You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs: port hotspot retention, setup command, DHCP ranges and geoblocking docs
Backport content from upstream commits that landed on main and the
nethsecurity-8.8 branch after this repo's Sphinx-to-Docusaurus migration
diverged, so the new docs stay in sync with upstream additions.
Assisted-by: Claude Code:claude-sonnet-5
Copy file name to clipboardExpand all lines: docs/administrator-manual/installation/install.mdx
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -73,6 +73,8 @@ You can use the downloaded image as a virtual machine disk:
73
73
74
74
If you wish to save the logs locally, it is recommended to attach an additional virtual hard drive to the virtual machine and select it as the destination for logs in the `Storage` page under the `System` section.
75
75
76
+
If you are deploying a remote virtual machine on a cloud provider, you can also complete the network configuration over the virtual monitor with the [`setup` command](./remote_access.md#setup-command-section) as a quick start. This is often the fastest way to configure the keyboard layout and network interfaces before opening the web user interface.
Copy file name to clipboardExpand all lines: docs/administrator-manual/installation/remote_access.md
+23-14Lines changed: 23 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -180,30 +180,39 @@ From a Linux machine, use the following command: :
180
180
ssh root@192.168.1.1
181
181
```
182
182
183
-
## VGA console and keyboard layout
183
+
## Using the setup command {#setup-command-section}
184
184
185
-
If the machine has a VGA/DVI/HDMI video port, connect a monitor to it. Then, you will be able to log in to the console using the default credentials above.
185
+
If the machine has a VGA/DVI/HDMI video port, connect a monitor to it. You can then use the `setup` command from the console to perform the first configuration steps.
186
186
187
-
Please note that the system is configured with the US keyboard layout.
187
+
Use `setup` when the web user interface is not yet reachable, or when you are working from VGA, serial console, or SSH on a new firewall.
188
188
189
-
To temporarily change the current keyboard layout to Italian, log in to the system and then execute the following command: :
189
+
Run the tool as `root`:
190
190
191
191
```bash
192
-
loadkmap < /usr/share/keymaps/it.map.bin
192
+
setup
193
193
```
194
194
195
-
The keyboard layout configuration can be saved by writing the keymap code inside `/etc/keymap`. Example for `it` (Italian) keymap: :
To obtain the list of available keymaps, execute the following command: :
200
+
### Keyboard layout
203
201
204
-
```bash
205
-
ls -1 /usr/share/keymaps/ | cut -d'.' -f1
206
-
```
202
+
The system starts with the US keyboard layout. In the `setup` menu, choose the `keymap` item to switch between the available layouts. The tool currently supports `us` and `it` keymaps.
203
+
204
+
The selected keymap is applied immediately and saved automatically, so it remains active after reboot. It's also preserved inside the backup to be restored in case of system recovery or upgrade.
205
+
206
+
### Network settings
207
+
208
+
The `setup` tool allows you to configure the following network settings:
209
+
210
+
- LAN interface: DHCP or static IP address with netmask in CIDR notation
211
+
- WAN interface: DHCP or static IP address with netmask in CIDR notation and gateway
212
+
213
+
After making changes, the network configuration must be applied with the `Apply network changes` button in the network section.
214
+
215
+
If you are using a non-US keyboard layout, you can change it in the setup tool before entering the network configuration. This is important because the network configuration requires typing IP addresses and other information that may be affected by the keyboard layout.
Copy file name to clipboardExpand all lines: docs/administrator-manual/network/dns_dhcp.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -36,6 +36,8 @@ Available fields:
36
36
-`Range IP end` : last IP address of DHCP range
37
37
-`Lease time` : lease time (default 1 hour)
38
38
39
+
Each DHCP server can serve more than one address range: under `IP ranges` you can specify multiple distinct IP ranges for the same interface, each one defined by its own `Range IP start` and `Range IP end`. Click **Add IP range** to define an additional range, or use the trash icon next to a range to remove it. At least one range must be specified, while the others are optional. Each range must belong to the interface network class, and the `Range IP end` must be higher than the `Range IP start`. Ranges are allowed to overlap.
Then repeat the steps 2 and 3 in the previous section to apply the changes.
123
+
124
+
## Data retention for Hotspot service with NethSpot cloud portal
125
+
126
+
:::note
127
+
128
+
NethSpot cloud portal users only
129
+
130
+
This section applies only to NethSecurity firewalls with a valid subscription that are specifically using the NethSpot cloud portal, available at <https://my.nethspot.com/>. If the Hotspot service is used without the NethSpot cloud portal, the information in this section does not apply.
131
+
132
+
:::
133
+
134
+
NethSpot stores hotspot-related data on cloud infrastructure located in a European data center in the Netherlands. The retained data includes connection logs, guest login data, voucher information, email-based access data, and SMS-based access data.
135
+
136
+
### Connection logs
137
+
138
+
Connection logs are retained for **6 months**.
139
+
140
+
These logs include information related to guest sessions, such as:
141
+
142
+
- connection and disconnection date and time
143
+
- guest user
144
+
- guest device
145
+
- device MAC address
146
+
- NethSecurity unit MAC address
147
+
148
+
Connection logs are the first data to be deleted. When the retention period expires, the related guest sessions are deleted, including the `device_mac` of the guest device and the `unit_mac` of the connected NethSecurity appliance.
149
+
150
+
:::note
151
+
152
+
NethSpot does not collect or store the browsing activity of Hotspot users. Visited websites, URLs, DNS queries, or other navigation details are neither collected nor retained by the NethSpot cloud portal. The retained information is limited to session data required to identify the guest access session.
153
+
154
+
:::
155
+
156
+
### Guest login data and vouchers
157
+
158
+
Guest login data is retained for the whole validity period of the guest account and for the following **24 months**. This additional retention period allows expired guest accounts to be reactivated, for example by extending their validity from the portal, without having to recreate them. It also helps preserve the association between the guest identity and the previously issued voucher, so that operators can review or extend an existing access record when needed.
159
+
160
+
This includes data related to platform users, vouchers, email login, and SMS login. When vouchers are used, all the information entered in the voucher is retained, including the data used to identify the guest.
161
+
162
+
For voucher-based access, retained data may include:
163
+
164
+
- guest first name and last name, if entered in the voucher
165
+
- guest email address, if entered in the voucher
166
+
- voucher data
167
+
- MAC address of the device used by the guest
168
+
169
+
The guest name is required when creating a voucher because it is used to identify the association between the guest and the voucher.
170
+
171
+
### Voucher validity and account expiration
172
+
173
+
Vouchers can be created in two ways:
174
+
175
+
- with a fixed expiration date
176
+
- with a duration, counted from the first activation
177
+
178
+
Before the first use, a voucher is inactive. When the voucher is used for the first time, it is associated with the guest using it. From that moment, the voucher and the guest account refer to the same access identity.
179
+
180
+
Administrative hotspot users are not related to guest vouchers.
181
+
182
+
The additional 24-month retention period starts from the voucher expiration date.
183
+
184
+
For example, if a voucher expires on **June 30, 2026** and the guest starts using it before that date, the guest account associated with that voucher expires on **June 30, 2026**. The 24-month retention period starts from that date.
185
+
186
+
This retention period allows the account to be reactivated later, for example by extending its validity from the portal, without deleting the guest data too early.
187
+
188
+
### Contract or service termination
189
+
190
+
If the contract or service is terminated, guest data is deleted according to the same retention periods described above.
191
+
192
+
### Marketing consent
193
+
194
+
NethSpot can be configured to ask WiFi guests for marketing consent through the captive portal. The marketing consent is collected exclusively for the organization using the hotspot, it is **not used by Nethesis** for its own marketing purposes.
195
+
196
+
The guest panel clearly shows which guests have given marketing consent: this allows exporting only the contacts that have explicitly provided consent.
197
+
198
+
Nethesis does not use collected guest contacts for marketing activities and does not sell or transfer this data to third parties.
Copy file name to clipboardExpand all lines: docs/administrator-manual/security/threat_shield_ip.md
+32Lines changed: 32 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -85,6 +85,38 @@ To access and customize the blocklist, navigate to the `Local blocklist` tab in
85
85
86
86
When adding addresses to the local blocklist, ensure you enter them correctly to avoid accidentally blocking legitimate traffic. It\'s also a good practice to include a descriptive comment for each entry to help with future management and auditing of your blocklist.
87
87
88
+
## Geoblocking {#geoblocking-section}
89
+
90
+
The `Geoblocking` tab allows you to block network traffic based on the geographic origin of the IP addresses, relying on country-based IP feeds. This is useful to keep out traffic coming from countries you never expect to interact with.
91
+
92
+
The feature is disabled by default. To enable it, open the `Geoblocking` tab and turn on the `Geo IP Blocking` switch. Threat Shield IP must be enabled for geoblocking to work.
93
+
94
+
Countries are organized into regions (Africa, Americas, Asia, Europe, Oceania and Others), each shown as a card reporting the number of currently blocked countries. Selecting a region displays the list of its countries, where you can:
95
+
96
+
- block or allow individual countries using their checkbox;
97
+
- use the **Block all** and **Allow all** buttons to act on the whole region at once;
98
+
- filter the list by country name or by status (blocked / not blocked).
99
+
100
+
Click **Save** to apply the configuration.
101
+
102
+
:::warning
103
+
104
+
Avoid blocking the regions where your own users are located, otherwise legitimate traffic may be dropped.
105
+
106
+
:::
107
+
108
+
### Blocking direction
109
+
110
+
By default, geoblocking only blocks **incoming** connections, i.e. traffic initiated from the selected countries towards your firewall and networks. Outgoing connections (traffic initiated by your local clients towards hosts in the selected countries) are still allowed.
111
+
112
+
If you also want to block **outgoing** connections to the selected countries, add the `country` feed to the `ban_blockforwardlan` property, which applies the feed to the LAN-forward chain. From the command line:
## Block brute force attacks {#brute_force-section}
89
121
90
122
When Threat Shield IP is enabled, the system automatically starts checking for brute force attack attempts on firewall services. By default, the monitored services include SSH access and the login to NethSecurity UI. The system detects login attempts and automatically blocks IPs that have failed to enter the correct credentials.
0 commit comments