从 PAN-OS 8.0 开始,我们可以启用 IPSec VPN 特定的点对点:
前 PAN-OS 8.0
admin@PA-VM-7.1> debug ike
> global global
> pcap pcap
> socket socket
> stat show IKE daemon statistics
后 PAN-OS 8.0
admin@PA-VM-8.0> debug ike
> gateway debug IKE gateway
> global global
> pcap pcap
> socket socket
> stat show IKE daemon statistics
> tunnel debug IPSec tunnel
使用"网关"或"隧道"关键字,您可以启用每个 VPN 网关或隧道的日志 IPSEC
示例:
admin@PA-VM-8.0> debug ike gateway IKE-GW-HQ
> clear clear IPSec tunnel statistics
> off Turn off IPSec tunnel debug logging
> on Turn on IPSec tunnel debug logging
> stats show IPSec tunnel statistics
admin@PA-VM-8.0> debug ike gateway IPSEC-HQ
> clear clear IPSec tunnel statistics
> off Turn off IPSec tunnel debug logging
> on Turn on IPSec tunnel debug logging
> stats show IPSec tunnel statistics
要关闭当前启用的设置,请使用:
admin@PA-VM-8.0> debug ike gateway <name> off
要查看当前调试设置,请使用:
admin@PA-VM-8.0> debug ike global show => The default settings are generally set to normal mode
日志存储在ikemgr .log可以使用命令"少mp-log ikemgr".log。