Sophos¦h¦~«e´¿¦³¤@´ÚSFM(Sophos Firewall Manager)¥Î¨Ó¶°¤¤±±ºÞ¦h¥x¨¾¤õÀð¡A ´X¦~«áSophos±N¨¾¤õÀð¶°¤¤±±ºÞªº¥\¯à²¾¨ìSophos Central¤W¡ASFM¤]©ó2021 July¥¿¦¡EoL¡C ³Ìªñ«È¤áè¦n¦³¶°¤¤±±ºÞªº»Ý¨D¡A ¶X³oÓ¾÷·|¨ÓÁA¸Ñ¤@¤USophos Central¦p¦ó¶°¤¤±±ºÞ¦aºÝ¨¾¤õÀð§a¡C
¦aºÝªºSophos¨¾¤õÀðn¯à°÷³z¹LSophos Central¨Ó¶°¤¤±±ºÞ¡A ²Ä¤@Ӱʧ@´N§â¦aºÝ¨¾¤õÀð¡§µù¥U¡¨¨ìSophos Central¤¤¡C ³o¸Ìªº¡§µù¥U¡¨«üªº¬O±N¦aºÝ¨¾¤õÀðµn°O¦bSophos Central¤¤¡A¨Ã½á¤©Sophos CentralºÞ²z¥\¯à¡A ¸ò¦aºÝ¨¾¤õÀðªºlicenseºÞ²z¨S¦³¥ô¦óÃö«Y¡C ¦aºÝ¨¾¤õÀðªºlicense±ÂÅvºÞ²z¦b2023¦~10¤ë±j¨î¥Ñ쥻ªºMySophos Portal²¾Âà¨ìSophos Central«á¡A ¨¾¤õÀðªºlicenseºÞ²z¤]¦P¼Ë¦bSophos Central¤¤¶i¦æ¡D ¦ý¥Ñ©ó¡§µù¥U(Register)¡¨³oÓ¦Wµü¤w³Q®³¨Ó°µ¬°¦aºÝ¨¾¤õÀð±ÂÅv©óSophos CentralºÞ²z©Ò¨Ï¥Î¡A ©Ò¥Hlicense©óSophos Central¤¤ªººÞ²z¡A³Q¢´«¤FÓ¦Wµü-«Å§i(Claim)¨Ó°µ¬°¨Ï¥Î¤Wªº°Ï¤À¡C µù¥U(Register)«üªº¬O¦aºÝ¨¾¤õÀð±ÂÅv©óSophos Central¤¤¶i¦æ¶°¤¤ºÞ²z¡A ¦Ó«Å§i(Claim)«üªº¬O¦aºÝ¨¾¤õÀðªºLicenseºÞ²z¡A ¨âªÌ¤£¦P¡A½Ð¤£n·d¿ù¡I (¨Æ¹ê¤W¶¶¤lı±o¡§«Å§i¡¨§ó¾A¦X¶°¤¤ºÞ²z¡A¡§µù¥U¡¨«h¾A¦XlicenseºÞ²z¡A¦ý¥ý·m¥ý¾Æ¡ASophos¤]¨S¦³«i®ð¥h°µ¥¿¦W¤F...) n±N¦aºÝSophos¨¾¤õÀðµù¥U©óSophos Central«Ü²³æ¡A ¦ýº¥ý±z¥²»Ýn¦³¤@ÓSophos Central±b¸¹¡AÁÙ¨S¦³±b¸¹¥i©ó¥H¤U³sµ²¥Ó½Ð¤@Ó±b¸¹¡C https://cloud.sophos.com/manage/login ¦³¤FSophos Central±b¸¹´N¥i¥H¦b SYSTEM/Sophos Central ¤¤¡A±N¨¾¤õÀðµù¥U¨ìSophos Central±b¸¹¤¤¡C µù¥U«á¡A¦^¨ìSophos CentralÀ˵ø¨¾¤õÀ𪬺A¡A·|µo¥Í¦¹¨¾¤õÀð¤w¥[¤J¡A ¦ýª¬ºA¬O Management Disconnect¡AÁÙ¥¼¯à³s½u¡C ³o®É¥²»Ý¦^¨ì¦aºÝ¨¾¤õÀðµe±¡A§âSophos Central Services±Ò¥Î¡A¤~¯à©ñ¦æCentralªººÞ²z¡C §¹¦¨«á¡A¦bSophos Central¤¤·|Åܦ¨ Approval Pending¡Aµ¥«Ý®Öã¡C ½Ð®Ö㦹¨¾¤õÀð¡C ®Öã«á¡A¨äª¬ºA·|Åܦ¨ Disconnected¡C µ¹¥¦¤@ÂI®É¶¡¡A´X¤ÀÄÁ«á¥h¬Ý¡A·|µo²{ª¬ºAÅܦ¨ Connected¡A ¨¾¤õÀð¤w¦¨¥\¯ÇºÞ©óSophos Central¤F¡ã
¨¾¤õÀ𬰦ón¶°¤¤±±ºÞ¡H ·íµM¬O§Q¥Î¬Fµ¦²Î¤@³¡¸pªºÀu¶Õ¡A²¤Æ»P¦P¨B¦h¥x¨¾¤õÀ𪺵¦²¤¡C n¹ê²{¦¹¥\¯à¡A²Ä¤@¨B´N¬O«Ø¥ß¸s²ÕGroup¡C ½Ð¦b Sophos Central ¤¤ªº Firewall Managment - Firewalls «Ø¥ß¤@ÓGroup¡C µM«á§ân¥[¤J¦¹¸s²Õªº¨¾¤õÀðÓÅé¥[¤J¡C (*¤@¥x¨¾¤õÀð¥u¯à¥[¤J¤@ÓGroup) ¥[¤J«áªº¨¾¤õÀð¡A¥i¥HÓÅéºÞ²z¡C ¥¦·|Âà¨ì¸Ó¨¾¤õÀ𪺺޲z¶±¡Aª½±µ¦bSophos Central¤¤ºÞ²z¨¾¤õÀð¡A´N¦p¦P¦aºÝ¤@¯ë¡C Y¬O³z¹LGroupºÞ²z¡A«h·|¶}±Ò¤@Ó·sªºGroupºÞ²z¶±¨ÓºÞ²zGroup³W«h¡C ¦b¨¾¤õÀðÓÅé¯Ç¤JSophos CentralºÞ²z«á¡AY©ó¦aºÝ¨¾¤õÀðµn¤J¡A ·|µo²{³Ì¤W¤è¥X²{¤@Óĵ¥Ü¡A³qª¾±z¦¹¨¾¤õÀð¤w¦bSophos Central¤¤±±ºÞ¡A½Ð¤p¤ß¾Þ§@¡A¥HÁ×§K½Ä¬ðµo¥Í¡C §Ú̸յۦbGroup¤¤«Ø¥ß¤@±ø·sªºtest³W«h¨Ó´ú¸Õ¡C ¦^¨ì¦aºÝ¡A§ÚÌ·|µo²{¦¹³W«h¤w¦P¨B¼g¤J¨¾¤õÀð¡C ¦bSophos Central ªº Firewall Managment - Tasks Queue ¤¤¤]¥i¥HÀ˵ø¦P¨Bªº°Ê§@¬O§_§¹¦¨¡C
¦b¨¾¤õÀð¯Ç¤JSophos Central²Î¤@¶°¤¤±±ºÞ«á¡A §Ú·Q³ÌÅý¤H¾á¤ßªº¬O¶³ºÝGroup»P¦aºÝªº³W«h©Îª«¥óµo¥Í½Ä¬ð®É¡A·|«ç»ò³B²z¡H ¥ý¨Ó´ú¸Õ¨¾¤õÀð³W«h §ÚÌ¥ý©ó¦aºÝ«Ø¥ß¤@±ø¦W¬°test1ªºVPN to WAN¡AÀu¥ý¶¶§Ç³Ì§Cªº¨¾¤õÀð³W«h¡C ¦aºÝ³W«h«Ø¥ß«á¡A§Ú̦b©óGroup¤¤«Ø¥ß¤@±ø¬Û¦P¦WºÙ¡A¦ý¤º®e¤£¦PªºDMZ to WAN¸m³»³W«h¡C ¬d¬ÝTasks Queue¡A§ÚÌ·|µo²{³W«h¤w¦P¨B¦¨¥\ªº¼g¤J¦aºÝ¡C ¦ý©ó¦aºÝ¬d¬Ý¡AÁöµM¦aºÝ³W«h¤º®e³QGroup³W«hÂл\¹L¥h¡A¦ýÀu¥ý¶¶§Ç«h«o¨S¦³¸òµÛÅܧó¡C ³o³¡¤À¦³¨Ç©Ç©Çªº... ±µµÛ´ú¸Õ¥D¾÷ª«¥ó §ÚÌ¥ý©ó¦aºÝ«Ø¥ß¤@Ó¦W¬°shunzeªº1.1.1.1/32 hostª«¥ó¡C ¦A©óGroup¤¤«Ø¥ß¤@Ó¦WºÙ¬Û¦P¡A¦ý¤º®e¤£¦Pªº1.0.0.0/24ºô¬qª«¥ó¡C ´ú¸Õµo²{¡A¥Ñ©ó¬J¦³ªº¦WºÙª«¥ó¤w¦s¦b¡A©Ò¥HµLªk¦¨¥\¶i¦æ¦P¨B¡I ¹ï©ó³o¼Ëªºª¬ªp¡A§Ú̦³¨âÓ¿ï¾Ü¡A¤@Ó¬O¦A¸Õ¤@¦¸¡A¥t¤@Ó¬O²¤¹L¦¹°Ê§@¡C ¦pªG¤£ºÞ³o½Ä¬ðªºª¬ªp¡A«ùÄò¶i¦æ¨ä¥¦Åܧó¡A·|µo²{«áÄòªº°Ê§@³£·|¥d¦í¡AµLªk¶i¦æ¡I n¹À²¤¹L¦¹½Ä¬ð°Ê§@¡An¹À±Æ°£½Ä¬ðªº°ÝÃD¡A«áÄòªº°Ê§@¤~¦³¿ìªkÄ~Äò¶i¦æ¡C
Sophos Central¤Wªº³øªí¸ê®Æ¤º®e»P¨¾¤õÀð±ÂÅv¦³ª½±µÃö«Y¡C Base license¥u¦³«O¯d7¤Ñªº¸ê®Æ¶q¡A ¦³Central Orchestration(¨ó§@) license«h¥i«O¯d30¤Ñªº¸ê®Æ¡A Yn«O¯d¤@¦~ªº¸ê®Æ¡A»Ýn¦³Central Firewall Reporting Advanced¿W¥ß±ÂÅv¡C ¦p¦ó½T»{¨¾¤õÀð©Ò¾Ö¦³ªº³øªí±ÂÅv¡H ¥i¥H¦bÓ§Oªº¨¾¤õÀ𤤪½±µ½T»{¸Ó¨¾¤õÀð¾Ö¦³ªº±ÂÅvºØÃþ¡C ¥H§Ṳ́½¥qªº¨¾¤õÀ𬰨ҡA§Ṳ́½¥q¾Ö¦³ªº¬OXstream Protection bundle±ÂÅv¡Aùر¥]§t¤FCentral Orchestration±ÂÅv¡A ¦]¬°¦³Central Orchestration±ÂÅv¡A©Ò¥H³o¥x¨¾¤õÀð¥i¥H¦bSophos Central¤¤¬d¸ßªñ30¤Ñ¤ºªº¸ê®Æ¡C Y¥u¦³¤@¯ë§K¶O±ÂÅvªº¨¾¤õÀð¡A´N¥u¯à¬d¸ß7¤Ñ¤ºªº³øªí¸ê®Æ¡D ¥t¥~¦³Central Orchestration±ÂÅvªº¨¾¤õÀð¡A¦b³øªí¤¤´N¥i¥H²Õ¦Xªº¤è¦¡¡A¤@¦¸¿ï¾Ü¦h¥x¨¾¤õÀð¡C ³z¹L¦h¥x¨¾¤õÀ𪺳øªí¿é¥X¡A¥i¥HºîÆ[¨ä¶¡ªº®t²§¡C ¦ý¨S¦³Central Orchestration±ÂÅvªº¨¾¤õÀð¡A¨ä§Ç¸¹«e·|¦³¤@Ó i ²Å¸¹¡A ´£¥Ü±z¦h¥x³øªíªº¿é¥X¥u´£¨Ñµ¹¦³¶i¶¥±ÂÅvªº¨¾¤õÀð¡C Multi-device reporting is only available with the Advanced license. ¦Ü©ó´£¨Ñªº³øªí¤º®e¡Aª½±µ¤WSophos CentralªH¬Ý¤ñ¸û§¹¾ã¡C ¦ý¤ñ¸û¦³·N«äªº¬O¡ALog viewer¤]¥X²{¦b¨ä¤¤¡C ¦Ó¥B¥i¥H¬d¸ß¹L¥h´Á¶¡ªºlog°O¿ý¡A ¤£¹³¦aºÝ¥u¯à¬d²{¦b®É¶¡©¹«e±Àªº¤@¬q®É¶¡¸ê®Æ(¦Ó¦aºÝªº³oÓ´Á¶¡ÁÙ¤£©T©w)... ³oºâ¬OÓÅý¤H²´·ú¤@«Gªº¥\¯à¡I ¡ô¨Ò¦p§Ú¥i¥H¬d¸ß«e30¤Ñªºlog°O¿ý¡C
¶l¥óĵ¥Ü¾÷¨î¬O«È¤á«Ü¦b·Nªº¤@Ó¥\¯à¡A ²¦³º³£¤w¸g¦bSophos Central¶°¤¤±±ºÞ¤F¡A©Ò¦³¨¾¤õÀ𪺪¬ºA¤]À³¸Ón¥D°Ê³qª¾¡C ¦bFirewall Management¤¤¦³¤TÓ©w¸q¦nªºÄµ¥ÜÀW²v²ÕºA¡A ¥i¥H¨Ì·Ó»Ý¨D§â¨¾¤õÅéÓÅé©Ô¨ì¹ïÀ³ªº²ÕºA¤¤¡C Defaultªº¹w³]¨C¤K¤p®Éµo°e¤@¦¸¡Dª¬ªpY¥¼±Æ°£¡A«h·|¦b¤K¤p®É«á¦Aµo¤@¦¸¡C Verbose«h¬O¸û±K¶°ªº¡A¨C¤@¤p®É´Nµo°e¤@¦¸¡C ¦ÓSilent«h¬O¤@¤Ñ¥u·|µo°e¤@¦¸¡C ¶l¥óµo°eÀW²v©w¸q¦n¤F¡A¨ºþ¨Ç¤H¤S·|¦¬¨ì¶l¥ó³qª¾©O¡H ¹w³]¬O©Ò¦³Administrators¦¨û³£·|¦¬¨ì«H¡A ¦pªGn½Õ¾ã¡A¥i¥H¦b General Settings ¤¤ªº Configure email alerts ¶i¦æ½Õ¾ã¡C ¦b Adminstrators ¶±¤¤¡A±z¥i¥H½Õ¾ãAdministrators¦¨ûªº±µ¦¬ª¬ºA¡C Y¦³¥~³¡«H½c»Ýn¦¬¨ì«H¡A¥i¥H¦bDistribution lists¤¤¡A±N¶l¥ó«H½c¥[¤J¡C ±z¥i¥H¦bFrequency¤¤¨ÌÄY«©Ê¡B²£«~»PÃþ§O¨Ó½Õ¾ãµo°eÀW²v¡C ¯S§O»¡©ú¤@¤U¡A¸ò¨¾¤õÀð¦³ÃöªºÃþ§O¬°Security¡BSystem health¡BConnectivity»PGeneral³o¥|ÓÃþ§O¡A ³o¥|ÓÃþ§O¹ïÀ³ªº§¹¾ã¨Æ¥ó¡A½Ð°Ñ¦Ò¥H¤U³sµ²¡C Firewall alerts ¥t¥~¤]¥i¥H¦Û¦æ³]©w±ø¥ó¡A¨Ó¨M©wþ¨Ç¤Hn¦¬¨ìþ¨ÇÃþ§OªºÄµ¥Ü«H¥ó¡C ¦ý¤@¥¹«Ø¥ß Custom rules «á¡A¹w³]¡§©Ò¦³Administrators¦¨û³£·|¦¬¨ì³qª¾«H¡¨³oӰʧ@±N·|°±¥Î¡A ©Ò¦³n¦¬¨ì«HªºAdministrators³£n¦³¹ïÀ³ªº Custom rules ¤~·|IJµoĵ¥Ü³qª¾¾÷¨î¡I «Ø¥ß Custom rules ªº²Ä¤@¨B¡A´N¬O¿ï¾Üadmin¨¤¦â»P¦¨û¡C Admin¿ï¦n«á¡A±µµÛ¿ï»Ýn¦¬¨ì³qª¾ªº¥~³¡«H½c(¦pªG¦³ªº¸Ü)¡C ±µµÛ¿ï¾Ün¦¬¨ìªºÄµ¥Ü«H¥óÃþ§O±ø¥ó¡C ¡ô³oÃä°O±o§â¸ò¨¾¤õÀð¦³Ãöªº¥|ÓÃþ§OSecurity¡BSystem health¡BConnectivity»PGeneral³£¿ï°_¨Ó³á¡ã §¹¦¨«á¡A«ö¤USaveÀx¦s¡C ¦pªG¦³¹ïÀ³ªº¨Æ¥óµo¥Íªº¸Ü¡A¦¬¥ó¤Hªº«H½c´N·|¦¬¨ì¨Ó¦ÛSophos Centralªº³qª¾«H¥ó¡C ¦pªG¦bCustom rulen«Ø¥ß«á¡A¤S§ârule¤¤ªºadmin±b¸¹°±¥Î¡A¤£¦¬³qª¾«H¡C «h¸ÓCustom rule·|¦]¬°¦¬«H±b¸¹¦³°ÝÃD¦Ó³Q±j¢°±¥Î¡C ÂI¶}³W«h¡A¥i¥H¬d¬Ý¨äª¬ºA¡A¥H¥»¨Ò¨Ó»¡¡A¦]¬°¹ïÀ³ªº±b¸¹³Q°±¥Î¡A©Ò¥H¥X²{±b¸¹¤£¦s¦bªº¿ù»~¡C ³o¼Ëªº¿ù»~¥²»Ý¥h½s¿è¦¹³W«h¡Aª½¨ì×¥¿¿ù»~«á¡A³W«h¤~¯à¦A¦¸¹B§@¡C
Sophos Central¤¤ªºSD-WAN Connection Groups¨ä¹ê´N¬O§â¦h¥x¨¾¤õÀð¥Hroute baseªºsite to site VPN¦ê°_¨Ó¡A µM«á³z¹Lpolicy route¥h¾É³q¥»¦a»P»·ºÝªº¤À¨Éºô¬q¡C ¥H¤U¶¶¤l¥H¨â¥x¨¾¤õÀ𬰨ҡA¤@¨B¨B¾Þ§@¡A¬Ý¬Ý¦¹¥\¯à¦p¦ó³z¹LºëÆF§âroute base site to site VPN«Ø°_¨Ó¡C º¥ý¡A§Ú̫إߤ@ÓConnection group¡C µM«á§â¥Ø¼Ðªº¨â¥x¨¾¤õÀð¥[¤J¦¹group¡C ²Ä¤G¨B¡A´N¬O§âsite to site VPN¤¤n¤À¨Éµ¹¹ïºÝªº¸ê·½¥[¤J¡C ¨â¥x¨¾¤õÀðn¤À¨Éªººô¬q¸ê·½³£¥[¤J«á¡A«ö¤U¤@¨B¡C ¨ì²Ä¤T¨BConfigure Networks¡A·|´£¥ÜÁÙ¨S¦³¥»¦a¸ê·½¡C ®i¶}«á¡A³v¤@§â¨â¥x¨¾¤õÀ𪺥»¦a¸ê·½¥[¤J¡C ¥»¦a¸ê·½¥]¥»¦aªººô¬q»P¥Î¨Ó¼·±µªºWAN Port¡C ¨â¥x¸ê·½³£¥[¤J«á¡A«ö¤U§¹¦¨¡C §¹¦¨«á»Ýnµ¹¥¦¤@ÂI®É¶¡¡A±N²ÕºA³¡¸p¨ì¨â¥x¨¾¤õÀ𤤡C ³¡¸p§¹¦¨¡A¨â²Õªºª¬ºA·|Åã¥Üºñ¿O¡C ¨ì¦aºÝ¨¾¤õÀð¥h¬Ý¡A·|µo²{¦¹ºëÆF¤w¦¨¥\«Ø¥ß¤@±øtunnel baseªºSite to site VPN¡C ¨Ã¦b¹ïÀ³ªºWAN port¤W¡A«Ø¥ß¤@ÓVPN tunnelªº¤¶±IP¡C ¦P®É¥H¦¹IP«Ø¥ß¤F¤@Ógateway¡C ¨Ã¥H³]©wªº¥»¦aºô毁»P¹ïºÝ¤À¨Éªººô¬q³z¹Lpolicy route«Ø¥ß¤F«ü¦V³W«h¡C ³z¹L³o¼Ëªº¥Ü½d¡A§ÚÌ¥i¥H²M·¡¬Ý¨ìSD-WAN Connection Groups½T¹ê´N¬O§â¦h¥x¨¾¤õÀð¡A ¥Hroute baseªºsite to site VPN¦ê°_¨Óªº¤@ÓºëÆF¡ã
Powered by: Burning Board 1.1.1 2001 WoltLab GbR