Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesBrowse to Diagnostics > Routes and review the routes known by the firewall. For site-to-site VPNs, routes will be present for the remote network(s) to the appropriate tun or tap interface. If the routes are missing or in
The status of connected wireless clients and nearby access points can be viewed by navigating to Status > Wireless . This menu option only appears when a wireless interface is present and enabled. On this page, click Res
Resetting the cache in squid can often clear up issues without performing a more complicated procedure. Before performing a full reset, try clearing and resetting the cache: mv /var/squid/cache /var/squid/cache.old squid
If the GUI update is not functioning as expected, there are a handful of shell commands that can help gather information or resolve problems. Force pkg Metadata Update Often times DNS or connectivity problems will preven
The DNS cache on a Windows PC may be cleaned from a command prompt or Start > Run : ipconfig /flushdns This may need to be executed from an Administrator command prompt on Windows Vista and later. Other operating systems
When configuring a site-to-site PKI OpenVPN setup, an iroute statement must be configured using the Remote Network fields on the Client Specific Overrides entry set for the common name of the client certificate. First, e
Test if the client can ping the LAN IP of the firewall If this fails, check the LAN rules, client IP/subnet mask, LAN IP/subnet mask, etc. Test if the client can ping the WAN IP of the firewall If this fails, check the c
The slowness may not be from any cause on the firewall. It could be the client itself or how it connects. Testing a 100Mbit/s WAN over 802.11g wireless, for example, would never show full speed. Testing a 300Mbit/s WAN f
In a clustered environment, traffic arriving via the primary and leaving an internal interface can appear to be blocked on the secondary if the destination is a broadcast or multicast address like those used for Microsof
There are several common misconfigurations that happen which prevent HA from working properly. Incorrect Interface Order The interface assignment order and internal identifiers must match identically on both nodes. If th
NAT and firewall rules not correctly added (see Port Forwards ) Tip: Do NOT set a source portFirewall enabled on client machine 2. Firewall enabled on client machine 3. Client machine is not using AZTCO-FW as its default
What happens in most cases is this: Client sends a TCP SYN packet, which arrives to AZTCO-FW software and gets a state table entry AZTCO-FW softwaresends back an ICMP redirect letting the client know to reach the target
When troubleshooting squid/squidGuard there are some procedures that may be followed to ensure things are com- pletely reset. Remove the packages from System > Packages on the Installed Packages tab in the proper order:
Double check the following items when problems with configuration synchronization are encountered: The username must be admin on all nodes. The password in the configuration synchronization settings on the primary must m
Ensure firewall rules have been added to the L2TP VPN interface . Also ensure the remote subnet across the VPN is different from the local subnet. It is not possible to reach a 192.168.1.0/24 network across the VPN when
If the IPsec layer appears to complete, but no L2TP traffic passes, it is likely a known incompatibility between Win- dows and the strongSwan daemon used on AZTCO-FW. There is currently no known workaround except to move
IPsec does not gracefully handle fragmented packets. Many of these issues have been resolved over the years, but there may be some lingering problems. If hangs or packet loss are seen only when using specific protocols (
Make sure that the LDAP server is listening on the expected port, and that connectivity to the LDAP server’s network is functional. Performing a packet capture filtered on the LDAP server’s IP address and port will help
By far the most troublesome connection issues people have are with LDAP+SSL (ldaps) because it is so secure in how it operates. Hostname Required When connecting to LDAP with SSL, the hostname given for the server is als
If cosmetic problems occur after performing an upgrade, this is nearly always due to stale browser cache entries for CSS, JavaScript, or other files where the browser does not pull the updated version. Force a refresh of
Check connectivity from the firewall itself: Try to ping 8.8.8.8 ( Diagnostics > Ping ) If this does not work, ensure proper WAN settings, gateway, etc. Check DNS: Try to lookup pfsense.org ( Diagnostics > DNS Lookup ) I
If the FTP proxy must be disabled, this may be done by visiting System > Advanced , on the System Tunables tab, then set debug.pfftpproxy=1 . Set it to 0 again to enable the proxy.
The swap.state from Squid file can grow large and consume all available drive space
First, ensure the base DN and similar settings match those configured on the LDAP server. Check the LDAP server for more information. For Base DN , it’s typical to use the root of the LDAP tree but typically Entire Subtr