The following article applies to AppGate (classic) and describes how to capture debug log information for an IP tunneling session, respectively ag_galed. Since debug log for all session can load the server heavily, the below steps describe how to discrete the debug logging only for the session of interest.
Note the IP tunneling address of that session. (Can be seen in the log or under Active Sessions.)
Make sure ag_galed log level is Normal.
Edit /var/opt/appgate/conf/appgate.conf and add this line (or change if it already exists), with <ip> being the IP tunneling address:
ag_galed.log_subnet = "<ip>"
- If this is a cluster, wait until appgate.conf is propagated to the other nodes.
Set ag_galed log level to Debug 4.
Now you can reproduce the issue and the information is collected in the appgate log file. When finished, set the log level to normal again.
Note: setting ag_galed level to normal or to level 4 does not disconnect users.