AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Testing DNS over TLS

There are several ways to validate that outbound queries are using DNS over TLS. Test via Diagnostics > DNS Lookup and ensure the result from 127.0.0.1 is correct. Check for states using port 853 going to the DNS servers

Testing the connection

The configuration is now complete and the connection will immediately be active upon saving on the client side. Try to ping across to the remote end to verify connectivity. If problems arise.

Testing the connection

The connection will immediately be active upon saving on the client side. Try to ping across to the remote end to verify connectivity.

Thanks

Thanks to the AZTCO-FW forum, in particular to user unguzov, who wrote a shorter version of this recipe. I adapted his version and added screenshots. Thanks to Evan Jensen for providing some English version screenshots.

The client

This part is done on the user’s computer. Screenshots were taken in Windows but Shrew Soft VPN is available for Linux and BSD (so probably Mac) too. Download and install Shrew Soft VPN. Once finished, open ipseca.exe. Th

Transparent Proxies and HTTP/HTTPS

When using a proxy, it is only possible to intercept HTTP traffic transparently. That is, only HTTP traffic may be grabbed automatically and forced through a proxy without intervention from the user or their knowledge. T

Troubleshooting

By default iOS will tunnel all traffic over the VPN, including traffic going to the Internet. If Internet sites are inacces- sible once connected, a DNS server may need to be pushed to the client for it to use, such as t

Troubleshooting

I’ve been using AZTCO-FW software in combination with Shrew Soft VPN for a long time and in my experience it is a very stable combination. However things can always go wrong. If it doesn’t work, here are some hints to he

Troubleshooting

Sometimes things don’t work as expected. The following options can be helpful in troubleshooting FreeRADIUS and OpenVPN. Commands must be run at a shell prompt either via the console or via SSH unless otherwise specified

Try It!

Once firewall rules are in place, check for IPv6 connectivity. A good site to test with is test-ipv6.com. An example of the output results of a successful configuration from a client on LAN is shown here Figure 65: IPv6

Updating the Tunnel Endpoint

For a dynamic WAN, such as DHCP or PPPoE, HE.net can still be used as a tunnel broker. AZTCO-FW includes a DynDNS type that will update the tunnel endpoint IP address whenever the WAN interface IP changes. If DynDNS is d

Use a VPN

The safest way to accomplish the task is to setup a VPN that will allow access to the firewall and the network it protects. There are several VPN options available in AZTCO-FW software, such as IPsec OpenVPN SSH tunnelin

Use G Suite for AZTCO-FW Administrative Logins

If all is well and the user authenticated as expected: Navigate to System > User manager , SettingsSet the Authentication server to G Suite Click Save After saving, firewall users will be authenticated against Google Clo

Use HTTPS

The best practice is to always use HTTPS to encrypt access to the GUI port. Modern browsers may complain about the certificate, but an exception can usually be stored so it will only complain the first time. To disable (

Using a Proxy

If web traffic flows through a proxy server, that proxy server can likely be used to prevent access to such sites. For example, Squid has an add-on called SquidGuard which allows for blocking web sites by URL or other si

Using DNS

If the built in DNS Resolver or Forwarder are active an override can be entered there to resolve the unwanted website to an invalid IP address such as 127.0.0.1. With the DNS Resolver, additional methods are possible via

Using Firewall Rules

If a website rarely changes IP addresses, access to it can be blocked using an alias containing its IP addresses and then using this alias in firewall rules. Warning: This is not a feasible solution for sites that return

Using Mobile-One-Time-Password (mOTP) with the FreeRADIUS package

Using Mobile-One-Time-Password (mOTP) with the FreeRADIUS package

Using NAT and FTP without a Proxy

AZTCO-FW do not include an FTP Proxy, this doesn’t affect clients and servers as much as one might think. Important: Use of FTP is strongly discouraged. It is an outdated protocol that transmits credentials and other dat

Using the Shaper Wizard to Configure ALTQ Traffic Shaping

The easiest way to get started with traffic shaping is by using the wizard for the first time, which guides administrators through the shaper configuration process. Tip: Due to the complexity of the shaper queues and rul

Using the Windows client

Set the Windows Client to run as Administrator. To use the client, double click the OpenVPN GUI icon on the Desktop Windows will ask to confirm the execution. Confirm. OpenVPN will start but that’s not enough. Right-clic

Verifying the Setup

Look at firewall rules ( WAN and OpenVPN tabs) WAN tab rule should pass from any to the OpenVPN port on the WAN address OpenVPN tab rule should allow anything from any/to any

Versions

AZTCO-FW software version 2.x Active Directory on Windows Server 2008 R2 – I’m using a Forest Functional Level of 2008 R2 but I don’t think that’s really a prerequisite. If it doesn’t work, user account passwords may nee

VLANS

If any VLANs were in use directly on the interfaces involved, migrate them as follows: Add new VLAN tags using the LAGG interface as the parent ( Interfaces > Assignments , VLAN tab) Fix the assignments to use the LAGG v

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.