Juniper SSL VPN 配置手册(juniper) 联系客服

发布时间 : 星期六 文章Juniper SSL VPN 配置手册(juniper)更新完毕开始阅读bb7fdd747fd5360cba1adbe1

Juniper Netscreen SSL VPN

配置手册

Juniper network

目 录

一、初始化设置 ............................................................................................................. 3

1.1、通过Console连接SSL VPN ...................................................................... 3 1.2、填写初始化信息 ................................................................................................ 3 1.3、使用浏览器连接SSL VPN ............................................................................ 5

二、SSL VPN基本设置 ............................................................................................. 5

2.1、网络接口设置 .................................................................................................... 5 2.2、设置SSL VPN的License ............................................................................ 6 2.3、添加用户认证服务器 ....................................................................................... 7 2.4、添加认证用户 .................................................................................................... 9 2.5、添加SSL VPN的认证域 ............................................................................. 11

三、角色映射和功能模块 ...................................................................................... 12

3.1、添加角色 ........................................................................................................... 12 3.2、角色映射 ........................................................................................................... 14 3.3、功能模块 ........................................................................................................... 16

四、使用SSL VPN的各个功能模块 ............................................................... 17

4.1、使用Core功能模块 ...................................................................................... 18 4.2、使用SAM功能模块 ...................................................................................... 19 4.3、使用Network Connect模块 ...................................................................... 23

五、资源访问控制 ...................................................................................................... 25

5.1、Core和SAM的资源访问控制 .................................................................. 26 5.2、SAM和NC的资源访问控制 ..................................................................... 27

六、设备管理 ................................................................................................................. 28

6.1、系统概览 ........................................................................................................... 28 6.2、日志系统 ........................................................................................................... 28 6.3、系统升级 ........................................................................................................... 30 6.4、设备排除 ........................................................................................................... 31

一、初始化设置

1.1、通过Console连接SSL VPN

SSL VPN的初始化是通过设备的Console端口完成的,Console的设置如下:9600,8,N,1。

在管理员的计算机上使用任意终端软件,包括HyperTerminal,Crt,SecureCrt等等都行。把设备的Console线连接至SSL VPN的Console端口,开启电源开关,通过终端软件就能观察到设备启动自检的过程。 1.2、填写初始化信息

当系统自检到如下信息时:

Welcome to the initial configuration of your server!

NOTE: Press 'y' if this is a stand-alone server or the first machine in a clustered configuration.

If this is going to be a member of an already running cluster

press n to reboot. When you see the 'Hit TAB for clustering options' message press TAB and follow the directions. Would you like to proceed (y/n)?: y(选择Y)

Note that continuing signifies that you accept the terms of the Neoteris license agreement. Type \license agreement (the text is also available at any time from the License tab in the Administrator Console).

Do you agree to the terms of the license agreement (y/n/r)?: y(选择Y)

初始化网络信息:

Please provide ethernet configuration information IP address: 192.168.0.190

Network mask: 255.255.255.0 Default gateway: 192.168.0.254

(填入用户需要的IP地址,掩码和网关等信息。

注意:所有网络信息都会设置到SSL VPN的 Internal Interface上) Link speed [Auto]: 0) Auto

1) 1000 Mb/s, Full Duplex 2) 1000 Mb/s, Half Duplex 3) 100 Mb/s, Full Duplex 4) 100 Mb/s, Half Duplex

5) 10 Mb/s, Full Duplex 6) 10 Mb/s, Half Duplex Select 0-6: 0(选择用户需要的速率)

Please provide DNS nameserver information: Primary DNS server: 202.106.0.20

Secondary (optional): 202.99.8.1(填入用户需要的DNS地址,可以是内部的DNS服务器的IP地址)

DNS domain(s): juniper.net(填入用户需要的域名,无特别限制) Please provide Microsoft WINS server information: WINS server (optional):

确认初始化信息:

Please confirm the following setup: IP address: 192.168.0.190 Network mask: 255.255.255.0 Gateway IP: 192.168.0.254 Link speed: Auto

Primary DNS server: 202.106.0.20 Secondary DNS: 202.99.8.1 DNS domain(s): juniper.net WINS server:

Correct? (y/n): y(确认无误后,选择Y)

初始化安全信息:

Admin username: admin Password:

Confirm password:

The administrator was successfully created.(填入用户设定的管理员帐号和密码)

设置SSL VPN自签证书:

Please provide information to create a self-signed Web server digital certificate. Common name (example: secure.company.com): timerwell.juniper.net Organization name (example: Company Inc.): juniper (这个部分输入用户的证书信息,无特殊限制)

Please enter some random characters to augment the system's random key generator. We recommend that you enter approximately thirty characters.

Random text (hit enter when done): dkfjlkkjffieejjkdnfkkfjiiiffoperjoootpqe454646 (这个部分输入30个左右的字符以产生证书) Creating self-signed digital certificate...

The self-signed digital certificate was successfully created.

Congratulations! You have successfully completed the initial set up of your server. (当您看到这句话时证明你已经成功的初始化SSL VPN了) https:///admin (note the 's' in https://)