AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

IPsec Site-to-Site VPN Example with Certificate Authentication

Using certificate-based authentication for identification of VPN tunnel peers is much stronger than using a simple Pre-Shared Key. To utilize certificate authentication, first create a PKI structure. This can be performe

IPsec Site-to-Site VPN Example with Pre-Shared Keys

A site-to-site IPsec tunnel interconnects two networks as if they were directly connected by a router. Systems at Site A can reach servers or other systems at Site B, and vice versa. This traffic may also be regulated vi

L2TP Setup

To setup L2TP navigate to VPN > L2TP Select Enable L2TP Server Interface is WAN (or the same chosen for IPsec) Server Address is an unused IP address in a new subnet. It MUST NOT overlap any IP in use on the firewall, e.

L2TP/IPsec Remote Access VPN Configuration Example

On current versions of AZTCO-FW software, L2TP/IPsec may be configured for mobile clients, though it is not a con- figuration we recommend. Warning: Users have reported issues with Windows L2TP/IPsec clients behind NAT.

LDAP or RADIUS Users

Adding LDAP and RADIUS users will fully depend on the server implementation and management tools,  which  are beyond the scope of this documentation. Contact the server administrator or software vendor for assistance. Ce

Lightsquid Web Access Reporting

Lightsquid is used to create reports that detail the web history of computers that have accessed sites through the proxy. After the Lightsquid package has been installed, the report settings may be found under Status > S

Local Users

To add a user that can connect to OpenVPN, they must be added to the User Manager as follows: Navigate to System > User Manager Click + Add to create a new user Enter a Username, Password, and password confirmation Fill

Manual Outbound NAT

For Manual Outbound NAT , navigate to Firewall > NAT , Outbound tab, switch from Automatic Outbound NAT to Manual Outbound NAT and press Save . Then at the top of the list, create a rule that looks like so: Interface : W

Method 1: NAT Reflection

In order to access ports forwarded on the WAN interface from internal networks, NAT reflection must be enabled. In order to do this, navigate to System > Advanced , Firewall/NAT tab. On that page, select Pure NAT for NAT

Method 2: Split DNS

The more elegant solution to this problem involves using Split DNS. Basically this means that internal and external clients resolve hostnames differently. Internal clients would access resources by hostname, not IP, and

Migrate LAN to a LAGG

Ensure the second NIC for the LAGG is not assigned (e.g. re0 mapped to OPT1 ) In the AZTCO-FW webGUI, check Interfaces > Assignments and remove its entry if present Create a new LAGG including only the second NIC Navigat

Migrating an Assigned LAN to LAGG

Only unassigned physical ports can be added to a LAGG, so to move an assigned LAN interface to a LAGG requires some shuffling around. In this example, the LAN of an APU ( re2 ) will be moved into a LAGG with the OPT1 por

Mobile IPsec User Creation

The next step is to add users for use by EAP-MSCHAPv2. Navigate to VPN > IPsec , Pre-Shared Keys tab Click Add to add a new key Configure the options as follows: Identifier The username for the client, can be expressed i

Mobile IPsec User Creation

The next step is to add users for use by EAP-MSCHAPv2. Navigate to VPN > IPsec , Pre-Shared Keys tab Click Add to add a new key Configure the options as follows: Identifier The username for the client, can be expressed i

Move the GUI to an Alternate Port

Moving the GUI to a non-standard, random port is also beneficial. This does not improve the actual security of the GUI itself, but can potentially reduce the number of brute force attempts. The GUI can still be found by

Multi-WAN HA with DMZ Diagram

Due to the additional WAN and DMZ elements,a diagram of this layout is much more complex. Fig. 9: Diagram of Multi-WAN HA with DMZ

NAT Configuration

The default of translating internal traffic to the WAN IP must be overridden when using public IP addresses on an internal interface. Browse to Firewall > NAT Click the Outbound tab Select Hybrid Outbound NAT rule genera

NAT Configuration

The NAT configuration when using HA with Multi-WAN is the same as HA with a single WAN. Ensure that only CARP VIPs are used for inbound traffic or routing.

Netgear Managed Switches

This example is on a GS108Tv1, but other Netgear models are all very similar if not identical. There are also several other vendors including Zyxel who sell switches made by the same manufacturer, using the same web inte

Network Games

Online games typically rely on low latency for acceptable player experiences. If a user on the network attempts to download large files or game patches while playing, that traffic can easily drown out the packets associa

Network Overview

The example network depicted here is a data center environment consisting of two AZTCO-FW firewalls with four inter- faces each: WAN, LAN, DBDMZ, and pfsync. This network contains a number of web and database servers. It

Networks and Speeds

This step, shown in Figure 107: Shaper Configuration , defines the network interfaces that will be the inside and outside from the point of view of the shaper, along with the Download and Upload speeds for a given WAN. W

Notes

Adding this rule to the AZTCO-FW firewall will block access to bridge devices like cable modems or upstream routers outside of the WAN interface. For example, many cable modems use an IP address of 192.168.100.1. This ma

Notes

Remember a client in this scheme needs to have a push route and a firewall rule to be be able access resources. It is recommended to allow ICMP everywhere on the OpenVPN firewall rules tab to help debugging. Why use port

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.