What information should I collect before I open a case for a Dynamic VPN that won’t connect? What logs or files will assist the Juniper Networks Technical Assistance Center (JTAC) with troubleshooting a Dynamic VPN on a SRX Series device?
After following the steps in Dynamic VPN Resolution Guide, KB17220 - Troubleshoot Dynamic VPN client that is not working [juniper.net] , if the Dynamic VPN is still not working, which logs are needed to further troubleshoot the issue with JTAC?
The data to collect on the SRX and ways to capture the data are shown below:
request support information | no-more show log messages | no-more show log kmd | no-more show security ike security-associations | no-more show security ike security-associations detail | no-more show security ipsec security-associations | no-more show security ipsec security-associations detail | no-more show security ipsec statistics | no-more show security flow session tunnel | no-more
request support information | no-more
show log messages | no-more
show log kmd | no-more
show security ike security-associations | no-more
show security ike security-associations detail | no-more
show security ipsec security-associations | no-more
show security ipsec
security-associations detail | no-more
show security ipsec statistics | no-more
show security flow session tunnel | no-more
Note, for the detail commands listed above, it may expedite resolution if the ID, index numbers or peer IP of the IKE and IPSec security associations are included. If any of the following traceoptions logs were requested to be collected in the previous articles, also include them. For authentication issues, collect all logs that start with authd .
authd
show log ike-debug | no-more show log flow-debug | no-more show log https-debug | no-more show log authd | no-more show log authd.dbg | no-more show log authd.sta | no-more show log authd_libstats | no-more show log authd_profilelib | no-more authd_sdb.log | no-more
HOW TO CAPTURE DATA Capture the above information on the SRX by saving it in a terminal session or saving it to a file:
request support information | save /var/tmp/support-info-case-2010-1234-5678
2020-03-31: Minor, non-technical update.