A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesSimilar to OpenVPN, a set of certificates is required for the server and clients. Create a Certificate Authority If one is not already available, then the first task is to create a Certificate Authority. Navigate to Syst
To assign IPv6 addresses to clients automatically, setup Router Advertisements and/or DHCPv6. A brief overview is as follows: Navigate to Services > DHCPv6 Server/RA Check Enable Enter a range of IPv6 IP addresses inside
These settings have been tested and found to work with some clients, but other similar settings may function as well. Feel free to try other encryption algorithms, hashes, etc. Mobile Clients Tab Navigate to VPN > IPsec
The DNS servers likely answer DNS queries with AAAA results already. Entering the DNS servers supplied by the tunnel broker service under System > General Setup is recommended. Enter at least one IPv6 DNS server or use G
The following setup can be used instead if outbound access is more lenient, but still controlled between local interfaces. This assumes all local networks are privately numbered, and that interfaces have already been con
Once the tunnel is configured and online, the firewall itself has IPv6 connectivity. To ensure clients can access the internet on IPV6, the LAN must be configured also. One method is to set LAN as dual stack IPv4 and IPv
Before proceeding, the Sync interfaces on the cluster nodes must be configured. Sync IP Address Assignments lists the addresses to use for the Sync interfaces on each node. Once that has been completed on the primary nod
When the interface is configured as listed above, a dynamic IPv6 gateway is added automatically, but it is not yet marked as default. Navigate to System > RoutingEdit the dynamic IPv6 gateway with the same name as the IP
The shaper wizard creates rules for IPv4 traffic only. Rules can be manually adjusted or cloned and set for IPv6.
Before a tunnel can be created, ICMP echo requests must be allowed to the WAN. A rule to pass ICMP echo requests from a source of any is a good temporary measure. Once the tunnel endpoint for HE.net has been chosen, the
In this example 10.3.0.0/24 is the LAN on both sides of a VPN. Hosts on the 10.3.0.0/24 subnet will never reach the other end of the VPN to communicate with the remote 10.3.0.0/24 subnet. Clients will always treat that n
This section describes how to map multiple subnets that have the same IP address range using OpenVPN so that they can be accessed from a central site. For example 192.168.0/24 is a very common addressing scheme and the m
The key to making a working IPsec tunnel is to ensure that both sides have matching settings for authentication, encryption, and so on. Before starting, make a note of the local and remote WAN IP addresses, as well as th
Recommendations for specific games can be found below. If any special handling is required but not listed here. NB: What works to make a single console/device work from behind a firewall may not work for multiple con- so
Squid is the foundation of many other tasks that start with a proxy: It can act as a cache for improving web perfor- mance, it can hook into SquidGuard for content filtering, and its logs provide the basis for reporting
Squid provides the possibility to ask for a username and password for users who want to connect to the internet through squid proxy. This works only if squid is running in non-transparent mode. SQUID configuration: Disab
The SquidGuard package enables very powerful URL content filtering and access control. It can use blacklists or custom lists of web sites, and can selectively allow or deny access to those sites. To use SquidGuard: Insta
Each wizard name is followed by the filename of the wizard, which is a link. Click the link to start the wizard. This example uses the Multiple LAN/WAN wizard, so click traffic_shaper_wizard_multi_all.xml. Next, the wiza
For installations where the above scenarios do not apply, an additional firewall rule can be put in place to prevent RFC1918 traffic from leaking out of the WAN interface. This provides a small increase in security and p
To enhance the security of a network, in many environments access to the firewall GUI is limited by firewall rules. Restricting access to the management interface is the best practice. The default configuration of AZTCO-
Generally three or four things must be configured on VLAN capable switches: 1. Add/define the VLANs Most switches have a means of defining a list of configured VLANs, and they must be added before they can be configur
Start a browser on a client behind the AZTCO-FW firewall, and see what happens. If squid is configured for authentication, the client will be greeted with a login prompt. Otherwise, check squid’s logs to ensure traffic i
With the complete configuration described above, it is now possible to authenticate against Google G Suite LDAP. First, test the authentication to ensure it is working properly. Navigate to Diagnostics > Authentication S
Navigate to Diagnostics > Authentication Select the authentication server entered above Fill in a Username and Password configured in FreeRADIUS Click Test If the test succeeded, continue. Otherwise, see the Troubleshoot