Nebula and CLI
Hi everyone,
I would like to capture packets on CLI of a Nebula connected security appliance.
But when requesting the interface status, I do not get the configuration as shown in Nebula.
For example, here is how the USG Flex is configured in Nebula :
show interface all
And the answer is :
Nothing to do with the Nebula configuration.
What I need is troubleshooting an RDP remote connection on port 3389. I would like to see if the packets are well received by my WAN interface like this :
packet-trace interface wan port 3389
0 packets are captured event if the connection is successfull !
I have the same problem with ddns, nat rules, secure-policy rules, ... The CLI do not return the Nebula configuration but the default rules as if the apppliance would be in stand-alone mode.
What am I doing wrong ? Wrong command ? Wrong command context ?
Regards,
Sebastien
I would like to capture packets on CLI of a Nebula connected security appliance.
But when requesting the interface status, I do not get the configuration as shown in Nebula.
For example, here is how the USG Flex is configured in Nebula :
- wan1 : PPPoE (fixed public IP from ISP)
- lan1 : 192.168.10.0/24
- lan2 : disabled
show interface all
And the answer is :
Nothing to do with the Nebula configuration.
What I need is troubleshooting an RDP remote connection on port 3389. I would like to see if the packets are well received by my WAN interface like this :
packet-trace interface wan port 3389
0 packets are captured event if the connection is successfull !
I have the same problem with ddns, nat rules, secure-policy rules, ... The CLI do not return the Nebula configuration but the default rules as if the apppliance would be in stand-alone mode.
What am I doing wrong ? Wrong command ? Wrong command context ?
Regards,
Sebastien
0
Accepted Solution
-
The CLI on cloud mode is Router> show sdwan interface.
You can hit CLI Router> packet-trace interface eth0 extension-filter port 3389 to capture packets.
0
All Replies
-
The CLI on cloud mode is Router> show sdwan interface.
You can hit CLI Router> packet-trace interface eth0 extension-filter port 3389 to capture packets.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight