cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
214
Views
1
Helpful
7
Replies

debug crypto on firepower managed by FMC

michael18
Level 1
Level 1

how do you see output on a Firepower cli that is manged by FMC. Im trying to run debug crypto ikev2 protocol and platform. I dont see any messages in the FMC syslog

7 Replies 7

Thanks for the info. Ill take a look at that document.

in diag CLI, when I enable the debug I get response:


  INFO: 'logging debug-trace' is enabled. All debug messages are currently being redirected to syslog:711001 and will not appear in any monitor session

When i look in FMC syslog I dont see any info relating to the VPN im looking at

the logging level was set to errors. ive updated this to debugging but still dont see anything in FMC syslogs.

michael18_0-1726144312547.png

michael18_1-1726144408248.png

how do I enable monitor logging so i can see debug on local CLI

Thanks

 



I reply to your Q below 
you need to clear crypto to see new IPsec VPN in CLI

MHM

711001 is level 7 so you need to config FMC platform setting syslog to use level 7

and it not appear in CLI meaning there is no new IPsec phase1 and phase2 exhange between peer 

you need to force peer to re-exchange ipsec by clear crypto sa 
MHM