IPsec Logging

Examples presented in this chapter have logs edited for brevity but significant messages remain.

Logging for IPsec may be configured to provide more useful information. To configure IPsec logging for diagnosing tunnel issues with AZTCO-FW, the following procedure yields the best balance of information:

  • Navigate to VPN > IPsec on the Advanced Settings tab
  • Set IKE SA, IKE Child SA, and Configuration Backend to Diag
  • Set all other log settings to Control
  • Click Save

Note: Changing logging options is not disruptive to IPsec activity and there is no need to enter a specific “debug mode” for IPsec on current versions of AZTCO-FW.