A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesThis section is not meant to be a formal, detailed, and comprehensive recipe for using Squid and other related web proxy software, but a quick run-through to get it up and running and to cover the most commonly asked que
Most end-user Customer Premise Equipment (CPE) devices like cable or DSL modems have a web interfaces on a private IP address. Since these sit outside the firewall and do not typically have a public IP address, accessing
By default, AZTCO-FW software does not redirect internally connected devices to reach forwarded ports and 1:1 NAT on WAN interfaces. If a client is trying to reach a service on port 80 or 443 (or the port a web interface
In this example, AZTCO-FW is setup to connect to an Active Directory structure in order to authenticate users for a VPN. The results are restricted to the VPNUsers group. Omit the Extended Query to accept any user. Descr
Navigate to Services > FreeRADIUS Select the NAS / Clients tab Click + to add a new entry Enter 127.0.0.1 in the Client IP Address field Enter AZATCO-FW, OpenVPN, or similar in the Client Shortname field Enter a random/l
Navigate to Services > FreeRADIUS Select the Interfaces tab Click + to add a new entry Enter * for the Interface IP Address, or 127.0.0.1 to bind only to Localhost Enter 1812 for the Port Select Authentication for the In
Once LAN addresses have been assigned, add firewall rules to allow the IPv6 traffic to flow. Navigate to Firewall > Rules , LAN tab. Check the list for an existing IPv6 rule. If a rule to pass IPv6 traffic already exists
Firewall rules are necessary to pass traffic from IPsec clients. Navigate to Firewall > Rules , IPsec tab Review the current rules. If there is an “allow all” style rule, then there is no need to add another. Continue to
With the certificates properly imported, now it is time to create the client VPN connection. There are several ways to add such a connection, depending on the version of Windows being used. Adapt as needed. Open Network
Navigate to Services > FreeRADIUSSelect the Users tab. This is where every user to authenticate with FreeRadius/OpenVPN is managed Click + to add a new entry Enter a Username and Password Enter any additional desired opt
If no RADIUS servers exist, or Add new RADIUS server was selected, a screen is presented with the options needed to add a new server. If there is any uncertainty about the settings, consult the RADIUS server administrato
This screen creates a new server certificate which will be used to verify the identity of the server to the clients. The server certificate will be signed by the certificate authority chosen or created previously in
If the mode has been left at the wizard’s default or on a mode that includes local user authentication, a user must be created in the user manager. Navigate to System > User Manager Click + To add a user Fill in Usernam
If no LDAP servers exist or Add new LDAP server is chosen a screen will be presented with the options needed to add a new server. Many of these options will depend on the specific LDAP directory configuration and structu
At this point the VPN server is configured but there may not be any clients which can connect. The method for adding users to the VPN will depend upon the authentication method chosen when creating the OpenVPN server.
Some settings are not presented in the wizard but might be a better fit for some situations than the defaults chosen by the wizard. Server Mode The OpenVPN Server Mode allows selecting a choice between requiring Certific
It is easiest to start by making a few entries under Firewall > Aliases to make the rules easier to accomplish: Host alias for the PBX itself, named PBX , containing the local IP address of the PBX. Network or Host alias
ICMP echo requests must be allowed on the WAN address that is terminating the tunnel to ensure that it is online and reachable. If ICMP is blocked, the tunnel broker may refuse to setup the tunnel to the IPv4 address. Ed
The tunnel should now be operational however no traffic is allowed through it until a firewall rule is added to pass it. The rule must be added to the routers at both sites. From the Firewall menu, choose Rules . Go to t
On new installations of pfSense after 2.1, IPv6 traffic is allowed by default. If the configuration on the firewall has been upgraded from older versions, then IPv6 would still be blocked. To enable IPv6 traffic, perform
Several ways exist to remotely administer a firewall running AZTCO-FW software that come with varying levels of recommendation. They all work, but their use may vary for any number of reasons (Client restrictions, corpor
Some users prefer to configure LAN with a “private” IPv6 subnet from the fc00::/7 space and setup NPt for both WANs.
On the phone/tablet/device: Go to the system settings and VPN settings (varies by device and specific Android version Tap Add VPN Profile Enter a name For Type , tap L2TP/IPsec PSK Server Address : The WAN IP of the AZTC
Some functionality for WireGuard interfaces depends upon them being assigned as their own interfaces on the firewall. Benefits of assignment include: Adds a firewall tab under Firewall > Rules Allows the interface to be