In order to identify why packets are discarded on the firewall, we can make use of the debugging dataplane trace command which enables the debugging function of packet tracing on the data plane and can provide information about the discard cause.
The command can be used in the user view in order to trace how the packets are processed at the data plane or to specificaly trace the discarded packets. The command also provides the possibility to select the traffic of interest by making use of an ACL.
Format
debugging dataplane trace [ discard [ type ] ] acl acl-number [ number num ] [ slot slot-id cpu cpu-id ]
undo debugging dataplane trace [ slot slot-id cpu cpu-id]
Example
Enable debugging function of packet tracing on the data plane to identify why packets sourced from 192.168.100.228 are not reaching the firewall.
1. Define an ACL to select the traffic sourced from the 192.168.100.228 IP address
acl 3002
rule permit ip source 192.168.100.228 0
2.Enable debugging to trace the discarded packets that match the acl
Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
Politically sensitive content
Content concerning pornography, gambling, and drug abuse
Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."