{"id":6869,"date":"2022-04-22T14:25:30","date_gmt":"2022-04-22T21:25:30","guid":{"rendered":"https:\/\/www.xh86.me\/?p=6869"},"modified":"2022-04-22T14:25:30","modified_gmt":"2022-04-22T21:25:30","slug":"%e4%b8%80%e7%af%87%e8%83%bd%e8%a7%a3%e5%86%b390%e4%bb%a5%e4%b8%8assl-vpn%e9%97%ae%e9%a2%98%e7%9a%84%e6%ad%a6%e6%9e%97%e7%a7%98%e7%b1%8d","status":"publish","type":"post","link":"https:\/\/www.xh86.me\/?p=6869","title":{"rendered":"\u4e00\u7bc7\u80fd\u89e3\u51b390%\u4ee5\u4e0aSSL VPN\u95ee\u9898\u7684\u6b66\u6797\u79d8\u7c4d"},"content":{"rendered":"<div class=\"wxsyncmain\">\n<section><\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u524d\u9762\u6211\u4eec\u5df2\u7ecf\u901a\u8fc7\u51e0\u7bc7\u6587\u7ae0\u628aSSL VPN\u76843\u79cd\u63a5\u5165\u65b9\u5f0f\u548c\u5bf9\u5e94\u7684\u5de5\u4f5c\u673a\u5236\u4e86\u89e3\u4e86\uff0cIP\u63a5\u5165\u65b9\u5f0f\u8bf7\u67e5\u770b<strong>\uff08<\/strong><strong>VSR\u767d\u9001\u7684SSL VPN\u529f\u80fd\uff0c\u4f60\u8981\u4e0d\u8981\uff1f<\/strong><strong>\uff09<\/strong><\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u73b0\u5728\u6211\u4eec\u56de\u8fc7\u5934\u6765\u8865\u5145\u4e00\u4e9b\u548c\u5b9e\u9645\u4f7f\u7528\u76f8\u5173\u7684\u7ec6\u8282\u95ee\u9898\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u9996\u5148\u770b\u4e00\u4e0bSSL VPN\u7f51\u5173\u7684\u90e8\u7f72\u65b9\u5f0f\uff0c\u4e3b\u8981\u6709\u4e24\u79cd\uff1a<strong>\u7f51\u5173\u6a21\u5f0f\u548c\u65c1\u8def\u6a21\u5f0f<\/strong>\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u5148\u770b\u6211\u4eec\u5728\u4e91\u4e0a\u90e8\u7f72VSR\u65f6\u4f7f\u7528\u7684<strong>\u65c1\u8def\u6a21\u5f0f<\/strong>\uff0c\u53c8\u79f0<strong>\u5355\u81c2\u65c1\u6302\u3001\u5355\u81c2\u6a21\u5f0f<\/strong>\u3002\u6b64\u65f6SSL VPN\u7f51\u5173\u548c\u5185\u7f51\u7684\u4e1a\u52a1\u7f51\u5173\u4e0d\u662f\u540c\u4e00\u53f0\u8bbe\u5907\uff0cSSL VPN\u76f8\u5173\u7684\u4e1a\u52a1\u6d41\u91cf\u9700\u8981\u7ecf\u4e1a\u52a1\u7f51\u5173\u7ed5\u8f6c\u5230SSL VPN\u7f51\u5173\u3002\u56e0\u4e3aSSL VPN\u7f51\u5173\u4e0d\u5904\u5728\u4e1a\u52a1\u6d41\u91cf\u8f6c\u53d1\u7684\u5173\u952e\u8def\u5f84\u4e0a\uff0c\u6027\u80fd\u53ea\u9700\u6ee1\u8db3SSL VPN\u7684\u4e1a\u52a1\u6027\u80fd\u5373\u53ef\uff0c\u5373\u4f7f\u6027\u80fd\u4e0d\u8db3\u4e5f\u4e0d\u4f1a\u5f71\u54cd\u5176\u4ed6\u5185\u5916\u7f51\u901a\u4fe1\u3002\u751a\u81f3\u8bbe\u5907\u5b95\u673a\u4e5f\u53ea\u662f\u5f71\u54cdSSL VPN\u4e1a\u52a1\u3002<\/p>\n<p style=\"margin-top: 5px; margin-bottom: 5px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-27341076c8a2a09f3f144b6daf0e02ed.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" style=\"height: auto !important;\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-27341076c8a2a09f3f144b6daf0e02ed.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.5291529152915292\" data-type=\"png\" data-w=\"909\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u6240\u4ee5\uff0c\u524d\u9762\u4ecb\u7ecd\u7684\u4e91\u4e0a\u90e8\u7f72VSR\u7684\u573a\u666f\uff0c\u5b9e\u9645\u4e1a\u52a1\u6a21\u578b\u662f\u4e0a\u56fe\u8fd9\u6837\u7684\uff0cGW\u8bbe\u5907\u662f\u4e91\u4e3b\u673a\u7684\u7f51\u5173\u8bbe\u5907\uff0cPC\u548cVSR\u76f4\u63a5\u5efa\u7acbSSL VPN\u96a7\u9053\u8fde\u63a5\u3002VSR\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u8def\u7531\u53ef\u8fbe\uff0cPC\u548cServer\u4e92\u8bbf\u7684\u6d41\u91cf\u5747\u9700\u8981\u7ed5\u8f6cVSR\u8bbe\u5907\uff1b\u800cServer\u548c\u516c\u7f51\u5176\u4ed6\u4e3b\u673a\u901a\u4fe1\u7684\u6d41\u91cf\u76f4\u63a5\u901a\u8fc7\u7f51\u5173\u8bbe\u5907GW\u8f6c\u53d1\uff0c\u65e0\u9700\u7ed5\u8f6cVSR\u3002\u8fd9\u6837\uff0c\u5373\u4f7fVSR\u5b95\u673a\uff0c\u4e5f\u53ea\u662f\u5f71\u54cdSSL VPN\u7528\u6237\u7684\u8bbf\u95ee\u6d41\u91cf\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u800c\u7f51\u5173\u6a21\u5f0f\u662f\u6307\u8bbe\u5907\u4f5c\u4e3a\u5185\u7f51\u7f51\u5173\u4e32\u63a5\u5728\u5185\u5916\u7f51\u4e4b\u95f4\uff0c\u5185\u5916\u7f51\u4e92\u901a\u7684\u6240\u6709\u6d41\u91cf\u9700\u8981\u901a\u8fc7SSL VPN\u7f51\u5173\u8fdb\u884c\u8f6c\u53d1\u3002\u4f18\u52bf\u662f\u7f51\u5173\u6a21\u5f0f\u53ef\u4ee5\u63d0\u4f9b\u5bf9\u5185\u7f51\u7684\u5b8c\u5168\u4fdd\u62a4\uff0c\u4f46\u662f\u7531\u4e8eSSL VPN\u7f51\u5173\u5904\u5728\u5185\u7f51\u4e0e\u5916\u7f51\u901a\u4fe1\u7684\u5173\u952e\u8def\u5f84\u4e0a\uff0c\u5176\u6027\u80fd\u5bf9\u5185\u5916\u7f51\u4e4b\u95f4\u7684\u6570\u636e\u4f20\u8f93\u6709\u5f88\u5927\u7684\u5f71\u54cd\u3002<\/p>\n<p style=\"margin-top: 5px; margin-bottom: 5px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-3cae3f6ceab51965d5d0550c727d6379.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" style=\"height: auto !important;\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-3cae3f6ceab51965d5d0550c727d6379.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.5238095238095238\" data-type=\"png\" data-w=\"903\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u8fd8\u662f\u524d\u9762\u4ecb\u7ecd\u7684\u4e91\u4e0a\u90e8\u7f72VSR\u7684\u573a\u666f\uff0c\u56e0\u4e3a\u6ca1\u6709\u529e\u6cd5\u66ff\u6362\u6389GW\u8bbe\u5907\uff0c\u6240\u4ee5\u53ea\u80fd\u662f\u628aVSR\u4e32\u5728GW\u548cServer\u4e2d\u95f4\u3002\u5982\u679c\u662f\u7269\u7406\u8bbe\u5907\u573a\u666f\uff0c\u5728SSL VPN\u7f51\u5173\u80fd\u6ee1\u8db3\u4e1a\u52a1\u9700\u6c42\u7684\u60c5\u51b5\u4e0b\uff0c\u53ef\u4ee5\u5c06SSL VPN\u7f51\u5173\u590d\u7528\u4e3a\u4e1a\u52a1\u7f51\u5173\uff0c\u964d\u4f4e\u90e8\u7f72\u6210\u672c\u3002\u4f46\u5982\u679cSSL VPN\u7f51\u5173\u5b95\u673a\uff0c\u6240\u6709\u4e1a\u52a1\u5747\u53d7\u5f71\u54cd\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u7efc\u4e0a\uff0c<strong>\u5728\u5b9e\u9645\u90e8\u7f72\u65f6\uff0c\u8fd8\u662f\u5efa\u8bae\u4f18\u5148\u8003\u8651\u91c7\u7528\u65c1\u8def\u6a21\u5f0f\u90e8\u7f72<\/strong>\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u7136\u540e\u5c31\u662fSSL VPN\u7f51\u5173\u7684\u914d\u7f6e\u4e86\u3002\u6211\u4eec\u524d\u9762\u662f\u628a3\u79cd\u63a5\u5165\u65b9\u5f0f\u5206\u5f00\u8bb2\u7684\uff0c\u5176\u5b9e\u4e5f\u662f\u53ef\u4ee5\u7ec4\u5408\u5728\u4e00\u8d77\u8fdb\u884c\u4f7f\u7528\u7684\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u53ef\u4ee5\u53d1\u73b0\uff0c3\u79cd\u63a5\u5165\u65b9\u5f0f\u4e2dSSL\u670d\u52a1\u5668\u7aef\u7684\u7b56\u7565\u914d\u7f6e\u90fd\u662f\u4e00\u6837\u7684\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u9996\u5148\u914d\u7f6ePKI\u57df\uff0c\u5e76\u5bfc\u5165CA\u8bc1\u4e66\u548c\u670d\u52a1\u5668\u8bc1\u4e66\uff0c\u8bc1\u4e66\u7684\u751f\u6210\u65b9\u5f0f\u8bf7\u53c2\u8003\u6587\u7ae0\uff08Windows Server\u914d\u7f6e\u751f\u6210\u8ba4\u8bc1\u8bc1\u4e66\uff09\u3002\u7136\u540e\u914d\u7f6eSSL\u670d\u52a1\u5668\u7aef\u7b56\u7565\uff0c\u5e76\u7ed1\u5b9aPKI\u57df\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"sql\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">pki domain guotiejun<\/span><\/code><code><span class=\"code-snippet_outer\"> public-key rsa general name guotiejun<\/span><\/code><code><span class=\"code-snippet_outer\"> undo crl <span class=\"code-snippet__keyword\">check<\/span> <span class=\"code-snippet__keyword\">enable<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">pki <span class=\"code-snippet__keyword\">import<\/span> <span class=\"code-snippet__keyword\">domain<\/span> guotiejun pem ca filename certguo.cer<\/span><\/code><code><span class=\"code-snippet_outer\">pki <span class=\"code-snippet__keyword\">import<\/span> <span class=\"code-snippet__keyword\">domain<\/span> guotiejun p12 <span class=\"code-snippet__keyword\">local<\/span> filename serverguo.pfx<\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">ssl\u00a0<span class=\"code-snippet__keyword\">server<\/span>-<span class=\"code-snippet__keyword\">policy<\/span>\u00a0guotiejun<\/span><\/code><code><span class=\"code-snippet_outer\"> pki-<span class=\"code-snippet__keyword\">domain<\/span> guotiejun<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">SSL VPN\u7f51\u5173\u914d\u7f6e\u7684IP\u5730\u5740\u548c\u7aef\u53e3\u53f7\u53ef\u4ee5\u5408\u5e76\u4e3a\u4e00\u4e2a\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">sslvpn<\/span> <span class=\"code-snippet__string\">gateway guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">ip<\/span> <span class=\"code-snippet__string\">address 172.30.1.19 port 10086<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">ssl<\/span> <span class=\"code-snippet__string\">server-policy guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">service<\/span> <span class=\"code-snippet__string\">enable<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">IP\u63a5\u5165\u65b9\u5f0f\u9700\u8981\u521b\u5efaSSL VPN AC\u63a5\u53e3\uff0c\u4ee5\u53ca\u4e3aSSL VPN\u5ba2\u6237\u7aef\u5206\u914d\u5730\u5740\u7684\u5730\u5740\u6c60\uff0c\u8fd8\u8981\u521b\u5efa\u5141\u8bb8SSL VPN\u5730\u5740\u6c60\u8bbf\u95ee\u8d44\u6e90\u7684ACL\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"css\"><code><span class=\"code-snippet_outer\">#<\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__selector-tag\">interface<\/span> <span class=\"code-snippet__selector-tag\">SSLVPN-AC1<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__selector-tag\">ip<\/span> <span class=\"code-snippet__selector-tag\">address<\/span> 10<span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.1<\/span> 255<span class=\"code-snippet__selector-class\">.255<\/span><span class=\"code-snippet__selector-class\">.255<\/span><span class=\"code-snippet__selector-class\">.0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">#<\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__selector-tag\">sslvpn<\/span> <span class=\"code-snippet__selector-tag\">ip<\/span> <span class=\"code-snippet__selector-tag\">address-pool<\/span> <span class=\"code-snippet__selector-tag\">tiejun<\/span> 10<span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.100<\/span> 10<span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.200<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">#<\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__selector-tag\">acl<\/span> <span class=\"code-snippet__selector-tag\">advanced<\/span> 3402<\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__selector-tag\">rule<\/span> 0 <span class=\"code-snippet__selector-tag\">permit<\/span> <span class=\"code-snippet__selector-tag\">ip<\/span> <span class=\"code-snippet__selector-tag\">source<\/span> 10<span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.0<\/span> 0<span class=\"code-snippet__selector-class\">.0<\/span><span class=\"code-snippet__selector-class\">.0<\/span><span class=\"code-snippet__selector-class\">.255<\/span> <span class=\"code-snippet__selector-tag\">destination<\/span> 172<span class=\"code-snippet__selector-class\">.30<\/span><span class=\"code-snippet__selector-class\">.1<\/span><span class=\"code-snippet__selector-class\">.0<\/span> 0<span class=\"code-snippet__selector-class\">.0<\/span><span class=\"code-snippet__selector-class\">.0<\/span><span class=\"code-snippet__selector-class\">.255<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u7136\u540e\u5c31\u662f\u628a3\u79cd\u63a5\u5165\u65b9\u5f0f\u7684\u8bbf\u95ee\u5b9e\u4f8b\u914d\u7f6e\u878d\u5408\u5230\u4e00\u8d77\u3002IP\u63a5\u5165\u65b9\u5f0f\u6dfb\u52a0\u8d44\u6e90172.30.1.0\/24\uff0cWeb\u63a5\u5165\u65b9\u5f0f\u6dfb\u52a0\u8d44\u6e90172.30.1.17\u7684HTTP\u548cHTTPS\u7ba1\u7406\u9875\u9762\uff0cTCP\u63a5\u5165\u65b9\u5f0f\u6dfb\u52a0\u8d44\u6e90172.30.1.17\u7684SSH\u3001FTP\u3001Telnet\u3001HTTP\u548cHTTPS\u7aef\u53e3\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">sslvpn<\/span> <span class=\"code-snippet__string\">context guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">gateway<\/span> <span class=\"code-snippet__string\">guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">ip-tunnel<\/span> <span class=\"code-snippet__string\">interface SSLVPN-AC1<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">ip-tunnel<\/span> <span class=\"code-snippet__string\">address-pool tiejun mask 255.255.255.0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">port-forward-item<\/span> <span class=\"code-snippet__string\">ftp17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__meta\">local-port<\/span> <span class=\"code-snippet__string\">17021 local-name 127.0.0.1 remote-server 172.30.1.17 remote-port 21<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">port-forward-item<\/span> <span class=\"code-snippet__string\">http17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__meta\">local-port<\/span> <span class=\"code-snippet__string\">17080 local-name 127.0.0.1 remote-server 172.30.1.17 remote-port 80<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">port-forward-item<\/span> <span class=\"code-snippet__string\">https17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__meta\">local-port<\/span> <span class=\"code-snippet__string\">17443 local-name 127.0.0.1 remote-server 172.30.1.17 remote-port 443<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">port-forward-item<\/span> <span class=\"code-snippet__string\">ssh17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__meta\">local-port<\/span> <span class=\"code-snippet__string\">17022 local-name 127.0.0.1 remote-server 172.30.1.17 remote-port 22<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">port-forward-item<\/span> <span class=\"code-snippet__string\">telent17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__meta\">local-port<\/span> <span class=\"code-snippet__string\">17023 local-name 127.0.0.1 remote-server 172.30.1.17 remote-port 23<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">port-forward<\/span> <span class=\"code-snippet__string\">tcp<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward-item ftp17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward-item http17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward-item https17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward-item ssh17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward-item telent17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">ip-route-list<\/span> <span class=\"code-snippet__string\">guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">include<\/span> <span class=\"code-snippet__string\">172.30.1.0 255.255.255.0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">url-item<\/span> <span class=\"code-snippet__string\">http17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">url<\/span> <span class=\"code-snippet__string\">http:\/\/172.30.1.17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">url-item<\/span> <span class=\"code-snippet__string\">https17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">url<\/span> <span class=\"code-snippet__string\">https:\/\/172.30.1.17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">url-list<\/span> <span class=\"code-snippet__string\">web<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">heading<\/span> <span class=\"code-snippet__string\">WebManagement<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">url-item http17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">url-item https17<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">policy-group<\/span> <span class=\"code-snippet__string\">guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward tcp<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">filter<\/span> <span class=\"code-snippet__string\">ip-tunnel acl 3402<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__meta\">ip-tunnel<\/span> <span class=\"code-snippet__string\">access-route ip-route-list guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">url-list web<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">default-policy-group<\/span> <span class=\"code-snippet__string\">guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">service<\/span> <span class=\"code-snippet__string\">enable<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u6700\u540e\u5c31\u662f\u521b\u5efa\u6388\u6743\u6709\u7b56\u7565\u7ec4\u7684\u7528\u6237\u7ec4\uff0c\u5e76\u521b\u5efa\u672c\u5730SSL VPN\u7528\u6237\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__meta\">user-group<\/span> <span class=\"code-snippet__string\">sslvpn<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">authorization-attribute<\/span> <span class=\"code-snippet__string\">sslvpn-policy-group guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__meta\">local-user<\/span> <span class=\"code-snippet__string\">guotiejun class network<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">password<\/span> <span class=\"code-snippet__string\">simple guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">service-type<\/span> <span class=\"code-snippet__string\">sslvpn<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">group<\/span> <span class=\"code-snippet__string\">sslvpn<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">authorization-attribute<\/span> <span class=\"code-snippet__string\">user-role network-operator<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u7136\u540e\u5c31\u53ef\u4ee5\u767b\u5f55\u5230SSL VPN\u7f51\u5173\u4e86\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"javascript\"><code><span class=\"code-snippet_outer\">https:<span class=\"code-snippet__comment\">\/\/bj.h3cadmin.cn:10086\/<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"margin-top: 5px; margin-bottom: 5px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-a6e1e60f20979f06dafd18181e4022d7.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" style=\"height: auto !important;\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-a6e1e60f20979f06dafd18181e4022d7.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"1.381578947368421\" data-type=\"png\" data-w=\"836\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u6211\u4eec\u770b\u5230\u9875\u9762\u4e2d\u8fd8\u6709\u4e00\u4e2a\u542f\u52a8IP\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u7684\u5730\u65b9\uff0c\u9ed8\u8ba4\u662f\u6ca1\u6709\u5ba2\u6237\u7aef\u8f6f\u4ef6\u7684\u3002\u6b64\u65f6\u6211\u4eec\u9700\u8981\u5f00\u542f\u8bbe\u5907\u7684\u8f7b\u91cf\u7ea7Web\u670d\u52a1\u5668\u529f\u80fdLighttpd\uff0c\u5e76\u5c06\u5b9a\u5236\u597d\u7684iNode\u5ba2\u6237\u7aef\u91cd\u547d\u540d\u540e\u4e0a\u4f20\u5230\u6307\u5b9a\u8def\u5f84\u3002<\/p>\n<p style=\"margin-top: 5px; margin-bottom: 5px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-5101fb495cc184f56d8d05d92c16a87c.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" style=\"height: auto !important;\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-5101fb495cc184f56d8d05d92c16a87c.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.4153498871331828\" data-type=\"png\" data-w=\"443\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u7b80\u5355\u89e3\u91ca\u4e00\u4e0b\uff0c\u4e3a\u4ec0\u4e48\u8981\u6307\u5b9a\u8def\u5f84\u3002\u56e0\u4e3a\u76ee\u524d\u6682\u65f6\u4e0d\u652f\u6301\u4fee\u6539\u4e0b\u8f7d\u94fe\u63a5\uff0c\u9ed8\u8ba4\u7684\u4e0b\u8f7d\u94fe\u63a5\u5982\u4e0b\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<ul class=\"code-snippet__line-index code-snippet__js\">\n<li><\/li>\n<\/ul>\n<pre class=\"code-snippet__js\" data-lang=\"ruby\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__symbol\">https:<\/span>\/<span class=\"code-snippet__regexp\">\/bj.h3cadmin.cn:10086\/client<\/span><span class=\"code-snippet__regexp\">\/ip\/<\/span>SvpnClient.exe<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u6240\u4ee5\u6211\u4eec\u9700\u8981\u5728Web\u670d\u52a1\u5668\u6839\u76ee\u5f55\u4e0b\u521b\u5efa<strong>client\/ip\/\u8def\u5f84<\/strong>\uff0c\u5e76\u4e14<strong>\u8bbe\u5907\u540d\u79f0\u5fc5\u987b\u4fee\u6539\u4e3aSvpnClient.exe<\/strong>\uff0c\u6240\u4ee5\u6839\u76ee\u5f55\u4e0b\u5fc5\u987b\u6709\u5305\u542bip\u7684\u6587\u4ef6\u5939client\u3002\u914d\u7f6e\u597d\u4e4b\u540e\u5c31\u80fd\u4ece\u9875\u9762\u76f4\u63a5\u4e0b\u8f7dSSL VPN\u5ba2\u6237\u7aef\u4e86\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">TCP\u5ba2\u6237\u7aef\u5c31\u4e0d\u591a\u8bf4\u4e86\uff0c\u7ec8\u7aef\u9700\u8981\u5177\u6709Java\u73af\u5883\uff0c\u5e76\u4e14\u8981\u6dfb\u52a0\u4f8b\u5916\u7ad9\u70b9\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u518d\u5c31\u662f\u5bf9\u7528\u6237\u8bbf\u95ee\u8d44\u6e90\u7684\u6388\u6743\u7ba1\u7406\u90e8\u5206\u4e86\uff0c\u8fd9\u90e8\u5206\u4e4b\u524d\u53d1\u8fc7\u4e00\u7bc7\u5173\u4e8eIP\u63a5\u5165\u65b9\u5f0f\u7684\u8bbf\u95ee\u63a7\u5236<strong>\uff08<\/strong><a href=\"http:\/\/mp.weixin.qq.com\/s?__biz=MzI4NjAzMTk3MA==&amp;mid=2458838812&amp;idx=1&amp;sn=8c41132f39854429adb5d4bf9257e10c&amp;chksm=fc996e11cbeee707eb3f3e0f8bc55f41d76be0e2f290eee97413b5129d56f6f9caef00c240dc&amp;scene=21#wechat_redirect\" data-linktype=\"2\"><strong>SSL VPN\u8bbf\u95ee\u63a7\u5236<\/strong><\/a><strong>\uff09<\/strong>\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u5176\u5b9e\u4e3b\u8981\u5c31\u662f\u901a\u8fc7\u9ad8\u7ea7ACL\uff083000\u6bb5\uff09\u6216\u8005URI ACL\u8fdb\u884c\u8bbf\u95ee\u63a7\u5236\uff0cIP\u63a5\u5165\u65b9\u5f0f\u53ef\u4ee5\u4f7f\u7528\u4e0a\u8ff0\u4e24\u8005\uff0c\u800cWeb\u63a5\u5165\u65b9\u5f0f\u548cTCP\u63a5\u5165\u65b9\u5f0f\u4e3b\u8981\u662f\u901a\u8fc7URI ACL\u3002\u9996\u5148\u5bf9\u6d41\u91cf\u8fdb\u884cURI ACL\u7684\u89c4\u5219\u68c0\u67e5\uff0c\u5339\u914dURI ACL\u4e2dpermit\u89c4\u5219\u653e\u884c\uff1b\u5982\u679cURI ACL\u5339\u914d\u5931\u8d25\uff0c\u518d\u5339\u914d\u9ad8\u7ea7ACL\uff0c\u5339\u914dpermit\u89c4\u5219\u653e\u884c\uff1b\u5982\u679c\u90fd\u5339\u914d\u5931\u8d25\uff0c\u62d2\u7edd\u8bbf\u95ee\u3002\u4f46\u662f\u4e0d\u600e\u4e48\u5b9e\u7528\uff0c\u628a\u8d44\u6e90\u5217\u51fa\u6765\u53c8\u4e0d\u7ed9\u7528\u6237\u8bbf\u95ee\uff0c\u5c5e\u5b9e\u6709\u70b9\u6d41\u6c13\u7684\u610f\u601d\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u5176\u5b9e\u7528\u7684\u6bd4\u8f83\u591a\u7684\u8fd8\u662fsslvpn-policy-group\u548cuser-group\uff0c\u53ef\u4ee5\u521b\u5efa\u7528\u6237\u7ec4\u5339\u914dSSL VPN\u7b56\u7565\u7ec4\uff0c\u56e0\u4e3aSSL VPN\u7b56\u7565\u7ec4\u4e2d\u662f\u6dfb\u52a0\u4e86VPN\u8d44\u6e90\u7684\uff0c\u6240\u4ee5\u76f8\u5f53\u4e8e\u662f\u5728\u7528\u6237\u7ec4\u5185\u7684\u7528\u6237\u90fd\u6709\u8bbf\u95ee\u6743\u9650\uff0c\u53ea\u8981\u8c03\u6574\u7528\u6237\u6216\u8005\u7528\u6237\u7ec4\u5c31\u80fd\u8fdb\u884c\u533a\u5206\u4e86\u3002\u4e5f\u53ef\u4ee5\u914d\u7f6e\u672c\u5730\u7528\u6237\u76f4\u63a5\u5339\u914dSSL VPN\u7b56\u7565\u7ec4\uff0c\u770b\u4e2a\u4eba\u559c\u597d\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u6b64\u65f6\u6211\u4eec\u518d\u521b\u5efa\u4e00\u4e2aSSL VPN\u7b56\u7565\u7ec4yancaipin\uff0c\u53ea\u6dfb\u52a0TCP\u8d44\u6e90\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">sslvpn<\/span> <span class=\"code-snippet__string\">context guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">policy-group<\/span> <span class=\"code-snippet__string\">yancaipin<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">  <span class=\"code-snippet__attr\">resources<\/span> <span class=\"code-snippet__string\">port-forward tcp<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u7136\u540e\u521b\u5efa\u4e00\u4e2a\u7528\u6237yancaipin\uff0c\u76f4\u63a5\u5339\u914dSSL VPN\u7b56\u7565\u7ec4yancaipin\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"ruby\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">local-user yancaipin <span class=\"code-snippet__class\"><span class=\"code-snippet__keyword\">class<\/span> <span class=\"code-snippet__title\">network<\/span><\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> password simple yancaipin<\/span><\/code><code><span class=\"code-snippet_outer\"> service-type sslvpn<\/span><\/code><code><span class=\"code-snippet_outer\"> authorization-attribute user-role network-operator<\/span><\/code><code><span class=\"code-snippet_outer\"> authorization-attribute sslvpn-policy-group yancaipin<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u767b\u5f55\u8d26\u53f7yancaipin\u8bd5\u4e00\u4e0b\u3002<\/p>\n<p style=\"margin-top: 5px; margin-bottom: 5px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-ffde63a23e44a89209ee182856d012c0.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" style=\"height: auto !important;\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-ffde63a23e44a89209ee182856d012c0.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.7172330097087378\" data-type=\"png\" data-w=\"824\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u53ef\u4ee5\u770b\u5230Web\u8d44\u6e90\u6ca1\u6709\u4e86\uff0c\u53ea\u5269\u4e0bTCP\u8d44\u6e90\u4e86\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u6700\u540e\u5e94\u8be5\u5c31\u662f\u9650\u5236\u5728\u7ebf\u7528\u6237\u4e86\uff0c\u7f3a\u7701\u60c5\u51b5\u4e0b\uff0c\u540c\u4e00\u7528\u6237\u7684\u540c\u65f6\u6700\u5927\u5728\u7ebf\u6570\u4e3a32\uff0c\u5982\u679c\u7528\u5230\u4e0a\u9762\u7684\u5206\u7c7b\u7528\u6237\u4e86\uff0c\u90a3\u80af\u5b9a\u662f\u8981\u533a\u5206\u7528\u6237\u7684\uff0c\u6240\u4ee5\u6211\u4eec\u4e00\u822c\u5c06\u6bcf\u4e2a\u7528\u6237\u540d\u7684\u540c\u65f6\u6700\u5927\u5728\u7ebf\u6570\u9650\u5236\u4e3a2-3\u4e2a\uff0c\u6309\u4e2a\u4eba\u7ec8\u7aef\u7b97\u3002\u914d\u7f6e\u65b9\u5f0f\u4e3a\u5728SSL VPN\u8bbf\u95ee\u5b9e\u4f8b\u89c6\u56fe\u4e2d\u914d\u7f6e\uff0c\u540c\u65f6\u5f00\u542f\u8fbe\u5230\u6700\u5927\u5728\u7ebf\u6570\u518d\u767b\u5f55\u65f6\u5f3a\u5236\u4e0b\u7ebf\u529f\u80fd\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"bash\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">sslvpn context guotiejun<\/span><\/code><code><span class=\"code-snippet_outer\"> max-onlines 3<\/span><\/code><code><span class=\"code-snippet_outer\"> force-logout max-onlines <span class=\"code-snippet__built_in\">enable<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u4e0e\u6b64\u76f8\u5173\u7684\u6709\u4e00\u4e2aSSL VPN\u8bbf\u95ee\u5b9e\u4f8b\u7684\u6700\u5927\u4f1a\u8bdd\u6570\uff0c\u7f3a\u7701\u6700\u5927\u4f1a\u8bdd\u6570\u4e3a1048575\uff0c\u8fd9\u4e2a\u5c31\u4e0d\u7528\u7ba1\u4e86\u3002\u8fd8\u6709\u6bcf\u4e2a\u4f1a\u8bdd\u7684\u6700\u5927\u8fde\u63a5\u6570\u7f3a\u7701\u4e3a64\uff0c\u4e5f\u4e0d\u7528\u7ba1\u3002\u8fd8\u6709\u4e00\u4e2aSSL VPN\u4f1a\u8bdd\u4fdd\u6301\u7a7a\u95f2\u72b6\u6001\u7684\u6700\u957f\u65f6\u95f4\uff0c\u7f3a\u7701\u4e3a30\u5206\u949f\uff0c\u53ef\u4ee5\u89c6\u60c5\u51b5\u8fdb\u884c\u8c03\u6574\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">sslvpn<\/span> <span class=\"code-snippet__string\">context guotiejun<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">timeout<\/span> <span class=\"code-snippet__string\">idle 60<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u518d\u6709\u53ef\u80fd\u5c31\u662f\u9650\u901f\u4e86\uff0c\u5982\u679c\u7528\u6237\u6bd4\u8f83\u591a\uff0c\u9650\u901f\u8fd8\u662f\u5f88\u6709\u5fc5\u8981\u7684\u3002IP\u63a5\u5165\u65b9\u5f0f\u7684\u9650\u901f\u529f\u80fd\u5982\u4e0b\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"nginx\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attribute\">sslvpn<\/span> context guotiejun<\/span><\/code><code><span class=\"code-snippet_outer\"> ip-tunnel rate-limit upstream kbps <span class=\"code-snippet__number\">2048<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> ip-tunnel rate-limit downstream kbps <span class=\"code-snippet__number\">2048<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u8fd8\u53ef\u4ee5\u57fa\u4e8e\u4f1a\u8bdd\u8fdb\u884c\u9650\u901f\uff0c\u547d\u4ee4\u5982\u4e0b\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"nginx\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attribute\">sslvpn<\/span> context guotiejun<\/span><\/code><code><span class=\"code-snippet_outer\"> rate-limit upstream <span class=\"code-snippet__number\">1024<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> rate-limit downstream <span class=\"code-snippet__number\">1024<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 5px; margin-bottom: 5px;\">\u4ee5\u6211\u5904\u7406\u8fc7\u51e0\u5343\u4e2a\u95ee\u9898\u7684\u7ecf\u9a8c\uff0c\u4e0d\u5938\u5f20\u7684\u8bb2\uff0c\u672c\u7bc7\u4ecb\u7ecd\u7684\u5185\u5bb9\u57fa\u672c\u4e0a\u80fd\u8986\u76d690%\u4ee5\u4e0a\u7684\u5ba2\u6237\u9700\u6c42\u4e86\uff0c\u4e0b\u8bfe\uff01<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u9762\u6211\u4eec\u5df2\u7ecf\u901a\u8fc7\u51e0\u7bc7\u6587\u7ae0\u628aSSL VPN\u76843\u79cd\u63a5\u5165\u65b9\u5f0f\u548c\u5bf9\u5e94\u7684\u5de5\u4f5c\u673a\u5236\u4e86\u89e3\u4e86\uff0cIP\u63a5\u5165\u65b9\u5f0f\u8bf7\u67e5\u770b\uff08VSR\u767d\u9001\u7684 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,2],"tags":[],"class_list":["post-6869","post","type-post","status-publish","format-standard","hentry","category-19","category-network"],"_links":{"self":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/6869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6869"}],"version-history":[{"count":1,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/6869\/revisions"}],"predecessor-version":[{"id":7796,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/6869\/revisions\/7796"}],"wp:attachment":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}