Configuration Mode Commands : Interceptor commands : conn-trace rule
  
conn-trace rule
Configures connection tracing rules.
Syntax
[no] conn-trace rule [protocol {tcp | udp | any}] srcnet {<subnet> | all-ip | all-ipv4 | all-ipv6} srcport-start <start‑port> srcport-end <end-port> dstnet {<ip-address> | all-ip | all-ipv4 | all-ipv6} dstport-start <start-port> dstport-end <end-port> vlan <vlan-id>
Parameters
protocol
Specifies the protocol type.
• tcp—Specifies Transmission Control Protocol (TCP). This is the default.
• udp—Specifies User Datagram Protocol (UDP).
• any—Specifies both TCP and UDP.
srcnet
Specifies the IP address and mask for the traffic source.
• <subnet>—IPv4 or IPv6 address and mask.
– For IPv4 addresses, use this format: xxx.xxx.xxx.xxx/xx
– For IPv6 addresses, use this format: x:x:x::x/xxx
• all-ip—Specifies all IPv4 and IPv6 addresses.
• all-ipv4—Specifies all IPv4 addresses.
• all-ipv6—Specifies all IPv6 addresses.
srcport-start <start‑port>
Specifies the starting port number for the traffic source.
srcport-end <end‑port>
Specifies the ending port number for the traffic source.
dstnet
Specifies the IP address and mask for the traffic destination.
• <subnet>—IPv4 or IPv6 address and mask:
– For IPv4 addresses, use this format: xxx.xxx.xxx.xxx/xx
– For IPv6 addresses, use this format: x:x:x::x/xxx
• all-ip—Specifies all IPv4 and IPv6 addresses.
• all-ipv4—Specifies all IPv4 addresses.
• all-ipv6—Specifies all IPv6 addresses.
dstport-start <start‑port>
Specifies the starting port number for the traffic destination.
dstport-end <end‑port>
Specifies the ending port number for the traffic destination.
vlan <vlan-id>
Specifies the VLAN ID.
• all for all VLANs.
• 0 (zero) for untagged VLANs.
• VLAN numbers from 1 to 4094 for tagged VLANs.
Usage
Connection tracing rules let you determine to which SteelHeads the Interceptor has redirected specific connections. Connection traces can be used as a debugging tool for troubleshooting issues with failing or unoptimized connections or connections requiring path selection.
If you manually restart the Interceptor, the connection traces are lost. Prior to restarting, perform a system dump.
The no command option disables connection tracing.
Example
amnesiac (config) # conn-trace rule protocol tcp srcnet 10.0.0.1/32 srcport-start 1234 srcport-end 4567 dstnet 10.0.0.2/32 dstport-start 7890 dstport-end 8890 vlan 20
Product
Interceptor
Related Commands
show conn-trace