Troubleshoot remote access VPNs

This topic provides troubleshooting methods for remote access VPNs using logs, debug commands, DART diagnostics, and AAA server connectivity commands.

Use troubleshooting logs

To view remote access VPN logs, choose Troubleshooting > + Show more > Advanced > Troubleshooting Logs. To view these logs, you must configure the syslog settings in the Firewall Threat Defense device. For more information about configuring syslog settings in the device, refer to Monitor denied remote access VPN sessions.

Use debug commands

Caution

Debug output is CPU-intensive and can make the system unusable. Follow these guidelines when using debug commands:

  • Use these commands only when troubleshooting specific problems or working with Cisco TAC.

  • Run debug commands during periods of low network traffic and minimal user activity to reduce processing overhead.

The table lists debug commands for remote access VPN.

CLI Command

Description

system support diagnostic-CLI

Log in to Firewall Threat Defense Lina CLI.

debug webvpn

Debugs WebVPN configurations.

debug SSL

Debugs SSL sessions.

debug crypto ipsec

Debugs IPsec configurations.

debug crypto ikev2

Debugs IKEv2 configurations.

debug crypto ikev1

Debugs IKEv1 configurations.

debug crypto CA

Debugs CA operations.

Use DART to troubleshoot Secure Client issues

Use the Secure Client Diagnostics and Reporting Tool (DART) to collect diagnostic data for troubleshooting Secure Client installation and connection issues.

Use commands to troubleshoot AAA server connectivity

The table lists debug commands to troubleshoot AAA server connectivity in remote access VPN connections.

CLI Command

Description

show AAA-server

Displays AAA server statistics.

show network

Displays IP address settings, DNS, and management details.

show network-static-routes

Displays the management interface default route and static routes.

show route

Displays data traffic routing table entries.

ping system and traceroute system

Verifies the path to the AAA server through the management interface.

ping interface and traceroute

Verifies the path to the AAA server through the data interfaces.

test AAA-server authentication and test AAA-server authorization

Tests authentication and authorization on the AAA server.

clear AAA-server statistics or clear AAA-server statistics protocol

Clears AAA server statistics by group or protocol.

AAA-server groupname activehosthostname

Activates a failed AAA server.

AAA-servergroupnamefailhosthostname

Marks a AAA server as failed.

debug LDAP

Debugs LDAP issues.

debug AAA authentication

Debugs AAA authentication.

debug AAA authorization

Debugs AAA authorization.

debug AAA accounting

Debugs AAA accounting.