This document discusses packet capture, traceflows, and live logs for troubleshooting NSX. It provides examples of commands to capture packets on distributed NSX firewalls at different points including the switchport, uplink, and output. It also discusses using traceflow to trace packet flows and viewing live logs to see firewall packet logs.
10. Live Logs
[root@localhost:~] tail var/log/dfwpktlogs.log
2023-06-10T01:10:33.985Z d6f0765e INET6 TERM 2 IN ICMP 130 0 fe80::ffff:ffff:ffff:ffff->ff02::1 1/0 76/0
2023-06-10T01:10:34.985Z d6f0765e INET6 TERM 2 OUT ICMP 143 0 fe80::3584:27ce:269c:bbfa->ff02::16 1/0
76/0
2023-06-10T01:11:10.594Z d6f0765e INET match PASS 2024 OUT 114 ICMP 13.13.13.1->12.12.12.2
2023-06-10T01:11:14.033Z d6f0765e INET TERM 2 IN PROTO 2 0.0.0.0->224.0.0.1 1/0 36/0
2023-06-10T01:12:19.094Z d6f0765e INET match PASS 2 IN 36 PROTO 2 0.0.0.0->224.0.0.1
2023-06-10T01:12:19.095Z d6f0765e INET6 match PASS 2 IN 76 ICMP fe80::ffff:ffff:ffff:ffff->ff02::1
2023-06-10T01:12:19.100Z d6f0765e INET6 match PASS 2 OUT 76 ICMP fe80::3584:27ce:269c:bbfa->ff02::16
2023-06-10T01:12:39.145Z d6f0765e INET6 TERM 2 OUT ICMP 143 0 fe80::3584:27ce:269c:bbfa->ff02::16 1/0
76/0
2023-06-10T01:12:41.146Z d6f0765e INET6 TERM 2 IN ICMP 130 0 fe80::ffff:ffff:ffff:ffff->ff02::1 1/0 76/0
2023-06-10T01:13:19.194Z d6f0765e INET TERM 2 IN PROTO 2 0.0.0.0->224.0.0.1 1/0 36/0