Debugging VPN
In the R81.10.X releases, this command is available starting from the R81.10.00 version.
Description
Instructs the VPN daemon vpnd
to write debug messages to the applicable log files.
Debugging of the VPN daemon takes place according to Debug Topics and Debug Levels:
-
A Debug Topic is a specific area, on which to perform debugging.
For example, if the Debug Topic is "
LDAP
", all traffic between the VPN daemon and the LDAP server is written to the log file.Check Point Support provides the specific Debug Topics when needed.
-
Debug Levels range from 1 (least informative) to 5 (most informative - write all debug messages).
|
Important - For the complete VPN debug procedure, follow sk62482. |
Syntax
|
Parameters
Parameter |
Description |
||||
---|---|---|---|---|---|
No Parameters |
Shows the built-in usage. |
||||
|
Starts only the VPND daemon debug (a high level debug). The VPND daemon debug writes the information in these files:
|
||||
|
Specifies the Debug Topic and the Debug Level. Check Point Support provides these.
|
||||
|
Stops the VPND daemon debug and the IKE debug.
|
||||
|
Starts only the IKE debug. The IKE debug writes the information in these files:
You can specify the size of the log file, when to perform the log rotation (close the current active file, rename it, open a new active file). |
||||
|
Stops only the IKE debug. Run this command to stop the IKE debug:
|
||||
or
|
Run this command to start the VPND daemon debug and the IKE debug:
|
||||
|
Stops the VPND daemon debug and the IKE debug.
|
||||
|
Enables the periodic timestamp in the log files. Prints one timestamp after the specified number of seconds. By default, prints the timestamp every 10 seconds. |
||||
|
Disables the periodic timestamp in the log files every number of seconds. |
||||
|
Logs failed IKE negotiations. You can specify the size of the log file (see below), when to perform the log rotation (close the current active file, rename it, open a new active file).
|
||||
|
Enables the IKE Monitor. Saves the IKE packets in the
|
||||
|
Disables the IKE Monitor. |
||||
|
Saves the specified text string in the log file (see below). For example, run:
|
||||
|
|