Custom RPZ Blacklist Insertion
18 min
the import rpz lists service allows the importation of custom rpz lists onto the dns proxy file variation checking and possible importation are performed every 30 minutes to manage the service, access the admin panel at a advanced configuration » \[z] import rpz lists it is advisable to block proxy & bypass filters on the cloud panel for the proper functioning of rpz policies initial configuration access the import rpz list menu enable the service by typing y and pressing enter on the next screen, type y and press enter to create the fsupload user on the next screen, type y and press enter to proceed with entering the password for the fsupload user it is always possible to change the password from the change fsupload password menu how to import an rpz list to import an rpz list, it is necessary to use an sftp client sftp access parameters standard access mode connect with any sftp client using the listed parameters and the password chosen during configuration ssh key access mode enable the access mode from the change configuration menu and insert the ssh keys of the machines authorized to access via the manage ssh keys » add key menu supported list formats the following formats are supported standard rpz zone file domain list standard rpz zone file standard rpz file with policy triggers and policy actions rpz zone example domain list it is possible to import a list of domains to block and define the policies of the list the policy definition must be inserted on the first line respecting the following format variable definition block type indicates the block type, insert one of these values block the domain is blocked with a not existent domain error send to ip the domain is resolved with the ip indicated in destination send to domain the domain is resolved with the domain indicated in destination destination mandatory if block type is send to ip or send to domain, indicates the ip or domain it must resolve to example file with resolution to the example com domain rpz insertion into the configuration access the machine via sftp with the fsupload user access the fsupload/rpz/ folder upload the file with the load extension wait for the procedure timing or, to execute the import immediately, access the check rpz lists now menu rpz removal from the configuration access the machine via sftp with the fsupload user access the fsupload/rpz/ folder remove the file with the db extension wait for the procedure timing or, to execute the removal immediately, access the check rpz lists now menu import error check access the machine via sftp access the fsupload/rpz/ folder download the file with the error extension and remove it from the folder open the file with a text editor and scroll to the end of the file to verify the error correct the file and retry the rpz insertion into the configuration list import example the example below shows the import of an rpz file using the sftp command, available on both windows and linux, in ssh key access mode note upon first access, authorization to access is requested, type yes and press enter import rpz list menu disable service / enable service access the menu to deactivate or activate the rpz import service disable service access the \[d] disable service menu type y and press enter to confirm the deactivation enable service access the main import rpz lists menu type y and press enter to confirm the activation note if the fsupload user was not present, it will be created and configured change configuration enable access via public ssh key access the \[c] change configuration menu type y and press enter to prepare access type y and press enter to immediately manage the enabled ssh keys, or type n and press enter to return to the import rpz lists menu it is possible to manage the enabled ssh keys from the menu manage ssh keys through this menu, it is possible to manage the ssh keys authorized to access access the \[m] manage ssh keys menu view authorized keys access the \[v] view authorized keys menu if there are multiple ssh keys, the system divides the display into blocks, press the spacebar to view the next block add key access the \[a] add key menu enter an identification name for the key and press enter, only letters, numbers, and the character are allowed this name will be used for the deletion of the key insert/copy the ssh key of the machine authorized to access and press enter delete key to delete an ssh key, it is necessary to know the identification name given to the key during insertion if you do not remember the name, it is possible to view it via the manage ssh keys » view authorized keys menu access the \[d] delete single key menu enter the identification name of the key to be deleted and press enter clear all keys through this menu, all ssh keys will be deleted access the \[c] clear all keys menu type y and press enter to confirm the deletion change fsupload password access the \[p] change fsupload password menu type y and press enter to proceed with entering the password for the fsupload user check rpz lists now the checking of the lists to import is performed automatically every 30 minutes; if execution is necessary, access this menu access the \[i] check rpz lists now menu type y and press enter to confirm the check at the end, the system will show the current import status view rpz lists import status access the \[s] view rpz lists import status menu type y and press enter to confirm legend last check/last import » last check performed last check indicates that the check was performed but no variations were present last import indicates that the check was performed and variations were applied loaded » rpz lists successfully loaded into the configuration file with a db extension to be parsed » rpz lists to be checked by the system file with a load extension to be removed » rpz lists to be removed, they are loaded in the configuration but the db files are no longer present in the folder error » rpz lists that were checked but generated an error and were not loaded in the configuration file with a error extension
