AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Requirements

To setup Multi-WAN for IPv6 the firewall must have: IPv6 connectivity with static addresses on two or more WANs Gateways added to System > Routing for both IPv6 WANs, and confirmed connectivity on both. A routed /64 from

Requirements

A working OpenVPN server. See OpenVPN Remote Access Configuration Example FreeRADIUS Installed.

Requirements

This feature is only supported by the DNS Resolver. If the firewall is currently using the DNS Forwarder , convert to the DNS Resolver before starting this procedure. Pick a DNS over TLS upstream provider, such as a priv

Reset States

After making the changes to NAT rules, the states for the PBX must be reset. Navigate to Diagnostics > States Enter the IP address of the PBX and click Filter Click Kill Once the PBX re-registers it test inbound and outb

Restricted Firewall Access

If the webGUI port must be accessible to the Internet, restrict it by IP address/range as much as possible. Ideally, if there is a static IP address at the location to manage from, allow traffic from that IP address or s

RIP

RIP is part of the routed package. To install it: Navigate to System > Package Manager Click Available PackagesLocate routed in the list, or search for it Click the  Install to the right of the routed package entry. Clic

Routing and gateway considerations

When the VPN endpoint, in this case a AZTCO-FW firewall, is the default gateway for a network there are normally no problems with routing. As a client PC sends traffic, it will go to the AZTCO-FW firewall, over the tunne

Routing Internet Traffic Through a Site-to-Site IPsec Tunnel

It is possible to use IPsec on a AZTCO-FW router to send Internet traffic from Site A such that it would appear to be coming from Site B. This may be needed if a vendor requires that connections originate from a specific

Routing Internet Traffic Through A Site-To-Site OpenVPN Tun- nel

This article shows how to create a site-to-site connection using OpenVPN and how to route the Internet connection of site A through site B using AZTCO-FW software. This is effectively the same as using an IPsec site-to-s

Routing Public IP Addresses

This section covers the routing of public IP addresses where a public IP subnet is assigned to an internal interface on a single firewall deployment.

Scenarios where RFC1918 addresses should NOT be blocked on the WAN interface

In its default configuration, AZTCO-FW software is not configured to block RFC1918 addresses from being routed from the LAN subnet to the outside WAN, because there are two common scenarios where blocking this traffic is

Server Behind AZTCO-FW

FTPS, or encrypted FTP, is not affected. The proxy could not have affected its traffic before. A server behind AZTCO-FW would work fine with active mode, there would be no difference here. In active mode the server would

Set Conservative state table optimization

The default UDP timeouts in pf are too low for some VoIP services. If phones mostly work, but randomly disconnect, set Firewall Optimization Options to Conservative under System > Advanced , Firewall/NAT tab. A keep-aliv

Set up Mobile IPsec for IKEv2+EAP-TLS

With the certificate structure prepared, the next task is to configure the necessary IPsec settings. The settings below have been tested and found to work, but other similar settings may function as well. Feel free to tr

Set up OpenVPN at Site B

From the VPN menu choose OpenVPN . On the page under the Server tab, click the + button to create a new OpenVPN server. Enter these values: Sever Mode Peer to Peer (Shared Key) Protocol UDP Device Mode tun Interface WAN

Set up outbound NAT at Site B

From the Firewall menu, choose NAT and click on the Outbound tab. Select Manual Outbound NAT rule genera- tion (AON – Advanced Outbound NAT) and click Save . On the next page, click Apply Changes . A couple of rules are

Set up the Authentication Server

In the AZTCO-FW webGUI, go to System > User Manager , on the Servers tab. Click on the right. Enter these values: Descriptive name RADIUS Type Radius Hostname or IP address 192.168.77.15 Shared Secret Paste the shared se

Set up the client at site A

From the VPN menu choose OpenVPN and go to the Client tab. Click the + button to configure a client. Enter these values: Disabled not checked Server Mode Peer to Peer (Shared Key) Protocol UDP same as Site B Device mode

Set up the IPsec tunnel Phase 1

Site A Configuration In the VPN menu select IPsec . It opens on the Tunnels tab . Click the + button to create a new Phase 1 setup. (Make sure Enable IPsec is checked and saved.) Enter these values: Field Value Notes Int

Set up the IPsec tunnel Phase 2

Site A Configuration Click + under the Phase 1 entry. It will show an overview of all available Phase 2 entries. Since we haven’t made any yet none are shown. Click  + to create a new Phase 2. Enter these values: Field V

Set up the OpenVPN server

Go to VPN > OpenVPN , Servers tab and click+ . Enter these values: Server Mode: Remote Access ( SSL/TLS User Auth) Backend for authentication RADIUS Protocol UDP Device Mode tun Interface WAN Local port 1194 Description

Setting up WPAD Autoconfigure for the Squid Package

AZTCO-FW software can be configured to serve up automatic proxy configuration data to clients to point users to squid running either on the AZTCO-FW system or another local system, assuming their systems settings are con

Setup

OpenVPN server Create the OpenVPN server as normal Set TCP , port 443 , and mode tun Set the IPV4 Tunnel Network as something similar to 10.33.249.0/24 Do not set IPv4 Local Network(s) . The third octet should be a numbe

Setup

The setup for IPv6 Multi-WAN is very close to the setup for IPv4. The main difference is that it uses NPt instead of NAT. First, under System > Routing on the Gateway Groups tab, add Gateway Groups for the IPv6 gateways,

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.