{"id":389,"date":"2013-12-09T12:10:22","date_gmt":"2013-12-09T11:10:22","guid":{"rendered":"http:\/\/janscholten.de\/blog\/?p=389"},"modified":"2013-12-09T12:10:57","modified_gmt":"2013-12-09T11:10:57","slug":"fortigate-debug-eines-bestimmten-vpn-tunnels","status":"publish","type":"post","link":"https:\/\/janscholten.de\/blog\/2013\/12\/fortigate-debug-eines-bestimmten-vpn-tunnels\/","title":{"rendered":"Fortigate: Debug eines bestimmten VPN Tunnels"},"content":{"rendered":"<p>Wenn man eine gut best\u00fcckte Fortigate hat muss man hin und wieder auch mal Fehler suchen.<br \/>\nZ.B. warum kommt ein VPN Tunnel nicht hoch.<\/p>\n<p>Der &#8222;einfache&#8220; Weg<br \/>\n<code>diag debug enable<br \/>\ndiag debug console<br \/>\ndiag debug ike -1<\/code><\/p>\n<p>gibt nat\u00fcrlich Daten \u00fcber alle VPN Verbindungen, was schnell un\u00fcbersichtlich wird.<\/p>\n<p>Man kann das ganze aber auch beschr\u00e4nken um z.B. nur Daten f\u00fcr eine Gegenstelle oder eine Phase2 zu sehen:<\/p>\n<p>Zur Auswahl stehen:<br \/>\n<code>diag vpn ike log-filter<br \/>\nclear        Erase the current filter.<br \/>\ndst-addr4    IPv4 destination address range to filter by.<br \/>\ndst-addr6    IPv6 destination address range to filter by.<br \/>\ndst-port     Destination port range to filter by.<br \/>\ninterface    Interface that IKE connection is negotiated over.<br \/>\nlist         Display the current filter.<br \/>\nname         Phase1 name to filter by.<br \/>\nnegate       Negate the specified filter parameter.<br \/>\nsrc-addr4    IPv4 source address range to filter by.<br \/>\nsrc-addr6    IPv6 source address range to filter by.<br \/>\nsrc-port     Source port range to filter by.<br \/>\nvd           Index of virtual domain. -1 matches all.<br \/>\n<\/code><\/p>\n<p>z.B.<\/p>\n<p><code>diag vpn ike log-filter dst-addr4 10.10.10.10<br \/>\ndiag debug enable<br \/>\ndiag debug console<br \/>\ndiag debug app ike -1<br \/>\n<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wenn man eine gut best\u00fcckte Fortigate hat muss man hin und wieder auch mal Fehler suchen. Z.B. warum kommt ein VPN Tunnel nicht hoch. Der &#8222;einfache&#8220; Weg diag debug enable diag debug console diag debug ike -1 gibt nat\u00fcrlich Daten \u00fcber alle VPN Verbindungen, was schnell un\u00fcbersichtlich wird. Man kann das ganze aber auch beschr\u00e4nken &hellip; <a href=\"https:\/\/janscholten.de\/blog\/2013\/12\/fortigate-debug-eines-bestimmten-vpn-tunnels\/\" class=\"more-link\"><span class=\"screen-reader-text\">Fortigate: Debug eines bestimmten VPN Tunnels<\/span> weiterlesen<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,7,28,12],"tags":[40,53],"class_list":["post-389","post","type-post","status-publish","format-standard","hentry","category-allgemein","category-erfahrungen","category-fortinet","category-job","tag-debug","tag-fortinet"],"_links":{"self":[{"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/posts\/389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/comments?post=389"}],"version-history":[{"count":2,"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/posts\/389\/revisions"}],"predecessor-version":[{"id":391,"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/posts\/389\/revisions\/391"}],"wp:attachment":[{"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/media?parent=389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/categories?post=389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/janscholten.de\/blog\/wp-json\/wp\/v2\/tags?post=389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}