1
<?xml version="1.0" encoding="ISO-8859-1"?>
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.1.2//EN"
3
"http://www.oasis-open.org/docbook/xml/4.1.2/docbookx.dtd">
4
<!-- lifted from troff+man by doclifter -->
7
<refentrytitle>IPSEC_KLIPSDEBUG</refentrytitle>
8
<manvolnum>8</manvolnum>
9
<refmiscinfo class='date'>21 Jun 2000</refmiscinfo>
11
<refnamediv id='name'>
12
<refname>ipsec klipsdebug</refname>
13
<refpurpose>set KLIPS (kernel IPSEC support) debug features and level</refpurpose>
15
<!-- body begins here -->
16
<refsynopsisdiv id='synopsis'>
18
<command>ipsec</command>
19
<arg choice='plain'><replaceable>klipsdebug</replaceable></arg>
21
<arg choice='plain'><replaceable>ipsecklipsdebug</replaceable></arg>
22
<arg choice='plain'>--set </arg>
23
<arg choice='plain'><replaceable>flagname</replaceable></arg>
25
<arg choice='plain'><replaceable>ipsecklipsdebug</replaceable></arg>
26
<arg choice='plain'>--clear </arg>
27
<arg choice='plain'><replaceable>flagname</replaceable></arg>
29
<arg choice='plain'><replaceable>ipsecklipsdebug</replaceable></arg>
30
<arg choice='plain'>--all </arg>
32
<arg choice='plain'><replaceable>ipsecklipsdebug</replaceable></arg>
33
<arg choice='plain'>--none </arg>
35
<arg choice='plain'><replaceable>ipsecklipsdebug</replaceable></arg>
36
<arg choice='plain'>--help </arg>
38
<arg choice='plain'><replaceable>ipsecklipsdebug</replaceable></arg>
39
<arg choice='plain'>--version </arg>
44
<refsect1 id='description'><title>DESCRIPTION</title>
45
<para><emphasis remap='I'>Klipsdebug</emphasis>
46
sets and clears flags that control
47
various parts of the debugging output of Klips
48
(the kernel portion of FreeS/WAN IPSEC).
49
The form with no additional arguments lists the present contents of
50
/proc/net/ipsec_klipsdebug.
52
<option>--set</option>
53
form turns the specified flag on,
55
<option>--clear</option>
56
form turns the specified flag off.
58
<option>--all</option>
60
turns all flags on except verbose, while the
61
<option>--none</option>
62
form turns all flags off.</para>
64
<para>The current flag names are:</para>
65
<variablelist remap='TP'>
67
<term><emphasis remap='B'>tunnel</emphasis></term>
69
<para>tunnelling code</para>
73
<term><emphasis remap='B'>tunnel-xmit</emphasis></term>
75
<para>tunnelling transmit only code</para>
79
<term><emphasis remap='B'>pfkey</emphasis></term>
81
<para>userspace communication code</para>
85
<term><emphasis remap='B'>xform</emphasis></term>
87
<para>transform selection and manipulation code</para>
91
<term><emphasis remap='B'>eroute</emphasis></term>
93
<para>eroute table manipulation code</para>
97
<term><emphasis remap='B'>spi</emphasis></term>
99
<para>SA table manipulation code</para>
103
<term><emphasis remap='B'>radij</emphasis></term>
105
<para>radij tree manipulation code</para>
109
<term><emphasis remap='B'>esp</emphasis></term>
111
<para>encryptions transforms code</para>
115
<term><emphasis remap='B'>ah</emphasis></term>
117
<para>authentication transforms code
118
<emphasis remap='B'>rcv</emphasis>
123
<term><emphasis remap='B'>ipcomp</emphasis></term>
125
<para>ip compression transforms code</para>
129
<term><emphasis remap='B'>verbose</emphasis></term>
131
<para>give even more information, BEWARE:
132
a)this will print authentication and encryption keys in the logs
133
b)this will probably trample the 4k kernel printk buffer giving inaccurate output</para>
138
<para>All Klips debug output appears as
139
<emphasis remap='B'>kernel.info</emphasis>
141
<citerefentry><refentrytitle>syslogd</refentrytitle><manvolnum>8</manvolnum></citerefentry>.
142
Most systems are set up
143
to log these messages to
144
<filename>/var/log/messages</filename>.
146
<emphasis remap='B'>klipsdebug</emphasis>
147
<option>--all</option>
148
produces a lot of output and the log file will grow quickly.</para>
150
<para>The file format for /proc/net/ipsec_klipsdebug is discussed in
151
ipsec_klipsdebug(5).</para>
154
<refsect1 id='examples'><title>EXAMPLES</title>
155
<variablelist remap='TP'>
157
<term><userinput>klipsdebug --all</userinput></term>
159
<para>turns on all KLIPS debugging except verbose.</para>
163
<term><userinput>klipsdebug --clear tunnel</userinput></term>
165
<para>turns off only the
166
<emphasis remap='B'>tunnel</emphasis>
167
debugging messages.</para>
174
<refsect1 id='files'><title>FILES</title>
175
<para>/proc/net/ipsec_klipsdebug, /usr/local/bin/ipsec</para>
178
<refsect1 id='see_also'><title>SEE ALSO</title>
179
<para>ipsec(8), ipsec_manual(8), ipsec_tncfg(8), ipsec_eroute(8),
180
ipsec_spi(8), ipsec_spigrp(8), ipsec_klipsdebug(5)</para>
183
<refsect1 id='history'><title>HISTORY</title>
184
<para>Written for the Linux FreeS/WAN project
185
<<ulink url='http://www.freeswan.org/'>http://www.freeswan.org/</ulink>>
186
by Richard Guy Briggs.</para>
189
<refsect1 id='bugs'><title>BUGS</title>
190
<para>It really ought to be possible to set or unset selective combinations
193
<!-- $Log: klipsdebug.8.xml,v $
194
<!-- Revision 1.1 2004/05/26 17:49:20 ken
195
<!-- Import XML version
197
<!-- Revision 1.18 2002/04/24 07:35:39 mcr -->
198
<!-- Moved from ./klips/utils/klipsdebug.8,v -->
200
<!-- Revision 1.17 2000/10/10 20:10:19 rgb -->
201
<!-- Added support for debug_ipcomp and debug_verbose to klipsdebug. -->
203
<!-- Revision 1.16 2000/08/18 17:33:11 rgb -->
204
<!-- Updated obsolete netlink reference and added pfkey and tunnel\-xmit. -->
206
<!-- Revision 1.15 2000/06/30 18:21:55 rgb -->
207
<!-- Update SEE ALSO sections to include <citerefentry><refentrytitle>ipsec_version</refentrytitle><manvolnum>5</manvolnum></citerefentry> and <citerefentry><refentrytitle>ipsec_pf_key</refentrytitle><manvolnum>5</manvolnum></citerefentry> -->
208
<!-- and correct FILES sections to no longer refer to /dev/ipsec which has -->
209
<!-- been removed since PF_KEY does not use it. -->
211
<!-- Revision 1.14 2000/06/28 05:53:09 rgb -->
212
<!-- Mention that netlink is obsolete. -->
214
<!-- Revision 1.13 2000/06/21 16:54:58 rgb -->
215
<!-- Added 'no additional args' text for listing contents of -->
216
<!-- /proc/net/ipsec_* files. -->
218
<!-- Revision 1.12 1999/07/19 18:47:24 henry -->
219
<!-- fix slightly\-misformed comments -->
221
<!-- Revision 1.11 1999/04/06 04:54:37 rgb -->
222
<!-- Fix/Add RCSID Id: and Log: bits to make PHMDs happy. This includes -->
223
<!-- patch shell fixes. -->