AIMdefense Plugins

AIMdefense ships its own add-on modules that go beyond the base installation. This chapter describes what they do, where to find them in the user interface, and what you should know when running them.

All modules described here carry package names starting with os-s2f. They are managed under System ▸ Firmware ▸ AIMdefense AppStore.

Connecting to the central platform

COD Registration (os-s2fcod)

Menu: Lobby ▸ COD Registration

The Central Operations Dashboard, COD for short, is the central management system for a fleet of AIMdefense firewalls. Before COD can manage a firewall, that firewall has to register with it. That is what this module does.

Registration has three steps. You sign in with your COD account, you pick a tenant and a location, and you submit the firewall for approval.

In doing so the firewall hands COD an API key and secret generated on the firewall itself. COD uses those credentials to access the firewall afterwards. The secret is shown exactly once and is not stored on the page.

Settings

Field

Meaning

COD URL

Base address of your COD instance. If the scheme is missing, https:// is added.

Firewall IP / FQDN

The address COD uses to reach this firewall. Detected automatically on first load, in the order WAN, LAN, first interface with an IPv4 address. A value you set yourself is never overwritten.

Firewall Port

Port of the firewall API. Default 443.

User

The local firewall user the API key belongs to.

API Key / Secret

Credentials for COD. Can be regenerated with Generate new key.

Username / Password / OTP

Credentials of your COD account. The one-time code is only required if it is enabled for that account.

Tenant / Location

Tenant and location. These appear only after a successful sign-in.

What you should know

Note

The page has no save button. Address, port and COD URL are only stored permanently on a successful registration. Aborting halfway through leaves nothing behind.

Note

Your COD account needs permission to create a firewall in the target location. Without it, registration fails even though sign-in worked. If COD returns no locations, the registration area stays hidden.

Warning

The certificate of the COD instance is not verified. This is deliberate, because COD is usually operated by the customer and often uses a private or self-signed certificate. Run the connection on a network you trust.

The COD session lasts about 15 minutes. Once it expires you have to sign in again, with a fresh one-time code if that is enabled.

If COD does not offer the required interface, sign-in aborts with a note that COD and AIMdefense need compatible versions.

The firewall identifies itself by its serial number. If no usable serial number is available, the system UUID is used, and failing that the host name.

Event reporting to COD

After registration the firewall reports events to COD on its own: failover switches, configuration changes and gateway alarms. Which of these are monitored is set by the location in COD. Reporting errors are written to the system log and otherwise discarded, firewall operation is not affected.

License administration (os-s2flic)

Menu: Lobby ▸ AIMdefense License

This is where you register your AIMdefense and manage the license. Both registration with a license key and trial registration are available.

On registration the firewall transmits hardware details, the license key and a machine identifier. The check then runs regularly in the background.

Note

Registration additionally triggers an expansion of the file system, provided unused space is available on the storage device. This is intended and makes sure a device uses its full storage after commissioning.

User interface and navigation

Themes (os-s2fthemes)

This package carries the AIMdefense look, that is colours, fonts and logos. It has no menu entry of its own. The theme is set during installation and only written to the configuration if it actually changes.

Note

The menu icons of some modules come from these themes. Without the theme package they are missing.

Software sources and app store

Package sources (os-s2frepo)

Menu: System ▸ Firmware ▸ AIMdefense Repository

This is where you set which source the firewall uses for packages and updates.

Note

Only the production source is supported for productive use. Other sources are meant for testing.

The configured source is checked periodically in the background and restored if needed.

App store (os-s2fappstore)

Menu: System ▸ Firmware ▸ AIMdefense AppStore

The app store shows the available add-on modules as tiles, grouped into tabs by topic. This is where you install and remove modules.

Note

Not every system sees the same tiles. Only what matches the hardware present and the licensed scope is shown. If no tile in a topic matches, the whole tab disappears. If you are missing a module, check your license first.

The progress of an installation is written to an output field.

Base module and system tools

Base module (os-s2fbase)

The base module carries the AIMdefense branding of the interface and makes sure the AIMdefense modules are added on existing devices. It has a menu entry of its own at the very bottom of the menu.

Environment (os-s2fenv)

Menu: System ▸ Settings ▸ AIMdefense Environment

This is where you store environment settings, among them a proxy server for outgoing connections.

Note

Address and port of the proxy belong together. Either you fill in both fields or you leave both empty.

Toolkit (os-s2ftools)

The toolkit contains command line scripts, mainly for expanding the file system. It has no interface of its own.

Danger

These scripts change the partitioning. They ask for confirmation and abort if the preconditions are not met. Take a backup first.

Connecting to other systems

Unifi controller (os-s2funifi)

Menu: Wireless ▸ Unifi ▸ Controller

Runs a Unifi controller directly on the firewall. This lets you manage your access points without setting up an additional server.

Host routing (os-s2fhostroute)

Allows routes to individual hosts instead of whole networks only. The module has no interface of its own, it extends the existing route management.

Mail and defence

Fetchmail (os-s2ffetchmail)

Menu: Services ▸ AIMdefense Fetchmail

Collects messages from remote mailboxes and delivers them locally. For each mailbox you create an entry with server, credentials and target recipient. There is a dedicated log view.

rspamd (os-s2frspamd)

Menu: Services ▸ AIMdefense Rspamd

Checks messages for unwanted mail. Besides the settings there is a statistics view and a learning function.

Warning

The password of the rspamd web interface is stored in clear text in the configuration. Do not use a password there that you use anywhere else. Without a password set, the web interface is not configured at all.

Defence (os-s2fdefense)

Menu: Firewall ▸ AIMdefense

Blocks connections based on origin lists. The overview page shows a map and, next to it, a breakdown of blocked addresses, networks and countries.

You maintain your own block and exception lists. Which lists are available depends on your licensed scope.

Note

Entries of your own lists can only be added and removed in the interface, not disabled individually and temporarily.