AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Troubleshooting

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

28 subcategories

Articles

198 results

A gateway is incorrectly marked offline

If a gateway is listed as offline, but the WAN is actually up, several things could be at fault: First, test to see if the monitor IP address responds to a ping from a client device on the LAN, and again from Diagnostics

ACK queue bandwidth calculations

This is a complex topic and most users gloss over it and guess a sufficiently high value.

Active Directory Group Membership

Depending on how the Active Directory groups were made, the way they are specified may be different for things like Authentication Containers and/or Extended Query. For example, a traditional user group in AD is exposed

Alternate Causes

On occasion these issues can be caused by other factors that lead to asymmetric routing, such as issues with route-to or reply-to , both having to do with gateways on interface settings. Defining gateways under System >

Apple devices are unable to load the portal page or login

Certain versions of Safari on iOS do not properly handle the login form for the Captive Portal page. The most common resolution is to disable autofill for forms in Safari on iOS. In some cases, Apple devices will not aut

Asymmetric Routing

Blocked packets are also common for legitimate-looking traffic where routed networks and/or Multi-WAN are involved when Asymmetric Routing or other related causes are present in the network.

Asymmetric Routing

If reply traffic such as TCP:A, TCP:SA, or TCP:RA is shown as blocked in the logs, the problem could be asymmetric routing. See Troubleshooting Asymmetric Routing for more info.

Authentication failures

Authentication failures are normally the result of users entering an incorrect username or password. In the case of RADIUS authentication, these can occur because of connectivity problems to the configured RADIUS server(

Automatic Fix

The Bypass firewall rules for traffic on the same interface option located under System > Advanced on the Fire- wall/NAT tab activates rules for traffic to/from the static route networks which are much more permissive wh

Bind Credentials

If Anonymous binds are not being used, the username supplied can be the short name (e.g. DOMAIN\User for AD) or a full LDAP specification for a user (e.g. CN=administrator,CN=Users,DC=example,DC=com). Tip: If the full DN

Bittorrent traffic not using the P2P queue

Bittorrent is known for not using standard ports. Clients are allowed to declare which port other clients use to reach them, which means chaos for network administrators trying to track the traffic based on port alone. C

Boot from hard drive after installation fails

After the installation completes and the firewall restarts, there are conditions which may prevent the operating system from fully booting. The most common reasons are typically BIOS-related. For example, a BIOS implemen

Boot from Install Media Fails

Due to the wide array of hardware combinations in use, it is not uncommon for a memstick or CD to boot incorrectly (or not at all). Given the unpredictable nature of commodity hardware support, using hardware from the Ne

Both Systems Appear as MASTER

This will happen if the secondary cannot see the CARP advertisements from the primary. Check for firewall rules, connectivity trouble, switch configurations. Also check the system logs for any relevant errors that may le

Cannot connect

Check that firewall rules have been added to the external interface where the L2TP traffic enters the firewall. Also make sure the client is connecting to the interface IP address chosen on the L2TP settings.

Cannot route to clients on an SSL/TLS site-to-site tunnel

If an SSL/TLS site-to-site tunnel is used and all of the routes appear correct but traffic still cannot flow properly, check the tunnel network size. If this is a site-to-site setup between only two locations, the tunnel

Captive Portal Does not Redirect

If clients are not being redirected to the portal page when attempting to browse on an interface with captive portal enabled, it’s most always one of the following causes: DNS resolution not functioning Clients on the ca

Captive Portal Rules

Captive Portal uses ipfw under the hood. ipfw is a program performing packet filtering. When having issues with the captive portal, it is possible to list ipfw rules for debugging. To list all ipfw rules, which includes

Check Firewall Log

If a VPN connection does not establish, or does establish but does not pass traffic, check the firewall logs under Status System Logs on the Firewall tab. If traffic for the tunnel itself is being blocked, such as traffi

Check OpenVPN Status

The first place to look is Status > OpenVPN . The connection status for each VPN is shown there. If a VPN is connected, waiting, reconnecting, etc, it would be indicated on that screen. For more information,

Check the Antenna

Before spending any time diagnosing an issue, double and triple check the antenna connection. If it is a screw-on type, ensure it is fully tightened. For mini-PCI cards, ensure the pigtail connectors are properly connect

Check The Firewall Logs

The first step when troubleshooting suspected blocked traffic is to check the firewall logs ( Status > System Logs , on the Firewall tab). By default AZTCO-FW will log all dropped traffic and will not log any passed tra

Check the OpenVPN logs

Browse to Status > System Logs and click the OpenVPN tab to view the OpenVPN logs. Upon connecting, OpenVPN will log messages similar to the following example: openvpn[32194]: UDPv4 link remote: 1.2.3.4:1194 openvpn[3219

Check the State Table

Attempt a connection and immediately check the state table at Diagnostics > States and filter on the source or desti- nation to see if a state exists. If a state table entry is present, the firewall has passed the traffi

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.