CheatSheet FortiOS 7.2 v1.0
CheatSheet FortiOS 7.2 v1.0
Network
Interface Information
diag ip address list List of IPs on FGT interfaces
diag firewall iplist list List of IPs on VIP
diag firewall ippool list List of IP on pools
diag netlink interface list List IF with MTU & device id
Network Troubleshooting
Traffic Processing get router info routing-table Shows Routing decision for
details x.x.x.x specified Destination-IP
General Debugging
get router info routing-table Routing table with inactive
Realtime debugger for different database routes
diag debug appl [appl] [level]
applications
get router info kernel Forwarding information base
diag test appl [appl] [test_level] Monitor proxy operations
diag firewall proute list List of policy-based routes
diag debug console timestamp
Enables timestamp in console diag ip rtcache list List of route cache
enable
Overview of dynamic routing
Enable/disable output for “diag get router info protocols
diag debug [enable/disable] protocol configuration
debug” or “diag ip” commands
exec router restart Restart of routing process
diag debug reset Reset debug levels
diag sys link-monitor Shows link monitor status / per
Firewall Session Troubleshooting status/interface/launch interface / for WAN LLB
Session and memory statistics, exec ha manage [index] [admin] Jump to cluster member
diag sys session stat
drops, clashes get sys ha status Information about HA status
diag firewall iprope clear 100004 Resets counter for all or specific diag sys ha history read Details about past HA events
[<id>] firewall policy id
diag sys ha dump-by vcluster Show cluster member uptime
Packet Sniffer diag sys ha reset-uptime Reset cluster member uptime
diag sniffer packet [any/<if>] Packet sniffer. Use filters! diag debug appl hatalk -1 Debugging of HA-Talk/-Sync
‘[filter]’ [verbose] [count] Verbose levels 1-6 for different diag debug appl hasync -1 protocol
[timestamp] output
exec ha ignore-hardware-revision Set ignore status for different
GUI: Network > Diagnostics > Packet Capture is newly status / enable / disable HW revisions
Packet Capture available in webUI. exec ha failover status View failover status
Device stays in failover state
Flow Trace exec ha failover set <cluster_id> regardless of condition. Triggers
Use filters to narrow down trace a HA failover on master device.
diag debug flow filter [filter]
results
diag debug flow show iprop en Cluster Synchronisation
diag debug flow show fun en Show config checksums of all
Debug command for traffic flow diag sys ha checksum cluster
diag debug flow trace start cluster member
[count]
diag sys ha checksum Detailed config checksum for a
GUI: Network > Diangostics > Flow trace is newly available in show [vdom] VDOM
Debug Flow webUI.
diag sys ha checksum Recalculation of config
recalculate checksums
UTM Services
FortiGuard Distibution Network (FDN) Logging
update.fortiguard.net Generates dummy log
URLs to access the FortiGuard diag log test
service.fortiguard.net messages
Distribution Network (FDN)
securewf.fortiguard.net exec log list List log file information
diag fdsm image-list / image- Download firmware image list diag test app miglogd 6 Show log queue and fails
update-matrix and update-matrix
Traffic Shaper
Signature Update
diag firewall shaper traffic-shaper
Traffic shaper list / statistics
diag autoupdate status Summary of Fortiguard settings list / stats
diag autoupdate versions Detailed versions of packages diag firewall shaper per-ip-shaper Per IP traffic shaper list /
list / stats statistics
diag test update info Update & license information
IPS
Authentication
diag ips anomaly list Lists statistics of DoS-Policies
Authentication
diag ips packet status IPS packet statistics
diag firewall auth filter … Filter for authentication list
diag test appl ipsmonitor 2 Enable / disable IPS engine
diag firewall auth list List of authenticated user
diag test appl ipsmonitor 5 Toggle bypass status
diag test authserver
diag test appl ipsmonitor 99 Restart all IPS processes [auth-protocol] [server] [user] Authentication test
[password]
Web- & Email-Filter
Debugging of local
diag debug appl authd -1
diag debug rating Webfilter/AS Server information authentication protocol
diag webfilter fortiguard Debugging of remote
Statistics of FortiGuard requests diag debug appl fnbamd -1
statistics list authentication protocol
Device Detection diag debug fsso-polling … Info for clientless polling FSSO
VPN
IPsec VPN Security Rating
diag debug appl ike 63 Debugging of IKE negotiation Manually run security rating
diag report-runner trigger
report
diag vpn ike log filter Filter for IKE negotiation output
diag vpn ike gateway list Phase 1 state
diag vpn ike gateway flush Delete Phase 1 Wireless, Switch, FortiExtender
diag vpn tunnel list Phase 2 state Access Point (CLI commands on Access Point)
diag vpn tunnel flush Delete Phase 2 cfg –a Change IP from DHCP to static
get vpn ike gateway Detailed gateway information ADDR_MODE=DHCP|STATIC on FortiAP
System
Default Device Information Hardware Acceleration
admin / no password Default login config firewall policy Disable session offloading per
set auto-asic-offload disable firewall policy
Default IP on port1, internal or
192.168.1.99 config vpn ipsec phase-1-int Disable VPN offloading per
management port
set npu-offload disable Phase 1
9600/8-N-1
Default serial console settings
hardware flow control disabled
HQIP Hardware Check
Factory Reset
Download Hardware Quick
exec factoryreset Reset whole configuration
https://support.fortinet.com → Inspection Package (HQIP)
exec factoryreset-shutdown Reset config and shutdown Download → HQIP Images to scan hardware for
possible faults
Reset with retaining admin,
exec factoryreset2
interfaces and static routing
exec factoryreset keepvmlicense Reset whole config but license
General Information
Firmware Update Fortinet Links
Show config errors after Documentation, Cookbooks,
diag debug config-error-log read docs.fortinet.com
firmware upgrades Release Notes
community.fortinet.com Knowledge Base, User Forum
VDOMs
www.fortiguard.com FortiGuard Website
sudo global/ vdom-name Sudo-command to access
support.fortinet.com Support Site (Login required)
diag / exec / show / get global / VDOM settings directly
Fortinet Developer Network
fndn.fortinet.net
(Login required)
Transparent Mode
blog.boll.ch Boll Blog
diag netlink brctl name host Bridge MAC table
Disk Operation
diag sys logdisk usage Logdisk usage information
diag hardware deviceinfo disk List disks with partitions
exec disk list List the disks and partitions
exec disk scan [ref_int] Run a disk check operation
Format the specified partitions
exec disk format [ref_int]
or disks and reboots the system
Formatting the log disk, reboot
exec formatlogdisk
included