IPCOP
Overview
If you have not yet registered for the service, you can do so by visiting our registration page. Connect to the control panel by entering the IP address of the IPCOP router in the address bar of any browser. Please note that you must type the address securely using port 8443, for example https://YourIPAddress:8443. Then, log in by entering your administrative credentials.
Enable SSH Access
First, you need to change the DNS used by the IPCOP on the RED Network. To do this, click on the System menu, then open the SSH Access section. Check the SSH Access item and click on the Save button to apply the changes.
Change the Device DNS via SSH
To access the console using the SSH protocol, you can use a terminal emulator software like Putty. Open your SSH client and enter the IP address of the IPCOP GREEN Network inside the host field and 8022 in the Port field. Then click on Open to connect to the console.
Log in with your root credentials and type the command setup. Press the enter key, and a new page with a setup wizard will open. Select the Networking item and click on the Select button.
To check if the DNS addresses have been set correctly, click on Status in the IPCOP web panel, and then open the Network Status menu. Look for the Red DNS configuration item and verify that our cloud IPs are correctly listed.
Navigate to the DNS and Gateway settings item and click on the Select button. Enter the address 185.236.104.104 in the Primary DNS field and 185.236.105.105 in the Secondary DNS field. Click on the Ok button and wait for the network reconfiguration procedure to complete. You can then close your SSH program.
Configure Dynamic DNS Service
At this point, we need to configure IPCOP so that it can authenticate with our cloud servers. Open the Services menu and click on Dynamic DNS. As the service provider, choose dyndns.org.
You absolutely do not need to be registered with the dyndns.org service. Our system will automatically intercept and redirect the update requests directly to themselves.
Click on the Add button to proceed with the service configuration and fill in the fields exactly as follows:
- Enabled: Check the item to enable the service.
- Hostname: Enter any name you like, for example, the word hostname.
- Domain: Enter a domain of your choice, for example domain.com.
- Username: Enter the specific username assigned to your dynamic network inside our dashboard. Do not use your main registration email.
- Password: Enter the specific password assigned to your dynamic network.
Finally, click Update to save the changes.
Configure the DHCP Server
You can now enable the DHCP Server so that it automatically assigns network parameters, including our filtered DNS, to the various internal devices. To configure the DHCP Server, open the Services menu and click on DHCP Server. Fill in the various fields as follows:
- Enabled: Put a checkmark to enable the service.
- Start address: Enter the first IP address in your DHCP range.
- End address: Enter the last IP address of your DHCP range.
- Default lease time mins: Set the DHCP lease time in minutes.
- Primary DNS: Enter the address 185.236.104.104.
- Secondary DNS: Enter the address 185.236.105.105.
Click on the Save button to apply the changes. Alternatively, the DNS of the various devices within the network can be changed manually one by one.
Optional: Deny DNS Changes by Users
It is possible to increase security by denying users the ability to browse unfiltered by manually changing the DNS on their local devices. To do this, proceed as follows:
Open the Firewall menu and click on Firewall. At this point, you need to create rules to block all outbound traffic on port 53 for both TCP and UDP protocols, except for requests directed specifically to our cloud IPs.
Click on the Outgoing Traffic button to create a new rule. Ensure the rule permits traffic where the Destination IP or Net field is set to 185.236.104.104. Then click Save to add the rule.
Create another rule exactly similar to the previous one, but the Destination IP or Net field must be 185.236.105.105.
Finally, you need to create an additional rule with the purpose of blocking all remaining traffic on port 53 for both TCP and UDP. This drop rule must be logically placed to catch traffic that does not match the two specific allow rules above.