Hi,
I am trying to debug the SSL VPN using the commands below but they only last 30 minutes, is there a way of making debug last longer or turn on at a certain point?
diagnose debug application sslvpn -1
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Changing-debug-duration/ta-p/191069
its a bit older so not sure if that still works in current FortiOSes.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Yes I tried and it still works fine.
You can refer to the following commands:
# diagnose debug application fnbamd 255
#diagnose debug duration 0 ----------------------> For unlimited duration (You can also change to specific time. Instead of 0 add any digits that will count as minute)
# diagnose debug application sslvpn -1
# diagnose debug console timestamp enable
# diagnose debug enable
Also combine below if you have too many users and want to see only one user's log.
# diag vpn ssl debug-filter src-addr4 <user_public_ip>
Toshi
If you checked something trigger, I think utilizing automation would also be useful. (like eventlog or memory)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1013 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.