Teldat
Overview
To activate the containment filter on Teldat devices, please connect to the control panel by entering the IP address of the Teldat router in your browser. Then, enter your administrative login credentials to access the configuration.
Change the Device DNS
For web filtering to work on your devices, you need to configure the router and replace the current DNS addresses with our cloud servers. To do this, go to the router panel and enter the following configuration:
feature dns
; -- DNS resolver user configuration --
;
server 185.236.104.104
server 185.236.105.105
exitDynamic IP Configuration
Web filtering works perfectly with both dynamic and static IPs. If you have a dynamic IP address, you must configure the Dynamic DNS service directly on the router.
When configuring the DynDNS client on your Teldat device, it is strictly necessary to use the specific username and password assigned to your dynamic network inside our dashboard. Do not use your main account email address. Enter the following configuration, making sure to replace the placeholder tags with your actual data:
feature dns-updater
; -- DNS UPDATER configuration --
;
enable
entry 1 protocol DynDNS system dynamic
entry 1 interface <INTERFACE_WAN>
entry 1 hostname <HOSTNAME>
entry 1 servername members.dyndns.org
entry 1 user <USERNAME> password <PASSWORD>
exitOptional: Deny DNS Changes by Users
You can significantly strengthen your network security by preventing unauthorized user DNS changes. To do this, simply create a new access list for use on the WAN interface to block external DNS resolution, and apply it to your external interface as follows:
network direct-ipl
; -- Generic Direct IP Encapsulation User Configuration --
;
description WAN
ip access-group 100 out
exitOptional: Configure Multiprofile
The advanced Multiprofile feature allows you to create multiple filtering profiles for each client or license and associate them with a single network or IP address. Our Web Filter recognizes the remote network and the specific configuration profile based on the public IP and the destination port used for the DNS request.
For example, if you have the address 1.2.3.4, you can route your traffic using different ports:
- Standard port 53: Used for the default profile.
- Alternative ports: Used for secondary profiles, choosing among 110, 143, 5402, and 5403.
If you want to create two or more profiles for a network with the same IP address, you need to configure a different destination port for each profile.
Enable AFS and Configure NAT
First, you must enable the AFS feature on your Teldat device. Enter these commands:
feature afs
enable
exitThen, you need to change the DNS request originating on port 53 to the new port via NAT. Please note that a port other than 53 must be entered in the PORT_PROFILE2 tag, choosing exclusively from 110, 143, 5402, or 5403. The default port 53 connects directly, so no special NAT configuration is needed for your primary profile.
protocol ip
; -- Internet protocol user configuration --
;
nat
rule 1 out <LAN_INTERFACE_PROFILE2> static
rule 1 translation source tcp 185.236.104.104 <PORT_PROFILE2> 185.236.104.104 53
;
rule 2 out <LAN_INTERFACE_PROFILE2> static
rule 2 translation source udp 185.236.104.104 <PORT_PROFILE2> 185.236.104.104 53
;
rule 3 out <LAN_INTERFACE_PROFILE2> static
rule 3 translation source tcp 185.236.105.105 <PORT_PROFILE2> 185.236.105.105 53
;
rule 4 out <LAN_INTERFACE_PROFILE2> static
rule 4 translation source udp 185.236.105.105 <PORT_PROFILE2> 185.236.105.105 53
;
exit
;
exit
;
feature dns-updater
no cache enable
exitFull Configuration Example
Here is a complete example of configuring the web filter with MultiProfile and Dynamic DNS in Teldat, so that only the designated DNS servers can be used on the network:
;
;
user admin hash-password 3A574FAF7E28F15516BEB5C876D8B5BC
global-profiles dial
; -- Dial Profiles Configuration --
;
profile INTERNET default
profile INTERNET dialout
profile INTERNET 3gpp-apn movistar.es
exit
;
network cellular1/0
; -- Interface AT. Configuration --
;
pin ciphered 0xBE35DF12FBFA1154
network mode automatic
network domain cstps
exit
;
network direct-ipl
; -- Generic Direct IP Encapsulation User Configuration --
;
description WAN
ip access-group 100 out
ip address dhcp-negotiated
exit
;
base-interface
; -- Base Interface Configuration --
;
base-interface cellular1/1 link
base-interface cellular1/1 profile INTERNET
exit
;
direct-ip
; -- Direct IP encapsulator user configuration --
;
address dhcp
authentication sent-user MOVISTAR ciphered-pwd 0xD2650CEF62FBEF55D3AC337DA700103F
exit
;
network ethernet0/0.16
; -- Ethernet Subinterface Configuration --
;
description VLAN 16
ip address 172.16.0.1 255.255.0.0
encapsulation dot1q 16
exit
;
protocol ip
; -- Internet protocol user configuration --
;
nat
rule 4 translation source udp 185.236.105.105 5403 185.236.105.105 53
rule 10 out direct-ipl dynamic overload
rule 10 translation source interface direct-ipl
exit
exit
;
;
feature dns
; -- DNS resolver user configuration --
;
no cache enable
server 185.236.104.104
server 185.236.105.105
exit
;
feature dns-updater
; -- DNS UPDATER configuration --
;
enable
entry 1 protocol DynDNS system dynamic
entry 1 interface direct-ipl
entry 1 hostname ejemplo
entry 1 servername members.dyndns.org
entry 1 user ejemplo username ciphered-pwd 0x5E8102555EDEC919914FD3E6D9AD48CD
exit
;
dump-command-errors