Debug Flow and Policy Matching

Use debug flow when traffic is denied, matched to the wrong policy, translated unexpectedly, or routed through the wrong path.

Start clean

diagnose debug reset
diagnose debug flow filter clear
diagnose debug console timestamp enable

Common filters

Filter by source:

diagnose debug flow filter saddr 10.0.0.10

Filter by destination:

diagnose debug flow filter daddr 203.0.113.10

Filter by protocol and port:

diagnose debug flow filter proto 6
diagnose debug flow filter dport 443

Run the trace

diagnose debug flow show function-name enable
diagnose debug flow trace start 50
diagnose debug enable

Generate the traffic after enabling the trace.

Stop and clean up

diagnose debug disable
diagnose debug flow trace stop
diagnose debug flow filter clear
diagnose debug reset

What to look for

  • Policy ID matched by the packet.
  • Route lookup result and outgoing interface.
  • NAT decision.
  • Deny reason, such as iprope_in_check() or policy 0.
  • Session reuse, which can explain why a new policy change is not visible yet.