AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Cisco CatOS based switches

Creating VLANs on CatOS is a little different, though the terminology is the same as using VLANs under IOS. Standalone VLANs and VTP are both possible to maintain the VLAN database: # set vtp domain example mode server #

Cisco IOS based switches

Configuring and using VLANs on Cisco switches with IOS is a fairly simple process, taking only a few commands to create and use VLANs, trunk ports, and assigning ports to VLANs. Many switches from other vendors behave si

Client Behind AZTCO-FW

FTPS, or encrypted FTP, is not affected. The proxy could not have affected its traffic before. A client on a LAN or other internal interface behind a pfSense firewall will likely not notice any difference. Most clients,

Client Setup

When configuring clients, there are a few points to look for: Ensure that the client operating system configuration is set to connect to the proper external address for the VPN. It may be necessary to force the VPN type

Client tweaks

Personally I like to tweak it a little bit so the windows hide themselves nicely in the system tray. This is optional but I find it improves the user experience. In the VPN Access Manager, go to File > Preferences . For

Cluster Configuration Basics

Each node requires some basic configuration outside of the actual HA setup. Do not connect both nodes into the same LAN before both nodes have a non- conflicting LAN setup. Installation, interface assignment and basic co

Configure a AZATCO-FW Authentication Server

In the AZATCO-FW webGUI, navigate to System > User Manager Select the Servers tab Click + to add a new entry Enter a Descriptive name such as FreeRADIUS Select RADIUS for the Type Enter 127.0.0.1 for the Hostname or IP a

Configure a new Interface

A PPPoE WAN is actually assigned to a virtual PPPoE adapter, not the physical port. Under Interfaces > Assignments , create a new OPT interface, and assign it to the physical network card that is on WAN. For example, if

Configure a WireGuard Tunnel

To configure a WireGuard Tunnel: Navigate to VPN > WireGuard Click Add Tunnel Fill in the WireGuard Tunnel settings as described in WireGuard Tunnel Settings Click Add Peer Fill in the WireGuard Peer settings as describe

Configure Configuration Synchronization (XML-RPC)

Warning: Configuration synchronization must only be configured on the primary node . Never activate options in this section on the secondary node of a two-member cluster. On the primary node only, perform the following:

Configure DNS

Now to setup the DNS portion. WPAD will take the domain name given to the machine, likely assigned by DHCP, and prepend wpad. . If the domain is example.com , it will look for wpad.example.com . This task may be accompli

Configure DNS Servers

First, configure the DNS servers on the firewall. Warning: When the firewall uses DNS over TLS, every DNS server used by the firewall must support DNS over TLS. Navigate to System > GeneralLocate the DNS Server Settings

Configure firewall rules at Site B

From the Firewall menu, choose Rules . Open the WAN tab, unless using a different interface for the VPN connection. Click on the + button to add a new rule. Enter these values: Action Pass Disabled not checked Interface

Configure LDAP authentication on AZTCO-FW

From the web interface on pfSense: Select System > User manager , Authentication servers tab Click Add to create a new entry Enter a Descriptive name for this LDAP server, such as G Suite Set Type to LDAP The server sett

Configure NAT

Now NAT needs to be configured to translate traffic destined to the modem to the new interface. This is necessary so the modem sees the traffic sourced from an IP on its local subnet. Without this NAT, it would be necess

Configure OpenVPN to use RADIUS

Navigate to VPN > OpenVPN Select the Servers tab Edit the existing Remote Access server Ensure that the Mode is either Remote Access (User Auth) or Remote Access (SSL/TLS + User Auth) Select FreeRADIUS or the Descriptive

Configure outbound NAT

In the default setup outbound NAT is configured automatically. We need to set it to Manual in order to add Site A’s subnet. This configuration step is not required on the router at site A. Site B Configuration From the F

Configure pfsync

State synchronization using pfsync must be configured on both the primary and secondary nodes to function. First on the primary node and then on the secondary, perform the following: Navigate to System > High Avail Sync

Configure the BIND Server

On the server in named.conf, add the following block: include “/etc/namedb/dns.keys.conf”; zone “dyn.example.com” { type master; file “dynamic/dyn.example.com”; update-policy { grant *.dyn.example.com. self dyn.example.c

Configure the firewall

Go to Firewall > Rules , WAN tab and click + to create a new rule. Enter these values: Action Pass Disabled not checked Interface WAN Protocol UDP Source unchecked, any Destination unchecked, WAN address Destination port

Configure the LDAP Application on the G Suite admin portal

Follow the instructions from Google for configuring and enabling the G Suite LDAP application . Warning: Follow these directions exactly . No special provisions are required for AZTCO-FW, but please note that the LDAP ap

Configure the New OPT Interface

The new interface is now accessible under Interfaces > OPTx , where x depends on the number assigned to the interface. Navigate to the new interface configuration page. ( Interfaces > OPTx ) Check Enable Interface . Ente

Configure the Squid Package

After the installation has finished, the Squid proxy server may be configured. Click on the Local Cache tab. Hard disk cache size (in MB): Set this as needed, but keep it a reasonable size. 3000 (3GB) may be a good place

Configure the stunnel package (CE or 2.4.4-RELEASE)

From the web interface on AZTCO-FW: Navigate to Services > STunnelClick Add to create a new profile Enter a Description for this connection, such as G Suite Check Client ModeSet Listen on IP to 127.0.0.1 Set Listen on po

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.