Table of Contents

Subscriber Traffic Tracing by IP

Tracing lets you record a detailed log of how fastDPI processes traffic for a specific subscriber IP address. It is useful for diagnosing problems with classification, rule enforcement, or routing of traffic through SSG.

Before You Start

It is recommended to trace subscribers one at a time. Capture the trace for one IP, stop it, and only then repeat the procedure for the next subscriber — this makes it easier to match the log to a specific address.

Tracing can be enabled in two ways:

Before repeating the procedure for the next subscriber, it is recommended to back up the current subscriber's fastdpi_slave_*.log files to a separate location — otherwise the new subscriber's entries will be appended to the existing ones and mixed with them.

After the backup, you can clear the log with:

truncate -s0 /var/log/dpi/fastdpi_slave_*.log
If you have enabled tracing but the log is empty, possible causes are:
  1. The trace_ip parameter was not applied — see the "Verifying the Parameter" subsection for the method you used.
  2. The subscriber's traffic does not pass through SSG.
  3. The log files were deleted and recreated manually. If fastdpi_slave_*.log is recreated without restarting SSG, no trace will be written to it. Always clear the log with truncate.

Tracing via the Configuration File

Enabling

Steps using fastdpi.conf:

  1. Open the configuration file /etc/dpi/fastdpi.conf.
  2. Add the parameter trace_ip=1.1.1.1, where 1.1.1.1 is the IP address of the subscriber to trace.
    You can specify up to two IP addresses separated by a comma without spaces, for example: trace_ip=172.16.105.67,172.16.105.86. If you specify more than two addresses, fastDPI returns an error and applies only the first two.
  3. Apply the changes with service fastdpi reload.
    Configuration changes are applied without interrupting traffic.
    Once applied, fastDPI starts writing a step-by-step processing log for the specified subscriber's traffic to /var/log/dpi/fastdpi_slave_*.log.

Disabling

  1. Comment out or remove the trace_ip=1.1.1.1 line in /etc/dpi/fastdpi.conf.
  2. Apply the changes with service fastdpi reload.

Verifying the Parameter

After each service fastdpi reload, the list of parameters and their resulting values is written to /var/log/dpi/fastdpi_alert.log:

cat /var/log/dpi/fastdpi_alert.log | grep trace_ip
[INFO    ][2026/09/25-11:27:03:895457][0x7f322f378400] Option 'trace_ip' changed: '' -> '172.16.105.2,172.16.105.3,'
                trace_ip                 : 172.16.105.2,172.16.105.3
                trace_ipv6               : null
                plc_trace_ip             : null
                auth_trace_ip              =null

You can also check the current value with fdpi_cli dpi config get trace_ip.

A common reason the parameter is not applied: "cold" fastdpi.conf parameters were changed together with trace_ip, and these require a full restart instead of reload.

Tracing via CLI

Enabling

Via CLI, tracing can be enabled without editing fastdpi.conf. A value set via CLI is not saved to the configuration file and is reset by the next service fastdpi reload.

For one IP address:

fdpi_cli dpi config set trace_ip=172.16.105.67

For two IP addresses:

fdpi_cli dpi config set trace_ip=172.16.105.67,172.16.105.86

If you specify more than two addresses, the command returns an error, but the first two addresses are still applied.

Disabling

Run the command with an empty value:

fdpi_cli dpi config set trace_ip=

Tracing enabled via CLI is also reset by service fastdpi reload.

If trace_ip is set in fastdpi.conf, the fdpi_cli dpi config set trace_ip= command disables tracing only until the next reload — after that, the value is read from the file again. To disable tracing permanently, remove the parameter from fastdpi.conf.

Verifying the Parameter

Run:

fdpi_cli dpi config get trace_ip

A change made via CLI is also recorded in /var/log/dpi/fastdpi_alert.log, just as with a change made via fastdpi.conf.

Trace Log

The trace log is saved to /var/log/dpi/fastdpi_slave_*.log.

Example — L2 BRAS with termination, routing, and blacklist blocking:

[TRACE   ][001937909944762840][0004DF1C174F65F0] PACKET : flw_dir=0, ind_if=0, dev_id=0
[TRACE   ][001937909944762840][0004DF1C174F65F0] ETH : bc:24:11:69:3f:1c --> bc:24:11:f7:1c:dd, ether_type=0x8100
[TRACE   ][001937909944762840][0004DF1C174F65F0] ETH_VLAN : ether_type=0x800, VLAN : tag=0x458, vlan=1112 p=0
[TRACE   ][001937909944762840][0004DF1C174F65F0] IP : IPv4 192.168.27.86 --> 172.67.207.203, protocol=6, lenhdr=20, tot_len=392, l4_size=372, tos=0, id=45630, ttl=64, frag_off=0x4000, check=0x2f24
[TRACE   ][001937909944762840][0004DF1C174F65F0] TCP : ports 58582 --> 443 seq=1853477189, ack_seq=2032920904, header_len=32 useful_len=340  A  P, win=63, check=0xa0c8, doff=8
[TRACE   ][001937909944762840][0004DF1C174F65F0] TCPFLAGS : 192.168.27.86:58582 -> 172.67.207.203:443 direction=0, tcpbits=0x18 -AP---, 1, tcpbits=0x12 -A--S-
[TRACE   ][001937909944762840][0004DF1C174F65F0] SSL : SKEEP_extension_type, SSL_STATE : ehp='TLS_normal'(0), rc=-1, whp=10, rec_type=22, vers=0x0301, hnd_type=1, hnd_vers=0x0303, parse=1653/1728, pos_cmnname=0, cmn_size=0/0, fnd=0, skeep_size=65281, ind_skeep=9, cmn_name=__, vdpi_proto=0, cipher_suites_len=32, cipher_suites=16 : {  0x8a8a,0x1303,0x1301,0x1302,0xcca9,0xcca8,0xc02b,0xc02f,0xc02c,0xc030,0xc013,0xc014,0x009c,0x009d,0x002f,0x0035 }, prsd_srv_hello=0, ver_serv=0x0000, cipher=0x0000, metod=0, view_hdr=1, ext_len=0, ext_parse=0, h_supported_version=0x0000/0/0, i=265, pl=75, size=340
[TRACE   ][001937909944762840][0004DF1C174F65F0] SSL : End parse, SSL_STATE : ehp='TLS_normal'(0), rc=1, whp=24, rec_type=22, vers=0x0301, hnd_type=1, hnd_vers=0x0303, parse=1728/1728, pos_cmnname=0, cmn_size=0/18, fnd=0, skeep_size=0, ind_skeep=14, cmn_name=_cloudflare-ech.com_, vdpi_proto=0, cipher_suites_len=32, cipher_suites=16 : {  0x8a8a,0x1303,0x1301,0x1302,0xcca9,0xcca8,0xc02b,0xc02f,0xc02c,0xc030,0xc013,0xc014,0x009c,0x009d,0x002f,0x0035 }, prsd_srv_hello=0, ver_serv=0x0000, cipher=0x0000, metod=0, view_hdr=1, ext_len=0, ext_parse=0, h_supported_version=0x0000/0/0, i=0, pl=0, size=340
[TRACE   ][001937909944762840][0004DF1C174F65F0] CHECK_SSL_SNI : IP : 192.168.27.86:58582 --> 172.67.207.203:443 dirdata=0, cname=_cloudflare-ech.com_, prg=0x0, prof_idx={0,0,0,0,0,0,0,0,0,0,0}, blocked=0
[TRACE   ][001937909944762840][0004DF1C174F65F0] DPI_PROTO_SNI_SET_IP_SNI_CNAME : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, cname='cloudflare-ech.com', proto=0(ukn)-->0(ukn), bts_check_ip=0x2-->0x2
[TRACE   ][001937909944762840][0004DF1C174F65F0] DPI_PROTO_CHECK_SNI : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, sni='cloudflare-ech.com', proto=0(ukn)-->0(ukn), asnum=0x2000000fc00/0x3417, bts_check_ip=0x2-->0x2
[TRACE   ][001937909944762840][0004DF1C174F65F0] DPI_CHANGE_PROTO_BLOCK : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, proto=0(ukn)-->91(ssl)
[TRACE   ][001937909944762840][0004DF1C174F65F0] CHECK_IP : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, prg_id=0x0, prof_idx={0,0,0,0,0,0,0,0,0,0,0}, blocked=1, bts_check_ip=0x102
[TRACE   ][001937909944968740][0000000000000000] PROTO_DSCP : 192.168.27.86:58582 --> 172.67.207.203:443, ret_stat=0x150, ret_stat_srv18=0x0, dscp=0x0 --> 0x0, ( 0x0/0x0/0x0/0x0/0x0 ) , proto=https(443), nvc=1, , rg=0
[TRACE   ][001937909944973900][0004DF1C174F65F0] DPI DEF_PROTO : 192.168.27.86:58582 -> 172.67.207.203:443 : ind_alfs=1, cntr_fin=0, direction=0, who_is_clnt=0, dirdata=0, proto=91(ssl)
[TRACE   ][001937909944762840][0004DF1C174F65F0] PLS_S_IP : flw_dir=0, selected : 192.168.27.86( ind_mdata=1, 0), 172.67.207.203( ind_mdata=4294967295, 0)
[TRACE   ][001937909944981400] [ROUTER][FIB4] destIP=172.67.207.203 - use route from flow: VRF='' arp_id=1 from ''
[TRACE   ][001937909944983580] [ROUTER][FIB4] destIP=172.67.207.203 VRF='' arp_id=1: dstMAC=bc:24:11:fa:b6:b9 vlan=1111 tx-dev=00-14.0
[TRACE   ][001937909944988540] [BRAS] change_vlan: 0:1112.0 bc:24:11:f7:1c:dd -> bc:24:11:fa:b6:b9 192.168.27.86 -> 172.67.207.203, IPproto=6: 1:1112.0 -> 1:1111.0
[TRACE   ][001937909944992000] [BRAS] terminate_packet: 0:1111.0 bc:24:11:f7:1c:dd -> bc:24:11:fa:b6:b9 192.168.27.86 -> 172.67.207.203, IPproto=6: enter
[TRACE   ][001937909944993000] latency: total=115 us (230500 ticks), DPI=115 us (230160 ticks), inter-packet gap=2 us (4940 ticks)