Saturday, March 29, 2014

Juniper Hardware/Software diagnostics commands for troubleshooting Part 2

                                                                  Juniper commands




set cli timestamp
request support information | no-more

Log
----------------
show log messages | no-more
show log chassisd | no-more

Ospf
----------------
show ospf overview
show ospf neighbor detail
show ospf route
show ospf statistics
show ospf interface
show ospf log
show route protocol ospf
show ospf database
show ospf database summary
show ospf database extensive

BGP

show route advertising-protocol bgp 220.227.29.7
show route receive-protocol bgp 220.27.29.8
show route receive-protocol bgp 125.17.74.4
show route receive-protocol bgp 121.241.5.117

SYSTEM

set cli timestamp
show chassis routing-engine
show system processes extensive
show system users
show system connections
show system statistics
show chassis forwarding
show security monitor fpc pic <SPC-slot> (use 0 for Branch platforms)
show security monitor performance spu
show security monitor performance sess


OSPF

set cli timestamp
show ospf overview
show ospf database
show ospf neighbor detail
show ospf route
show ospf statistics
show ospf interface
show ospf log
show route protocol ospf
show route <x.x.x.x> extensive
show ospf database extensive


UTM

set cli timestamp
show system licenses
show security utm status
show security utm session
show security utm anti-virus status detail
show security utm anti-virus statistics
show chassis routing-engine
show system processes extensive
show security utm session
show security utm web-filtering status
show security utm web-filtering statistics
show chassis routing-engine
show system processes extensive

IPSEC


show security ike security-association
show security ike security-association index <#> detail
show security ipsec security-association
show security ipsec security-association index <#> detail
show security ipsec statistics
show security ipsec statistics index <#>
show security ipsec next-hop-tunnels
monitor interface st0.x


 IPSEC IKE

show interfaces extensive st0.x
show security flow session tunnel
show route
show security pki local-cert detail
show security pki ca-cert detail
show security pki crl detail
show security ike security-association
show security ike security-association index <#> detail
show security ipsec security-association
show security ipsec security-association index <#> detail
show security ipsec statistics
show security ipsec statistics index <#>
show security ipsec next-hop-tunnels
show security flow session tunnel
IF PKI certs are used:
show security pki local-cert detail
show security pki ca-cert detail
show security pki crl detail
show security policies detail
show log /var/etc/policy.id



VRF Instance commands
----------------------------------

> show ospf interface instance AVAYA extensive
> show ospf neighbor instance AVAYA extensive
> show ospf database instance AVAYA extensive
> show ospf route instance AVAYA extensive
> show route protocol ospf table AVAYA.inet.0 extensive

Optimization of fortigate IPS

IPS signature need select according to infrastructure environment  Eg:-  if  we are not have Linux servers this ips signature can disable (d...