|
SOLUTION |
Please perform the following debug procedure on the firewall. 1. Enable ike debug and vpnd debug: vpn debug trunc vpn debug on TDERROR_ALL_ALL=5 2. Start fw monitor # fw monitor -e "accept;" -o vpn_traffic.mon 3. Start kernel debug in a new console, and run: fw ctl debug 0 fw ctl debug -buf 32768 fw ctl debug -m fw + conn drop vm fw ctl debug -m VPN + all fw ctl kdebug -f -T>& vpn_kernel.dbg 4. Now please inital traffic through the tunnel 5. Stop kernel debug by pressing Ctrl-C # fw ctl debug 0 6. Stop fw monitor by pressing Ctrl-C 7. Stop ike and vpnd debug: vpn debug off vpn debug ikeoff 8. You can verify using debug tools or Please zip the file: vpn_traffic.mon, vpn_kernel.dbg, $FWDIR/log/ike.elg, and all $FWDIR/log/vpnd.elg* files, and upload files to us once you open a Service Request. |
Labels
- Cheat Sheets (7)
- Checkpoint (159)
- Cisco (24)
- Commands (5)
- Fortigate (2)
- Frame-Relay (9)
- Linux (3)
- Netscaler (29)
- Netscreen (2)
- Nokia (7)
- UNIX (2)
Live Traffic
How do I run full blown VPN debug on gateway for trouble shooting VPN issues?
6/25/2011 09:18:00 AM
Posted by MK | Filed Under Checkpoint | 0 Comments
Comments
Search This Blog
Blog Archive
-
▼
2011
(107)
-
▼
June
(49)
- Configuring controller E1
- Autonegotiation Valid Configuration
- Hardware Troubleshooting for Cisco 12000 Series In...
- troubleshooting high CPU utilization
- NetScaler Password Recovery Procedure
- Configuring DNS
- Configuring Link Aggregate Channels
- To configure a VLAN by using the NetScaler command...
- Configuring Network Interfaces
- Enabling and Disabling MAC-Based Forwarding Mode
- Enabling and Disabling Layer 2 or 3 Mode
- Binding the SSL Policy to an SSL Vserver
- Creating SSL Policies
- Creating an SSL Action to Enable OWA Support
- Binding an SSL Certificate Key Pair to the Vserver
- Adding a Certificate Key Pair
- Binding Services to the SSL Vserver
- Adding an SSL-Based Vserver
- Securing Load Balanced Traffic by Using SSL
- Binding a Compression Policy to a Vserver
- Configuring Services to Compress Data
- Enabling Compression
- Configuring Backup Vservers
- Configuring URL Redirection
- How To Perform a SecurePlatform Firewall Health Ch...
- VPN between Check Point Security Gateway and Cisco...
- SmartView Tracker allows a maximum of 0 windows
- What is ike.elg?
- How can I troubleshoot Cisco to Check Point VPN
- How to increase sizes of buffer / ring descriptor ...
- The CPinfo utility
- What information is required to troubleshoot the V...
- Enabling IKE and VPN debugging
- How do I run full blown VPN debug on gateway for t...
- How to generate a valid ike debug, vpn debug and f...
- The reason why we need LDAP profiles
- How To Perform a SecurePlatform Firewall Health Ch...
- Checkpoint - Log File Corrupted
- The netstat Command
- VI - Cheat Sheet
- Checkpoint - Critical error messages and logs
- TCP DUMP
- Checkpoint : Unwanted Services : Save Memory
- Checkpoint Commands - In depth - tHEY dONT liKE BU...
- Path of Database Revision Controls
- NTP in Splat
- Upgrade and Roadmap Diagrams Now Include R75.10
- CPX 2011: Security Gateways in the data center
- Advanced migration of Provider-1 R7x
-
▼
June
(49)
Post a Comment