Transcription of Cheat Sheet - General for FortiOS 6.4 FortiGate CLI ...
1 FortiGate Cheat Sheet - General for FortiOS The Cheat Sheet from BOLL. Here Network Troubleshooting you can find all important FortiGate get hardware nic [port] Interface Information CLI commands for the operation and diag ip arp list ARP table troubleshooting of FortiGates with exec clear system arp table Clears ARP table FortiOS exec ping Ping utility exec ping-options [option]. exec traceroute System exec traceroute-options [option]. Traceroute utility General System Commands exec telnet [port] Telnet utility get system status General system information Integrated Iperf Utility exec tac report Generates report for support diag traffictest server-intf tree Lists all commands diag traffictest client-intf <command> ? / tab Use ? or tab in CLI for help Iperf test directly run from diag traffictest port [port] FortiGate <command> | grep [filter] Grep command to filter outputs diag traffictest run -c [public_iperf_server_ip].
2 Diag debug cli 8 Shows webGUI changes in CLI. General Routing Troubleshooting Process Information get router info routing-table all Routing table get system performance status General performance infos get router info routing-table Shows Routing decision for Process list diag sys top [sec] [number] details specified Destination-IP. Sort with P (CPU) / M (Memory). get router info routing-table Routing table with inactive diag debug crashlog read Crash log database routes get router info kernel Forwarding information base Traffic Processing diag firewall proute list List of policy-based routes diag ip rtcache list List of route cache General Debugging Overview of dynamic routing Realtime debugger for different get router info protocols diag debug appl [appl] [level] protocol configuration applications exec router restart Restart of routing process diag test appl [appl] [test_level] Monitor proxy operations diag sys link-monitor Shows link monitor status / per diag debug console timestamp Enables timestamp in console status/interface/launch interface / for WAN LLB.
3 Enable Enable/disable output for diag diag debug [enable/disable]. debug or diag ip commands diag debug reset Reset debug levels High Availability HA General Firewall Session Troubleshooting exec ha manage [index] [admin] Jump to cluster member diag sys session filter Filter for session list get sys ha status Information about HA status diag sys session list (expect) Lists all (or expected) sessions diag sys ha history read Details about past HA events diag sys session clear Clear all / filtered sessions diag sys ha dump-by vcluster Show cluster member uptime Session and memory statistics, diag sys ha reset-uptime Reset cluster member uptime diag sys session stat drops, clashes diag debug appl hatalk -1 Debugging of HA-Talk/-Sync diag firewall iprope clear 100004 Resets counter for all or specific diag debug appl hasync -1 protocol [<id>] firewall policy id exec ha ignore-hardware-revision Set ignore status for different status / enable / disable HW revisions Packet Sniffer exec ha failover status View failover status diag sniffer packet [any/<if>] Packet sniffer.
4 Use filters! [filter]' [verbose] [count] Verbose levels 1-6 for different Device stays in failover state [timestamp] output exec ha failover set <cluster_id> regardless of condition. Triggers a HA failover on master device. Flow Trace Cluster Synchronisation Use filters to narrow down trace diag debug flow filter [filter] Show config checksums of all results diag sys ha checksum cluster cluster member diag debug flow show iprop en diag debug flow show fun en diag sys ha checksum Detailed config checksum for a Debug command for traffic flow show [vdom] VDOM. diag debug flow trace start [count]. diag sys ha checksum Recalculation of config recalculate checksums Network Interface Information diag ip address list List of IPs on FGT interfaces diag firewall iplist list List of IPs on VIP and IP-Pools page 1. FortiGate Cheat Sheet - Firewalling for FortiOS UTM Services Logging Generates dummy log FortiGuard Distibution Network (FDN) diag log test messages URLs to access the FortiGuard exec log list List log file information Distribution Network (FDN).
5 Traffic Shaper diag firewall shaper traffic-shaper Signature Update Traffic shaper list / statistics list / stats diag autoupdate status Summary of Fortiguard settings diag firewall shaper per-ip-shaper Per IP traffic shaper list /. diag autoupdate versions Detailed versions of packages list / stats statistics diag debug appl update -1 Realtime debugging for updating process with manual SIP. exec update-now update diag sys sip status SIP session helper status diag sys sip-proxy stats list SIP ALG session status Antivirus diag sys sip-proxy calls list/clear List/Clear active SIP calls diag antivirus database-info Antivirus database information diag debug appl sip -1 Realtime Debugger for SIP. diagnose antivirus test Different tests for AV engine "command . IPS Authentication diag ips anomaly list Lists statistics of DoS-Policies Authentication diag ips packet status IPS packet statistics diag firewall auth filter Filter for authentication list diag test appl ipsmonitor 2 Enable / disable IPS engine diag firewall auth list List of authenticated user diag test appl ipsmonitor 5 Toggle bypass status diag test authserver diag test appl ipsmonitor 99 Restart all IPS processes [auth-protocol] [server] [user] Authentication test [password].
6 Webfilter Debugging of local diag debug appl auth -1. authentication protocol Webfilter / AntiSpam Server diag debug rating information Debugging of remote diag debug appl fnbamd -1. authentication protocol diag webfilter fortiguard Statistics of FortiGuard requests statistics list FortiToken diag webfilter fortiguard cache List content of webfilter cache diag fortitoken info Current FortiToken status dump exec fortitoken activate [Forti- diag test appl urlfilter 1 Lists webfilter test commands Manual FortiToken activation TokenSN]. diag debug urlfilter src-addr Filter and Realtime Debugging diag deb appl forticldd 255 FortiToken activation debugging for Webfiltering diag debug appl urlfiter -1 diag fortitoken debug enable FortiToken debugging exec fortitoken-mobile import Recover Trial FortiToken (delete Emailfilter 0000-0000-0000-0000-0000 existing Trial Token before).
7 Diag emailfilter fortishield servers Displays FortiShield server list FSSO. diag emailfilter fortishield stat list Statistics of FortiShield requests diag debug authd fsso filter Filter for FSSO user list diag debug authd fsso list List of FSSO authenticated user Firewall Policy diag debug authd fsso List of FSSO collector agents server-status Device Detection diag debug fsso-polling Info for clientless polling FSSO. exec update-src-vis Update device detection DB. Debugging of clientless polling diag user device list / clear Show / clear detected devices diag debug appl fssod -1. FSSO. Internet Service Database (ISDB) Explicit Proxy diag internet-service Lists summary/details for diag wad user list/clear List / clear of explicit proxy user info vdom proto port ip specific Internet Service diag wad filter Filtering / listing of web proxy Reverse ISDB lookup for sessions diag internet-service info diag wad session list specific IP, protocol or port diag test appl wad 104 DNS statistics for explicit proxy diag internet-service match Reverse ISDB lookup for <vdom> <ip> <netmask> specific IP diag test appl wad 110 Current proxy user Enables output of subsequent FQDN diag test appl wad 112.
8 Commands diag test application dnsproxy 6 Dump FQDN cache diag test appl wad 2200 Maximum number of users diagnose firewall fqdn list List all FQDN. page 2. FortiGate Cheat Sheet - Networking for FortiOS VPN Wireless, Switch, FortiExtender IPsec VPN Access Point (CLI commands on Access Point). diag debug appl ike 63 Debugging of IKE negotiation cfg a Change IP from DHCP to static ADDR_MODE=DHCP|STATIC on FortiAP. diag vpn ike log filter Filter for IKE negotiation output cfg a diag vpn ike gateway list Phase 1 state Set static IP on FortiAP. AP_IPADDR= . diag vpn ike gateway flush Delete Phase 1. cfg a AP_NET- Set subnet mask on FortiAP. diag vpn tunnel list Phase 2 state MASK= . diag vpn tunnel flush Delete Phase 2 cfg a IPGW= Set gateway on FortiAP. get vpn ike gateway Detailed gateway information cfg a Specify IP of Wireless Controller AC_IPADDR_1= on FortiAP.
9 Get vpn ipsec tunnel details Detailed tunnel information cfg s / -c List / Save config on FortiAP. get vpn ipsec state tunnel Detailed tunnel statistics cfg -x Reset to factory default diag vpn ipsec status Shows IPSEC crypto status Wireless Controller exec wireless-controller restart- Restart wireless controller SD-WAN & Security Fabric acd daemon SD-WAN exec wireless-controller reset-wtp Restart FortiAPs diag sys virtual-wan-link member Provide Interface details diag wireless-controller List rogue APs diag sys virtual-wan-link health- wlac -c ap-rogue State of SLAs check <name> exec wireless-controller spectral- diag sys virtual-wan-link service scan <wtp-id> <radio-id > <on |. SD-WAN-Rule-State Start or stop spectrum analysis <rule-id> off> <duration> <channel>. <report-interval>. diag sys virtual-wan-link intf-sla- Link Traffic History diag wireless-controller wlac -c rf- log <intf-name>.
10 Sa <wtp-id> <radio-id>. diag sys virtual-wan-link sla-log <channel> Show spectrum analysis results SLA-Log on specific interface <sla> <link_id> get wireless-controller spectral- diag test appl lnkmtd 1/2/3 Statistics of link-monitor info <wtp-id> <radio-id>. Real-time debugger of link- diag debug appl link-mon -1 Switch Controller monitor diag switch-controller switch-info Managed fortiswitch MAC. Security Fabric mac-table address list diag sys csf upstream / diag switch-controller switch-info Managed fortiswitch port List of up/downstream devices port-stats statistics downstream MAC/IP list of connected FGT diag switch-controller switch-info diag sys csf neighbor list Trunk information devices trunk diag test appl csfd 1 Display security fabric statistics diag switch-controller switch-info Dumps MCLAG related mclag information from fortiswitch diag debug appl csfd -1 Real-time debugger exec switch-controller get-conn- Get fortiswitch connection diag automation test status status Test stitches in the CLI.