Mokhoa oa ho theha Hailbytes VPN netefatso

Selelekela

Kaha joale u na le setaele sa HailBytes VPN 'me u se u hlophisitse, u ka qala ho hlahloba tse ling tsa likarolo tsa ts'ireletso tseo HailBytes e fanang ka tsona. U ka sheba blog ea rona bakeng sa litaelo tsa ho seta le likarolo tsa VPN. Sehloohong sena, re tla akaretsa mekhoa ea netefatso e tšehetsoeng ke HailBytes VPN le mokhoa oa ho eketsa mokhoa oa ho netefatsa.

Overview

HailBytes VPN e fana ka mekhoa e mengata ea netefatso ntle le netefatso ea setso ea lehae. Ho fokotsa likotsi tsa ts'ireletso, re khothaletsa ho tima netefatso ea lehae. Sebakeng seo, re khothaletsa netefatso ea lintho tse ngata (MFA), OpenID Connect, kapa SAML 2.0.

  • MFA e eketsa karolo e 'ngoe ea ts'ireletso holim'a netefatso ea lehae. HailBytes VPN e kenyelletsa mofuta oa lehae o hahelletsoeng kahare le ts'ehetso bakeng sa MFA ea kantle bakeng sa bafani ba boitsebahatso ba bangata ba joalo ka Okta, Azure AD, le Onelogin.

 

  • OpenID Connect ke lera la boitsebiso le hahiloeng holim'a protocol ea OAuth 2.0. E fana ka mokhoa o sireletsehileng le o tloaelehileng oa ho netefatsa le ho fumana lintlha tsa mosebelisi ho tsoa ho mofani oa boitsebiso ntle le ho kena hangata.

 

  • SAML 2.0 ke mokhoa o bulehileng oa XML oa ho fapanyetsana lintlha tsa netefatso le tumello lipakeng tsa mekha. E lumella basebelisi ho netefatsa hang le mofani oa boitsebiso ntle le ho netefatsa hape ho fihlella lits'ebetso tse fapaneng.

OpenID Connect le Azure Seta

Karolong ena, re tla bua ka bokhuts'oane mabapi le mokhoa oa ho hokahanya mofani oa hau oa boitsebiso ka OIDC Multi-Factor Authentication. Tataiso ena e reretsoe ho sebelisa Azure Active Directory. Bafani ba boitsebahatso ba fapaneng ba kanna ba ba le litlhophiso tse sa tloaelehang le litaba tse ling.

  • Re u khothalletsa hore u sebelise e 'ngoe ea lik'hamphani tse tšehetsang le tse lekiloeng ka botlalo: Azure Active Directory, Okta, Onelogin, Keycloak, Auth0, le Google Workspace.
  • Haeba o sa sebelise mofani oa OIDC ea khothaletsoang, ho hlokahala litlhophiso tse latelang.

           a) discovery_document_uri: URI ea tlhophiso ea mofani oa OpenID Connect e khutlisetsang tokomane ea JSON e sebelisitsoeng ho etsa likopo tse latelang ho mofani enoa oa OIDC. Bafani ba bang ba bitsa sena "URL e tsebahalang".

          b) client_id: ID ea moreki ea kopo.

          c) client_secret: Lekunutu la moreki la kopo.

          d) redirect_uri: E laela mofani oa OIDC hore na o tla fetisetsa hokae ka mor'a ho netefatsa. Ena e lokela ho ba Firezone ea hau EXTERNAL_URL + /auth/oidc/ /callback/, mohlala https://firezone.example.com/auth/oidc/google/callback/.

          e) response_type: Beha khoutu.

          f) scope: OIDC scopes ho fumana ho tsoa ho mofani oa hau oa OIDC. Bonyane, Firezone e hloka openid le scopes tsa imeile.

          g) label: Sengoloa sa leibole ea konopo e bonts'itsoeng leqepheng la ho kena portal ea Firezone.

  • E ea leqepheng la Azure Active Directory ho portal ea Azure. Khetha sehokelo sa ngoliso ea App tlasa Manage menu, tobetsa Ngoliso e Ncha, 'me u ingolise ka mor'a ho kenya tse latelang:

          a) Lebitso: Firezone

          b) Mefuta ea ak'haonte e tšehetsoeng: (Default Directory feela - Mohiri a le mong)

          c) Tsamaisa URI hape: Ena e lokela ho ba Firezone ea hau EXTERNAL_URL + /auth/oidc/ /callback/, mohlala https://firezone.example.com/auth/oidc/azure/callback/.

  • Kamora ho ingolisa, bula pono ea lintlha tsa kopo ebe u kopitsa ID ea Kopo (moreki). Ena e tla ba boleng ba client_id.
  • Bula lethathamo la li-endpoints ho fumana tokomane ea metadata ea OpenID Connect. Ena e tla ba boleng ba discovery_document_uri.

 

  • Khetha sehokelo sa Litifikeiti le liphiri tlas'a menu ea Laola 'me u thehe lekunutu le lecha la moreki. Kopitsa lekunutu la moreki. Ena e tla ba boleng ba client_secret.

 

  • Khetha sehokelo sa litumello tsa API tlasa Manage menu, tobetsa Kenya tumello, ebe u khetha Microsoft Graph. Kenya lengolo-tsoibila, openid, offline_access le profaele ho litumello tse hlokahalang.

 

  • E ea leqepheng la / litlhophiso / ts'ireletso ho portal ea admin, tobetsa "Eketsa OpenID Connect Provider" 'me u kenye lintlha tseo u li fumaneng mehatong e kaholimo.

 

  • Numella kapa o tima khetho ea Auto Auto ya ho iketsetsa mosebelisi ea se nang tokelo ha o kena ka mochini ona oa netefatso.

 

Kea u babatsa! U lokela ho bona konopo ea ho kena ka Azure leqepheng la hau la ho kena.

fihlela qeto e

HailBytes VPN e fana ka mekhoa e fapaneng ea netefatso, ho kenyelletsa netefatso ea lintlha tse ngata, OpenID Connect, le SAML 2.0. Ka ho kopanya OpenID Connect le Azure Active Directory joalo ka ha ho bonts'itsoe sengolong, basebetsi ba hau ba ka fumana lisebelisoa tsa hau habonolo le ka mokhoa o sireletsehileng ho Cloud kapa AWS.