From 469cd1de9f904bcc451379316f39f7ef34f0eca0 Mon Sep 17 00:00:00 2001 From: Christian Poessinger Date: Sat, 3 Jul 2021 17:47:52 +0200 Subject: ipsec: T2816: rework log options for debugging Renamed CLI from "logging log-modes" to "log subsystem" and "logging log-level" to "log level". THat is more human firendly. --- interface-definitions/vpn_ipsec.xml.in | 57 ++++++++++++++++++++-------------- 1 file changed, 33 insertions(+), 24 deletions(-) (limited to 'interface-definitions') diff --git a/interface-definitions/vpn_ipsec.xml.in b/interface-definitions/vpn_ipsec.xml.in index a2e9a7a5a..fdd091dd9 100644 --- a/interface-definitions/vpn_ipsec.xml.in +++ b/interface-definitions/vpn_ipsec.xml.in @@ -525,100 +525,109 @@ - + IPsec logging - + strongSwan Logger Level - u32:0-2 - Logger Verbosity Level (default 0) + u32:0 + Very basic auditing logs e.g. SA up/SA down (default) + + + u32:1 + Generic control flow with errors, a good default to see whats going on + + + u32:2 + More detailed debugging control flow + 0 - + - Log mode. To see what each log mode exactly does, please refer to the strongSwan documentation + Subsystem in the daemon the log comes from dmn mgr ike chd job cfg knl net asn enc lib esp tls tnc imc imv pts any dmn - Debug log option for strongSwan + Main daemon setup/cleanup/signal handling mgr - Debug log option for strongSwan + IKE_SA manager, handling synchronization for IKE_SA access ike - Debug log option for strongSwan + IKE_SA/ISAKMP SA chd - Debug log option for strongSwan + CHILD_SA/IPsec SA job - Debug log option for strongSwan + Jobs queuing/processing and thread pool management cfg - Debug log option for strongSwan + Configuration management and plugins knl - Debug log option for strongSwan + IPsec/Networking kernel interface net - Debug log option for strongSwan + IKE network communication asn - Debug log option for strongSwan + Low-level encoding/decoding (ASN.1, X.509 etc.) enc - Debug log option for strongSwan + Packet encoding/decoding encryption/decryption operations lib - Debug log option for strongSwan + libstrongswan library messages esp - Debug log option for strongSwan + libipsec library messages tls - Debug log option for strongSwan + libtls library messages tnc - Debug log option for strongSwan + Trusted Network Connect imc - Debug log option for strongSwan + Integrity Measurement Collector imv - Debug log option for strongSwan + Integrity Measurement Verifier pts - Debug log option for strongSwan + Platform Trust Service any - Debug log option for strongSwan + Any subsystem ^(dmn|mgr|ike|chd|job|cfg|knl|net|asn|enc|lib|esp|tls|tnc|imc|imv|pts|any)$ -- cgit v1.2.3