版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、排错入门 debug and snoop Basic Debugs Traffic Not Passing - debug flow basic VPN Not Working - debug ike detail Everything Else! - debug ? The Snoop Tool - snoop ? Flow Debugger Basics Never send the debug to the console! set console dbuf Always use a flow filter! set ffilter ? The flow filter uses an O
2、R algorithm. You can set multiple filters and it will filter any traffic that fits any of the filters. To turn the flow debugger ON/OFF debug/undebug flow basic Try to run debugs only during scheduled downtimes. Flow Debugger Example, ICMP request * 997629.0: packet received 60* ipid = 5359(14ef), 0
3、3c9f550 packet passed sanity check. trust:05/4608-51/512,1(8/0) chose interface trust as incoming nat if. search route to (trust, 05-51) in vr trust-vr for vsd-0/flag-0/ifp-null Dest 2.route 51-, to untrust routed (51, 0.0.
4、0.0) from trust (trust in 0) to untrust policy search from zone 2- zone 1 No SW RPC rule match, search HW rule Permitted by policy 9 No src xlate choose interface untrust as outgoing phy if no loop on ifp untrust. session application type 0, name None, timeout 60sec service lookup identified service
5、 0. Session (id:818) created for first pak 1 route to 51 arp entry found for 51 nsp2 wing prepared, ready cache mac in the session flow got session. flow session id 818 post addr xlation: 05-51. Flow Debugger Example, ICMP Response * 997629.0: packet rec
6、eived 60* ipid = 29278(725e), 03c391d0 packet passed sanity check. untrust:51/512-05/4608,1(0/0) existing session found. sess token 3 flow got session. flow session id 818 post addr xlation: 51-05. IKE Debugger Basics For simplicity, try to only initia
7、te only 1 IKE tunnel at a time. Always send the debug to the buffer set console dbuf To turn the debugger ON/OFF debug ike basic/debug ike detail Try to run the debug during a scheduled downtime IKE Debug Example, P1 :Initiate IKE * Recv kernel msg IDX-0, TYPE-5 * IKE Phase 1: Initiated negotiation
8、in main mode. 08 IKE Construct ISAKMP header. IKE Construct SA for ISAKMP IKE Construct NetScreen VID IKE Construct custom VID IKE Xmit : SA VID VID IKE * Recv packet if of vsys * IKE Recv : SA VID VID IKE Process VID: IKE Process VID: IKE Process SA: IKE Construct ISAKMP header. IKE Cons
9、truct KE for ISAKMP IKE Construct NONCE IKE Xmit : KE NONCE IKE * Recv packet if of vsys * IKE Recv : KE NONCE IKE Process KE: IKE Process NONCE: IKE Construct ISAKMP header. IKE Construct ID for ISAKMP IKE Construct HASH IKE Xmit*: ID HASH IKE * Recv packet if of vsys * IKE Recv*: ID HASH IKE Proce
10、ss ID: IKE Process HASH: IKE Phase 1: Completed Main mode negotiation with a -second lifetime. IKE Debug Example, P2 :Initiate IKE Phase 2: Initiated Quick Mode negotiation. IKE Construct ISAKMP header. IKE Construct HASH IKE Construct SA for IPSEC IKE Construct NONCE for IPSec IKE Construct KE for
11、PFS IKE Construct ID for Phase 2 IKE Construct ID for Phase 2 IKE Xmit*: HASH SA NONCE KE ID ID IKE * Recv packet if of vsys * IKE Recv*: HASH SA NONCE KE ID ID IKE Process SA: IKE Process KE: IKE Process NONCE: IKE Process ID: IKE Process ID: IKE Phase 2 msg-id : Completed Quick Mode negotiation wi
12、th SPI , tunnel ID , and lifetime seconds/ KB. IKE Construct ISAKMP header. IKE Construct HASH in QM IKE Xmit*: HASH IKE Debug Example, P1 :Responser IKE * Recv packet if of vsys * IKE Recv : SA VID VID IKE Process VID: IKE Process VID: IKE Process SA: IKE Construct ISAKMP header. IKE Construct SA f
13、or ISAKMP IKE Construct NetScreen VID IKE Construct custom VID IKE Xmit : SA VID VID IKE * Recv packet if of vsys * IKE Recv : KE NONCE IKE Process KE: IKE Process NONCE: IKE Construct ISAKMP header. IKE Construct KE for ISAKMP IKE Construct NONCE IKE Xmit : KE NONCE IKE * Recv packet if of vsys * I
14、KE Recv*: ID HASH IKE Process ID: IKE Process HASH: IKE Construct ISAKMP header. IKE Construct ID for ISAKMP IKE Construct HASH IKE Xmit*: ID HASH IKE Phase 1: Completed Main mode negotiation with a -second lifetime. IKE Debug Example, P2 :Responser IKE * Recv packet if of vsys * IKE Recv*: HASH SA
15、NONCE KE ID ID IKE Process SA: IKE Process KE: IKE Process NONCE: IKE Process ID: IKE Process ID: IKE Construct ISAKMP header. IKE Construct HASH IKE Construct SA for IPSEC IKE Construct NONCE for IPSec IKE Construct KE for PFS IKE Construct ID for Phase 2 IKE Construct ID for Phase 2 IKE Xmit*: HAS
16、H SA NONCE KE ID ID IKE * Recv packet if of vsys * IKE Recv*: HASH IKE Phase 2 msg-id : Completed Quick Mode negotiation with SPI , tunnel ID , and lifetime seconds/ KB. Debug ? admin debug admin arp arp debugging asp ASP debugging asset-recovery asset recovery debugging auth user authentication deb
17、ugging autocfg Auto config debugging av AntiVirus debugging bgp bgp debugging cluster command propagated to cluster members cpapi cpapi debugging dhcp debug dhcp dip dip debugging dlog dlog debugging dns dns debugging driver driver debugging emweb EmWeb debugging filesys Filesys debugging flash flas
18、h operating debugging flow Flow level debugging flow-tunnel Flow Tunnel debugging fs file system debugging gc gc receive and transmit debug gdb GDB debugging global-pro global-pro debugging gt generic tunnel debugging gtmac gtmac debug h323 h323 debugging httpfx http-fx debugging icmp icmp debugging
19、 idp set idp debug parameters ids ids debugging igmp igmp debugging ike ike debugging interface interface debugging intfe Intfe debugging ip ip debugging ixf ixf debug l2tp L2TP debugging lance Lance debugging ldap ldap debug menu logging logging debugging memory Memory debugging mip mip debugging m
20、odem Moden debugging Debug ? nasa nasa debugging nat nat debugging netif netif debugging npak npak debugging nrtp Reliable Xfer Protocol debugging nsgp debug nsgp nsmgmt debug nsmgmt nsp NSM NSP message content nsrd NSRD debugging nsrp debug nsrp obj-id obj id debugging ospf ospf debugging pccard Pc
21、card debugging pim pim debugging pki pki debug menu pluto Pluto debugging policy policy debugging portnum portnum debugging ppcdrv driver debugging ppp ppp debugging pppoe pppoe debugging proxy tcp proxy debugging rd rd debug info report report debugging rip rip debugging rm rm debugging rms rms deb
22、ug info rpc rpc debugging rs rs debug info sa-mon sa monitor debugging scan-mgr scan manager debugging sendmail sendmail debugging session session debugging shaper debug shaper sip sip debugging snmp snmpnew debugging socket socket debug ssh debug ssh ssl ssl debugging stflow saturn flow debug info
23、sw-key software key debugging syslog syslog debugging Debug ? tag tag info task Task debugging tcp tcp debug telnet debug telnet time device clock time debugging timer Timer debugging trackip debug trackip traffic traffic control debugging udp udp debugging uf UF debugging url-blk url filtering debu
24、gging user user/group database debugging vip vip debugging vr vritual router debugging vsys vsys debugging vwire VWIRE debugging web WebUI debugging webtrends webtrends debugging zone zone debugging Debug ? Some debugs do not flow to the buffer Many not tested or minimally tested Try to run the debu
25、g during scheduled downtimes Debug Flow vs. Snoop Debug Flow Sampled at higher flow level Provides information about how the NetScreen processes a packet Can be used to debug higher level flow problems Snoop Sampled at lower driver level Provides information as to whether a packet reached the NetScr
26、eens interface Can be used to debug very basic IP/Ethernet level problems. The snoop tool should be used when the debug tool is showing that no packets are being processed, yet you are certain that data is reaching the NetScreen. Snoop Basics Always send snoop to the debug buffer To Turn the Snoop o
27、n/off ns5gt- snoop Start Snoop, type ESC or snoop off to stop, continue? y/n y ALWAYS run the snoop during scheduled downtime! Snoop Basics Always set a filter on the Snooper tool ns5gt- snoop ? detail snoop detail configuration filter snoop filter configuration info show snoop information off turn
28、off snoop Note: Snoop uses an AND algorithm in the filter. ns5gt- snoop filter ? delete delete snoop filter ethernet snoop specified ethernet id snoop filter id ip snoop ip packet off turn off snoop filter on turn on snoop filter tcp snoop tcp packet udp snoop udp packet Snoop Example ns5gt- snoop info Snoop: ON Filters Defined: 2, Active Filters 2 Detail: OFF, Detail Display length: 96 Snoop filter based on: id 1(on): IP src-ip 05 dst-ip 51 dir(B) id 2(on): IP src-ip 51 dst-ip 05 dir(B) Snoop Example ns5gt- get db s 999
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 重大经济责任制度
- 院长经济责任制度
- 零起点领导责任制度
- 韩国公务员责任制度
- 项目经济目标责任制度
- 食品安全两责任制度
- 食堂安全岗位责任制度
- 食药安全监管责任制度
- 餐饮区域责任制度
- 饲养动物行政责任制度
- 土地管理课件
- 大米加工企业安全生产管理制度
- 活鸡屠宰合同范本
- 做账实操-农资站的账务处理会计分录示例
- 2025年及未来5年市场数据中国软磁铁氧体磁芯行业发展前景预测及投资战略数据分析研究报告
- 西门子-PLM产品协同研发平台建设规划方案
- 单招职业适应性测试题库附参考答案详解【综合卷】
- 宜宾市翠屏区2025年面向社会公开招聘社区工作者(社区综合岗)(16人)备考题库附答案解析
- KA-T 22.3-2024 矿山隐蔽致灾因素普查规范 第3部分:金属非金属矿山及尾矿库
- 中建项目平面布置CAD制图标准
- 2026年印刷公司油墨化学品存储安全管理制度
评论
0/150
提交评论