AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Troubleshooting

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

28 subcategories

Articles

198 results

DNS Forwarder

To clear the DNS Forwarder cache, restart the dnsmasq daemon as follows: Click Status > Services Find dnsmasq in the list Click or stop the service using then start again with Restarting the daemon will clear the interna

Duplex Mismatch

A duplex mismatch is also possible, though this is more common on circuits 100Mbit/s or less. Some providers are stuck in the stone age and still insist on hard-coding ports on CPEs such as fiber converters at 100Mbit/s

Enable Rule Logging

Determine which rule is matching the traffic in question. The hit counters in the rule list can help with this to some degree. By enabling logging on pass rules, the firewall logs will show an individual entry specifical

Ensure no overlapping IPsec connections

Because of the way IPsec ties into the FreeBSD kernel, any enabled IPsec connection matching the local and remote subnets that exists when IPsec is enabled (even if it is not up) will cause that traffic to never be route

Extended Query

The most common mistake with Extended Query is that the given directive fails to include both the item to be searched as well as how, such as: memberOf=CN=VPNUsers,CN=Users,DC=example,DC=com Note that in the above exampl

Failover not working

If problems occur when an Internet connection fails, typically it is because the monitor IP address is still answering, so the firewall thinks the connection is still available. Check Status > Gateways to verify. An IP a

Fatal Errors

The following errors would indicate more serious problems such as a faulty HDD/CF, faulty cable/controller, a faulty CF/SATA/IDE converter, a device out of space, or possibly that DMA needs disabled on that combination o

Firewall/Rules

Check the firewall log for blocked connections from the LAN ( Status > System Logs , Firewall tab) If blocks are observed, check the rule that blocked and adjust rules accordingly ( Firewall > Rules , LAN tab) Check that

Forced pkg Reinstall

Forcing a reinstallation of all packages may resolve problems that otherwise may require a full reinstall. This is not ideal, as a clean install is more likely to have a positive result, but that is not always an option

FTP Ports

FTP traffic is identified by the use of port 21. Other ports can be used if they added to a comma-separated list in the system tunable debug.pfftpports (e.g. 21,2121,4559 )

HA and Multi-WAN Troubleshooting

If trouble is encountered reaching CARP VIPs from when dealing with Multi-WAN, double check that a rule is present like the one mentioned in FirewallConfiguration

HAProxy Troubleshooting

For troubleshooting there are 2 parts are helpful, depending on the issue: Stats page Syslog logging Stats If health checks have been configured on the servers, the backend will show what servers are up or down. Layer 7

Hardware Troubleshooting

the following suggestions will help resolve general hardware issues. Booting from USB If the boot stops with a mountroot> prompt while booting off the installer image, usually with USB CD/DVD drives, escape to the loader

Hardware/Driver Tuning Required

If a CPU core is fully utilized by interrupts, the network card driver may need tuning. Some cards, such as igb, are able to use more queues for processing packets which will spread the load across multiple cores and res

Hypervisor users (Especially VMware ESX/ESXi)

The below settings are specifically for VMware ESX/ESXi but similar settings may be present on Hyper-V, VirtualBox, and other similar hypervisors. Enable promiscuous mode on the vSwitch Enable MAC Address changes Enable

Importing OpenVPN DH Parameters

When importing an existing OpenVPN setup into AZTCO-FW, there is no need to import DH Parameters. DH parameters are not specific to a given setup in the way that certificates or keys are. To put it simply, the DH paramet

Incorrect Hash Error

There are a few reasons why this error turns up in the system logs, some more worrisome than others. If CARP is not working properly when this error is present, it could be due to a configuration mismatch. Ensure that fo

Insufficient Hardware

The first thing to check is that the hardware is capable of pushing the expected amount of traffic. In some cases this is more obvious, such as a newer multi-core server being unable to transfer small amounts of packets,

Interface link up not detected

If the firewall complains that it did not detect an interface link up event during automatic assignment, first make sure that the cable is unplugged and that the interface does not have a link light prior to choosing the

Interface Unavailable for Assignment

If a wireless interface does not appear in the list of interfaces Interfaces > Assignments there are two possibile issues: If the wireless card is supported, a wireless instance must first be created . Once the instance

IPsec Log Interpretation

The IPsec logs available at Status > System Logs , on the IPsec tab contain a record of the tunnel connection process and some messages from ongoing tunnel maintenance activity. Some typical log entries are listed in thi

IPsec Logging

Examples presented in this chapter have logs edited for brevity but significant messages remain. Logging for IPsec may be configured to provide more useful information. To configure IPsec logging for diagnosing tunnel is

IPv6 Connectivity Problems

If IPv6 is configured on the firewall, the AZTCO-FW software will prefer to use it when performing an update. There are cases when a firewall may have broken IPv6 connectivity, however, that contribute to problems updati

ISP Issues

If every other factor has been eliminated, test the modem without the firewall involved. If the speed is still low, it may be the ISP to blame, or the Modem/CPE.

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.