Isolating Faults; Common Errors - Avaya 2330/4134 Troubleshooting Manual

Secure router
Table of Contents

Advertisement

Isolating faults

• Is the firewall at fault?
- Try disabling the firewall so see if connectivity is restored. The simplest way to disable
the firewall is not to remove the policy from the zone, but to remove the interface from
the zone. Remember to remove the necessary interfaces from both the trusted and
untrusted zones.
• Is an ALG at fault?
- Application level gateways examine packets into the application area (beyond the
protocol area) to make allow/deny decisions. But applications are not standardized.
Using SIP as an example, a SIP application from different vendors, or even different
versions of a SIP application from the same vendor may exhibit different behaviors
which the firewall's SIP ALG did not anticipate. The Avaya Secure Router firewall ALGs
are enabled by default. If you are having trouble with one particular application, try
disabling the relevant ALG(s).
firewall global algs no <algName | all> exit exit show firewall
algs
• Does the packet leave the firewall?
- You may find the answer to this with a packet sniffer, or with an interface based packet
capture. But debug firewall packet will also show which packets are egressing
the firewall. The absence of any printing of a "FW out: ..." means that a packet did not
egress the firewall. Most often the firewall will log reasons when it drops packets. But
in a few cases, the firewall may silently drop packets.
• Which type of packets seems to cause the problem?
- If some packets get through and some don't, try to determine which property the firewall
does not like about the offending packets. Is it a particular address or protocol? Is it
fragmented or non-fragmented?
• Are other systems besides the firewall dropping packets?
- In particular, is the QOS system dropping packets?

Common errors

• At least one interface must be in a trusted zone and at least one interface must be in the
untrusted zone.
• Firewalling requires that the Secure Router know the route to both the destination as well
as the source of every packet.
Troubleshooting
Troubleshooting firewall
August 2013
199

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents