AIMdefense Plugins
AIMdefense ships its own add-on modules that go beyond the base installation. This chapter describes what they do, where to find them in the user interface, and what you should know when running them.
All modules described here carry package names starting with os-s2f.
They are managed under System ▸ Firmware ▸ AIMdefense AppStore.
Connecting to the central platform
COD Registration (os-s2fcod)
Menu: Lobby ▸ COD Registration
The Central Operations Dashboard, COD for short, is the central management system for a fleet of AIMdefense firewalls. Before COD can manage a firewall, that firewall has to register with it. That is what this module does.
Registration has three steps. You sign in with your COD account, you pick a tenant and a location, and you submit the firewall for approval.
In doing so the firewall hands COD an API key and secret generated on the firewall itself. COD uses those credentials to access the firewall afterwards. The secret is shown exactly once and is not stored on the page.
Settings
Field |
Meaning |
|---|---|
COD URL |
Base address of your COD instance. If the scheme is missing,
|
Firewall IP / FQDN |
The address COD uses to reach this firewall. Detected automatically on first load, in the order WAN, LAN, first interface with an IPv4 address. A value you set yourself is never overwritten. |
Firewall Port |
Port of the firewall API. Default 443. |
User |
The local firewall user the API key belongs to. |
API Key / Secret |
Credentials for COD. Can be regenerated with Generate new key. |
Username / Password / OTP |
Credentials of your COD account. The one-time code is only required if it is enabled for that account. |
Tenant / Location |
Tenant and location. These appear only after a successful sign-in. |
What you should know
Note
The page has no save button. Address, port and COD URL are only stored permanently on a successful registration. Aborting halfway through leaves nothing behind.
Note
Your COD account needs permission to create a firewall in the target location. Without it, registration fails even though sign-in worked. If COD returns no locations, the registration area stays hidden.
Warning
The certificate of the COD instance is not verified. This is deliberate, because COD is usually operated by the customer and often uses a private or self-signed certificate. Run the connection on a network you trust.
The COD session lasts about 15 minutes. Once it expires you have to sign in again, with a fresh one-time code if that is enabled.
If COD does not offer the required interface, sign-in aborts with a note that COD and AIMdefense need compatible versions.
The firewall identifies itself by its serial number. If no usable serial number is available, the system UUID is used, and failing that the host name.
Event reporting to COD
After registration the firewall reports events to COD on its own: failover switches, configuration changes and gateway alarms. Which of these are monitored is set by the location in COD. Reporting errors are written to the system log and otherwise discarded, firewall operation is not affected.
License administration (os-s2flic)
Menu: Lobby ▸ AIMdefense License
This is where you register your AIMdefense and manage the license. Both registration with a license key and trial registration are available.
On registration the firewall transmits hardware details, the license key and a machine identifier. The check then runs regularly in the background.
Note
Registration additionally triggers an expansion of the file system, provided unused space is available on the storage device. This is intended and makes sure a device uses its full storage after commissioning.
Software sources and app store
Package sources (os-s2frepo)
Menu: System ▸ Firmware ▸ AIMdefense Repository
This is where you set which source the firewall uses for packages and updates.
Note
Only the production source is supported for productive use. Other sources are meant for testing.
The configured source is checked periodically in the background and restored if needed.
App store (os-s2fappstore)
Menu: System ▸ Firmware ▸ AIMdefense AppStore
The app store shows the available add-on modules as tiles, grouped into tabs by topic. This is where you install and remove modules.
Note
Not every system sees the same tiles. Only what matches the hardware present and the licensed scope is shown. If no tile in a topic matches, the whole tab disappears. If you are missing a module, check your license first.
The progress of an installation is written to an output field.
Base module and system tools
Base module (os-s2fbase)
The base module carries the AIMdefense branding of the interface and makes sure the AIMdefense modules are added on existing devices. It has a menu entry of its own at the very bottom of the menu.
Environment (os-s2fenv)
Menu: System ▸ Settings ▸ AIMdefense Environment
This is where you store environment settings, among them a proxy server for outgoing connections.
Note
Address and port of the proxy belong together. Either you fill in both fields or you leave both empty.
Toolkit (os-s2ftools)
The toolkit contains command line scripts, mainly for expanding the file system. It has no interface of its own.
Danger
These scripts change the partitioning. They ask for confirmation and abort if the preconditions are not met. Take a backup first.
Connecting to other systems
Unifi controller (os-s2funifi)
Menu: Wireless ▸ Unifi ▸ Controller
Runs a Unifi controller directly on the firewall. This lets you manage your access points without setting up an additional server.
Host routing (os-s2fhostroute)
Allows routes to individual hosts instead of whole networks only. The module has no interface of its own, it extends the existing route management.
Mail and defence
Fetchmail (os-s2ffetchmail)
Menu: Services ▸ AIMdefense Fetchmail
Collects messages from remote mailboxes and delivers them locally. For each mailbox you create an entry with server, credentials and target recipient. There is a dedicated log view.
rspamd (os-s2frspamd)
Menu: Services ▸ AIMdefense Rspamd
Checks messages for unwanted mail. Besides the settings there is a statistics view and a learning function.
Warning
The password of the rspamd web interface is stored in clear text in the configuration. Do not use a password there that you use anywhere else. Without a password set, the web interface is not configured at all.
Defence (os-s2fdefense)
Menu: Firewall ▸ AIMdefense
Blocks connections based on origin lists. The overview page shows a map and, next to it, a breakdown of blocked addresses, networks and countries.
You maintain your own block and exception lists. Which lists are available depends on your licensed scope.
Note
Entries of your own lists can only be added and removed in the interface, not disabled individually and temporarily.