
846 Chapter 18 Troubleshooting
320818-A
For more information about the starttrace command, the tags you can specify
for the trace, and the available output modes, see “Performing maintenance using
the CLI” on page 726.
Table 187 shows sample output for the various tags.
To disable tracing, press Enter to display the Maintenance menu prompt, then
enter
stoptrace.
Table 187
Sample output for the trace command
Tag Description Sample output
aaa Logs authentication
method, user
name, group, and
profile
>> Maintenance#
12:54:08.875111: Trace started
12:54:28.834571 10.1.82.145 (1) aaa: "local user db Accept
1:john with groups ["trusted"]"
12:54:28.835144 10.1.82.145 (1) aaa: "final groups for
user: john groups: trusted:<base> "
12:54:29.917926 10.1.82.145 (1) aaa: "new groups for user:
john groups: trusted:<base> "
dns Logs failed DNS
lookups made
during a session
>> Maintenance#
13:00:09.868682 10.1.82.145 (1) dns: "Failed to lookup
www.example.com in DNS (DNS domain name does not exist)"
ssl Logs information
related to the SSL
handshake
procedure (for
example, the cipher
used)
>> Maintenance#
13:15:55.985432: Trace started
13:16:26.808831 10.1.82.145 (1) ssl: "SSL accept done,
cipher is RC4-MD5"
13:16:28.802199 10.1.82.145 (1) ssl: "SSL accept done,
cipher is RC4-MD5"
13:16:29.012856 10.1.82.145 (1) ssl: "SSL accept done,
cipher is RC4-MD5"
tg Logs information
related to a
TunnelGuard check
(for example, SRS
rule check result)
>> Maintenance#
13:27:50.715545: Trace started
13:27:54.976137 10.1.82.145 (1) tg: "ssl user
john[192.168.128.19] - starting tunnelguard ssl session"
13:28:17.204049 10.1.82.145 (1) tg: "ssl user
john[192.168.128.19] - agent authentication ok"
13:28:18.807447 10.1.82.145 (1) tg: "user
john[192.168.128.19] - SRS checks ok, open session"
Commentaires sur ces manuels