Description

In some scenarios where multiple logical systems are involved,  traceoptions  must be applied for debugging purposes. However,  traceoptions  cannot be applied within logical systems; it must be configured in the root logical system and the  lsys  name called in the filter.

This article describes the step-by-step configuration of traceoptions for logical systems by using an example.

 

Solution

To configure traceoptions in logical systems:

  1. Log in to the SRX device and enter configuration mode.

  2. Specify the file in which the debug log will be stored for "security flow " :

​# set security flow ​traceoptions file flow-trace

This sets the security flow debug file to the name flow-trace .

  1. Set the traceoptions flag:

# set security flow traceoptions flag basic-datapath

This sets ​ traceoptions to perform a basic data flow.

  1. Use filters to reduce the volume of data:

# set security flow traceoptions packet-filter pf1 source-prefix 198.20.20.2
  1. Add the logical system’s name in the packet filter.

# set security flow traceoptions packet-filter pf1 logical-system LSYS-STS 

This sets traceoptions to log traces for the specified logical systems.

  1. Issue commit to apply the configuration and exit configuration mode. Logging starts after the commit.

# commit and-quit

Viewing Debugs

The traceoptions debug files can be viewed with the show log <tracefilename>  command.

For the above example, run the following command:

> show log flow-trace

Use additional options to match, trim, and find by using the pipe output (see the " Making Output More Readable " section in KB16108 - SRX Getting Started -- Configuring Traceoptions for Debugging and Trimming Output [juniper.net] ).

Stopping  traceoptions

  • Enter deactivate <option> traceoptions to stop the trace. This is a good option if you need to activate the trace in the future.
  • Use activate <option>   traceoptions to start capturing debug information again.
# deactivate security flow traceoptions
# commit

OR

  • If you want to delete the option, enter the delete <option> traceoptions  command.
# delete security flow traceoptions
# commit

 

Modification History

2020-10-29: ​​Article reviewed for accuracy, article accurate and valid

 

Related Information