{"id":108972,"date":"2022-12-30T09:23:44","date_gmt":"2022-12-30T08:23:44","guid":{"rendered":"https:\/\/www.avanet.com\/kb\/comment-configurer-sophos-ztna-zero-trust-network-access\/"},"modified":"2024-02-02T16:24:24","modified_gmt":"2024-02-02T15:24:24","slug":"comment-configurer-sophos-ztna-zero-trust-network-access","status":"publish","type":"kb","link":"https:\/\/www.avanet.com\/fr\/kb\/comment-configurer-sophos-ztna-zero-trust-network-access\/","title":{"rendered":"Comment configurer Sophos ZTNA (Zero Trust Network Access)"},"content":{"rendered":"\n<p>Cet article explique comment configurer Sophos Zero Trust Network Access, ou ZTNA.\nTu pourras ainsi te faire une id\u00e9e du fonctionnement du logiciel. <\/p>\n\n<div class=\"wp-block-yoast-seo-table-of-contents yoast-table-of-contents\"><h2>Table des mati\u00e8res<\/h2><ul><li><a href=\"#h-voraussetzungen-fur-sophos-zero-trust\" data-level=\"2\">Conditions requises pour Sophos Zero Trust<\/a><\/li><li><a href=\"#h-sophos-central-ztna-aktivieren\" data-level=\"2\">Activer Sophos Central ZTNA<\/a><\/li><li><a href=\"#h-wildcard-zertifikat\" data-level=\"2\">Certificat Wildcard<\/a><\/li><li><a href=\"#h-ztna-einrichten\" data-level=\"2\">Mettre en place ZTNA<\/a><\/li><\/ul><\/div>\n\n<h2 class=\"wp-block-heading\" id=\"h-voraussetzungen-fur-sophos-zero-trust\">Conditions requises pour Sophos Zero Trust<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Compte Sophos Central<a href=\"https:\/\/www.sophos.com\/de-de\/products\/sophos-central\/free-trial?id=0013000001EjyeY\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">(cr\u00e9er un compte d&rsquo;essai gratuit de 30 jours pour Sophos Central<\/a>)<\/li>\n\n\n\n<li>Azure Active Directory avec Utilisateur et groupes<\/li>\n\n\n\n<li>Environnement VMware ESXi, Microsoft Hyper-V ou Amazon Cloud AWS pour la nouvelle VM<\/li>\n\n\n\n<li><span style=\"color: var(--ast-global-color-3); font-size: 1rem; background-color: var(--ast-global-color-5);\">Adresse IP fixe pour VM<\/span><\/li>\n\n\n\n<li>Certificat Wildcard<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"h-sophos-central-ztna-aktivieren\">Activer Sophos Central ZTNA<\/h2>\n\n<p>Si tu n&rsquo;as pas encore test\u00e9 Zero Trust Network Access, tu peux le faire avec un nouveau compte central ou un compte existant.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1433\" data-id=\"80907\" src=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled.jpg\" alt=\"\" class=\"wp-image-80907\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-scaled-64x36.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-300x168.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-1024x573.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-768x430.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-1536x860.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-2048x1147.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-start-trial-600x336.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/a><figcaption class=\"wp-element-caption\">Lancer l&rsquo;essai Sophos ZTNA<\/figcaption><\/figure>\n<\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"h-wildcard-zertifikat\">Certificat Wildcard<\/h2>\n\n<p>Pour ZTNA, il faut un certificat Wildcard.\nJe recommande d&rsquo;utiliser un certificat dont la dur\u00e9e de validit\u00e9 est sup\u00e9rieure \u00e0 trois mois, comme c&rsquo;est le cas des certificats Let&rsquo;s Encrypt.\nMais souvent, on souhaite tester la solution ZTNA pendant les 30 jours de la p\u00e9riode d&rsquo;essai et Let&rsquo;s Encrypt s&rsquo;y pr\u00eate parfaitement si l&rsquo;on ne poss\u00e8de pas d\u00e9j\u00e0 un certificat Wildcard.  <\/p>\n\n<p>Si un certificat existe d\u00e9j\u00e0, c&rsquo;est parfait.\nSi ce n&rsquo;est pas le cas, instructions : <a href=\"\">Cr\u00e9er un certificat Let&rsquo;s Encrypt Wildcard<\/a> <\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-ztna-einrichten\">Mettre en place ZTNA<\/h2>\n\n<p>Pour pouvoir utiliser ZTNA, il faut d&rsquo;abord mettre en place les cinq choses suivantes.<\/p>\n\n<ol class=\"wp-block-list\">\n<li>Ajouter un service d&rsquo;annuaire : Azure AD Sync avec Central pour synchroniser les utilisateurs et les groupes.<\/li>\n\n\n\n<li>Ajouter des fournisseurs d&rsquo;identit\u00e9 : Configurer les fournisseurs d&rsquo;identit\u00e9 n\u00e9cessaires \u00e0 l&rsquo;authentification<\/li>\n\n\n\n<li>Ajouter une passerelle : Cr\u00e9er une passerelle virtuelle pour chaque site du r\u00e9seau<\/li>\n\n\n\n<li>Ajouter une politique : D\u00e9finir des r\u00e8gles d&rsquo;acc\u00e8s aux ressources<\/li>\n\n\n\n<li>Ajouter une ressource : Sp\u00e9cifier les ressources et les groupes d&rsquo;utilisateurs autoris\u00e9s \u00e0 acc\u00e9der aux ressources<\/li>\n<\/ol>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1433\" data-id=\"80927\" src=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled.jpg\" alt=\"\" class=\"wp-image-80927\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-scaled-64x36.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-300x168.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-1024x573.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-768x430.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-1536x860.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-2048x1147.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-setup-dashboard-600x336.jpg 600w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/a><figcaption class=\"wp-element-caption\">Tableau de bord Sophos ZTNA<\/figcaption><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">1. Synchroniser les utilisateurs (Set up directory sync)<\/h3>\n\n<p>Il est utile, non seulement pour ZTNA mais aussi pour Central en g\u00e9n\u00e9ral, d&rsquo;utiliser un service d&rsquo;annuaire qui synchronise les Utilisateur et les groupes avec Central.\nDans le cas de ZTNA, on a besoin d&rsquo;Azure AD ou d&rsquo;Okta. <\/p>\n\n<p>Ce guide explique comment remplir cette condition : <a href=\"https:\/\/www.avanet.com\/kb\/sophos-central-azure-ad-hinzufugen\/\">AjouterSophos Central Azure AD<\/a><\/p>\n\n<h3 class=\"wp-block-heading\">2. Ajouter un fournisseur d&rsquo;identit\u00e9 (Add identitv provider)<\/h3>\n\n<p>Apr\u00e8s avoir configur\u00e9 Azure AD, on peut maintenant saisir les donn\u00e9es correspondantes ici : <strong>Client ID<\/strong>, <strong>Tenant ID<\/strong>, and <strong>Client secret<\/strong>.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1664\" height=\"1482\" data-id=\"99626\" src=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider.jpg\" alt=\"\" class=\"wp-image-99626\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider.jpg 1664w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-64x57.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-300x267.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-1024x912.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-768x684.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-1536x1368.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-zero-trust-network-access-ztna-identity-provider-600x534.jpg 600w\" sizes=\"auto, (max-width: 1664px) 100vw, 1664px\" \/><\/a><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\">3. Ajouter une passerelle \/ un connecteur (Set up gateways)<\/h3>\n\n<p>La passerelle Zero Trust Network Access de Sophos est un composant de l&rsquo;architecture ZTNA.\nCette passerelle permet de fournir un acc\u00e8s s\u00e9curis\u00e9 et contr\u00f4l\u00e9 aux applications et aux ressources pour les utilisateurs et les appareils. <\/p>\n\n<p>L&rsquo;article <a href=\"https:\/\/www.avanet.com\/fr\/kb\/creer-une-passerelle-un-connecteur-sophos-ztna\/\">Cr\u00e9er une passerelle Sophos ZTNA<\/a> explique comment cr\u00e9er une passerelle ZTNA sur site ou une passerelle ZTNA dans le cloud.<\/p>\n\n<h3 class=\"wp-block-heading\">4. Ajouter une politique (Add policy)<\/h3>\n\n<p>Les instructions suivront.\n\u00c9crivez-nous via le <a href=\"\">formulaire de contact<\/a> si vous souhaitez que nous en fassions une priorit\u00e9. <\/p>\n\n<h3 class=\"wp-block-heading\">5. Ajouter une ressource (Add resources)<\/h3>\n\n<p>Les instructions suivront.\n\u00c9crivez-nous via le <a href=\"\">formulaire de contact<\/a> si vous souhaitez que nous en fassions une priorit\u00e9. <\/p>\n\n<h3 class=\"wp-block-heading\">6. Installer le client ZTNA sur les syst\u00e8mes d&rsquo;extr\u00e9mit\u00e9<\/h3>\n\n<p>Les instructions suivront.\n\u00c9crivez-nous via le <a href=\"\">formulaire de contact<\/a> si vous souhaitez que nous en fassions une priorit\u00e9. <\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"template":"","format":"standard","kb_kategorie":[716],"class_list":["post-108972","kb","type-kb","status-publish","format-standard","hentry","kb_kategorie-zero-trust"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/kb\/108972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/users\/5"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/media?parent=108972"}],"wp:term":[{"taxonomy":"kb_kategorie","embeddable":true,"href":"https:\/\/www.avanet.com\/fr\/wp-json\/wp\/v2\/kb_kategorie?post=108972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}