I am trying to debug some ssl-vpn connection stuff. If I run "diag debug application sslvpn -1" it generates a lot of debug lines. Downloading the output and filtering through it to find what I need is not fun.
Is there a way to filter this by the source IP of the remote VPN client? Or by some sort of VPN session ID? Or something so that I can focus on troubleshooting a single user without having to wade through all the other connection data?
Solved! Go to Solution.
Greetings!
Yes there is a way to filter with public IP source address.
diagnose vpn ssl debug-filter src-addr4 x.x.x.x -------> public IP of the endpoint
diagnose debug application sslvpn -1
diagnose debug enable
If you wish to clear the filter, use this command, diagnose vpn ssl debug-filter clear
ref: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542
Regards!
Yes you can with this command.
diagnose vpn ssl debug-filter ...
Full info here:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542
Hope it helps.
Greetings!
Yes there is a way to filter with public IP source address.
diagnose vpn ssl debug-filter src-addr4 x.x.x.x -------> public IP of the endpoint
diagnose debug application sslvpn -1
diagnose debug enable
If you wish to clear the filter, use this command, diagnose vpn ssl debug-filter clear
ref: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542
Regards!
Perfect! Thank you.
Yes you can with this command.
diagnose vpn ssl debug-filter ...
Full info here:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542
Hope it helps.
Thanks!
User | Count |
---|---|
2624 | |
1393 | |
804 | |
670 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.