Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FatalHalt
Contributor II

Can I filter diag debug app ike -1?

Hey guys. I have a firewall with TONS of tunnels of it. I know from experience with smaller boxes that the power of diag debug app ike -1 is fantastic. However, I know as soon as I run it on this box it's gonna just absolutely be insane due to the number of tunnels. 

 

Can I filter down to the ones I want in some way?

 

Edit - Totally might have just found my own answer - seems like diag vpn ike log-filter has what I'm after. Can anyone confirm?

1 Solution
Carl_Wallmark
Valued Contributor

Hi,

 

Yes you can ;)

 

diag vpn ike log filter name <phase1name>               user "?" after filter to view alot of options

diag debug app ike -1

diag debug en

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

View solution in original post

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
1 REPLY 1
Carl_Wallmark
Valued Contributor

Hi,

 

Yes you can ;)

 

diag vpn ike log filter name <phase1name>               user "?" after filter to view alot of options

diag debug app ike -1

diag debug en

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Labels
Top Kudoed Authors