There are many ways to troubleshoot in NetScreen Firewall when some one reports a Incident, that they are unable to access a Server / Application.
Understand the Packet flow
Packet flow tell the order in which the packet is processed by the firewall, when it reaches the firewall.
Packet flow in NetScreen Firewall |
Looking @ Session
It is always a good idea to start the troubleshooting with a session, check if traffic is passing through the firewalls.
spiceup.net.in_FW-> get session src-ip 1.1.1.1 dst-ip 2.2.2.2
You should see matching session output similar to this:
id 1454/s**,vsys 0,flag 00000050/0080/20,policy 320002,time 1, dip 0
1(0001):1.1.1.1/60185->2.2.2.2/512,1,000d60765d03,3,vlan 0,tun 0,vsd 0,route 2
3(0010):1.1.1.1/60185<-2.2.2.2/512,1,000000000000,4,vlan 0,tun 0,vsd 0,route 10
The Source IP Address 1.1.1.1 has source port as 60185 and destionation ip 2.2.2.2 has destination port as 512, the Source port here is the ICMP Sequence Number, the destination port is the ICMP Identifier, is sending the ping packet (echo request) to the destination and the destination sends back the reply to the ping echo reply.
The below is the output of the partial packet capture using sniffer for the above sessions:
ECHO REQUEST:
Internet Control Message Protocol
Type: 8 (Echo (ping) request)
Code: 0
Checksum: 0x6042 (correct)
Identifier: 0x0200
Sequence number: 0xeb19
Data (32 bytes)
ECHO REPLY:
Internet Control Message Protocol
Type: 0 (Echo (ping) reply)
Code: 0
Checksum: 0x6842 (correct)
Identifier: 0x0200
Sequence number: 0xeb19
Data (32 bytes)
Debug flow basic
Shows the flow of traffic through the firewall, allowing for troubleshooting route selection, policy selection, any address translation and whether the packet is recieved or dropped by the firewall.
1) get ffilter - see if an filters have been set already, if they have you use 'unset ffilter' to remove, repeat the steps until you remove all the filters
2) set ffilter src-ip 10.1.1.5 dst-ip 1.1.70.250 - allows you to limit the traffic that you capture using src-ip, src-port, dst-ip, dst-port & etc... Recommeded as debug flow basic can be intensive on the firewall especially if it is under heavy load.
3) debug flow basic - turns on flow debuging with a level of basic logging
4) clear db - make sure there is nothing in the debug buffer from previous debugs
5) Begin the test, do a ping or try to access the resource that you are having problems with.
6) undebug all or press Esc key - turns off debug
7) get db str - reads the debug buffer and outputs.
8) unset ffilter - remove ffilters when finished
9) clear db - make sure there is nothing in the debug buffer from previous debugs
debug flow basic
|
Snoop
Snoop is a powerful troubleshooting tool that gives the user the ability to view packet information from Layer 2 to Layer 4, as it comes into and out of the firewall interfaces. (Bi-directional traffic) Here is the typical procedure when using snoop:
spiceup.net.in_FW-> snoop filter ip 2.2.2.222 - set a filter to limit the traffic that you capture.
spiceup.net.in_FW-> snoop info - check whether the filter is applied properly.
spiceup.net.in_FW-> snoop - "switch on" the snoop and initiate the traffic.
spiceup.net.in_FW-> snoop off - "Turn off" the snoop
spiceup.net.in_FW-> get dbuf stream - check the output of the snoop
spiceup.net.in_FW-> clear db - clear the buffer
spiceup.net.in_FW-> snoop info - check whether the filter is applied properly.
spiceup.net.in_FW-> snoop - "switch on" the snoop and initiate the traffic.
spiceup.net.in_FW-> snoop off - "Turn off" the snoop
spiceup.net.in_FW-> get dbuf stream - check the output of the snoop
spiceup.net.in_FW-> clear db - clear the buffer
Traffic details |
Buffer commands:
get dbuf info - Displays debug buffer size in bytes
set dbuf size - Allocates system memory for the debug buffer
get dbuf stream - Displays the contents of the debug buffer
clear dbuf - Clears the contents of the debug buffer
Awesome post! It's very simple to understand. thx so much :)
ReplyDeleteGreat post and defined in very simple way. Nice work.
ReplyDeletethx for the comment.
ReplyDeleteGreat information, thanks for sharing this valuable information.
ReplyDeleteIts very effective and helpful article. Thank you so much admin.
ReplyDeleteMobile Repairing Institute in Delhi
Mobile Repairing Course in Delhi
Laptop Repairing Course in Delhi
Mobile Repairing Course in Laxmi Nagar
Mobile Repairing Institute in Laxmi Nagar
LED LCD Repairing Course in Delhi
THIS IS VERY INSPIRATION POSTING mobile repairing course in laxmi nagar
ReplyDeletelaptop repairing course in laxmi nagar
Computer Hardware repairing course in laxmi nagar
advance mobile repairing course in laxmi nagar
Hitech institute in laxmi nagar
nice posting mobile repairing course in delhi
ReplyDeletelaptop repairing course in delhi
Computer hardware repairing course in delhi
hitech institute in delhi
advance mobile repairing course in delhi
I believe there are many more pleasurable opportunities ahead for individuals that looked at your site.
ReplyDeleteoracle training in bangalore
Your adblocker blocker is really appreciable ..
ReplyDeleteLED LCD TV Repairing Course in Delhi
LED LCD Smart TV Repairing Course in Delhi
LED Smart TV Repairing Course in Delhi
LED LCD TV Repair Training
LED LCD TV Repair Training in Delhi
LED LCD TV Repairing Course
LED LCD TV Repair Course
LED LCD TV Repair Institute in Delhi
LCD TV Repair Training Institute in Delhi
Mobile Repairing Course in Delhi
Mobile Repairing Institute in Delhi
Mobile Repairing Course in India
Mobile Repairing Course in Laxmi Nagar
Mobile Repairing Institute in Laxmi Nagar
Mobile Repairing Institute in India
LED LCD TV Repairing Course in Laxmi Nagar
awsome post. Thank you for share.
ReplyDeleteLed Lcd Tv Repairing Institute in Delhi
Led Lcd Tv Repairing Course in Delhi
Led Lcd Smart Tv Repairing Course in Delhi
Led Lcd Smart Tv Repairing Institute in Delhi
Led Lcd Tv Repairing Course in Laxmi Nagar
Led Lcd Tv Repairing Institute in Laxmi Nagar
Led Lcd Tv Repairing Institute in India
Led Lcd Tv Repairing Course in India
Mobile Repairing Institute in Delhi
Mobile Repairing course in Delhi
Amazing post. thanks for share.
ReplyDeleteLed Lcd Smart Tv Repairing Course In Delhi
Led Lcd Smart Tv Repairing Institute In Delhi
Led Lcd Tv Repairing Course In Delhi
Led Lcd Tv Repairing Institute In Delhi
Led Lcd Tv Repairing Course In India
Mobile Repairing Course In Delhi
Mobile Repairing Institute In Delhi
Mobile Repairing Course In Laxmi nagar
Mobile Repairing Institute In Laxmi Nagar
Mobile Repairing Course In India
This article gives the light in which we can watch the truth. This is exceptionally decent one and gives indepth data. A debt of gratitude is in order for this decent article. visit website
ReplyDeleteWhen a blind man bears the standard pity those who follow…. Where ignorance is bliss ‘tis folly to be wise…. prywatnoscwsieci
ReplyDeleteMy friend mentioned to me your blog, so I thought I’d read it for myself. Very interesting insights, will be back for more! https://weneedprivacy.com
ReplyDeleteI needed to thank you for this phenomenal read!! I unquestionably adored each and every piece of it. I have you bookmarked your site to look at the new stuff you post. lemigliorivpn.com
ReplyDeletevery simple and to the point information..
ReplyDeletedigital marketing
Digital Marketing Training Institute in Laxmi Nagar Delhi
Digital Marketing Training course in Laxmi Nagar Delhi
Digital Marketing course in Delhi
Digital Marketing institute in Delhi
Digital Marketing Training Institute in nirman vihar
Digital Marketing Training course in nirman vihar
Digital Marketing Training Institute in preet vihar
Digital Marketing Training course in preet vihar
Wow.Title u have chosen is awesome and captive.THe way u expressed the terms is brilliant.
ReplyDeleteapple service center chennai
apple service center in chennai
iphone service center in chennai
iphone service centre
lenovo service center
lenovo mobile service center near me
I would like to thank you for the efforts you have made in writing this article. I am hoping the same best work from you in the future as well. In fact your creative writing abilities has inspired me to start my own BlogEngine blog now. Really the blogging is spreading its wings rapidly. Your write up is a fine example of it. Klik hier
ReplyDeletePretty blog, so many ideas in a single site, thanks for the informative article, keep updating more article.
ReplyDeleteDigital Marketing Institute in Chennai
Digital Marketing Institute in Chennai
Best Digital Marketing Courses in Bangalore
Digital Marketing Training Institute in Coimbatore
This is a wonderful article, Given so much info in it, These type of articles keeps the users interest in the website, and keep on sharing more ... good luck
ReplyDeleteDigital Marketing Training Course in Chennai | Digital Marketing Training Course in Anna Nagar | Digital Marketing Training Course in OMR | Digital Marketing Training Course in Porur | Digital Marketing Training Course in Tambaram | Digital Marketing Training Course in Velachery
kalakai | Karonda Pickle
ReplyDeleteThis is an incredible high goals screen which you have shared for the clients. Making a site isn't a simple undertaking however dealing with a decent site is extremely a diligent work. To the extent this site is concerned, I am extremely glad. 먹튀사이트
ReplyDeleteMany homework on the continual hunt along with offstage on the road to winning. Definitely not attached, simple to-fall as a result of wayside; And not investigation, afterward into a path travel toward the black. Low-Cost Health Insurance
ReplyDeletewonderful article. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. สล็อตออนไลน์
ReplyDeleteI was reading some of your content on this website and I conceive this internet site is really informative ! Keep on putting up.slotxo
ReplyDeleteGood content. You write beautiful things.
ReplyDeletesportsbet
vbet
sportsbet
mrbahis
korsan taksi
hacklink
vbet
taksi
hacklink
sms onay
ReplyDeleteSPFZ5
kocaeli
ReplyDeletekonya
kuşadası
kütahya
malatya
4ZF