Troubleshoot geolocation-based access control policies

This topic provides syslogs and CLI commands to troubleshoot geolocation-based access control policies using Threat Defense devices.

Syslogs

To enable syslogs for remote access VPN service access policies, perform these steps:

  1. Choose Devices > Platform Settings.

  2. Create a platform settings policy, or edit an existing one.

  3. In the left pane, click Syslog.

  4. Click the Logging Setup tab and check the Enable Logging check box.

  5. Click the Syslog Settings tab and enable the syslogs for service access syslog 751031 and 716166.

CLI commands

  • Use the show running-config service-access , and show service-access commands to view details of user-defined service access policies.

  • Use the show geodb command to view details of the geolocation table.

  • Use the debug geolocation <debug-level> command to capture debug logs for geolocation. The debug levels are 1 (Error), 2 (Warning), 3 and 4 (Info), 5 (Debug), or 255 (Debug all).

  • Use the clear geodb counters command to clear the geolocation table counters such as the hit counts of the service access policies. To clear the permitted and denied counters for locations, reboot the device. The command does not clear these counters.