Bug ID 1307197: IKEv2 allow SK_ logging to be enabled without debug2

Last Modified: Apr 17, 2024

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4

Opened: Jun 14, 2023

Severity: 4-Minor

Symptoms

SK_logging requires you to enable multiple db variables and debug2 logging. When it is enabled, the message ID is the same for all the logs.

Impact

Configuring IKEv2 key logging is cumbersome and the logs are difficult to parse through when there are many tunnels.

Conditions

- Create tunnels, enable below sys-db variables ipsec.debug.logkeys ipsec.debug.logsk ipsec.debug.pfkey.msg - Enable debug2 logging

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips