AZTCOFWCYBER SECURITY SOLUTIONS
Knowledge baseChange logDocumentation in English

AZTCOFW / DOCUMENTATION

Troubleshooting

Configuration guides, troubleshooting and practical advice for AZTCOFW.

502 articles85 topicsRelease history ↗

Subcategories

28 subcategories

Articles

198 results

Troubleshooting with packet captures

Packet captures can be invaluable for troubleshooting and debugging traffic issues. With a packet capture, it is easy to tell if the traffic is reaching the outside interface or leaving an inside interface, among many ot

Troubleshooting “login on console as root” Log Messages

Occasionally, the following messages may appear in the system log: login: login on console as root or: login: login on ttyv0 as root This is normal. It means that the console menu stopped and restarted, or someone presse

Troubleshooting “promiscuous mode enabled” Log Messages

The following log messages are recorded when a utility has placed the network card into “promiscuous mode”: Feb 10 01:41:58 kernel: vr0: promiscuous mode disabled Feb 10 01:41:57 kernel: vr0: promiscuous mode e

Troubleshooting/Alternatives

Disable the FTP Proxy and attempt the connection again Use SCP/SFTP which only needs 1 port to traverse the firewall since it is wrapped in SSH (yes a safe AND simple way of traversing a firewall!) Don’t use FTP (highly

Try with multiple clients or wireless cards

To eliminate a possible incompatibility between wireless functions on AZTCO-FW and a wireless client, be sure to try it with multiple devices or cards first. If the same problem is repeatable with several different makes

Tunnel does not establish

First check the service status at Status > Services . If the IPsec service is stopped, double check that it is enabled at VPN > IPsec . Also, if using mobile clients, ensure that on the Mobile clients tab, the enable box

Tunnel establishes but no traffic passes

The top suspect if a tunnel comes up but won’t pass traffic is the IPsec firewall rules. If Site A cannot reach Site B, check the Site B firewall log and rules. Conversely, if Site B cannot contact Site A, check the Site

Tunnel Establishes When Initiating, but not When Responding

If a tunnel will establish sometimes, but not always, generally there is a mismatch on one side. The tunnel may still establish because if the settings presented by one side are more secure, the other may accept them, bu

Tunnels Establish and Work but Fail to Renegotiate

In some cases a tunnel will function properly but once the phase 1 or phase 2 lifetime expires the tunnel will fail to renegotiate properly. This can manifest itself in a few different ways, each with a different resolut

Unfilterable Traffic

Certain traffic cannot be filtered. Not because the AZTCO-FW software isn’t capable, but because they actually do not touch the firewall at all. A prime example of this is trying to keep one device on the LAN from access

Upgrade Log

AZTCO-FW -upgrade keeps a log of the last update attempt, which may contain additional useful information. This log is located at /conf/upgrade_log.latest.txt. Please include the contents of this log with any post or sup

Upgrade not Offered / Library Errors

If the update system does not offer an upgrade to the most recent version, the upgrade will not proceed, or the upgrade process encounters errors with shared libraries, take the following steps: Navigate to System > Upda

UPnP / NAT-PMP passed traffic

If UPnP/NAT-PMP is enabled and a LAN device opens a port to the world, the traffic may still get in even if it appears it should otherwise be blocked.

UPnP traffic shaping

Out of the box, traffic allowed in by the UPnP daemon will end up in the default queue. This happens because the rules generated dynamically by the UPnP daemon do not have any knowledge of queues unless UPnP is configure

Upstream Issues

Rule problems can almost always be solved by waiting 20-30 minutes and then trying the download again. Failing that, uninstall the package completely and then reinstall the package to ensure the snort binaries are the la

Using traceroute

Traceroute is a useful tool for testing and verifying routes and multi-WAN functionality, among other uses. It shows each “hop” along the path a packet travels from one end to the other, along with the latency encountere

Verify Firewall Rule Configuration

The most common error when configuring multi-WAN is improper firewall rules. Remember, the first matching rule wins and any further rules are ignored. If a policy routing rule is below the default LAN rule in the list, n

View CPU Processes

To view the top processes, including interrupt processing CPU usage and system CPU top -aSH

View I/O Operations

To view I/O operations: systat -iostat 1 Or: top -aSH Then press m to switch to I/O mode to view disk activity.

View Interrupt Counters

To view the interrupt counters and other system usage: systat -vmstat 1

View mbuf Usage

To view the mbuf usage: netstat -m Note: Alternately, check the dashboard mbuf counter, and the graph under Status > Monitoring on the System tab.

Viewing Routes

There are two ways to view the routes: Via the WebGUI, and via the command line. To view the routes in the WebGUI, navigate to Diagnostics > Routes and output is shown similar to this Figure. The output from the command

VirtualBox Issues

Setting Promiscuous mode: Allow All on the relevant interfaces of the VM allows CARP to function on any interface type (Bridged, Host-Only, Internal)

WAN Connection

There could also be issues between the WAN and the Modem/CPE. It could be a cable, or a quirk in how the two interfaces talk to each other. Place a small switch between the firewall and the Modem/CPE as a test.

Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.