Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

How to perform firewall flow filter debugging

From Tech-Wiki


Historical ScreenOS flow-debug procedure retained for legacy NetScreen systems.

ⓘ
Validation status
Reviewed against current Junos tracing concepts on 27 September 2026. Modern SRX/Junos uses security flow traceoptions rather than the ScreenOS ffilter syntax below.
!
Tracing can affect performance and expose traffic
Use a narrow filter, reproduce briefly, stop tracing and remove the diagnostic configuration.

Original technical reference

The debug buffer is a circular buffer, once the buffer has reached the size limit, the oldest data will be overwritten.
The buffer size is configurable.
To change the size, use the following commands:

set db size 4096
set console dbuf
clear db

To set-up the flow filter:

get ffilter
set ffilter src-ip / dst-ip ... (see the CLI-help for more ffilter options) (same row = AND, more rows = OR)
debug flow basic

Reproduce the issue. The timestamp resolution of the output is in tenths of a second. Stop the ffilter and then display the output with the following commands:

undebug all
get dbuf stream or get dbuf stream > tftp <host> <name-of-file>

Official and supporting references