A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesMore information on automation, customization and registry tweaks are available in this text document: http://openvpn.se/install.txt Troubleshooting If something doesn’t work, here are some pointers for troubleshooting:
The shortcut to OpenVPN GUI can be edited to directly connect to a firewall instead of first starting OpenVPN and then starting the connection by right-clicking the shortcut and adding to the Target field: –connect “Head
Next, configure the DNS Resolver to use DNS over TLS for outgoing queries. Navigate to Services > DNS ResolverUncheck Enable DNSSEC Support Note: DNSSEC is not generally compatible with forwarding mode, with or without D
The DNS Resolver can also act as a DNS over TLS server, though it does not affect outbound/forwarded queries, so this section is optional. Only enable this feature if local clients must talk to the DNS Resolver using DNS
This documentation will cover many parts from installation, configuration, modification. A one time password is a password which can be only used one time and will be only usable within a short time period (10s). So it c
There are countless ways to configure the user manager to connect to an external RADIUS or LDAP server, but there are some common methods that can be helpful to use as a guide. The following are all tested/working exampl
Click Finish to complete the wizard. The firewall will then create all of the rules and queues for enabled options, and then it will reload the ruleset to activate the new traffic shaper settings. Due to the firewall ope
Click Finish and the wizard is now complete; The tunnel is fully configured and ready for client connections. From here the next steps are to add users and configure client devices. If adjustments to the automatically ge
With Multi-WAN a firewall rule must be in place to pass traffic to local networks using the default gateway. Otherwise, when traffic attempts to reach the CARP address or from LAN to DMZ it will instead go out a WAN conn
The NAT and IP address configuration is now complete. Firewall rules will need to be added to permit outbound and inbound traffic. Figure 90: OPT1 Firewall Rules shows a DMZ-like configuration, where all traffic destined
As with other parts of the firewall, by default all traffic is blocked from connecting to VPNs or passing over VPN tunnels. This step of the wizard adds firewall rules automatically to allow traffic to connect to the VPN
As with the static site-to-site tunnels, mobile tunnels will also need firewall rules added to the IPsec tab under Firewall Rules . In this instance the source of the traffic would be the subnet chosen for the mobile cli
The default EAP settings will work in most situations (EAP-MD5, EAP-TLS, EAP-TTLS, EAP-PEAP) so there is no need to change them without any need. If EAP-TTLS or EAP-PEAP is used with VLAN assignment then set Use Tunneled
This recipe describes a simple three interface HA configuration. The three interfaces are LAN, WAN, and Sync. This is functionally equivalent to a two interface LAN and WAN deployment, with the Sync interface being used
HA can also be deployed for firewall redundancy in a multi-WAN configuration. This section details the VIP and NAT configuration needed for a dual WAN HA deployment. This section only covers topics specific to HA and mul
As mentioned earlier, only CARP VIPs provide redundancy for addresses directly handled by the firewall, and they can only be used in conjunction with NAT or services on the firewall itself. Redundancy can also be provide
HP ProCurve switches only support 802.1q trunking, so no configuration is needed for encapsulation. First, ssh or telnet into the switch and bring up the management menu. Enable VLAN Support First, VLAN support needs to
To open the firewall GUI, create a firewall rule to allow remote firewall administration. Note: Do not create a port forward or other NAT configuration. Firewall > Rules , WAN Tab Action : pass Interface : WAN Protocol :
Create a Certificate Authority If a suitable Certificate Authority (CA) is not present in the Cert Manager, creating one is the first task: Navigate to System > Cert Manager on the AZTCO-FW firewall Click Add to create a
There are several components to the server configuration for mobile clients: Creating a certificate structure for the VPN Configuring the IPsec Mobile Client settings Creating the phase 1 and phase 2 for the client conne
The server setup is complete, the following tasks will configure the client side. Export CA Cert from the AZTCO-FW router and download it to the client PC Navigate to System > Cert Manager , Certificate Authorities tab i
From the web interface of a firewall running AZTCO-FW: Navigate to System > Cert manager, Certificates tab Click Add/Sign to display the certificate import interface Change Method to Import an existing certificate Enter
Export client certificate from the pfSense router and download it to the client PC Navigate to System > Cert Manager , Certificates tab in the pfSense webGUI Click by the certificate to download a .p12 file containing th
Go to System > Cert Manager , CAs tab and click +. Enter these values: Descriptive name TestDomain VPN CA Method Create an internal Certificate Authority Key length 2048 Lifetime 3650 days Ten years should be enough for