18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Appendix F: Basic Troubleshooting<br />

Troubleshooting proxy rules<br />

658<br />

cf acl set loglevel=4<br />

This increases the level <strong>of</strong> rule audits from the default level 2 (minor) to<br />

level 4 (major).<br />

Note: Modifications to the log level setting will not be overwritten if acld is<br />

restarted. To return the log level to its default value, you must manually reset it.<br />

When the connection attempt is rejected, the proxy or server will generate a<br />

more verbose audit message as shown below:<br />

May 5 02:37:42 2002 CDT f_ping_proxy a_aclquery t_info<br />

p_major<br />

pid: 184 ruid: 0 euid: 0 pgid: 184 fid: 2000001 logid: 0<br />

cmd: 'pingp'<br />

domain: Ping edomain: Ping<br />

+|pingp|INFO|MAJOR|PING_PROXY|aclQUERY<br />

=Skipped 'http_out': query service 'ping' != rule 'http'.<br />

Skipped 'telnet_external': query agent 'proxy' != rule<br />

'server'.<br />

Skipped 'http_ssl_out': query service 'ping' != rule<br />

'https'.<br />

Skipped 'ftp_out': query service 'ping' != rule 'ftp'.<br />

Skipped 'telnet_out': query service 'ping' != rule<br />

'telnet'.<br />

Skipped 'nntp_out': query service 'ping' != rule 'nntp'.<br />

Skipped 'real_media_out': query service 'ping' != rule<br />

'RealMedia'.<br />

Skipped 'rtsp_out': query service 'ping' != rule 'rtsp'.<br />

Skipped 'gopher_out': query service 'ping' != rule<br />

'gopher'.<br />

Skipped 'finger_out': query service 'ping' != rule<br />

'finger'.<br />

Skipped 'dns_self': query service 'ping' != rule 'dns'.<br />

Skipped 'smtp_out': query service 'ping' != rule 'smtp'.<br />

Skipped 'smtp_in': query service 'ping' != rule 'smtp'.<br />

Skipped 'cobra_all': query agent 'proxy' != rule<br />

'server'.<br />

Skipped 'login_console': query agent 'proxy' != rule<br />

'server'.<br />

Access denied by rule 'deny_all'.<br />

You can use this output to determine why each proxy rule failed to match<br />

the connection request. Locate the proxy rule that you thought should have<br />

matched. Then inspect and correct the proxy rule.<br />

6 When you are done troubleshooting, type the following command to lower<br />

the level <strong>of</strong> rule audits back to the default:<br />

cf acl set loglevel=2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!