AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Authenticating from Active Directory using RADIUS/NPS

Windows 2008 and later can be configured as a RADIUS server using Microsoft’s Network Policy Server (NPS).  This allows authentication for OpenVPN, Captive Portal, the PPPoE server, or even the AZTCO-FW GUI itself using

Authenticating OpenVPN Users with RADIUS via Active Direc- tory

This recipe demonstrates setting up OpenVPN on AZTCO-FW software for Windows clients, using certificates with user authentication via RADIUS in Active Directory. The target audience of this recipe is small businesses tha

Authenticating Squid Package Users with FreeRADIUS

Using the Squid Proxy package with the FreeRADIUS package .

Authenticating Users with Google Cloud Identity

Google Cloud Identity LDAP service can be used to authenticate users on AZTCO-FW software installations. The method varies depending on the version of AZTCO-FW software installed on the firewall. This is due to the fact

AZTCO-FW-initiated Traffic and IPsec

To access the remote end of IPsec connections from the AZTCO-FW firewall itself, “fake” the system out by adding a static route pointing the remote network to the LAN IP address of the AZTCO-FW firewall. Note this exampl

Basic Firewall Configuration Example

This article is designed to describe how AZTCO-FW software performs rule matching and a basic strict set of rules. The approach described in this document is not the most secure, but will help show how rules are setup. R

Basic lock down of the LAN and DMZ outgoing rules

Outbound LAN Make sure the Default LAN > any rule is either disabled or removed. Allowing DNS access: If AZTCO-FW is the DNS server: Allow TCP/UDP 53 (DNS) from LAN subnet to LAN Address . If using Upstream DNS Servers:

Before Starting The Wizard

Before starting the wizard to configure the Remote Access Server, there are some details that must be planned. Determine an IP addressing scheme An IP subnet must be chosen for use by the OpenVPN clients themselves. This

BGP

A BGP package using OpenBGPD from OpenBSD is available. To install it: Navigate to System > Package Manager Click Available Packages Locate OpenBGPD in the list, or search for it Click the  Install to the right of the Op

Block Port 80 Out from LAN

Create a firewall rule at the TOP of the LAN tab (or appropriate interface) that blocks anything from <internal subnet> to * on port 80. Note: If the firewall is used to serve WPAD and the WebGUI anti-lockout rule has be

Blocking External Client DNS Queries

This procedure configures the firewall to block DNS requests to servers outside the local network. With no other accessible DNS servers, clients are forced to send DNS requests to the DNS Resolver or DNS Forwarder on AZT

Blocking Web Sites

There are several options for blocking websites with AZTCO-FW software, some of which are described on this article. It’s not an exact science, but these solutions typically function well enough for a majority of use cas

Bridging OpenVPN Connections to Local Networks

The OpenVPN configurations discussed to this point have all been routed, using tun interfaces. This is the preferable method, but OpenVPN also offers the option of using tap interfaces and bridging clients directly onto

Caveats

In most cases, NAT is not used with IPv6 in any capacity as everything is routed. That is great for connectivity and for businesses or locations that can afford Provider Independent (PI) address space and a BGP peering,

Caveats

Clients can make their own connections to DNS over TLS servers, so block them on TCP/UDP ports 53 and 853 to ensure they only query the DNS Resolver ( Blocking External Client DNS Queries ). Redirecting DNS over TLS quer

Change the cryptoapicert SUBJ

Open       C:\Program Files\OpenVPN\config\config.ovpn   or       C:\Program Files(x86)\ OpenVPN\config\config.ovpn and change the line that says cryptoapicert “SUBJ:” to cryptoapicert “SUBJ:username” . . . replace usern

Change the name of the .ovpn file

When connecting to the firewall OpenVPN shows a balloon announcing that the VPN is up. It contains a rather cryptic Windows Installer name, but that can be changed to something more appropriate by renaming the .ovpn file

Choose Authentication Type

On the first screen of the OpenVPN Remote Access server wizard, choose a method for user authentication. The choices available for Authentication Backend Type are Local User Access , LDAP , and RADIUS . If an existing au

Choosing a Certificate Authority

If there is an existing Certificate Authority defined on the AZTCO-FW firewall, it may be chosen from the list. To create a new Certificate Authority, choose Add new CA . If no Certificate Authorities are defined, this s

Choosing a RADIUS Server

If there is an existing RADIUS server defined on the AZTCO-FW firewall, choose it from the list. To use a different RADIUS server, instead choose Add new RADIUS server . If no RADIUS servers are defined on AZTCO-FW, this

Choosing a Server Certificate

If there is an existing Certificate defined on the AZTCO-FW firewall, it may be chosen from the list. To create a new Certificate, choose Add new Certificate . If no Certificates are defined, this step is skipped.

Choosing a server for NPS

NPS requires a minimal amount of resources and is suitable for addition to an existing Windows Server in most environments. Microsoft recommends installing it on an Active Directory domain controller to improve performan

Choosing a Wizard

To get started with the Traffic Shaping Wizard, navigate to Firewall > Traffic Shaper and click the Wizards tab. This page displays a list of available traffic shaper wizards, including: Multiple LAN/WAN Used when the fi

Choosing an LDAP Server

If an LDAP server is already defined on the AZTCO-FW firewall it may be chosen from the list. To use a different LDAP server instead choose Add new LDAP server . If there are no LDAP servers defined, this step is skipped

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.