Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesIf problems are encountered while attempting a port forward using AZTCO-FW software, try the following. If the Port Forwards guide was not followed exactly, delete anything that has been tried and start from scratch with
If an improperly specified NAT Port Forward exists it can cause problems when NAT Reflection is enabled . The most common way this issue arises is when there is a local web server, and port 80 on the WAN is forwarded the
The following list covers nearly every cause of outbound connectivity failure in common usage scenarios. Each test assumes the items above it have been checked
The Status > DHCP Leases page only reports systems as “online” if the MAC address for a given system appears in the AZTCO-FW firewall’s ARP table. This can be verified by checking Diagnostics > ARP Table . Systems that h
If problems are encountered when trying to use OpenVPN, consult this section for information on troubleshooting common issues.
When configuring a site-to-site PKI (SSL) OpenVPN setup, an internal route must be configured for the client subnet on the Client Specific Overrides tab set for the client certificate’s common name , using either the IPv
If it appears that OpenVPN will not push routes to a client, ensure that a Multi-site style PKI/SSL setup is in use and not a shared key setup or an SSL/TLS setup using a /30 tunnel network. Routes cannot be pushed on a
If the same certificate has been used for multiple clients (which we do not recommend!), then all clients may be assigned the same IP address when they connect. To work around this, duplicate connections must be allowed
When diagnosing traffic flow issues, one of the first things to check is the routes known to AZTCO-FW.
On rare occasions one might need to troubleshoot issues with certain queries to the DNS Forwarder (dnsmasq) or DNS Resolver (Unbound). In such cases it can be helpful to view the queries received by the DNS Forwarder and
On rare occasions one might need to troubleshoot issues with certain queries to the DNS Forwarder (dnsmasq) or DNS Resolver (Unbound). In such cases it can be helpful to view the queries received by the DNS Forwarder and
Troubleshooting steps for HAProxy package
If the clock is several hours off, but accurate to the minute, it is most likely a time zone setting issue. If using a GMT offset time (e.g. -0500 ), try using a more specific geographic time zone such as America/New_Yor
When traceroute is run from LAN to a destination on the Internet, the router itself may be missing from the traceroute output depending on the firewall configuration. This happens on Multi-WAN due to the way that route-t
Traffic Shaping/QoS is a tricky topic, and can prove difficult to get right the first time. This section covers several common pitfalls.
The RRD for traffic shaping graphs must be reset when a change is made to the traffic shaper settings. The RRD files are in a very specific format and refer to the number and name of the queues as they exist in the shape
This document describes methods of troubleshooting problems firewalls may encounter when attempting to run a AZTCO-FW upgrade
Packet captures can be invaluable for diagnosing errors as well. If an unencrypted method (RADIUS, LDAP without SSL) is in use, the actual password being used may not be visible but enough of the protocol exchange can be
Authentication failures are typically logged by the target server (FreeRADIUS, Windows Event Viewer, etc), assuming the request is making it all the way to the authentication host. Check the server logs for a detailed e
If there is a VPN connection to a CARP cluster (site-to-site or mobile/road warrior), often one can communicate with the master but the backup node is unreachable. The reason for this is that the VPN is configured on bot
If some sites will load, but other sites will not, there are a few possible causes. Check all of the items listed on Connectivity Troubleshooting before proceeding Ensure the WAN gateway is reachable and set to the prope
Historically, OpenVPN clients on Windows had issues with routing due to lack of privileges. Current versions of the OpenVPN client for Windows run as a service which does not require administrative privileges. Older lega
If Windows/SMB shares are not able to accessed by OpenVPN clients but other services work as desired, visit VPN > OpenVPN , edit the server in question, and check Enable NetBIOS over TCP/IP .
When it comes to wireless, there are a lot of things that can go wrong. From faulty hardware connections to radio interference to incompatible software/drivers, or simple settings mismatches, anything is possible, and it