Fortinet black logo
7.2.0

Debugging

Debugging

FNC-CA

Use the following KB article to gather the appropriate logs using the debugs below.

Gather logs for debugging and troubleshooting

Note: Debugs disable automatically upon restart of FortiNAC control and management processes.

Function Syntax Log File
Syslog activity nacdebug –name SyslogServer true /bsc/logs/output.master
Persistent Agent activity nacdebug -name PersistentAgent true /bsc/logs/output.nessus
Dissolvable Agent activity nacdebug -name AgentServer true /bsc/logs/output.nessus
VPN activity nacdebug -name RemoteAccess true /bsc/logs/output.master
PaloAlto nacdebug -name PaloAlto true /bsc/logs/output.master
VPN activity
Disable debug nacdebug –name <debug name> false N/A

device –ip <Palo Alto IP> -setAttr -name DEBUG "ForwardingInterface"

FNC-CAX

Use the following KB article to gather the appropriate logs using the debugs below.

Gather logs for debugging and troubleshooting

Note: Debugs disable automatically upon restart of FortiNAC control and management processes.

Function Syntax Log File
Syslog activity diagnose debug plugin enable SyslogServer /bsc/logs/output.master
Persistent Agent activity nacdebug -name PersistentAgent /bsc/logs/output.nessus
Dissolvable Agent activity nacdebug -name AgentServer /bsc/logs/output.nessus
VPN activity nacdebug -name RemoteAccess /bsc/logs/output.master
PaloAlto nacdebug -name PaloAlto /bsc/logs/output.master
VPN activity
Disable debug diagnose debug plugin disable <debug name> N/A

device –ip <Palo Alto IP> -setAttr -name DEBUG "ForwardingInterface"

Debugging

FNC-CA

Use the following KB article to gather the appropriate logs using the debugs below.

Gather logs for debugging and troubleshooting

Note: Debugs disable automatically upon restart of FortiNAC control and management processes.

Function Syntax Log File
Syslog activity nacdebug –name SyslogServer true /bsc/logs/output.master
Persistent Agent activity nacdebug -name PersistentAgent true /bsc/logs/output.nessus
Dissolvable Agent activity nacdebug -name AgentServer true /bsc/logs/output.nessus
VPN activity nacdebug -name RemoteAccess true /bsc/logs/output.master
PaloAlto nacdebug -name PaloAlto true /bsc/logs/output.master
VPN activity
Disable debug nacdebug –name <debug name> false N/A

device –ip <Palo Alto IP> -setAttr -name DEBUG "ForwardingInterface"

FNC-CAX

Use the following KB article to gather the appropriate logs using the debugs below.

Gather logs for debugging and troubleshooting

Note: Debugs disable automatically upon restart of FortiNAC control and management processes.

Function Syntax Log File
Syslog activity diagnose debug plugin enable SyslogServer /bsc/logs/output.master
Persistent Agent activity nacdebug -name PersistentAgent /bsc/logs/output.nessus
Dissolvable Agent activity nacdebug -name AgentServer /bsc/logs/output.nessus
VPN activity nacdebug -name RemoteAccess /bsc/logs/output.master
PaloAlto nacdebug -name PaloAlto /bsc/logs/output.master
VPN activity
Disable debug diagnose debug plugin disable <debug name> N/A

device –ip <Palo Alto IP> -setAttr -name DEBUG "ForwardingInterface"