Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesIf a gateway is listed as offline, but the WAN is actually up, several things could be at fault: First, test to see if the monitor IP address responds to a ping from a client device on the LAN, and again from Diagnostics
This is a complex topic and most users gloss over it and guess a sufficiently high value.
Depending on how the Active Directory groups were made, the way they are specified may be different for things like Authentication Containers and/or Extended Query. For example, a traditional user group in AD is exposed
On occasion these issues can be caused by other factors that lead to asymmetric routing, such as issues with route-to or reply-to , both having to do with gateways on interface settings. Defining gateways under System >
Certain versions of Safari on iOS do not properly handle the login form for the Captive Portal page. The most common resolution is to disable autofill for forms in Safari on iOS. In some cases, Apple devices will not aut
Blocked packets are also common for legitimate-looking traffic where routed networks and/or Multi-WAN are involved when Asymmetric Routing or other related causes are present in the network.
If reply traffic such as TCP:A, TCP:SA, or TCP:RA is shown as blocked in the logs, the problem could be asymmetric routing. See Troubleshooting Asymmetric Routing for more info.
Authentication failures are normally the result of users entering an incorrect username or password. In the case of RADIUS authentication, these can occur because of connectivity problems to the configured RADIUS server(
The Bypass firewall rules for traffic on the same interface option located under System > Advanced on the Fire- wall/NAT tab activates rules for traffic to/from the static route networks which are much more permissive wh
If Anonymous binds are not being used, the username supplied can be the short name (e.g. DOMAIN\User for AD) or a full LDAP specification for a user (e.g. CN=administrator,CN=Users,DC=example,DC=com). Tip: If the full DN
Bittorrent is known for not using standard ports. Clients are allowed to declare which port other clients use to reach them, which means chaos for network administrators trying to track the traffic based on port alone. C
After the installation completes and the firewall restarts, there are conditions which may prevent the operating system from fully booting. The most common reasons are typically BIOS-related. For example, a BIOS implemen
Due to the wide array of hardware combinations in use, it is not uncommon for a memstick or CD to boot incorrectly (or not at all). Given the unpredictable nature of commodity hardware support, using hardware from the Ne
This will happen if the secondary cannot see the CARP advertisements from the primary. Check for firewall rules, connectivity trouble, switch configurations. Also check the system logs for any relevant errors that may le
Check that firewall rules have been added to the external interface where the L2TP traffic enters the firewall. Also make sure the client is connecting to the interface IP address chosen on the L2TP settings.
If an SSL/TLS site-to-site tunnel is used and all of the routes appear correct but traffic still cannot flow properly, check the tunnel network size. If this is a site-to-site setup between only two locations, the tunnel
If clients are not being redirected to the portal page when attempting to browse on an interface with captive portal enabled, it’s most always one of the following causes: DNS resolution not functioning Clients on the ca
Captive Portal uses ipfw under the hood. ipfw is a program performing packet filtering. When having issues with the captive portal, it is possible to list ipfw rules for debugging. To list all ipfw rules, which includes
If a VPN connection does not establish, or does establish but does not pass traffic, check the firewall logs under Status System Logs on the Firewall tab. If traffic for the tunnel itself is being blocked, such as traffi
The first place to look is Status > OpenVPN . The connection status for each VPN is shown there. If a VPN is connected, waiting, reconnecting, etc, it would be indicated on that screen. For more information,
Before spending any time diagnosing an issue, double and triple check the antenna connection. If it is a screw-on type, ensure it is fully tightened. For mini-PCI cards, ensure the pigtail connectors are properly connect
The first step when troubleshooting suspected blocked traffic is to check the firewall logs ( Status > System Logs , on the Firewall tab). By default AZTCO-FW will log all dropped traffic and will not log any passed tra
Browse to Status > System Logs and click the OpenVPN tab to view the OpenVPN logs. Upon connecting, OpenVPN will log messages similar to the following example: openvpn[32194]: UDPv4 link remote: 1.2.3.4:1194 openvpn[3219
Attempt a connection and immediately check the state table at Diagnostics > States and filter on the source or desti- nation to see if a state exists. If a state table entry is present, the firewall has passed the traffi