AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Configuration Recipes

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

53 subcategories

Articles

292 results

On AZTCO-FW

Begin by enabling IPsec. Navigate to VPN > IPsecCheck Enable IPsec Click Save Now, create a phase 1 entry. Do not click on this page to create a phase 1 entry. That button will not go the page needed to create a phase 1

On security and a disclaimer

I am not a security expert. However the method described in this article is they way it should be: Two-factor authentication: something the user has (the installed certificate) and something the user knows (AD user accou

OpenLDAP Example

In this example, AZTCO-FW software is setup to connect back to an OpenLDAP server for the company. Descriptive Name ExCoLDAP Type LDAP Hostname or IP Address ldap.example.com Port 636 Transport SSL – Encrypted Peer Certi

OpenVPN Client Export Package

The OpenVPN Client Export Package allows exporting configurations formatted for a wide variety of platforms. It also allows exporting a pre-packaged Windows installer executable which includes the configuration bundled i

OpenVPN Remote Access Configuration Example

The OpenVPN wizard is a convenient way to setup a remote access VPN for mobile clients. It configures all of the necessary prerequisites for an OpenVPN Remote Access Server: An authentication source (Local, RADIUS server

OpenVPN Server Settings

Most of the settings for a bridged remote access VPN are the same as above for a traditional remote access VPN. Only the differences will be noted here. Device Mode To create a bridged connection, this must be set to tap

OpenVPN Site-to-Site Configuration Example with Shared Key

Fig. 78: OpenVPN Example Site-to-Site Network This section describes the process of configuring a site-to-site connection using a shared key style OpenVPN tunnel. When configuring a shared key site-to-site OpenVPN connec

OpenVPN Site-to-Site Configuration Example with SSL/TLS

Fig. 80: OpenVPN Example Site-to-Site SSL/TLS Network The process of configuring a site-to-site connection using SSL/TLS is more complicated than Shared Key . However, this method is typically much more convenient for ma

OSPF

An OSPF package using the Quagga routing daemon is also available. As with BGP, to install it: Navigate to System > Package Manager Click Available PackagesLocate Quagga_OSPF in the list, or search for it Click the  Inst

Other Thoughts

In theory, Mutual RSA should also work, but so far it has not succeeded in testing. In RSA mode, Phase 1 requires main mode, but otherwise should be OK.

PEAP and MSCHAPv2

FreeRADIUS package configuration: Configure an interface in FreeRADIUS > Interfaces Create a CA-Certificate and a Server-Certificate . Choose AZTCO-FW Cert-Manager or FreeRADIUS Cert- Manager but never use the default ce

Peer-to-Peer Networking

The next step, shown in Figure 110: Peer-to-Peer Networking , sets controls for many Peer-to-Peer (P2P) networking proto- cols. By design, P2P protocols will utilize all available bandwidth unless limits are put in place

Penalty Box

The penalty box, depicted in Figure 109: Penalty Box , is a place to relegate misbehaving users or devices that would otherwise consume undesirable amounts of bandwidth. These devices are assigned a hard bandwidth cap wh

Port Forwards

For the port forward ( Firewall > NAT , Port Forwards tab), it can be set as follows: Interface : WAN Protocol : UDP (or TCP/UDP if needed) Source : Type Single Host or Alias: SIP_Trunks – or a Any for the type if the SI

Prepare the Windows package

Go to VPN > OpenVPN and note that there is an extra tab called Client Export . Click it. Enter these values: Remote Access Server VPN with RADIUS UDP:1194 Host Name Resolution If WAN has a static IP, enter Interface IP A

Prerequisites

This recipe assumes squid is already operating in a non-transparent configuration.

Prerequisites/Assumptions

The switch must be properly configured to accommodate the LAGG. This typically means configuring an LACP group and setting ports to use that group. The NICs involved, in this example re0 and re2, should be connected to p

Prevent Bypassing Restrictions

With any of the above methods, there are many ways to get around the defined blocks. The easiest and likely most prevalent is using any number of proxy websites. Finding and blocking all of these individually and keeping

Preventing RFC1918 Traffic from Exiting a WAN Interface

RFC1918 addresses are blocks of network IP addresses reserved for private use that are commonly used behind fire- walls to allow a single public IP address to be shared with multiple devices using NAT. The default AZTCO-

Public IP Assignments

At least a /29 public IP block for the WAN side of pfSense® is necessary, which provides six usable IP addresses. Only three are required for a two firewall deployment, but this is the smallest IP subnet that will accomm

Purpose

This document demonstrates how to setup OpenVPN while allowing for authentication via RADIUS. Usernames and Passwords can be managed centrally on the firewall, and additional RADIUS-specific options may be used. This is

RADIUS Server Example

This example was made against FreeRADIUS but doing the same for Windows Server would be identical. This assumes the RADIUS server has already been configured to accept queries from this firewall as a client with a shared

Raising or Lowering Other Applications

The last configuration screen of the shaper wizard, seen in Figure 112: Raise or Lower Other Applications , lists a number of other commonly available applications and protocols. The needs of a particular network dictate

Redirecting Client DNS Requests

To restrict client DNS to only the DNS Resolver or Forwarder on AZTCO-FW software, use a port forward to capture all DNS requests clients send to other servers. Note: Either The DNS Forwarder or DNS Resolver must be acti

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.