際際滷

際際滷Share a Scribd company logo
M畉NG RING 畉O
n 畛nh ngh挑a
n Ph但n lo畉i m畉ng ri棚ng 畉o :
n Remote-Access VPN
n Intranet-based VPN
n Extranet-based VPN
3. mang rieng ao
n L畛i 鱈ch c畛a m畉ng ri棚ng 畉o
n M畛 r畛ng v湛ng 畛a l箪 c坦 th畛 k畉t n畛i 動畛c
Tng c動畛ng b畉o m畉t cho h畛 th畛ng m畉ng
n Gi畉m chi ph鱈 v畉n hnh so v畛i m畉ng
WAN truy畛n th畛ng
n Gi畉m th畛i gian v chi ph鱈 truy畛n d畛 li畛u
畉n ng動畛i d湛ng 畛 xa
VPN (Client to Gateway)
n M叩y 1 : (card Cross)
n 畛a ch畛 IP : 172.16.1.2
n Subnet Mask : 255.255.0.0
n Default Gateway : 172.16.1.1
n M叩y 2 :
n Card Cross
n 畛a ch畛 IP : 172.16.1.1
n Subnet Mask : 255.255.0.0
n Card Lan
n 畛a ch畛 IP : 192.168.1.1
n Subnet Mask : 255.255.255.0
n M叩y 3 : (card Lan)
n 畛a ch畛 IP : 192.168.1.2
n Subnet Mask : 255.255.255.0
n M叩y 2 :
n B1: Start  Programs 
Administrative Tools  Routing and
Remote Access  t畉i c畛a s畛 Routing
and Remote Access  click chu畛t ph畉i
l棚n m叩y 2 , ch畛n Configuration and
Enable Routing and Remote Access 
t畉i c畛a s畛 Welcome to the Routing and
Remote Access Server setup wizard,
ch畛n Next
 t畉i c畛a s畛 Configuration , 叩nh d畉u
ch畛n Remote Access (Dial-up or VPN)
 Next  t畉i c畛a s畛 Remote Access ,
叩nh d畉u ch畛n vo 担 VPN  Next 
t畉i c畛a s畛 VPN Connection, ch畛n card
Lan , b畛 d畉u ch畛n t畉i 担 Enable security
on the selected interface by setting up
static packet filters  Next
 t畉i c畛a s畛 IP Address Assignment,
ch畛n 担 From a specified range of
addresses  t畉i c畛a s畛 Address Range
Assignment, ch畛n New  t畉i c畛a s畛
New Address Range  g探 vo d達y IP
nh動 sau :
Start IP address : 172.16.1.200
End IP address : 172.16.1.220
 t畉i c畛a s畛 Managing Multiple Remote
Access Servers, 叩nh d畉u ch畛n 担 No,
use Routing and Remote Access to
authenticate connection requests 
Next  Finish.
n B2 : 坦ng c叩c c畛a s畛 vo Start 
Administrative Tools  Computer
Management  t畉o user (user name :
h1 ; password : hoa1) v b畛 d畉u ch畛n
t畉i 担 User must change password at
next log on  click chu畛t ph畉i tr棚n
user h1  Properities  vo tab Dial-
in, trong Remote Access Permission
(Dial-in or VPN) , 叩nh d畉u ch畛n 担 Allow
Access  OK
n M叩y 3:
n B1 : Click chu畛t ph畉i tr棚n My Network
Places  Properties, ch畛n Create a new
connection  t畉i c畛a s畛 Welcome to the
New Connection Wizzard, ch畛n Next 
t畉i c畛a s畛 Network Connection Type,
叩nh d畉u ch畛n 担 Connect to the network
at my workplace  Next
n  t畉i c畛a s畛 Network Connection 
叩nh d畉u ch畛n Virtual Private Network
connection  Next  t畉i c畛a s畛
Connection Name , t畉i 担 Company
Name g探 vo VPIT  Next  t畉i c畛a
s畛 VPN Server Selection , g探 畛a ch畛 IP
card Lan c畛a m叩y 2 (192.168.1.1) vo
担 Host name or IP address  Next
 t畉i c畛a s畛 Connection Availability,
叩nh d畉u ch畛n 担 My use only  Next
 Finish  t畉i c畛a s畛 Connect VPIT
 g探 username : h1 ; password : hoa1
 connect  sau khi connect thnh
c担ng ch炭ng ta c坦 th畛 ping gi畛a 2 m叩y 1
v m叩y 3
VPN (Gateway to Gateway)
n Chu畉n b畛 :
n M叩y 1 : (card Cross)
n 畛a ch畛 IP : 172.16.1.2
n Subnet Mask : 255.255.0.0
n Default Gateway : 172.16.1.1
n M叩y 2 :
n Card Cross
n 畛a ch畛 IP : 172.16.1.1
n Subnet Mask : 255.255.0.0
n Card Lan
n 畛a ch畛 IP : 192.168.1.2
n Subnet Mask : 255.255.255.0
n M叩y 3 :
n Card Cross
n 畛a ch畛 IP : 172.16.2.1
n Subnet Mask : 255.255.0.0
n Card Lan
n 畛a ch畛 IP : 192.168.1.3
n Subnet Mask : 255.255.255.0
n M叩y 4 : (card Cross)
n 畛a ch畛 IP : 172.16.2.2
n Subnet Mask : 255.255.0.0
n Default Gateway : 172.16.2.1
n M叩y 2 :
n B1 : 坦ng c叩c c畛a s畛 vo Start 
Administrative Tools  Computer
Management  t畉o user (user name :
hanoi ; password : hanoi) v b畛 d畉u
ch畛n t畉i 担 User must change password
at next log on  click chu畛t ph畉i tr棚n
user hanoi  Properities  vo tab
Dial-in, trong Remote Access
Permission
(Dial-in or VPN) , 叩nh d畉u ch畛n 担
Allow Access  OK
n B2 : Start  Programs 
Administrative Tools  Routing and
Remote Access  t畉i c畛a s畛 Routing
and Remote Access  click chu畛t ph畉i
l棚n m叩y 2 , ch畛n Configuration and
Enable Routing and Remote Access 
t畉i c畛a s畛 Welcome to the Routing and
Remote Access Server setup wizard,
ch畛n Next
 t畉i c畛a s畛 Configuration , 叩nh d畉u
ch畛n 担 Custom configuration  Next
 t畉i c畛a s畛 Custom Configuration,
叩nh d畉u ch畛n nh畛ng 担 sau : VPN
access ; Demain-dial connections (user
for branch office routing) ; LAN
routing  Next  Finish (ch畛n Yes
khi h畛 th畛ng y棚u c畉u restart service)
 Trong c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i tr棚n
Network Interfaces , ch畛n New
Demand-dial Interface  T畉i c畛a s畛
Welcome ch畛n Next  t畉i c畛a s畛
Interface Name , g探 hanoi vo 担
Interface name  Next
 T畉i c畛a s畛 Connection Type , 叩nh
d畉u ch畛n Connect using virtual private
network (VPN)  Next  t畉i c畛a s畛
VPN Type  Ch畛n 担 Point to Point
Tunneling Protocol (PPTP)  Next 
t畉i c畛a s畛 Destination Address , g探 畛a
ch畛 IP card Lan c畛a m叩y 3
(192.168.1.3) vo 担 host name or IP
address  t畉i c畛a s畛 Protocol and
Security , 畛 nguy棚n l畛a ch畛n m畉c
畛nh (Route IP Packets on this
interface)  Next  t畉i c畛a s畛
Static Routes for Remote Networks
, ch畛n Add  t畉i c畛a s畛 Static
Route , c畉u h狸nh nh動 sau :
n Destination : 172.16.2.0
n Network Mask : 255.255.255.0
n Metric : 1
 OK  Next  t畉i c畛a s畛 Dial out
Credentials nh畉p vo nh畛ng th担ng
tin sau :
n User name : saigon
n Domain :
n Password : saigon
n Confirm password : saigon
 Next  Finish.
n B3 : T畉i c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i l棚n m叩y 2 ,
ch畛n Properities  ch畛n tab IP 
Ch畛n 担 Static address pool  Add 
T畉i c畛a s畛 New Address Range , g探
vo d達y s畛 IP sau :
n Start IP address : 172.16.1.200
n End IP address : 172.16.1.220
 OK  OK  t畉i c畛a s畛 Routing and
Remote Access , click chu畛t ph畉i l棚n
m叩y 2  All Task  Restart
n M叩y 3 :
n B1 : 坦ng c叩c c畛a s畛 vo Start 
Administrative Tools  Computer
Management  t畉o user (user name :
saigon ; password : saigon) v b畛 d畉u ch畛n
t畉i 担 User must change password at next log
on  click chu畛t ph畉i tr棚n user hanoi 
Properities  vo tab Dial-in, trong Remote
Access Permission
(Dial-in or VPN) , 叩nh d畉u ch畛n 担 Allow
Access  OK
n B2 : Start  Programs  Administrative
Tools  Routing and Remote Access  t畉i
c畛a s畛 Routing and Remote Access  click
chu畛t ph畉i l棚n m叩y 3 , ch畛n Configuration
and Enable Routing and Remote Access 
t畉i c畛a s畛 Welcome to the Routing and
Remote Access Server setup wizard, ch畛n
Next
 t畉i c畛a s畛 Configuration , 叩nh d畉u
ch畛n 担 Custom configuration  Next
 t畉i c畛a s畛 Custom Configuration,
叩nh d畉u ch畛n nh畛ng 担 sau : VPN
access ; Demain-dial connections (user
for branch office routing) ; LAN
routing  Next  Finish (ch畛n Yes
khi h畛 th畛ng y棚u c畉u restart service)
 Trong c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i tr棚n
Network Interfaces , ch畛n New
Demand-dial Interface  T畉i c畛a s畛
Welcome ch畛n Next  t畉i c畛a s畛
Interface Name , g探 saigon vo 担
Interface name  Next
 T畉i c畛a s畛 Connection Type , 叩nh
d畉u ch畛n Connect using virtual private
network (VPN)  Next  t畉i c畛a s畛
VPN Type  Ch畛n 担 Point to Point
Tunneling Protocol (PPTP)  Next 
t畉i c畛a s畛 Destination Address , g探 畛a
ch畛 IP card Lan c畛a m叩y 2
(192.168.1.2) vo 担 host name or IP
address  t畉i c畛a s畛 Protocol and
n Security , 畛 nguy棚n l畛a ch畛n m畉c
畛nh (Route IP Packets on this
interface)  Next  t畉i c畛a s畛
Static Routes for Remote Networks
, ch畛n Add  t畉i c畛a s畛 Static
Route , c畉u h狸nh nh動 sau :
n Destination : 172.16.1.0
n Network Mask : 255.255.255.0
n Metric : 1
 OK  Next  t畉i c畛a s畛 Dial out
Credentials nh畉p vo nh畛ng th担ng
tin sau :
n User name : hanoi
n Domain :
n Password : hanoi
n Confirm password : hanoi
 Next  Finish
n B3 : T畉i c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i l棚n m叩y 2 ,
ch畛n Properities  ch畛n tab IP 
Ch畛n 担 Static address pool  Add 
T畉i c畛a s畛 New Address Range , g探
vo d達y s畛 IP sau :
n Start IP address : 172.16.2.200
n End IP address : 172.16.2.220
 OK  OK  t畉i c畛a s畛 Routing and
Remote Access , click chu畛t ph畉i l棚n
m叩y 3  All Task  Restart.
Sau 坦 ki畛m tra b畉ng l畛nh ping
172.16.1.2 ho畉c ping 172.16.2.2 , gi畛a
2 m叩y : m叩y 1 v m叩y 4.
THANKS

More Related Content

3. mang rieng ao

  • 1. M畉NG RING 畉O n 畛nh ngh挑a n Ph但n lo畉i m畉ng ri棚ng 畉o : n Remote-Access VPN n Intranet-based VPN n Extranet-based VPN
  • 3. n L畛i 鱈ch c畛a m畉ng ri棚ng 畉o n M畛 r畛ng v湛ng 畛a l箪 c坦 th畛 k畉t n畛i 動畛c Tng c動畛ng b畉o m畉t cho h畛 th畛ng m畉ng n Gi畉m chi ph鱈 v畉n hnh so v畛i m畉ng WAN truy畛n th畛ng n Gi畉m th畛i gian v chi ph鱈 truy畛n d畛 li畛u 畉n ng動畛i d湛ng 畛 xa
  • 4. VPN (Client to Gateway)
  • 5. n M叩y 1 : (card Cross) n 畛a ch畛 IP : 172.16.1.2 n Subnet Mask : 255.255.0.0 n Default Gateway : 172.16.1.1
  • 6. n M叩y 2 : n Card Cross n 畛a ch畛 IP : 172.16.1.1 n Subnet Mask : 255.255.0.0 n Card Lan n 畛a ch畛 IP : 192.168.1.1 n Subnet Mask : 255.255.255.0
  • 7. n M叩y 3 : (card Lan) n 畛a ch畛 IP : 192.168.1.2 n Subnet Mask : 255.255.255.0
  • 8. n M叩y 2 : n B1: Start Programs Administrative Tools Routing and Remote Access t畉i c畛a s畛 Routing and Remote Access click chu畛t ph畉i l棚n m叩y 2 , ch畛n Configuration and Enable Routing and Remote Access t畉i c畛a s畛 Welcome to the Routing and Remote Access Server setup wizard, ch畛n Next
  • 9. t畉i c畛a s畛 Configuration , 叩nh d畉u ch畛n Remote Access (Dial-up or VPN) Next t畉i c畛a s畛 Remote Access , 叩nh d畉u ch畛n vo 担 VPN Next t畉i c畛a s畛 VPN Connection, ch畛n card Lan , b畛 d畉u ch畛n t畉i 担 Enable security on the selected interface by setting up static packet filters Next
  • 10. t畉i c畛a s畛 IP Address Assignment, ch畛n 担 From a specified range of addresses t畉i c畛a s畛 Address Range Assignment, ch畛n New t畉i c畛a s畛 New Address Range g探 vo d達y IP nh動 sau : Start IP address : 172.16.1.200 End IP address : 172.16.1.220
  • 11. t畉i c畛a s畛 Managing Multiple Remote Access Servers, 叩nh d畉u ch畛n 担 No, use Routing and Remote Access to authenticate connection requests Next Finish.
  • 12. n B2 : 坦ng c叩c c畛a s畛 vo Start Administrative Tools Computer Management t畉o user (user name : h1 ; password : hoa1) v b畛 d畉u ch畛n t畉i 担 User must change password at next log on click chu畛t ph畉i tr棚n user h1 Properities vo tab Dial- in, trong Remote Access Permission
  • 13. (Dial-in or VPN) , 叩nh d畉u ch畛n 担 Allow Access OK
  • 14. n M叩y 3: n B1 : Click chu畛t ph畉i tr棚n My Network Places Properties, ch畛n Create a new connection t畉i c畛a s畛 Welcome to the New Connection Wizzard, ch畛n Next t畉i c畛a s畛 Network Connection Type, 叩nh d畉u ch畛n 担 Connect to the network at my workplace Next
  • 15. n t畉i c畛a s畛 Network Connection 叩nh d畉u ch畛n Virtual Private Network connection Next t畉i c畛a s畛 Connection Name , t畉i 担 Company Name g探 vo VPIT Next t畉i c畛a s畛 VPN Server Selection , g探 畛a ch畛 IP card Lan c畛a m叩y 2 (192.168.1.1) vo 担 Host name or IP address Next
  • 16. t畉i c畛a s畛 Connection Availability, 叩nh d畉u ch畛n 担 My use only Next Finish t畉i c畛a s畛 Connect VPIT g探 username : h1 ; password : hoa1 connect sau khi connect thnh c担ng ch炭ng ta c坦 th畛 ping gi畛a 2 m叩y 1 v m叩y 3
  • 17. VPN (Gateway to Gateway)
  • 18. n Chu畉n b畛 : n M叩y 1 : (card Cross) n 畛a ch畛 IP : 172.16.1.2 n Subnet Mask : 255.255.0.0 n Default Gateway : 172.16.1.1
  • 19. n M叩y 2 : n Card Cross n 畛a ch畛 IP : 172.16.1.1 n Subnet Mask : 255.255.0.0 n Card Lan n 畛a ch畛 IP : 192.168.1.2 n Subnet Mask : 255.255.255.0
  • 20. n M叩y 3 : n Card Cross n 畛a ch畛 IP : 172.16.2.1 n Subnet Mask : 255.255.0.0 n Card Lan n 畛a ch畛 IP : 192.168.1.3 n Subnet Mask : 255.255.255.0
  • 21. n M叩y 4 : (card Cross) n 畛a ch畛 IP : 172.16.2.2 n Subnet Mask : 255.255.0.0 n Default Gateway : 172.16.2.1
  • 22. n M叩y 2 : n B1 : 坦ng c叩c c畛a s畛 vo Start Administrative Tools Computer Management t畉o user (user name : hanoi ; password : hanoi) v b畛 d畉u ch畛n t畉i 担 User must change password at next log on click chu畛t ph畉i tr棚n user hanoi Properities vo tab Dial-in, trong Remote Access Permission
  • 23. (Dial-in or VPN) , 叩nh d畉u ch畛n 担 Allow Access OK n B2 : Start Programs Administrative Tools Routing and Remote Access t畉i c畛a s畛 Routing and Remote Access click chu畛t ph畉i l棚n m叩y 2 , ch畛n Configuration and Enable Routing and Remote Access t畉i c畛a s畛 Welcome to the Routing and Remote Access Server setup wizard, ch畛n Next
  • 24. t畉i c畛a s畛 Configuration , 叩nh d畉u ch畛n 担 Custom configuration Next t畉i c畛a s畛 Custom Configuration, 叩nh d畉u ch畛n nh畛ng 担 sau : VPN access ; Demain-dial connections (user for branch office routing) ; LAN routing Next Finish (ch畛n Yes khi h畛 th畛ng y棚u c畉u restart service)
  • 25. Trong c畛a s畛 Routing and Remote Access , click chu畛t ph畉i tr棚n Network Interfaces , ch畛n New Demand-dial Interface T畉i c畛a s畛 Welcome ch畛n Next t畉i c畛a s畛 Interface Name , g探 hanoi vo 担 Interface name Next
  • 26. T畉i c畛a s畛 Connection Type , 叩nh d畉u ch畛n Connect using virtual private network (VPN) Next t畉i c畛a s畛 VPN Type Ch畛n 担 Point to Point Tunneling Protocol (PPTP) Next t畉i c畛a s畛 Destination Address , g探 畛a ch畛 IP card Lan c畛a m叩y 3 (192.168.1.3) vo 担 host name or IP address t畉i c畛a s畛 Protocol and
  • 27. Security , 畛 nguy棚n l畛a ch畛n m畉c 畛nh (Route IP Packets on this interface) Next t畉i c畛a s畛 Static Routes for Remote Networks , ch畛n Add t畉i c畛a s畛 Static Route , c畉u h狸nh nh動 sau :
  • 28. n Destination : 172.16.2.0 n Network Mask : 255.255.255.0 n Metric : 1 OK Next t畉i c畛a s畛 Dial out Credentials nh畉p vo nh畛ng th担ng tin sau :
  • 29. n User name : saigon n Domain : n Password : saigon n Confirm password : saigon Next Finish.
  • 30. n B3 : T畉i c畛a s畛 Routing and Remote Access , click chu畛t ph畉i l棚n m叩y 2 , ch畛n Properities ch畛n tab IP Ch畛n 担 Static address pool Add T畉i c畛a s畛 New Address Range , g探 vo d達y s畛 IP sau : n Start IP address : 172.16.1.200 n End IP address : 172.16.1.220
  • 31. OK OK t畉i c畛a s畛 Routing and Remote Access , click chu畛t ph畉i l棚n m叩y 2 All Task Restart
  • 32. n M叩y 3 : n B1 : 坦ng c叩c c畛a s畛 vo Start Administrative Tools Computer Management t畉o user (user name : saigon ; password : saigon) v b畛 d畉u ch畛n t畉i 担 User must change password at next log on click chu畛t ph畉i tr棚n user hanoi Properities vo tab Dial-in, trong Remote Access Permission
  • 33. (Dial-in or VPN) , 叩nh d畉u ch畛n 担 Allow Access OK n B2 : Start Programs Administrative Tools Routing and Remote Access t畉i c畛a s畛 Routing and Remote Access click chu畛t ph畉i l棚n m叩y 3 , ch畛n Configuration and Enable Routing and Remote Access t畉i c畛a s畛 Welcome to the Routing and Remote Access Server setup wizard, ch畛n Next
  • 34. t畉i c畛a s畛 Configuration , 叩nh d畉u ch畛n 担 Custom configuration Next t畉i c畛a s畛 Custom Configuration, 叩nh d畉u ch畛n nh畛ng 担 sau : VPN access ; Demain-dial connections (user for branch office routing) ; LAN routing Next Finish (ch畛n Yes khi h畛 th畛ng y棚u c畉u restart service)
  • 35. Trong c畛a s畛 Routing and Remote Access , click chu畛t ph畉i tr棚n Network Interfaces , ch畛n New Demand-dial Interface T畉i c畛a s畛 Welcome ch畛n Next t畉i c畛a s畛 Interface Name , g探 saigon vo 担 Interface name Next
  • 36. T畉i c畛a s畛 Connection Type , 叩nh d畉u ch畛n Connect using virtual private network (VPN) Next t畉i c畛a s畛 VPN Type Ch畛n 担 Point to Point Tunneling Protocol (PPTP) Next t畉i c畛a s畛 Destination Address , g探 畛a ch畛 IP card Lan c畛a m叩y 2 (192.168.1.2) vo 担 host name or IP address t畉i c畛a s畛 Protocol and
  • 37. n Security , 畛 nguy棚n l畛a ch畛n m畉c 畛nh (Route IP Packets on this interface) Next t畉i c畛a s畛 Static Routes for Remote Networks , ch畛n Add t畉i c畛a s畛 Static Route , c畉u h狸nh nh動 sau :
  • 38. n Destination : 172.16.1.0 n Network Mask : 255.255.255.0 n Metric : 1 OK Next t畉i c畛a s畛 Dial out Credentials nh畉p vo nh畛ng th担ng tin sau :
  • 39. n User name : hanoi n Domain : n Password : hanoi n Confirm password : hanoi Next Finish
  • 40. n B3 : T畉i c畛a s畛 Routing and Remote Access , click chu畛t ph畉i l棚n m叩y 2 , ch畛n Properities ch畛n tab IP Ch畛n 担 Static address pool Add T畉i c畛a s畛 New Address Range , g探 vo d達y s畛 IP sau : n Start IP address : 172.16.2.200 n End IP address : 172.16.2.220
  • 41. OK OK t畉i c畛a s畛 Routing and Remote Access , click chu畛t ph畉i l棚n m叩y 3 All Task Restart. Sau 坦 ki畛m tra b畉ng l畛nh ping 172.16.1.2 ho畉c ping 172.16.2.2 , gi畛a 2 m叩y : m叩y 1 v m叩y 4.