---
title: "Debug a site tunnel"
canonical: "https://docs.aryaka.com/space/KNOW/529399904/Debug%20a%20site%20tunnel"
format: markdown
---
You can view the current status of a site tunnel and, if necessary, debug it using the provided logs or with the assistance of Aryaka customer support. Complete the following procedure to access the Sites page if it is not already open. To debug a site tunnel  Log in to MyAryaka. The Home page appears. Click  SD-WAN  >  Status  in the left navigation pane. The SD-WAN Status page appears. Click the site you want to debug in the Network Discovery diagram or table. The  <siteName > page appears. Click the POP Tunnels tab, then make a note of the time and date. The results displayed after performing step 5 and the download results files do  not  include a timestamp. If you need to contact Aryaka customer support, it helps them to know exactly when you got results. In the Tunnel Status pane, click  Debug  in the Action column of the tunnel you want to debug. The following five commands are issued to the selected site's POP. The Ping tab page and results appear by default. Click any of the other tabs to display the results for that command. Command Description Ping The POP initiates a ping to the site's public IP address with a packet size of 64. This IP address is configured in the IP Address to Monitor field on the Sites >  siteName  > Site Information page. Ping tab options:   Packet Size field—Enables you to edit the ping packet size by entering a new value. Refresh icon—Initiates another ping, for example, after changing the packet size.  Download icon—Generates and downloads a text file containing the results of the ping to your local computer. The file uses the following naming convention:   <company> _ <site>_<tunnel> _Ping.txt For example:  ARYK_Bangalore_Primary_Tunnel_Ping.txt Traceroute UDP traceroute is run from the POP to the site's public IP address. This IP address is configured in the IP Address to Monitor field on the Sites >  siteName  > Site Information page. Traceroute tab options:  Refresh icon—Runs the traceroute command again.  Download icon—Generates and downloads a text file containing the results of the traceroute to your local computer. The file uses the following naming convention:   <company> _ <site>_<tunnel> _Traceroute.txt For example:  ARYK_Bangalore_Secondary_Tunnel_Traceroute.txt MTR The my traceroute (MTR) command is run from the POP to the site's public IP address with a packet size of 64. This IP address is configured in the IP Address to Monitor field on the Sites >  siteName  > Site Information page. MTR tab options:  Packet Size field—Enables you to edit the MTR packet size by entering a new value. Refresh icon—Initiates another MTR, for example, after changing the packet size.  Download icon—Generates and downloads a text file containing the results of the MTR to your local computer. The file uses the following naming convention:   <company> _ <site>_<tunnel> _MTR.txt For example:  ARYK_Chicago_Primary_Tunnel_MTR.txt Packet Capture A packet capture is run at the POP's interface where the site's IPSec tunnel terminates. Use this TCPDump result to view the IPSec handshake between the site and the POP. By default, the results filter out any ICMP packets that are exchanged between the site and the POP. Packet Capture tab options:   Hide ICMP Packets checkbox—Clear this checkbox to display ICMP packets in the results. Refresh icon—Initiates another packet capture, for example, after clearing the Hide ICMP Packets checkbox.  Download icon—Generates and downloads a text file containing the results of the packet capture to your local computer. The file uses the following naming convention:   <company> _ <site>_<tunnel> _Packet Capture.txt For example:  ARYK_SanMateo_Primary_Tunnel_Packet Capture.txt IPSec Log Collects the last 30 IPSec log lines that were written on the POP as a result of IPSec negotiations with the site. The IPSec log contains information about the tunnel that connects your site with with the POP. It also includes the phase 2 policy status and errors (for example, DPD losses and no proposal messages). IPSec Logs tab options: Refresh icon—Runs the IPSec Log command again.  Download icon—Generates and downloads a text file containing the results of the logging to your local computer. The file uses the following naming convention:   <company> _ <site>_ IPSec Logs.txt For example:  ARYK_Bangalore_IPSec Logs.txt Note: If you need help understanding any of results, contact Aryaka customer support. You should note the time and date when the commands were run, and take a screen capture of the results or download the appropriate results text file. You can rerun all five commands at once by clicking the Refresh icon in the page's banner (top right above the tabs). You can download all five results text files in a zip file by clicking the Download icon in the page's banner (top right above the tabs). Related topics Configure site information View a site’s status