1. M畉NG RING 畉O
n 畛nh ngh挑a
n Ph但n lo畉i m畉ng ri棚ng 畉o :
n Remote-Access VPN
n Intranet-based VPN
n Extranet-based VPN
3. n L畛i 鱈ch c畛a m畉ng ri棚ng 畉o
n M畛 r畛ng v湛ng 畛a l箪 c坦 th畛 k畉t n畛i 動畛c
Tng c動畛ng b畉o m畉t cho h畛 th畛ng m畉ng
n Gi畉m chi ph鱈 v畉n hnh so v畛i m畉ng
WAN truy畛n th畛ng
n Gi畉m th畛i gian v chi ph鱈 truy畛n d畛 li畛u
畉n ng動畛i d湛ng 畛 xa
5. n M叩y 1 : (card Cross)
n 畛a ch畛 IP : 172.16.1.2
n Subnet Mask : 255.255.0.0
n Default Gateway : 172.16.1.1
6. n M叩y 2 :
n Card Cross
n 畛a ch畛 IP : 172.16.1.1
n Subnet Mask : 255.255.0.0
n Card Lan
n 畛a ch畛 IP : 192.168.1.1
n Subnet Mask : 255.255.255.0
7. n M叩y 3 : (card Lan)
n 畛a ch畛 IP : 192.168.1.2
n Subnet Mask : 255.255.255.0
8. n M叩y 2 :
n B1: Start Programs
Administrative Tools Routing and
Remote Access t畉i c畛a s畛 Routing
and Remote Access click chu畛t ph畉i
l棚n m叩y 2 , ch畛n Configuration and
Enable Routing and Remote Access
t畉i c畛a s畛 Welcome to the Routing and
Remote Access Server setup wizard,
ch畛n Next
9. t畉i c畛a s畛 Configuration , 叩nh d畉u
ch畛n Remote Access (Dial-up or VPN)
Next t畉i c畛a s畛 Remote Access ,
叩nh d畉u ch畛n vo 担 VPN Next
t畉i c畛a s畛 VPN Connection, ch畛n card
Lan , b畛 d畉u ch畛n t畉i 担 Enable security
on the selected interface by setting up
static packet filters Next
10. t畉i c畛a s畛 IP Address Assignment,
ch畛n 担 From a specified range of
addresses t畉i c畛a s畛 Address Range
Assignment, ch畛n New t畉i c畛a s畛
New Address Range g探 vo d達y IP
nh動 sau :
Start IP address : 172.16.1.200
End IP address : 172.16.1.220
11. t畉i c畛a s畛 Managing Multiple Remote
Access Servers, 叩nh d畉u ch畛n 担 No,
use Routing and Remote Access to
authenticate connection requests
Next Finish.
12. n B2 : 坦ng c叩c c畛a s畛 vo Start
Administrative Tools Computer
Management t畉o user (user name :
h1 ; password : hoa1) v b畛 d畉u ch畛n
t畉i 担 User must change password at
next log on click chu畛t ph畉i tr棚n
user h1 Properities vo tab Dial-
in, trong Remote Access Permission
14. n M叩y 3:
n B1 : Click chu畛t ph畉i tr棚n My Network
Places Properties, ch畛n Create a new
connection t畉i c畛a s畛 Welcome to the
New Connection Wizzard, ch畛n Next
t畉i c畛a s畛 Network Connection Type,
叩nh d畉u ch畛n 担 Connect to the network
at my workplace Next
15. n t畉i c畛a s畛 Network Connection
叩nh d畉u ch畛n Virtual Private Network
connection Next t畉i c畛a s畛
Connection Name , t畉i 担 Company
Name g探 vo VPIT Next t畉i c畛a
s畛 VPN Server Selection , g探 畛a ch畛 IP
card Lan c畛a m叩y 2 (192.168.1.1) vo
担 Host name or IP address Next
16. t畉i c畛a s畛 Connection Availability,
叩nh d畉u ch畛n 担 My use only Next
Finish t畉i c畛a s畛 Connect VPIT
g探 username : h1 ; password : hoa1
connect sau khi connect thnh
c担ng ch炭ng ta c坦 th畛 ping gi畛a 2 m叩y 1
v m叩y 3
18. n Chu畉n b畛 :
n M叩y 1 : (card Cross)
n 畛a ch畛 IP : 172.16.1.2
n Subnet Mask : 255.255.0.0
n Default Gateway : 172.16.1.1
19. n M叩y 2 :
n Card Cross
n 畛a ch畛 IP : 172.16.1.1
n Subnet Mask : 255.255.0.0
n Card Lan
n 畛a ch畛 IP : 192.168.1.2
n Subnet Mask : 255.255.255.0
20. n M叩y 3 :
n Card Cross
n 畛a ch畛 IP : 172.16.2.1
n Subnet Mask : 255.255.0.0
n Card Lan
n 畛a ch畛 IP : 192.168.1.3
n Subnet Mask : 255.255.255.0
21. n M叩y 4 : (card Cross)
n 畛a ch畛 IP : 172.16.2.2
n Subnet Mask : 255.255.0.0
n Default Gateway : 172.16.2.1
22. n M叩y 2 :
n B1 : 坦ng c叩c c畛a s畛 vo Start
Administrative Tools Computer
Management t畉o user (user name :
hanoi ; password : hanoi) v b畛 d畉u
ch畛n t畉i 担 User must change password
at next log on click chu畛t ph畉i tr棚n
user hanoi Properities vo tab
Dial-in, trong Remote Access
Permission
23. (Dial-in or VPN) , 叩nh d畉u ch畛n 担
Allow Access OK
n B2 : Start Programs
Administrative Tools Routing and
Remote Access t畉i c畛a s畛 Routing
and Remote Access click chu畛t ph畉i
l棚n m叩y 2 , ch畛n Configuration and
Enable Routing and Remote Access
t畉i c畛a s畛 Welcome to the Routing and
Remote Access Server setup wizard,
ch畛n Next
24. t畉i c畛a s畛 Configuration , 叩nh d畉u
ch畛n 担 Custom configuration Next
t畉i c畛a s畛 Custom Configuration,
叩nh d畉u ch畛n nh畛ng 担 sau : VPN
access ; Demain-dial connections (user
for branch office routing) ; LAN
routing Next Finish (ch畛n Yes
khi h畛 th畛ng y棚u c畉u restart service)
25. Trong c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i tr棚n
Network Interfaces , ch畛n New
Demand-dial Interface T畉i c畛a s畛
Welcome ch畛n Next t畉i c畛a s畛
Interface Name , g探 hanoi vo 担
Interface name Next
26. T畉i c畛a s畛 Connection Type , 叩nh
d畉u ch畛n Connect using virtual private
network (VPN) Next t畉i c畛a s畛
VPN Type Ch畛n 担 Point to Point
Tunneling Protocol (PPTP) Next
t畉i c畛a s畛 Destination Address , g探 畛a
ch畛 IP card Lan c畛a m叩y 3
(192.168.1.3) vo 担 host name or IP
address t畉i c畛a s畛 Protocol and
27. Security , 畛 nguy棚n l畛a ch畛n m畉c
畛nh (Route IP Packets on this
interface) Next t畉i c畛a s畛
Static Routes for Remote Networks
, ch畛n Add t畉i c畛a s畛 Static
Route , c畉u h狸nh nh動 sau :
28. n Destination : 172.16.2.0
n Network Mask : 255.255.255.0
n Metric : 1
OK Next t畉i c畛a s畛 Dial out
Credentials nh畉p vo nh畛ng th担ng
tin sau :
29. n User name : saigon
n Domain :
n Password : saigon
n Confirm password : saigon
Next Finish.
30. n B3 : T畉i c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i l棚n m叩y 2 ,
ch畛n Properities ch畛n tab IP
Ch畛n 担 Static address pool Add
T畉i c畛a s畛 New Address Range , g探
vo d達y s畛 IP sau :
n Start IP address : 172.16.1.200
n End IP address : 172.16.1.220
31. OK OK t畉i c畛a s畛 Routing and
Remote Access , click chu畛t ph畉i l棚n
m叩y 2 All Task Restart
32. n M叩y 3 :
n B1 : 坦ng c叩c c畛a s畛 vo Start
Administrative Tools Computer
Management t畉o user (user name :
saigon ; password : saigon) v b畛 d畉u ch畛n
t畉i 担 User must change password at next log
on click chu畛t ph畉i tr棚n user hanoi
Properities vo tab Dial-in, trong Remote
Access Permission
33. (Dial-in or VPN) , 叩nh d畉u ch畛n 担 Allow
Access OK
n B2 : Start Programs Administrative
Tools Routing and Remote Access t畉i
c畛a s畛 Routing and Remote Access click
chu畛t ph畉i l棚n m叩y 3 , ch畛n Configuration
and Enable Routing and Remote Access
t畉i c畛a s畛 Welcome to the Routing and
Remote Access Server setup wizard, ch畛n
Next
34. t畉i c畛a s畛 Configuration , 叩nh d畉u
ch畛n 担 Custom configuration Next
t畉i c畛a s畛 Custom Configuration,
叩nh d畉u ch畛n nh畛ng 担 sau : VPN
access ; Demain-dial connections (user
for branch office routing) ; LAN
routing Next Finish (ch畛n Yes
khi h畛 th畛ng y棚u c畉u restart service)
35. Trong c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i tr棚n
Network Interfaces , ch畛n New
Demand-dial Interface T畉i c畛a s畛
Welcome ch畛n Next t畉i c畛a s畛
Interface Name , g探 saigon vo 担
Interface name Next
36. T畉i c畛a s畛 Connection Type , 叩nh
d畉u ch畛n Connect using virtual private
network (VPN) Next t畉i c畛a s畛
VPN Type Ch畛n 担 Point to Point
Tunneling Protocol (PPTP) Next
t畉i c畛a s畛 Destination Address , g探 畛a
ch畛 IP card Lan c畛a m叩y 2
(192.168.1.2) vo 担 host name or IP
address t畉i c畛a s畛 Protocol and
37. n Security , 畛 nguy棚n l畛a ch畛n m畉c
畛nh (Route IP Packets on this
interface) Next t畉i c畛a s畛
Static Routes for Remote Networks
, ch畛n Add t畉i c畛a s畛 Static
Route , c畉u h狸nh nh動 sau :
38. n Destination : 172.16.1.0
n Network Mask : 255.255.255.0
n Metric : 1
OK Next t畉i c畛a s畛 Dial out
Credentials nh畉p vo nh畛ng th担ng
tin sau :
39. n User name : hanoi
n Domain :
n Password : hanoi
n Confirm password : hanoi
Next Finish
40. n B3 : T畉i c畛a s畛 Routing and Remote
Access , click chu畛t ph畉i l棚n m叩y 2 ,
ch畛n Properities ch畛n tab IP
Ch畛n 担 Static address pool Add
T畉i c畛a s畛 New Address Range , g探
vo d達y s畛 IP sau :
n Start IP address : 172.16.2.200
n End IP address : 172.16.2.220
41. OK OK t畉i c畛a s畛 Routing and
Remote Access , click chu畛t ph畉i l棚n
m叩y 3 All Task Restart.
Sau 坦 ki畛m tra b畉ng l畛nh ping
172.16.1.2 ho畉c ping 172.16.2.2 , gi畛a
2 m叩y : m叩y 1 v m叩y 4.