As shown in Figure 1, a remote user is a network administrator and needs to remotely access the Telnet server on the enterprise intranet for work.
Local authentication is used to authenticate remote users (user group: group1). The authentication domain is default. Authenticated users can access the enterprise intranet. After a user logs in to the virtual gateway, port forwarding is automatically enabled.
of GigabitEthernet 0/0/1 and set parameters as follows:
Zone |
untrust |
|---|---|
IPv4 |
|
IP address |
1.1.1.1/24 |
Zone |
trust |
|---|---|
IPv4 |
|
IP address |
10.2.0.1/24 |
User user0001 belongs to user group /default/group1. Authentication Type is local authentication, and Password is Password@123. Before creating user user0001, you need to create group /default/group1 so that you have a group to reference when creating a user.




Name |
policy01 |
|---|---|
Source Zone |
untrust |
Destination Zone |
local |
Destination Address/Region |
1.1.1.1/24 |
Service |
https NOTE:
If the HTTPS port number is changed, use the new port number when creating the security policy. |
Action |
Permit |
Name |
policy02 |
|---|---|
Source Zone |
local |
Destination Zone |
trust |
Destination Address/Region |
10.2.0.0/24 |
Action |
Permit |
Install the control as prompted upon the first login.
After the login succeeds, click Start under Port Forwarding. Then you can access the corresponding port forwarding resources.

# aaa authentication-scheme default authorization-scheme default domain default service-type ssl-vpn internet-access mode password reference user current-domain # interface GigabitEthernet 0/0/1 ip address 1.1.1.1 255.255.255.0 # interface GigabitEthernet 0/0/2 ip address 10.2.0.1 255.255.255.0 # firewall zone trust set priority 85 add interface GigabitEthernet 0/0/2 # firewall zone untrust set priority 5 add interface GigabitEthernet 0/0/1 # v-gateway gateway authentication-domain default # #****BEGIN***gateway**1****# v-gateway gateway basic ssl version tlsv11 tlsv12 ssl timeout 5 ssl lifecycle 1440 ssl ciphersuit custom aes256-sha aes128-sha service port-forwarding enable port-forwarding resource Telnet-Server host-ip 10.2.0.2 23 security policy-default-action permit vt-src-ip certification cert-anonymous cert-field user-filter subject cn group-filter subject cn certification cert-anonymous filter-policy permit-all certification cert-challenge cert-field user-filter subject cn certification user-cert-filter key-usage any undo public-user enable hostchecker cachecleaner vpndb group /default group /default/group1 role role default role default condition all role role role role condition all role role port-forwarding enable role role port-forwarding resource Telnet-Server #****END****# # security-policy rule name policy01 source-zone untrust destination-zone local destination-address 1.1.1.0 mask 255.255.255.0 service https action permit rule name policy02 source-zone local destination-zone trust destination-address 10.2.0.0 mask 255.255.255.0 action permit # # The following configurations are saved in the database and are not displayed in the configuration file. user-manage user user0001 domain default password %$%$j@p.U.0bwNQv9nE#tf]G-+"v%$%$ parent-group /default/group1 v-gateway gateway role role role group /default/group1