A Brief Introduction to Web Proxies and Reporting: Squid, SquidGuard, and Lightsquid
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles2 articles
Browse articles2 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles9 articles
Browse articles19 articles
Browse articles1 articles
Browse articles9 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles2 articles
Browse articles6 articles
Browse articles5 articles
Browse articles12 articles
Browse articles4 articles
Browse articles4 articles
Browse articles3 articles
Browse articles6 articles
Browse articles2 articles
Browse articles2 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles2 articles
Browse articles5 articles
Browse articles4 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles2 articles
Browse articles6 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles17 articles
Browse articles3 articles
Browse articles3 articles
Browse articles3 articles
Browse articles4 articles
Browse articles4 articles
Browse articles4 articles
Browse articles6 articles
Browse articles3 articles
Browse articles1 articles
Browse articles2 articles
Browse articles10 articles
Browse articlesBegin by enabling IPsec. Navigate to VPN > IPsecCheck Enable IPsec Click Save Now, create a phase 1 entry. Do not click on this page to create a phase 1 entry. That button will not go the page needed to create a phase 1
I am not a security expert. However the method described in this article is they way it should be: Two-factor authentication: something the user has (the installed certificate) and something the user knows (AD user accou
In this example, AZTCO-FW software is setup to connect back to an OpenLDAP server for the company. Descriptive Name ExCoLDAP Type LDAP Hostname or IP Address ldap.example.com Port 636 Transport SSL – Encrypted Peer Certi
The OpenVPN Client Export Package allows exporting configurations formatted for a wide variety of platforms. It also allows exporting a pre-packaged Windows installer executable which includes the configuration bundled i
The OpenVPN wizard is a convenient way to setup a remote access VPN for mobile clients. It configures all of the necessary prerequisites for an OpenVPN Remote Access Server: An authentication source (Local, RADIUS server
Most of the settings for a bridged remote access VPN are the same as above for a traditional remote access VPN. Only the differences will be noted here. Device Mode To create a bridged connection, this must be set to tap
Fig. 78: OpenVPN Example Site-to-Site Network This section describes the process of configuring a site-to-site connection using a shared key style OpenVPN tunnel. When configuring a shared key site-to-site OpenVPN connec
Fig. 80: OpenVPN Example Site-to-Site SSL/TLS Network The process of configuring a site-to-site connection using SSL/TLS is more complicated than Shared Key . However, this method is typically much more convenient for ma
An OSPF package using the Quagga routing daemon is also available. As with BGP, to install it: Navigate to System > Package Manager Click Available PackagesLocate Quagga_OSPF in the list, or search for it Click the Inst
In theory, Mutual RSA should also work, but so far it has not succeeded in testing. In RSA mode, Phase 1 requires main mode, but otherwise should be OK.
FreeRADIUS package configuration: Configure an interface in FreeRADIUS > Interfaces Create a CA-Certificate and a Server-Certificate . Choose AZTCO-FW Cert-Manager or FreeRADIUS Cert- Manager but never use the default ce
The next step, shown in Figure 110: Peer-to-Peer Networking , sets controls for many Peer-to-Peer (P2P) networking proto- cols. By design, P2P protocols will utilize all available bandwidth unless limits are put in place
The penalty box, depicted in Figure 109: Penalty Box , is a place to relegate misbehaving users or devices that would otherwise consume undesirable amounts of bandwidth. These devices are assigned a hard bandwidth cap wh
For the port forward ( Firewall > NAT , Port Forwards tab), it can be set as follows: Interface : WAN Protocol : UDP (or TCP/UDP if needed) Source : Type Single Host or Alias: SIP_Trunks – or a Any for the type if the SI
Go to VPN > OpenVPN and note that there is an extra tab called Client Export . Click it. Enter these values: Remote Access Server VPN with RADIUS UDP:1194 Host Name Resolution If WAN has a static IP, enter Interface IP A
This recipe assumes squid is already operating in a non-transparent configuration.
The switch must be properly configured to accommodate the LAGG. This typically means configuring an LACP group and setting ports to use that group. The NICs involved, in this example re0 and re2, should be connected to p
With any of the above methods, there are many ways to get around the defined blocks. The easiest and likely most prevalent is using any number of proxy websites. Finding and blocking all of these individually and keeping
RFC1918 addresses are blocks of network IP addresses reserved for private use that are commonly used behind fire- walls to allow a single public IP address to be shared with multiple devices using NAT. The default AZTCO-
At least a /29 public IP block for the WAN side of pfSense® is necessary, which provides six usable IP addresses. Only three are required for a two firewall deployment, but this is the smallest IP subnet that will accomm
This document demonstrates how to setup OpenVPN while allowing for authentication via RADIUS. Usernames and Passwords can be managed centrally on the firewall, and additional RADIUS-specific options may be used. This is
This example was made against FreeRADIUS but doing the same for Windows Server would be identical. This assumes the RADIUS server has already been configured to accept queries from this firewall as a client with a shared
The last configuration screen of the shaper wizard, seen in Figure 112: Raise or Lower Other Applications , lists a number of other commonly available applications and protocols. The needs of a particular network dictate
To restrict client DNS to only the DNS Resolver or Forwarder on AZTCO-FW software, use a port forward to capture all DNS requests clients send to other servers. Note: Either The DNS Forwarder or DNS Resolver must be acti