netscreen debug cheat sheet

1
NetScreen Debug Cheat Sheet System Related Debug Commands policy, syslog, task, auth, flash, admin, dlog, filesys, ids, interface, logging, nat, nsmgmt, user, vr, timer Traffic and Packet Flow Debug Commands traffic, flow, ip, session, socket, portnum, trackip, zone Protocol Related Debug Commands arp, ssh, snmp, dns, dhcp, icmp, tcp, web VPN Related Debug Commands pki, flow-tunnel, ssl COMMANDS Created by: Bryan Murphy ( http://downgrade.org ) -- v1.1 SUB COMMANDS Enabling Debug debug <command> <sub_command> ENABLING Example get db <command> Include/Exclude get db stream | <include/exclude> <string> Note: <string> may be a string or a regular expression DISPLAY ffilter Example set ff dst-ip <ip> dest-port <port> Note: Apply the filters before enabling and producing debug outputs. ffilters dest-ip, dest-port, src-ip, src-port, ip-protocol Display Active ffilters get ff FILTERING Disable a ffilter unset ff <id number> Clear/Erase the Debug Buffer clear db Disable All Debugging undebug all Disable Specific Debugging undebug <command> <sub_command>l dynpol dynamic policy search drop drop pak basic basic debuging all all flow shows available subs Explanation ? Sub Comand internal internal debug illegal illegal debug CLEANING UP

Upload: lukasz-motyka

Post on 30-Nov-2015

36 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Netscreen Debug Cheat Sheet

NetScreen Debug Cheat Sheet

System Related Debug Commandspolicy, syslog, task, auth, flash, admin, dlog, filesys, ids, interface, logging, nat, nsmgmt, user, vr, timer

Traffic and Packet Flow Debug Commands traffic, flow, ip, session, socket, portnum, trackip, zone

Protocol Related Debug Commandsarp, ssh, snmp, dns, dhcp, icmp, tcp, web

VPN Related Debug Commandspki, flow-tunnel, ssl

COMMANDS

Created by: Bryan Murphy ( http://downgrade.org ) -- v1.1

SUB COMMANDS

Enabling Debugdebug <command> <sub_command>

ENABLING

Exampleget db <command>

Include/Excludeget db stream | <include/exclude> <string>

Note: <string> may be a string or a regular expression

DISPLAY

ffilter Exampleset ff dst-ip <ip> dest-port <port>

Note: Apply the filters before enabling and producing debug outputs.

ffiltersdest-ip, dest-port, src-ip, src-port, ip-protocol

Display Active ffiltersget ff

FILTERING

Disable a ffilterunset ff <id number>

Clear/Erase the Debug Bufferclear db

Disable All Debuggingundebug all

Disable Specific Debuggingundebug <command> <sub_command>l

dynpol dynamic policy searchdrop drop pakbasic basic debugingall all flow

shows available subsExplanation

?Sub Comand

internal internal debugillegal illegal debug

CLEANING UP