AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

Install and configure RADIUS

If RADIUS isn’t already set up, add the role to the Domain Controller. If it is set up, skip this step. Open Server Manager and click the Roles node in the tree on the left. On the right side, click Add Roles . This will

Install the OpenVPN Client Export Package

Go to System > Packages , Available Packages tab. Scroll down to OpenVPN Client Export Package and click on the right. Confirm the selection and the package will be installed. When it says Installation completed the inst

install the OpenVPN package

Copy the downloaded Windows Installed to the client. It is named after the tunnel configuration, for example router- udp-1194-install.exe . Run the installer with all defaults. When selecting components, make sure they a

Install the Package

First, install the Squid package. Click System > Package Manager Click Available Packages Enter squid in the search bar and click search or scroll down until the squid package listing is visible Click the install button

Install the stunnel AZTCO-FW package (CE or 2.4.4-RELEASE)

From the web interface on AZTCO-FW: Navigate to System > Package manager, Installed Packages tab Check the list for stunnel and if it is listed as installed If the package is installed and up-to-date, with a version of 5

Installing NPS

On Windows Server 2008: Navigate to Server Manager Click Roles on the left and expand it Click Add Roles on the right Click Next to skip the intro screen On Server 2012: Open the System Manager Dashboard Click Add Roles

Installing OpenVPN Remote Access Clients

An OpenVPN client needs to be installed on most end-user devices, as the client functionality is not yet built into most operating systems. This section provides an overview of installation on several common operating sy

Installing the OpenVPN Client Configuration Manually

Performing a manual client installation instead of using the OpenVPN Client Export Package requires additional steps to install the software and settings onto the client devices. Installing the client on other operating

Installing the OpenVPN Client on Android

For devices running Android 4.0 or a newer release, there is a free OpenVPN app in the Google Play store that works excellently without needing root access. It is called OpenVPN for Android by Arne Schwabe. OpenVPN Clien

Installing the OpenVPN Client on FreeBSD

If the client has a stock FreeBSD installation, OpenVPN may be found in the ports collection. To install OpenVPN, run the following as root : # pkg install openvpn Alternately, it can be installed from ports: # cd /usr/p

Installing the OpenVPN Client on iOS

iOS is also capable of running OpenVPN natively using the iOS OpenVPN Connect client available in the App Store. This app does not require jailbreaking the iOS device. The app must have the config file and certificates c

Installing the OpenVPN Client on Linux

Installing OpenVPN on Linux will vary depending on the preferred distribution and method of managing software installations. OpenVPN is included in the package repositories of most major Linux distributions. With all the

Installing the OpenVPN Client on Mac OS X

There are three client options for Mac OS X.: The OpenVPN command line client. Most users prefer a graphical client, so this option will not be covered. Tunnelblick, a free option available for download at the Tunnelblic

Installing the OpenVPN Client on Windows

The OpenVPN project provides an installer for Windows 2000 through Windows 10, downloadable from The Open- VPN Community Downloads Page . Alternately, use OpenVPN Client Export Package to create an installer bundled with

Interface Configuration

First configure the WAN and OPT interfaces. The LAN interface can also be used for public IP addresses if desired. In this example, LAN is a private IP subnet and OPT1 is the public IP subnet. Configure WAN Add the IP ad

IP Assignments

At least two public IP subnets must be assigned by the ISP. One is for the WAN of the firewall, and one for the inside interface. This is commonly a /30 subnet for the WAN, with a second subnet assigned for the internal

IPsec Export Package

The IPsec Export package generates client configurations for mobile IPsec, making it easier to configure remote access clients. This package is available on AZTCO-FW Plus as well as older Factory Edition versions of AZTC

IPsec Firewall Rules

Firewall rules are necessary to pass traffic from the client host over IPsec to establish the L2TP tunnel, and inside L2TP to pass the actual tunneled VPN traffic to systems across the VPN. Adding the L2TP rules was cove

IPsec Remote Access VPN Example Using IKEv1 with Pre- Shared Keys

This article describes how to set up Mobile IPsec in AZTCO-FW software with a Pre-Shared Key, and how to configure the Shrew Soft VPN Client to match. The Shrew Soft VPN client is freely available for Windows, Linux and

IPsec Remote Access VPN Example Using IKEv1 with Xauth

This document covers IPsec using Xauth and a mutual Pre-Shared Key. Note: The current best practice is to use IKEv2 for IPsec Remote Access on modern clients. See IPsec Remote Access VPN Example Using IKEv2 with EAP-MSCH

IPsec Remote Access VPN Example Using IKEv2 with EAP- RADIUS

To setup IKEv2 with EAP-RADIUS, follow the directions for IKEv2 with EAP-MSCHAPv2 with a slight variation: Define a RADIUS server under System > User Manager , Servers tab before starting Select the RADIUS server on VPN

IPsec Remote Access VPN Example Using IKEv2 with EAP-TLS

Under construction. Needs testing. IKEv2 is supported starting with AZTCO-FW software version 2.2 and one way to make it work is by using EAP-TLS, which is covered in this article.

IPsec Server Setup

This is the setup for the AZTCO-FW side of the connection Mobile Clients Navigate to VPN > IPsec , Mobile Clients tab Check Enable IPsec Mobile Client Support Check Provide a virtual IP address to clients Enter an unused

IPsec Setup

The setup is similar to a standard IPsec Remote Access VPN Example Using IKEv1 with Xauth setup except that xauth is not used, but rather “ Mutual PSK ”, and Phase 2 uses Transport mode rather than Tunnel. Pre-Shared Key

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.