<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Easy VPN Debug Tool in Scripts</title>
    <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/90153#M337</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/40848"&gt;@Nauuk_K&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The script executes the following vpn debug commands:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;BR /&gt;vpn debug on&lt;BR /&gt;vpn debug ikeon&lt;BR /&gt;vpn debug on TDERROR_ALL_ALL=5;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; Wait for the vpn error &amp;lt;&amp;lt;&amp;lt;&lt;/P&gt;
&lt;P&gt;vpn debug off&lt;BR /&gt;vpn debug ikeoff&lt;BR /&gt;vpn debug truncoff;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2020 06:52:21 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2020-06-30T06:52:21Z</dc:date>
    <item>
      <title>Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/89755#M335</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="evpdt123.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9432i2EA8F5938EBCBD3A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="evpdt123.JPG" alt="evpdt123.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ffffff; font-size: large;"&gt;CLI command&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;This tool creates a VPN debug with one cli command:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;evpn -d&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Creates all VPN debug files ike.elg and vpnd.elg&lt;BR /&gt;&lt;STRONG&gt;evpn -d -m&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Creates all VPN debug files ike.elg, vpnd.elg and a fw monitor capture file of all network packages&lt;/P&gt;
&lt;P&gt;evpn -o&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Shows overlaped encdoms 'overlap_encdom'&lt;BR /&gt;evpn -r&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Shows vpn routes 'fw tab -t vpn_routing -u'&lt;BR /&gt;evpn -t&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Shows tunnel list 'vpn tu tlist'&lt;BR /&gt;evpn -v&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; Shows the vpn tu tool 'vpn tu'&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ffffff; font-size: large;"&gt;Install&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;"&lt;FONT color="#000000"&gt;&lt;STRONG&gt;copy and past&lt;/STRONG&gt;&lt;/FONT&gt;" the following script block from "Spoiler" to the Check Point gateway:&lt;/P&gt;
&lt;LI-SPOILER&gt;&lt;LI-CODE lang="markup"&gt;curl_cli -k http://www.ankenbrand24.de/inst_evpn &amp;gt; /tmp/inst_evpn &amp;amp;&amp;amp; chmod 770 /tmp/inst_evpn &amp;amp;&amp;amp; /tmp/inst_evpn&lt;/LI-CODE&gt;&lt;/LI-SPOILER&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ffffff; font-size: large;"&gt;Script&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;LI-SPOILER&gt;&lt;LI-CODE lang="markup"&gt;cat &amp;lt;&amp;lt;EOT &amp;gt; /usr/bin/evpn
#!/bin/bash

# trap ctrl-c and call ctrl_c()
trap ctrl_c INT
FWMONITOR="off";
FILTER_SHOW="off";
FWDEBUG="off";
FWDEBUG_SHOW="off";
NOW=\$(date +"%Y_%m_%d_%H%M");
FILE_PATH="/var/log/";
REMOTE_FILE="\$FILE_PATH\$NOW-evpn.tgz";
echo -e "\e[7m";
clear;
printf '%.s-' {1..78};echo;
echo '- Easy VPN Debug Tool v1.3                 - Copyright Heiko Ankenbrand 2020 -';
printf '%.s-' {1..78};
echo -e "\e[0m";
echo;
mSITIONAL=();
while [[ \$# -gt 0 ]]
do
key="\$1"
case \$key in
    -h|--help|-\?)
       shift;
       echo;echo 'Help: ';echo;
       echo "-t                         Displays the tunnel list 'vpn tu tlist'";
       echo "-r                         Displays the vpn routes 'fw tab -t vpn_routing -u'";
       echo "-o                         Displays the overlaped encdoms 'overlap_encdom'";
       echo "-v                         Displays the vpn tu tool 'vpn tu'";echo;
       echo "-d                         Execute a full VPN debug (sk34467, sk89940)";
       echo "                             # vpn debug trunc";
       echo "                             # vpn debug on";
       echo "                             # vpn debug ikeon";
       echo "                             # vpn debug on TDERROR_ALL_ALL=5";
       echo "                             &amp;gt;&amp;gt;&amp;gt; VPN ISSUE &amp;lt;&amp;lt;&amp;lt;";
       echo "                             CTRL-C        ---&amp;gt; Stop debug";
       echo "                             # vpn debug off";
       echo "                             # vpn debug ikeoff";
       echo "                             # vpn debug truncoff";
       echo;
       echo "Optitions for full VPN debug:";
       echo "-s                         Show live debug output";
       echo "-m                         Enable fw monitor for all packets.";
       echo "-f &amp;lt;display filter&amp;gt;        Set display filter for example 'ike'. ";echo;
       echo "Example filter:";
       echo "           CPTLS           SSL VPN connections (VPN Capsule client)";
       echo "           ike             IKE VPN connections (Site to Site VPN)";echo;
       exit 0;

       exit 0;
    ;;
    -m)
       shift;
       FWMONITOR="on";
    ;;
    -f)
       FILTER_SHOW="\$2";
       shift;
       shift;
    ;;
    -r)
       shift;
       echo; echo "VPN routing:";echo;
       fw tab -t vpn_routing -u | awk 'NR&amp;gt;3 {\$0=substr(\$0,2,28); gsub(", ", ""); gsub("; ", ""); gsub("..", "0x&amp;amp; "); print}' | xargs printf "%d.%d.%d.%d\t-\t%d.%d.%d.%d\tPeer: %d.%d.%d.%d\r\n" | sort -k1n,1;
       echo;
       exit 0;
    ;;
     -v)
       shift;
       function ctrl_c() {
                echo;
                exit 0;
           }
       vpn tu;
       exit 0;
    ;;
     -o)
       shift;
       echo; echo "Overlapping VPN encryption domains:";echo;
       vpn overlap_encdom;
       echo;
       exit 0;
    ;;
     -t)
       shift;
       echo; echo "VPN tunnel list:";echo;
       vpn tu tlist;
       echo;
       exit 0;
    ;;
     -d)
       shift;
       FWDEBUG="on";
    ;;
    
     -s)
       shift;
       FWDEBUG_SHOW="on";
    ;;

    *)    # unknown option
    #echo "unknown"
    POSITIONAL+=("\$1") # save it in an array for later
    shift
    ;;
esac
done
if [ \$FWDEBUG == "on" ] ;
   then
   if [ \$FWMONITOR == "on" ] ;
      then
        echo "Start fw monitor for all packets. ";
        #echo "EASY VPN DEBUG TOOL: Start fw monitor for all packets." &amp;gt;&amp;gt; \$FWDIR/log/vpnd.elg;
        fw monitor -e "accept;" -o /var/log/evpn_fw_mon.cap &amp;amp;&amp;gt; /dev/null &amp;amp;
   fi
   vpn debug trunc
   vpn debug on
   vpn debug ikeon
   vpn debug on TDERROR_ALL_ALL=5;
   
   function ctrl_c() {
        echo; echo "VPN debug stop"; echo;
        vpn debug off;
        vpn debug ikeoff;
        vpn debug truncoff;
        echo "EASY VPN DEBUG TOOL: VPN debug stop CTRL-C" &amp;gt;&amp;gt; \$FWDIR/log/vpnd.elg
        echo "   # vpn debug truncoff";
        echo "   # vpn debug off";
        echo "   # debug ikeoff";
        echo;echo -e "Create tgz file...";
        tar -czf \$REMOTE_FILE \$FWDIR/log/ike.elg* \$FWDIR/log/vpnd.elg* /var/log/evpn_fw_mon.cap &amp;amp;&amp;gt; /dev/null ;
        echo;echo "   Tar file location: \$REMOTE_FILE";echo;
        echo "   Included file: \$FWDIR/log/ike.elg";
        echo "   Included file: \$FWDIR/log/vpnd.elg";
        if [ \$FWMONITOR == "on" ] ;
           then
              echo "   Included file: /var/log/evpn_fw_mon.cap"; 
        fi
        echo;
        rm /var/log/evpn_fw_mon.cap &amp;amp;&amp;gt; /dev/null ;
        exit 0
   }
   # echo "EASY VPN DEBUG TOOL: VPN debug start" &amp;gt;&amp;gt; \$FWDIR/log/vpnd.elg
   echo "VPN debug start ";echo;
   echo "   # vpn debug trunc";
   echo "   # vpn debug on";
   echo "   # debug ikeon";
   echo "   # vpn debug on TDERROR_ALL_ALL=5";
   if [ \$FWMONITOR == "on" ] ;
      then
      echo "   # fw monitor -e 'accept;' -o /var/log/evpn_fw_mon.cap";
   fi
   echo;echo " &amp;gt;&amp;gt;&amp;gt; Wait until the issue occurs &amp;lt;&amp;lt;&amp;lt;";
   echo -e "\e[7m";
   echo "      Stop VPN debug with CTRL-C     ";
   echo -e "\e[0m";
   
   if [ \$FWDEBUG_SHOW == "on" ] ;
      then
        echo;echo;
        if [ \$FILTER_SHOW == "off" ] ;
           then
             tail -f \$FWDIR/log/vpnd.elg
         else
             tail -f \$FWDIR/log/vpnd.elg | grep "\[\$FILTER_SHOW"
         fi
      else 
      sleep 10000000;
   fi 
   vpn debug off
   vpn debug ikeoff
   vpn debug truncoff;
   
else
   echo;echo "Please start 'evpn -h' for help.";echo;
fi
EOT
chmod 770 /usr/bin/evpn;&lt;/LI-CODE&gt;&lt;/LI-SPOILER&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ffffff; font-size: large;"&gt;Version&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;1.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06-25-2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EA version&lt;BR /&gt;1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06-27-2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bugfix&lt;BR /&gt;1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06-28-2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; GA version&lt;BR /&gt;1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06-30-2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; include all ike.elg* and vpnd.elg* files&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 15:34:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/89755#M335</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-12-01T15:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/89787#M336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What exactly does this script do?&lt;BR /&gt;So I don't have to type in all VPN debug commands anymore!&lt;/P&gt;&lt;P&gt;Am I getting this right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 09:57:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/89787#M336</guid>
      <dc:creator>Nauuk_K</dc:creator>
      <dc:date>2020-06-25T09:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/90153#M337</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/40848"&gt;@Nauuk_K&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The script executes the following vpn debug commands:&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;BR /&gt;vpn debug on&lt;BR /&gt;vpn debug ikeon&lt;BR /&gt;vpn debug on TDERROR_ALL_ALL=5;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; Wait for the vpn error &amp;lt;&amp;lt;&amp;lt;&lt;/P&gt;
&lt;P&gt;vpn debug off&lt;BR /&gt;vpn debug ikeoff&lt;BR /&gt;vpn debug truncoff;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 06:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/90153#M337</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-06-30T06:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/110604#M764</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 20:12:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/110604#M764</guid>
      <dc:creator>O_H</dc:creator>
      <dc:date>2021-02-11T20:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/115141#M773</link>
      <description>&lt;P&gt;Hello Heiko,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;as always a wonderful tool.&lt;BR /&gt;but is there way to limot the debug to only ONE tunnel peer IP or community name ?&lt;BR /&gt;&lt;BR /&gt;because this command offers an option "tunnel"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;vpn debug ?&lt;BR /&gt;Usage: vpn debug &amp;lt; on [ DEBUG_TOPIC=level ] | off | ikeon [ -s size(Mb) ]| ike off | trunc [ DEBUG_TOPIC=level ] | truncon [ DEBUG_TOPIC=level ] | truncoff | ti meon [ SECONDS ] | timeoff | ikefail [ -s size(Mb) ]| mon | moff | say [ string ] | &lt;EM&gt;&lt;STRONG&gt;tunnel&lt;/STRONG&gt; &lt;/EM&gt;[ level ] &amp;gt;&lt;BR /&gt;&lt;BR /&gt;what is&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;|&lt;/EM&gt; tunnel&amp;nbsp;|&lt;/STRONG&gt; supposed to mean?&lt;BR /&gt;can i filter the debug on one tunnel ?&lt;BR /&gt;in most time the logs are rapidly filling up and there is no chance to a for long term VPN debugging ...&lt;BR /&gt;&lt;BR /&gt;would be wonderful to filter the debug output in one specfic file and focus only on one specific remote peer or tunnel name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 10:37:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/115141#M773</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-04-02T10:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/115147#M774</link>
      <description>&lt;P&gt;Confining a vpnd debug to one tunnel or peer doesn't seem possible, the &lt;STRONG&gt;tunnel&lt;/STRONG&gt; option you are referring to looks like it is just a shortcut to execute multiple debug commands (kind of like &lt;STRONG&gt;zdebug&lt;/STRONG&gt;).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are having problems with the vpnd.elg files rolling off before you can look at them, make sure you are only debugging IKE by just using the &lt;STRONG&gt;ikeon&lt;/STRONG&gt; argument which is typically all that you need in most VPN troubleshooting scenarios.&amp;nbsp; Doing a &lt;STRONG&gt;vpn debug on&lt;/STRONG&gt; enables IKE debugging but lots of other debug flags in vpnd as well that will seriously clutter up your debug files.&amp;nbsp; &amp;nbsp;Also you won't typically need to set TDERROR_ALL_ALL which will really overwhelm your output files.&lt;/P&gt;
&lt;P&gt;If you do require that level of debugging, you can adjust how large the vpnd.elg files are allowed to get before rolling over and/or specify the number of files to keep before they are automatically removed here:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112515&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk112515: How to increase maximum size and number of rotated $FWDIR/log/vpnd.elg log files on SecurePlatform / Gaia OS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 14:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/115147#M774</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-04-02T14:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/200580#M1133</link>
      <description>&lt;P&gt;Great tool, I wonder in case we can add&amp;nbsp;ikev2.xmll to the compressed file&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 03:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/200580#M1133</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2023-12-14T03:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Easy VPN Debug Tool</title>
      <link>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/270976#M1489</link>
      <description>&lt;P&gt;Hello, since I believe this is something really useful I would like to understand if it is still valid for 81.20 with the iked change for the debug, thanks&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2026 09:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Scripts/Easy-VPN-Debug-Tool/m-p/270976#M1489</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2026-02-16T09:28:31Z</dc:date>
    </item>
  </channel>
</rss>

