Professional Documents
Culture Documents
VSX Troubleshooting: Quick Guide
VSX Troubleshooting: Quick Guide
Troubleshooting
Q u i c k g u i d e
Management scheme
Gateway architecture
Licensing
Issues to fix
Two types
SmartCenter
Provider-1
Nothing special
network_object
- security aspects of a Virtual Device
vs_slot_objects
- networking aspects of a Virtual Device
Network interfaces of VS
Routes of VS
Common kernel
VRF ID
Interfaces
Unicast routing table
Routing cache
Multicast forwarding cache
ARP table
Loopback interface
Sockets
- traceroute –Z vrfid
- ip route vrf vrfid
- “-z vrfid” for the rest (arp –z 1, netstat –z 2 -rn)
Use “all” instead of “vrfid” to show information for
all VRFs
Processes:
$CPDIR/CTX/CTX00xxx/conf
$FWDIR/CTX/CTX00xxx/log, database, …
CPUG 2010 Chur Switzerland 24 (c) Valeri Loukine 2010
Creating VS object 2
Create initial policy
ClusterXL
SecureXL
Provisioning
Changes
vsx_util operations
policy installation
Policy installation:
TDERROR_ALL_INSTMGR
fw debug fwm on
TDERROR_ALL_VSXM=INFO
Or
export TDERROR_ALL_VSXM=INFO
and restart fwm process
$FWDIR/log/fwm.elg
Connectivity
Policy
Interfaces
Clustering
Connectivity
Local times
Licenses
Mind VS number
Interfaces status
cphaprob -a [-vs vsid] if
ping -z...
To unload policy:
fw [-vs <vsid>] unloadlocal