Subscriber Traffic Tracing by IP
Tracing lets you record a detailed log of how fastDPI processes traffic for a specific subscriber IP address. It is useful for diagnosing problems with classification, rule enforcement, or routing of traffic through SSG.
Before You Start
Tracing can be enabled in two ways:
- via the
fastdpi.confconfiguration file — the value persists across subsequentservice fastdpi reloadruns; - via CLI — the value stays in effect until the next reload.
Before repeating the procedure for the next subscriber, it is recommended to back up the current subscriber's fastdpi_slave_*.log files to a separate location — otherwise the new subscriber's entries will be appended to the existing ones and mixed with them.
After the backup, you can clear the log with:
truncate -s0 /var/log/dpi/fastdpi_slave_*.log
- The
trace_ipparameter was not applied — see the "Verifying the Parameter" subsection for the method you used. - The subscriber's traffic does not pass through SSG.
- The log files were deleted and recreated manually. If
fastdpi_slave_*.logis recreated without restarting SSG, no trace will be written to it. Always clear the log withtruncate.
Tracing via the Configuration File
Enabling
Steps using fastdpi.conf:
- Open the configuration file
/etc/dpi/fastdpi.conf. - Add the parameter
trace_ip=1.1.1.1, where1.1.1.1is the IP address of the subscriber to trace.
You can specify up to two IP addresses separated by a comma without spaces, for example:trace_ip=172.16.105.67,172.16.105.86. If you specify more than two addresses, fastDPI returns an error and applies only the first two. - Apply the changes with
service fastdpi reload.
Configuration changes are applied without interrupting traffic.
Once applied, fastDPI starts writing a step-by-step processing log for the specified subscriber's traffic to/var/log/dpi/fastdpi_slave_*.log.
Disabling
- Comment out or remove the
trace_ip=1.1.1.1line in/etc/dpi/fastdpi.conf. - Apply the changes with
service fastdpi reload.
Verifying the Parameter
After each service fastdpi reload, the list of parameters and their resulting values is written to /var/log/dpi/fastdpi_alert.log:
cat /var/log/dpi/fastdpi_alert.log | grep trace_ip
[INFO ][2026/09/25-11:27:03:895457][0x7f322f378400] Option 'trace_ip' changed: '' -> '172.16.105.2,172.16.105.3,'
trace_ip : 172.16.105.2,172.16.105.3
trace_ipv6 : null
plc_trace_ip : null
auth_trace_ip =null
You can also check the current value with fdpi_cli dpi config get trace_ip.
A common reason the parameter is not applied: "cold" fastdpi.conf parameters were changed together with trace_ip, and these require a full restart instead of reload.
Tracing via CLI
Enabling
Via CLI, tracing can be enabled without editing fastdpi.conf. A value set via CLI is not saved to the configuration file and is reset by the next service fastdpi reload.
For one IP address:
fdpi_cli dpi config set trace_ip=172.16.105.67
For two IP addresses:
fdpi_cli dpi config set trace_ip=172.16.105.67,172.16.105.86
If you specify more than two addresses, the command returns an error, but the first two addresses are still applied.
Disabling
Run the command with an empty value:
fdpi_cli dpi config set trace_ip=
Tracing enabled via CLI is also reset by service fastdpi reload.
trace_ip is set in fastdpi.conf, the fdpi_cli dpi config set trace_ip= command disables tracing only until the next reload — after that, the value is read from the file again. To disable tracing permanently, remove the parameter from fastdpi.conf.
Verifying the Parameter
Run:
fdpi_cli dpi config get trace_ip
A change made via CLI is also recorded in /var/log/dpi/fastdpi_alert.log, just as with a change made via fastdpi.conf.
Trace Log
The trace log is saved to /var/log/dpi/fastdpi_slave_*.log.
Example — L2 BRAS with termination, routing, and blacklist blocking:
[TRACE ][001937909944762840][0004DF1C174F65F0] PACKET : flw_dir=0, ind_if=0, dev_id=0
[TRACE ][001937909944762840][0004DF1C174F65F0] ETH : bc:24:11:69:3f:1c --> bc:24:11:f7:1c:dd, ether_type=0x8100
[TRACE ][001937909944762840][0004DF1C174F65F0] ETH_VLAN : ether_type=0x800, VLAN : tag=0x458, vlan=1112 p=0
[TRACE ][001937909944762840][0004DF1C174F65F0] IP : IPv4 192.168.27.86 --> 172.67.207.203, protocol=6, lenhdr=20, tot_len=392, l4_size=372, tos=0, id=45630, ttl=64, frag_off=0x4000, check=0x2f24
[TRACE ][001937909944762840][0004DF1C174F65F0] TCP : ports 58582 --> 443 seq=1853477189, ack_seq=2032920904, header_len=32 useful_len=340 A P, win=63, check=0xa0c8, doff=8
[TRACE ][001937909944762840][0004DF1C174F65F0] TCPFLAGS : 192.168.27.86:58582 -> 172.67.207.203:443 direction=0, tcpbits=0x18 -AP---, 1, tcpbits=0x12 -A--S-
[TRACE ][001937909944762840][0004DF1C174F65F0] SSL : SKEEP_extension_type, SSL_STATE : ehp='TLS_normal'(0), rc=-1, whp=10, rec_type=22, vers=0x0301, hnd_type=1, hnd_vers=0x0303, parse=1653/1728, pos_cmnname=0, cmn_size=0/0, fnd=0, skeep_size=65281, ind_skeep=9, cmn_name=__, vdpi_proto=0, cipher_suites_len=32, cipher_suites=16 : { 0x8a8a,0x1303,0x1301,0x1302,0xcca9,0xcca8,0xc02b,0xc02f,0xc02c,0xc030,0xc013,0xc014,0x009c,0x009d,0x002f,0x0035 }, prsd_srv_hello=0, ver_serv=0x0000, cipher=0x0000, metod=0, view_hdr=1, ext_len=0, ext_parse=0, h_supported_version=0x0000/0/0, i=265, pl=75, size=340
[TRACE ][001937909944762840][0004DF1C174F65F0] SSL : End parse, SSL_STATE : ehp='TLS_normal'(0), rc=1, whp=24, rec_type=22, vers=0x0301, hnd_type=1, hnd_vers=0x0303, parse=1728/1728, pos_cmnname=0, cmn_size=0/18, fnd=0, skeep_size=0, ind_skeep=14, cmn_name=_cloudflare-ech.com_, vdpi_proto=0, cipher_suites_len=32, cipher_suites=16 : { 0x8a8a,0x1303,0x1301,0x1302,0xcca9,0xcca8,0xc02b,0xc02f,0xc02c,0xc030,0xc013,0xc014,0x009c,0x009d,0x002f,0x0035 }, prsd_srv_hello=0, ver_serv=0x0000, cipher=0x0000, metod=0, view_hdr=1, ext_len=0, ext_parse=0, h_supported_version=0x0000/0/0, i=0, pl=0, size=340
[TRACE ][001937909944762840][0004DF1C174F65F0] CHECK_SSL_SNI : IP : 192.168.27.86:58582 --> 172.67.207.203:443 dirdata=0, cname=_cloudflare-ech.com_, prg=0x0, prof_idx={0,0,0,0,0,0,0,0,0,0,0}, blocked=0
[TRACE ][001937909944762840][0004DF1C174F65F0] DPI_PROTO_SNI_SET_IP_SNI_CNAME : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, cname='cloudflare-ech.com', proto=0(ukn)-->0(ukn), bts_check_ip=0x2-->0x2
[TRACE ][001937909944762840][0004DF1C174F65F0] DPI_PROTO_CHECK_SNI : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, sni='cloudflare-ech.com', proto=0(ukn)-->0(ukn), asnum=0x2000000fc00/0x3417, bts_check_ip=0x2-->0x2
[TRACE ][001937909944762840][0004DF1C174F65F0] DPI_CHANGE_PROTO_BLOCK : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, proto=0(ukn)-->91(ssl)
[TRACE ][001937909944762840][0004DF1C174F65F0] CHECK_IP : 192.168.27.86:58582 --> 172.67.207.203:443 flw_dir=0, prg_id=0x0, prof_idx={0,0,0,0,0,0,0,0,0,0,0}, blocked=1, bts_check_ip=0x102
[TRACE ][001937909944968740][0000000000000000] PROTO_DSCP : 192.168.27.86:58582 --> 172.67.207.203:443, ret_stat=0x150, ret_stat_srv18=0x0, dscp=0x0 --> 0x0, ( 0x0/0x0/0x0/0x0/0x0 ) , proto=https(443), nvc=1, , rg=0
[TRACE ][001937909944973900][0004DF1C174F65F0] DPI DEF_PROTO : 192.168.27.86:58582 -> 172.67.207.203:443 : ind_alfs=1, cntr_fin=0, direction=0, who_is_clnt=0, dirdata=0, proto=91(ssl)
[TRACE ][001937909944762840][0004DF1C174F65F0] PLS_S_IP : flw_dir=0, selected : 192.168.27.86( ind_mdata=1, 0), 172.67.207.203( ind_mdata=4294967295, 0)
[TRACE ][001937909944981400] [ROUTER][FIB4] destIP=172.67.207.203 - use route from flow: VRF='' arp_id=1 from ''
[TRACE ][001937909944983580] [ROUTER][FIB4] destIP=172.67.207.203 VRF='' arp_id=1: dstMAC=bc:24:11:fa:b6:b9 vlan=1111 tx-dev=00-14.0
[TRACE ][001937909944988540] [BRAS] change_vlan: 0:1112.0 bc:24:11:f7:1c:dd -> bc:24:11:fa:b6:b9 192.168.27.86 -> 172.67.207.203, IPproto=6: 1:1112.0 -> 1:1111.0
[TRACE ][001937909944992000] [BRAS] terminate_packet: 0:1111.0 bc:24:11:f7:1c:dd -> bc:24:11:fa:b6:b9 192.168.27.86 -> 172.67.207.203, IPproto=6: enter
[TRACE ][001937909944993000] latency: total=115 us (230500 ticks), DPI=115 us (230160 ticks), inter-packet gap=2 us (4940 ticks)
Was this information helpful?