A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesTo add a DynDNS entry in the AZTCO-FW GUI: Navigate to Services > Dynamic DNS , RFC 2136 tab Click Add to create a new entry with the following settings: Enable Checked Interface WAN Hostname The fully qualified hostname
This recipe details one way to make a single OpenVPN server go a long way. Using this method access can be provided to a large pool of addresses for general access and then make use of some of the less intuitive features
This page provides information on using AZTCO-FW software with online games. First, many games will require the use of Static Port or UPnP/NAT-PMP . The forum often has a wide array of threads for specific games and cons
If the DNS for a domain is directly controlled on a BIND server, RFC 2136 Dynamic DNS support can be setup for use by AZTCO-FW. This section shows how to configure BIND to support this feature. The exact location of the
Navigate to VPN > OpenVPN , Client tab on the client system Click Add to create a new OpenVPN client instance Fill in the fields as follows, with everything else left at defaults: Server Mode Select Peer to Peer (Shared
Several popular public DNS providers provide encrypted DNS service using DNS over TLS. This prevents intermedi- ate parties from viewing the content of DNS queries and can also assure that DNS is being provided by the ex
Most operating systems include native client support for IPsec IKEv2 VPN connections, and others typically have an app or add-on package which adds the capability. This section covers IPsec IKEv2 client configuration for
Note: Android considers using a VPN an action that must be secure. When activating any VPN option the OS will force the user to add some form of locking to the device if one is not already present. It doesn’t matter whic
As of version 9, iOS has built-in support for IKEv2 that can be configured from the GUI without requiring a VPN Profile. As with other clients, the CA Certificate must be installed. Import the CA to the iOS Device Import
As of OS X 10.11 (El Capitan) it is possible to configure an IKEv2 type VPN manually in the GUI without needing a VPN Profile configuration file. Configuration for IKEv2 is integrated into the network management settings
Before starting, install network-manager-strongswan and strongswan-plugin-eap-mschapv2 using apt-get or a similar mechanism. Setup the VPN Connection Copy the CA Certificate for the VPN from the firewall to the workstati
Windows 8 and newer easily support IKEv2 VPNs, and Windows 7 can as well though the processes are slightly different. The procedure in this section was performed on Windows 10, but Windows 8 is nearly identical. The proc
A location that doesn’t have access to native IPv6 connectivity may obtain it using a tunnel broker service such as Hurricane Electric . A core site with IPv6 can deliver IPv6 connectivity to a remote site by using a VPN
Multi-WAN can be utilized with IPv6 provided that the firewall is connected to multiple ISPs or tunnels with static addresses. See also: See Configuring IPv6 Through A Tunnel Broker Service for help setting up a tunnel.
For VoIP there are typically a few components to get right for proper inbound and outbound audio from a local PBX. Port forward entries with firewall rules (Or 1:1 NAT with Firewall Rules) Manual Outbound NAT with a rule
If VoIP is being used, the default settings may not be correct in certain circumstances. The default settings handle the majority of scenarios, but depending on the specifics of a particular setup, changes may be necess
To configure NPS, bring up the Server Manager and either Network Policy and Access Services (2008) or NAP (2012) should be present. A RADIUS client will be added for AZTCO-FW first, then remote access policies will be co
The options on this step of the wizard configure each aspect of how the OpenVPN server itself will behave as well as options which are passed on to clients. The options presented here are the same as those discussed prev
Navigate to VPN > OpenVPN, Server tab Click Add to create a new server entry Fill in the fields as follows, with everything else left at defaults: Server Mode Select Peer to Peer (Shared Key) . Description Enter text her
On the client, import the CA certificate along with the client certificate and key for that site. This is the same CA and client certificate made on the server and exported from there. This can be done under System > Cer
Before the VPN can be configured, a certificate structure for this VPN is required. Create a CA unique to this VPN and from that CA create a server certificate, and then a user certificate for each remote site. For the c
This section provides guidance on configuring a few varieties of switches for use with VLANs. This offers generic guidance that will apply to most if not all 802.1Q capable switches, then goes on to cover configuration o
This recipe describes how to install and configure Squid as a transparent proxy on AZTCO-FW software.
Clients connecting to the VPN must also be set to use tap mode. Once that has been set, connect with a client such as one exported using the OpenVPN Client Export package. The clients will receive an IP address inside t