A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesThere are several ways to validate that outbound queries are using DNS over TLS. Test via Diagnostics > DNS Lookup and ensure the result from 127.0.0.1 is correct. Check for states using port 853 going to the DNS servers
The configuration is now complete and the connection will immediately be active upon saving on the client side. Try to ping across to the remote end to verify connectivity. If problems arise.
The connection will immediately be active upon saving on the client side. Try to ping across to the remote end to verify connectivity.
Thanks to the AZTCO-FW forum, in particular to user unguzov, who wrote a shorter version of this recipe. I adapted his version and added screenshots. Thanks to Evan Jensen for providing some English version screenshots.
This part is done on the user’s computer. Screenshots were taken in Windows but Shrew Soft VPN is available for Linux and BSD (so probably Mac) too. Download and install Shrew Soft VPN. Once finished, open ipseca.exe. Th
When using a proxy, it is only possible to intercept HTTP traffic transparently. That is, only HTTP traffic may be grabbed automatically and forced through a proxy without intervention from the user or their knowledge. T
By default iOS will tunnel all traffic over the VPN, including traffic going to the Internet. If Internet sites are inacces- sible once connected, a DNS server may need to be pushed to the client for it to use, such as t
I’ve been using AZTCO-FW software in combination with Shrew Soft VPN for a long time and in my experience it is a very stable combination. However things can always go wrong. If it doesn’t work, here are some hints to he
Sometimes things don’t work as expected. The following options can be helpful in troubleshooting FreeRADIUS and OpenVPN. Commands must be run at a shell prompt either via the console or via SSH unless otherwise specified
Once firewall rules are in place, check for IPv6 connectivity. A good site to test with is test-ipv6.com. An example of the output results of a successful configuration from a client on LAN is shown here Figure 65: IPv6
For a dynamic WAN, such as DHCP or PPPoE, HE.net can still be used as a tunnel broker. AZTCO-FW includes a DynDNS type that will update the tunnel endpoint IP address whenever the WAN interface IP changes. If DynDNS is d
The safest way to accomplish the task is to setup a VPN that will allow access to the firewall and the network it protects. There are several VPN options available in AZTCO-FW software, such as IPsec OpenVPN SSH tunnelin
If all is well and the user authenticated as expected: Navigate to System > User manager , SettingsSet the Authentication server to G Suite Click Save After saving, firewall users will be authenticated against Google Clo
The best practice is to always use HTTPS to encrypt access to the GUI port. Modern browsers may complain about the certificate, but an exception can usually be stored so it will only complain the first time. To disable (
If web traffic flows through a proxy server, that proxy server can likely be used to prevent access to such sites. For example, Squid has an add-on called SquidGuard which allows for blocking web sites by URL or other si
If the built in DNS Resolver or Forwarder are active an override can be entered there to resolve the unwanted website to an invalid IP address such as 127.0.0.1. With the DNS Resolver, additional methods are possible via
If a website rarely changes IP addresses, access to it can be blocked using an alias containing its IP addresses and then using this alias in firewall rules. Warning: This is not a feasible solution for sites that return
Using Mobile-One-Time-Password (mOTP) with the FreeRADIUS package
AZTCO-FW do not include an FTP Proxy, this doesn’t affect clients and servers as much as one might think. Important: Use of FTP is strongly discouraged. It is an outdated protocol that transmits credentials and other dat
The easiest way to get started with traffic shaping is by using the wizard for the first time, which guides administrators through the shaper configuration process. Tip: Due to the complexity of the shaper queues and rul
Set the Windows Client to run as Administrator. To use the client, double click the OpenVPN GUI icon on the Desktop Windows will ask to confirm the execution. Confirm. OpenVPN will start but that’s not enough. Right-clic
Look at firewall rules ( WAN and OpenVPN tabs) WAN tab rule should pass from any to the OpenVPN port on the WAN address OpenVPN tab rule should allow anything from any/to any
AZTCO-FW software version 2.x Active Directory on Windows Server 2008 R2 – I’m using a Forest Functional Level of 2008 R2 but I don’t think that’s really a prerequisite. If it doesn’t work, user account passwords may nee
If any VLANs were in use directly on the interfaces involved, migrate them as follows: Add new VLAN tags using the LAGG interface as the parent ( Interfaces > Assignments , VLAN tab) Fix the assignments to use the LAGG v