firewall-ao-bang-file-kvm-va-dung-lenh-cli-tren-proxmox/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site To Site Giữa 2 Thiết Bị Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 08:07:55 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Cấu Hình VPN Site To Site]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29071</guid>

					<description><![CDATA[Bài viết này hướng dẫn cấu hình IPsec Site-to-Site VPN giữa hai thiết bị Sophos Firewall XGS sử dụng firmware v22, nhằm xây dựng kết nối bảo mật giữa hai hệ thống mạng đặt tại hai địa điểm khác nhau. Mục tiêu của bài lab: Môi trường triển khai: Doanh nghiệp có hai site sử [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;text&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;text&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u &quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn chi ti\u1ebft c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa 2 thi\u1ebft b\u1ecb Sophos Firewall Firmware V22&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-chi-ti\u1ebft-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-2-thi\u1ebft-b\u1ecb-sophos-firewall-firmware-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 1&quot;,&quot;value&quot;:&quot;1-c\u1ea5u-h\u00ecnh-tr\u00ean-sophos-firewall-1&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u1ea5u h\u00ecnh tr\u00ean Sophos Firewall 2&quot;,&quot;value&quot;:&quot;2-c\u1ea5u-h\u00ecnh-tr\u00ean-sophos-firewall-2&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu </a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn chi tiết cấu hình VPN site to site giữa 2 thiết bị Sophos Firewall Firmware V22</a><li><a href="#eb-table-content-5">1. Cấu hình trên Sophos Firewall 1</a><li><a href="#eb-table-content-6">2. Cấu hình trên Sophos Firewall 2</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cấu hình IPsec Site-to-Site VPN giữa hai thiết bị Sophos Firewall XGS sử dụng firmware v22, nhằm xây dựng kết nối bảo mật giữa hai hệ thống mạng đặt tại hai địa điểm khác nhau.</p>



<p><strong>Mục tiêu của bài lab:</strong></p>



<ul class="wp-block-list">
<li>Thiết lập thành công đường hầm IPsec giữa hai firewall.</li>



<li>Cho phép hai mạng LAN tại hai site truy cập và trao đổi dữ liệu với nhau.</li>



<li>Đảm bảo toàn bộ lưu lượng truyền qua Internet được mã hóa an toàn.</li>



<li>Kiểm tra và xác minh trạng thái hoạt động của VPN Tunnel.</li>



<li>Hiểu rõ cơ chế hoạt động của Phase 1 (IKE SA) và Phase 2 (IPsec SA) trong quá trình thiết lập VPN.</li>
</ul>



<p><strong>Môi trường triển khai:</strong></p>



<ul class="wp-block-list">
<li>02 Sophos Firewall XGS (Virtual Appliance).</li>



<li>Cài đặt trên nền tảng ảo hóa Proxmox VE.</li>



<li>Hai đầu sử dụng IP WAN tĩnh, được cấp từ firewall/router thật để mô phỏng môi trường thực tế.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="903" src="https://vacif.com/wp-content/uploads/2026/03/image-13.png" alt="" class="wp-image-29072" srcset="https://vacif.com/wp-content/uploads/2026/03/image-13.png 975w, https://vacif.com/wp-content/uploads/2026/03/image-13-300x278.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-13-768x711.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<p>Doanh nghiệp có hai site sử dụng hai thiết bị Sophos Firewall XGS kết nối ra Internet qua router Viettel với IP WAN lần lượt là <strong>123.123.123.11 và 123.123.123.15.</strong> Mỗi site có một mạng LAN riêng là <strong>100.100.100.0/24 và 200.200.200.0/24.</strong> Hiện tại hai mạng này không thể truy cập lẫn nhau qua Internet. Yêu cầu đặt ra là cho phép hai mạng LAN giao tiếp an toàn và ổn định. Giải pháp là triển khai VPN Site-to-Site IPsec để mã hóa và kết nối hai hệ thống qua Internet.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-p2o1y"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-p2o1y "><div class="eb-advance-heading-wrapper eb-advance-heading-p2o1y button-1 undefined" data-id="eb-advance-heading-p2o1y"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu </span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chuẩn bị thông tin cấu hình</li>



<li>Tạo các Network Object (Host/Subnet)</li>



<li>Cấu hình IPsec Site-to-Site VPN</li>



<li>Tạo Firewall Rule cho phép lưu lượng LAN <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2194.png" alt="↔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> VPN</li>



<li>Kiểm tra trạng thái hoạt động của VPN</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8kdbt"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8kdbt "><div class="eb-advance-heading-wrapper eb-advance-heading-8kdbt button-1 undefined" data-id="eb-advance-heading-8kdbt"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn chi tiết cấu hình VPN site to site giữa 2 thiết bị Sophos Firewall Firmware V22</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Cấu hình trên Sophos Firewall 1</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-unl1v"><div class="eb-parent-wrapper eb-parent-eb-text-unl1v "><div class="eb-text-wrapper eb-text-unl1v" data-id="eb-text-unl1v"><p class="eb-text"><strong>Bước 1:  </strong>Kiểm tra cấu hình interface, Ở Sophos Firewall 1, Có cổng WAN IP là 123.123.123.11, LAN là 100.100.100.1/24</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="780" src="https://vacif.com/wp-content/uploads/2026/03/image-15.png" alt="" class="wp-image-29074" srcset="https://vacif.com/wp-content/uploads/2026/03/image-15.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-15-300x250.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-15-768x640.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-lmfk5"><div class="eb-parent-wrapper eb-parent-eb-text-lmfk5 "><div class="eb-text-wrapper eb-text-lmfk5" data-id="eb-text-lmfk5"><p class="eb-text"><strong>Bước 2:</strong> Thêm Local và Remote LAN Network</p></div></div></div>



<p>Đến phần <strong>Hosts and services &gt; IP Host &gt; Add </strong>để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="727" src="https://vacif.com/wp-content/uploads/2026/03/image-14.png" alt="" class="wp-image-29073" srcset="https://vacif.com/wp-content/uploads/2026/03/image-14.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-14-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-14-768x597.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="728" src="https://vacif.com/wp-content/uploads/2026/03/image-19.png" alt="" class="wp-image-29079" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-19-768x597.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4keta"><div class="eb-parent-wrapper eb-parent-eb-text-4keta "><div class="eb-text-wrapper eb-text-4keta" data-id="eb-text-4keta"><p class="eb-text"><strong>Bước 3: </strong>Vào mục <strong>Administrator > Device Access > WAN: </strong>tick chọn <strong>IPsec</strong></p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-20.png" alt="" class="wp-image-29078" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-uouu5"><div class="eb-parent-wrapper eb-parent-eb-text-uouu5 "><div class="eb-text-wrapper eb-text-uouu5" data-id="eb-text-uouu5"><p class="eb-text"><strong>Bước 4: </strong>Tạo IPsec Connection</p></div></div></div>



<p>Vào mục <strong>Site to site &gt; IPsec &gt; Add</strong></p>



<ul class="wp-block-list">
<li><strong>IP Version: IPv4 </strong>-&gt; Tunnel sử dụng địa chỉ IPv4 để thiết lập IKE và truyền dữ liệu ESP.</li>



<li><strong>Connection Type: Policy-based</strong> -&gt; Chỉ những subnet khai báo ở Local subnet và Remote subnet mới được phép đi qua tunnel.</li>



<li><strong>Gateway Type: Respond only </strong>-&gt; Firewall này không chủ động kết nối, chỉ phản hồi khi bên kia gọi.</li>



<li><strong>Profile: IKEv2</strong> → Chuẩn VPN mới, ổn định và bảo mật hơn IKEv1.</li>



<li><strong>Authentication: Preshared Key (PSK) </strong>→ Hai firewall dùng chung một mật khẩu bí mật</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-16.png" alt="" class="wp-image-29076" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<ul class="wp-block-list">
<li><strong>Listening interface: 123.123.123.11</strong> -&gt; Đây là IP WAN của firewall này, firewall sẽ chờ kết nối VPN tại IP này.</li>



<li><strong>Gateway address: 123.123.123.15</strong> -&gt; Đây là IP WAN của firewall bên kia, VPN sẽ kết nối đến IP này.</li>



<li><strong>Local Subnet: LOCAL_VLAN_100 </strong>-&gt; Mạng nội bộ phía mình được phép đi qua VPN.</li>



<li><strong>Remote Subnet: VPN_VLAN_200 </strong>-&gt; Mạng nội bộ phía bên kia.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="729" src="https://vacif.com/wp-content/uploads/2026/03/image-18.png" alt="" class="wp-image-29077" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x234.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-18-768x598.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="732" src="https://vacif.com/wp-content/uploads/2026/03/image-17.png" alt="" class="wp-image-29075" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-17-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-iljad"><div class="eb-parent-wrapper eb-parent-eb-text-iljad "><div class="eb-text-wrapper eb-text-iljad" data-id="eb-text-iljad"><p class="eb-text"><strong>Bước 5:</strong> Tạo Firewall Rule</p></div></div></div>



<ul class="wp-block-list">
<li><strong>Rule name: VPN_SF_TO_SF1</strong></li>



<li><strong>Action: Accep</strong>t -&gt; Cho phép lưu lượng đi qua</li>



<li><strong>Log firewall traffic: Tick chọn</strong> -&gt; Ghi log để kiểm tra khi cần</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="741" src="https://vacif.com/wp-content/uploads/2026/03/image-21.png" alt="" class="wp-image-29080" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x238.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x608.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<ul class="wp-block-list">
<li><strong>Source zones: LAN, VPN </strong>-&gt; Nghĩa là lưu lượng có thể xuất phát từ mạng nội bộ, hoặc từ phía VPN bên kia</li>



<li><strong>Source networks: LOCAL_VLAN_100, VPN_VLAN_200 </strong>-&gt;chỉ những mạng này mới được phép sử dụng rule</li>



<li><strong>Destination zones: LAN, VPN </strong>-&gt; Cho phép truy cập hai chiều giữa LAN và VPN</li>



<li><strong>Destination networks: LOCAL_VLAN_100, VPN_VLAN_200</strong></li>



<li><strong>Services: Any</strong> -> Cho phép tất cả dịch vụ (ping, RDP, SMB, HTTP&#8230;)</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="692" src="https://vacif.com/wp-content/uploads/2026/03/image-31.png" alt="" class="wp-image-29093" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.png 975w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x213.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x545.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-8iylg"><div class="eb-parent-wrapper eb-parent-eb-text-8iylg "><div class="eb-text-wrapper eb-text-8iylg" data-id="eb-text-8iylg"><p class="eb-text"><strong>Bước 6: </strong>Kiểm tra trạng thái VPN</p></div></div></div>



<p>&nbsp;Vào mục <strong>Site to site VPN -&gt; IPsec -&gt; </strong>Tick chọn <strong>Active</strong> và Connection để bật cấu hình.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="736" src="https://vacif.com/wp-content/uploads/2026/03/image-22.png" alt="" class="wp-image-29081" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x236.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x604.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8jx05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8jx05 "><div class="eb-advance-heading-wrapper eb-advance-heading-8jx05 button-1 undefined" data-id="eb-advance-heading-8jx05"><h2 class="eb-ah-title"><span class="first-title">2. Cấu hình trên Sophos Firewall 2</span></h2></div></div></div>



<p>Vào <strong>Hosts and services &gt; IP Host &gt; Add</strong> để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="782" src="https://vacif.com/wp-content/uploads/2026/03/image-24.png" alt="" class="wp-image-29083" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x251.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x642.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="726" src="https://vacif.com/wp-content/uploads/2026/03/image-23.png" alt="" class="wp-image-29082" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x233.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x596.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-hch3o"><div class="eb-parent-wrapper eb-parent-eb-text-hch3o "><div class="eb-text-wrapper eb-text-hch3o" data-id="eb-text-hch3o"><p class="eb-text"><strong>Bước 1: </strong>Tạo kết nối IPsec VPN đến Firewall 1</p></div></div></div>



<p>Đến phần <strong>Site-to-Site VPN &gt; IPsec</strong> và chọn <strong>Add</strong>. Tạo kết nối với thông số bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="730" src="https://vacif.com/wp-content/uploads/2026/03/image-25.png" alt="" class="wp-image-29086" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x234.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x599.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="734" src="https://vacif.com/wp-content/uploads/2026/03/image-27.png" alt="" class="wp-image-29084" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x602.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-patfl"><div class="eb-parent-wrapper eb-parent-eb-text-patfl "><div class="eb-text-wrapper eb-text-patfl" data-id="eb-text-patfl"><p class="eb-text"><strong>Bước 2: </strong>Tạo Firewall Rules cho Firewall 2</p></div></div></div>



<p>Đến phần <strong>Rules and Policies -&gt; Firewall rules</strong> chọn <strong>Add</strong> như hình bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="733" src="https://vacif.com/wp-content/uploads/2026/03/image-29.png" alt="" class="wp-image-29088" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-tglf7"><div class="eb-parent-wrapper eb-parent-eb-text-tglf7 "><div class="eb-text-wrapper eb-text-tglf7" data-id="eb-text-tglf7"><p class="eb-text"><strong>Bước 3: </strong>Kiểm tra trạng thái VPN</p></div></div></div>



<ul class="wp-block-list">
<li>Vào mục<strong> Site to site -&gt; IPsec -&gt;</strong> Tick chọn <strong>Active</strong> và <strong>Connection </strong>để bắt đầu kết nối.</li>



<li>Từ máy tính đang ở trong <strong>LAN 100.100.100.0/24 </strong>ping đến máy tính trong<strong> LAN 200.200.200.0/24</strong> <strong>-&gt; ping thành công.</strong></li>



<li>Ngược lại, từ máy tính đang ở trong <strong>LAN 200.200.200.0/24</strong> ping đến máy tính trong <strong>LAN 100.100.100.0/24</strong> &#8211;<strong>&gt; ping thành công.</strong></li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="733" src="https://vacif.com/wp-content/uploads/2026/03/image-28.png" alt="" class="wp-image-29087" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-28-300x235.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-28-768x601.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="756" src="https://vacif.com/wp-content/uploads/2026/03/image-30.png" alt="" class="wp-image-29089" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x242.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x620.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="537" src="https://vacif.com/wp-content/uploads/2026/03/image-26.png" alt="" class="wp-image-29085" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x172.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x441.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-2-thiet-bi-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Theo Dõi &#038; Xuất Report Firewall Trên Sophos Central</title>
		<link>https://vacif.com/moi-nhat-2026-huong-dan-theo-doi-xuat-report-firewall-tren-sophos-central/</link>
					<comments>https://vacif.com/moi-nhat-2026-huong-dan-theo-doi-xuat-report-firewall-tren-sophos-central/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 05:03:46 +0000</pubDate>
				<category><![CDATA[Bảo mật]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[log in and report]]></category>
		<category><![CDATA[Sophos Central]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29054</guid>

					<description><![CDATA[Bài viết này nhằm: Qua đó, giúp hệ thống được giám sát hiệu quả và vận hành an toàn hơn. Sophos Central giúp quản trị viên theo dõi và quản lý toàn bộ Sophos Firewall ttrên một giao diện web duy nhất, không cần đăng nhập từng thiết bị. Để giám sát, theo dõi, xuất [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 h\u01b0\u1edbng d\u1eabn theo d\u00f5i &amp; xu\u1ea5t report Firewall tr\u00ean Sophos Central&quot;,&quot;text&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 h\u01b0\u1edbng d\u1eabn theo d\u00f5i &amp; xu\u1ea5t report Firewall tr\u00ean Sophos Central&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 h\u01b0\u1edbng d\u1eabn theo d\u00f5i &amp; xu\u1ea5t report Firewall tr\u00ean Sophos Central&quot;,&quot;value&quot;:&quot;ii-chi-ti\u1ebft-v\u1ec1-h\u01b0\u1edbng-d\u1eabn-theo-d\u00f5i-xu\u1ea5t-report-firewall-tr\u00ean-sophos-central&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Chi tiết về hướng dẫn theo dõi &amp; xuất report Firewall trên Sophos Central</a></ul></div></div></div></div></div>


<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="974" height="398" src="https://vacif.com/wp-content/uploads/2026/03/image-9.png" alt="" class="wp-image-29060" srcset="https://vacif.com/wp-content/uploads/2026/03/image-9.png 974w, https://vacif.com/wp-content/uploads/2026/03/image-9-300x123.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-9-768x314.png 768w" sizes="auto, (max-width: 974px) 100vw, 974px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này nhằm:</p>



<ul class="wp-block-list">
<li>Hướng dẫn cách theo dõi và lọc log Sophos Firewall trên Sophos Central.</li>



<li>Hướng dẫn xuất report phục vụ vận hành và báo cáo.</li>



<li>Giúp quản trị viên nhanh chóng phát hiện sự cố và mối đe dọa bảo mật.</li>
</ul>



<p>Qua đó, giúp hệ thống được giám sát hiệu quả và vận hành an toàn hơn.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Chi tiết về hướng dẫn theo dõi &amp; xuất report Firewall trên Sophos Central</span></h2></div></div></div>



<p>Sophos Central giúp quản trị viên theo dõi và quản lý toàn bộ Sophos Firewall ttrên một giao diện web duy nhất, không cần đăng nhập từng thiết bị. Để giám sát, theo dõi, xuất Report tổng quan các thiệt bị Firewall, làm như sau:</p>



<p>Trên Sophos Central, chọn My <strong>Products</strong> -&gt; <strong>Firewall Management</strong> -&gt; <strong>Report Generator</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="463" src="https://vacif.com/wp-content/uploads/2026/03/image-34.jpg" alt="" class="wp-image-29064" srcset="https://vacif.com/wp-content/uploads/2026/03/image-34.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-34-300x149.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-34-768x380.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Report Generator là công cụ để quản trị viên giám sát, theo dõi và tạo báo cáo (report) tùy chỉnh cho Sophos Firewall.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-35.jpg" alt="" class="wp-image-29063" srcset="https://vacif.com/wp-content/uploads/2026/03/image-35.jpg 934w, https://vacif.com/wp-content/uploads/2026/03/image-35-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-35-768x350.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-30qog"><div class="eb-parent-wrapper eb-parent-eb-text-30qog "><div class="eb-text-wrapper eb-text-30qog" data-id="eb-text-30qog"><p class="eb-text">Để theo dõi &amp; xuất Report cho Firwall được chỉ định &#8211; Trên <strong>Report Generator,</strong> chọn:</p></div></div></div>



<ul class="wp-block-list">
<li><strong>Firewalls</strong>: chọn Firewall cần xuất report.</li>



<li><strong>Report Template</strong>: Chọn Template có sẵn phù hợp với nhu cầu xem, chi tiết:
<ul class="wp-block-list">
<li><strong>Antivirus:</strong> Các mã độc hoặc đối tượng nghi ngờ đã bị chặn.</li>



<li><strong>Bandwidth usage:</strong> Mức sử dụng băng thông theo từng ứng dụng.</li>



<li><strong>Cloud app risks and usage:</strong> Các ứng dụng Cloud được sử dụng và rủi ro liên quan.</li>



<li><strong>Firewall:</strong> Số lượng kết nối giữa các địa chỉ IP cụ thể.</li>



<li><strong>IPS:</strong> Các cuộc tấn công bị phát hiện/chặn bởi hệ thống IPS.</li>



<li><strong>Log viewer and search:</strong> Log chi tiết của firewall (chỉ có biểu đồ dạng bảng).</li>



<li><strong>SD-WAN:</strong> Tóm tắt mức độ đáp ứng SLA theo từng profile SD-WAN, kèm biểu đồ xu hướng.</li>



<li><strong>SD-WAN SLA trend:</strong> Xu hướng SLA theo gateway (jitter, latency, packet loss).</li>



<li><strong>SD-WAN Bandwidth usage:</strong> Thống kê băng thông theo gateway và theo thời gian.</li>



<li><strong>Security posture assessment (SPA):</strong> Đánh giá tổng thể mức độ an toàn của hệ thống. (Có thể chọn tối đa 10 thành phần như: Bandwidth, Web usage, Threat geo activity…) (Recommend sử dụng)</li>



<li><strong>Synchronized app:</strong> Thống kê ứng dụng được nhận diện bởi Synchronized App Control.</li>



<li><strong>Threat geo activity:</strong> Các mối đe dọa bị chặn theo quốc gia.</li>



<li><strong>Threats and events blocked:</strong> Toàn bộ các mối đe dọa/sự kiện đã bị chặn.</li>



<li><strong>VPN usage:</strong> Mức độ sử dụng các kết nối VPN.</li>



<li><strong>Web usage:</strong> Thống kê truy cập website.</li>



<li><strong>Web user risk:</strong> Hoạt động web của người dùng truy cập website rủi ro cao.</li>



<li><strong>X-Ops:</strong> Hoạt động tấn công nâng cao (Advanced Threat activities) do firewall phát hiện/chặn. Bao gồm traffic trong MDR.</li>



<li><strong>Zero-day protection:</strong> File/email nghi ngờ được gửi đến module phân tích Sandstorm</li>
</ul>
</li>
</ul>



<ul class="wp-block-list">
<li><strong>Time Frame</strong>: Chọn mốc thời gian phù hợp với nhu cầu xem</li>



<li><strong>Query</strong>: Tùy chọn query phù hợp với nhu cầu lọc.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="484" src="https://vacif.com/wp-content/uploads/2026/03/image-33.jpg" alt="" class="wp-image-29062" srcset="https://vacif.com/wp-content/uploads/2026/03/image-33.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-33-300x155.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-33-768x398.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Sau đó, nhấn Schedule để lên lịch gửi report:</p>



<ul class="wp-block-list">
<li><strong>Template Name</strong>: Đặt tên của mẫu báo cáo.</li>



<li><strong>Export scheduling</strong>: Bật/Tắt việc xuất report tự động theo lịch.</li>



<li><strong>Time frame</strong>: Chọn khoảng thời gian dữ liệu trong mỗi report</li>



<li><strong>Export frequency</strong>: Chọn chu kỳ xuất báo cáo</li>



<li><strong>Export format</strong>: Chọn định xạng file xuất (PDF, CSV, HTML)</li>



<li><strong>Export notification / delivery</strong>: Chọn cách gửi email</li>



<li><strong>Send this export to other Sophos admins?:</strong> Chọn chia sẻ report cho các admin khác</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="485" src="https://vacif.com/wp-content/uploads/2026/03/image-11.png" alt="" class="wp-image-29067" srcset="https://vacif.com/wp-content/uploads/2026/03/image-11.png 936w, https://vacif.com/wp-content/uploads/2026/03/image-11-300x155.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-11-768x398.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Sau khi hoàn tất, Nhấn Save.</p>



<p>Thông báo hiển thị đã tạo Template và Schedule thành công</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="404" height="143" src="https://vacif.com/wp-content/uploads/2026/03/image-10.png" alt="" class="wp-image-29061" srcset="https://vacif.com/wp-content/uploads/2026/03/image-10.png 404w, https://vacif.com/wp-content/uploads/2026/03/image-10-300x106.png 300w" sizes="auto, (max-width: 404px) 100vw, 404px" /></figure>



<p>Đúng Schedule, Sophos sẽ tự động xuất file Export dựa trên cấu hình đã setup</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="482" src="https://vacif.com/wp-content/uploads/2026/03/image-36.jpg" alt="" class="wp-image-29065" srcset="https://vacif.com/wp-content/uploads/2026/03/image-36.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-36-300x155.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-36-768x396.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="440" src="https://vacif.com/wp-content/uploads/2026/03/image-37.jpg" alt="" class="wp-image-29066" srcset="https://vacif.com/wp-content/uploads/2026/03/image-37.jpg 934w, https://vacif.com/wp-content/uploads/2026/03/image-37-300x141.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-37-768x362.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-huong-dan-theo-doi-xuat-report-firewall-tren-sophos-central/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Cấu Hình VPN Site to Site Giữa Firewall Fortinet và Sophos Firewall Firmware V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Wed, 04 Mar 2026 05:41:35 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[Fortinet Firewall]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[Sophos Firewall Firmware V22]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=29017</guid>

					<description><![CDATA[Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet. Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;text&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;text&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;text&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;text&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;text&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;text&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;text&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;text&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-9&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;text&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;link&quot;:&quot;eb-table-content-10&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;text&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;text&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;link&quot;:&quot;eb-table-content-12&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;text&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;link&quot;:&quot;eb-table-content-13&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;text&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;link&quot;:&quot;eb-table-content-14&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;text&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;link&quot;:&quot;eb-table-content-15&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 b\u00e0i vi\u1ebft&quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-b\u00e0i-vi\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - S\u01a1 \u0111\u1ed3 m\u1ea1ng&quot;,&quot;value&quot;:&quot;ii-s\u01a1-\u0111\u1ed3-m\u1ea1ng&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - T\u00ecnh hu\u1ed1ng c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iii-t\u00ecnh-hu\u1ed1ng-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;IV - C\u00e1c b\u01b0\u1edbc c\u1ea5u h\u00ecnh&quot;,&quot;value&quot;:&quot;iv-c\u00e1c-b\u01b0\u1edbc-c\u1ea5u-h\u00ecnh&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;V - H\u01b0\u1edbng d\u1eabn c\u1ea5u h\u00ecnh VPN site to site gi\u1eefa Firewall Fortinet v\u00e0 Sophos Firewall Firmware V22 chi ti\u1ebft&quot;,&quot;value&quot;:&quot;v-h\u01b0\u1edbng-d\u1eabn-c\u1ea5u-h\u00ecnh-vpn-site-to-site-gi\u1eefa-firewall-fortinet-v\u00e0-sophos-firewall-firmware-v22-chi-ti\u1ebft&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Tr\u00ean thi\u1ebft b\u1ecb Fortinet:&quot;,&quot;value&quot;:&quot;1-tr\u00ean-thi\u1ebft-b\u1ecb-fortinet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.1 - T\u1ea1o VPN Tunnels&quot;,&quot;value&quot;:&quot;11-t\u1ea1o-vpn-tunnels&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.2 - T\u1ea1o Static Route&quot;,&quot;value&quot;:&quot;12-t\u1ea1o-static-route&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;1.3 - T\u1ea1o Firewall Policy&quot;,&quot;value&quot;:&quot;13-t\u1ea1o-firewall-policy&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2. Tr\u00ean thi\u1ebft b\u1ecb Sophos&quot;,&quot;value&quot;:&quot;2-tr\u00ean-thi\u1ebft-b\u1ecb-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.1 - T\u1ea1o subnet&quot;,&quot;value&quot;:&quot;21-t\u1ea1o-subnet&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.2 - T\u1ea1o IPSec Profile&quot;,&quot;value&quot;:&quot;22-t\u1ea1o-ipsec-profile&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.3 - T\u1ea1o IPSec Connection&quot;,&quot;value&quot;:&quot;23-t\u1ea1o-ipsec-connection&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;2.4 - T\u1ea1o Firewall Rule Sophos&quot;,&quot;value&quot;:&quot;24-t\u1ea1o-firewall-rule-sophos&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;3. Ki\u1ec3m tra k\u1ebft qu\u1ea3&quot;,&quot;value&quot;:&quot;3-ki\u1ec3m-tra-k\u1ebft-qu\u1ea3&quot;,&quot;isDelete&quot;:true},{&quot;label&quot;:&quot;* Ghi ch\u00fa &amp; L\u01b0u \u00fd tri\u1ec3n khai&quot;,&quot;value&quot;:&quot;ghi-ch\u00fa-l\u01b0u-\u00fd-tri\u1ec3n-khai&quot;,&quot;isDelete&quot;:true}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về bài viết</a><li><a href="#eb-table-content-1">II &#8211; Sơ đồ mạng</a><li><a href="#eb-table-content-2">III &#8211; Tình huống cấu hình</a><li><a href="#eb-table-content-3">IV &#8211; Các bước cấu hình</a><li><a href="#eb-table-content-4">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về bài viết</span></h2></div></div></div>



<p>Bài viết này hướng dẫn cách cấu hình IPSec VPN Site-to-Site giữa hai thiết bị tường lửa Fortinet Firewall và Sophos Firewall, nhằm kết nối an toàn các mạng LAN tại hai site khác nhau thông qua Internet.</p>



<p>Sau khi cấu hình hoàn tất, các lớp mạng LAN sau có thể kết nối và truy cập lẫn nhau:</p>



<ul class="wp-block-list">
<li>172.16.16.0/24 – Site A</li>



<li>10.10.10.0/24 – Site B</li>



<li>192.168.20.0/24 – Site B</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="366" src="https://vacif.com/wp-content/uploads/2026/03/image-8.png" alt="" class="wp-image-29019" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x127.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x325.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-mm8bi"><div class="eb-parent-wrapper eb-parent-eb-text-mm8bi "><div class="eb-text-wrapper eb-text-mm8bi" data-id="eb-text-mm8bi"><p class="eb-text">Giải thích sơ đồ mạng:</p></div></div></div>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site A – Fortinet Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào cổng WAN của thiết bị Fortinet</li>



<li>IP WAN: 192.168.1.2</li>



<li>Mạng LAN nội bộ: 172.16.16.0/24</li>



<li>LAN được cấu hình trên interface LAN của Fortinet</li>
</ul>



<p><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Site B – Sophos Firewall</strong></p>



<ul class="wp-block-list">
<li>Đường Internet được kết nối vào interface a (WAN) của Sophos Firewall</li>



<li>IP WAN: 192.168.1.3</li>



<li>Mạng LAN nội bộ gồm 2 lớp mạng: 10.10.10.0/24, 192.168.20.0/24</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-w4aye"><div class="eb-parent-wrapper eb-parent-eb-text-w4aye "><div class="eb-text-wrapper eb-text-w4aye" data-id="eb-text-w4aye"><p class="eb-text">Lưu ý sơ đồ:</p></div></div></div>



<ul class="wp-block-list">
<li>Kết nối VPN sử dụng IPSec Site-to-Site</li>



<li>Xác thực bằng Pre-shared Key</li>



<li>Sử dụng IKEv2</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8qbrk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8qbrk "><div class="eb-advance-heading-wrapper eb-advance-heading-8qbrk button-1 undefined" data-id="eb-advance-heading-8qbrk"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-jmoxo"><div class="eb-parent-wrapper eb-parent-eb-text-jmoxo "><div class="eb-text-wrapper eb-text-jmoxo" data-id="eb-text-jmoxo"><p class="eb-text">Chúng ta sẽ thực hiện cấu hình IPSec VPN Site-to-Site giữa:</p></div></div></div>



<ul class="wp-block-list">
<li>Fortinet (192.168.1.2)</li>



<li>Sophos (192.168.1.3)</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-oylnm"><div class="eb-parent-wrapper eb-parent-eb-text-oylnm "><div class="eb-text-wrapper eb-text-oylnm" data-id="eb-text-oylnm"><p class="eb-text">Mục tiêu:</p></div></div></div>



<p>Mạng LAN 172.16.16.0/24 (Fortinet) ⬄ Mạng LAN 10.10.10.0/24 và 192.168.20.0/24 (Sophos) có thể kết nối qua lại trực tiếp.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yq4nn"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yq4nn "><div class="eb-advance-heading-wrapper eb-advance-heading-yq4nn button-1 undefined" data-id="eb-advance-heading-yq4nn"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Các bước cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-queb7"><div class="eb-parent-wrapper eb-parent-eb-text-queb7 "><div class="eb-text-wrapper eb-text-queb7" data-id="eb-text-queb7"><p class="eb-text">Trên thiết bị Fortinet:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo VPN Tunnels</li>



<li>Tạo Static Route</li>



<li>Tạo Firewall Policy</li>
</ul>



<div class="wp-block-essential-blocks-text  root-eb-text-vlwq4"><div class="eb-parent-wrapper eb-parent-eb-text-vlwq4 "><div class="eb-text-wrapper eb-text-vlwq4" data-id="eb-text-vlwq4"><p class="eb-text">Trên thiết bị Sophos:</p></div></div></div>



<ul class="wp-block-list">
<li>Tạo subnet</li>



<li>Tạo IPSec Profile</li>



<li>Tạo IPSec Connection</li>



<li>Tạo Firewall Rule</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-76g77"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-76g77 "><div class="eb-advance-heading-wrapper eb-advance-heading-76g77 button-1 undefined" data-id="eb-advance-heading-76g77"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Hướng dẫn cấu hình VPN site to site giữa Firewall Fortinet và Sophos Firewall Firmware V22 chi tiết</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-hbhxd"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-hbhxd "><div class="eb-advance-heading-wrapper eb-advance-heading-hbhxd button-1 undefined" data-id="eb-advance-heading-hbhxd"><h2 class="eb-ah-title"><span class="first-title">1. Trên thiết bị Fortinet:</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wc297"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wc297 "><div class="eb-advance-heading-wrapper eb-advance-heading-wc297 button-1 undefined" data-id="eb-advance-heading-wc297"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Tạo VPN Tunnels</span></h2></div></div></div>



<p>Vào VPN → IPsec Tunnels → Create New → Custom</p>



<div class="wp-block-essential-blocks-text  root-eb-text-i1ir1"><div class="eb-parent-wrapper eb-parent-eb-text-i1ir1 "><div class="eb-text-wrapper eb-text-i1ir1" data-id="eb-text-i1ir1"><p class="eb-text">Bảng VPN Create Wizard</p></div></div></div>



<p>Name: S2S-LAB</p>



<p>Template Type: Custom</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg" alt="" class="wp-image-29020" srcset="https://vacif.com/wp-content/uploads/2026/03/image-16.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-16-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-16-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>Dùng Custom để chủ động cấu hình Phase 1 / Phase 2</p>



<div class="wp-block-essential-blocks-text  root-eb-text-xvm9r"><div class="eb-parent-wrapper eb-parent-eb-text-xvm9r "><div class="eb-text-wrapper eb-text-xvm9r" data-id="eb-text-xvm9r"><p class="eb-text">Bảng Network</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="746" height="709" src="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg" alt="" class="wp-image-29021" srcset="https://vacif.com/wp-content/uploads/2026/03/image-17.jpg 746w, https://vacif.com/wp-content/uploads/2026/03/image-17-300x285.jpg 300w" sizes="auto, (max-width: 746px) 100vw, 746px" /></figure>



<figure class="wp-block-table is-style-regular"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>IP Version</td><td>IPv4</td></tr><tr><td>Remote Gateway</td><td>Static IP Address</td></tr><tr><td>IP Address</td><td>192.168.1.3 (WAN Sophos)</td></tr><tr><td>Interface</td><td>WAN</td></tr><tr><td>Local Gateway</td><td>Không bật</td></tr><tr><td>Mode Config</td><td>Bỏ chọn</td></tr><tr><td>NAT Traversal</td><td>Disable</td></tr><tr><td>Dead Peer Detection</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-h7m6p"><div class="eb-parent-wrapper eb-parent-eb-text-h7m6p "><div class="eb-text-wrapper eb-text-h7m6p" data-id="eb-text-h7m6p"><p class="eb-text">&#8211; Disable NAT-T vì không NAT giữa 2 WAN<br>&#8211; Disable DPD để tránh reset tunnel trong lab</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-8oxg9"><div class="eb-parent-wrapper eb-parent-eb-text-8oxg9 "><div class="eb-text-wrapper eb-text-8oxg9" data-id="eb-text-8oxg9"><p class="eb-text">Bảng Authentication</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="735" height="331" src="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg" alt="" class="wp-image-29022" srcset="https://vacif.com/wp-content/uploads/2026/03/image-18.jpg 735w, https://vacif.com/wp-content/uploads/2026/03/image-18-300x135.jpg 300w" sizes="auto, (max-width: 735px) 100vw, 735px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Method</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>(ví dụ) FortiSophos@123</td></tr><tr><td>IKE Version</td><td>2</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-2qql7"><div class="eb-parent-wrapper eb-parent-eb-text-2qql7 "><div class="eb-text-wrapper eb-text-2qql7" data-id="eb-text-2qql7"><p class="eb-text">&#8211; PSK phải giống 100% bên Sophos</p></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-11jdu"><div class="eb-parent-wrapper eb-parent-eb-text-11jdu "><div class="eb-text-wrapper eb-text-11jdu" data-id="eb-text-11jdu"><p class="eb-text">Phase 1 Proposal</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="757" height="376" src="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg" alt="" class="wp-image-29023" srcset="https://vacif.com/wp-content/uploads/2026/03/image-19.jpg 757w, https://vacif.com/wp-content/uploads/2026/03/image-19-300x149.jpg 300w" sizes="auto, (max-width: 757px) 100vw, 757px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>28800</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6r9aw"><div class="eb-parent-wrapper eb-parent-eb-text-6r9aw "><div class="eb-text-wrapper eb-text-6r9aw" data-id="eb-text-6r9aw"><p class="eb-text">Phase 2 Selectors</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="578" height="714" src="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg" alt="" class="wp-image-29032" srcset="https://vacif.com/wp-content/uploads/2026/03/image-28.jpg 578w, https://vacif.com/wp-content/uploads/2026/03/image-28-243x300.jpg 243w" sizes="auto, (max-width: 578px) 100vw, 578px" /></figure>



<p><strong>Selector 1</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 10.10.10.0/24</li>
</ul>



<p><strong>Selector 2</strong></p>



<ul class="wp-block-list">
<li>Local Address: 172.16.16.0/24</li>



<li>Remote Address: 192.168.20.0/24</li>
</ul>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>Diffie-Hellman Group</td><td>14</td></tr><tr><td>Key Lifetime</td><td>43200</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-4mf91"><div class="eb-parent-wrapper eb-parent-eb-text-4mf91 "><div class="eb-text-wrapper eb-text-4mf91" data-id="eb-text-4mf91"><p class="eb-text">&#8211; Mỗi subnet Sophos cần 1 Phase 2<br>&#8211; Nếu gộp → tunnel UP nhưng không có traffic</p></div></div></div>



<p>Nhấn OK để tạo VPN Tunnel.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ljz9a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ljz9a "><div class="eb-advance-heading-wrapper eb-advance-heading-ljz9a button-1 undefined" data-id="eb-advance-heading-ljz9a"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Tạo Static Route</span></h2></div></div></div>



<p>Vào Network → Static Routes → Create New</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg" alt="" class="wp-image-29027" srcset="https://vacif.com/wp-content/uploads/2026/03/image-22.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-22-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-22-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p></p>



<div class="wp-block-essential-blocks-text  root-eb-text-i0llt"><div class="eb-parent-wrapper eb-parent-eb-text-i0llt "><div class="eb-text-wrapper eb-text-i0llt" data-id="eb-text-i0llt"><p class="eb-text">Route 1</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>10.10.10.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-t16sq"><div class="eb-parent-wrapper eb-parent-eb-text-t16sq "><div class="eb-text-wrapper eb-text-t16sq" data-id="eb-text-t16sq"><p class="eb-text">Route 2</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg" alt="" class="wp-image-29026" srcset="https://vacif.com/wp-content/uploads/2026/03/image-23.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-23-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-23-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Destination</td><td>192.168.20.0/24</td></tr><tr><td>Interface</td><td>S2S-LAB</td></tr><tr><td>Gateway</td><td>0.0.0.0</td></tr><tr><td>Status</td><td>Enable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-175x1"><div class="eb-parent-wrapper eb-parent-eb-text-175x1 "><div class="eb-text-wrapper eb-text-175x1" data-id="eb-text-175x1"><p class="eb-text">&#8211; Nếu thiếu static route → ping không bao giờ đi vào VPN</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-siaef"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-siaef "><div class="eb-advance-heading-wrapper eb-advance-heading-siaef button-1 undefined" data-id="eb-advance-heading-siaef"><h2 class="eb-ah-title"><span class="first-title"><a>1.3</a> &#8211; Tạo Firewall Policy</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-k0mcg"><div class="eb-parent-wrapper eb-parent-eb-text-k0mcg "><div class="eb-text-wrapper eb-text-k0mcg" data-id="eb-text-k0mcg"><p class="eb-text">Policy 1 – LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg" alt="" class="wp-image-29030" srcset="https://vacif.com/wp-content/uploads/2026/03/image-26.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-26-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-26-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>LAN</td></tr><tr><td>Outgoing Interface</td><td>S2S-LAB</td></tr><tr><td>Source</td><td>172.16.16.0/24</td></tr><tr><td>Destination</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr><tr><td>NAT</td><td>Disable</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-04oaf"><div class="eb-parent-wrapper eb-parent-eb-text-04oaf "><div class="eb-text-wrapper eb-text-04oaf" data-id="eb-text-04oaf"><p class="eb-text">Policy 2 – VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="395" src="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg" alt="" class="wp-image-29031" srcset="https://vacif.com/wp-content/uploads/2026/03/image-27.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-27-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-27-768x351.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Incoming Interface</td><td>S2S-LAB</td></tr><tr><td>Outgoing Interface</td><td>LAN</td></tr><tr><td>Source</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination</td><td>172.16.16.0/24</td></tr><tr><td>Service</td><td>ALL</td></tr><tr><td>Action</td><td>ACCEPT</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-i77g3"><div class="eb-parent-wrapper eb-parent-eb-text-i77g3 "><div class="eb-text-wrapper eb-text-i77g3" data-id="eb-text-i77g3"><p class="eb-text">&#8211; Policy VPN phải nằm trên policy Internet</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qh3q2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qh3q2 "><div class="eb-advance-heading-wrapper eb-advance-heading-qh3q2 button-1 undefined" data-id="eb-advance-heading-qh3q2"><h2 class="eb-ah-title"><span class="first-title"><a>2. </a>Trên thiết bị Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a7f6u"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a7f6u "><div class="eb-advance-heading-wrapper eb-advance-heading-a7f6u button-1 undefined" data-id="eb-advance-heading-a7f6u"><h2 class="eb-ah-title"><span class="first-title">2.1 &#8211; Tạo subnet</span></h2></div></div></div>



<p>Vào Hosts and Services → Add</p>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tên</strong></th><th><strong>Loại</strong></th><th><strong>Thông số</strong></th></tr></thead><tbody><tr><td>LAN_SOPHOS_10</td><td>Network</td><td>IP: 10.10.10.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_SOPHOS_20</td><td>Network</td><td>IP: 192.168.20.0 / Subnet: 255.255.255.0</td></tr><tr><td>LAN_FORTI</td><td>Network</td><td>IP: 172.16.16.0 / Subnet: 255.255.255.0</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bkx0m"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bkx0m "><div class="eb-advance-heading-wrapper eb-advance-heading-bkx0m button-1 undefined" data-id="eb-advance-heading-bkx0m"><h2 class="eb-ah-title"><span class="first-title">2.2 &#8211; Tạo IPSec Profile</span></h2></div></div></div>



<p>Vào SYSTEM &gt; Profiles → IPsec Profiles → Add</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg" alt="" class="wp-image-29024" srcset="https://vacif.com/wp-content/uploads/2026/03/image-20.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-20-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-20-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>Fortinet-Vacif</td></tr><tr><td>IKE Version</td><td>IKEv2</td></tr><tr><td>Encryption</td><td>AES256</td></tr><tr><td>Authentication</td><td>SHA256</td></tr><tr><td>DH Group</td><td>14</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-x0jn2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-x0jn2 "><div class="eb-advance-heading-wrapper eb-advance-heading-x0jn2 button-1 undefined" data-id="eb-advance-heading-x0jn2"><h2 class="eb-ah-title"><span class="first-title">2.3 &#8211; Tạo IPSec Connection</span></h2></div></div></div>



<p>Vào CONFIGURE → Site-to-site VPN → &nbsp;IPsec → Add</p>



<div class="wp-block-essential-blocks-text  root-eb-text-b8zwg"><div class="eb-parent-wrapper eb-parent-eb-text-b8zwg "><div class="eb-text-wrapper eb-text-b8zwg" data-id="eb-text-b8zwg"><p class="eb-text">General Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg" alt="" class="wp-image-29025" srcset="https://vacif.com/wp-content/uploads/2026/03/image-21.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-21-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-21-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Name</td><td>VPN_SOPHOS_VACIF</td></tr><tr><td>Connection Type</td><td>Policy-based</td></tr><tr><td>Gateway Type</td><td>Initiate the connection</td></tr><tr><td>Create firewall rule</td><td>Không chọn (tạo thủ công)</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-86g8b"><div class="eb-parent-wrapper eb-parent-eb-text-86g8b "><div class="eb-text-wrapper eb-text-86g8b" data-id="eb-text-86g8b"><p class="eb-text">Authentication</p></div></div></div>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Profile</td><td>Fortinet Vacif ( tạo ở bước trên )</td></tr><tr><td>Authentication Type&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td><td>Pre-shared Key</td></tr><tr><td>Pre-shared Key</td><td>FortiSophos@123</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-6opfg"><div class="eb-parent-wrapper eb-parent-eb-text-6opfg "><div class="eb-text-wrapper eb-text-6opfg" data-id="eb-text-6opfg"><p class="eb-text">Gateway Settings</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg" alt="" class="wp-image-29033" srcset="https://vacif.com/wp-content/uploads/2026/03/image-29.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-29-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-29-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<ul class="wp-block-list">
<li>Listening interface: Port 2 – 192.168.1.3</li>



<li>Gateway address: 192.168.1.2 (WAN Fortinet)</li>



<li>Local Subnet: 10.10.10.0/24 , 192.168.20.0/24</li>



<li>Remote Subnet: 172.16.16.0/24</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2dz5o"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2dz5o "><div class="eb-advance-heading-wrapper eb-advance-heading-2dz5o button-1 undefined" data-id="eb-advance-heading-2dz5o"><h2 class="eb-ah-title"><span class="first-title"><a>2.4</a> &#8211; Tạo Firewall Rule Sophos</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-069m1"><div class="eb-parent-wrapper eb-parent-eb-text-069m1 "><div class="eb-text-wrapper eb-text-069m1" data-id="eb-text-069m1"><p class="eb-text">LAN → VPN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg" alt="" class="wp-image-29028" srcset="https://vacif.com/wp-content/uploads/2026/03/image-25.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-25-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-25-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>LAN</td></tr><tr><td>Destination Zone</td><td>VPN</td></tr><tr><td>Source Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Destination Network</td><td>172.16.16.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-text  root-eb-text-0pm0n"><div class="eb-parent-wrapper eb-parent-eb-text-0pm0n "><div class="eb-text-wrapper eb-text-0pm0n" data-id="eb-text-0pm0n"><p class="eb-text">VPN → LAN</p></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="426" src="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg" alt="" class="wp-image-29029" srcset="https://vacif.com/wp-content/uploads/2026/03/image-24.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-24-300x148.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-24-768x379.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<figure class="wp-block-table"><table class="has-background has-fixed-layout" style="background-color:#f0f0f0"><thead><tr><th><strong>Tham số</strong></th><th><strong>Giá trị</strong></th></tr></thead><tbody><tr><td>Source Zone</td><td>VPN</td></tr><tr><td>Destination Zone</td><td>LAN</td></tr><tr><td>Source Network</td><td>172.16.16.0/24</td></tr><tr><td>Destination Network</td><td>10.10.10.0/24, 192.168.20.0/24</td></tr><tr><td>Action</td><td>Allow</td></tr></tbody></table></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeg05"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeg05 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeg05 button-1 undefined" data-id="eb-advance-heading-qeg05"><h2 class="eb-ah-title"><span class="first-title"><a>3</a>. Kiểm tra kết quả</span></h2></div></div></div>



<p><strong>Sophos:</strong> VPN → IPsec Connections → Status: <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f7e2.png" alt="🟢" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Connected</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg" alt="" class="wp-image-29034" srcset="https://vacif.com/wp-content/uploads/2026/03/image-30.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-30-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-30-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Fortinet:</strong> Monitor → IPsec Monitor → Tunnel: UP (Có Incoming / Outgoing Data)</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg" alt="" class="wp-image-29035" srcset="https://vacif.com/wp-content/uploads/2026/03/image-31.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-31-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-31-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p><strong>Test:</strong></p>



<ul class="wp-block-list">
<li>172.16.16.x → 10.10.10.x</li>



<li>172.16.16.x → 192.168.20.x</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="454" src="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg" alt="" class="wp-image-29036" srcset="https://vacif.com/wp-content/uploads/2026/03/image-32.jpg 864w, https://vacif.com/wp-content/uploads/2026/03/image-32-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-32-768x404.jpg 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-iq8fr"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-iq8fr "><div class="eb-advance-heading-wrapper eb-advance-heading-iq8fr button-1 undefined" data-id="eb-advance-heading-iq8fr"><h2 class="eb-ah-title"><span class="first-title">* Ghi chú &amp; Lưu ý triển khai</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đảm bảo thời gian hệ thống đồng bộ (NTP) để tránh lỗi IKEv2 do lệch thời gian.</li>



<li>PSK, thuật toán mã hóa và nhóm DH phải trùng khớp 2 đầu – sai khác sẽ khiến Phase 1/2 thất bại.</li>



<li>Tắt NAT trên policy đi vào VPN; bật NAT sẽ làm sai nguồn và gói tin không match selector.</li>



<li>Mỗi cặp Local/Remote subnet cần 1 selector (Phase 2). Không gộp nhiều subnet nếu thiết bị không hỗ trợ.</li>



<li>Nếu tunnel UP nhưng không ping được, kiểm tra: Static Route, Policy thứ tự, và bảng ARP/Route trên hai đầu.</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-cau-hinh-vpn-site-to-site-giua-firewall-fortinet-va-sophos-firewall-firmware-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới nhất 2026] Sophos Firewall: Hướng Dẫn Theo Dõi &#038; Xuất Report Từ Sophos Firewall V22</title>
		<link>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-theo-doi-xuat-report-tu-sophos-firewall-v22/</link>
					<comments>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-theo-doi-xuat-report-tu-sophos-firewall-v22/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Tue, 03 Mar 2026 09:20:47 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[log and report]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<category><![CDATA[sophos firewall v22]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=28977</guid>

					<description><![CDATA[Bài viết này nhằm: Qua đó, giúp hệ thống được giám sát hiệu quả và vận hành an toàn hơn. Xem thông tin về lưu lượng mạng đi qua firewall và các mối đe dọa bảo mật Các loại Dashboard chính: Xem thông tin về việc sử dụng ứng dụng và Internet trên hệ thống [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="974" height="287" src="https://vacif.com/wp-content/uploads/2026/03/image.png" alt="" class="wp-image-28978" srcset="https://vacif.com/wp-content/uploads/2026/03/image.png 974w, https://vacif.com/wp-content/uploads/2026/03/image-300x88.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-768x226.png 768w" sizes="auto, (max-width: 974px) 100vw, 974px" /></figure>


<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22 &quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22 &quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22&quot;,&quot;text&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22&quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. Gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng Report &amp; Log c\u1ee7a Sophos Firewall&quot;,&quot;text&quot;:&quot;1. Gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng Report &amp; Log c\u1ee7a Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.1 - Dashboards&quot;,&quot;text&quot;:&quot;1.1 - Dashboards&quot;,&quot;link&quot;:&quot;11-dashboards&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.2 - Application &amp; Webs&quot;,&quot;text&quot;:&quot;1.2 - Application &amp; Webs&quot;,&quot;link&quot;:&quot;12-application-webs&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.3 - Networks &amp; Threat&quot;,&quot;text&quot;:&quot;1.3 - Networks &amp; Threat&quot;,&quot;link&quot;:&quot;13-networks-threat&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.4 - VPN&quot;,&quot;text&quot;:&quot;1.4 - VPN&quot;,&quot;link&quot;:&quot;14-vpn&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.5 - Email&quot;,&quot;text&quot;:&quot;1.5 - Email&quot;,&quot;link&quot;:&quot;15-email&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.6 - Compliance&quot;,&quot;text&quot;:&quot;1.6 - Compliance&quot;,&quot;link&quot;:&quot;16-compliance&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.7 - Custom&quot;,&quot;text&quot;:&quot;1.7 - Custom&quot;,&quot;link&quot;:&quot;17-custom&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1.8 - Log Viewer&quot;,&quot;text&quot;:&quot;1.8 - Log Viewer&quot;,&quot;link&quot;:&quot;18-log-viewer&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. C\u00e1ch xu\u1ea5t Report tr\u00ean Sophos Firewall&quot;,&quot;text&quot;:&quot;2. C\u00e1ch xu\u1ea5t Report tr\u00ean Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-11&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22 &quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-theo-d\u00f5i-v\u00e0-xu\u1ea5t-report-t\u1eeb-sophos-firewall-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - Chi ti\u1ebft v\u1ec1 theo d\u00f5i v\u00e0 xu\u1ea5t report t\u1eeb Sophos Firewall V22&quot;,&quot;value&quot;:&quot;ii-chi-ti\u1ebft-v\u1ec1-theo-d\u00f5i-v\u00e0-xu\u1ea5t-report-t\u1eeb-sophos-firewall-v22&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. Gi\u1edbi thi\u1ec7u t\u00ednh n\u0103ng Report &amp; Log c\u1ee7a Sophos Firewall&quot;,&quot;value&quot;:&quot;1-gi\u1edbi-thi\u1ec7u-t\u00ednh-n\u0103ng-report-log-c\u1ee7a-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.1 - Dashboards&quot;,&quot;value&quot;:&quot;11-dashboards&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.2 - Application &amp; Webs&quot;,&quot;value&quot;:&quot;12-application-webs&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.3 - Networks &amp; Threat&quot;,&quot;value&quot;:&quot;13-networks-threat&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.4 - VPN&quot;,&quot;value&quot;:&quot;14-vpn&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.5 - Email&quot;,&quot;value&quot;:&quot;15-email&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.6 - Compliance&quot;,&quot;value&quot;:&quot;16-compliance&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.7 - Custom&quot;,&quot;value&quot;:&quot;17-custom&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1.8 - Log Viewer&quot;,&quot;value&quot;:&quot;18-log-viewer&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. C\u00e1ch xu\u1ea5t Report tr\u00ean Sophos Firewall&quot;,&quot;value&quot;:&quot;2-c\u00e1ch-xu\u1ea5t-report-tr\u00ean-sophos-firewall&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về theo dõi và xuất report từ Sophos Firewall V22 </a><li><a href="#eb-table-content-1">II &#8211; Chi tiết về theo dõi và xuất report từ Sophos Firewall V22</a><li><a href="#eb-table-content-2">1. Giới thiệu tính năng Report &amp; Log của Sophos Firewall</a><li><a href="#11-dashboards">1.1 &#8211; Dashboards</a><li><a href="#12-application-webs">1.2 &#8211; Application &amp; Webs</a><li><a href="#13-networks-threat">1.3 &#8211; Networks &amp; Threat</a><li><a href="#14-vpn">1.4 &#8211; VPN</a><li><a href="#15-email">1.5 &#8211; Email</a><li><a href="#16-compliance">1.6 &#8211; Compliance</a><li><a href="#17-custom">1.7 &#8211; Custom</a><li><a href="#18-log-viewer">1.8 &#8211; Log Viewer</a><li><a href="#eb-table-content-11">2. Cách xuất Report trên Sophos Firewall</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về theo dõi và xuất report từ Sophos Firewall V22 </span></h2></div></div></div>



<p>Bài viết này nhằm:</p>



<ul class="wp-block-list">
<li>Hướng dẫn cách xem và lọc log trên Sophos Firewall.</li>



<li>Hướng dẫn đọc và xuất report phục vụ vận hành và báo cáo.</li>



<li>Giúp quản trị viên nhanh chóng phát hiện sự cố và mối đe dọa bảo mật.</li>
</ul>



<p>Qua đó, giúp hệ thống được giám sát hiệu quả và vận hành an toàn hơn.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5y1xh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5y1xh "><div class="eb-advance-heading-wrapper eb-advance-heading-5y1xh button-1 undefined" data-id="eb-advance-heading-5y1xh"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Chi tiết về theo dõi và xuất report từ Sophos Firewall V22</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Giới thiệu tính năng Report &amp; Log của Sophos Firewall</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-lo7kj"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-lo7kj "><div class="eb-advance-heading-wrapper eb-advance-heading-lo7kj button-1 undefined" data-id="eb-advance-heading-lo7kj"><h2 class="eb-ah-title"><span class="first-title">1.1 &#8211; Dashboards</span></h2></div></div></div>



<p>Xem thông tin về lưu lượng mạng đi qua firewall và các mối đe dọa bảo mật<strong></strong><strong></strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="974" height="463" src="https://vacif.com/wp-content/uploads/2026/03/image-1.png" alt="" class="wp-image-28979" srcset="https://vacif.com/wp-content/uploads/2026/03/image-1.png 974w, https://vacif.com/wp-content/uploads/2026/03/image-1-300x143.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-1-768x365.png 768w" sizes="auto, (max-width: 974px) 100vw, 974px" /></figure>



<p><strong>Các loại Dashboard chính:</strong></p>



<ul class="wp-block-list">
<li><strong>Traffic dashboard</strong>: Phân loại theo lưu lượng mạng</li>



<li><strong>Security dashboard</strong>:&nbsp; Hoạt động bị chặn và các mối đe dọa: Malware, IPS, Spam, nguồn tấn công.</li>



<li><strong>Executive report</strong>: Thông tin tổng hợp cho người quản lý: Traffic &amp; Threat nổi bật.</li>



<li><strong>User threat quotient (UTQ):</strong> Xếp hạng người dùng dựa trên điểm rủi ro bảo mật.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-z9r4w"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-z9r4w "><div class="eb-advance-heading-wrapper eb-advance-heading-z9r4w button-1 undefined" data-id="eb-advance-heading-z9r4w"><h2 class="eb-ah-title"><span class="first-title">1.2 &#8211; Application &amp; Webs</span></h2></div></div></div>



<p>Xem thông tin về việc sử dụng ứng dụng và Internet trên hệ thống mạng của bạn.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="445" src="https://vacif.com/wp-content/uploads/2026/03/image-3.jpg" alt="" class="wp-image-28981" srcset="https://vacif.com/wp-content/uploads/2026/03/image-3.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-3-300x143.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-3-768x366.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p><strong>Application risk meter</strong> là cách thức mà Firewall sẽ tính điểm dựa trên mức độ rủi ro và số lần truy cập (hits) của từng ứng dụng. Chỉ số rủi ro ứng dụng được xác định dựa trên điểm trung bình của toàn bộ lưu lượng ứng dụng</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="273" height="75" src="https://vacif.com/wp-content/uploads/2026/03/image-2.png" alt="" class="wp-image-28982" style="aspect-ratio:3.6400133824021412;width:336px;height:auto"/></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>User app risks &amp; usage</strong>: Thống kê việc sử dụng các ứng dụng và mức độ rủi ro tương ứng.</li>



<li><strong>Cloud applications usage</strong>: Thống kê việc sử dụng các ứng dụng đám mây</li>



<li><strong>Blocked user apps</strong>: Các lần truy cập ứng dụng bị chặn.</li>



<li><strong>Synchronized applications</strong>: Các ứng dụng được phân loại và đồng bộ từ endpoint lên firewall.</li>



<li><strong>Web risks &amp; usage</strong>: Hoạt động truy cập web trong mạng và các rủi ro liên quan.</li>



<li><strong>Blocked web attempts</strong>: Các lần truy cập web bị chặn</li>



<li><strong>Search engine</strong>: Thống kê hành vi tìm kiếm của người dùn</li>



<li><strong>Web content</strong>: Các kết quả khớp của bộ lọc nội dung và các thông tin liên quan.</li>



<li><strong>Web server usage</strong>: Lưu lượng Application, Web, Internet và FTP.</li>



<li><strong>Web server protection</strong>: Trạng thái bảo mật của các Web Server, bao gồm các cuộc tấn công và nguồn tấn công.</li>



<li><strong>User data transfer</strong>: User traffic</li>



<li><strong>FTP usage</strong>: FTP activity</li>



<li><strong>FTP protection</strong>: Malicious FTP activity</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-01ner"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-01ner "><div class="eb-advance-heading-wrapper eb-advance-heading-01ner button-1 undefined" data-id="eb-advance-heading-01ner"><h2 class="eb-ah-title"><span class="first-title">1.3 &#8211; Networks &amp; Threat</span></h2></div></div></div>



<p>Xem thông tin về việc sử dụng mạng và các mối đe dọa liên quan.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="443" src="https://vacif.com/wp-content/uploads/2026/03/image-4.jpg" alt="" class="wp-image-28983" srcset="https://vacif.com/wp-content/uploads/2026/03/image-4.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-4-300x142.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-4-768x364.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Intrusion attacks</strong>: Các lượt tấn công</li>



<li><strong>Active threat response</strong>: Threat events và các máy bị xâm nhập được phát hiện bởi MDR (Managed Detection and Response) và Sophos X-Ops</li>



<li><strong>Wireless</strong>: Access point và SSID được sử dụng</li>



<li><strong>Security Heartbeat</strong>: Tình trạng sức khỏe của máy trạm trong mạng dựa trên kết nối giữa máy trạm và Firewall.</li>



<li><strong>Zero-day protection</strong>: Bảo vệ nâng cao trước các cuộc tấn công mới.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-2x5jk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-2x5jk "><div class="eb-advance-heading-wrapper eb-advance-heading-2x5jk button-1 undefined" data-id="eb-advance-heading-2x5jk"><h2 class="eb-ah-title"><span class="first-title">1.4 &#8211; VPN</span></h2></div></div></div>



<p>Xem thông tin về remote user (người dùng kết nối từ xa) vào hệ thống mạng của bạn thông qua IPSEC VPN, SSL VPN và Clientless access</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="450" src="https://vacif.com/wp-content/uploads/2026/03/image-5.jpg" alt="" class="wp-image-28984" srcset="https://vacif.com/wp-content/uploads/2026/03/image-5.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-5-300x144.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-5-768x370.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>VPN</strong>: Lưu lượng phát sinh từ remote users qua IPsec, L2TP hoặc PPTP</li>



<li><strong>SSL VPN</strong>: Lưu lượng phát sinh từ remote users thông qua SSL VPN Client.</li>



<li><strong>Clientless Access</strong>: Lưu lượng phát sinh từ remote users thông qua trình duyệt web.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-dlae4"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-dlae4 "><div class="eb-advance-heading-wrapper eb-advance-heading-dlae4 button-1 undefined" data-id="eb-advance-heading-dlae4"><h2 class="eb-ah-title"><span class="first-title">1.5 &#8211; Email</span></h2></div></div></div>



<p>Xem thông tin về email traffic (lưu lượng email) trong hệ thống mạng</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="445" src="https://vacif.com/wp-content/uploads/2026/03/image-6.jpg" alt="" class="wp-image-28985" srcset="https://vacif.com/wp-content/uploads/2026/03/image-6.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-6-300x143.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-6-768x365.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Các nhóm <strong>Setting</strong> có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Email Usage</strong>: Email traffic trong hệ thống mạng của mình</li>



<li><strong>Email Protection</strong>: Email Traffic bị Virus và Spam trong hệ thống mạng của mình</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-kgyit"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-kgyit "><div class="eb-advance-heading-wrapper eb-advance-heading-kgyit button-1 undefined" data-id="eb-advance-heading-kgyit"><h2 class="eb-ah-title"><span class="first-title">1.6 &#8211; Compliance</span></h2></div></div></div>



<p>Xem thông tin về việc tuân thủ các quy định/quy chuẩn:</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="446" src="https://vacif.com/wp-content/uploads/2026/03/image-7.jpg" alt="" class="wp-image-28986" srcset="https://vacif.com/wp-content/uploads/2026/03/image-7.jpg 934w, https://vacif.com/wp-content/uploads/2026/03/image-7-300x143.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-7-768x367.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></figure>



<p>Các nhóm Quy chuẩn có thể theo dõi trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>HIPAA</strong>: Security Report tuân thủ chuẩn HIPAA</li>



<li><strong>GLBA:</strong> Security Report tuân thủ chuẩn GLBA</li>



<li><strong>SOX</strong>: Security Report tuân thủ chuẩn SOX</li>



<li><strong>FISMA</strong>: Security Report tuân thủ chuẩn FISMA</li>



<li><strong>PCI</strong>: Security Report tuân thủ chuẩn PCI</li>



<li><strong>NERC CIP v3</strong>: Security Report tuân thủ chuẩn NERC CIP v3</li>



<li><strong>CIPA</strong>: Security Report tuân thủ chuẩn CIPA</li>



<li><strong>Events</strong>: Network Event và các mức độ nghiêm trọng tương ứng</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4fdmh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4fdmh "><div class="eb-advance-heading-wrapper eb-advance-heading-4fdmh button-1 undefined" data-id="eb-advance-heading-4fdmh"><h2 class="eb-ah-title"><span class="first-title">1.7 &#8211; Custom</span></h2></div></div></div>



<p>Tạo báo cáo bao gồm các tiêu chí được chỉ định.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="443" src="https://vacif.com/wp-content/uploads/2026/03/image-8.jpg" alt="" class="wp-image-28987" srcset="https://vacif.com/wp-content/uploads/2026/03/image-8.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-8-300x142.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-8-768x364.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Các loại <strong>Report</strong> có thể tạo trong phần này, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Web Report</strong>: Tìm kiếm hoạt động duyệt web hoặc virus. Có thể lọc theo user, domain và các tiêu chí khác</li>



<li><strong>Mail Report</strong>: Tìm kiếm lưu lượng Email, Spam và Virus. Có thể lọc theo protocol, user và các tiêu chí khác.</li>



<li><strong>FTP Report</strong>: Tìm kiếm hoạt động FTP và Virus. Có thể lọc theo kiểu truyền, user, file hoặc source IP</li>



<li><strong>User Report</strong>: Thống kê mức độ sử dụng: ứng dụng rủi ro cao, website không hiệu quả, virus phát hiện. Có thể lọc theo username, source host.</li>



<li><strong>Web Server Report</strong>: Tìm kiếm hoạt động Web Server (time, user, URI) và cả các sự kiện bảo vệ Web Server.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wsam0"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wsam0 "><div class="eb-advance-heading-wrapper eb-advance-heading-wsam0 button-1 undefined" data-id="eb-advance-heading-wsam0"><h2 class="eb-ah-title"><span class="first-title">1.8 &#8211; Log Viewer</span></h2></div></div></div>



<p>Log Viewer hiển thị event logs và được tự động cập nhật khi có event mới (Real-time).</p>



<p>Để truy cập, ở góc phải phía trên Sophos Firewall, nhấn Log viewer</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="130" src="https://vacif.com/wp-content/uploads/2026/03/image-10.jpg" alt="" class="wp-image-28990" srcset="https://vacif.com/wp-content/uploads/2026/03/image-10.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-10-300x42.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-10-768x107.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Cửa sổ Log Viewer mới sẽ xuất hiện, và quản trị viên có thể xem log Realtime ở đây</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="552" src="https://vacif.com/wp-content/uploads/2026/03/image-9.jpg" alt="" class="wp-image-28989" srcset="https://vacif.com/wp-content/uploads/2026/03/image-9.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-9-300x177.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-9-768x453.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Quản trị viên có thể tùy chọn các loại log cụ thể để giám sát như sau:</p>



<ul class="wp-block-list">
<li>Admin</li>



<li>Active Threat Response</li>



<li>Application filter</li>



<li>Authentication</li>



<li>Email</li>



<li>Firewall</li>



<li>IPS</li>



<li>Malware</li>



<li>Security Heartbeat</li>



<li>SSL/TLS inspection</li>



<li>SD-WAN</li>



<li>System</li>



<li>VPN</li>



<li>Web content policy</li>



<li>Web filter</li>



<li>Web server protection</li>



<li>Zero-day protection</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="200" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-3.png" alt="" class="wp-image-28988" srcset="https://vacif.com/wp-content/uploads/2026/03/image-3.png 200w, https://vacif.com/wp-content/uploads/2026/03/image-3-151x300.png 151w" sizes="auto, (max-width: 200px) 100vw, 200px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-mw44a"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-mw44a "><div class="eb-advance-heading-wrapper eb-advance-heading-mw44a button-1 undefined" data-id="eb-advance-heading-mw44a"><h2 class="eb-ah-title"><span class="first-title">2. Cách xuất Report trên Sophos Firewall</span></h2></div></div></div>



<p>Trong quá trình quản trị hệ thống, người quản trị cần các file báo cáo tổng hợp phản ánh tình trạng sử dụng hệ thống và các mối đe dọa tiêu biểu. Vì vậy, trong bài hướng dẫn này sẽ lựa chọn <strong>Executive report</strong> để thực hiện việc xuất báo cáo.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="490" src="https://vacif.com/wp-content/uploads/2026/03/image-12.jpg" alt="" class="wp-image-28992" srcset="https://vacif.com/wp-content/uploads/2026/03/image-12.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-12-300x157.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-12-768x402.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>&nbsp;Để xuất Report báo cáo theo lịch trình, chọn <strong>Show Reports Settings</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="936" height="483" src="https://vacif.com/wp-content/uploads/2026/03/image-11.jpg" alt="" class="wp-image-28991" srcset="https://vacif.com/wp-content/uploads/2026/03/image-11.jpg 936w, https://vacif.com/wp-content/uploads/2026/03/image-11-300x155.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-11-768x396.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>



<p>Chọn <strong>Report Scheduling</strong>, nhấn <strong>Add</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="935" height="491" src="https://vacif.com/wp-content/uploads/2026/03/image-13.jpg" alt="" class="wp-image-28993" srcset="https://vacif.com/wp-content/uploads/2026/03/image-13.jpg 935w, https://vacif.com/wp-content/uploads/2026/03/image-13-300x158.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-13-768x403.jpg 768w" sizes="auto, (max-width: 935px) 100vw, 935px" /></figure>



<p>Nhập thông tin sau:</p>



<ul class="wp-block-list">
<li><strong>Name:</strong> Đặt tên lịch report.</li>



<li><strong>Description:</strong> Mô tả (không bắt buộc).</li>



<li><strong>To email address:</strong> Địa chỉ email nhận report (có thể nhập nhiều email)</li>



<li><strong>Report type: </strong>Chọn loại report (VD: Report group)</li>



<li><strong>Report group:</strong> Chọn nhóm report phù hợp (VD: Executive Report)</li>



<li><strong>Email frequency: </strong>Chọn Daily hoặc Weekly và mốc thời gian gửi report qua email.</li>
</ul>



<p>Sau khi nhập hoàn tất, nhấn <strong>Save</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="934" height="425" src="https://vacif.com/wp-content/uploads/2026/03/image-15.jpg" alt="" class="wp-image-28995" srcset="https://vacif.com/wp-content/uploads/2026/03/image-15.jpg 934w, https://vacif.com/wp-content/uploads/2026/03/image-15-300x137.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-15-768x349.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></figure>



<p>Đúng lịch trình cấu hình, Sophos sẽ gửi email bảng báo cáo report về email.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="794" height="473" src="https://vacif.com/wp-content/uploads/2026/03/image-14.jpg" alt="" class="wp-image-28994" srcset="https://vacif.com/wp-content/uploads/2026/03/image-14.jpg 794w, https://vacif.com/wp-content/uploads/2026/03/image-14-300x179.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-14-768x458.jpg 768w" sizes="auto, (max-width: 794px) 100vw, 794px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-sophos-firewall-huong-dan-theo-doi-xuat-report-tu-sophos-firewall-v22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[Mới Nhất 2026] &#8211; Hướng Dẫn Activate &#038; Renew License Sophos Firewall</title>
		<link>https://vacif.com/moi-nhat-2026-huong-dan-activate-renew-license-sophos-firewall/</link>
					<comments>https://vacif.com/moi-nhat-2026-huong-dan-activate-renew-license-sophos-firewall/#respond</comments>
		
		<dc:creator><![CDATA[Trang Nguyen]]></dc:creator>
		<pubDate>Tue, 03 Mar 2026 04:54:12 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[export]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Tài liệu và Hướng dẫn]]></category>
		<category><![CDATA[activate license]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[renew license]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=28952</guid>

					<description><![CDATA[Nếu chưa có tài khoản Sophos Central, tham khảo: https://thegioifirewall.com/sophos-central-huong-dan-tao-tai-khoan-sophos-central-trial/ Đăng nhập Sophos Central bằng tài khoản Super Admin. &#8211; Vào Account → Licensing Firewall licenses &#8211; Chọn&#160;Firewall&#160;licenses&#160; &#8211;&#160;Chọn&#160;Claim&#160;firewall&#160; &#8211;&#160;Nhập&#160;Serial Number&#160;thiết&#160;bị&#160; Sau khi claim thành công, thiết bị sẽ hiển thị trong danh sách quản lý. &#8211; Chọn thiết bị → Apply subscriptions &#8211; Nhập License Key [&#8230;]]]></description>
										<content:encoded><![CDATA[<div class="root-eb-toc-71c36 wp-block-essential-blocks-table-of-contents"><div class="eb-parent-wrapper eb-parent-eb-toc-71c36 "><div class="eb-toc-container eb-toc-71c36  eb-toc-is-not-sticky eb-toc-not-collapsible eb-toc-initially-not-collapsed eb-toc-scrollToTop style-1 list-style-none" data-scroll-top="false" data-scroll-top-icon="fas fa-angle-up" data-collapsible="false" data-sticky-hide-mobile="false" data-sticky="false" data-scroll-target="scroll_to_toc" data-copy-link="false" data-editor-type="" data-hide-desktop="false" data-hide-tab="false" data-hide-mobile="false" data-itemCollapsed="false" data-highlight-scroll="false"><div class="eb-toc-header"><h2 class="eb-toc-title">Mục lục</h2></div><div class="eb-toc-wrapper " data-headers="[{&quot;level&quot;:2,&quot;content&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 Activate v\u00e0 Renew License Sophos Firewall &quot;,&quot;text&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 Activate v\u00e0 Renew License Sophos Firewall &quot;,&quot;link&quot;:&quot;eb-table-content-0&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;II - H\u01b0\u1edbng d\u1eabn Activate License Sophos Firewall &quot;,&quot;text&quot;:&quot;II - H\u01b0\u1edbng d\u1eabn Activate License Sophos Firewall &quot;,&quot;link&quot;:&quot;eb-table-content-1&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. T\u1ea1o t\u00e0i kho\u1ea3n Sophos Central&quot;,&quot;text&quot;:&quot;1. T\u1ea1o t\u00e0i kho\u1ea3n Sophos Central&quot;,&quot;link&quot;:&quot;eb-table-content-2&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Claim thi\u1ebft b\u1ecb Sophos Firewall&quot;,&quot;text&quot;:&quot;2. Claim thi\u1ebft b\u1ecb Sophos Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-3&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;3. Apply License cho thi\u1ebft b\u1ecb&quot;,&quot;text&quot;:&quot;3. Apply License cho thi\u1ebft b\u1ecb&quot;,&quot;link&quot;:&quot;eb-table-content-4&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;4. \u0110\u1ed3ng b\u1ed9 License v\u1ec1 Firewall&quot;,&quot;text&quot;:&quot;4. \u0110\u1ed3ng b\u1ed9 License v\u1ec1 Firewall&quot;,&quot;link&quot;:&quot;eb-table-content-5&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;III - L\u01b0u \u00fd khi Renew License Sophos Firewall &quot;,&quot;text&quot;:&quot;III - L\u01b0u \u00fd khi Renew License Sophos Firewall &quot;,&quot;link&quot;:&quot;eb-table-content-6&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;1. C\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 license khi renew:&quot;,&quot;text&quot;:&quot;1. C\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 license khi renew:&quot;,&quot;link&quot;:&quot;eb-table-content-7&quot;},{&quot;level&quot;:2,&quot;content&quot;:&quot;2. Tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng nh\u1eadn \u0111\u01b0\u1ee3c License Key:&quot;,&quot;text&quot;:&quot;2. Tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng nh\u1eadn \u0111\u01b0\u1ee3c License Key:&quot;,&quot;link&quot;:&quot;eb-table-content-8&quot;}]" data-visible="[true,true,true,true,true,true]" data-delete-headers="[{&quot;label&quot;:&quot;I - T\u1ed5ng quan v\u1ec1 Activate v\u00e0 Renew License Sophos Firewall &quot;,&quot;value&quot;:&quot;i-t\u1ed5ng-quan-v\u1ec1-activate-v\u00e0-renew-license-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;II - H\u01b0\u1edbng d\u1eabn Activate License Sophos Firewall &quot;,&quot;value&quot;:&quot;ii-h\u01b0\u1edbng-d\u1eabn-activate-license-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. T\u1ea1o t\u00e0i kho\u1ea3n Sophos Central&quot;,&quot;value&quot;:&quot;1-t\u1ea1o-t\u00e0i-kho\u1ea3n-sophos-central&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. Claim thi\u1ebft b\u1ecb Sophos Firewall&quot;,&quot;value&quot;:&quot;2-claim-thi\u1ebft-b\u1ecb-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;3. Apply License cho thi\u1ebft b\u1ecb&quot;,&quot;value&quot;:&quot;3-apply-license-cho-thi\u1ebft-b\u1ecb&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;4. \u0110\u1ed3ng b\u1ed9 License v\u1ec1 Firewall&quot;,&quot;value&quot;:&quot;4-\u0111\u1ed3ng-b\u1ed9-license-v\u1ec1-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;III - L\u01b0u \u00fd khi Renew License Sophos Firewall &quot;,&quot;value&quot;:&quot;iii-l\u01b0u-\u00fd-khi-renew-license-sophos-firewall&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;1. C\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 license khi renew:&quot;,&quot;value&quot;:&quot;1-c\u01a1-ch\u1ebf-\u0111\u1ed3ng-b\u1ed9-license-khi-renew&quot;,&quot;isDelete&quot;:false},{&quot;label&quot;:&quot;2. Tr\u01b0\u1eddng h\u1ee3p kh\u00f4ng nh\u1eadn \u0111\u01b0\u1ee3c License Key:&quot;,&quot;value&quot;:&quot;2-tr\u01b0\u1eddng-h\u1ee3p-kh\u00f4ng-nh\u1eadn-\u0111\u01b0\u1ee3c-license-key&quot;,&quot;isDelete&quot;:false}]" data-smooth="true" data-top-offset=""><div class="eb-toc__list-wrap"><ul class='eb-toc__list'><li><a href="#eb-table-content-0">I &#8211; Tổng quan về Activate và Renew License Sophos Firewall </a><li><a href="#eb-table-content-1">II &#8211; Hướng dẫn Activate License Sophos Firewall </a><li><a href="#eb-table-content-2">1. Tạo tài khoản Sophos Central</a><li><a href="#eb-table-content-3">2. Claim thiết bị Sophos Firewall</a><li><a href="#eb-table-content-4">3. Apply License cho thiết bị</a><li><a href="#eb-table-content-5">4. Đồng bộ License về Firewall</a><li><a href="#eb-table-content-6">III &#8211; Lưu ý khi Renew License Sophos Firewall </a><li><a href="#eb-table-content-7">1. Cơ chế đồng bộ license khi renew:</a><li><a href="#eb-table-content-8">2. Trường hợp không nhận được License Key:</a></ul></div></div></div></div></div>


<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về Activate và Renew License Sophos Firewall </span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-3m3jy"><div class="eb-parent-wrapper eb-parent-eb-text-3m3jy "><div class="eb-text-wrapper eb-text-3m3jy" data-id="eb-text-3m3jy"><p class="eb-text">Bài viết hướng dẫn cách activate và renew license Sophos Firewall thông qua Sophos Central.<br>Sophos Central là nền tảng quản lý tập trung cho phép quản lý thiết bị, license và đồng bộ trạng thái license từ cloud về firewall.</p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-v3lxg"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-v3lxg "><div class="eb-advance-heading-wrapper eb-advance-heading-v3lxg button-1 undefined" data-id="eb-advance-heading-v3lxg"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Hướng dẫn Activate License Sophos Firewall </span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Tạo tài khoản Sophos Central</span></h2></div></div></div>



<p>Nếu chưa có tài khoản Sophos Central, tham khảo: <a href="https://thegioifirewall.com/sophos-central-huong-dan-tao-tai-khoan-sophos-central-trial/"><em><strong>https://thegioifirewall.com/sophos-central-huong-dan-tao-tai-khoan-sophos-central-trial/</strong></em></a></p>



<p>Đăng nhập Sophos Central bằng tài khoản Super Admin.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-3wm20"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-3wm20 "><div class="eb-advance-heading-wrapper eb-advance-heading-3wm20 button-1 undefined" data-id="eb-advance-heading-3wm20"><h2 class="eb-ah-title"><span class="first-title">2. Claim thiết bị Sophos Firewall</span></h2></div></div></div>



<p>&#8211; Vào Account → Licensing Firewall licenses</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-4.png" alt="" class="wp-image-29011" srcset="https://vacif.com/wp-content/uploads/2026/03/image-4.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-4-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-4-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>&#8211; Chọn&nbsp;Firewall&nbsp;licenses&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-5.png" alt="" class="wp-image-29013" srcset="https://vacif.com/wp-content/uploads/2026/03/image-5.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-5-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-5-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>&#8211;&nbsp;Chọn&nbsp;Claim&nbsp;firewall&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-6.png" alt="" class="wp-image-29014" srcset="https://vacif.com/wp-content/uploads/2026/03/image-6.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-6-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-6-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>&#8211;&nbsp;Nhập&nbsp;Serial Number&nbsp;thiết&nbsp;bị&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="396" src="https://vacif.com/wp-content/uploads/2026/03/image-7.png" alt="" class="wp-image-29012" srcset="https://vacif.com/wp-content/uploads/2026/03/image-7.png 864w, https://vacif.com/wp-content/uploads/2026/03/image-7-300x138.png 300w, https://vacif.com/wp-content/uploads/2026/03/image-7-768x352.png 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>Sau khi claim thành công, thiết bị sẽ hiển thị trong danh sách quản lý.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-lrwd4"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-lrwd4 "><div class="eb-advance-heading-wrapper eb-advance-heading-lrwd4 button-1 undefined" data-id="eb-advance-heading-lrwd4"><h2 class="eb-ah-title"><span class="first-title">3. Apply License cho thiết bị</span></h2></div></div></div>



<p>&#8211; Chọn thiết bị → Apply subscriptions</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-2.jpg" alt="" class="wp-image-28961" srcset="https://vacif.com/wp-content/uploads/2026/03/image-2.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-2-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-2-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p>&#8211; Nhập License Key</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="397" src="https://vacif.com/wp-content/uploads/2026/03/image-1.jpg" alt="" class="wp-image-28960" srcset="https://vacif.com/wp-content/uploads/2026/03/image-1.jpg 863w, https://vacif.com/wp-content/uploads/2026/03/image-1-300x138.jpg 300w, https://vacif.com/wp-content/uploads/2026/03/image-1-768x353.jpg 768w" sizes="auto, (max-width: 863px) 100vw, 863px" /></figure>



<p>&#8211; Preview subscription → Apply license</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qeqj6"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qeqj6 "><div class="eb-advance-heading-wrapper eb-advance-heading-qeqj6 button-1 undefined" data-id="eb-advance-heading-qeqj6"><h2 class="eb-ah-title"><span class="first-title">4. Đồng bộ License về Firewall</span></h2></div></div></div>



<div class="wp-block-essential-blocks-text  root-eb-text-y512i"><div class="eb-parent-wrapper eb-parent-eb-text-y512i "><div class="eb-text-wrapper eb-text-y512i" data-id="eb-text-y512i"><p class="eb-text">&#8211; Vào Sophos Firewall → Administrator → Device access<br>&#8211; Nhấn Synchronize<br><br><img loading="lazy" decoding="async" width="575" height="265" src="data:image/png;base64,/9j/4AAQSkZJRgABAQEAkACQAAD/2wBDAAoHBwgHBgoICAgLCgoLDhgQDg0NDh0VFhEYIx8lJCIfIiEmKzcvJik0KSEiMEExNDk7Pj4+JS5ESUM8SDc9Pjv/2wBDAQoLCw4NDhwQEBw7KCIoOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozv/wAARCAGNA18DASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwDkvFWu3+q69ema6lMMc7pFEHIRFBIGB07Vh1Y1H/kKXn/XxJ/6Ea0fCC6W3ivTxrWwWJk/eeZ93ODt3e27GaYGLvX+8PzoJA5JAr2GeDxU9xMNN0zwhcxhmMMcSKWZO3GeuKwZJYvCHgrT9Wi0uzl1bV7iUyyXUAcQgE5RVPT0/OgR57kYzkY9aQMp6MD+Neu6Rp+m61deFPEn9mWtvNeyzQXcEcYEUhCPhtvTqv61bsdP1W71C/t/E/hrSbXQxHKftKwojqAflIIJOcUAeMZB4zRkHuK9Fv8AwlPrngbw3JpYsYmWKXzJJpFiaQE/KScc9K3tQ0LS7bxHqGp3Wn286aRo0UyWwQeW8nz8kDg/d/WgDxsMD0IP0oLKOrAfjXomkXkPjzRNcttS0uwgurK0Nza3NpAI2QjPyn1HH61uGOQ2dj/wiMHhaTTzbJzeYMxfvuz3oA8gBB6HNKqs5woJPoK3fGaarH4gaPWLG1s7pYlGy0QLGy84YY69/wAqxUyIXx1YhaqC5mTJ2QfZ5v8Anm1I0UiLuZCB609rWQMVUbsde1Nxtgb1L4/KtXTSvdNf16EKd9mn/XqR19BfDP8A5J9pf+7J/wCjGr59r6C+Gf8AyT7S/wDdk/8ARjVganU0VQ1fV7fRbRbi4SRwzhAsYy3Qkn6AAk+wq8CGAKnIIyCO9IYtFVpb6KK9trQhme5DlGXGBtAJz+dWe+O/pQAUU1mwjMqlyoPyqRkn0+tNt5Gmto5ZIWgZkDNG5GU9jjjigCSiobqZ4LcyxW73LAjEcZGWycZGTjjrUpIBGSOenvQAtFQ/a4ftv2PcfP8AK83bj+HOM5+tTd8d/SgAooHPQg84qmuorPaR3NnDJco8vl4TAK/NtZjnHAINAFyikOBjkc9PeloAKKQHIyOQe9LQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUVyUHxK0Ca7FuwuYVyR5siAKMfQ57V0EWq2stvZXALLHfDMRfAx8pbn04FbToVYfFGxnGrTn8LLtFUU1ixfYGnVDJIyIGPUq23PHbI4NSrqFm7BVuY2YhSADz82Qv54P5Vm4SXQrmj3LNFVZ9RtLW5FvPL5b+UZcsDgKDg8/jTlv7RrM3gnXyF6v6dsY65z260csrXsPmXcsUVVj1KxlQyJdRlQMk56c4/nxUL61ZxLFvfEkrBVjU7jy+0dOOv8jTUJPoLmj3NCiqZ1bTwrt9qQhGCnGTyemB36Hp6GrasrqGUhlYZBHcVLi1uhpp7C0VDcXKW3lbwx82VY1x6npTXv7SO6Fq9wizMMhCf8+ho5WwuixRVWDUrK5jlkhuUdIV3SEZ+Uc8/Tg0PqNrHLsMyYClnbcMKMA8/gafJK9rC5lvctUVUXVLF0Di6jwSBycHJbaBg988Uv9p2PmrF9qTe2cDPpnv8Agfyo5Jdg5o9y1RUVvcw3cCz28gkjb7rDoaS7uo7K1e4lyUTGce5A/rSs726jurXJqKpPq1lHJMrzACHaCw5BLAkAY69DSPrNhEWEtwsYVtoY8h/lDZGO2GHNVyS7C549y9RSAggEEEHkEd6jubqG0i82eQImcZwTz9BUpN6DvYloqjLrNhFPHCbhWZz/AA8hRtLZJ6dBn8RSf23p7KxiuUkZUZtoOM4GTyeOnP05qvZz7C549y/RVeG/tLi4e3inV5UzuQdsHB/I9ajTV9Ne+Nil/btdAlTAJBvyOoxS5Jdg5l3LMn3R9aoQtPcmVbi08gK37pt4bevvjoeOnuKvyfd/GqsF1Hc7/Lz8hwcipKPmnUf+Qpef9fEn/oRp2my2UGoQy6javdWik+ZCj7C4x2PbnFN1H/kKXn/XxJ/6Ear0xHa6d4q8IaNepqGmeE7hLyHJheS9JVSRjJH41XtvGtteaS+leJdKOo24uHuIXhl8qSFmJJA9sk/nXJUUAdunxDhg1fR2tNJNtpOkB/KtFly7llILFj35/U1yV9fzXt1cStNN5c0rOI2kJABJOKq0UAbeta/Fq3hzRdJW2aNtLjdGkZgRJuI6Dt0rcl+I7f8ACQ/2hFp2+zmsUsrq0mf/AFqjPII6dT+tcRRQB10vi/StP0W+0/w1okmnyagnlz3E9wZGCf3V/M/nUcereBFjQS+Ert3CgMftpG4965WigDa8V+Iz4m1dbwWwtYYoVghhDbiqL0ye55rMVJDAhjUk7i3Hb0qCirhJRvcmSbJ1S5TO1WGTk4pkg2IkZ6jJI9M1HRTc1ayv9/8AwBKLvdhX0F8M/wDkn2l/7sn/AKMavn2voL4Z/wDJPtL/AN2T/wBGNWZZJqE8134lZI9Mlv7extzG6xuigSSDnO4jPyY/76qpFdTv4ZttNuvMt3hvo7G7BfDCPPy5YH+JSgyD3NdVBawWxlMMYQzSGSQj+Jj1J/IVHLptlP8AafNtkf7WoWcMMiQAYGR7UXCxjNp1jpvi7SY7KNLffFOWgj4U4C/Nj17Z71lRadbDwfZ6gqMt4bhF+0hyJArTbSobrjaSMV1NromnWUyTwW2Jkztkd2dgCMEZYk49qlGmWQskshbr9nRgyx5OAQ24H8+adxWMV7K20vXZ7exhW3hm0yR5I4+FZlYANj1wTzVWztIb+fw7DdKZYv7JZmjYna5/d/eHf8a6iS0t5bj7Q8QaXyjFuPXYTkj9BTItPtIHgeKBVa2i8mIjPyJxwP8AvkflSuOxzF5EtlpmuWVvmO3gu7cxRg8R7jGSB6DJJx71a1fTvM1G+vJrCLVrfYqlVmCzWmF5Cg8c/e4IPP0rcl02zmE4kt1YXLK0uSfnK42k/TA/KobvQtMv52nuLXdI4CyFXZRIB0DAEBvxp3FYy7K20678VW17FCsu/TEmjlkXLn5sBifXFVtLg0+y8JTalcRytLKJUkljY+aQZSoVWz8ozj0xXRyadZy3FvcNABLbDETKSu0enHUcDg8Uo06zWwawFuhtWDAxEZUgkk/qTSuOxzltZ/Y/EWnwf2XbadFdQzJLDHNvMyhQfnGAOPXk81DZ2lva+GbB7eFImk1VA5QY3YnIGfw4ro7XRNNs50uIbb99HnZI8jOwBGCMsSce1OTR9PQvttgA8wnK7jjzAchgM4BzzxTuKxl2unWWtX+qyapCtxLDcmBFc/6mMKpXb/dzknI5/KqFon9rN4eS+driMx3QJZv9cqkBS3rkAH3rob3RNN1CczXNtvkZdrMrsm9fRsEbh7GrH2O282CUQoHtlKQkDGwEAEAfQClcLGZosEdlq+rWNsvl20ZikjiH3ULKd20dgcZxW1USW0MdxLcJGFlm2+Y3dtvA/LNS0igooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACk68UtFAHF2/wAMNHivfPlubmePJJhfABznuOeK6RNGtVtLC1b95FYjCLIA27ClRn860KK3niKtT4pXMo0acPhRk/2BCoZIp3jikJEiKi4Zd5cAf3cFiOO1Oh0C2hvRdCR2Ikd9hxg7ug+i84+prUoqPaz7lezj2M2bRLZ1VID9mRUK7I1GM7gwP1BUH3ol01xp80aSmW4eUT+YcL84IIPQgYwOK0qKPaS7hyRMOHQZnhLXF2ySyM5lCBW3AvvAzjg/T1qf+wkBwl1IsbMjSJtB3lXLDnt1xWrRTdab6iVOJjL4ciSBoUnwMBUJiUlVGcDPXPPXjp9a1oY/Jgji3tJsULvc5ZsDqfen0VMpyluVGCjsVr6zN5EirMYXjkWRXChsEexqpLoonZjPdPIkhVpU2hRI4GAc9R24HpWpRQpyitAcE9zL0iwurd7iS9YP5iRxqpIb5VB64AHemf8ACOW32QW7TSsBv+Y4yc4x/wB8hVA+la9FP2sr3QvZxtYyH8OwSogkmbcpclkQLuLDg49sAj3FC+HrdJFZZW2hFVgyAliq4DZ7HvWvRT9rPuL2cOxHBEILeKFSSI0CAnvgYqO9tEvrOS1kJCSYzgZ6EH+lWKKzu07l2VrGVP4ftpJmmhIgYsrKEjG0EKVPHfIao30Jlmj+zXJhQIyuQi5AKIuAMY6Ln2rZorRVZrqR7OPYZDEsEMcMeQkahVz6AYFV9Qsft8KR+c8QVtxwMhuCMEd+ufqKt0h+6cZzjtWak07ltJqxkL4djSFbdbyUQLzs2ry3l+XnP05x61NPosU6OrTSAOSTgD/nn5f8uaghuLmOMgNLjIDTMjN2P8J5BzjOOOaR72/mjmVcrIMqUSM/u/lBzu78nGK09pNvcjkj2L0OnRwTxyiRiUMpAIH/AC0IJ/LFSLYWi3z3620YunQI0wX5io7Zqm11fI4Qrkq5APlH9783T/Z471YsJ55vOE4OVbg7Co/DNQ5S7lJIsyfdH1rJ0jrcf7w/rWtJ90fWsnSOtx/vD+tSUfPF4nmazcoeA104/wDHzUHmp2gTHuW/xqzcf8h2f/r7f/0M1VhbZKjZAwwOSMgfhTEO81f+eEf5t/jSean/ADwj/Nv8auebaMxMrCRto6kkDk5AJGfSmF7RYBtCNIEOMr3wOv45oArean/PCP8ANv8AGjzU/wCeEf5t/jVrzrePfsERVlAVdh6ZH3vfrVOXZ5r+X9zcdv07UAO81P8AnhH+bf40ean/ADwj/Nv8ajooAk81P+eEf5t/jR5qf88I/wA2/wAajooAk81P+eEf5t/jR5qf88I/zb/Go6KAJPNT/nhH+bf404kqoZrVQp6E7sfzqIHBB681b3RyNKRPkyqcIwxg+/atqVOM07vUzqTcbWRXkC7UdV27wcgHjg1798M/+SfaX/uyf+jGrwF/9RD/AMC/nXv3wz/5J9pf+7J/6MasTQ6miiikMKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAM0gAXOABk5OO5paKACiiigBkn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB873zFNXunHVbmQj/AL7NQ7oP+ecg9g4/wqTUf+Qpef8AXxJ/6EaXTrCfVL+Gyt9glmOFMjhVHGSST0FMRFmD+5J/32P8KMwf3JP++x/hWtF4U1KSPezW8JEnlskkuChJABb0B3DH4+lQvoF1FZG9kntVtgdpk83PzbypXAGc8Zxjpg0AZ+YP7kn/AH2P8KMwf3JP++x/hWtZ+FNQvoY57eazMMg+SRpwoJ3EbcHndxnGOhHrUV94du9Ps7q6mmtWjtZkhkCS5bcyhgAMc8E/TBoAzswf3JP++x/hRmD+5J/32P8ACta58KalaW7z3D2sSLEJVDTDMi7Q2VHfAYD607/hEdRDlWnskPUFrkYZNyr5g/2fmHPoD6UAY+YP7kn/AH2P8KMwf3JP++x/hWpceFtSt1kY+Q/lH96BKAYgRkMwOMCpT4P1MMyebZFkcq4FwPlUEguf9jjOfQj1oAxswf3JP++x/hRmD+5J/wB9j/CrV9pU+nxl5ZYHHmCP91Ju5KK+fphhz65FUaAJMwf3JP8Avsf4UZg/uSf99j/Co6KAHyOGCqq7VUcAnJr3/wCGf/JPtL/3ZP8A0Y1eaD4R+KCAd1hgjP8Ax8H/AOJr1jwZpN1oXhOx0y88vz4A+/y23Ly5IwfoaBm5RRg0YPpSAKKMH0owfSgAoowfSjB9KACijB9KMH0oAKKMH0owfSgAoowfSjpQAUUmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRketAC0UmR60ZHrQAtFJketGR60ALRSZHrRmgBsn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB866j/yFLz/r4k/9CNFjYT6ndraW6o0jhiA7BVwoJJJPA4Bo1H/kKXn/AF8Sf+hGn6XqDaXqCXawpMVV0MbkgMGUqeRz0JpiJpfDmpRbQtp5xcjYLf8Ae7wV3BlK5BXHeoE0nUZI0lj066ZHbajLAxDEdgcdeD+Vbdp42uLNI4Y9Ntfs8G0QRbm/dADAwSck9SSfU1bfxyv9ns625OozYWQnKxqo8zGPm5/1hxwDxzmgDmG0q/UOz6fcgRuI3Jhb5WPRTx15HHuKuHR9c/swrNbXEVlA7tslBVQ4UFuPUjFX08b3yxRD7LEZYYxCkvmOCEGzIwDySYx83UZOO1Obxzd7pHisLaNmJKkFjtJQKSR0YnANAGPc6fq8kskt3ZXjSRxqztJC2VQDCk5HTAx+FUNo9BXRHxdIFvUTToQl4p3o00jqGO7LYYn++cdMfnnnhxQAm0ego2r6D8qWigAwB2ooooAKUfeH1FJSj7w+ooA+mZLZ5pbeZbqWIRAHy0xtf13evHHt1q/H90VAn3F/3R/Kp4/uikM8N8R3VyviXU1W4mVRdSYAkIA+Y1m/bLr/AJ+p/wDv43+NXfEn/Izan/19Sf8AoRrMr7OlFezjp0R8xUk+d6k32y6/5+p/+/jf40fbLr/n6n/7+N/jUNaOkWA1D7bGI2kmjtTJCqnkuGUdO/BPFVLlirtCjzSdkyp9suv+fqf/AL+N/jR9suv+fqf/AL+N/jW/J4agNtFIZXjcxxiQIoKwMVBLSZbIGSenofpUs/hOxhZlOoTBi2xA0QGG2ucnJ+78nb1rH29L+kaeyqHN/bLr/n6n/wC/jf40fbLr/n6n/wC/jf41048J2aROXunCmNZA7KA/AYnC574xz+BqtP4Yto7C5uoruWTyojMuEXCgBCFfnhjv7ccUKvRbt+g3Sqowftl1/wA/U/8A38b/ABo+2XX/AD9T/wDfxv8AGoaK6OVdjDmfcm+2XX/P1P8A9/G/xr1zwCzSeD7V5GLsXkyzHJ+8a8dr2H4ff8ibaf8AXST/ANDNeXmiSoL1/wAzvwDbqv0OkwPQflRgeg/Kiqmq3Mlnp0k8bojKVAZxkLlgCT+dfPRV2kj2W7K5bwPQflRgeg/KsNNelWRbfyVunLsqyxtsWUBgAV69zzz2pf8AhIt+yRIMRuCo3vtG4MinJxwAWIJ9q19hPsR7WBt4HoPyowPQflWZa6z9q1FbMW4wV5kWQMM7d3HqvbPrVZPEqyO6JBGMPhXebahGGOSSOD8p4pexn2D2kO5uYHoPyowPQflWNL4g8tHZbdGxL5ar5w3DkjLjHyjjjrnIpr+I9vmj7IAyKrBWlGSDjJOARxnp19qPY1Owe1h3NvA9B+VGB6D8qZBKs9vHMv3ZEDDHuM0+stjQMDHQflRgeg/Kl7UlADZHjijaSRlREBZmbgADqab50HlxyeYmyUgRtnhs9MfWotQtDfWbWwlMSuy72UZO0HJA+uKyz4bkzGPtauseAjSR5dFBYgAg4H3ueOwrWEYNe87ESlJPRG27RxruYgDIHT1OKdgegrEXw0qbDDMsZUjcVTGQAnHX1Qn/AIFUsWi/ZbCe0jmRTNHGpJTjKgAkg+tDhT6S/ASlPqjWwPQUxHikLhGVijbWx2OM4/UViQ+GwYBi8DMBsWZF5UYcEA5/2x/3zVmHRpbezeJJIY5DcpcLsiIjUrt4xnODt/Whwpr7X4ApTfQ1cD0FGB6CsE+G5SMfbFGYlRjsPzkEHnJ4HHQetXtM0pdPd5Cyu7IqA4PygZyAT2yf0olGCV1L8AUpN6o0MD0H5UYHoPyoorI0DA9B+VGB6D8qKKADA9B+VGB6D8qKKADA9B+VGB6D8qzL+6u7a9ISdBCLWScp5WWymOM5759Krr4hkyC1nmPOCwl+Y/PsyFx1z2zWqpSaujN1Ip2Zt4HoPyowPQflVLStROp27TGDysEY+bcCCAf681drOUXF2ZaaaugwPQflRgeg/KiikMABnoPyowPQflSjqKSgAwPQflRgeg/Kufk8Q3Ftcuk8KsgnmEZQffRAePZgQM+xp/8Ab8z3KxLDCFyFysm7c3mbTtOOV569a29hMy9rA3cD0H5UYHoPyrAs9euPKiW5WJpZERyzSCNBld2M469MClk8Rs07RQwx7Vk2mRn6rh+nHXKdPej2E77B7WFjewPQflRgeg/KsSLxE0nlotsHeQqqgygHJKrlhj5RlsjrkCp5NbEVpZXDQALcnDZk/wBXzj0yefb8qTozXQaqwfU1MD0H5UYHoPyrn38SXDpugs0UZf8A1snXCMwHA4OV6e9Sxa/IWw1usgBBdlk4UEovy8fNy/tT9hU7C9rA28D0H5UYHoPyrC/4SYbN7WyBQVJInztDAnnjORjkc4zW7UTpyh8RcZxlsBA9B+VGB6D8qU0lQUGB6D8qMD0H5UUUAGB6D8qMD0H5VmarqEtlc26rLEkTDL5AZz8wHAyDjntk5xxWW/iHUfJWNYoRdMrOmVO2RfMVVxz7kH3wa2jRlJJoylVjF2Z0+B6D8qMD0H5VzR8Q31zORZx4ikdRCBDvcjY5ORkfxJj2FdFCZGgjaZQkpUF1U5AbHIH41M6cofEVGalsPwPQflRgeg/KiisywwPQflRgccD8qKX0oATA9B+VGB6D8qKKADA9B+VGB6D8qKxdQ1m5stQmh2IYAYUR9pJV3PIPsRnHuPerhBzdkTKSirs2sD0H5UYHoPyrnpvEtw1uZLe0jTIfBlk9EZh268cipI9dnibyZ4kllV9pIbbu5UAKMfMctk9OKv2EyPbQN3A9B+VGB6D8qy9N1xdSujbpbMmFLli3YYH/AKFuX/gNalZyg4O0i4yUldBgeg/KjA9B+VFFSUGBjoPyowPQflS9qSgAwPQflRgeg/KiigAwPQflRgeg/KuYg8T3fl27TQKxRHa5CKRu+UtHt9MgZPWrv/CQlTGHtAu9W/5bDkjOAOO+OpxW7w9RdDJVoM2sD0H5UYHoPyrD/wCEnjHk/wCj7y+Q6xuSyn5sAAgZ+6aRPEu6RI/siuxYAmOYMuCFPBxyfn6expewqdh+1h3N3A9B+VGB6D8qpabqQ1ATfuxG0L7Sofd9DnGPyzV2spRcXZlppq6DA9B+VIQPQUtB6UhkknT8aydI63H+8P61rSdPxrJ0jrcf7w/rSGfOuo/8hS8/6+JP/QjVerN+C2rXajqbmQD/AL7NSf2VMWwJI8FtoPzctnGOnr+FMRSoq19gkA+aSNWABdcnKA9CePp09RStp0q78Oj7JDH8oY5b06e/egCpRVpbAtMIluICx3DhjwR1HT9elVjwTg5HqO9ACUUUUAFFFFABRRRQAUo+8PqKSlH3h9RQB9Qp9xf90fyqeP7oqBPuL/uj+VTocKKQzwjxJ/yM2p/9fUn/AKEazK9V1D4aWeoajc3r6nOjXErSFRGuBk5xVf8A4VRY/wDQVuP+/a19LTzDDqCTfTszwp4Ks5NpHmVFem/8Kosf+grcf9+lo/4VRY/9BW4/79LV/wBpYbv+DJ+o1ux5lRXpv/CqLH/oK3H/AH6Wj/hVFj/0Fbj/AL9LR/aWG7/gw+o1+x5lVhL66jtHtEnZYHPzIOh/zgce1ei/8Kosf+grcf8AfpaP+FUWP/QVuP8Av0tDzHDPd/gNYKuun4nmVFem/wDCqLH/AKCtx/36Wj/hVFj/ANBW4/79LR/aWG7/AIMX1Gt2PMq9h+H3/Im2n/XST/0M1l/8Kosf+grcf9+lrqdC0VdC0qPT4rhpkjZmDuuDyc9q4cfi6VakowetzrwmGqUqnNJdC/QQGBDAMD1BGRS7G9R+VGxvUflXjHpjdifL8i/L93gfL9PSgopBBVSD1BFO2N6j8qNjeo/KgBoRQQwVQQMA45A9KTy48EeWmCckbRyfWn7G9R+VGxvUflRcBhjQ7sxqd33sqOfr60GOM5zGh3dcqOfrT9jeo/KjY3qPyouAlFLsb1H5UbG9R+VAB2pKXY3qPyo2N6j8qAEopdjeo/KjY3qPyoAzdQ0+6ur2Ga3uBCEQqSWPGc8hfX3z+dZreG7iSFRLJHI4Rl+eRiByh447lTn610mxvUflRsb1H5VrGtOKsjN0oy3MI6JeAPILwrLzsKO3ygh8gDp/Ev8A3zUVhpl+0kVwR9nWOfcIpJHOFwucA/Q9SOtdFsb1H5UbG9R+VP28rC9lESil2N6j8qNjeo/KsTUSil2N6j8qNjeo/KgBKKXY3qPyo2N6j8qAEopdjeo/KjY3qPyoAQgHqAfwpNq/3R+VO2N6j8qNjeo/KgBqqqjCqFGc4AxS0uxvUflRsb1H5UAJRS7G9R+VGxvUflQADqKSl2t6j8qNjeo/KgBu1f7o/KgRoAAEUBemFHH0p2xvUflRsb1H5UANKIRgopGc8qKTy4+f3acnJ+Ucmn7G9R+VGxvUflRcBuxASQignGTj06UFFOMop2nIyOn0p2xvUflRsb1H5UAN8tOfkXk5Pyjk+v1oCIvRFH0Ap2xvUflRsb1H5UAVoLC1ti5jhGXYMxYljkdOv1NWKXY3qPyo2N6j8qbbe4JJbAaSl2t6j8qNjeo/KkAlFLsb1H5UbG9R+VADSqsQWVSVOQSM4+lG1ePlHHTinbG9R+VGxvUflQA3ao/hA/Clpdjeo/KjY3qPyoASil2N6j8qNjeo/KgBKX0o2N6j8qNjeo/KgBKKXY3qPyo2N6j8qAEowD2B/Cl2N6j8qNjeo/KgBnlx8/u15OT8o5PrS7FJB2rkHIOOhp2xvUflRsb1H5UAIAB0AH0FFLsb1H5UbG9R+VACUUuxvUflRsb1H5UAHakpdjeo/KjY3qPyoASil2N6j8qNjeo/KgBu1f7o/KkEcYxiNBtGBhRwPan7G9R+VGxvUflRcBnlR4A8tBgYGFAwPb0qK3sra1QpDCAC275iWOemcn2qxsb1H5UbG9R+VO7FZDVVVztULk5OBjJpaXY3qPyo2N6j8qQxKD0pdjeo/KjYfUflQA+Tp+NZOkdbj/eH9a1nOR+NZOkdbj/eH9aQz52vyV1a7YdRcyEf99mlXUrtZnlErF3YFsknuePpyeKbqP8AyFLz/r4k/wDQjVvw7qEGla3Fe3G/y40kHydclGAwe3JHPbrTEVGvZGQrsQEhVZgPmYL0B/IflS/b5sOPly8hlyMjDH8cdu9dcNe8MXGpQ6lcK4lhIIDwM7vhIwu5s8srK53HrnNMOr+EZJoJDZQ8szSNLAxYMQ2S2Bhskgjrj0FAHJm9fzVkSKKNgWJ2r1LDBzVeum0u78LwnU/t0ZlSSVvsytb8hMHaRjO05xkZHHr0rRsdd8Kw6kl4LSC2eKfcrCzLL5QlJAC54cpt+b2oA4ilAJ6AnvwK6jSpvD0GgibVIYZnkuZg0axkzuuE2YbPyAEt168irw17wxBbXNvHESJgd32a3aJX+WUKAM8EB0BPc80AcTg4JwcDqccUldnHq3hVJbiOSKJ4ZHDQrHaNGiYEm3zBk7yNyZOOfeqGsXvhy40eWPT7eOC6+0bo/LhYZXJzlm6DHQD6Y70Ac3RRRQAUo+8PqKSlH3h9RQB9Qp9xf90fyqdPuCoE+4v+6P5VOn3BSGRG6txL5RmQODgqT39KlxWa1xAg1CCUhneVtsWMs2VGMCoZZLlJTHLOscqLGIyzsMnAyQoHzc5BpiubHSkUh1DKQVIyCO9UA8/2trTc+IS0pbnlSPlGfqT/AN81FFMpVPtdxLEfJjMW1iCxI5OP4jnjFAGrijFZfmzG/ZWmWOUT7VQu2SnptxggjvVu4Vn1CBAzhfLdtqsQCQVxmgCzikdljUs5CqOpNY8M900ZaOYNceU5kj3Mzbsf3SMKQf8AJokuFDSC0uJZEEAY5YnDbwD17+tAXNnGKOtZcr7ruaHzGlaQuoCSMCo2ngr6e49qLUjbGyPK8cVmrhUc8tk5+p7YoC5qHjrgCkVlYsFIJU4I9DWFJIZoJ08wtEIkkO2Vnwd3OT646gVbab98yyTOtr55BcORxsUqN3YE5oC5p4oxWZbh7maKN5ZjCUlKEOVLKGAUk/SpfOnOhpNubzCi7mA+YDPJ+uM0AXcqWK5G4DJHpS9PxrHeULJctZys8WIgzlyQq5bdhuT/AIZpy4aS3eSYPEtzhSkjEL8h43Hrz/PFAXNViFUsxAUDJJ7UKyvnawOOuO1Yxu5GZ2jdwXhlLKZCzKQOMjGFPsKldyPNLSiMGZc72KB/3Y4LDp/9aiwXNXFGKis5PNs4pMONy/xnJ/PvU1IYmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAJijFLRQAmKMUtFACYoxS0UAMfoPrWVpHW4/3h/WtaToPrWTpHW4/wB4f1oA+ddR/wCQpef9fEn/AKEal0jTxqmoraGQxbo5H3AZ+6hbH44xUWo/8hS8/wCviT/0I1HBPNbSiW3keOQAjchwQCMH9CRTEdGnga8JlR9QsxKpCKqliDJ5ioVJxxguvPTmqqeEb2WVFju7NkcBll8wqmDIY88gfxKaoprmrxSNImo3KuxJZt55JIJP4lVP4Cki1vVreBbeLULiOJX3qgfgHOc4+vNAGu/gm9WKImeGNmlMJaVmVWcsFRVG3OWz3GKqXvha+sXtY5JbdpLmdLfYjnMbsqsobj0YdM1WHiHWhI0g1S63sCCfMPQ9f5D6YqJNWvhcQTSXLzGCZJlWRiRuUAKT+AA+lAGuvgjUJCpjvLF1kkEUbh2xI+XBUfL2MbZz6e9C+B9WlkVYZbSZWIAkSX5cnbtB44J3jA9j6Vm3XiDV7y5NxNqE5fzBIuHICMCSMemNx/M1E2r6k7OzX8+XkSRsPjLL908dx29KANceCb7JJvbHaT8hEjHfhdzYGOMLng46VJc+CLiOTy4LyBwJ3gEkhKiSQOUVVGCQTtPXjjrWLJrWqSsWfUJySSfv46rtPT/Z4+lSf8JDrW93/tS63OpVj5nUHk/r360AP1bQLrR4Y5Z5oJN7+WyxMSY22K+GyB/CwPGay6nnvbu6XbcXMsq7t2HbPO0Ln64AH0FQUAFKPvD6ikpR94fUUAfSk88sd7axq2EZRuHrWon3BWPdf8hGz/3VrYT7opDF3AfxD86Ny/3h+dOj/wBWKdQBHuX+8Pzo3D+8PzqSigCPcv8AeH50bl/vD86kooAiYqylSRhhg81DBbQwOZBI7uRt3SSbiB6CrdFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/AHh+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/wB4fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/AHh+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/wB4fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/AHh+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/3h+dSUUAR7l/vD86Ny/wB4fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv94fnUlFAEe5f7w/Ojcv8AeH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8Pzo3L/eH51JRQBHuX+8PzoBB6EH8akpsnQfUUARyfdH1rJ0jrcf7w/rWtJ90fWsnSOtx/vD+tAHzrqP/ACFLz/r4k/8AQjVjQr6HTtZt7i5DNbZMdwFGSY2BVsD1wTVfUf8AkKXn/XxJ/wChGn6Vp8mrata6fFw9xIEzjO0dz+AyaYjsZfFvh28KLPZ8Nu3+ZDuRdnyQEr3/AHec8cE1ma/rGhahoyQ2kKrPGkccKC3KtCA7lvnJ+ZSpUAdqZdeCLuG9uYIrqLakmy3EwZXn/d+aMAAgfLnqeoxU9t4DmYzedexyCKTyv9HJ/wBYDhlJYDGODkAg5oA5Kiuht/Bl9c3zWMV5aNcRjEq/PiN+MITtxnnr061NP4NMdqJ01CEoqLJNM4YJErRq2MAEk5cDj17UAcxRXSSeBtRhdY5ruyjlLAOjSMNgLMoYnGMEoehz0rD1Cyl06/ms5uZIW2kgEZ/AgGgCvRRRQAUUUUAFKPvD6ikpR94fUUAfSF1/yEbP/dWtiP7orHuv+QjZ/wC6tbEf3RSGSR/6tfpSkgAknAHUmkj/ANWv0qO7hNxZzQjGZI2UbunIxQBLuUkDcMkZAz2oJAxk9elYa6NdxyCQSqxSPyVAcqTEGBC57EjOT9KV9L1J9n+kDzEB2ymVjs+QrjGOeT97rQBt5GcZ59KWs/TrOe2d3nfcWQKMtuK4LHGfTmtCgAooooAKKKKACiiigApjTRI6xvIiuwyqlgCfpT6w9V0m6u9SFxbxw4KBWeRs8DP8JB554II96ANeO6t5s+VPG+Bk7XBxTlljfbtkVt3TB61gt4dnTT7WGCZRKq+VOxUDMTABwNoGegxmpbPQ57W/gn8791HNM/lbhtRWzt2jHXnnmgDcooooAKKKKACiiigAooooAKT60tIeeBQAtFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUVkatrn9l6vpdm8O6K/d0eXP+qIxt49CSB+NVYvFsDX+pQSW8nlWc0cEJjUu9w7BshVHoVI/A0AdDRXP3/jCwttPe5gjnnkWB5TGsLZj25H7zj5fmBHPoatvr9qtm0oyZBI0AXBx5gQvjPpgdaANWisS18U2M72sMgkSWdYwzBCY0kdQwQt68/wAqtz6zawakunlZnmIVnMcRZYwxIUsR0BINAGhRWFf+KrO10xLyFWl8yJZ0UqRlC6oT9fm6d6efFWnqi/u7szF2Q2wt281SoDElfTBB988UAbVFZT+IrFLmSHbcMsQO+ZYWMasF3FS3rj/DrVUeLLQbZXinWGRIzEhgfzXLswXC46HHFAG/RXOXHjC3UlYLaY4t5JWeWNlEbIwUo4xkHJ/l61cfxPpsdxLC5mAi3gy+U3lsyAllVuhYAHj2NAGvRWfpetWureYIFmjeMKxSaIoxVvusAexwfyrQoAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACmSdB9RT6ZJ0H1FAEcn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB866j/wAhS8/6+JP/AEI1HDNNA5e3keN9pUshwdpGCPoRkVJqP/IUvP8Ar4k/9CNWNCvotN1m3ubhWa2BKTqoyWjYFXA98E0xEkGuaxFpZ02C4nW3B3MFzkIFxtz2TBPHvReeJda1C8kuZNQnDyEnZG5CqM5wB6V01x4y0W62rJayhJFdZ1EfDKuEhHXn5M596jtPE/h2B47j+z0imSd2zFahWC7m2lSMY+QhSPqfegDmV8Q6ym3bqt2NiBFxKeFHQfoKbHrmrRGIx6lcr5I2x4kPyjGMD8OK6Vdb8JG4T/iXRxw+SVyLQM6fd+Xk4LcN8xB69fTG1280i7srBdOhEU0SbZgsAjB4GMnqTkEnkjn8KAKK6vqaOJF1C5DjGD5h7En+bE/iar3FxNdTvPcSvLLIcs7nJJqOigAooooAKKKKAClH3h9RSUo+8PqKAPpC6/5CNn/urWxH90Vj3X/IRs/91a2I/uikMkj/ANWv0p1Nj/1a/SmXSSS2k0cLbJGQhWz0OOKAJaKxTa3iR/6HavaA9UWVclscE9sZ69zTpINUQvN57kjLbQwx95ugx/d20AbFFYSx6yYYinmfeVvnkUsPu5z7fe/w9HOmqQeWgmdmmKqckHaSDuPTjHBFAG3RWbeRah9oaS2dioACpvAB4bPbrnbVeK11Z1UTTSoA2OHAO3cc5684x3oA2qKy7GLVFuw13ITHsGQMEE4Hv1zntWpQAUUUUAFFFYOq2F7Lq8d1aQB2VVCySMCiYzz2YHntkHvQBvUVyZXX1lihzd7mVmQGVCQw2cuehXJbA64qRdP1y1t1jjknaMjc6RyqGDZfhSeg+4TQB1FFY+lR6smoTm/ZmiKLtbcNu7jO0Dt154/GtigAooooASloooAKKKKAEpaKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAzNX0OLV2UyyvHthkiG0cgvtww9wVBFUo/CcduqNbXskc8SxeVKUDYZA4LEd929s/WugooA5ybwiWt5Ug1SaGS6ieO7k8tSZtzFicfwnLHp2OPenyeFi9yWGoyrbGYz+R5a43mMoTu645zj1roKKAOct/B1rbahDdJKpEZjZg1ujOzIoUEORlQcAkDv0Iq3qOg/2hqtvetdmNYWVtgiXcNpz8r/eUHoRyCPStiigDmD4NZoTCdWn8tIfJtwIkBhXzFcc9z8gHNSXfhN72CUTakXnnk3zSNboQflCjaP4SAOCDnOetdHRQBh/8I5Ipnih1SdLS4DGSEorFnZNpJY84PXHr37VX1Pw3cSG0eyuWWWE20ZcgfKsRY7sHqfm6V0lFAHOS+EhLG2dQk82ZJVuJPLX975hBJA/hwVGPapJvC6zmWJr6QWjNLJFBsH7uSQMC27qQN7ED3rfooAo2elrZ3j3IlZi9vFBtI6BN3P47qvUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABTJOg+op9Mk6D6igCOT7o+tZOkdbj/eH9a1pPuj61k6R1uP94f1oA+ddR/5Cl5/18Sf+hGrOg6bHq+sRWM0rRRurszrjI2oW78Dp1NVtR/5Cl5/18Sf+hGm2kt1BcCayeZJ4wWDwkhlGOTkdsZzTEb0Pg83gE1vqVtFC7lYxKxkY4ZUJ3ICp+Z1HB7+1T2ngO7YxtdzqqPlWWPIeNsr1BHIwc+/rWHPfawMzXFzergqS8jMMZwy8n12gj1wD2ok1jWQI1l1C9A27ow0rDKnuPUcdfagCteQC2vbi3DFhDK0YJ74JGf0qGhpN7s7vuZiSWJySTSbh6j86AFopNwPcfnS0AFFFFABRRRQAUo+8PqKSlH3h9RQB9IXX/IRs/wDdWtiP7orHuv8AkI2f+6tbEf3RSGSR/wCrX6U6mx/6tfpTLozC0mNvzNsOz644oAlorFM91DHm0+1up6m4iLHdjhQODgnqeg7U559U8xCysqGTLBIskKGI2++Rg5oA2KKxbe+1KVlEsTRJv4byGJbheCO3VuenFOe8vodPswzMZ5CwkJgJbIBONo9wBmgDYorHju9WllZGgWLLqPuE7Bkc56HjPfim/btT2t+5bKs2GEDEMf4VHcA88npQBtUVRspb153FygCFSy4TG35iMZ78AGr1ABRRRQAUUVg6rLfxavG9stzKoVdsKZVCecknBUjpkNg+lAG9RXK/23rAeKMqSzBmT/RGBlIC/LjPygFiN1OW9122tlWQSMGG4ym2LtHy+FwD83Ree2aAOoorH0q+1K51CeK8gMaKisoEZCqeMjcep69OK2KACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKAM7V7qaJI4bYyCaQlv3abiAoz09CcD8ary6tJMEMDRxpuhyGPztuIzj+X51sbRu3YG7GM4pnkQllbyk3L0O0cUxGfY3011fJvePy3gLiNDyvzAfN7/wD16fZak11fPBhCmxmRlBHAbHfr+Qq8sUaMzJGqs3UhQCaFhiRi6RorN1IUAmgDNXVpBI6yCJcSKAAeil9uc5wf0qF9WmFxLIjw+XHGx2Mfv7XK/L7kCtf7PDhx5MeJPv8Ayj5vr60fZ4Pl/cx/Lyvyjj6UAZr6tLHLLGyxKQ2IwTxjcF3EjsM8jgiie/uAkiBoGCQPI7xsecEjA9D+eK0vIhy58pMv987R8319aVYYlXasaBcbcBRjHpQBky6pcKJghhG1njUclgQm4MfbihNRn8zyxJFvfbmSQnYPkDHA9/8AGtOK0ghd5EjXe7EsxGTz/SlNvAU8swxlP7u0YoAzodVnmeN/LjWJnjQqSd2WXOadPf3EN/LCHi2kxrHvGNm7OSfXp+eK0tiZzsXOc9O9I8MUmd8aNkYOVByPSgCmNQf+zhdsqYR8SEHI2hsFh7d6gOrT8N5cSqAr7GJ3OrMQNvvjH4nFaM1tHPbm3OVjYbSEOOPT6U4wxEoxjQlPukqPl+lAGW2sSeWvlrEZCrZUt90iQIM/nVjULyayiib92ScmRj0GB1AznH5496tiCEMzCJAWOWO0c0skUcoAkjVwDkbhnBoAyZNamV5ykCmOPeBk4OVGc9eh+lOn1Ce2llQshl+XjBKn5STgZ46etaZhiLlzEhdhgttGSPSleGKT/WRo/OfmUGgDPg1CR7O7u+DsQSIhPA/dq2M/U0JqUqXAhuPKHz7S4JAxs3Dr+VaIjQKVCKAeox1pGhicEPGjAkE5UHp0oAyo9Uu5/KMawKJDGvzZOCybs/SmQ6tcNKZCYihEOYs/NluDt/nWyI4xjCKMdOKb5EO5X8pNy/dO0ZH0oAyo9YuZVJWGNd5UJuP3cuFwecnr7elWr69ltiiKYQxjaRmkyFO3HA9zmrYhiVmYRICxyxCjk+9LJFHKAJI1cA5AYZwaAKtleS3XnSOqpEhAA53fdBOfzqnFrM0reWBCC5TbIwIUBgx5Gc/w8dM5rYCgZwAMnJx3qMW0AVkEEYVvvDYMH60AYv8Aat0bE4miV1AYuTy+ZCPl+gFW9Ru54Ll0DqIvI37RwxO4Dg/jWgbeE7cwxnb935Rx9Kc0cbkFkViOhIzigDJk1S7Xe4WDYqyOAc5wj7SPqf0qa21Kae/aEwgR7nUHOCNp69ec/TjitDy4zxsXoR09etIIoxIZBGocjBYDk/jQBljUbpXkjaS33ebIAz8BVXHB56nP5ZqxPqRgs7e7aPEUq5YHqpK5Ufnx+Iq20EL53wo245OVByfWknt0uAgkyVVg20HgkdM/jzQBnf2pcKxDxw5DGMxgncGCbs/T/wDXSrqss88UMHkkvsyxJIGVZj0/3f1rS8qPzPN8tfMxjdjnH1pEghj+5Ei85+VQKAKN9qU1teCGKEOAgdsnG7JxgHIx+tRf2nJLI8ZCgRTomVYjflsZHt2+oNajxRyMrPGrFTlSRnH0oEUYxiNeOnHSgDKj1O5mkhUvDGxmCyLjPylWIwc4PTqPypLfVLgpEdiNGPLVsklyWXPWtUW8KjasMYBbdgKOvr9aURxjoijp29OlAFDT9Rlu7gRv5JDQiUeWSSuT901HFq8hcLMIlJkVSAeFU7uc5wen/wBarttYQ20ryqXZ3GCWOeM5/wA96k+zwbWXyY9rnLDaPmPvQBkrq85dpg0RjEaN5ZPLZdl+X8hUh1aYPJGREr7wqZyQoLY3Eg4I/LnitPyIcqfJTKfdO0cfSjyIfn/cp+8+/wDKPm+vrQBm3F/ceXKA0JWODezxMeTuI4PbpUdzqtyqT+WYAQZVTGSylM8kenH6itcRRhdojULjGAvGPSo4rWCEuUjXc5JYkZJycn8KAM86jNHJJGrw7tzEvIx2cIpwPTO6pIdTmllRmjjSF5BHg53AmPfn09qumGAoEMMZUHIUqMU8qh6qpyc9O/SgBysGUMpBBGQR3psnQfUU5QFUKoAAGAB2psnQfUUhkcn3R9aydI63H+8P61rSfdH1rJ0jrcf7w/rQB866j/yFLz/r4k/9CNTaLqC6XrFteSRtJEjESxqeXjYFWX8QTUOo/wDIUvP+viT/ANCNSaRp0mr6va6fGcG4kClv7q9WP4AE0xHWHx5YzPGZtOdT8+6Tar7ccQkKSMlUyp5HXis7XPE1hqujC0itJEkUIsaNGgSHa7MSpHPIYLt6DFF94MazvnR75YrZplS2eSNmeVSqtn5AQMBu/GQafdeB5VLi0vI3SFpfOeTI2ojuvmYxwPkwevJHrQBbbxhopkkkXTW3vAqFmt49vBb5AueFIIyc9ulVG8W2Lz3kkmlJKvyfYUZEAh+Xa4bA5BGSOvODVdvCElvrun6XdX8A+2SNEzxAsYmHUEfiMGpZvBqhBNb6pEYEt1mnMkbho8xCToByCM4x+NAC674ostQsbi2sbPyHnZMyGBFPlguSmQSf4lGRj7tcvXVD4f6g12LUX1oX+62NxCPkAKeOM54Pfmqc/hlY9TezTUE2RWC3ksskbDaCFJUADJ+8MUAYNFdPJ4FvI7iSD7faNLGjEom5mLqcFAoGSfekbwRdIjyNqFsIodqzv5ch8pmCFRjGWz5i8jgc0AczRXTN4HvI5Fil1C0jlyPNU7v3YO/BzjByY2HHtVbVfCV5pGntd3NxACrf6nlXKliobBHqOnXFAGFSj7w+opKUfeH1FAH0hdf8hGz/AN1a2I/uise6/wCQjZ/7q1sR/dFIZJH/AKtfpTqbH/q1+lRXryRWNxJFnzFiYrgZ5A4oAnorCj1PUIXWGSBnJkx+9IDfw8ZGBk5JHt+NC6zdOWxHHuRNxHICkg8Nn0x7UAbtJgEg45HSsNtZvEBcRIyvtKBkK4ypPOT3IwP61M+qXqTxobZNsjsByRwG24ye/f8AzmgDXorHg1S6eC8nMYkMUaMkaKRgnOQc9SOM00apfuqlIIsdM4JB+/yMdvlH50AbVFYbaxcyu8ccJXChgQpyp44Pr19qnudUntpLaNYTK0iAuNpBOfT/AD+VAGrRXPNrF8Y5Spj5+44jbGdq/KPU5J6+n5Wv7UvBcRRtbpiTJ7jI3EY+oAyeO9AGvRWPb6xPK9srxIBK5VyoJ546c8jnrz+FR6trl1YagbeKBJF8nzB8rFiec9OgwPf8KANvapYNtG4DAOORS1zJ8UTtdukUcLRg/IuG3yruYZHbAAyc0yLxReSQI4hgYMAwdVfbIcA+Wv8At8/TigDqaK5a513VYlEzLDGksb7EEZypEgXOSeuOcdKhi8R6lBbzM+ycIy4kdCMZ7cBcn8u/XigDr6K5mbxNdRu4MUEY8wITIr/ufmx8/wBRyMU2PxBqapJcPbK0TnCIVYGM7FO7pyvJPrQB1FFc7b+I52vLeOeOJYXVy0qKx3AFvmHovA9ev0ySeIbpRL8tvHtl2fOr/uRlsF8DvgYx/eFAHRUVza6/qjMJPsUSRZyUZX3gDZkZ6Z+f9K6SgAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAoqKWXy8ADJNR/aW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390UfaW/uigCzRVb7S390VOjb1DetADqKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKQmgBC2Kw/EXizSfDFsJtSudrP/q4UG6ST6D09zxUviPW4dA0W61OcblgTKpn77HhV/E4r5x1XVLzWtSm1C/mMtxMck9lHZQOwHpVRjcD0W9+NtyZCLDRYhH2NxMSx/Ben51NpvxszKF1TR9iE8yWsmSP+At1/Oua8LfDPWfE9kL8SxWNo/8Aq5JgWaT3Cjt7k1T8W+BNW8IbJrpo7i0kbatxDnAb0YHoau0dhHvOja9p2vWK3mm3S3EJODjgqfRh1BrQc5UfUV89+CR4p0vUo9V0fSb66tWIWdUiOyZO4yeCfQ172kkrxK3kuucHDDBH1qJKwyaT7o+tZOkdbj/eH9a1CWI+ZSB71l6R1uP94f1qQPnXUf8AkKXn/XxJ/wChGoo5ZIWLRSNGxUqSrYOCMEfQipdR/wCQpef9fEn/AKEar0xFmPUr+K3NtHfXCQsoQxrKwUqOgxnpyaJdSv5y5mvbiQyKUctKx3KTkg+oJ5xVaigCzJqV9LLDNJe3DyW+PJdpSTHjptPakfUL2TzN95O3mjD5kPzDGMH144+lV6KALq61qylSup3YKpsBE7cL6dage8upPv3MzfuvK5cn5P7v09qhooAuHWNUOT/aV3ny/Lz5zfd9OvSp7nxFrFzeJdNqE8cka7Y/KkKhBgDCgHjIArMooAsx6lfxOHjvrhGXABErZGM4/mfzPrRLqN9cQGCa8uJYmfzCjyEgt64Peq1FABSj7w+opKUfeH1FAH0hdf8AIRs/91a2I/uise6/5CNn/urWxH90Uhkkf+rX6U6mx/6tfpTqACoobeG33eTEse45baMZqWigAooooAKKKKACiiigAooooAKKKKAIzBEzu5jUs67GOOo54P5n86ciLGixooVVGFA6AU6igBrokiMkih0YYKsMgimW9tBaR+XbxJEhOdqjAzUtFADJIo5dvmIG2MGXI6EdDT6KKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooArXP3l+lQ1Nc/eX6VDTERiUZbPQdMd6VpCP4SOD17UvlJgDb0FBjU9ST+NAB5g9803zhxwcc5PpinGNSSSOowaTyl9z+PWgBVkVgT/d60glUjOD0JpwUAEZPPqab5S+/1zQACUEnIIGcA/hQJQQCFJz0FL5ag55+maTylHrn1zzQAGTnGCOQDkUnnDAwp5xinbF/XPWkWJQoBJJAHOaAASjHIJ9SB05pVkDHGCPTPejyl9/z60oQAjHbNAC1bh/1S1Uq3D/qloAkooopDCiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKY54p9MfpQB5j8Zrl00Gxt1J2TXWW99qkj+deOtypx1xXt/xW0uTUPCrTRKWeylE2B/d6N+hz+FeI1rDYTPpzwxdWt34W0yeyKmA2qBQO2FAI/AgirN5p9pq0DW19bpcW+5WMcgyCQcj9RXlPwk1/UIra80W1t7e5Ifz41mu/KIB4IUbTnkZP1r0PSNZ/tm51PSZxFbXdptDi2ufNwGHBzgYIwQRjioa1B7GxNdW9mYYnZUMrCOJB3PoBTYbzzb2a28iRRGAQ5Xhs1yniew1JtYs5IYri4hjRQjR/eDA889j05rr7ZmaBPMKmQAB9pzhu9bzpxhTjJO9/wADmp1ZzqSi1a34jpvuD61jaR1uP94f1rZm+4PrWNpHW4/3h/WuY6j53vgG1i6Vm2qbpwT6DeeastZoGl/0Jg0e7y03k+bggZ9Twc8cGqmo/wDIUvP+viT/ANCNLYWM+pXiWtts81gzAu4UAKCxJJ6YANMRe/s60ZlRSVk+dmQv2Cglc+oJ/HmmCzs3u3iBG1Av3WIOSRwSfXpx61HcaDqlu5Bs5JUAQiWAeYjBwCpDDg5yPzpH0HWI2RJNKvFaRtqAwN8xxnA49OaAJG09XjUrAVlYoTErMSoJIJIPI7VMun2TOFXDDd/CzE4y3X24HTn86rtoGsqsT/2bdHz9+wCMljtOGyOoweOaqx2N5NbvcRWkzwxtteRYyQp9CfyoAZOoSZlC7QO2CP0PNR1dk0bVYzKJNNu1MKB5Mwt8i+p46cH8jQdG1QFgdNugVj8xgYW4X16dOtAFKir0ejajJdx2htJIp5Y2kjSUbC6gEnGevANWofC2q3FrHcIkAWVA0aNOod8qXAC+u0E49KAMeitLUfD+p6SsrXsAjWJowSHBzvUspGOowp+hGKzaAClH3h9RSUo+8PqKAPpC6/5CNn/urWxH90Vj3X/IRs/91a2I/uikMkj/ANWv0p1Nj/1Y+lOoAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigBrxq/3hTPs8fv+dS0UARfZ4/f86Ps8fv+dS0UARfZ4/f86Ps8fv8AnUtFAEX2eP3/ADo+zx+/51LRQBF9nj9/zo+zx+/51LRQBF9nj9/zo+zx+/51LRQBF9nj9/zo+zx+/wCdS0UARfZ4/Q/nUgAAwOAKWigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAprCnUhoAoXcCyIysoZWBBBGQR6V4l4x+H13pFxJeaVC9xYMdxjQZeD2x3X3r3l0yKpzW27tTTsB8uhircMVZfQ4IrT8O67qPh7Wor7S2LT/daLBYTKeqkDk17veeGNLvn33Wm2s7f3nhBJ/GpLHw9p9gf9Esbe3PrHEFP51fOhWJ9E8SNqWnRXF9ps+nzuOYXwxHvx/XBrSS9tlB2KVBOThMZJqGKyUfw1O1uoUcdxWYxWuI5RtTOevIqGKCKHd5aBdxycVKYwoyKbQB8yaj/wAhS8/6+JP/AEI0/TNSn0m/S9tseaiuqk9tylc/UZzTNR/5Cl5/18Sf+hGrOgfZv7btvtcUEsOTlJ5AiE7TjJPHXGM8E9eKYjWHj3VMAtFC0gcPv3MMn5d2QDg7tg46DnFQR+Mr5YpIXtoJIZo/KlQlhuT95kZByP8AWnkegrbksvDEkNxFcXFiJWYEPCyx+SP3O4gAkFgC/AJUkHArMmsPDNp4itYzcyNbeZH5kRZZIyC+GzIrfKNuD0P4UAIvjzUBIXa1tyTkfKzqQNysoyD2Kjnqe9VtM8XX2k2s8Vvb27SzStIZ3BLZJUnPPPKjGfU1Z1LSvDsFmJVvDE5kUZhmW4JyX3rsyMBcLhs85q3pmneGIrC3u7i6iZniIljmnXc53Doozt49wfr1oAyX8UO0ckS6bbpG0nnRgSSny5cEF8lufvHg8dOOubcnju/mklaS0t3EqMGjdnKbiSS23OOp6dqTXtM0C102S40+cNc+edqJcLIgG9vlx1IChTu96vhvC0IaZVs/9KtpLsBohL9lbagWEISATu8w4z0xQBhX3ia7vdQsb4QxQz2WCjqSS5BzliTk+n0p914s1S4jvI43W1W8mEjiDK7VCbBGPRQtbbnwje2LywwW9nOttdSxxu33ySwRDzw4+VlHoSO1cSKANrU/FN/q1hLZXKQ+VJci4UqDmM4I2g5+7yTj1JrFoooAKUfeH1FJSj7w+ooA+kLr/kI2f+6tbCfcFY91/wAhGz/3VrYT7gpDF2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaWigBNo/wAmjaP8mlooATaP8mjaP8mlooATaP8AJo2j/JpaKAE2j/Jo2j/JpaKAE2j/ACaNo/yaWigBNo/yaNo/yaZPPHbW8k8rbY41LscdABk1zv8AwsHw/wBrmUj1+zv/AIVMpxjuzelh61VN04N27Js6XaP8mjaP8muZ/wCFgeH/APn4l/8AAd/8KP8AhYHh/wD5+Jf/AAHf/Cp9rT/mRr9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/wo/4WB4f/AOfiX/wHf/Cj2tP+ZB9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/wo/4WB4f/AOfiX/wHf/Cj2tP+ZB9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/wo/4WB4f/AOfiX/wHf/Cj2tP+ZB9Qxf8Az6l9zOm2j/Jo2j/Jrmf+FgeH/wDn4l/8B3/woPxB8PgZNzKB/wBcH/wo9rT/AJkH1DF/8+pfczpto/yaNo/yar2V9Bf26T277o3UMpx2NWa0ORpp2Ym0f5NG0f5NLRQITaP8mjaP8mlooATaP8mjaP8AJpaKAE2j/Jo2j/JpaKAG7R/k00xqf/11JRQBCYV9P1pREvp+tSUUANEaj/8AXShQO1OooAZJ938aiqWT7v41FQB8yaj/AMhS8/6+JP8A0I0/S9MutY1GLT7JVe4mzsVmCg4BJ5PsKZqP/IUvP+viT/0I0un30um3YuoVUuEdBuzjDKVP6GmInfQdVRFb7DM4MXmkIpYou5l+b0OVbj2pbnw7rFncvby6bceYhGdqFhyQByOOrAfU1pP451aW3MMqwufJWPzBuVshWXeSDyxDHPY06Hx5q1sZvJitkE773G0n5igQ4546Bsf3gKAMldC1dtm3S7o+YpZf3R5UdT9BkfnUeo6XeaVctBeQmNgxUN1Vsddp7itKbxbfTWE9oYLdRdRbLiQBt0pCqobrgHaoHHHWquua9deILpLq9jhEyLs3xgjK54B57c4oAzKKKKACiiigAooooAKUfeH1FJSj7w+ooA+kLr/kI2f+6tbCfcFY91/yEbP/AHVrYT7gpDK8F8Jry5t2TYYCMMT94Y5P4Go7bVYp7bz5FMYMrIigFmbHQ4Az05plxpskrOySqheU7j6xsAGH14pRZTQyiaHy2ZZXYIxIBVgOM44IwKegtSw1/aqkb+ZuEgJXapY4HU4A4xTba/inthMSFPlCVh12qc8/oahis7m3kE0ZieRwwkDEhQWbdkfT9ajXTrqG28qN4WL2whctkYIzyOOevSgC0L+LMu/hUZVUgEl8qCMAc96mjnilh85HGwZyTxjHXOelUX0yQneGVmV1ZV3MucJtIyORVm3tjFavHsjVnLEgEsMn1zyfegBUvreQZVyMlQNyEZ3dOo6H1plxqEUEiIecyeW2ASVO3cMDv2quthciIqGRApRo4vMZ1BU5PJ5APTHalNneGf7RmDzPP83Zk4xs24zjr70AWTqFsI1k8wkNnAVCW465GMjHele+to2VWk6gHIUkAHoSR0z71VewnKFsRGV5HckSMhQkADaw+nPHNSR295A7FJIpDKE8x3yCGAAJwOuce1AEhv4S5SNgzLKI2yGABJxjOOtC6laPnZIzcNjCNhiOoBxyeOlM+xSbNu5c/a/O/DdnH1qvZW1zLbW6SBEijkaQHnceWwMduvWgCzDqUMsaTEiONofNO/IYDPpjpT/7RtRGXMhUBghDIwYE9BjGeaqjTZ2hjVnjVo4VjBGSCVYEH6cVI1ncTXAuJTGj+ZGdqkkBVJPXHXmjQC3BPHcIXiYkA7SCCCD6EHpVcalA9zFDG24SbvnIIGAM5BPBH0qWGAxvcliCJpNwx2G0D+lUxp1xIkEErRCKCN4wyZ3MCu0HHagCaXVbWOB5hvcIA20IQWBOMjI5HvUxvbcSiIswYkDlDgE9ATjAPsao/wBmTNA6MsSv5WxX8x2ycg9+g4HrUk1ldT3Ad2QjzUkGZG+QDBKheh6Hn3o0DUlXUED4kKKgR3LgnA2ttx0qxDPHOpaPd8pwQylSD7g1SGnSANkxPlJF2uDg7n3DP4VYs4ZoUcStkFsom8vsGOm48mgCzRRRSGFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQBn69/wAgG+/695P/AEE1zHhHTorrSIHkySIV/lXT6/8A8gG+/wCveT/0E1ieCP8AkCQf9cV/lWf/AC8+R1/8wj/xL8maX9iW/oaP7Et/Q1pVk6vc3FvPvW4aO3ih3yeTsLoc/eZW5ZcDt71vCLk7HDJqKuSf2Jb+ho/sS39DUNxrskRnjW3VpbcM0gLkDblQh6fxbv0NO/tW7M7WohthcRtJvZ5CsZChTwcZyd4+mCav2UyfaRJP7Et/Q0f2Jb+hqsdYurdrh5I4pIRLMseG+YbE3gdMY4Iz1qX+17lJMSwQbY2iWUK53EydNoxzjI+vPpR7GYe0iSf2Jb+ho/sS39DVaPWbiYQeZEkfn+VInlSZ+Vn2kNkfypW1q5CFlghlEk/kwvFuZWIBLHHXAxgY6mj2Mw9pEsf2Jb+hrO8QaRBDoF/Io5W3cj/vk1uWVw13ZRXDxGJpFyUJztNUvEv/ACLeo/8AXtJ/6CawqKyaOrDWdaD81+ZT8GEjSIBn/lmv8hXSZNc14N/5BMP/AFyT+Qro3fYjMewoj8KCv/Fl6sdk0ZNV45nICHBfOMsMds0vmyFiPl+8AAD6iqMSfJoyag+0ErlVHpz645pBcMcnaDkjaPTIzQBYyaMmoTMRErbfmY4x6UgnJIBTBboM/nQBPk0ZNVvtDHHAHIPHcc/4U4znjAGSAR+NAE+TRk1WE7Nhjwvy4A6804Tsdo2rlsEc9M+tAE+TRk1AJ2JXKgA8E575xU1ADwc0tNWnUhjJPu/jUVSyfd/GoqAPmTUf+Qpef9fEn/oRq34daxTW4m1LyzbKkhbzVDLnY23g8E7sYB71U1H/AJCl5/18Sf8AoRptnay317BaQDMs8gjQH1JxTEdfcWPhC6kNwbqKOIhfMeKYRlTtTGIgP4iX3AfdI/NbfT/DNnE8bXNpLOG3GY3KvtUiYAAYwekWR6tmuen8NapDqElmsAnZJTEJI2Gxzs35BOONnzZ9KsXng3WrRQ32dLg+a0RWBw5Vg4Tp6Ekcj15xQBuWHh7wxqN55FmXnZJBH5Yuz86bkBk3beDhmwOhIri7qNYryeKM5SOVlUk54BIFaqeGfEMDOyWc0OBtZ1lVcggE4IPIwcnGRii68Javall+ziQx7xIUYbVKsVwGJwxO04A54oAxaK27bwjrNxGJTbiKIhCHZ1O4MwUYAPJBYZHWoh4W1tiNlg5U5IYsqgAc5bJ+UY55xxQBk0VJcW81pcSW9xG0c0TFHRuqkdRUdABRRRQAUo+8PqKSlH3h9RQB9IXX/IRs/wDdWthPuCse6/5CNn/urWwn3BSGOooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAz9f/5AN9/17yf+gmsTwR/yBIP+uK/yrodTtjeabcWyttMsTIDjpkYrhrPSvE2lILe11BFjQBV/0cHgVnK6ne1ztpck6Dg5qLvfW/Z9kzvM1DNaWtw6PPbxSsn3S6Biv0zXJ7fF/wD0E4//AAEWk2+L/wDoJR/+Ai01Uktov8P8yPq1N/8AL2P/AJN/8idWllAs1xKw817gjfvweB0X6Dn86dLaWs4Imt4ZAW3kOgPzdM/WuS2+L/8AoJR/+Ai0bfF//QSj/wDARaftZdn+H+YfVaf/AD9j/wCTf/InXmCBgQ0MZBJJBUdSMH8xxSNbW7TJM0ERljGEcoNyj2Ncjt8X/wDQSj/8BFo2+L/+glH/AOAi0e0l2f4f5h9Vp/8AP2P/AJN/8idf9ntwFHkx/KAF+UcAHIx+NQrpunpG8aWNsqPjcqxKA2Oma5bb4v8A+glH/wCAi0bfF/8A0Eo//ARaPay7P8P8w+q0v+fsf/Jv/kTsUVI0VI1VEUYVVGAB7Cs3xL/yLeo/9e0n/oJrA2+L/wDoJR/+Ai1Fd2niu8tJbabUUaOVCjgWoGQetRKcmmuV/h/ma0qNOFSMnVjZNfzf/Imv4N/5BMP/AFyT+QrpCAeozWP4Z0+XT9PSGbkqoXOPQVt4HpWkdEjkqtSqSa7sjZFb7yg59RRtXOdoz9KkwPSjA9KozIyikYKgjOcYo2If4F6Y6VJgelGB6UAR7VK7do2+mKAqjGFAx046VJgelGB6UARhEXoqj6Ck8uPGNi4+lS4HpRgelAEexQQdo46cUBFHRQOc8CpMD0owPSgCPYmQdoyOhxS0/A9KMD0oARadRRSAZJ938aiqWT7v41FQB8yaj/yFLz/r4k/9CNLp+oXGl3iXlowSeMMEcjO3IIyPfng9qTUf+Qpef9fEn/oRqzoLW6a3bNdJbvCCcrcttQnacZOCBzjGRjOM8UxFoeMNYMZWSSGdim3zZYgzj5Cm7d/e2nGfTFKfGGsfahcpJBFKNxBSEDlnDk/iyg/nWvdaZ4fmiutRmlDJDNFCTARFHIzhehUFcph9xXg8HAqaTTvBuPIWa2ysxcFbo7jmP5ULE4xuByQcZ7jNAHPS+KtUlZTuhQLv2qsfC7k2NjJPYfnT7jxbqV3E8NxFZSxOzP5b2wKq5JJcD+9lm/OtZLLwWJFiaUsrOAZGuzlAZGU9Bg7VCtnvVPQ9P8N3OlxSapdrBP8AaMSEz4LJkYAUdPcnj3GMUARN421l9gb7KQgG0eQMZDKwPXrlFPp7VDL4s1Wa3mhZrcC4TZO6wgNKMbRuPcgcCtCey8JieG3WTYbiVo5JvtW4Wv7tdrcZDLvJzyeBUs9r4Xmsf9Gmid4Q6qk115RCb3+fIXLNwpCnPDUAcve3c1/ezXlwQZp3LuVGBk+1QV2g0rwa10sa3a+WYSRLJdgKeVwzAcg/e+X9DXFngkZzz19aACiiigApR94fUUlKPvD6igD6Quv+QjZ/7q1sJ9wVj3X/ACEbP/dWthPuikMdRXDPrjCy1Wx+0SyagmrnZCd+4Reeg4I/hwfXFV5vFuuLpUtxHcRyXBmjW4iFmyf2cCzAgs3yt0A59c9CKAPQaK4Gy8TeJp3gupvJWHdBG9uLViH8xGJcN1ABAOAO+PSs9/HHiMaVFJH5buJXElybbERYIrLGpzyCSewbjGM0AenUVw1jreq3/jWwt7qdoAs06yaekLL5aCL5HZ/4gTyP/rGmv4t1WDWNRgkkRoLa5TOy1JWGHzlVix6htpJ5GO4OBQB3dFeap4q1h9Za6iumIlVVt7M2rkXQ+0yJhf7p2YJP0PSp4/F+sObmKe8jgRLoJLerZF47VDvx7kkqowwBGc85FAHodFcDda1rkiNeG4WSGC7iSJEtXiDfuN5kOTnGT908DvVO38Ta3qEdhN/awa1MsRnuIrIopaSJyYT9GC8+rjuKAPSqK83tvFevQWMap/r47Xiya1dm2C33icuTz8/y4/DrU1/4n8RaXGY57mKQxXC7pVsyHlVolcIq52kgsR1BOOOc0AehUVmRXTXGmXEhufMdZnRGgiZCpDYC4PUg8E9DUQvLqCKIyMRMZCJ12bju44UdNuD65/WgDYorHS7v0ifD+a0SSMwMfJIcgD8BzTZNTu0hQgq7bjghOJACBj68npTsK5tUVkm7vwxbcpXJbb5XYSbcZ+nNSXUd1LqbJAWVVjQh/MKqp3HPHRuBRYLmlRWQ99epGrsygsGZR5R+YhsBPy70xr69iYp5gY+ZJy6ejfKn5HNFgubVFZMl3cvHIftHlOsg3RiEkxrvA698jmkjvblXROnzfKhQky5cg89sDmiwXNeiqFlPdShhOQd0AkXCbdpORj9BVW01C4WKHzZPMjxH5shjIKEg5U++QOfeiwXNmisiO/vnVZdoK/KPL8sgtlSevbnFQre3hkaVHachVIVUKrnY5K4+uP0osFzdoqlp928yFZnVmLEIyjG4AAn24zUMVxcnVWkZJPs0jGFST8oI6HHXkhhn6UhmnRWPcTXdtc3EiyHDyhQzLwgCAgDtyTilfUNQWURiFc/KMhDjLgbfwBzn8KdhXNeis++vZre8hii5BK7gU+8C2Dg+3Wm3dzdQskjRmPCvwh3j+HBPT1NAGlRWfb3l5JZGX7OsjKH53YyQTjjHOcCq8+pXEdoHjmEznJ3CEgcDO3n39OaLBc2KKynub3ck2/C+cyiIR/eAU4BPucVJZXdzNazySFCyLlTtIwcZIIHofxosFzRorHXVJ1tyzfM2x9reXwzjGAMdep/yKRL27TzlWQOQZDh4z+6w3yknuDRYLmzRWVDfzyPGGk8sEDAaHJlOSDjB4xgfnmo2vLuJYZJJFVpUj3OYzhNxORj2osFzZorGW6u3kVnYsGEZSMIVDfOQWH1GDj3p8N7eztHGsi/OV3P5J/dkhiVweuMCiwXNaisqDUZ2uIxPhUaIMyrGfl+XJJ7j9fTrWoDkAjoaQxaKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKTavpS0UAN2r6CjavoKdRQA3avoKNq+gp1FADdq+go2r6CnUUAN2r6CjavoKdRQA3avoKNq+gp1FACYxS0UUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFADJPu/jUVSyfd/GoqAPmTUf8AkKXn/XxJ/wChGq9WNR/5Cl5/18Sf+hGq9MQu5toXcdoOQM8A0lFGD6UAFFFFABRRRQAUUUUAFFFFABSj7w+opKUfeH1FAH0hdf8AIRs/91a2E+4Kx7r/AJCNn/urWwn3RSGRJexu7qN4EZKs7LhQR1Gac15brKYmuEDhSxBYcAHBqmumOslyweHE5bkoSw3fjg/lTf7I/cpCJVKLGY/mTJI3Bhn3459aYtS+LqAkgXEZIXcfnHA9fpQt1A+dtxG21dxw4OB6/SqEuj+bLMfMXbIWYZBJUnGR1xjj0pZtIWUPiQIWZ24X1ZSAf++aA1NATIyK6yKyN91g3B+lNNzCp2mZN2CQu4ZOOvFVxYYsHt94V2YuHUHCtnIPJ9agbSGLRYuBsj2nBXkkZyevcnPNAGglxHIiusgKuMjJ9s/yoWeN4/NWZGjH8YYEfnWcdHdo/JNwBFjsnzZ2bOuenepksHSznhEqrJMcl1BIHAHcn0oAnlltJ4fKllieOdSu0uMODwR70kEtrEyWMDIDEmFjQ/cVcDHt2qomj4SQNKpZw3O0nGWDdzntU1rYNb3SymRGVFdVATDEMwPJ70AWftUGGP2iPCfe+cfL9fSmyXttEjs9zGAgBb5hwD0rPg0qQxx+c0a7CcKE6jzA3zc89B+dSSaS0m8eagXLlPk5yxB+Y55HFAF7z4SXHnJlBlhvHyj39KZ9uttwRZldioYKjA5BOM/nVM6QWaQmVeSWU7ScEsGIIzgjIqRtPkkfe0kQJA3BI8Dh93HP4UAWzcwAMTPHhDhjvHyn39KZPew28SSvJlZGCptIO4npiqkeklXjLyoViKhQExkA5+b1NTrYhbWGDeMRSb87evJOP1oAnNzAAzfaI8IdrHePlPoacZEGcuoxjOT0z0rPi0ko0ReRGEWwKBHjIUk8+/NS3No0+oQvgiNV/enI+bByo/A80AWlnickJMjENtOGB59PrQs0bvsWVGbGdoYE49aoR6XLGY3WaMPCFVP3eAQufvc9eansLH7ErZcOzKoJC46DFAEwuoCjOLiPan3jvGF+vpQt3A8rRLOjOuMqG9RkVROj4SIJKoaJVA+UgMQSecH3o/sgiB40mVCyptYKcqy9xz05oDUvtcwKoZp4wpxglxjnpSNdQrIIzKpctt2g5IOCefTpVBdG8kfuZUyCwUSJkBCMBcZ7f1NObRke1NuZWAMocsBhjhduKA1NAyqIjKCWULu+XnI9vWokvraRWcTrsXGXJwvPIGT3pVS4WFlMke/aAjBMAHHXGfWqZ0kpbmCGYbQ+9S4OVYg7iCD3Jz+dAFxby3csq3EZKvsI3D73pS/arfYZPtEWwHaW3jGfSqi6X+83PKGGWOQmDllCk/pmof7GkEBjE6AkBSQrfMApAzz79qA1NFrq3jYq9xErDqC4BFNuLyO2ZVkEhJUt8iFsAYyTj61UGjrs2mRScMMlPVAv9M1PLp8c8kLSsWWKMoVBK7s464PTjpQBN9rtwpb7REFGMkuBjPSk+2WwMgNxGDEQr5YDaT0qs2mkHfE8YbzGcB48rhhjBHtUR0dgFCTLhSCu5Tz8m05wfxoAvy3dvDuMs8a7F3sCwyB64oF3CeTKqgttUswG44zx69apjSysUsKyR+XIpGTHlgdu3g56cf0pJNKdzI3mx7pQyvmPIAYDO3nrxQBfWaN5GjWVGdfvKGBI+opq3ULlV8xVdiQqswDHB9PwqGCwEE6ShgSrSE/LydxB6+2KiXSgN2ZASzKQdvIw5b+uKALRvIAwHnKSW2na2cHBPPpwDTpbmGFC8kyKq9csPTNUhpbGBIXljCoNqlI8Ejay889fm/zmmtpczFpGniMjAqcxHbgqF6Z68UAXkuoZMbZlyyB9pbB2+pFR3F1apa/apXV4UYEOvzAHOM8fWqiaNtJBkR1Kn76k87NvrjFTrYP9i+zyTBiZA+ccABgcep6dTQBP9rgBcNMqhCAxY4HIyOaVbuB2dVnQmMkON3Q4yf0rPbRSGYxzjG/cisDhV27dvBzx2/KntpAaEw+YAnmKwwvONoVl69CB+tGgal5riJSA0yAscDLjk+lNN3biTy/OXdznB+7jrn0qiNGKx7VmUllZHZ0z8pIxjnggAD8KdJpAkSMCbaY5HkB29STkZHcfzoAvyzJDH5jnC5Azj1OB/Oolv7Z2KiTkSNEcjowGT+GO9K8UlzazRTbVL7lUrzgdj9e9UTogZSDcHmHYfl6vnl/x6YoAvfbbXeiefHlxlDuGG5xwald0jQvIyoo6sxwBWYdHc7v3sQMiMr/IT1IORk9eKuTQz3FqULrG+/IxyNoPAP1HcUAS/aISyr50e5xlRvGW+nrTUuoJZnijkV3RdzBTnHOPz4qnDo4ii2NKGOU+YLyNrFuPzqWysXtZN7SRtiJYlCpt4BOCeevNAEiX0DtIrb4vKALmVdoGenJqQ3MC53TxjC7jlx09fpVL+zbhoNkk8bOJRLvCMNze/PTHp0wKE0ny4/kdA4ZGXKHblex5zjmgNTRDKyB1YFSMhgeMVAt9avu23EeFYLu3DBJGQAe9QjTENo0LSNvZWUspIUbiT93OMc1BNpE0yy5uIlM2dwSMhR8oX1z2oA0w6MQA6knOMHrjrVePUbaQkbmQYJDSLtUgHBwT71HZWjQ3k8zAhM7YlOOM4LH8TTV0iJbfZndIWyXbJGN+7ABOB07UAWXvLWNHd7iMBFDN8w4B6Gn+fCWZfOj3Ku5huHA9T7VRl0kymQeagVi7L8nOW9T3A/w9Ka+jmR5GaVfnJYfKThjgkdcY4/KgNS4b61BCrMjsy7lCMDkZxkfjUhuIBvzPH+7OH+cfKff0qpJp0krK7SRK2MNsjwPvBuOfamJpJDxlpUKxEbQE5IDbvm9TQBoK6ugdWDKRkMDkEVBFfW8qNJuZECht8i7VKnoQTRawSW6tDlfKGSpA5yWJPHoMiqq6VKp3edECrKyosZCEjPJXPU57UAX/AD4d6p50e5/ujeMt9PWmR3ttLCZlnj2AZYlgNv19Kox6VKszKXQR4jJbZySGLELzwMmnjSSgiaORA8SqBlPlYgnqP+BUAX/Oi3qnmpucZVdwyR6iomvYVnMPzkhgrMEJVSegJ/L86rwaY0E8MizKAg+fC4LdeOuMc8dxUwtp0nkMU6pFK+9xsywPGQDnvj0oAlNzbhWYzxAIdrHePlPoab9stdzr9ojBTG7LDjPSqdvpHktGWkVxEy4+U5IGeuT15p0OleU0eZFZUKNjZ1Kgj+v6UaBqWzdQAgCVWO8JhTnDHsfSmteQrOYfnLKQGIQlVJGQCaqw6VIlwJnuA5DKfunnBJ9eOvapZrGSW8E4kRACOQmHx/dznkH3oAltr2G6IWPeCy71DoV3L6j1oN9biVIi5DvKYgMfxAZP6VBBpzbI0upElWKLykVFKjHGSeevApk+kCSSV45vK3IojG3PlsMfN+QH5UBqWY7+2lkjjVzukQyKCpGVFLb31vdLE0L7hMCU4x0659OtVv7JCyiVJ3V0Zdg/hCgbcEfQnn3p1tpf2a4hlWXIji2Mm3hmwBu9uBRoGpM9/bpEJGc7SWH3Tn5c7uPbBpo1O13ojM8bu4QK6EHJGR+dRy6YJJbl/Nws0bKq7fuMwwx/HA/WlbSrc+WuDtGd+4li+V29Sc8UaBqWVuImiaXeFRSQzNwBg4P60puIBjM8fK7h845Hr9Kqpp7rYJbmcPIkvmh2XhjuzyKYuk4ST94hd9pzs4BDlsY/u5PSgC0Ly2aVYhMhZlDL8w+YHPT16GnG4gCuxnjAjOHO8fKff0qsdOMhZ3eMOwT7keAMOW4qFNHKRlRIjEYCMQ2QASeeevPagC6Ly1LOouI8oQGG4cEjIoa8tVIBuI8s/ljDA/N6fWq8OmtHNHI8qybCrH5MEkIV+nvUUWkyxyiVrhXcMh5Q843e/H3u1AF9LmF9v7xVZl3hGYBseuKVZ4XQukqMi9WDAgfjWeujsqCPzl2cEnZ82Qu3rnpVmGwSJJkJBSWNUIC46LigCd54oxkuD823AIzn/JqKPULSZlWO4Ri4yvP3uSOPfIqpDovlnc1xvYhSSV6sGBZvxCgfhThpPyFTIpO0KpCdAH3f/Wo0DU0qKDRSGFFFFADJPu/jUVSyfd/GoqAPmW/ONWuj6XMnbP8AGatyahEJ9+8TAoxIKkqHzlCM8jnt0HSqeo/8hS8/6+JP/QjUuj2cF/qkNtdSvDC24u8a7iAAT6HHTrjjr2piJVvlEVuzXD+ZG6EhARwCd2R0z7jr3p0d/GFjZpW3LcGQ5LZI3AjjoenetSXwTO83+jTiJZObdJzuaRQqszb0yuMOMHjPoKf/AMIKwtpGOqRGQzeTARG4WRwZAynIyDmPg9OaAMW9u7WW0MVupUvMJmBXGGIOR9Bxis6umj8DXkkqx/brYNko42vkSYQ7Bx8xw45HvVSz0W1bTEuLv7c8s88sESWkQfy2jUElweTnPQY4BNAGJRXTt4Fuo5Nk2p2abdqyY3NsdmVQuAM9XXnp1pZ/BMkfkiPUY2eXyk2GFyfMcMSBgdAFJz7UAcvRW3r/AIcbQba1aS4E0k7uMp9zaFRlI+ofn6ViUAFFFFABSj7w+opKUfeH1FAH0hdf8hGz/wB1a2E+4Kx7r/kI2f8AurWwn3BSGZr6qY7+ZWBa3RWVcIeXUbj83T1GPamjVpYnla4SPy12geW2dpKkjnHOTx+VanlpgDYuAdwGO/rTVt4EUqkMaqSCQEAGR0piM+TWHidkMCkhT0c/eGMgnHv29KkXUZWlMPkxCRC3mbpcLgEDg4681cNvCXLmGMu3VtgyaGghcgvDGxB3DKg4PrQBQGruxO23ADNtjZmIGd235uOPwzSi9nbT/NLIjtcGIuOVQb9uferpt4CXJgjJk+/8g+b6+tOEUYjMQjQRnqm0Y/KgDPl1CS1PlKy3jgsSR8uAAODjjPPsKbPqtwscjRwxr9/yyzk/dYA5GPetD7NbmNY/s8WxTlV2DAP0pxijYEGNCDnIKjv1/OgDPn1WSGORzDGdruoXeSWCfePSllvZv7OuJ0PzrNsTCjOCwHfjPNXmt4HUK0MbKDkAoCAad5abSuxdpOSMcZoAzzeXEM0cO1ndwoAmKrgktydufSmLrJ2NK9vthHO7PQZxzx1zitMojMGKqWHQkc037PCC58mPL/f+QfN9fWgDNOtN9nMgt1DrwyMxzuAyw4Hbj86nsr2S5vChI8shiBjkfdx/6EatvBDIMPDGwzuwVB59acsaKcqiqfUDFAGNb6tcBd8m6TKD5WQKMl9oIxyR1z+HrVgatJn5rdVCBTIC/wA3LFflGOemeavmGIrtMSFcYwVGMelMWztlmEohQMAAvyjC4z09OpoApjVZG2BYEJl2mP8Aedi235uODTf7SuEb50jZt7oFVsA4dVGeM960VghUlliRSx3EhRyfWl8mLcW8pMk5J2jk/wCQPyoAzn1eRA2YI90f+sBkxn5yvy8c9M1bv5XihTypAheZELYBwCcHrRcWEFy6NIDhDnaMAHnNSC2hEPkmNWjznawyM5z396AM3+0LmO5VSyzRRM/msq8uo28jHcbjnHoaSG/uHWCZ51ETKmSiqeWP8Q6gHjBFaqxRoFCxqoUYACgYHpTfs0G5G8iPcgwh2D5fp6UAU57i7/tNoIN5CiM7QgK4JO7ceo4FMGrSeWshgjC7PMI8znbnAxxyf/rVphQGLAAMepxyaYYIW2ZiQ7PuZUfL9PSgDOTVZwVR4EdssW2E/d3lRjjrx3p51Gd1jeOOELJKqjdJltpbByMcGrpt4CQxhjJDbgSg4Pr9aX7PBlj5MeXOW+QfMfegDPi1VyqkxhlG0OWbDEsTjAxz/n0qzZXr3ORLGsZMaSLtfOQ2cD68VP5EO5X8mPcowp2jI+lBgiLI3lqDGcrgYxgED+ZoAzbrUbi3uLhSV8sSJHE2PusdpIP1BOPpTZL+5itzMLhXZ/OAj2j5Nu7B/QZz61rGONgQyKQxBOQOSOhpq28ClysMYL/eIQfN9fWgChDeXBsr2RmbdAp2GRArA7c8gdumKPt81vbRySKz7jlmlKjYMD+5nj/JrR8tDu+RfmGG46j3qMWlqFCi2hAByAIxwfWgClJqzI7x+Su/eFjG4nOTjJwOn0z6Uq6pM5XFsqj5A25+QWJAxx0yP1q6baA78wR/vPv/ACD5vr604RRqAFjQAYwAo7dKAMtdWmSAPIsbSNEj7ATjkMTjAz2708aq4G8opjaT7zHGxcKRnAP97r0q+bW3K7TbxFc5xsGP88mlNvA23MMZ2nIyg4NAalO7u7i3vyBtMSxrhS2MszbQSccAU+2vpLi58nykGwHzGD55BI+XjnpVto0fO9FbcMHIzkelIkccYASNUAGBtGMD0oGZy3dyftEjNIESYopCoFxvC8Hrn60f2vL+7/0UHeu/AYn5d2PTr+laWxMFdi4JyRjv601oIW27oY22HK5UfL9KBFBNZDT+SYdpztJLcAjO/wDIYP41DJrEzxkoqxsuc9SCCuR1ArW8uPO7y1zknO0dT1pq21ugwsEaj0CCgBLu4+zwl12ltwVQSeSTjHAJqlFq7yqkgtwI/k3/AD/MCxI4GOeRV4W8IiMXlqyEklWGcknJ/WnLDEoAWNFAxwFA6dKAKVpfTXMz7hGqfZ1lQK27GSevvxUVre3TWsDkeZLOQB5hVVHyk5G3Jxx3rRSGKIsY4kQt97aoGaSO2gi/1cEac5+VAKAM+LVpCxleNBbsVAJbBTMe705HXmgavMysFt03puLAuQMBQ3GRnoa0vKiAwI0x6bR9P5UiW8EYwkMaj0CAUAUm1UiKWfyVMSZAG/5yRjtjpzUM+rXC28u2FI5Y0ZmLtxgHHygjnr0OK0/Ih3F/Jj3MNpO0ZI9KT7LbbVX7PFtXlRsGBQBV1C4mgkUpKEjWMu+0KzDnqQeq9enNNm1YRpuWNWbLjBfH3WC/1zV2SGKUqZIkcr93coOKZLZ28wcPCmXxuYKATyDyfwoApNq0il18mLdErtJ+94O0jO3jnrSvqzrllgUqxZYwXwchgp3DHHWrhsrYyI/kJ8i7VXaMDnPA9c0/yId7P5Sbm+820ZP1oDUhtZ5pJbhJ/KUxyBFCE8/KD3+tWqZ5UfmeZ5ab853bRn86fSGFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAyT7v41FUsn3fxqKgD5k1H/AJCl5/18Sf8AoRpLH7Z9si/s/wA/7UDmPyM78+2OaXUf+Qpef9fEn/oRqxoepJpOqx3skJmVI5FMecbtyMvPtzzTEEmqaxZXcqXF3dxzGRZJop3YbmXBG9T16DrU8k/iLVWOol76cSyEq6MxG4H+H6FscdM1pQeM90MEd1b7CgkVnt41/dgoqRFA2SSmD1Pf1q4vjy0F7FL/AGfKIYVcRxqUG0mVX3D0OAQcdzQByq61qSFCup3SmJPLTE7fIv8AdHPA4H5VHDf3ltFLDBdzxRzj96iSECT6gda62DxppaS2pbTWSOKLYyJEmV4UEK2c4O0nPHXoec8bIytK7KpVWYkAnoM9KALD6nqEior31ywRQqgyscAEEAc9iAfwFH9qah+6/wBPuf3Lbo/3rfIeeRzx1P5mqtFAE1xe3V4Qbq5mnIJI8xy2M49foPyqGiigAooooAKUfeH1FJSj7w+ooA+kLr/kI2f+6tbCfcFY91/yEbP/AHVrYT7opDHUUxRlQSzfnS7f9pvzoAdRTdv+0350bf8Aab86AHUU3b/tN+dG3/ab86AHUU3b/tN+dG3/AGm/OgB1FN2/7TfnRt/2m/OgB1FN2/7TfnRt/wBpvzoAdRTdv+0350bf9pvzoAdRTdv+0350bf8Aab86AHUU3b/tN+dG3/ab86AHUU3b/tN+dG3/AGm/OgB1FN2/7TfnRt/2m/OgB1FN2/7TfnRt/wBpvzoAdRTdv+0350bf9pvzoAdRTdv+0350bf8Aab86AHUU3b/tN+dG3/ab86AHUU3b/tN+dG3/AGm/OgB1FN2/7TfnRt/2m/OgB1FN2/7TfnRt/wBpvzoAdRTdv+0350bf9pvzoAdRTdv+0350bf8Aab86AHUUxRlQdzdPWl2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6imAZz8zdfWl2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6im7f9pvzo2/7TfnQA6imMMAnc350+gBkn3fxqKpZPu/jUVAHzJqP/IUvP8Ar4k/9CNWND01NW1VLKSUxK8cjb/QqjMM+3HPtVfUf+Qpef8AXxJ/6Eas22nyHy3hnkSRxgbAc8jGOPXOK3pUKlZtQV7GVSrClrNmufBUklrazQX8LmeAMuMuryYdiAwHC7U6nvxUi+BSI3MmqRqSIvKkELeU25irZb2x/jis9NP1OF5bJLq8jYIY5IBuBCrklSueg54+tOhXVZ7hfJ1W8eZlCLtlbJA5A69O9b/2fiP5fxX+Zj9co9/wY6z8H3l5rV1pazrG9uFPmPGwVt2Nv0zn/DNTHwTMkfmvqMPlxoGuCsTkxZRGAAx82Q46dOaqQwah5k91DqN0JCuZ5VchiM4+Y555xSJDfwlZ01K6jOSFkDsOQMHBz6YH0p/2fif5fxX+YfXKHf8ABll/CMkupava2lyD/Z0xjRHUl5cZOeOnA59KkufBD2Qd7nWLRESVIWYIzbZGYrg46DIJz6VTgstQlMyW97dMbggTbGb94T03c85561HPFd3K7LjUriZQANsjlhx06ntzR/Z+J/l/Ff5h9cod/wAGaT+B7iC0ka6uUhmt2JucKz+Su3O3aBlm5U8HoaYngi4aOB31K1j875sMGBCfNg4IBydh4OMZGe+KSJfRzecmqXSy7t28SNuzjGc5644+lKn9oRhQmrXShGLqBI3DHqevU5P5mj+z8T/L+K/zF9dofzfgzNv7OTT7+ezmz5kEhRsqV5HseRVetJ9OaV2kkuWd2OWZhkk+pOab/ZY/57H/AL5o/s/E/wAv4r/MPrtD+b8GZ9KPvD6ir/8AZY/57H/vmlGljI/fHr/do/s/E/y/iv8AMPrtD+b8GfQF1/yEbP8A3VrYj+6Kx7r/AJCVn/urWxH90VwHYQ3ORp8xW5FqRGxE5AIi4+8c8cdea4iy8b6qdJm1GeKCaVZUh+ygMgjTYWM5G0uwcDIABwPoa7p4Yri3MM0aSxOMMjrkMPQjvUN1pOm32ftmn2txkAHzYVbIHQcjtk/nQBydt401WW5dRa2E8Ul06xGOZvlhSFZSfu/MSDx0yT2qBPiTPJpjXH9lIkzbXhR3kxIhRn4wmSwC8nG3nOa7ZNPsY7n7THZ26T4A81YgG4GBz9OPpVc6BorQtCdIsTE7+YyG3Tazf3iMdaAOXfx5qMgM1ppVq0DBvLMt0wbKwLO2QFI+62B7+1WPEeuap52krpEl1Gb6zlnWK3t0mZnAQoG3cBfmOTxXTjTrELtFlbgc8CJe67T2/ujH04qUW8CvG4hjDRKUjYKMopxkD0HA/KgDkV8X6wJDbyafYJP9oa2DyXTInmRxh5Cx2nA5wBz69KpL8QtQ2yzDT4ZEuJoltIwz7kDQCU79qknjpgfoK7WfTNPuoXhuLG2mikfzHSSJWVn/ALxBHJ96bPpGl3W/7Rp1pN5gVX3wqdwX7oPHbt6UAcrN441C50q+vbCys4Fggbat1c4lEgiEn3APmXBxwcnGelM/4Ta/tjdxywW001uJJ5d9xsjEaJGWWM7csxL8A/nXXf2VppuBcf2fa+cI/KEnkru2YxtzjpjjFM/sXSTFHCdLszHE++NDAuEbAGQMcHAHPtQBj6P4qudS1lLWWwiitbh7hLeRZSZMxEA71IAGQ3YnpWVbeOb61hb7dBa3AeedYXjmwwVLgRnzFxhRhhg+3PWu1W0tkkEiW8SupZgwQAgt9459+/rUC6PpaNOyabaK1yCs5EC/vQeobjn8aAOZuPHd0t5cJb6fby29pI/nSG4IYoswiyoCkE85xntiqVz421Sa/t2g+z29pNgoiMJJCouY4jvBHynBbgZ6+ortY9J02GIxRafaxxkbSiwqBjOcYx68/WkXSNLW4kuF020E0rBpJBCoZiCCCTjk5AP1FAGN4U8WyeJJplfT2tkEazRPkkMhJGDkD5uO2Rz14rpar21hZWckslrZwQPM26Voowpc+px1qxQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABSUtJQBz/im91G0gsl064ERkdvNWMxeeyhc/uxIQrYOCR1x0rBi8d6jHa3E7CxvEzCLUgSRvKGh8xiUCsRwDx0HPOBXbXVhZajbLDfWkF1EMMEmjDgH1wajn0XSbrP2jS7OXKqp3wKeF+6OnQdqAOX0nxveXlzvure1jtLiYLDiUholNt53zZGD6Z9z6Va0PxlLq2q2tpLZQ28V1bLLE3nFmdjGHIGFxxnGCQeM4xW9JoukyqyyaZZurBVIaBSCF+6Onbt6U6HStOt7oXUNhbRThBGJUhUMFHAGQOlAFuiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKAMLxbqF3pnh6S5sZGjn+0RRhlVScNIqnG75c4J68Vn/APCT3mnXel6ZcRm4m1HdsluZY0ePax3bxHlemNuDyeOK6ae1t7y3e3uoIriFj80cqBlPPcGoY9G0uGEwxabaxRsACqQqBwcjt2JyPfmgDjv+E/vJILSSS1ghaZEulW3uPMBjKyfI+V+U5QdPz4NTXHjzULd7OBrCzM91FGzCOZ2ETShjHk7AOwzzk846V0uneHNI0uxSzttPgEagZLRKWcgY3MccnBPPuasPpWmyXMVy+n2rTwqFilMKlkA6AHHGKAOOsPGmqP5EUsdnJd3UEEi75/Lt0zE0jfNtyCQBxzznsKv6X41uNT1C126bHHYXMyQLIZj5qu0HnDK4xjGR19DW+dE0hrc2x0qyMDEExmBdpIzg4x2yfzqwLO1DBxbQhg4cEIMhgNoP1xxn04oA4/VvGt1Z6r8iWsVjbXU0EvmTYkkZIS/K7TtUnGCMnjpzVUfEPUAWuZNPgW3tYbk3EW9w7vH5eNuVBA/eDIIz1PYZ7SXSNMnumuptOtJLh12NK8KlmXGME4zjHFJHoukwxpHFplmiRliirAoCkjBI47jg+tAFTw1rc2uWEs1xafZpYJjCyjO1sAHI3AEDnuK2KgtLK1sIBBZ20NtCCSI4UCLk9TgVPQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFADX+6adTX+6adQAyT7v41FUsn3fxqKgD5k1H/kKXn/XxJ/6Ea3tDvoNPurW8mjEwgG9Y92MsB8ufbODWDqP/ACFLz/r4k/8AQjVzw3p0Gq67BZ3Ku0TrIxCEgnajMOgJ6gdATXXhsT7By0vc569D2ttbWO0XxjZnzZWtZIp5kPneVIpWVjHs+Ytk4HB69SaX/hNLV5WMtp5ke4lULJ8vzkr27KdtZdx4AWVppbW5NtEFjaMTrleQm7LHDDBfoyg8c1B/whUDaddTC4uo5beYLie28t2TBBwhPIB+YtnhQeK6PrsP+ff4mP1Wf8/4GwfF9o8jM9pnD5jzsOxdyHGMf7Df99Utz4xt3gkSCOZGxIIy0inBcIC3sflPr97rWRF8PZWZlmu5o284xKFtCf8Alo6B254T5NxPoaq2PheK88GXmqqjvdwyOVKyDYI0xuY8e54zk5GBjNH16H/Pv8f+AH1WX8/4HTt40sPlRLWURDYSN6Zfa+4K3qMEjP6VAfF9qkX7i1KS7cI2UxB9z5U4+78pPPOTWVZ+FNMv9EtJI5ZIZ3tRcTzMpbALSZCrux0jI/Wq8Xg60ls47garIpkhEoVrbgAxGUZO7+6p/HFJY2C/5d/j/wAAHhZP7f4EV5cRXF7PPGFjSWVnVMj5QSSBUO9f7y/nWnN8PHt2iD6mknmMVxFFkjClz1YfwbG/4H7Uf8IBGl21rJqx8xd7EJbZ+VZPLyBuyTnkjsK6FmzStyfj/wAAxeXJv4vwMzev95fzo3r/AHl/OsSeLyLiWHcr+W5XcvRsHGRTMU/7Xf8AJ+P/AABf2cv5vwN7ev8AeX86UMuR8y9fWsDFAHzD6ij+1n/J+P8AwA/s5fzfgfSN1/yErT6L/OtiP7orHuv+QjZ/7q1sR/dFeIeqKiAoDlvzp3lj+8351zfjHVb3SdNsZLK4FuZbgo7koOPLcgZcEDkDt7VjL8Qr9RJEbOFpI7RJC0m6La/7vduU9B85I6A46+gB3vlj+8350eWP7zfnXLaF4wutX15bBrBY4TCH3lir/cVt2087TuIHHasuDxJ4itdKtb+4WSeS5d9iShBGRzj7i7gM4688UAd75Y/vN+dHlj+8351xEvjrVoLm+i/seOb7HJ5TLG53bt2xTt64ZipB/unvUU/xA1Dy7XGmrA11vUI27euMpuGRg4dW454x0zQB3nlj+8350eWP7zfnWP4T1G81PSGuL5t0omZc7NvAxjitugBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWB3b86PLH95vzps1zb2+3z544t5wu9wufpmpaAGeWP7zfnR5Y/vN+dOVlcZVgwzjINI0iJjcwGSAMn16UAJ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5QHdvzo8sf3m/OiWWOFC8sixoOrMcClR1kQOjBlYZBByDQAnlj+8350eWP7zfnRJLHCheV1RB1ZjgChJopGKpIjMAGIDAnB6GgA8sf3m/Ojyx/eb86a11bqzq08YMYy4Lj5R7+lAubcsqieMsy7lG8ZI9R7UAO8sf3m/Ojyx/eb86IpY5k3xSLIp/iRgRT6AGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAGeWP7zfnR5Y/vN+dPooAZ5Y/vN+dHlj+8350+igBnlj+8350eWP7zfnT6KAInQBCct+dLSyf6s0lADJPu/jUVSyfd/GoqAPmTUf+Qpef9fEn/oRqOCKea4jitkkeZ22osYJYn0GKk1H/kKXn/XxJ/6Eam0bURpWpx3bRmVAro6q21trKVOD2ODxTEQ3kF9YTPa3qTwSHDNHKSM56Ejv9aEhvblTMizyjBy+Sc4xnnvwRx71v2fifT9O0+extbK5eNlCo9xIsjMNpBVhjCrk5AHQ+/NWT48Li58yG4YvcSSwL5i7YlbZgdOq7OMf3jQBz91/a2lxy2N009uJyDJGz8tsyBnntkjFU4zMYpPLMnloA0m0naOwJ/lXVTeNYLmOcPa3MMkpdjNDIm9gXdgjEqflw4B/3RVhvHlmI0ij0yby1jVWV5FO8K6OEbjlflI/4F0oA4oOw4DsO2AaNzf3m/OusvfGVreWmoW7WczfaogiMSinIBALEcnGenOcdq5KgByySKwZZHDA5BDEEUCWRWDrI4YdGDHP502igAooooAKUfeH1FJSj7w+ooA+kLr/AJCNn/urWxH90Vj3X/IRs/8AdWtiP7opDIrq6a0tUkWLzMnBJJAUc8nAPH4d6gGs2+0tLG6AyCPPBBOByCDyPmFW3t4rmFFlUkDkYYqR+IqI6VYkj/R1GMYAJA7f/Ej8qAK4122KA+VIJShbyyBnjJA/HBqRdVTyoi8ZErsFKeh+XPPtuFTDTrRW3LCAcEHDHBBz2/E0HTrMzed5I38c5Pt2/wCAj8qAIJNUEd7Pb+Wg8nbkljk5x2xjv60HW7MMoYSAldwynOOcce+DVxraFvM3Rg+YQX9yMY/kKYLG2WRHWIBkXaME9Oeo79TQBXOt2QjkkVmZY87sL74/oaltL9buWREQgIMhs/eGSP6Un9k2Hl+WLZQuAPlJHQEDp7Ej8aeljbxOjxp5ZU5+U4z16/maAKtxrIgWT9zl4i29S+AoBABzjvuB/Oo/7fVc+ZbkAIWDB8qxBIABx3wSD3rQaytnkkkaFS0oUOf723pRPZW10HE8KyBwA2e4ByPyNADL++Fiiu0ZdWyODjnBIH44xVaLWo5AGMLgEAYHzEt8uVx7FgKuGzheFYZVMqq+8bzk7gcg/nSLYWq42wKMOXGP7xO4n8wDQBVOu2fJDEqpO5iOgAbkevK4pya1aOQB5mdrMfl6Yzn69O2am/s2zww8gEMSSCSRznOB26n86P7NtDszETszty7HGc89evJ5oAltrhLqBZo87W6ZqWo4LeK2j8uFNq5JxnOSeSakoAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAztSsLi6u7SeBwPILbh5hTOcdwD6dKo3Wh38sUqRXi8ufKLMwKJg7eeeQzH8AORit+ipcUyHBMwpNI1EFlhuYlVmLkktwfn4wOx3jP0qODQLuL52nj8wqVDBjlV3lgAcDjB9q6GilyIPZo5i90e9gVI7bfMGICqHbEZwmWznrkN+f59PRRTUUhxilsFFFFUUFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAFW/t5LiFBFs3pKrgOSAcHOKz/7Gu/MDLdCPIY/uyQI2JYnaMcjkenStqigCglpMlgYVjhV92QA7ED3DHkHv0qOz0+axliZRG/7lIZCOOmTn37CtOigDKuNOuLi4mkIhA48gqxBU5BJPHUkDnnoOOtQDQZcorSqUxmTk/M2G9unzdiPpW5RQBS02zltIpPOk3ySPuODnHAHoPT0q7RRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAyT/VmkpZP9WaSgBkn3fxqKpZPu/jUVAHzLqQI1W8BGCLiT/wBCNVq7vx74QhsdTl1G3uiEu2MphMedrHrg56Z9q4Q8GmDCiiigQUUUUAFFFFABRRRQAUUUUAFKPvD6ikpR94fUUAfTMkVu00MkkgWRFXaNwGfT9avx/dFU2tLed7eeWFHlgGY3YcrkdquR/dFIY6NTsHzGnbT/AH2/Sub8X65eaDZ6ZcWZTEl6kcyMud8ZDZXPY9Oa5y9+IWq2dm8SxQSTLE5Ezj+LMhU4GBgBAMd85zQB6PtP99v0o2n++36VwkvxFuYLp7dtPicoCSwkIziXZ0wccc1UPxG1K6tdkNtBBKYZZDIMtjb5ZAAP/XTvnp70AejbT/fb9KNp/vt+lcpJruoapo+k3NrP/Z7300oYxoshVUjkYD5gR1QZOKwovibqC2iSSWNu7BwrEEjdiNXY+2d3HpjvQB6RtP8Afb9KNp/vt+lcBZ/EK/D20dzaQS+Y0m9lJQkb5AoHXGBHz1zntUFr8QdUvrqNfJhhj2IzCMckmSMcE5x8rkdPfjsAejbT/fb9KNp/vt+lect8UL0WiTf2bBlpDkbz93Yr4+vOM/jjtXo4OQDQAm0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igBu0/32/Sjaf77fpTqKAG7T/fb9KNp/vt+lOooAbtP99v0o2n++36U6igCORTsPzE0Usn+rNJQAyT7v41Akkcn3JFbjPynP8AnofyqeT7v41neTBZmX7PAkTTtvkZRjcfWmho/9k="></p></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-he6fz"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-he6fz "><div class="eb-advance-heading-wrapper eb-advance-heading-he6fz button-1 undefined" data-id="eb-advance-heading-he6fz"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Lưu ý khi Renew License Sophos Firewall </span></h2></div></div></div>



<p>Đối với các lần gia hạn (renew) license trong tương lai, cần lưu ý</p>



<p>&#8211; License Number: chỉ dùng để tracking và support, không dùng để activate.</p>



<p>&#8211; License Key: bắt buộc để kích hoạt hoặc renew license.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0vyql"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0vyql "><div class="eb-advance-heading-wrapper eb-advance-heading-0vyql button-1 undefined" data-id="eb-advance-heading-0vyql"><h2 class="eb-ah-title"><span class="first-title">1. Cơ chế đồng bộ license khi renew:</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Trong hầu hết các trường hợp, nếu Sophos Firewall đã được liên kết đúng Sophos Central account, license sau khi renew sẽ tự động đồng bộ xuống thiết bị mà không cần thao tác thủ công.</li>



<li>Tuy nhiên, nếu license không tự đồng bộ và vẫn hiển thị trạng thái <strong>Expired</strong>, bạn có thể thực hiện các bước sau:
<ul class="wp-block-list">
<li>Kiểm tra license trong Sophos Central hoặc Sophos Partner Portal để xác định License Key tương ứng</li>



<li>Thực hiện apply License Key thủ công cho thiết bị Firewall (theo hướng dẫn ở Mục II.3)</li>
</ul>
</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-zrgo3"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-zrgo3 "><div class="eb-advance-heading-wrapper eb-advance-heading-zrgo3 button-1 undefined" data-id="eb-advance-heading-zrgo3"><h2 class="eb-ah-title"><span class="first-title">2. Trường hợp không nhận được License Key:</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Nếu email gia hạn không chứa License Key, khuyến nghị:
<ul class="wp-block-list">
<li>Kiểm tra lại thông tin license trong Sophos Portal</li>



<li>Hoặc liên hệ Sophos Support / Partner để xác nhận chính xác License Key trước khi apply</li>
</ul>
</li>
</ul>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/moi-nhat-2026-huong-dan-activate-renew-license-sophos-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng Dẫn NAT Forwarding (Đổi Port) Sophos Firewall Version 21</title>
		<link>https://vacif.com/huong-dan-nat-forwarding-doi-port-sophos-firewall-version21/</link>
					<comments>https://vacif.com/huong-dan-nat-forwarding-doi-port-sophos-firewall-version21/#respond</comments>
		
		<dc:creator><![CDATA[Long Nguyen]]></dc:creator>
		<pubDate>Fri, 14 Nov 2025 03:20:57 +0000</pubDate>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=27950</guid>

					<description><![CDATA[Trong môi trường thực tế, đôi khi chúng ta không muốn (hoặc không thể) mở đúng port gốc của một dịch vụ ra ngoài Internet. Thay vào đó, chúng ta sẽ chuyển hướng port ngoài sang port nội bộ để: Kỹ thuật này gọi là NAT Forwarding, hay còn gọi là Port Forwarding hoặc PAT [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Tổng quan về NAT Forwarding</span></h2></div></div></div>



<p>Trong môi trường thực tế, đôi khi chúng ta không muốn (hoặc không thể) mở đúng port gốc của một dịch vụ ra ngoài Internet. Thay vào đó, chúng ta sẽ chuyển hướng port ngoài sang port nội bộ để:</p>



<ul class="wp-block-list">
<li><strong>Tăng bảo mật</strong>: tránh sử dụng những port phổ biến dễ bị quét (ví dụ: 3389 – RDP, 21 – FTP…)</li>



<li><strong>Giải quyết xung đột port</strong>: khi có nhiều dịch vụ trong mạng nội bộ cùng sử dụng một port giống nhau, nhưng cần ánh xạ ra ngoài bằng port khác nhau</li>



<li><strong>Giảm rủi ro tấn công tự động</strong>, đặc biệt là các loại botnet hay brute force</li>
</ul>



<p>Kỹ thuật này gọi là NAT Forwarding, hay còn gọi là Port Forwarding hoặc PAT – Port Address Translation. Trên Sophos Firewall, việc cấu hình NAT Forwarding cực kỳ linh hoạt, dễ dàng thông qua giao diện đồ họa.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-rjcs2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-rjcs2 "><div class="eb-advance-heading-wrapper eb-advance-heading-rjcs2 button-1 undefined" data-id="eb-advance-heading-rjcs2"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Tình huống cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Yêu cầu:</span></h2></div></div></div>



<p>Doanh nghiệp có một máy chủ nội bộ sử dụng Remote Desktop Protocol (RDP) với port mặc định là 3389, nhưng vì lý do bảo mật, muốn người dùng bên ngoài truy cập bằng port 1606 thay vì 3389.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-wacy1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-wacy1 "><div class="eb-advance-heading-wrapper eb-advance-heading-wacy1 button-1 undefined" data-id="eb-advance-heading-wacy1"><h2 class="eb-ah-title"><span class="first-title">2. Thông tin tình huống cấu hình:</span></h2></div></div></div>



<ul class="wp-block-list">
<li>IP WAN của doanh nghiệp: 123.20.40.173</li>



<li>Máy chủ nội bộ cần truy cập: 192.168.206.104</li>



<li>Port dịch vụ nội bộ (gốc): 3389 (Remote Desktop)</li>



<li>Port truy cập từ ngoài Internet: 1606</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-aq9re"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-aq9re "><div class="eb-advance-heading-wrapper eb-advance-heading-aq9re button-1 undefined" data-id="eb-advance-heading-aq9re"><h2 class="eb-ah-title"><span class="first-title">3. Sơ đồ tình huống cấu hình:</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="440" src="https://vacif.com/wp-content/uploads/2025/11/image-90.png" alt="" class="wp-image-27959" srcset="https://vacif.com/wp-content/uploads/2025/11/image-90.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-90-300x135.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-90-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-urf9e"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-urf9e "><div class="eb-advance-heading-wrapper eb-advance-heading-urf9e button-1 undefined" data-id="eb-advance-heading-urf9e"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Hướng dẫn cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-uoku1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-uoku1 "><div class="eb-advance-heading-wrapper eb-advance-heading-uoku1 button-1 undefined" data-id="eb-advance-heading-uoku1"><h2 class="eb-ah-title"><span class="first-title">1. Thêm IP Host</span></h2></div></div></div>



<p>Để NAT port dịch vụ ra bên ngoài, trước hết các bạn cần định nghĩa IP của máy chủ nội bộ và dịch vụ cần mở. Các bạn click vào menu Host and services trên Dashboard, tại mục IP host các bạn click chọn Add.</p>



<p>Trong bảng thông tin này, các bạn cần điền:</p>



<ul class="wp-block-list">
<li><strong>Name</strong>: Đặt tên cho host cần mở port</li>



<li><strong>Type</strong>: chọn&nbsp;<strong>IP</strong></li>



<li><strong>IP address</strong>: Nhập IP nội bộ của host</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-91.png" alt="" class="wp-image-27960" srcset="https://vacif.com/wp-content/uploads/2025/11/image-91.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-91-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-91-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-yvhlv"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-yvhlv "><div class="eb-advance-heading-wrapper eb-advance-heading-yvhlv button-1 undefined" data-id="eb-advance-heading-yvhlv"><h2 class="eb-ah-title"><span class="first-title">2. Định nghĩa dịch vụ</span></h2></div></div></div>



<p>Tiếp theo, bạn cần định nghĩa các dịch vụ sẽ sử dụng</p>



<p>Vào Services và click chọn Add</p>



<ul class="wp-block-list">
<li><strong>Name</strong>: Remote_Desktop</li>



<li><strong>Type</strong>: TCP/UDP</li>



<li><strong>Destination Port</strong>: 3389</li>



<li>tab <strong>Source Port</strong>: Để mặc định (1:65535), trừ khi có yêu cầu cụ thể</li>
</ul>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-92.png" alt="" class="wp-image-27961" srcset="https://vacif.com/wp-content/uploads/2025/11/image-92.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-92-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-92-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Vào <strong>Services </strong>và click chọn <strong>Add</strong><strong></strong></p>



<ul class="wp-block-list">
<li><strong>Name</strong>: Forwarding_1606</li>



<li><strong>Type</strong>: TCP/UDP</li>



<li><strong>Destination Port</strong>: 1606</li>



<li>tab <strong>Source Port</strong>: Để mặc định (1:65535), trừ khi có yêu cầu cụ thể</li>
</ul>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="441" src="https://vacif.com/wp-content/uploads/2025/11/image-93.png" alt="" class="wp-image-27962" srcset="https://vacif.com/wp-content/uploads/2025/11/image-93.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-93-300x136.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-93-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0emgw"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0emgw "><div class="eb-advance-heading-wrapper eb-advance-heading-0emgw button-1 undefined" data-id="eb-advance-heading-0emgw"><h2 class="eb-ah-title"><span class="first-title">3. Tạo NAT Rule</span></h2></div></div></div>



<p>Tiến hành tạo NAT Policy để ánh xạ port từ IP WAN về máy chủ nội bộ.</p>



<p>Để tạo vào PROTECT > Rules and policies > NAT rules > Add NAT rule > New NAT rule.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-94.png" alt="" class="wp-image-27963" srcset="https://vacif.com/wp-content/uploads/2025/11/image-94.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-94-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-94-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-9iqr2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-9iqr2 "><div class="eb-advance-heading-wrapper eb-advance-heading-9iqr2 button-1 undefined" data-id="eb-advance-heading-9iqr2"><h2 class="eb-ah-title"><span class="first-title">Cấu hình các thông số như sau:</span></h2></div></div></div>



<figure class="wp-block-table"><table><tbody><tr><td>Rule status</td><td>ON</td></tr><tr><td>Rule name</td><td>VACIF_NAT_RDP</td></tr><tr><td>Rule position</td><td>Top</td></tr><tr><td>Original source</td><td>Any</td></tr><tr><td>Original destination</td><td>#Port1 (WAN interface)</td></tr><tr><td>Original service</td><td>Forwarding_1606</td></tr><tr><td>Translated source (SNAT)</td><td>Original</td></tr><tr><td>Translated destination (DNAT)</td><td>WINDOW_SERVER_2025 (IP Host nội bộ)</td></tr><tr><td>Translated service (PAT)</td><td>REMOTE_DESKTOP (Dịch vụ đã tạo)</td></tr><tr><td>Inbound interface</td><td>VNPT_Port1 (GATEWAY PORT1)</td></tr><tr><td>Outbound interface</td><td>Any</td></tr></tbody></table></figure>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu rule.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="441" src="https://vacif.com/wp-content/uploads/2025/11/image-95.png" alt="" class="wp-image-27964" srcset="https://vacif.com/wp-content/uploads/2025/11/image-95.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-95-300x136.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-95-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-rqhak"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-rqhak "><div class="eb-advance-heading-wrapper eb-advance-heading-rqhak button-1 undefined" data-id="eb-advance-heading-rqhak"><h2 class="eb-ah-title"><span class="first-title">4. Tạo Firewall Rule</span></h2></div></div></div>



<p><strong>Mặc định</strong>, Sophos Firewall sẽ <strong>chặn các lưu lượng truy cập từ Internet vào mạng nội bộ (LAN)</strong>.<br>Vì vậy, sau khi cấu hình NAT policy, bạn cần tạo thêm một <strong>Firewall Rule</strong> để cho phép lưu lượng sử dụng dịch vụ (VD: Remote Desktop) được đi vào.</p>



<p>Để tạo vào <strong>PROTECT &gt; Rules and policies &gt; Add firewall rule &gt; New firewall rule</strong><strong></strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="463" src="https://vacif.com/wp-content/uploads/2025/11/image-96.png" alt="" class="wp-image-27965" srcset="https://vacif.com/wp-content/uploads/2025/11/image-96.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-96-300x142.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-96-768x365.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Cấu hình các thông số như sau</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Rule name</strong></td><td>VACIF_NAT_RDP_RULE</td></tr><tr><td><strong>Rule pos</strong><strong>ition</strong></td><td>Top</td></tr><tr><td><strong>Source zones</strong></td><td>WAN</td></tr><tr><td><strong>Source network</strong></td><td>Any</td></tr><tr><td><strong>Destination zones</strong></td><td>LAN</td></tr><tr><td><strong>Destination network</strong></td><td>#Port1</td></tr><tr><td><strong>Service</strong></td><td>Forwarding_1606</td></tr><tr><td><strong>Action</strong></td><td>Accept</td></tr><tr><td><strong>Log traffic</strong></td><td>Tích chọn để giám sát</td></tr></tbody></table></figure>



<p>Sau khi điền đầy đủ, nhấn <strong>Save</strong> để lưu rule.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="441" src="https://vacif.com/wp-content/uploads/2025/11/image-97.png" alt="" class="wp-image-27966" srcset="https://vacif.com/wp-content/uploads/2025/11/image-97.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-97-300x136.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-97-768x347.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-1cnab"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-1cnab "><div class="eb-advance-heading-wrapper eb-advance-heading-1cnab button-1 undefined" data-id="eb-advance-heading-1cnab"><h2 class="eb-ah-title"><span class="first-title">5. Kiểm tra NAT Forwarding</span></h2></div></div></div>



<p>Sau khi cấu hình xong, bạn có thể kiểm tra xem port đã mở thành công chưa bằng cách:</p>



<ul class="wp-block-list">
<li>Truy cập trang:<br><a href="https://www.yougetsignal.com/tools/open-ports/">https://www.yougetsignal.com/tools/open-ports/</a></li>



<li>Nhập port <strong>1606</strong>, nhấn <strong>Check</strong>.<br>Nếu hiển thị <strong>&#8220;Port is open&#8221;</strong>, nghĩa là NAT thành công.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="636" src="https://vacif.com/wp-content/uploads/2025/11/image-98.png" alt="" class="wp-image-27967" srcset="https://vacif.com/wp-content/uploads/2025/11/image-98.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-98-300x196.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-98-768x501.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/huong-dan-nat-forwarding-doi-port-sophos-firewall-version21/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Sophos Firewall Home Edition: Giải Pháp Tường Lửa Cho Chi Nhánh Nhỏ và Home Lab</title>
		<link>https://vacif.com/sophos-firewall-home-edition-giai-phap-tuong-lua-cho-chi-nhanh-nho-va-home-lab/</link>
					<comments>https://vacif.com/sophos-firewall-home-edition-giai-phap-tuong-lua-cho-chi-nhanh-nho-va-home-lab/#respond</comments>
		
		<dc:creator><![CDATA[Long Nguyen]]></dc:creator>
		<pubDate>Wed, 05 Nov 2025 04:12:50 +0000</pubDate>
				<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Hướng dẫn/Tài liệu]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://vacif.com/?p=27783</guid>

					<description><![CDATA[Sophos Firewall Home Edition là một thiết bị bảo mật đầy đủ chức năng, được thiết kế dành riêng cho người dùng cá nhân. Tuy nhiên, nó cũng là một lựa chọn tuyệt vời để làm router/tường lửa cho môi trường home lab. Bên cạnh chức năng định tuyến và kiểm soát lưu lượng, Sophos [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1019" height="536" src="https://vacif.com/wp-content/uploads/2025/11/image-20.png" alt="" class="wp-image-27790" srcset="https://vacif.com/wp-content/uploads/2025/11/image-20.png 1019w, https://vacif.com/wp-content/uploads/2025/11/image-20-300x158.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-20-768x404.png 768w" sizes="auto, (max-width: 1019px) 100vw, 1019px" /></figure>



<p><strong>Sophos Firewall Home Edition</strong> là một thiết bị bảo mật đầy đủ chức năng, được thiết kế dành riêng cho người dùng cá nhân. Tuy nhiên, nó cũng là một lựa chọn tuyệt vời để làm router/tường lửa cho môi trường home lab.</p>



<p>Bên cạnh chức năng định tuyến và kiểm soát lưu lượng, Sophos còn tích hợp nhiều công cụ bảo vệ mạng, giúp bảo vệ hệ thống home lab. Điều này có nghĩa là ngoài việc học tập, thử nghiệm kỹ thuật, người dùng còn có thể yên tâm rằng hệ thống mô phỏng của mình không dễ dàng bị tấn công từ bên ngoài.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-oiy73"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-oiy73 "><div class="eb-advance-heading-wrapper eb-advance-heading-oiy73 button-1 undefined" data-id="eb-advance-heading-oiy73"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Sophos Firewall Home Edition là gì?</span></h2></div></div></div>



<p>Nhiều hãng tường lửa và bảo mật lớn thường tung ra phiên bản gọi là “home edition”. Đây là một chiến lược thông minh, bởi vì nhiều chuyên gia IT trong doanh nghiệp thường sẽ cài đặt thử nghiệm những sản phẩm này tại nhà. Khi đã quen thuộc và đánh giá cao tính năng, họ có xu hướng đề xuất cùng giải pháp đó cho doanh nghiệp trong công việc hàng ngày.</p>



<p><strong>Sophos Firewall Home Edition</strong> chính là một giải pháp bảo mật như vậy. Người dùng có thể lựa chọn chạy trực tiếp trên phần cứng riêng (bare metal) hoặc chạy trong máy ảo (VM). Sản phẩm được thiết kế chuyên biệt cho người dùng cá nhân nhưng vẫn kế thừa công nghệ và danh tiếng của Sophos trong mảng bảo mật doanh nghiệp, giúp mang lại trải nghiệm chuyên nghiệp ngay trong môi trường gia đình.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="928" height="577" src="https://vacif.com/wp-content/uploads/2025/11/image-21.png" alt="" class="wp-image-27791" srcset="https://vacif.com/wp-content/uploads/2025/11/image-21.png 928w, https://vacif.com/wp-content/uploads/2025/11/image-21-300x187.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-21-768x478.png 768w" sizes="auto, (max-width: 928px) 100vw, 928px" /></figure>



<p>Không chỉ dừng lại ở việc <strong>chặn hay cho phép gói tin dựa trên các rule định sẵn</strong>, Sophos Firewall Home Edition còn mang đến <strong>một bộ tính năng bảo mật nâng cao</strong> giúp bảo vệ toàn diện cho mạng gia đình.</p>



<p>Các khả năng nổi bật bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Web Security</strong>: giám sát và ngăn chặn truy cập đến các website nguy hiểm hoặc chứa mã độc.</li>



<li><strong>Application Control</strong>: kiểm soát ứng dụng nào được phép chạy trong mạng, hạn chế rủi ro từ phần mềm không mong muốn.</li>



<li><strong>URL Filtering</strong>: lọc truy cập theo danh mục trang web (ví dụ: chặn nội dung người lớn, mạng xã hội, hoặc trang tiêu tốn băng thông).</li>



<li><strong>Anti-malware</strong>: tích hợp công cụ chống mã độc, giúp ngăn chặn virus, trojan, và các mối đe dọa khác.</li>
</ul>



<p>Bạn có thể tải xuống tại đây: <a href="https://www.sophos.com/en-us/free-tools/sophos-xg-firewall-home-edition">Free Home Firewall | Sophos Home Edition Firewall.</a></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bzgrb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bzgrb "><div class="eb-advance-heading-wrapper eb-advance-heading-bzgrb button-1 undefined" data-id="eb-advance-heading-bzgrb"><h2 class="eb-ah-title"><span class="first-title">1. Sophos XGS Firewall – nền tảng của giải pháp</span></h2></div></div></div>



<p><strong>Sophos Firewall Home Edition</strong> được xây dựng dựa trên Sophos XGS Firewall, mang lại khả năng bảo mật nâng cao thông qua tính năng Synchronized Security. Với cơ chế này, các thiết bị kết nối trong mạng có thể trao đổi thông tin với nhau, từ đó tăng cường khả năng phản ứng tập thể trước các mối đe dọa tiềm ẩn.</p>



<p>Một điểm nổi bật khác khiến giải pháp này hấp dẫn chính là sự thân thiện với người dùng. Firewall có thể được cài đặt trên một máy tính chuyên dụng hoặc chạy dưới dạng máy ảo (VM), đồng thời hoạt động trên hệ điều hành riêng biệt của Sophos, giúp đảm bảo tính ổn định và tối ưu cho bảo mật.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-l1ksc"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-l1ksc "><div class="eb-advance-heading-wrapper eb-advance-heading-l1ksc button-1 undefined" data-id="eb-advance-heading-l1ksc"><h2 class="eb-ah-title"><span class="first-title">2. Traffic Shaping – Quản lý &amp; ưu tiên băng thông</span></h2></div></div></div>



<p>Một tính năng được nhiều người dùng đánh giá cao chính là traffic shaping. Cơ chế này cho phép ưu tiên loại lưu lượng quan trọng, chẳng hạn như gaming traffic, giúp đảm bảo hiệu năng ổn định ngay cả khi mạng đang chịu tải nặng.</p>



<p>Traffic shaping đặc biệt hữu ích với các nhu cầu dịch vụ streaming, cuộc gọi video (video calls), hoặc những người đam mê chơi game online. Nhờ khả năng phân bổ băng thông hợp lý, người dùng sẽ có trải nghiệm mượt mà hơn, không bị giật lag hay suy giảm chất lượng kết nối khi nhiều thiết bị cùng sử dụng mạng.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-qqc80"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-qqc80 "><div class="eb-advance-heading-wrapper eb-advance-heading-qqc80 button-1 undefined" data-id="eb-advance-heading-qqc80"><h2 class="eb-ah-title"><span class="first-title">3. Các tính năng mạng cốt lõi</span></h2></div></div></div>



<p>Sophos Firewall cung cấp đầy đủ các tính năng mạng cơ bản mà người dùng và quản trị viên mong đợi, bao gồm:</p>



<ul class="wp-block-list">
<li><strong>Layer 2 VLANs</strong>: hỗ trợ phân chia mạng ảo ở tầng 2, giúp tách biệt và quản lý lưu lượng hiệu quả.</li>



<li><strong>Layer 3 Routing</strong>: định tuyến ở tầng 3, cho phép kết nối và điều phối lưu lượng giữa các mạng con.</li>



<li><strong>Source &amp; Destination NAT</strong>: dịch địa chỉ mạng nguồn và đích, hỗ trợ ẩn địa chỉ IP nội bộ và quản lý truy cập từ bên ngoài.</li>



<li><strong>Port Forwarding</strong>: chuyển tiếp cổng, cho phép truy cập dịch vụ nội bộ từ Internet (ví dụ: web server, game server).</li>



<li><strong>Network Firewall Filtering</strong>: lọc lưu lượng mạng theo rule để tăng cường kiểm soát và bảo mật.</li>



<li><strong>Application Control</strong>: kiểm soát và quản lý việc sử dụng ứng dụng trong mạng.</li>



<li><strong>IDS/IPS (Intrusion Detection &amp; Prevention System)</strong>: hệ thống phát hiện và ngăn chặn xâm nhập, bảo vệ trước các tấn công khai thác lỗ hổng.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-ls6nz"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-ls6nz "><div class="eb-advance-heading-wrapper eb-advance-heading-ls6nz button-1 undefined" data-id="eb-advance-heading-ls6nz"><h2 class="eb-ah-title"><span class="first-title">4. Miễn phí cho người dùng cá nhân</span></h2></div></div></div>



<p>Sophos Firewall Home Edition được cung cấp hoàn toàn miễn phí cho mục đích sử dụng tại gia. Mặc dù tích hợp nhiều tính năng cao cấp và khả năng bảo mật tiên tiến vốn thường chỉ thấy trong các giải pháp doanh nghiệp (business-grade), Sophos vẫn mang đến cho người dùng cá nhân mà không thu phí.</p>



<p>Điều này thực sự ấn tượng, bởi nó cho phép bạn vừa trải nghiệm trực tiếp các tính năng enterprise vốn có trên thiết bị Sophos XGS trong môi trường data center, vừa rèn luyện kỹ năng quản trị – bảo mật, đồng thời vẫn bảo vệ tốt cho mạng gia đình.</p>



<p>Khác với nhiều bản “home edition” khác thường cắt giảm tính năng hoặc giới hạn số lượng client được phép kết nối sau firewall, Sophos Firewall Home Edition không áp dụng những giới hạn này. Nhờ đó, bạn có thể sử dụng trong home lab với quy mô gần sát thực tế doanh nghiệp, thay vì bị bó hẹp ở mức độ thử nghiệm nhỏ lẻ.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-v84wl"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-v84wl "><div class="eb-advance-heading-wrapper eb-advance-heading-v84wl button-1 undefined" data-id="eb-advance-heading-v84wl"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Quy trình cài đặt: Khởi chạy Sophos Firewall Home Edition</span></h2></div></div></div>



<p>Việc cài đặt Sophos XGS Firewall Home Edition yêu cầu một máy tính chuyên dụng, và được thực hiện khá đơn giản thông qua tập tin ISO. Người dùng có thể cài đặt phần mềm này trực tiếp trên máy vật lý (bare metal) hoặc trên máy ảo (VM).</p>



<ul class="wp-block-list">
<li>Khởi động từ ISO.</li>



<li>Thực hiện quá trình cài đặt dạng text-based (giao diện dòng lệnh hướng dẫn từng bước).</li>



<li>Cấu hình mạng cho các card mạng (interfaces).</li>



<li>Kết nối đến giao diện quản trị web (Web UI).</li>



<li>Hoàn tất và tùy chỉnh cấu hình theo nhu cầu.</li>
</ul>



<p>Dưới đây là ví dụ về một phần giao diện cài đặt dạng text-based.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="821" height="457" src="https://vacif.com/wp-content/uploads/2025/11/image-22.png" alt="" class="wp-image-27792" srcset="https://vacif.com/wp-content/uploads/2025/11/image-22.png 821w, https://vacif.com/wp-content/uploads/2025/11/image-22-300x167.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-22-768x427.png 768w" sizes="auto, (max-width: 821px) 100vw, 821px" /></figure>



<p>Ở đây, bạn sẽ thiết lập địa chỉ IP cho interface, từ đó có thể sử dụng địa chỉ này để kết nối vào giao diện quản trị web (Web UI) và tiếp tục tinh chỉnh hệ thống bằng GUI trực quan.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="521" src="https://vacif.com/wp-content/uploads/2025/11/image-23.png" alt="" class="wp-image-27793" srcset="https://vacif.com/wp-content/uploads/2025/11/image-23.png 975w, https://vacif.com/wp-content/uploads/2025/11/image-23-300x160.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-23-768x410.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Khi đã cấu hình địa chỉ mạng xong, bạn có thể truy cập vào https://&lt;IP hoặc hostname>:4444 để bắt đầu trình hướng dẫn thiết lập ban đầu (initial setup wizard).</p>



<p>Trong wizard này, bạn sẽ tiến hành các bước cấu hình cơ bản như:</p>



<ul class="wp-block-list">
<li>Thiết lập mật khẩu quản trị.</li>



<li>Tinh chỉnh một số thông số cấu hình quan trọng khác để firewall sẵn sàng</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="916" height="555" src="https://vacif.com/wp-content/uploads/2025/11/image-24.png" alt="" class="wp-image-27794" srcset="https://vacif.com/wp-content/uploads/2025/11/image-24.png 916w, https://vacif.com/wp-content/uploads/2025/11/image-24-300x182.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-24-768x465.png 768w" sizes="auto, (max-width: 916px) 100vw, 916px" /></figure>



<p>Cuối cùng, bạn sẽ truy cập được vào giao diện quản trị đầy đủ của Sophos Firewall, nơi cho phép tiếp tục tùy chỉnh cấu hình trong môi trường đồ họa (GUI).</p>



<p>Tại đây, quản trị viên có thể dễ dàng thực hiện các thao tác như: tạo rule firewall, thiết lập NAT, quản lý VLAN, cấu hình IDS/IPS, áp dụng chính sách lọc web hoặc kiểm soát ứng dụng… tất cả đều thông qua giao diện trực quan thay vì thao tác dòng lệnh.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="979" height="673" src="https://vacif.com/wp-content/uploads/2025/11/image-25.png" alt="" class="wp-image-27795" srcset="https://vacif.com/wp-content/uploads/2025/11/image-25.png 979w, https://vacif.com/wp-content/uploads/2025/11/image-25-300x206.png 300w, https://vacif.com/wp-content/uploads/2025/11/image-25-768x528.png 768w" sizes="auto, (max-width: 979px) 100vw, 979px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-sjhz8"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-sjhz8 "><div class="eb-advance-heading-wrapper eb-advance-heading-sjhz8 button-1 undefined" data-id="eb-advance-heading-sjhz8"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Yêu cầu phần cứng cho Sophos Firewall Home Edition</span></h2></div></div></div>



<p>Việc chạy Sophos Firewall không đòi hỏi một cấu hình quá mạnh. Chỉ cần một máy tính chuyên dụng với tối thiểu 2GB RAM là có thể hoạt động, mặc dù để đạt hiệu năng tối ưu, khuyến nghị nên có nhiều RAM hơn và bộ xử lý đa nhân (multicore CPU). Nhờ sự linh hoạt này, Sophos Firewall trở nên dễ tiếp cận với hầu hết người dùng gia đình.</p>



<p>Tuy nhiên, cần lưu ý rằng Sophos Firewall Home Edition có giới hạn phần cứng tối đa như sau:</p>



<ul class="wp-block-list">
<li>4 nhân CPU</li>



<li>6GB RAM</li>
</ul>



<p>Mặc dù những giới hạn này có thể hơi “hụt hẫng” với một số người muốn build lab lớn, nhưng với phần lớn nhu cầu kết nối Internet gia đình, cấu hình này hoàn toàn đáp ứng tốt.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-h0v3i"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-h0v3i "><div class="eb-advance-heading-wrapper eb-advance-heading-h0v3i button-1 undefined" data-id="eb-advance-heading-h0v3i"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Tương lai bền vững: Bảo vệ mạng gia đình với Sophos Firewall</span></h2></div></div></div>



<p>Sophos Firewall Home Edition được Sophos phát hành các bản cập nhật thường xuyên, đảm bảo hệ thống luôn được bảo vệ trước những mối đe dọa mới nhất. Điểm đáng chú ý là dịch vụ cập nhật này hoàn toàn không yêu cầu phí thuê bao.</p>



<p>Ngoài việc tăng cường khả năng bảo mật cho kết nối Internet, Sophos Firewall còn cho phép quản lý và phân bổ tài nguyên mạng hiệu quả, biến nó trở thành lựa chọn lý tưởng cho một home lab an toàn và ổn định.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-a3gik"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-a3gik "><div class="eb-advance-heading-wrapper eb-advance-heading-a3gik button-1 undefined" data-id="eb-advance-heading-a3gik"><h2 class="eb-ah-title"><span class="first-title">V &#8211; Sophos Firewall Home Edition – Lý tưởng cho Home Lab</span></h2></div></div></div>



<p>Tôi đã bắt đầu sử dụng Sophos Firewall Home Edition trong home lab của mình và phải nói rằng đây là một giải pháp tuyệt vời. Với tôi, nó hoạt động khá trực quan, dễ làm quen, và tôi có thể triển khai hầu hết những gì mình mong muốn.</p>



<p>Việc ngừng sử dụng Sophos không phải vì gặp vấn đề hay hạn chế nào đặc biệt, mà đơn giản chỉ vì tôi muốn thử nghiệm một giải pháp khác để so sánh và mở rộng trải nghiệm.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/sophos-firewall-home-edition-giai-phap-tuong-lua-cho-chi-nhanh-nho-va-home-lab/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng Dẫn Cấu Hình QoS Ưu Tiên Microsoft Teams Trên Sophos Firewall</title>
		<link>https://vacif.com/huong-dan-cau-hinh-qos-uu-tien-microsoft-teams-tren-sophos-firewall/</link>
					<comments>https://vacif.com/huong-dan-cau-hinh-qos-uu-tien-microsoft-teams-tren-sophos-firewall/#respond</comments>
		
		<dc:creator><![CDATA[Long Nguyen]]></dc:creator>
		<pubDate>Thu, 21 Aug 2025 03:38:03 +0000</pubDate>
				<category><![CDATA[Case study]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://new.vacif.com/?p=26372</guid>

					<description><![CDATA[Microsoft Teams hiện đang là nền tảng phổ biến cho các cuộc họp trực tuyến (Meeting) và làm việc từ xa. Để đảm bảo chất lượng đường truyền cho các cuộc họp Teams, việc thiết lập QoS (Quality of Service) trên firewall là rất cần thiết. Trong bài viết này, chúng ta sẽ thực hiện [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-7iftb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-7iftb "><div class="eb-advance-heading-wrapper eb-advance-heading-7iftb button-1 undefined" data-id="eb-advance-heading-7iftb"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Giới thiệu</span></h2></div></div></div>



<p>Microsoft Teams hiện đang là nền tảng phổ biến cho các cuộc họp trực tuyến (Meeting) và làm việc từ xa. Để đảm bảo chất lượng đường truyền cho các cuộc họp Teams, việc thiết lập QoS (Quality of Service) trên firewall là rất cần thiết.</p>



<p>Trong bài viết này, chúng ta sẽ thực hiện cấu hình QoS ưu tiên lưu lượng Microsoft Teams trên thiết bị <strong>Sophos Firewall</strong>.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-4es7f"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-4es7f "><div class="eb-advance-heading-wrapper eb-advance-heading-4es7f button-1 undefined" data-id="eb-advance-heading-4es7f"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Yêu cầu thực hiện</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Thiết bị Sophos Firewall đã hoạt động bình thường.</li>



<li>Quyền truy cập quản trị Sophos Central hoặc trực tiếp trên Firewall.</li>



<li>Đường truyền internet ổn định.</li>
</ul>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-d44tw"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-d44tw "><div class="eb-advance-heading-wrapper eb-advance-heading-d44tw button-1 undefined" data-id="eb-advance-heading-d44tw"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Các bước thực hiện</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0y5uy"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0y5uy "><div class="eb-advance-heading-wrapper eb-advance-heading-0y5uy button-1 undefined" data-id="eb-advance-heading-0y5uy"><h2 class="eb-ah-title"><span class="first-title">Bước 1: Đăng nhập Firewall Sophos và tạo application Team</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Đăng nhập vào Firewall Sophos.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-151.png" alt="" class="wp-image-26379" srcset="https://vacif.com/wp-content/uploads/2025/08/image-151.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-151-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-151-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-151-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Tiếp theo chọn Application-&gt;Application Filter -&gt; Add để tạo <strong>Microsoft Teams</strong> .</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-152.png" alt="" class="wp-image-26380" srcset="https://vacif.com/wp-content/uploads/2025/08/image-152.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-152-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-152-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Nhập name là: Mircrosoft Teams</li>
</ul>



<p>Nhấn add để vào Application filter policy rules</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-153.png" alt="" class="wp-image-26381" srcset="https://vacif.com/wp-content/uploads/2025/08/image-153.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-153-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-153-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Ở chỗ Category chọn: Conferencing -&gt; Select individual application -&gt; Mircrosoft Teams -&gt; Action chọn: Allow  -&gt; Schedule chọn: All the time -&gt; Save.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-154.png" alt="" class="wp-image-26382" srcset="https://vacif.com/wp-content/uploads/2025/08/image-154.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-154-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-154-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Xong phần thì nó sẽ hiện ra như thế này rồi mình nhấn Save.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-155.png" alt="" class="wp-image-26384" srcset="https://vacif.com/wp-content/uploads/2025/08/image-155.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-155-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-155-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-6nyg1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-6nyg1 "><div class="eb-advance-heading-wrapper eb-advance-heading-6nyg1 button-1 undefined" data-id="eb-advance-heading-6nyg1"><h2 class="eb-ah-title"><span class="first-title">Bước 2: Tạo Traffic Shaping Policy</span></h2></div></div></div>



<ul class="wp-block-list">
<li>Chọn vào System service-&gt;Traffic Shaping-&gt; Add</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-156.png" alt="" class="wp-image-26385" srcset="https://vacif.com/wp-content/uploads/2025/08/image-156.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-156-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-156-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Sau khi nhấn add-&gt;nhập những thông tin như này theo thứ tự ở trên hình ảnh</p>



<ul class="wp-block-list">
<li>Name : Team_QoS</li>



<li>Policy association: Rules</li>



<li>Rule Type: Guarantee</li>



<li>Limit upload/download separately: Enable</li>



<li>Priority: 0 – [ Real Time – e.g. VoIP] (highest)</li>



<li>Guarantee – limit upload: ( 400-500) KBps</li>



<li>Guarantee – limit download: (400-500) KBps</li>



<li>Bandwidth usage type: Individual</li>



<li>Save</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="468" src="https://vacif.com/wp-content/uploads/2025/08/image-157-1024x468.png" alt="" class="wp-image-26386" srcset="https://vacif.com/wp-content/uploads/2025/08/image-157-1024x468.png 1024w, https://vacif.com/wp-content/uploads/2025/08/image-157-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-157-768x351.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-157.png 1058w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>&nbsp;Sau khi nhập những bước trên xong thì chúng ta sẽ tạo 1 cái rule để Bước 1 và Bước 2 có thể chạy</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-d1y8k"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-d1y8k "><div class="eb-advance-heading-wrapper eb-advance-heading-d1y8k button-1 undefined" data-id="eb-advance-heading-d1y8k"><h2 class="eb-ah-title"><span class="first-title">Bước 3: Tạo Rule Policy để chạy QoS</span></h2></div></div></div>



<p>Muốn tạo được Rule Policy thì ta vào phần Protect-&gt;Rule and policies-&gt;Firewall rules-&gt; Add firewall rule-&gt;New firewall rules</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="424" src="https://vacif.com/wp-content/uploads/2025/08/image-158.png" alt="" class="wp-image-26387" srcset="https://vacif.com/wp-content/uploads/2025/08/image-158.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-158-300x130.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-158-768x334.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Sau khi nhấn New firewall rule thì firewall sẽ hiện ra trang edit firewall rule để mình điền thông rule</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="294" src="https://vacif.com/wp-content/uploads/2025/08/image-159.png" alt="" class="wp-image-26388" srcset="https://vacif.com/wp-content/uploads/2025/08/image-159.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-159-300x90.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-159-768x232.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Rule name: Allow_Teams_Meeting</li>



<li>Action: Accept</li>



<li>Tích vào Log firewall traffic</li>



<li>Rule group: None</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="349" src="https://vacif.com/wp-content/uploads/2025/08/image-160.png" alt="" class="wp-image-26389" srcset="https://vacif.com/wp-content/uploads/2025/08/image-160.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-160-300x107.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-160-768x275.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<ul class="wp-block-list">
<li>Source Zone: LAN</li>



<li>Source networks and devices: Khuyến khích chọn IP và subnet cố định, không nên để any ở mục này. Ở đây tôi sẽ để IP của máy mình.</li>



<li>Destination Zones: WAN</li>



<li>Destination networks: Any</li>



<li>Service: Any</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="779" height="193" src="https://vacif.com/wp-content/uploads/2025/08/image-23.jpg" alt="" class="wp-image-26375" srcset="https://vacif.com/wp-content/uploads/2025/08/image-23.jpg 779w, https://vacif.com/wp-content/uploads/2025/08/image-23-300x74.jpg 300w, https://vacif.com/wp-content/uploads/2025/08/image-23-768x190.jpg 768w" sizes="auto, (max-width: 779px) 100vw, 779px" /></figure>



<p>Kéo xuống dưới sẽ thấy phần Other security features trong phần này thì điền như sau:</p>



<ul class="wp-block-list">
<li>Identify and control applications (App control): Chọn Mircrosoft Teams mà nãy mình đã tạo ở Application (Bước 1).</li>



<li>Shape traffic: Chọn Teams-Qos mà nãy mình đã tạo ở Traffic Shaping Policy (Bước 2).</li>



<li>Tích vào Apply application-base traffic shaping policy</li>



<li>Cuối cùng là chọn Save.</li>
</ul>



<p>Khi xong hết những cấu hình ở trên thì tiếp theo mình sẽ vào bước test xem cấu hình của mình đã chạy hay chưa.</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-f9157"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-f9157 "><div class="eb-advance-heading-wrapper eb-advance-heading-f9157 button-1 undefined" data-id="eb-advance-heading-f9157"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Kết quả</span></h2></div></div></div>



<p>Ở đây em sẽ test với mức băng thông mình đã quy định là 400KBps ở trên bước 2, mình sẽ vào Teams để download 1 file mà mình đã tạo.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-161.png" alt="" class="wp-image-26390" srcset="https://vacif.com/wp-content/uploads/2025/08/image-161.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-161-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-161-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-161-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-162.png" alt="" class="wp-image-26391" srcset="https://vacif.com/wp-content/uploads/2025/08/image-162.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-162-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-162-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-162-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Tiếp theo sẽ tang băng thông lên thành 4000KBps tức là 4MBps để xem băng thông.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="446" src="https://vacif.com/wp-content/uploads/2025/08/image-163.png" alt="" class="wp-image-26392" srcset="https://vacif.com/wp-content/uploads/2025/08/image-163.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-163-300x137.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-163-768x351.png 768w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-164.png" alt="" class="wp-image-26393" srcset="https://vacif.com/wp-content/uploads/2025/08/image-164.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-164-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-164-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-164-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="975" height="548" src="https://vacif.com/wp-content/uploads/2025/08/image-165.png" alt="" class="wp-image-26394" srcset="https://vacif.com/wp-content/uploads/2025/08/image-165.png 975w, https://vacif.com/wp-content/uploads/2025/08/image-165-300x169.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-165-768x432.png 768w, https://vacif.com/wp-content/uploads/2025/08/image-165-800x450.png 800w" sizes="auto, (max-width: 975px) 100vw, 975px" /></figure>



<p>Nếu mà kết quả như trên mình đã làm thành công với QoS rồi nhé. Chúc các bạn thành công nhé.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/huong-dan-cau-hinh-qos-uu-tien-microsoft-teams-tren-sophos-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hướng Dẫn Cấu Hình IPsec Site-to-Site Policy-Based VPN Trên Sophos Firewall(v21).</title>
		<link>https://vacif.com/huong-dan-cau-hinh-ipsec-site-to-site-policy-based-vpn-tren-sophos-firewallv21/</link>
					<comments>https://vacif.com/huong-dan-cau-hinh-ipsec-site-to-site-policy-based-vpn-tren-sophos-firewallv21/#respond</comments>
		
		<dc:creator><![CDATA[Long Nguyen]]></dc:creator>
		<pubDate>Thu, 14 Aug 2025 08:52:23 +0000</pubDate>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Hướng dẫn]]></category>
		<category><![CDATA[Sophos Firewall]]></category>
		<guid isPermaLink="false">https://new.vacif.com/?p=25979</guid>

					<description><![CDATA[Bài viết này sẽ giúp bạn cấu hình IPSec site-to-site giữa Head office và Branch office trên Sophos Firewall. Ví dụ như mô hình mạng ở trên mô tả kết nối giữa trụ sở chính(HQ-Site) và chi nhánh văn phòng(Branch-Site). Đến phần Hosts and services &#62; IP Host &#62; Add để thêm local and remote [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-7iftb"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-7iftb "><div class="eb-advance-heading-wrapper eb-advance-heading-7iftb button-1 undefined" data-id="eb-advance-heading-7iftb"><h2 class="eb-ah-title"><span class="first-title">I &#8211; Sơ đồ mạng</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="988" height="788" src="https://vacif.com/wp-content/uploads/2025/08/image-91.png" alt="" class="wp-image-25999" srcset="https://vacif.com/wp-content/uploads/2025/08/image-91.png 988w, https://vacif.com/wp-content/uploads/2025/08/image-91-300x239.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-91-768x613.png 768w" sizes="auto, (max-width: 988px) 100vw, 988px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-0it1r"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-0it1r "><div class="eb-advance-heading-wrapper eb-advance-heading-0it1r button-1 undefined" data-id="eb-advance-heading-0it1r"><h2 class="eb-ah-title"><span class="first-title">II &#8211; Overview</span></h2></div></div></div>



<p>Bài viết này sẽ giúp bạn cấu hình IPSec site-to-site giữa Head office và Branch office trên Sophos Firewall. Ví dụ như mô hình mạng ở trên mô tả kết nối giữa trụ sở chính(HQ-Site) và chi nhánh văn phòng(Branch-Site).</p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-8vv2e"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-8vv2e "><div class="eb-advance-heading-wrapper eb-advance-heading-8vv2e button-1 undefined" data-id="eb-advance-heading-8vv2e"><h2 class="eb-ah-title"><span class="first-title">III &#8211; Cấu hình</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-szhf1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-szhf1 "><div class="eb-advance-heading-wrapper eb-advance-heading-szhf1 button-1 undefined" data-id="eb-advance-heading-szhf1"><h2 class="eb-ah-title"><span class="first-title">1/ Cấu hình trên Firewall HQ_Site</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-okm4w"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-okm4w "><div class="eb-advance-heading-wrapper eb-advance-heading-okm4w button-1 undefined" data-id="eb-advance-heading-okm4w"><h2 class="eb-ah-title"><span class="first-title">1.1/ Thêm Local và Remote LAN Network</span></h2></div></div></div>



<p>Đến phần <strong>Hosts and services</strong> &gt; <strong>IP Host</strong> &gt; <strong>Add</strong> để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="943" height="461" src="https://vacif.com/wp-content/uploads/2025/08/image-92.png" alt="" class="wp-image-26001" srcset="https://vacif.com/wp-content/uploads/2025/08/image-92.png 943w, https://vacif.com/wp-content/uploads/2025/08/image-92-300x147.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-92-768x375.png 768w" sizes="auto, (max-width: 943px) 100vw, 943px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="946" height="427" src="https://vacif.com/wp-content/uploads/2025/08/image-93.png" alt="" class="wp-image-26002" srcset="https://vacif.com/wp-content/uploads/2025/08/image-93.png 946w, https://vacif.com/wp-content/uploads/2025/08/image-93-300x135.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-93-768x347.png 768w" sizes="auto, (max-width: 946px) 100vw, 946px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-5flv2"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-5flv2 "><div class="eb-advance-heading-wrapper eb-advance-heading-5flv2 button-1 undefined" data-id="eb-advance-heading-5flv2"><h2 class="eb-ah-title"><span class="first-title">1.2/ Tạo kết nối IPsec VPN đến Firewall Branch_Site.</span></h2></div></div></div>



<p>Đến phần <strong>Site-to-Site VPN</strong> &gt; <strong>IPsec</strong> và chọn <strong>Add</strong>. Tạo kết nối với thông số bên dưới.</p>



<p>Đặt tên cho kết nối VPN và chọn <strong>Connection type</strong> là <strong>Site-to-Site</strong> đối với Policy-Based VPN. Tích chọn <strong>Active on save</strong>, tạo firewall rule sau. Chọn <strong>Gateway type</strong> là <strong>Respond only</strong> bởi vì khởi tạo từ chi nhánh sẽ được phản hồi từ trụ sở chính.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="376" src="https://vacif.com/wp-content/uploads/2025/08/image-94.png" alt="" class="wp-image-26003" srcset="https://vacif.com/wp-content/uploads/2025/08/image-94.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-94-300x120.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-94-768x307.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<p>Chọn <strong>Profile</strong>, có thể tạo <strong>Profile</strong> ở <strong>Profiles</strong> -&gt; <strong>IPSec Pprofiles</strong> hoặc có thể chọn những<strong> Profiles</strong> được định nghĩa sẵn trên Sophos Firewall.</p>



<p>Chọn <strong>Authentication type</strong> là <strong>Preshared key</strong> và nhập cùng preshared key trên cả 2 firewall.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="876" height="267" src="https://vacif.com/wp-content/uploads/2025/08/image-95.png" alt="" class="wp-image-26004" srcset="https://vacif.com/wp-content/uploads/2025/08/image-95.png 876w, https://vacif.com/wp-content/uploads/2025/08/image-95-300x91.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-95-768x234.png 768w" sizes="auto, (max-width: 876px) 100vw, 876px" /></figure>



<p>Chọn <strong>Listening interface</strong> là <strong>PortB</strong> và <strong>Gateway address</strong> là <strong>WAN IP address </strong>của Firewall phía Branch-Site. Tương tự chọn <strong>Local subnet</strong> là local_network_192.168.100.0 và <strong>Remote subnet</strong> là remote_network_192.168.200.0</p>



<p><strong>** </strong><span style="text-decoration: underline;"><strong>Chú ý</strong>:</span> <strong>Listening interface</strong> phải ở trong <strong>WAN zone</strong> để tạo kết nối VPN.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="924" height="425" src="https://vacif.com/wp-content/uploads/2025/08/image-96.png" alt="" class="wp-image-26005" srcset="https://vacif.com/wp-content/uploads/2025/08/image-96.png 924w, https://vacif.com/wp-content/uploads/2025/08/image-96-300x138.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-96-768x353.png 768w" sizes="auto, (max-width: 924px) 100vw, 924px" /></figure>



<p>Nhấn <strong>save</strong>, theo dõi trạng thái kết nối.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="926" height="241" src="https://vacif.com/wp-content/uploads/2025/08/image-97.png" alt="" class="wp-image-26007" srcset="https://vacif.com/wp-content/uploads/2025/08/image-97.png 926w, https://vacif.com/wp-content/uploads/2025/08/image-97-300x78.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-97-768x200.png 768w" sizes="auto, (max-width: 926px) 100vw, 926px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-jvrtk"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-jvrtk "><div class="eb-advance-heading-wrapper eb-advance-heading-jvrtk button-1 undefined" data-id="eb-advance-heading-jvrtk"><h2 class="eb-ah-title"><span class="first-title">1.3/ Tạo 1 firewall rule để cho phép traffic đi vào và đi ra qua kết nối VPN trên HQ_Site</span></h2></div></div></div>



<p>Đến phần <strong>Rules and Policies</strong> <strong>-&gt; Firewall rules</strong> chọn <strong>New firewall rule</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="540" src="https://vacif.com/wp-content/uploads/2025/08/image-98.png" alt="" class="wp-image-26008" srcset="https://vacif.com/wp-content/uploads/2025/08/image-98.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-98-300x172.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-98-768x441.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<p>Nhấn <strong>save.</strong></p>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-bbdru"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-bbdru "><div class="eb-advance-heading-wrapper eb-advance-heading-bbdru button-1 undefined" data-id="eb-advance-heading-bbdru"><h2 class="eb-ah-title"><span class="first-title">2/ Cấu hình trên Firewall Branch_Site</span></h2></div></div></div>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-cijny"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-cijny "><div class="eb-advance-heading-wrapper eb-advance-heading-cijny button-1 undefined" data-id="eb-advance-heading-cijny"><h2 class="eb-ah-title"><span class="first-title">2.1/ Thêm Local và Remote LAN Network</span></h2></div></div></div>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="394" src="https://vacif.com/wp-content/uploads/2025/08/image-99.png" alt="" class="wp-image-26009" srcset="https://vacif.com/wp-content/uploads/2025/08/image-99.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-99-300x126.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-99-768x322.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="753" height="310" src="https://vacif.com/wp-content/uploads/2025/08/image-10.jpg" alt="" class="wp-image-25989" srcset="https://vacif.com/wp-content/uploads/2025/08/image-10.jpg 753w, https://vacif.com/wp-content/uploads/2025/08/image-10-300x124.jpg 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-cxovh"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-cxovh "><div class="eb-advance-heading-wrapper eb-advance-heading-cxovh button-1 undefined" data-id="eb-advance-heading-cxovh"><h2 class="eb-ah-title"><span class="first-title">2.2/ Tạo kết nối IPsec VPN đến Firewall HQ_Site</span></h2></div></div></div>



<p>Đến phần <strong>Site-to-Site VPN</strong> &gt; <strong>IPsec Connections</strong> và chọn <strong>Add</strong>. Tạo kết nối với thông số bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="309" src="https://vacif.com/wp-content/uploads/2025/08/image-100.png" alt="" class="wp-image-26012" srcset="https://vacif.com/wp-content/uploads/2025/08/image-100.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-100-300x99.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-100-768x252.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="264" src="https://vacif.com/wp-content/uploads/2025/08/image-101.png" alt="" class="wp-image-26013" srcset="https://vacif.com/wp-content/uploads/2025/08/image-101.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-101-300x84.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-101-768x215.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="452" src="https://vacif.com/wp-content/uploads/2025/08/image-102.png" alt="" class="wp-image-26014" srcset="https://vacif.com/wp-content/uploads/2025/08/image-102.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-102-300x144.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-102-768x369.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Nhấn <strong>save</strong>, theo dõi trạng thái kết nối.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="895" height="251" src="https://vacif.com/wp-content/uploads/2025/08/image-103.png" alt="" class="wp-image-26015" srcset="https://vacif.com/wp-content/uploads/2025/08/image-103.png 895w, https://vacif.com/wp-content/uploads/2025/08/image-103-300x84.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-103-768x215.png 768w" sizes="auto, (max-width: 895px) 100vw, 895px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-tdn27"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-tdn27 "><div class="eb-advance-heading-wrapper eb-advance-heading-tdn27 button-1 undefined" data-id="eb-advance-heading-tdn27"><h2 class="eb-ah-title"><span class="first-title">2.3/ Tạo 1 firewall rule để cho phép traffic đi vào và đi ra qua kết nối VPN trên Branch_Site</span></h2></div></div></div>



<p>Đến phần <strong>Hosts and services</strong> &gt; <strong>IP Host</strong> &gt; <strong>Add</strong> để thêm local and remote LAN network như hình ở bên dưới.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="534" src="https://vacif.com/wp-content/uploads/2025/08/image-104.png" alt="" class="wp-image-26016" srcset="https://vacif.com/wp-content/uploads/2025/08/image-104.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-104-300x170.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-104-768x436.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Nhấn <strong>save</strong>.</p>



<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Đến phần <strong>Site-to-Site VPN</strong> &gt; <strong>IPsec Connections, </strong>kiểm tra trạng thái kết nối.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="911" height="233" src="https://vacif.com/wp-content/uploads/2025/08/image-105.png" alt="" class="wp-image-26017" srcset="https://vacif.com/wp-content/uploads/2025/08/image-105.png 911w, https://vacif.com/wp-content/uploads/2025/08/image-105-300x77.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-105-768x196.png 768w" sizes="auto, (max-width: 911px) 100vw, 911px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="911" height="220" src="https://vacif.com/wp-content/uploads/2025/08/image-106.png" alt="" class="wp-image-26018" srcset="https://vacif.com/wp-content/uploads/2025/08/image-106.png 911w, https://vacif.com/wp-content/uploads/2025/08/image-106-300x72.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-106-768x185.png 768w" sizes="auto, (max-width: 911px) 100vw, 911px" /></figure>



<div class="wp-block-essential-blocks-advanced-heading  root-eb-advance-heading-1s3o1"><div class="eb-parent-wrapper eb-parent-eb-advance-heading-1s3o1 "><div class="eb-advance-heading-wrapper eb-advance-heading-1s3o1 button-1 undefined" data-id="eb-advance-heading-1s3o1"><h2 class="eb-ah-title"><span class="first-title">IV &#8211; Kiểm tra kết nối</span></h2></div></div></div>



<p>&nbsp;Lấy 1 máy tính trong LAN ở HQ_Site ping đến máy tính trong LAN ở Branch_Site.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="613" src="https://vacif.com/wp-content/uploads/2025/08/image-107.png" alt="" class="wp-image-26019" srcset="https://vacif.com/wp-content/uploads/2025/08/image-107.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-107-300x195.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-107-768x500.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>



<p>Và ngược lại, Lấy 1 máy tính trong LAN ở Branch_Site ping đến máy tính trong LAN ở HQ_Site.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="941" height="704" src="https://vacif.com/wp-content/uploads/2025/08/image-108.png" alt="" class="wp-image-26020" srcset="https://vacif.com/wp-content/uploads/2025/08/image-108.png 941w, https://vacif.com/wp-content/uploads/2025/08/image-108-300x224.png 300w, https://vacif.com/wp-content/uploads/2025/08/image-108-768x575.png 768w" sizes="auto, (max-width: 941px) 100vw, 941px" /></figure>
]]></content:encoded>
					
					<wfw:commentRss>https://vacif.com/huong-dan-cau-hinh-ipsec-site-to-site-policy-based-vpn-tren-sophos-firewallv21/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
