AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Troubleshooting

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

28 subcategories

Articles

198 results

KVM+QEMU Issues

Be sure to use e1000 NICs (em(4)), not the ed(4) NICs or CARP VIPs will never leave init state.

L2TP Traffic Blocked Outbound

In some cases, such as when combined with IPsec, L2TP traffic may also require special handling via floating rules. This appears as blocked traffic in the outbound direction in the firewall logs, showing an L2TP server i

LAN Interface

Check that the LAN IP address is correct ( Interfaces > LAN ) Using an invalid IP address (e.g. .0 or .255 in a /24) will cause problems reaching addresses locally and will not work properly. Check that the LAN subnet ma

Last Resort

If nothing else works then a reinstall will eliminate any possibility of problems related to the upgrade itself. AZTCO-FW software supports multiple options to easily restore the configuration. The fastest method is Reco

Load balancing not working

Check that the Gateway Group is properly configured for load balancing, with at least two gateways on the same tier. Check that the firewall rules being matched direct traffic to the correct load balancing gateway group.

Manual Fix

The same rules may be created manually by adding one on the affected interface tab (e.g. LAN), and a second rule on the Floating tab using the same interface (LAN again) to match the traffic in the out direction. The rul

MD5 Signature Mismatch

Periodically, Sourcefire redesigns their site or updates the engine and rules, and the snort package needs an update  to accommodate this change. Removing and then installing the snort package again is required to restor

Miscellaneous Additional Areas

If Captive Portal is enabled, temporarily disable it ( Services > Captive Portal ). Check for packages such as Squid that might interfere, disable them if necessary Improperly configured proxies would allow certain traff

MTU Issues

Issues with upload speed frequently end up being issues with the MTU. If the MTU on AZTCO-FW software (default 1500), is higher than the MTU of the upstream link, it can result in packets being fragmented, lost, or other

NAT Confusion

When crafting rules for firewalls involving inbound NAT connections, remember to use the private IP address as the Destination. This applies for port forwards as well as 1:1 NAT

NAT Reflection Troubleshooting

NAT Reflection is complex, and as such may not work in some advanced scenarios. We recommend using Split DNS instead in most cases. However, NAT Reflection on current AZTCO-FW releases works reasonably well for nearly

New Rules Are Not Applied

If a new rule does not appear to apply, there are a couple possible explanations. First, If the rule is a block rule and there is a state table entry, the open connection will not be cut off. See Check the State Table .

Non-Fatal Errors

CF NID Not Found Error Some newer Compact Flash cards are giving users trouble, in particular the Sandisk 4GB 30MB/s cards seem to be problematic. ad0: FAILURE – READ status=51<READY,DSC,ERROR> error=10<NID_NOT_FOUND> LB

Other Causes

There are other pitfalls in firewall rules, NAT, routing, and network design that can interfere with connectivity. See Troubleshooting Network Connectivity for more suggestions.

Other Errors

The following errors have been observed on certain hardware platforms running AZTCO-FW While they do not appear to be fatal, the cause appears to be a disk driver issue in FreeBSD (9.2 and later) and it may degrade perfo

Other Switch and Layer 2 Issues

If the units are plugged into separate switches, ensure that the switches are properly trunking and passing broad- cast/multicast traffic. Some switches have broadcast/multicast filtering, limiting, or “storm control” fe

Outbound NAT

Check Outbound NAT , ensure it is set for Automatic Outbound NAT unless Manual is required ( Firewall > NAT , Outbound tab) Incorrect NAT settings will prevent traffic from reaching WAN Check Manual Outbound NAT rules, i

Outbound NAT Troubleshooting

When manual outbound NAT is enabled and there are multiple local subnets, an outbound NAT entry is required for each. This applies especially if traffic must exit with NAT after coming into the AZTCO-FW router via a VPN

Ping works by IP address, but web browsing fails

In this case, the most likely cause is DNS. If the firewall DNS settings do not match those in Interface and DNS Configuration, clients may not be able to resolve DNS when a WAN is down. Review the settings and fix any p

pkg.AZTCO-FW.org Has no A/AAAA Record

pkg does not use A/AAAA records. It uses service (SRV) records. The update server meta names such as pkg. AZTCO-FW.org are not meant to be accessed directly using a browser. To find the actual update servers, lookup the

Policy routing does not work for web traffic or all traffic

When a proxy package that can transparently capture HTTP traffic is used, such as squid, it overrides any policy routes that are defined for client traffic on that port. So no matter which gateway is set in firewall rule

Port Forward pass action

When creating a port forward, the pass action will bypass firewall rules and pass the traffic directly through without filtering. Change the setting to create an associated rule and then arrange the block rule above the

Port Forward Troubleshooting

Port Forwards in particular can be tricky, since there are many things to go wrong, many of which could be in the client configuration and not AZTCO-FW. Most issues encountered by users have been solved by one or more of

Port Forwards Behind Portal Only Work When Target Logs In

This is a side effect of how the portal operates. No traffic is allowed to reach a host behind the portal unless it has been authenticated or passed through the portal. If a port forward must always work to a device behi

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.