You are on page 1of 3

Tng la, khi nim v cch s dng hiu qu

http://www.pcworld.com.vn/pcworld/printArticle.asp?atcl_id=5f5e5c5a5...

Tng la, khi nim v cch s dng hiu qu


Kt ni my tnh ca mnh vo internet m khng thc hin bt c bin php bo v no th cng ging nh b nh i chi m qun kho ca. trnh mi him ha t internet, chng ta nn s dng tng la. Theo t in Merriam-Webster, 'tng la' (firewall) l mt bc tng c xy dng ngn nga s pht tn ca la t khu vc bp n vi phn cn li ca cn nh. i vi my tnh th tng la gip ngn nga s xm nhp my tnh ca bn bt hp php t bn ngoi (internet) bng cch d tm a ch IP v cc cng TCP, UDP b b ng. Ci t v tinh chnh mt tng la hot ng hiu qu khng phi l cng vic d lm, ngay c khi bn l ngi s dng my tnh nhiu kinh nghim. Bi vit s c gng gip bn vt chng ngi ny. Mi khi chng ta duyt web, chuyn nhn th tn in t hay truy xut tp tin, in n trn mng th cng chnh l lc xy ra hin tng c mt phn mm gin ip trong my bn ang tm cch gi thng tin ra bn ngoi hay c k no trn internet ang tm cch truy cp vo bn trong my tnh bn. Th thut ca chng u nh nhau: d tm cc cng dch v trn my tnh khng c bo mt hay nh la my tnh m cng dch v cho Hnh 1: khi ng chc nng firewall chng xm nhp. ca XP Tng la trn my tnh c chc nng gim st tt c cc cng dch v cho d l kt ni qua modem hay kt ni tc cao, t chi tt c giao dch bt hp php. C hai loi tng la: phn cng nh cc b nh tuyn, dn ng c tch hp chc nng tng la kt ni h thng mng ni b vi ng truyn internet; phn mm c ci t trong my tnh. Nhn chung, s dng tng la bng phn cng tt v hiu qu hn, v ngoi chc nng tng la, thit b cn c thm chc nng che giu ton b cc my tnh trong mng ni b trc internet. T ng la cho mi my tnh Nh trn cp, s dng tng la bng phn cng c nhiu chc nng chuyn bit gip bo v my tnh tt hn. Nhng ngi s dng phi c kin thc v mng, ngoi ra nu kt ni internet ca bn ch l kt ni qua modem th s lng ph mt vi chc nng. S dng tng la bng phn mm th th tc ci t d dng. Bn cnh cc chc nng tng t nh thit b tng la bng phn cng, chng ta cn c th ngn chn cc chng trnh phn mm gin ip chy trn my tnh ca mnh gi d liu ra ngoi, hoc m cng hu chng trnh t xa iu khin my tnh ca bn. Tng la bng phn mm cng rt ph hp khi kt ni internet dng modem. Trong Windows XP li c sn chc nng tng la. Th tc khi ng nh sau: nhn chut chn Start.Control Panel.Network Connection. Nhn chut phi vo biu tng kt ni cn s dng tng la, chn menu c nhn Properties, chn Advanced. nh du chn vo mc c nhn Protect my computer and network by limiting or preventing access to this computer from the Internet. Cui cng nhn phm OK. (Hnh 1) Tuy nhin chc nng tng la trong Windows XP kh hn ch, n ch gim st c cc kt ni n my tnh, cn khng chng c cc phn mm gin ip, 'm cng hu' nh l Back Orifice, NetBus... Chn phn mm tng la min ph Cc phn mm tng la min ph (xem thm phn gii thiu trong bi ny) nhn chung rt d ci t. Nhng ngay sau khi ci t chng ta phi khai bo thm mt s thng tin chng trnh c th qun l cc phn mm c truy cp internet nh trnh duyt, e-mail, chng trnh mng... Mi khi pht hin c mt ng dng bt u truy cp mng, phn mm firewall lin hin ln mt ca s mi yu cu xc nh cho php truy cp hay khng, v mt s thng s gip chn la ch kim sot qu trnh chy

1 of 3

5/29/2013 5:07 PM

Tng la, khi nim v cch s dng hiu qu

http://www.pcworld.com.vn/pcworld/printArticle.asp?atcl_id=5f5e5c5a5...

ca phn mm, v d nh: cho php t do truy cp mng, khai bo cc quy nh kim sot... (hnh 2). V sau mi khi pht hin ng dng truy cp ra internet th phn mm tng la t ng p dng cc quy nh m bn khai bo nh cp. gip tng la hot ng hiu qu, ngi dng phi c kin thc v phn mm ang chy trn my tnh ca mnh, ci no an ton, ci no nguy him... Tt nhin cc phn mm nh Outlook, Internet Explorer, Netscape... th ai cng bit n c an ton hay khng, nhng c rt nhiu phn mm rt kh xc nh tnh cht ny, v d nh ngay trong Windows XP c nhiu chng trnh chc nng m t ngi nh ht c. Thm vo , cc chng Hnh 2: Chn la thng s cu hnh trnh gin ip m cng hu cng rt ranh mnh, li dng vn tng la t ng kim sot ny n mnh hot ng di nhng tn tng chng v hi ng dng nh 'screen saver' lm bn mt cnh gic. V vy mi khi gp mt chng trnh no cha xc nh c c an ton hay khng th tt nht hy cm n truy cp vo internet, theo thi gian bn s hiu c y l chng trnh lm chc nng g v lc tin hnh thay i cch gim st hot ng ca chng cng cha mun. Bn cng c th s dng cc phn mm tng la c chc nng kim nh hot ng ca phn mm c truy cp internet cung cp thm thng tin v phn mm nh do ai sn xut, c chc nng g, tin cy... nhng rt tic trong s 4 chng trnh min ph gii thiu trong bi vit th ch c phn mm ZoneAlarm c chc nng ny (cng rt hn ch). (Hnh 3). Tinh chnh thng s hot ng cho ph hp. Sau khi hon thnh cc bc th tc cu hnh ti thiu phn mm hot ng, bn c th thc hin thm mt s th tc tinh chnh, to thm cc quy tc gim st, cp nht danh sch phn mm cn gim st tng la hot ng ph hp. Th tc thc hin nh sau: Kerio. Nhn chut phi vo biu tng ca Kerio nm trn khay h thng, chn menu c nhn Administration->Firewall->Advanced. Trong ca s cha danh sch cc phn mm Kerio ang gim st, mun thay i thng s, cch gim st hot ng ca phn mm no th nhn chut chn phn mm ri nhn chut vo phm bm c nhn Edit. Trong hp thoi c tiu 'Filter rule' chn phm c nhn l Permit (cho php chy) hay Deny (cm chy) thay i ch gim st hot ng. Ngoi ra cn mt s thng s khc cho php cp nht danh sch a ch IP, danh sch cng dch v internet cn gim st, ngn chn v tham kho ni dung thng bo li ca Kerio thng bo cho ngi s dng. Tuy nhin, a s mi trng hp ch cn s dng cc thng s c bn do Kerio thit lp cng an ton cho h thng ca bn. Outpost. Qun l ng dng c truy cp internet theo 3 tiu chun: cm hon ton, cho php c gii hn v cho php t do hot ng. Mun p dng ch i vi ng dng no th nhn chut phi vo biu tng ca Outpost nm trn khay h thng, chn menu Option->Application. Trong danh sch cc phn mm ( c sp xp theo 3 loi), nhn chut chn phn mm cn thay i cch gim st, chn Edit ri chn ch gim st tng ng. V d chuyn ch gim st mt phn mm t t do hot ng sang ch cho php c gii hn th thc hin nh sau: Nhn chut chn phn mm cn thay i, nhn chut vo phm c nhn Edit, chn menu Create rules using preset ri chn Browser (ch gim st p dng cho cc ng dng khai thc thng tin trn internet nh l mail, trnh duyt....) nh vy ng dng va ri ch c php hot ng vi cc cng TCP v giao thc nht nh m thi. Sygate. Nhn chut phi vo biu tng ca Sygate nm trn khay h Hnh 3: ZoneAlarm cnh thng, chn menu Application. Trong danh sch cc chong trnh ang b bo khi pht hin c qun l, nhn chut phi chn ng dng mun thay i quy tc gim st ri chng trnh l truy cp chn Allow (cho php) hay Block (cm) hay chn Ask Sygate cnh bo internet cho bn bit mi khi ng dng c hnh vi truy cp internet. ZoneAlarm . Nhn chut phi vo biu tng ca ZoneAlarm nm trn khay h thng, chn Restore ZoneAlarm Control Center, chn Program Control, chn tab c nhn Program ri thay i ch gim st hot ng sang 1 trong 4 trng thi: allow access (cho php truy cp internet), X (cm truy cp), du ? (hi kin bn mi khi pht hin c truy cp ra internet).

2 of 3

5/29/2013 5:07 PM

Tng la, khi nim v cch s dng hiu qu

http://www.pcworld.com.vn/pcworld/printArticle.asp?atcl_id=5f5e5c5a5...

Hot ng trong mi trng Windows Networks Mt thng s na cn phi thay i hay ch t cng phi xem xt l vic hot ng ca tng la trong mi trng mng ca Windows. Kerio. Phn mm ny (ngm nh) cm ton b dch v mng ca Windows, ch khi no bn khai bo danh sch a ch IP ca cc my tnh s cng hot ng trong mng. Th tc thc hin nh sau: nhn chut phi vo biu tng ca Kerio nm trn khay h thng (tn cng, bn phi ca thanh taskbar), chn Administration, Microsoft Networking. khai bo mt my tnh s lm vic vi, nhn chut vo nhn Add, chn mc Single address trong hp danh sch 'Address type', nhp vo 'Host address' a ch IP ca my tnh s cng lm vic trong mng. Cui cng nhn phm OK. Nu h thng mng ca bn c bo v bng thit b bc tng la ngn chn truy cp vo mng t cc cng UDP do Windows s dng th bn c th khai bo my tnh ca bn lm vic vi tt c cc my tnh trong mng ni b, th tc thc hin nh sau: b chn ti mc From Trusted Address, ri nhn chn OK. Outpost . Nhn chut phi vo biu tng ca Outpost nm trn khay h thng, chn menu Option, System. Nhn chut nh du chn vo mc c nhn Allow NetBios communication, cui cng nhn OK. Nu my tnh ca bn kt ni trc tip vi internet th khng nn nh du chn ti mc ny khng ai pht hin ra my tnh ca bn ang hin trn trn internet. Sygate. V ngm nh, Sygate cho php tt c cc my tnh trong mi trng mng ca Windows nhn thy my tnh ca bn nhng khng cho php truy cp tp tin v my in dng chung. Mun cho php, th tc thc hin nh sau: nhn chut phi vo biu tng ca Sygate nm trn khay h thng, chn menu Options, Network Neighborhood. Nhn chut chn card mng s lm vic trong mi trng mng ca Windows ri chn tip mc c nhn l Allow others to share my files and printer(s). Cui cng nhn OK. Thng th Sygate ch cho php cc my tnh trong mng ni b c php nhn thy v truy cp tp tin v my in dng chung trn my tnh ca bn. ZoneAlarm. Khc vi cc phn mm trn, ZoneAlarm cho php tt c cc my tnh trong mng ni b truy cp c tp tin v my in dng chung trn my tnh ca bn, ch cn bn khai bo danh sch a ch IP ca cc my tnh trong mng. Th tc thc hin nh sau: nhn chut phi vo biu tng ca ZoneAlarm nm trn khay h thng, chn menu Restore ZoneAlarm Control Center, chn mc c nhn Firewall bn tri ri chn tab c nhn Zones. Nhn chut chn menu c nhn Add ri IP Address ri nhp tun t tng a ch IP cc my tnh trong mng ni b vo danh sch Trusted Zone ( danh sch my tnh hp php). L Thu

[In trang]

[ng trang]

Tp ch Th Gii Vi Tnh - PC World VN. CQ ch qun: S Khoa Hc v Cng Ngh TP.HCM


Giy php s 196/GP-BVHTT do B Vn Ha Thng Tin cp ngy 27-06-2003 Ta son: 126 Nguyn Th Minh Khai, Q.3 TP.HCM - T: 84.8.39304324 - FAX: 84.8.39304338 Bn quyn ca Th Gii Vi Tnh - PC World VN

3 of 3

5/29/2013 5:07 PM

You might also like