A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesCreating VLANs on CatOS is a little different, though the terminology is the same as using VLANs under IOS. Standalone VLANs and VTP are both possible to maintain the VLAN database: # set vtp domain example mode server #
Configuring and using VLANs on Cisco switches with IOS is a fairly simple process, taking only a few commands to create and use VLANs, trunk ports, and assigning ports to VLANs. Many switches from other vendors behave si
FTPS, or encrypted FTP, is not affected. The proxy could not have affected its traffic before. A client on a LAN or other internal interface behind a pfSense firewall will likely not notice any difference. Most clients,
When configuring clients, there are a few points to look for: Ensure that the client operating system configuration is set to connect to the proper external address for the VPN. It may be necessary to force the VPN type
Personally I like to tweak it a little bit so the windows hide themselves nicely in the system tray. This is optional but I find it improves the user experience. In the VPN Access Manager, go to File > Preferences . For
Each node requires some basic configuration outside of the actual HA setup. Do not connect both nodes into the same LAN before both nodes have a non- conflicting LAN setup. Installation, interface assignment and basic co
In the AZATCO-FW webGUI, navigate to System > User Manager Select the Servers tab Click + to add a new entry Enter a Descriptive name such as FreeRADIUS Select RADIUS for the Type Enter 127.0.0.1 for the Hostname or IP a
A PPPoE WAN is actually assigned to a virtual PPPoE adapter, not the physical port. Under Interfaces > Assignments , create a new OPT interface, and assign it to the physical network card that is on WAN. For example, if
To configure a WireGuard Tunnel: Navigate to VPN > WireGuard Click Add Tunnel Fill in the WireGuard Tunnel settings as described in WireGuard Tunnel Settings Click Add Peer Fill in the WireGuard Peer settings as describe
Warning: Configuration synchronization must only be configured on the primary node . Never activate options in this section on the secondary node of a two-member cluster. On the primary node only, perform the following:
Now to setup the DNS portion. WPAD will take the domain name given to the machine, likely assigned by DHCP, and prepend wpad. . If the domain is example.com , it will look for wpad.example.com . This task may be accompli
First, configure the DNS servers on the firewall. Warning: When the firewall uses DNS over TLS, every DNS server used by the firewall must support DNS over TLS. Navigate to System > GeneralLocate the DNS Server Settings
From the Firewall menu, choose Rules . Open the WAN tab, unless using a different interface for the VPN connection. Click on the + button to add a new rule. Enter these values: Action Pass Disabled not checked Interface
From the web interface on pfSense: Select System > User manager , Authentication servers tab Click Add to create a new entry Enter a Descriptive name for this LDAP server, such as G Suite Set Type to LDAP The server sett
Now NAT needs to be configured to translate traffic destined to the modem to the new interface. This is necessary so the modem sees the traffic sourced from an IP on its local subnet. Without this NAT, it would be necess
Navigate to VPN > OpenVPN Select the Servers tab Edit the existing Remote Access server Ensure that the Mode is either Remote Access (User Auth) or Remote Access (SSL/TLS + User Auth) Select FreeRADIUS or the Descriptive
In the default setup outbound NAT is configured automatically. We need to set it to Manual in order to add Site A’s subnet. This configuration step is not required on the router at site A. Site B Configuration From the F
State synchronization using pfsync must be configured on both the primary and secondary nodes to function. First on the primary node and then on the secondary, perform the following: Navigate to System > High Avail Sync
On the server in named.conf, add the following block: include “/etc/namedb/dns.keys.conf”; zone “dyn.example.com” { type master; file “dynamic/dyn.example.com”; update-policy { grant *.dyn.example.com. self dyn.example.c
Go to Firewall > Rules , WAN tab and click + to create a new rule. Enter these values: Action Pass Disabled not checked Interface WAN Protocol UDP Source unchecked, any Destination unchecked, WAN address Destination port
Follow the instructions from Google for configuring and enabling the G Suite LDAP application . Warning: Follow these directions exactly . No special provisions are required for AZTCO-FW, but please note that the LDAP ap
The new interface is now accessible under Interfaces > OPTx , where x depends on the number assigned to the interface. Navigate to the new interface configuration page. ( Interfaces > OPTx ) Check Enable Interface . Ente
After the installation has finished, the Squid proxy server may be configured. Click on the Local Cache tab. Hard disk cache size (in MB): Set this as needed, but keep it a reasonable size. 3000 (3GB) may be a good place
From the web interface on AZTCO-FW: Navigate to Services > STunnelClick Add to create a new profile Enter a Description for this connection, such as G Suite Check Client ModeSet Listen on IP to 127.0.0.1 Set Listen on po