AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Edit more settings

More information on automation, customization and registry tweaks are available in this text document: http://openvpn.se/install.txt Troubleshooting If something doesn’t work, here are some pointers for troubleshooting:

Edit the shortcut to connect directly

The shortcut to OpenVPN GUI can be edited to directly connect to a firewall instead of first starting OpenVPN and then starting the connection by right-clicking the shortcut and adding to the Target field: –connect “Head

Enable DNS over TLS for Forwarded Queries

Next, configure the DNS Resolver to use DNS over TLS for outgoing queries. Navigate to Services > DNS ResolverUncheck Enable DNSSEC Support Note: DNSSEC is not generally compatible with forwarding mode, with or without D

Enable DNS over TLS Server (optional)

The DNS Resolver can also act as a DNS over TLS server, though it does not affect outbound/forwarded queries, so this section is optional. Only enable this feature if local clients must talk to the DNS Resolver using DNS

Enable Mobile-One-Time-Password (OTP) support

This documentation will cover many parts from installation, configuration, modification. A one time password is a password which can be only used one time and will be only usable within a short time period (10s). So it c

External User Authentication Examples

There are countless ways to configure the user manager to connect to an external RADIUS or LDAP server, but there are some common methods that can be helpful to use as a guide. The following are all tested/working exampl

Finishing the Wizard

Click Finish to complete the wizard. The firewall will then create all of the rules and queues for enabled options, and then it will reload the ruleset to activate the new traffic shaper settings. Due to the firewall ope

Finishing the Wizard

Click Finish and the wizard is now complete; The tunnel is fully configured and ready for client connections. From here the next steps are to add users and configure client devices. If adjustments to the automatically ge

Firewall Configuration

With Multi-WAN a firewall rule must be in place to pass traffic to local networks using the default gateway. Otherwise, when traffic attempts to reach the CARP address or from LAN to DMZ it will instead go out a WAN conn

Firewall Rule Configuration

The NAT and IP address configuration is now complete. Firewall rules will need to be added to permit outbound and inbound traffic. Figure 90: OPT1 Firewall Rules shows a DMZ-like configuration, where all traffic destined

Firewall Rule Configuration

As with other parts of the firewall, by default all traffic is blocked from connecting to VPNs or passing over VPN tunnels. This step of the wizard adds firewall rules automatically to allow traffic to connect to the VPN

Firewall Rules

As with the static site-to-site tunnels, mobile tunnels will also need firewall rules added to the IPsec tab under Firewall Rules . In this instance the source of the traffic would be the subnet chosen for the mobile cli

General EAP configuration

The default EAP settings will work in most situations (EAP-MD5, EAP-TLS, EAP-TTLS, EAP-PEAP) so there is no need to change them without any need. If EAP-TTLS or EAP-PEAP is used with VLAN assignment then set Use Tunneled

High Availability Configuration Example

This recipe describes a simple three interface HA configuration. The three interfaces are LAN, WAN, and Sync.  This is functionally equivalent to a two interface LAN and WAN deployment, with the Sync interface being used

High Availability Configuration Example with Multi-WAN

HA can also be deployed for firewall redundancy in a multi-WAN configuration. This section details the VIP and NAT configuration needed for a dual WAN HA deployment. This section only covers topics specific to HA and mul

High Availability Configuration Example without NAT

As mentioned earlier, only CARP VIPs provide redundancy for addresses directly handled by the firewall, and they can only be used in conjunction with NAT or services on the firewall itself. Redundancy can also be provide

HP ProCurve switches

HP ProCurve switches only support 802.1q trunking, so no configuration is needed for encapsulation. First, ssh or telnet into the switch and bring up the management menu. Enable VLAN Support First, VLAN support needs to

I Don’t Care About Security, How Do I Open Access To The GUI?

To open the firewall GUI, create a firewall rule to allow remote firewall administration. Note: Do not create a port forward or other NAT configuration. Firewall > Rules , WAN Tab Action : pass Interface : WAN Protocol :

IKEv2 Certificate Structure

Create a Certificate Authority If a suitable Certificate Authority (CA) is not present in the Cert Manager, creating one is the first task: Navigate to System > Cert Manager on the AZTCO-FW firewall Click Add to create a

IKEv2 Server Configuration

There are several components to the server configuration for mobile clients: Creating a certificate structure for the VPN Configuring the IPsec Mobile Client settings Creating the phase 1 and phase 2 for the client conne

Import the CA to the Client PC

The server setup is complete, the following tasks will configure the client side. Export CA Cert from the AZTCO-FW router and download it to the client PC Navigate to System > Cert Manager , Certificate Authorities tab i

Import the certificate and key

From the web interface of a firewall running AZTCO-FW: Navigate to System > Cert manager, Certificates tab Click Add/Sign to display the certificate import interface Change Method to Import an existing certificate Enter

Import the Client Certificate to the Client PC

Export client certificate from the pfSense router and download it to the client PC Navigate to System > Cert Manager , Certificates tab in the pfSense webGUI Click by the certificate to download a .p12 file containing th

Install a Certificate Authority

Go to System > Cert Manager , CAs tab and click +. Enter these values: Descriptive name TestDomain VPN CA Method Create an internal Certificate Authority Key length 2048 Lifetime 3650 days Ten years should be enough for

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.