Mastering in pfSense VPN - IPSec, L2TP, OpenVPN, OSPF - 2025

所在平台: Udemy

课程主页: https://www.udemy.com/course/pfsense-firewall-mastering-in-openvpn-site-to-site-vpn/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** pfSense VPN 精通 - IPSec, L2TP, OpenVPN, OSPF - 2025 **课程概述:** 本视频培训系列专注于实操演示如何配置 pfSense 防火墙,以实现多站点之间的安全互联。课程涵盖了以下关键内容: 1. **点对点共享密钥 VPN 隧道配置:** 演示如何配置一个基本的 Site-to-Site VPN 隧道,使用共享密钥进行认证。 2. **共享密钥 VPN 升级至 SSL/TLS VPN:** 指导如何将不安全的点对点共享密钥 VPN 转换为更安全的点对点 SSL/TLS VPN 隧道。 3. **IPSec VPN 隧道从零配置:** 全面讲解如何从头开始配置 IPSec VPN 隧道,实现办公室之间的互联。 4. **SSL/TLS VPN 上的多站点 VPN 配置:** 演示如何配置一个 Site-to-Multi-Site VPN,使多个分支机构能够安全地相互通信,并介绍相关的特殊配置。 5. **OPNsense 作为 OpenVPN 客户端连接 pfSense:** 展示如何将 OPNsense 防火墙配置为 OpenVPN 客户端,连接到 pfSense 防火墙,并建立 Site-to-Site VPN。 6. **pfSense 与 Active Directory/LDAP 集成:** 讲解如何将 pfSense 防火墙与 Active Directory 或 LDAP 集成,以集中化地增强 OpenVPN 的安全性。 7. **IPsec 远程访问 VPN (IKEv2/EAP-MSCHAPv2):** 分步指导如何配置 IPsec 远程访问 VPN,使用 IKEv2 和 EAP-MSCHAPv2 身份验证方法。 **为何需要 Site-to-Site VPN:** Site-to-Site VPN 允许您仅需配置远程子网中的网关,而无需单独配置网络节点。简而言之,Site-to-Site 方法将两个办公室连接到同一个网络。本课程将通过物理和虚拟网络的连接示例进行讲解。 **VPN 配置方式:** 您可以选择通过点对点(共享密钥)、点对点(SSL/TLS)和 IPSec VPN 隧道来配置 Site-to-Site VPN。 **重要安全提示:** OpenVPN 已弃用“点对点(共享密钥)”模式,因为它不符合最新的安全标准,并且将在未来版本中移除。因此,强烈建议将现有的“点对点(共享密钥)”VPN 升级为 SSL/TLS,并避免配置新的“共享密钥”OpenVPN 实例。 **前提条件:** 成功配置 pfSense 网络并满足所有先决条件。如果您不熟悉 pfSense 防火墙的安装和配置,课程中推荐观看相关的先前视频。 **网络场景:** 课程将详细讨论各种网络场景,并使用最新版本的 pfSense 防火墙 (2.7.0) 在所有分支机构中进行安装和运行。我们将创建多个站点,如“总公司”、“多个分支机构”等,这些站点可能位于同一城市、国内不同地区,乃至不同大洲,均位于您的 LAN 之外。 **课程价值:** 通过 Site-to-Site VPN,您可以实现远程站点资源的无缝访问,如同在内部 LAN 中工作一样,从而提供及时有效的远程支持,并跨网络共享服务器、桌面和打印机等 IT 资源。此外,通过 Site-to-Site VPN 连接您的站点或分支机构,您可以获得对网络的完全控制,强制执行集中的企业策略,控制互联网活动,并在互联的分支机构中实施 Active Directory 组策略,从而实现无限的可用控制。

课程评论(0条)

课程详情

In this video training series, I am going to practically demonstrate to you how to configure a Site-to-Site VPN between 2 or more sites/ branches, and interconnection between your head office and branches.These are 7 parts of the mastering video series. 1- Configure Site-to-Site VPN with a Peer-to-Peer Shared Key VPN tunnel.2- Convert Peer-to-Peer Shared Key non-security standard VPN tunnel to a "Peer-to-Peer SSL/TLS VPN tunnel"3- Configure an "IPSec VPN Tunnel" from scratch and interconnect your offices.4- Configure a Site-to-Multi-Site VPN over SSL/TLS VPN Tunnel how multiple branches can communicate securely with each other and what special configurations are involved.5- Connect the OPNsense firewall as an OpenVPN client situated in our different branch, show you how to connect your OPNsense as an OpenVPN Client with the pfSense firewall, and establish a site-to-site VPN.6- pfSense firewall incorporation with Active Directory or LDAP & centrally enhance your OpenVPN security.7- Configure step-by-step, IPsec Remote Access VPN Using IKEv2 with EAP-MSCHAPv2 authentication method.Why Site-to-Site VPN?Site-to-Site allows you to configure only gateways in remote subnets, and you do not need to configure the network nodes themselves. In simple terms, the Site-to-Site method connects two offices to a single network, and the Point-to-Site method connects remote employees to the office. In this video lecture, we will consider an example of connecting two existing networks - physical and virtual.You can configure your Site-to-Site VPN over the Peer-to-Peer (Shared Key), Peer-to-Peer (SSL/TLS), and IPsec VPN Tunnel.Please note: OpenVPN has deprecated the "Peer-to-Peer (Shared Key)" mode as it does not meet recent security standards. The shared key mode will be removed from future versions. So, you should convert any existing "Peer-to-Peer (Shared Key)" VPNs to SSL/TLS and avoid configuring any new "Shared Key" OpenVPN instances.Setting up your pfSense network and satisfying all the prerequisites are fairly very straightforward, if you want to know how to install and configure the pfSense firewall in your network then watch my related video created earlier.Network Diagram & the ScenarioFirst, we will discuss all possible network scenarios in detail and identically install and run pfSense firewall 2.7.0, the latest version, at all of our branches. We will create several sites, "Head Office, Numerous Branch Offices," or we could have more sites. They might be located in the same city, out of the region, maybe countrywide, or on different continents, but out of your LAN premises.So how could you be connected to each remote site and access the resources equally the same as you are working in your internal LAN, to deliver timely and effective remote support and share IT resources between the servers, desktops, and printers across the networks?Nonetheless, if you connect your sites or branches over the "Site-to-Site VPN" then your network will be in your complete control egregiously, you could also enforce the centralized corporate policy to control internet activities, implement Active Directory Group Policies all over your interconnected branches, and so much indefinite viable controls.

课程标签

0人关注该课程

主题相关的课程