Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
s_milidrag
Contributor
Contributor
Jump to solution

IPsec traffic debugging on Maestro

Hi all,

Does anybody can let me know how to debug IPsec on Maestro with # vpn debug trunc ALL=5 

Actually my question is where to run this command (I have two MHO with three GW blades)

tanks

SM
0 Kudos
1 Solution

Accepted Solutions
Dario_Perez
Employee Employee
Employee

Traffic passing through Security Group, the MHO is only pass through. So, all debug should be done on Security Group. 

run g_all before to use the debug commands to run on all SGM at same time. since traffic might pass through others SGM

At the end check size and time for ike.elg file

g_all ls -lr -h $FWDIR/log/ike.elg

you should see if file size is bigger than 0 and if time if for today, therefore that is the file you need. 

Also recommend to open a case with TAC. 

View solution in original post

6 Replies
the_rock
Legend
Legend

Maybe someone else can confirm, but since I installed elasticxl on R82, I was able to do it from main site expert mode.

Andy

[Expert@CP-EXL-1-s01-01:0]# vpn debug trunc ALL=5
[Expert@CP-EXL-1-s01-01:0]#

0 Kudos
Dario_Perez
Employee Employee
Employee

when you are in expert you run command locally you have to use g_all to run on all SGM

the_rock
Legend
Legend

I was just about to ask that 🙂

I see what you mean.

Andy

[Expert@CP-EXL-1-s01-01:0]# g_all
1_01:
[Expert@CP-EXL-1-s01-01:0]#

0 Kudos
Dario_Perez
Employee Employee
Employee

right in your case you have only 1 SGM, when you add more and you run g_all you can see the output on each line. 

check 
https://community.checkpoint.com/t5/Maestro/R81-20-Maestro-Cheat-Sheet-version-7/td-p/179757

 

the_rock
Legend
Legend

Yep, thanks for that, I have slightly updated version as well.

 

Cheers,

 

Andy

0 Kudos
Dario_Perez
Employee Employee
Employee

Traffic passing through Security Group, the MHO is only pass through. So, all debug should be done on Security Group. 

run g_all before to use the debug commands to run on all SGM at same time. since traffic might pass through others SGM

At the end check size and time for ike.elg file

g_all ls -lr -h $FWDIR/log/ike.elg

you should see if file size is bigger than 0 and if time if for today, therefore that is the file you need. 

Also recommend to open a case with TAC. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

 
Upcoming Maestro Events