Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Tracing Operations for Security Services

Configuring Tracing Operations

To configure trace options for security services, specify flags using the traceoptions statement:

You can include these statements at the following hierarchy levels:

  • [edit security]

  • [edit services ipsec-vpn]

You can specify one or more of the following security tracing flags:

  • all—Trace all security events

  • database—Trace database events

  • general—Trace general events

  • ike—Trace IKE module processing

  • parse—Trace configuration processing

  • policy-manager—Trace policy manager processing

  • routing-socket—Trace routing socket messages

  • timer—Trace internal timer events

Configuring Tracing Operations for IPsec Events for Adaptive Services PICs

To configure trace options to trace IPsec events for Adaptive Services PICs, include the following statements at the [edit services ipsec-vpn] hierarchy level:

Trace option output is recorded in the /var/log/kmd file.

You can specify one or more of the following security tracing flags:

  • all—Trace all security events

  • database—Trace database events

  • general—Trace general events

  • ike—Trace IKE module processing

  • parse—Trace configuration processing

  • policy-manager—Trace policy manager processing

  • routing-socket—Trace routing socket messages

  • timer—Trace internal timer events