AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Connecting OpenVPN Sites with Conflicting IP Subnets

One common use of NAT with OpenVPN is to mask conflicting LAN subnets between two locations. If two net- works are using the exact same subnet, or overlapping subnets, as their LAN or other internal network they cannot c

Connecting to L2TP/IPsec from Android

The L2TP/IPsec client on Android has the ability to set a custom identifier, which allows L2TP/IPsec to function with the AZTCO-FW server using Pre-Shared Keys. Clients on other operating systems do not allow for this, w

Create a Certificate

A certificate must be created for each user that is going to use the VPN system. In Descriptive and Common Name , enter the username the user uses to log on to Active Directory. Strictly speaking Descriptive name can be

Create a Group

Using a remote authentication server to manage administrative logins to services on AZTCO-FW requires a matching group to be present on both the authentication source server and on the firewall. The existing admins group

Create a group VPNusers

Create a security group in Active Directory Users and Computers called VPNusers . Everyone could have access but it’s a good idea to keep some granular control over it. Add all accounts that need to use the VPN system to

Create an internal certificate

Go to System > Cert Manager , Certificates tab and click+ . Enter these values: Method Create an internal Certificate Descriptive name vpn-testdomain-network Certificate Authority TestDomain VPN CA Key length 2048 Certif

Create and Assign the GIF Interface

Next, create the interface for the GIF tunnel in AZTCO-FW. Complete the fields with the corresponding information from the tunnel broker configuration summary. Navigate to Interfaces > Assignments on the GIF tab. Click A

Create wpad.dat

Before starting, a wpad.dat file must be crafted. This is a single file with a JavaScript function which tells the browser how to find a proxy hostname and port. This function can be as simple or as complex as desired, t

Creating a Certificate Authority

This step presents all of the necessary fields to create a new certificate authority (CA). Every option on this page is required, and all fields must be filled out correctly to proceed. The CA is used to establish a trus

Creating the Bridge

Once the OpenVPN tap server has been created, the OpenVPN interface must be assigned and bridged to the internal interface. Assign OpenVPN interface In order to include the VPN interface in a bridge, it must be assigned.

Dell PowerConnect managed switches

The management interface of Dell switches varies slightly between models, but the following procedure will accom- modate most models. The configuration is quite similar in style to Cisco IOS. First, create the VLANs: con

Determine IP Address Assignments

For this example, four IP addresses will be used on each WAN. Each firewall needs an IP address, plus one CARP VIP for Outbound NAT, plus an additional CARP VIP for a 1:1 NAT entry that will be used for an internal mail

Determine IP Address Assignments

The first task is to plan IP address assignments. A good strategy is to use the lowest usable IP address in the subnet as the CARP VIP, the next subsequent IP address as the primary firewall interface IP address, and the

Device Setup (Android)

Note: These settings are not present on all Android devices. Tap Settings, Networks & Wireless, VPN Settings, Advanced IPsec VPNs From there, press the menu button, then add. Connection Template : PSK v1 (AES, xauth, agg

Device Setup (iOS)

Tap Settings > General > Network > VPN Tap Add VPN Configuration Tap IPsec Description: AZTCO-FW VPN (Or some other description) Server: IP of the server Account : xauth username Password : xauth password (or leave blan

Disable scrub

In very rare circumstances, scrubbing needs to be disabled under System > Advanced , Firewall/NAT tab . In most cases this should be left at the default setting (unchecked). Only change this setting if it has been determ

Disable source port rewriting

By default AZTCO-FW software rewrites the source port on all outbound traffic. This is necessary for proper NAT in some circumstances such as having multiple SIP phones behind a single public IP registering to a single e

DNS Configuration

If DNS servers are supplied to the clients and the Unbound DNS Resolver is used, then the subnet chosen for the L2TP clients must be added to its access list. Navigate to Services > DNS Resolver , Access Lists tab Click

DNS over HTTPS

Similar to DNS over TLS, clients may also use DNS over HTTPS (DoH). This is harder to block as it uses port 443. Blocking port 443 on common public DNS servers may help (e.g. 1.1.1.1, 8.8.8.8). Some browsers automaticall

DNS over TLS

Another concern is that clients could use DNS over TLS to resolve hosts. DNS over TLS sends DNS requests over an encrypted channel on an alternate port, 853. This traffic can be blocked with a firewall rule for port 853

Download the certificate, key, username and password

Download the certificate, key, username and password from G Suite to a local directory on a workstation

EAP-RADIUS with FreeRADIUS

The default settings are OK for this

EAP-RADIUS with Windows Network Policy Server (NPS)

To allow strongSwan to authenticate against NPS using EAP-MSCHAPv2, alter the NPS policy as follows: •    Open Network Policy Server (NPS) Expand Policies Click Network Policies Edit the policy currently in use Click on

EAP-TLS

AZTCO-FW configuration: Create a CA , a Server-Certificate and a Client-Certificate . Using System > Cert Manager is recom- mended. FreeRADIUS configuration: Create an interface , add a NAS/Client and create a user . For

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.