Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesIn some cases, this is may happen normally for a short period after a system comes back online. However, certain hardware failures or other error conditions can cause a server to silently take on a high advskew of 240 in
If pkg is unable to update and complains about the repository metadata version, the pkg utility may need to be updated manually to version 1.13.x or later. Example metadata version error: > >> Updating repositories metad
Firewall rules are generally processed as follows: Floating Rules Interface Group rules Interface tab rules If a floating rule with quick checked passed the traffic, then a block rule on an interface would have no chance
Edit the rule in question and review the parameters for each field. For TCP and UDP traffic, remember the source port is almost never the same as the destination port, and should usually be set to any . If the default de
In some cases the repository information may need to be rewritten: Navigate to System > UpdatesSet the Branch to Latest Development Snapshots Wait for the page to refreshSet the Branch to Latest stable version If the upd
Depending on the VPN being used, a route may not display in the table for the far side. IPsec does not use the routing table, it is instead handled internally in the kernel using IPsec security policy database (SPD) entr
When attempting to use the Local Network setting or a push statement to push routes to a client, and the client isn’t receiving them properly, a couple things could be happening: Check that an SSL/TLS server setup is use
Ensure rules are on the correct interface to function as intended. Traffic is filtered only by the ruleset configured on the interface where the traffic is initiated . Traffic coming from a system on the LAN destined for
If problems are encountered with FTP, check the rules to/from FTP devices, ensure that both the control port and PASV range are allowed.
It is also possible that the rules are not being loaded properly. Typically this would result in a notification in the GUI, however manual tests can be performed to check. From the GUI, visit Status > Filter Reload . Cli
Certain cryptographic hardware can have a software-induced race condition which leads to a problematic state. In this state, pkg will crash with a segmentation fault: 1085486128:error:14099044:SSL routines:ssl3_send_clie
55 ENOBUFS No buffer space available. An operation on a socket or pipe was not performed because the system lacked ˓→ sufficient buffer space or because a queue was full. Several possible conditions can cause this. For a
64 EHOSTDOWN Host is down. A socket operation failed because the destination host was down. In this case, the firewall is unable to reach the a target host directly connected at layer 2 (No ARP response), or it received
65 EHOSTUNREACH No route to host. A socket operation was attempted to an unreachable host. Either there is no possible route to the target locally, or status information was received from an upstream router that indicate
If the signal is weak even when nearby the access point antenna, check the antenna again. For mini-PCI or mini-PCIe cards, if only one pigtail in use and there are two internal connectors, try hooking the pigtail up to t
As a security measure, squid will not allow a user to connect to a site that has a hostname that does not match its IP address. This prevents clients from hardcoding or altering DNS responses to evade access controls. Th
If traffic between some hosts over the VPN functions properly, but some hosts do not, this is commonly one of four things: Missing, incorrect or ignored default gateway If the device does not have a default gateway, or h
If traffic between some hosts over the VPN functions properly, but some hosts do not, this is commonly one of four things. Missing, incorrect or ignored default gateway If the device does not have a default gateway, or h
When crafting rules, bear in mind that typically only a source or a destination port needs to be specified, and rarely both. In the majority of cases, the source port does not matter at all. For example, to allow ssh acc
If the /tmp slice is small, because the firewall is running with /tmp on a RAM disk, current rulesets can easily fill the slice up and cause numerous rule- related errors. If there is sufficient RAM, increase the size of
Squid and most other packages on the firewall itself do not understand load balancing; They will use only the WAN connection with the default gateway.
If a “Stuck Beacon” error is found in the system or wireless log, it is usually an indication that the chosen wireless channel is too noisy: kernel: ath0: stuck beacon; resetting (bmiss count 4) The sensitivity of this b
If the connection appears to be up according to the logs, but it doesn’t work from the LAN, try it from the firewall itself. These tests may be easily performed using the Diagnostics > Ping page on the firewall. First te
Using packet captures to determine where the traffic is or isn’t flowing is one of the most helpful troubleshooting techniques. Start with the internal interface (commonly LAN) on the side where the traffic is being init