Debug Flow and Policy Matching
Use debug flow when traffic is denied, matched to the wrong policy, translated unexpectedly, or routed through the wrong path.
Start clean
diagnose debug reset
diagnose debug flow filter clear
diagnose debug console timestamp enableCommon filters
Filter by source:
diagnose debug flow filter saddr 10.0.0.10Filter by destination:
diagnose debug flow filter daddr 203.0.113.10Filter by protocol and port:
diagnose debug flow filter proto 6
diagnose debug flow filter dport 443Run the trace
diagnose debug flow show function-name enable
diagnose debug flow trace start 50
diagnose debug enableGenerate the traffic after enabling the trace.
Stop and clean up
diagnose debug disable
diagnose debug flow trace stop
diagnose debug flow filter clear
diagnose debug resetWhat to look for
- Policy ID matched by the packet.
- Route lookup result and outgoing interface.
- NAT decision.
- Deny reason, such as
iprope_in_check()or policy0. - Session reuse, which can explain why a new policy change is not visible yet.