Fortinet white logo
Fortinet white logo

CLI Reference

diagnose vpn ike

diagnose vpn ike

IKE

This topic includes the following commands:

diagnose vpn ike config

IKE configuration.

diagnose vpn ike config

diagnose vpn ike config list

List IKE configuration.

diagnose vpn ike config list

diagnose vpn ike config list summary

List IKE configuration summary.

diagnose vpn ike config list summary

diagnose vpn ike counts

IKE object counts.

diagnose vpn ike counts

diagnose vpn ike crypto

IKE crypto diagnostics.

diagnose vpn ike crypto

diagnose vpn ike crypto stats

IKE crypto statistics.

diagnose vpn ike crypto stats

diagnose vpn ike errors

IKE statistics.

diagnose vpn ike errors

diagnose vpn ike filter

IKE filter.

diagnose vpn ike filter

diagnose vpn ike filter clear

Erase the current filter.

diagnose vpn ike filter clear

diagnose vpn ike filter dst-addr4

IPv4 destination address range to filter by.

diagnose vpn ike filter dst-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address (from).

string

<ipv4-address>

Destination IPv4 address (to).

string

diagnose vpn ike filter dst-addr6

IPv6 destination address range to filter by.

diagnose vpn ike filter dst-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address (from).

string

<ipv6-address>

Destination IPv6 address (to).

string

diagnose vpn ike filter dst-port

Destination port range to filter by.

diagnose vpn ike filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port.

string

diagnose vpn ike filter interface

Interface that IKE connection is negotiated over.

diagnose vpn ike filter interface <index>

Parameter

Description

Type

Size

<index>

Interface index, 0 matches all.

string

diagnose vpn ike filter list

Display the current filter.

diagnose vpn ike filter list

diagnose vpn ike filter name

Phase1 name to filter by.

diagnose vpn ike filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose vpn ike filter negate

Negate the specified filter parameter.

diagnose vpn ike filter negate

diagnose vpn ike filter negate dst-addr4

Negate IPv4 destination address.

diagnose vpn ike filter negate dst-addr4

diagnose vpn ike filter negate dst-addr6

Negate IPv6 destination address.

diagnose vpn ike filter negate dst-addr6

diagnose vpn ike filter negate dst-port

Negate destination port.

diagnose vpn ike filter negate dst-port

diagnose vpn ike filter negate interface

Negate interface.

diagnose vpn ike filter negate interface

diagnose vpn ike filter negate name

Negate name.

diagnose vpn ike filter negate name

diagnose vpn ike filter negate src-addr4

Negate IPv4 source address.

diagnose vpn ike filter negate src-addr4

diagnose vpn ike filter negate src-addr6

Negate IPv6 source address.

diagnose vpn ike filter negate src-addr6

diagnose vpn ike filter negate src-port

Negate source port.

diagnose vpn ike filter negate src-port

diagnose vpn ike filter negate vd

Negate virtual domain.

diagnose vpn ike filter negate vd

diagnose vpn ike filter src-addr4

IPv4 source address range to filter by.

diagnose vpn ike filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address (from).

string

<ipv4-address>

Source IPv4 address (to).

string

diagnose vpn ike filter src-addr6

IPv6 source address range to filter by.

diagnose vpn ike filter src-addr6 <ipv6-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address (from).

string

<ipv4-address>

Source IPv6 address (to).

string

diagnose vpn ike filter src-port

Source port range to filter by.

diagnose vpn ike filter src-port <port> <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

<port>

Source port (to).

string

diagnose vpn ike filter vd

Index of virtual domain. -1 matches all.

diagnose vpn ike filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose vpn ike fragmentation-override

Override IKE fragmentation.

diagnose vpn ike fragmentation-override <flags>

Parameter

Description

Type

Size

<flags>

Bitmask of fragmentation override flags.

string

diagnose vpn ike gateway

IKE gateways.

diagnose vpn ike gateway

diagnose vpn ike gateway clear

Clear IKE gateways.

diagnose vpn ike gateway clear

diagnose vpn ike gateway clear name

Clear gateway by name.

diagnose vpn ike gateway clear name <name>

Parameter

Description

Type

Size

<name>

Name of IKE gateway to clear.

string

diagnose vpn ike gateway flush

Synonym for clear.

diagnose vpn ike gateway flush

diagnose vpn ike gateway flush name

Clear gateway by name.

diagnose vpn ike gateway flush name <name>

Parameter

Description

Type

Size

<name>

Name of IKE gateway to clear.

string

diagnose vpn ike gateway list

list

diagnose vpn ike gateway list

diagnose vpn ike gateway list name

List gateway by name.

diagnose vpn ike gateway list name <name>

Parameter

Description

Type

Size

<name>

Name of IKE gateway to list.

string

diagnose vpn ike ikev2-cookie-enforce

Set IKEv2 SA_INIT cookie enforcement.

diagnose vpn ike ikev2-cookie-enforce <enforce>

Parameter

Description

Type

Size

<enforce>

Enable/Disable responder IKEv2 cookie.

string

diagnose vpn ike log

IKE debug log.

diagnose vpn ike log

diagnose vpn ike log filter

IKE debug log filter.

diagnose vpn ike log filter

diagnose vpn ike log filter clear

Erase the current filter.

diagnose vpn ike log filter clear

diagnose vpn ike log filter dst-addr4

IPv4 destination address range to filter by.

diagnose vpn ike log filter dst-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address (from).

string

<ipv4-address>

Destination IPv4 address (to).

string

diagnose vpn ike log filter dst-addr6

IPv6 destination address range to filter by.

diagnose vpn ike log filter dst-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address (from).

string

<ipv6-address>

Destination IPv6 address (to).

string

diagnose vpn ike log filter dst-port

Destination port range to filter by.

diagnose vpn ike log filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port.

string

diagnose vpn ike log filter interface

Interface that IKE connection is negotiated over.

diagnose vpn ike log filter interface <index>

Parameter

Description

Type

Size

<index>

Interface index, 0 matches all.

string

diagnose vpn ike log filter list

Display the current filter.

diagnose vpn ike log filter list

diagnose vpn ike log filter mdst-addr4

multiple IPv4 destination address to filter by.

diagnose vpn ike log filter mdst-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter mdst-addr6

multiple IPv6 destination addresses to filter by.

diagnose vpn ike log filter mdst-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter msrc-addr4

multiple IPv4 source address to filter by.

diagnose vpn ike log filter msrc-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter msrc-addr6

multiple IPv6 source address to filter by.

diagnose vpn ike log filter msrc-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter name

Phase1 name to filter by.

diagnose vpn ike log filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose vpn ike log filter negate

Negate the specified filter parameter.

diagnose vpn ike log filter negate

diagnose vpn ike log filter negate dst-addr4

Negate IPv4 destination address.

diagnose vpn ike log filter negate dst-addr4

diagnose vpn ike log filter negate dst-addr6

Negate IPv6 destination address.

diagnose vpn ike log filter negate dst-addr6

diagnose vpn ike log filter negate dst-port

Negate destination port.

diagnose vpn ike log filter negate dst-port

diagnose vpn ike log filter negate interface

Negate interface.

diagnose vpn ike log filter negate interface

diagnose vpn ike log filter negate mdst-addr4

Negate multiple IPv4 destination addresses.

diagnose vpn ike log filter negate mdst-addr4

diagnose vpn ike log filter negate mdst-addr6

Negate multiple IPv6 destination address.

diagnose vpn ike log filter negate mdst-addr6

diagnose vpn ike log filter negate msrc-addr4

Negate multiple IPv4 source addresses.

diagnose vpn ike log filter negate msrc-addr4

diagnose vpn ike log filter negate msrc-addr6

Negate multiple IPv6 source addresses.

diagnose vpn ike log filter negate msrc-addr6

diagnose vpn ike log filter negate name

Negate name.

diagnose vpn ike log filter negate name

diagnose vpn ike log filter negate src-addr4

Negate IPv4 source address.

diagnose vpn ike log filter negate src-addr4

diagnose vpn ike log filter negate src-addr6

Negate IPv6 source address.

diagnose vpn ike log filter negate src-addr6

diagnose vpn ike log filter negate src-port

Negate source port.

diagnose vpn ike log filter negate src-port

diagnose vpn ike log filter negate vd

Negate virtual domain.

diagnose vpn ike log filter negate vd

diagnose vpn ike log filter src-addr4

IPv4 source address range to filter by.

diagnose vpn ike log filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address (from).

string

<ipv4-address>

Source IPv4 address (to).

string

diagnose vpn ike log filter src-addr6

IPv6 source address range to filter by.

diagnose vpn ike log filter src-addr6 <ipv6-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address (from).

string

<ipv4-address>

Source IPv6 address (to).

string

diagnose vpn ike log filter src-port

Source port range to filter by.

diagnose vpn ike log filter src-port <port> <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

<port>

Source port (to).

string

diagnose vpn ike log filter vd

Index of virtual domain. -1 matches all.

diagnose vpn ike log filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose vpn ike log terminal

IKE debug log terminal statistics.

diagnose vpn ike log terminal

diagnose vpn ike log terminal clear

Clear IKE debug log terminals.

diagnose vpn ike log terminal clear

diagnose vpn ike log terminal reset

Reset IKE debug log terminals.

diagnose vpn ike log terminal reset

diagnose vpn ike log terminal stats

Show IKE debug log terminal statistics.

diagnose vpn ike log terminal stats

diagnose vpn ike log-filter

Alias for log filter.

diagnose vpn ike log-filter

diagnose vpn ike log-filter clear

Erase the current filter.

diagnose vpn ike log-filter clear

diagnose vpn ike log-filter dst-addr4

IPv4 destination address range to filter by.

diagnose vpn ike log-filter dst-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address (from).

string

<ipv4-address>

Destination IPv4 address (to).

string

diagnose vpn ike log-filter dst-addr6

IPv6 destination address range to filter by.

diagnose vpn ike log-filter dst-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address (from).

string

<ipv6-address>

Destination IPv6 address (to).

string

diagnose vpn ike log-filter dst-port

Destination port range to filter by.

diagnose vpn ike log-filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port.

string

diagnose vpn ike log-filter interface

Interface that IKE connection is negotiated over.

diagnose vpn ike log-filter interface <index>

Parameter

Description

Type

Size

<index>

Interface index, 0 matches all.

string

diagnose vpn ike log-filter list

Display the current filter.

diagnose vpn ike log-filter list

diagnose vpn ike log-filter mdst-addr4

multiple IPv4 destination address to filter by.

diagnose vpn ike log-filter mdst-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter mdst-addr6

multiple IPv6 destination addresses to filter by.

diagnose vpn ike log-filter mdst-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter msrc-addr4

multiple IPv4 source address to filter by.

diagnose vpn ike log-filter msrc-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter msrc-addr6

multiple IPv6 source address to filter by.

diagnose vpn ike log-filter msrc-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter name

Phase1 name to filter by.

diagnose vpn ike log-filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose vpn ike log-filter negate

Negate the specified filter parameter.

diagnose vpn ike log-filter negate

diagnose vpn ike log-filter negate dst-addr4

Negate IPv4 destination address.

diagnose vpn ike log-filter negate dst-addr4

diagnose vpn ike log-filter negate dst-addr6

Negate IPv6 destination address.

diagnose vpn ike log-filter negate dst-addr6

diagnose vpn ike log-filter negate dst-port

Negate destination port.

diagnose vpn ike log-filter negate dst-port

diagnose vpn ike log-filter negate interface

Negate interface.

diagnose vpn ike log-filter negate interface

diagnose vpn ike log-filter negate mdst-addr4

Negate multiple IPv4 destination addresses.

diagnose vpn ike log-filter negate mdst-addr4

diagnose vpn ike log-filter negate mdst-addr6

Negate multiple IPv6 destination address.

diagnose vpn ike log-filter negate mdst-addr6

diagnose vpn ike log-filter negate msrc-addr4

Negate multiple IPv4 source addresses.

diagnose vpn ike log-filter negate msrc-addr4

diagnose vpn ike log-filter negate msrc-addr6

Negate multiple IPv6 source addresses.

diagnose vpn ike log-filter negate msrc-addr6

diagnose vpn ike log-filter negate name

Negate name.

diagnose vpn ike log-filter negate name

diagnose vpn ike log-filter negate src-addr4

Negate IPv4 source address.

diagnose vpn ike log-filter negate src-addr4

diagnose vpn ike log-filter negate src-addr6

Negate IPv6 source address.

diagnose vpn ike log-filter negate src-addr6

diagnose vpn ike log-filter negate src-port

Negate source port.

diagnose vpn ike log-filter negate src-port

diagnose vpn ike log-filter negate vd

Negate virtual domain.

diagnose vpn ike log-filter negate vd

diagnose vpn ike log-filter src-addr4

IPv4 source address range to filter by.

diagnose vpn ike log-filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address (from).

string

<ipv4-address>

Source IPv4 address (to).

string

diagnose vpn ike log-filter src-addr6

IPv6 source address range to filter by.

diagnose vpn ike log-filter src-addr6 <ipv6-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address (from).

string

<ipv4-address>

Source IPv6 address (to).

string

diagnose vpn ike log-filter src-port

Source port range to filter by.

diagnose vpn ike log-filter src-port <port> <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

<port>

Source port (to).

string

diagnose vpn ike log-filter vd

Index of virtual domain. -1 matches all.

diagnose vpn ike log-filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose vpn ike restart

Restart IKE.

diagnose vpn ike restart

diagnose vpn ike routes

IKE routes.

diagnose vpn ike routes

diagnose vpn ike routes list

List IKE routes.

diagnose vpn ike routes list

diagnose vpn ike stats

IKE statistics.

diagnose vpn ike stats

diagnose vpn ike status

IKE status.

diagnose vpn ike status

diagnose vpn ike status detailed

Detailed status.

diagnose vpn ike status detailed

diagnose vpn ike status summary

Status summary.

diagnose vpn ike status summary

diagnose vpn ike valgrind

Valgrind analysis.

diagnose vpn ike valgrind

diagnose vpn ike valgrind disable

Force daemon to restart.

diagnose vpn ike valgrind disable

diagnose vpn ike valgrind enable

Force daemon to restart.

diagnose vpn ike valgrind enable

diagnose vpn ike valgrind log

Valgrind logs.

diagnose vpn ike valgrind log

diagnose vpn ike valgrind log clear

Clear logs.

diagnose vpn ike valgrind log clear

diagnose vpn ike valgrind log show

Show logs.

diagnose vpn ike valgrind log show

diagnose vpn ike valgrind memcheck

Force daemon to restart.

diagnose vpn ike valgrind memcheck

diagnose vpn ike valgrind memcheck_less

Force daemon to restart.

diagnose vpn ike valgrind memcheck_less

diagnose vpn ike valgrind status

Show valgrind status.

diagnose vpn ike valgrind status

diagnose vpn ike

diagnose vpn ike

IKE

This topic includes the following commands:

diagnose vpn ike config

IKE configuration.

diagnose vpn ike config

diagnose vpn ike config list

List IKE configuration.

diagnose vpn ike config list

diagnose vpn ike config list summary

List IKE configuration summary.

diagnose vpn ike config list summary

diagnose vpn ike counts

IKE object counts.

diagnose vpn ike counts

diagnose vpn ike crypto

IKE crypto diagnostics.

diagnose vpn ike crypto

diagnose vpn ike crypto stats

IKE crypto statistics.

diagnose vpn ike crypto stats

diagnose vpn ike errors

IKE statistics.

diagnose vpn ike errors

diagnose vpn ike filter

IKE filter.

diagnose vpn ike filter

diagnose vpn ike filter clear

Erase the current filter.

diagnose vpn ike filter clear

diagnose vpn ike filter dst-addr4

IPv4 destination address range to filter by.

diagnose vpn ike filter dst-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address (from).

string

<ipv4-address>

Destination IPv4 address (to).

string

diagnose vpn ike filter dst-addr6

IPv6 destination address range to filter by.

diagnose vpn ike filter dst-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address (from).

string

<ipv6-address>

Destination IPv6 address (to).

string

diagnose vpn ike filter dst-port

Destination port range to filter by.

diagnose vpn ike filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port.

string

diagnose vpn ike filter interface

Interface that IKE connection is negotiated over.

diagnose vpn ike filter interface <index>

Parameter

Description

Type

Size

<index>

Interface index, 0 matches all.

string

diagnose vpn ike filter list

Display the current filter.

diagnose vpn ike filter list

diagnose vpn ike filter name

Phase1 name to filter by.

diagnose vpn ike filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose vpn ike filter negate

Negate the specified filter parameter.

diagnose vpn ike filter negate

diagnose vpn ike filter negate dst-addr4

Negate IPv4 destination address.

diagnose vpn ike filter negate dst-addr4

diagnose vpn ike filter negate dst-addr6

Negate IPv6 destination address.

diagnose vpn ike filter negate dst-addr6

diagnose vpn ike filter negate dst-port

Negate destination port.

diagnose vpn ike filter negate dst-port

diagnose vpn ike filter negate interface

Negate interface.

diagnose vpn ike filter negate interface

diagnose vpn ike filter negate name

Negate name.

diagnose vpn ike filter negate name

diagnose vpn ike filter negate src-addr4

Negate IPv4 source address.

diagnose vpn ike filter negate src-addr4

diagnose vpn ike filter negate src-addr6

Negate IPv6 source address.

diagnose vpn ike filter negate src-addr6

diagnose vpn ike filter negate src-port

Negate source port.

diagnose vpn ike filter negate src-port

diagnose vpn ike filter negate vd

Negate virtual domain.

diagnose vpn ike filter negate vd

diagnose vpn ike filter src-addr4

IPv4 source address range to filter by.

diagnose vpn ike filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address (from).

string

<ipv4-address>

Source IPv4 address (to).

string

diagnose vpn ike filter src-addr6

IPv6 source address range to filter by.

diagnose vpn ike filter src-addr6 <ipv6-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address (from).

string

<ipv4-address>

Source IPv6 address (to).

string

diagnose vpn ike filter src-port

Source port range to filter by.

diagnose vpn ike filter src-port <port> <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

<port>

Source port (to).

string

diagnose vpn ike filter vd

Index of virtual domain. -1 matches all.

diagnose vpn ike filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose vpn ike fragmentation-override

Override IKE fragmentation.

diagnose vpn ike fragmentation-override <flags>

Parameter

Description

Type

Size

<flags>

Bitmask of fragmentation override flags.

string

diagnose vpn ike gateway

IKE gateways.

diagnose vpn ike gateway

diagnose vpn ike gateway clear

Clear IKE gateways.

diagnose vpn ike gateway clear

diagnose vpn ike gateway clear name

Clear gateway by name.

diagnose vpn ike gateway clear name <name>

Parameter

Description

Type

Size

<name>

Name of IKE gateway to clear.

string

diagnose vpn ike gateway flush

Synonym for clear.

diagnose vpn ike gateway flush

diagnose vpn ike gateway flush name

Clear gateway by name.

diagnose vpn ike gateway flush name <name>

Parameter

Description

Type

Size

<name>

Name of IKE gateway to clear.

string

diagnose vpn ike gateway list

list

diagnose vpn ike gateway list

diagnose vpn ike gateway list name

List gateway by name.

diagnose vpn ike gateway list name <name>

Parameter

Description

Type

Size

<name>

Name of IKE gateway to list.

string

diagnose vpn ike ikev2-cookie-enforce

Set IKEv2 SA_INIT cookie enforcement.

diagnose vpn ike ikev2-cookie-enforce <enforce>

Parameter

Description

Type

Size

<enforce>

Enable/Disable responder IKEv2 cookie.

string

diagnose vpn ike log

IKE debug log.

diagnose vpn ike log

diagnose vpn ike log filter

IKE debug log filter.

diagnose vpn ike log filter

diagnose vpn ike log filter clear

Erase the current filter.

diagnose vpn ike log filter clear

diagnose vpn ike log filter dst-addr4

IPv4 destination address range to filter by.

diagnose vpn ike log filter dst-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address (from).

string

<ipv4-address>

Destination IPv4 address (to).

string

diagnose vpn ike log filter dst-addr6

IPv6 destination address range to filter by.

diagnose vpn ike log filter dst-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address (from).

string

<ipv6-address>

Destination IPv6 address (to).

string

diagnose vpn ike log filter dst-port

Destination port range to filter by.

diagnose vpn ike log filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port.

string

diagnose vpn ike log filter interface

Interface that IKE connection is negotiated over.

diagnose vpn ike log filter interface <index>

Parameter

Description

Type

Size

<index>

Interface index, 0 matches all.

string

diagnose vpn ike log filter list

Display the current filter.

diagnose vpn ike log filter list

diagnose vpn ike log filter mdst-addr4

multiple IPv4 destination address to filter by.

diagnose vpn ike log filter mdst-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter mdst-addr6

multiple IPv6 destination addresses to filter by.

diagnose vpn ike log filter mdst-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter msrc-addr4

multiple IPv4 source address to filter by.

diagnose vpn ike log filter msrc-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter msrc-addr6

multiple IPv6 source address to filter by.

diagnose vpn ike log filter msrc-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log filter name

Phase1 name to filter by.

diagnose vpn ike log filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose vpn ike log filter negate

Negate the specified filter parameter.

diagnose vpn ike log filter negate

diagnose vpn ike log filter negate dst-addr4

Negate IPv4 destination address.

diagnose vpn ike log filter negate dst-addr4

diagnose vpn ike log filter negate dst-addr6

Negate IPv6 destination address.

diagnose vpn ike log filter negate dst-addr6

diagnose vpn ike log filter negate dst-port

Negate destination port.

diagnose vpn ike log filter negate dst-port

diagnose vpn ike log filter negate interface

Negate interface.

diagnose vpn ike log filter negate interface

diagnose vpn ike log filter negate mdst-addr4

Negate multiple IPv4 destination addresses.

diagnose vpn ike log filter negate mdst-addr4

diagnose vpn ike log filter negate mdst-addr6

Negate multiple IPv6 destination address.

diagnose vpn ike log filter negate mdst-addr6

diagnose vpn ike log filter negate msrc-addr4

Negate multiple IPv4 source addresses.

diagnose vpn ike log filter negate msrc-addr4

diagnose vpn ike log filter negate msrc-addr6

Negate multiple IPv6 source addresses.

diagnose vpn ike log filter negate msrc-addr6

diagnose vpn ike log filter negate name

Negate name.

diagnose vpn ike log filter negate name

diagnose vpn ike log filter negate src-addr4

Negate IPv4 source address.

diagnose vpn ike log filter negate src-addr4

diagnose vpn ike log filter negate src-addr6

Negate IPv6 source address.

diagnose vpn ike log filter negate src-addr6

diagnose vpn ike log filter negate src-port

Negate source port.

diagnose vpn ike log filter negate src-port

diagnose vpn ike log filter negate vd

Negate virtual domain.

diagnose vpn ike log filter negate vd

diagnose vpn ike log filter src-addr4

IPv4 source address range to filter by.

diagnose vpn ike log filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address (from).

string

<ipv4-address>

Source IPv4 address (to).

string

diagnose vpn ike log filter src-addr6

IPv6 source address range to filter by.

diagnose vpn ike log filter src-addr6 <ipv6-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address (from).

string

<ipv4-address>

Source IPv6 address (to).

string

diagnose vpn ike log filter src-port

Source port range to filter by.

diagnose vpn ike log filter src-port <port> <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

<port>

Source port (to).

string

diagnose vpn ike log filter vd

Index of virtual domain. -1 matches all.

diagnose vpn ike log filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose vpn ike log terminal

IKE debug log terminal statistics.

diagnose vpn ike log terminal

diagnose vpn ike log terminal clear

Clear IKE debug log terminals.

diagnose vpn ike log terminal clear

diagnose vpn ike log terminal reset

Reset IKE debug log terminals.

diagnose vpn ike log terminal reset

diagnose vpn ike log terminal stats

Show IKE debug log terminal statistics.

diagnose vpn ike log terminal stats

diagnose vpn ike log-filter

Alias for log filter.

diagnose vpn ike log-filter

diagnose vpn ike log-filter clear

Erase the current filter.

diagnose vpn ike log-filter clear

diagnose vpn ike log-filter dst-addr4

IPv4 destination address range to filter by.

diagnose vpn ike log-filter dst-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address (from).

string

<ipv4-address>

Destination IPv4 address (to).

string

diagnose vpn ike log-filter dst-addr6

IPv6 destination address range to filter by.

diagnose vpn ike log-filter dst-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address (from).

string

<ipv6-address>

Destination IPv6 address (to).

string

diagnose vpn ike log-filter dst-port

Destination port range to filter by.

diagnose vpn ike log-filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port.

string

diagnose vpn ike log-filter interface

Interface that IKE connection is negotiated over.

diagnose vpn ike log-filter interface <index>

Parameter

Description

Type

Size

<index>

Interface index, 0 matches all.

string

diagnose vpn ike log-filter list

Display the current filter.

diagnose vpn ike log-filter list

diagnose vpn ike log-filter mdst-addr4

multiple IPv4 destination address to filter by.

diagnose vpn ike log-filter mdst-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Destination IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Destination IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter mdst-addr6

multiple IPv6 destination addresses to filter by.

diagnose vpn ike log-filter mdst-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Destination IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Destination IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter msrc-addr4

multiple IPv4 source address to filter by.

diagnose vpn ike log-filter msrc-addr4 <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address 1, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 2, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 3, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 4, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 5, up to 6 IP addresses

string

<ipv4-address>

Source IPv4 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter msrc-addr6

multiple IPv6 source address to filter by.

diagnose vpn ike log-filter msrc-addr6 <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address 1, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 2, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 3, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 4, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 5, up to 6 IP addresses

string

<ipv6-address>

Source IPv6 address 6, up to 6 IP addresses

string

diagnose vpn ike log-filter name

Phase1 name to filter by.

diagnose vpn ike log-filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose vpn ike log-filter negate

Negate the specified filter parameter.

diagnose vpn ike log-filter negate

diagnose vpn ike log-filter negate dst-addr4

Negate IPv4 destination address.

diagnose vpn ike log-filter negate dst-addr4

diagnose vpn ike log-filter negate dst-addr6

Negate IPv6 destination address.

diagnose vpn ike log-filter negate dst-addr6

diagnose vpn ike log-filter negate dst-port

Negate destination port.

diagnose vpn ike log-filter negate dst-port

diagnose vpn ike log-filter negate interface

Negate interface.

diagnose vpn ike log-filter negate interface

diagnose vpn ike log-filter negate mdst-addr4

Negate multiple IPv4 destination addresses.

diagnose vpn ike log-filter negate mdst-addr4

diagnose vpn ike log-filter negate mdst-addr6

Negate multiple IPv6 destination address.

diagnose vpn ike log-filter negate mdst-addr6

diagnose vpn ike log-filter negate msrc-addr4

Negate multiple IPv4 source addresses.

diagnose vpn ike log-filter negate msrc-addr4

diagnose vpn ike log-filter negate msrc-addr6

Negate multiple IPv6 source addresses.

diagnose vpn ike log-filter negate msrc-addr6

diagnose vpn ike log-filter negate name

Negate name.

diagnose vpn ike log-filter negate name

diagnose vpn ike log-filter negate src-addr4

Negate IPv4 source address.

diagnose vpn ike log-filter negate src-addr4

diagnose vpn ike log-filter negate src-addr6

Negate IPv6 source address.

diagnose vpn ike log-filter negate src-addr6

diagnose vpn ike log-filter negate src-port

Negate source port.

diagnose vpn ike log-filter negate src-port

diagnose vpn ike log-filter negate vd

Negate virtual domain.

diagnose vpn ike log-filter negate vd

diagnose vpn ike log-filter src-addr4

IPv4 source address range to filter by.

diagnose vpn ike log-filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

Source IPv4 address (from).

string

<ipv4-address>

Source IPv4 address (to).

string

diagnose vpn ike log-filter src-addr6

IPv6 source address range to filter by.

diagnose vpn ike log-filter src-addr6 <ipv6-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv6-address>

Source IPv6 address (from).

string

<ipv4-address>

Source IPv6 address (to).

string

diagnose vpn ike log-filter src-port

Source port range to filter by.

diagnose vpn ike log-filter src-port <port> <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

<port>

Source port (to).

string

diagnose vpn ike log-filter vd

Index of virtual domain. -1 matches all.

diagnose vpn ike log-filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose vpn ike restart

Restart IKE.

diagnose vpn ike restart

diagnose vpn ike routes

IKE routes.

diagnose vpn ike routes

diagnose vpn ike routes list

List IKE routes.

diagnose vpn ike routes list

diagnose vpn ike stats

IKE statistics.

diagnose vpn ike stats

diagnose vpn ike status

IKE status.

diagnose vpn ike status

diagnose vpn ike status detailed

Detailed status.

diagnose vpn ike status detailed

diagnose vpn ike status summary

Status summary.

diagnose vpn ike status summary

diagnose vpn ike valgrind

Valgrind analysis.

diagnose vpn ike valgrind

diagnose vpn ike valgrind disable

Force daemon to restart.

diagnose vpn ike valgrind disable

diagnose vpn ike valgrind enable

Force daemon to restart.

diagnose vpn ike valgrind enable

diagnose vpn ike valgrind log

Valgrind logs.

diagnose vpn ike valgrind log

diagnose vpn ike valgrind log clear

Clear logs.

diagnose vpn ike valgrind log clear

diagnose vpn ike valgrind log show

Show logs.

diagnose vpn ike valgrind log show

diagnose vpn ike valgrind memcheck

Force daemon to restart.

diagnose vpn ike valgrind memcheck

diagnose vpn ike valgrind memcheck_less

Force daemon to restart.

diagnose vpn ike valgrind memcheck_less

diagnose vpn ike valgrind status

Show valgrind status.

diagnose vpn ike valgrind status