What Information Should Be Collected for a Dial-UP VPN That Won’t Come Up? (KB ID: KB9395)
| Article ID: | KB9395 |
|---|---|
| Former Article ID: | |
| Published: | Feb 23, 2007 |
| Last Modified: | Feb 23, 2007 |
| Visible By: | Employee, PTAC, Partner, Customer, Public |
Back to Previous Page | Knowledge Base Home
Article URL
Synopsis
This document will assist you in gathering the required information to help resolve a problem with establishing a VPN Tunnel through your NetScreen Remote VPN Client. Collecting this information will help Technical support discover the cause of the problem.
Problem
After going through the steps in one of the following Troubleshooting documents, and the VPN continues to fail, which logs are needed to further troubleshoot the issue?
Capturing logs could be required to further troubleshoot VPN issues. Collecting the information listed below will help towards identifying the cause of the issue
Solution
The logs needed to further troubleshoot a VPN issue are:
- From the Firewall:
- get tech
- get event
- get ike cookie
- get sa
- From the NetScreen Remote Client:
- The .spd file from the NetScreen Remote Client
- The NetScreen Remote Client Log Viewer file
Follow the instructions below to capture the data:
Logs from the Juniper Firewall:
- Log in to the Juniper firewall, either by Telnet or a terminal software over the Console port. For assistance, see KB6011 - How to Setup a Serial Console Connection to the NetScreen's Communications Port Using Hyperterminal.
- Turn on the text capture feature of your Telnet or terminal software. For assistance, see KB6206 - How do I save the console or screen data from a telnet session?
- Issue the following commands:
- set console page 0 (this command disables the "more" option)
- get tech
- get ike cookie
- get sa
- set console page 22
- get event (only the first four or five pages are needed)
- Save the captured data to a file.
Logs from the NetScreen Remote Client:
- Save the NetScreen Remote's .spd file:
- At the Security Policy Editor, click on File -> Export Security Policy. This will display the Export Policy To... window.
- Save the policy to the PC's hard drive by naming the file and selecting a location to save it. Make sure the policy is unlocked.
- Click Export.
- Save the Log Viewer file:
- Right click on the NS-Remote's icon in the PC's System Tray.
- Left click on Log Viewer
- Click on Save Log. This will bring up the Save As window.
- Give the file a name, leaving the extension as .log, and save it to the PC's hard drive.
Category Description
By Product » Hardware » Firewalls
By Product » Hardware » Firewalls » NetScreen Firewall/IPSec VPN
By Product » Hardware » Firewalls » NetScreen Firewall/IPSec VPN » NetScreen-Remote VPN Client
By Product » Software » Network Operating Systems
By Product » Software » Network Operating Systems » ScreenOS Software
Purpose
Troubleshooting
Related Articles
Related Links
- KB9224 - How to troubleshoot a Dial-Up VPN that will not come active
- KB9444 - What is causing the Phase 2 error: Mismatched Proxy ID or Peer ID when connecting through my client VPN?

