Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesTo clear the DNS Forwarder cache, restart the dnsmasq daemon as follows: Click Status > Services Find dnsmasq in the list Click or stop the service using then start again with Restarting the daemon will clear the interna
A duplex mismatch is also possible, though this is more common on circuits 100Mbit/s or less. Some providers are stuck in the stone age and still insist on hard-coding ports on CPEs such as fiber converters at 100Mbit/s
Determine which rule is matching the traffic in question. The hit counters in the rule list can help with this to some degree. By enabling logging on pass rules, the firewall logs will show an individual entry specifical
Because of the way IPsec ties into the FreeBSD kernel, any enabled IPsec connection matching the local and remote subnets that exists when IPsec is enabled (even if it is not up) will cause that traffic to never be route
The most common mistake with Extended Query is that the given directive fails to include both the item to be searched as well as how, such as: memberOf=CN=VPNUsers,CN=Users,DC=example,DC=com Note that in the above exampl
If problems occur when an Internet connection fails, typically it is because the monitor IP address is still answering, so the firewall thinks the connection is still available. Check Status > Gateways to verify. An IP a
The following errors would indicate more serious problems such as a faulty HDD/CF, faulty cable/controller, a faulty CF/SATA/IDE converter, a device out of space, or possibly that DMA needs disabled on that combination o
Check the firewall log for blocked connections from the LAN ( Status > System Logs , Firewall tab) If blocks are observed, check the rule that blocked and adjust rules accordingly ( Firewall > Rules , LAN tab) Check that
Forcing a reinstallation of all packages may resolve problems that otherwise may require a full reinstall. This is not ideal, as a clean install is more likely to have a positive result, but that is not always an option
FTP traffic is identified by the use of port 21. Other ports can be used if they added to a comma-separated list in the system tunable debug.pfftpports (e.g. 21,2121,4559 )
If trouble is encountered reaching CARP VIPs from when dealing with Multi-WAN, double check that a rule is present like the one mentioned in FirewallConfiguration
For troubleshooting there are 2 parts are helpful, depending on the issue: Stats page Syslog logging Stats If health checks have been configured on the servers, the backend will show what servers are up or down. Layer 7
the following suggestions will help resolve general hardware issues. Booting from USB If the boot stops with a mountroot> prompt while booting off the installer image, usually with USB CD/DVD drives, escape to the loader
If a CPU core is fully utilized by interrupts, the network card driver may need tuning. Some cards, such as igb, are able to use more queues for processing packets which will spread the load across multiple cores and res
The below settings are specifically for VMware ESX/ESXi but similar settings may be present on Hyper-V, VirtualBox, and other similar hypervisors. Enable promiscuous mode on the vSwitch Enable MAC Address changes Enable
When importing an existing OpenVPN setup into AZTCO-FW, there is no need to import DH Parameters. DH parameters are not specific to a given setup in the way that certificates or keys are. To put it simply, the DH paramet
There are a few reasons why this error turns up in the system logs, some more worrisome than others. If CARP is not working properly when this error is present, it could be due to a configuration mismatch. Ensure that fo
The first thing to check is that the hardware is capable of pushing the expected amount of traffic. In some cases this is more obvious, such as a newer multi-core server being unable to transfer small amounts of packets,
If the firewall complains that it did not detect an interface link up event during automatic assignment, first make sure that the cable is unplugged and that the interface does not have a link light prior to choosing the
If a wireless interface does not appear in the list of interfaces Interfaces > Assignments there are two possibile issues: If the wireless card is supported, a wireless instance must first be created . Once the instance
The IPsec logs available at Status > System Logs , on the IPsec tab contain a record of the tunnel connection process and some messages from ongoing tunnel maintenance activity. Some typical log entries are listed in thi
Examples presented in this chapter have logs edited for brevity but significant messages remain. Logging for IPsec may be configured to provide more useful information. To configure IPsec logging for diagnosing tunnel is
If IPv6 is configured on the firewall, the AZTCO-FW software will prefer to use it when performing an update. There are cases when a firewall may have broken IPv6 connectivity, however, that contribute to problems updati
If every other factor has been eliminated, test the modem without the firewall involved. If the speed is still low, it may be the ISP to blame, or the Modem/CPE.