Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesBe sure to use e1000 NICs (em(4)), not the ed(4) NICs or CARP VIPs will never leave init state.
In some cases, such as when combined with IPsec, L2TP traffic may also require special handling via floating rules. This appears as blocked traffic in the outbound direction in the firewall logs, showing an L2TP server i
Check that the LAN IP address is correct ( Interfaces > LAN ) Using an invalid IP address (e.g. .0 or .255 in a /24) will cause problems reaching addresses locally and will not work properly. Check that the LAN subnet ma
If nothing else works then a reinstall will eliminate any possibility of problems related to the upgrade itself. AZTCO-FW software supports multiple options to easily restore the configuration. The fastest method is Reco
Check that the Gateway Group is properly configured for load balancing, with at least two gateways on the same tier. Check that the firewall rules being matched direct traffic to the correct load balancing gateway group.
The same rules may be created manually by adding one on the affected interface tab (e.g. LAN), and a second rule on the Floating tab using the same interface (LAN again) to match the traffic in the out direction. The rul
Periodically, Sourcefire redesigns their site or updates the engine and rules, and the snort package needs an update to accommodate this change. Removing and then installing the snort package again is required to restor
If Captive Portal is enabled, temporarily disable it ( Services > Captive Portal ). Check for packages such as Squid that might interfere, disable them if necessary Improperly configured proxies would allow certain traff
Issues with upload speed frequently end up being issues with the MTU. If the MTU on AZTCO-FW software (default 1500), is higher than the MTU of the upstream link, it can result in packets being fragmented, lost, or other
When crafting rules for firewalls involving inbound NAT connections, remember to use the private IP address as the Destination. This applies for port forwards as well as 1:1 NAT
NAT Reflection is complex, and as such may not work in some advanced scenarios. We recommend using Split DNS instead in most cases. However, NAT Reflection on current AZTCO-FW releases works reasonably well for nearly
If a new rule does not appear to apply, there are a couple possible explanations. First, If the rule is a block rule and there is a state table entry, the open connection will not be cut off. See Check the State Table .
CF NID Not Found Error Some newer Compact Flash cards are giving users trouble, in particular the Sandisk 4GB 30MB/s cards seem to be problematic. ad0: FAILURE – READ status=51<READY,DSC,ERROR> error=10<NID_NOT_FOUND> LB
There are other pitfalls in firewall rules, NAT, routing, and network design that can interfere with connectivity. See Troubleshooting Network Connectivity for more suggestions.
The following errors have been observed on certain hardware platforms running AZTCO-FW While they do not appear to be fatal, the cause appears to be a disk driver issue in FreeBSD (9.2 and later) and it may degrade perfo
If the units are plugged into separate switches, ensure that the switches are properly trunking and passing broad- cast/multicast traffic. Some switches have broadcast/multicast filtering, limiting, or “storm control” fe
Check Outbound NAT , ensure it is set for Automatic Outbound NAT unless Manual is required ( Firewall > NAT , Outbound tab) Incorrect NAT settings will prevent traffic from reaching WAN Check Manual Outbound NAT rules, i
When manual outbound NAT is enabled and there are multiple local subnets, an outbound NAT entry is required for each. This applies especially if traffic must exit with NAT after coming into the AZTCO-FW router via a VPN
In this case, the most likely cause is DNS. If the firewall DNS settings do not match those in Interface and DNS Configuration, clients may not be able to resolve DNS when a WAN is down. Review the settings and fix any p
pkg does not use A/AAAA records. It uses service (SRV) records. The update server meta names such as pkg. AZTCO-FW.org are not meant to be accessed directly using a browser. To find the actual update servers, lookup the
When a proxy package that can transparently capture HTTP traffic is used, such as squid, it overrides any policy routes that are defined for client traffic on that port. So no matter which gateway is set in firewall rule
When creating a port forward, the pass action will bypass firewall rules and pass the traffic directly through without filtering. Change the setting to create an associated rule and then arrange the block rule above the
Port Forwards in particular can be tricky, since there are many things to go wrong, many of which could be in the client configuration and not AZTCO-FW. Most issues encountered by users have been solved by one or more of
This is a side effect of how the portal operates. No traffic is allowed to reach a host behind the portal unless it has been authenticated or passed through the portal. If a port forward must always work to a device behi