Support Support Downloads Knowledge Base Case Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

Using filters with 'debug ike'



Article ID: KB5580 KB Last Updated: 06 Jul 2009Version: 4.0
Using ffilter with debug ike
  • How do I filter 'debug ike detail' to only show debugs from the VPN gateway I'm interested in?
  • Flow filters (set ffilter or set ff) are not working with 'debug ike detail'

The command 'debug ike detail' is used for obtaining debugs of the IKE negotiations. This occurs between VPN gateway to VPN gateway.

If you have multiple VPN gateways configured, and only want to see IKE negotiation to one specific VPN gateway, use the "set sa-filter" command to filter the debug ike detail messages.

For example, if you want to only obtain IKE negotiation debugging messages to, use the command:

set sa-filter

Don't forget to unset them when you're done to avoid being mislead the next time you run 'debug ike detail'.

For additional information on running 'debug ike detail', refer to KB14620 - How to run a 'debug ike detail.

Note:   The command 'set ffilter' (for setting a flow filter) does not apply to 'debug ike'.  The 'set ffilter' command only applies to 'debug flow'.

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search