AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid

This section is not meant to be a formal, detailed, and comprehensive recipe for using Squid and other related web proxy software, but a quick run-through to get it up and running and to cover the most commonly asked que

Accessing a CPE/Modem from Inside the Firewall

Most end-user Customer Premise Equipment (CPE) devices like cable or DSL modems have a web interfaces on a private IP address. Since these sit outside the firewall and do not typically have a public IP address, accessing

Accessing Port Forwards from Local Networks

By default, AZTCO-FW software does not redirect internally connected devices to reach forwarded ports and 1:1 NAT on WAN interfaces. If a client is trying to reach a service on port 80 or 443 (or the port a web interface

Active Directory LDAP Example

In this example, AZTCO-FW is setup to connect to an Active Directory structure in order to authenticate users for a VPN. The results are restricted to the VPNUsers group. Omit the Extended Query to accept any user. Descr

Add a NAS client to FreeRADIUS

Navigate to Services > FreeRADIUS Select the NAS / Clients tab Click + to add a new entry Enter 127.0.0.1 in the Client IP Address field Enter AZATCO-FW, OpenVPN, or similar in the Client Shortname field Enter a random/l

Add an interface to FreeRADIUS

Navigate to Services > FreeRADIUS Select the Interfaces tab Click + to add a new entry Enter * for the Interface IP Address, or 127.0.0.1 to bind only to Localhost Enter 1812 for the Port Select Authentication for the In

Add Firewall Rules

Once LAN addresses have been assigned, add firewall rules to allow the IPv6 traffic to flow. Navigate to Firewall > Rules , LAN tab. Check the list for an existing IPv6 rule. If a rule to pass IPv6 traffic already exists

Add Firewall Rules for IPsec

Firewall rules are necessary to pass traffic from IPsec clients. Navigate to Firewall > Rules , IPsec tab Review the current rules. If there is an “allow all” style rule, then there is no need to add another. Continue to

Add the Client VPN Connection

With the certificates properly imported, now it is time to create the client VPN connection. There are several ways to add such a connection, depending on the version of Windows being used. Adapt as needed. Open Network

Add Users

Navigate to Services > FreeRADIUSSelect the Users tab. This is where every user to authenticate with FreeRadius/OpenVPN is managed Click + to add a new entry Enter a Username and Password Enter any additional desired opt

Adding a RADIUS Server

If no RADIUS servers exist, or Add new RADIUS server was selected, a screen is presented with the options needed to add a new server. If there is any uncertainty about the settings, consult the RADIUS server administrato

Adding a Server Certificate

This screen creates a new server certificate which will be used to verify the identity of the server to the clients.     The server certificate will be signed by the certificate authority chosen or created previously in

Adding a User with a Certificate

If the mode has been left at the wizard’s default or on a mode that includes local user authentication, a user must be created in the user manager. Navigate to System > User Manager Click +  To add a user Fill in Usernam

Adding an LDAP Server

If no LDAP servers exist or Add new LDAP server is chosen a screen will be presented with the options needed to add a new server. Many of these options will depend on the specific LDAP directory configuration and structu

Adding OpenVPN Remote Access Users

At this point the VPN server is configured but there may not be any clients which can connect. The method for adding users to the VPN will depend upon the authentication method chosen when creating the OpenVPN server.

Adjustments

Some settings are not presented in the wizard but might be a better fit for some situations than the defaults chosen by the wizard. Server Mode The OpenVPN Server Mode allows selecting a choice between requiring Certific

Aliases to make it easy

It is easiest to start by making a few entries under Firewall > Aliases to make the rules easier to accomplish: Host alias for the PBX itself, named PBX , containing the local IP address of the PBX. Network or Host alias

Allow ICMP

ICMP echo requests must be allowed on the WAN address that is terminating the tunnel to ensure that it is online and reachable. If ICMP is blocked, the tunnel broker may refuse to setup the tunnel to the IPv4 address. Ed

Allow IPsec traffic through the firewall

The tunnel should now be operational however no traffic is allowed through it until a firewall rule is added to pass it. The rule must be added to the routers at both sites. From the Firewall menu, choose Rules . Go to t

Allow IPv6 Traffic

On new installations of pfSense after 2.1, IPv6 traffic is allowed by default. If the configuration on the firewall has been upgraded from older versions, then IPv6 would still be blocked. To enable IPv6 traffic, perform

Allowing Remote Access to the GUI

Several ways exist to remotely administer a firewall running AZTCO-FW software that come with varying levels of recommendation. They all work, but their use may vary for any number of reasons (Client restrictions, corpor

Alternate Tactics

Some users prefer to configure LAN with a “private” IPv6 subnet from the fc00::/7 space and setup NPt for both WANs.

Android Client Setup

On the phone/tablet/device: Go to the system settings and VPN settings (varies by device and specific Android version Tap Add VPN Profile Enter a name For Type , tap L2TP/IPsec PSK Server Address : The WAN IP of the AZTC

Assign a WireGuard Interface

Some functionality for WireGuard interfaces depends upon them being assigned as their own interfaces on the firewall. Benefits of assignment include: Adds a firewall tab under Firewall > Rules Allows the interface to be

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.