If you've spent any time configuring user authentication on... Full Story
By Manny Fernandez
May 27, 2024
My FortiGate FortiOS CLI Bible’ish
My FortiGate FortiOS CLI Bible’ish
A working collection of the FortiOS CLI commands I actually reach for day to day: recon, interfaces, sniffer, sessions, VPN, HA, routing, logging, and more. No fluff. Just the commands that work.
Quick jump
General Recon
Gather helpful info: version, serial number, etc.
get system status
Debug WebUI Activity
diag debug cli 8 diag debug enable
Multi-Line Grep
Search multiple strings in a single grep pass:
show | grep '%something\|%something-else\|%even-more'
Example:
get router info bgp summary | grep '10.255.255.164\|152.162.33.49'
Interface and IP Information
dia ip address list
All IP addresses on the box (Cisco equivalent: show ip int br | e unass)
diagnose netlink interface list diagnose netlink interface list port5
get system interface transceiver diag ip arp delete <interface> <ip-address> fnsysctl ifconfig port16
diag ip arp list shows the ARP table. Field reference:
| Field | Description |
|---|---|
| index | Interface index of the corresponding FortiGate interface |
| ifname | Name of the FortiGate interface |
| x.x.x.x | IP address of the neighbor device connected to the corresponding interface |
| MAC address | MAC address corresponding to the above IP address |
| state | Hexadecimal value of the 8-bit field defining the current state of the ARP entry |
| use | Time in seconds since the ARP entry was last used to add the MAC address to an egress packet |
| confirm | Time in seconds since the ARP entry entered the state REACHABLE/NOARP/PERMANENT |
| update | Time in seconds since the ARP entry was last updated with an ARP response |
| ref | Number of times the ARP entry was used to forward an egress packet |
| Command | Description |
|---|---|
| diagnose firewall iplist list | Get information on ip-pool/VIP |
| diagnose sys vd list | List virtual domains |
| diagnose sys cmdb info | CMDB information (run 2 to 4 times) |
| diagnose hardware deviceinfo disk | Display information on all disks (if the unit has one) |
| diagnose autoupdate versions | Update object versions |
| diagnose sys session full-stat | Displays the session stats (ESTABLISHED, SYN_SENT, etc.) |
| diagnose debug crashlog read | Get the crash log info |
| diagnose user banned-ip list | Display quarantined devices |
| diagnose user quarantine delete src4 x.x.x.x | Delete a banned IP |
| show firewall acl | Display the local ACLs on the FortiGate |
Referenced Objects
Check references and dependencies for a given object:
diagnose sys cmdb refcnt show system.interface.name %object-name% diag sys cmdb refcnt show system.interface.name <interface name> diag sys cmdb refcnt show firewall.address:name <address name> diag sys cmdb refcnt show firewall.profile: <profile name> diag sys cmdb refcnt show firewall.service.group:name <servicegroup name> diagnose sys cmdb info
The last line shows information about the latest configuration change performed by the daemon.
exec tac report
Generate a TAC report.
diag debug crashlog read diag debug crashlog get
The first shows the crash log in a readable format; the second shows it in an encrypted format.
Command Line Shortcuts
| Shortcut | Action |
|---|---|
| Up arrow, CTRL-P | Previous command |
| Down arrow, CTRL-N | Next command |
| CTRL-A | Beginning of line |
| CTRL-E | End of line |
| CTRL-B | Back one word |
| CTRL-F | Forward one word |
| CTRL-D | Delete current character |
| CTRL-C | Abort command and exit branch (can disconnect you) |
| CTRL-L | Clear screen |
| TAB key | Completes the current word, or iterates through the following words |
| ? | Possible commands |
Performance Commands
| Command | Description |
|---|---|
| get system status | Displays firmware and FortiGuard engine versions plus other system information |
| get system performance status | Run 5 times: CPU/memory states, average network usage, average sessions and session setup rate, viruses caught, IPS attacks blocked, and uptime |
| di sys top 2 50 | Run for 30 sec, CTRL-C to stop: top processes running on the unit |
| di sys top-all | Top threads information |
| diagnose sys mpstat | CPU information |
| diagnose hardware sysinfo interrupts | Display system interrupts information |
| diagnose hardware sysinfo memory | Display system memory information |
| diag hardware sysinfo slab | Display memory allocation information |
| diagnose sys top-mem | Display processes with the most used memory (default 5 processes) |
| diagnose hardware sys conserve | Aid in conserve mode issues |
| diagnose hardware deviceinfo nic %portx% | Display stats on interfaces |
Enabling / Disabling Features
Overlapping IP Addresses
config system settings
set allow-subnet-overlap [enable/disable]
end
Enabling Async on FortiGate
conf sys setting
set asymroute enable
end
Cisco Security Tag (SGT)
On the VWire, “wildcard VLAN” must be enabled:
set wildcard-vlan enable
On the policy, the SGT must be set:
config firewall policy
edit 76
set sgt-check enable
set sgt 30
next
end
Enabling LLDP on FortiGate
Globally:
config system global
set lldp-reception enable
set lldp-transmission enable
end
Per interface:
config system interface
edit <port>
set lldp-reception enable
set lldp-transmission enable
next
end
Showing LLDP neighbors:
diagnose lldprx neighbor {summary | details | clear}
diagnose lldprx port {details | summary | neighbor | filter}
diagnose lldprx port neighbor {summary | details}
Admin Connections
Showing Admin Connections
get system info admin status
Disconnect Admin Connection from CLI
execute disconnect-admin-session
Terminal Length on Console
Similar to term length 0 in Cisco:
config system console
set output standard
end
Sniffer
I wrote a detailed blog post about the sniffer and TCP flags.
diag sniffer packet %int-name% 'host|net %ip|subnet% and|or %host|net% %ip|subnet% and proto|' 4 l 0 diagnose sniffer packet <interface> "<options>" <verbosity level> <count> <timestamp format>
Breaking that down:
| Parameter | Description |
|---|---|
| diagnose sniffer packet | The base command |
| interface | Choose the interface specifically, or use the keyword any |
| options | Filter the capture by IP, protocol, etc. |
| verbosity level | How much information you’re collecting (1 to 6, see below) |
| count | Number of packets to capture (0 = unlimited) |
| timestamp | Format of the timestamps on the capture |
Verbosity levels:
| Level | Description |
|---|---|
| 1 | Print header of packets |
| 2 | Print header and data from IP of packets |
| 3 | Print header and data from ethernet of packets (if available) |
| 4 | Print header of packets with interface name |
| 5 | Print header and data from IP of packets with interface name |
| 6 | Print header and data from ethernet of packets (if available) with interface |
Examples:
diag sniffer packet any "src 10.1.105.3 and icmp" 4 l 0 diag sniffer packet any "dst 8.8.8.8 and icmp" 4 l 0 dia sniff packet any "(src 10.1.105.3 or src 10.1.105.1) and icmp" 4 l 0 dia sniffer packet any 'host 10.1.105.3 and !port 22' 4 l 0 diag sniffer packet wan1 'host 10.109.16.137 and (icmp or tcp)' 1 diag sniffer packet wan1 'host 10.109.16.137 and host 172.26.48.21 and tcp port 80' 1 3
Filter keywords you can combine:
| Address | Protocol |
|---|---|
| host, src, dst, net, src net, dst net, and/or | proto, port, !port, tcp, tcp port, udp, udp port |
Use verbosity 3 or 6 when capturing traffic you plan to convert to a PCAP:
fgt2eth.pl -in ~/Desktop/diadebug.txt -out /Users/fernandezm/Desktop/remote4.pcap
You can create a per-interface PCAP file by adding a -demux argument while converting the text file to a PCAP. It creates two separate files, which is useful for troubleshooting pre/post-NAT issues.
Session
I have another post on sessions specifically.
diagnose sys session filter clear diagnose sys session filter ? diagnose sys session filter dst 8.8.8.8 diagnose sys session filter dport 53 diagnose sys session list
The last line shows the session table with the filter just set.
| Filter Parameter | Description |
|---|---|
| clear | Clear session filter |
| dport | Destination port |
| dst | Destination IP address |
| negate | Inverse filter |
| policy | Policy ID |
| proto | Protocol number |
| sport | Source port |
| src | Source IP address |
| vd | Index of the virtual domain; -1 matches all |
TCP session states:
| State | Value | Expire Timer (default) |
|---|---|---|
| NONE | 0 | 10 s |
| ESTABLISHED | 1 | 3600 s |
| SYN_SENT | 2 | 10 s |
| SYN & SYN/ACK | 3 | 10 s |
| FIN_WAIT | 4 | 120 s |
| TIME_WAIT | 5 | 1 s |
| CLOSE | 6 | 10 s |
| CLOSE_WAIT | 7 | 120 s |
| LAST_ACK | 8 | 30 s |
| LISTEN | 9 | 120 s |
Flow
Packet flow debug, the equivalent of FW Monitor in Check Point, used to evaluate whether a packet is accepted, forwarded, or denied:
diag debug flow show function enable diag debug flow filter saddr X.X.X.X diag debug flow filter saddr Y.Y.Y.Y diag debug flow filter port N diag debug flow trace start 100 diag debug enable diag debug disable
IPerf
diag traffictest server-intf diag traffictest client-intf diag traffictest port [port] diag traffictest run -c [public_iperf_server_ip]
VPN
VPN Debug Commands
diag vpn tunnel list diag vpn ike log filter name diag vpn ike log filter src-addr4 X.X.X.X diag vpn ike log filter dst-addr4 Y.Y.Y.Y diag debug application ike -1 (or 255) diag debug enable diag vpn tunnel flush diag vpn tunnel reset diag debug disable
Reset/Clear VPN Tunnels
diagnose vpn ike gateway list diag vpn ike gateway clear name diag vpn ike gateway flush name diag vpn tunnel up|down <phase2-name> diag vpn ike restart
gateway flush name tears down the specified phase 1. tunnel up|down brings the specified phase 2 up or down. ike restart restarts all tunnels.
Disable VPN offloading per phase 1:
config vpn ipsec phase-1-int
set npu-offload disable
diagnose debug enable diagnose debug application sslvpn -1 diagnose debug application sslvpn 0
The last line negates the debug.
config vpn ssl settings
set idle-timeout 300
set auth-timout 28000
idle-timeout only applies when idle. The auth timeout is a hard stop whether idle or not.
HA
| Command | Description |
|---|---|
| execute ha manage 0/1 | Connect to the secondary box via CLI |
| get system ha status | Show HA status |
| dia sys ha status | More streamlined HA status view |
| get system checksum status | Get the HA checksum |
| diagnose sys ha hadiff status | Show HA difference (Global, Root, etc.) |
| diagnose sys ha checksum cluster | Compare checksum with other cluster members |
| diagnose sys ha reset uptime | Force fail-over |
| diag sys ha history read | Check the history of the election process |
| diag sys ha mac | Show HA MAC address assignment |
| diagnose sys ha reset-health-status | Only use in response to the related error condition |
| execute ha failover set 1 | Force fail-over from the active unit |
| diag debug appl hatalk -1 | HA talk debug |
| diag debug appl hasync -1 | HA sync debug |
Disable the Shutting of Interfaces on Failover
config system ha
set link-failed-signal enable
set ha-mgmt-interface "mgmt"
end
Routing
dia ip rtcache list dia firewall proute list dia ip proute match <destination ip> <source ip> <incoming interface> <proto> <destination port number> get router info get router info protocol
ip rtcache list shows the route cache; firewall proute list shows matching PBR and SD-WAN rules; get router info protocol shows routing protocol information.
get router info routing-table subcommands:
| Subcommand | Shows |
|---|---|
| all | Routing table information |
| protocols | Routing protocols information |
| rip | RIP information |
| ospf | OSPF information |
| bgp | Router BGP information |
| filter | Filter for router information |
| multicast | Routing multicast information |
| bfd | BFD information |
| isis | IS-IS information |
| kernel | Kernel routing table |
| vrrp | VRRP status |
get router info routing-table detail 8.8.8.8 get router info routing-table all execute router restart
The second line shows the current active routing table. The last line restarts the routing daemon.
BGP
get router info bgp summary get router info routing-table bgp get router info bgp neighbors 10.125.113.2 received-routes get router info bgp neighbors 10.125.113.2 advertised-routes
The last two require graceful restart to be configured.
diagnose ip router bgp all enable diagnose ip router bgp level info
TTL security for BGP (filed under BGP, though it lives under firewall):
config firewall ttl-policy
edit 0
set status enable
set action deny
set srcintf "any"
set srcaddr "all"
set service "BGP"
set schedule "always"
set ttl 1-252
next
end
BGP best-path selection priority:
| Priority | Attribute |
|---|---|
| 1 | Weight |
| 2 | Local Preference |
| 3 | Originate |
| 4 | AS path length |
| 5 | Origin code |
| 6 | MED |
| 7 | eBGP path over iBGP path |
| 8 | Shortest IGP path to BGP next hop |
| 9 | Oldest path |
| 10 | Router ID |
| 11 | Neighbor IP address |
Security Profile
diag test application ipsmonitor options:
| Option | Description |
|---|---|
| 1 | Display engine information |
| 2 | Enable/disable IPS engine |
| 5 | Toggle bypass status |
| 99 | Restart IPS engines/monitor |
diag test application ipsengine 99
Restarts the IPS engine.
Contract and license check:
exec log fortiguard test-connectivity get system fortiguard-service status
Verifying FortiGuard Labs:
diagnose autoupdate status diagnose autoupdate versions
Log
exec log subcommands:
| Subcommand | Description |
|---|---|
| backup | Backup |
| delete | Delete local logs of one category |
| delete-all | Delete all local logs and recreate the report database |
| detail | Display UTM log entries for a particular traffic log |
| display | Display filtered log entries |
| filter | Filter |
| flush-cache | Write disk log cache of the current category to disk in compressed format |
| flush-cache-all | Write disk log cache of all categories to disk in compressed format |
| fortianalyzer / fortianalyzer-cloud / fortianalyzer2 / fortianalyzer3 | FortiAnalyzer targets |
| fortiguard | FortiGuard |
| list | List current and rolled log file info |
| raw-backup | Raw backup |
| roll | Roll log files now |
exec log filter % parameters:
| Parameter | Description |
|---|---|
| category | Category |
| device | Device to get log from |
| dump | Dump current filter settings |
| field | Filter by field |
| free-style | Filter by free-style expression |
| ha-member | HA member |
| local-search-mode | Local log search mode |
| max-checklines | Maximum number of lines to check |
| pre-fetch-pages | Number of pages to check in advance under on-demand log search mode |
| reset | Reset filter |
| start-line | Start line to display |
| view-lines | Lines per view |
execute log filter category values:
| Value | Category |
|---|---|
| 0 | traffic |
| 1 | event |
| 2 | utm-virus |
| 3 | utm-webfilter |
| 4 | utm-ips |
| 5 | utm-emailfilter |
| 7 | utm-anomaly |
| 8 | utm-voip |
| 9 | utm-dlp |
| 10 | utm-app-ctrl |
| 12 | utm-waf |
| 15 | utm-dns |
| 16 | utm-ssh |
| 17 | utm-ssl |
| 19 | utm-file-filter |
| 20 | utm-icap |
| 22 | utm-sctp-filter |
diag log test execute log filter reset execute log filter category event execute log filter field execute log filter field dstport 8001 execute log filter view-lines 1000 execute log filter start-line 1 execute log display
execute log filter field with no arguments prompts you with available field options.
To the FortiGate
See Established TCP/UDP Sessions to the FGT
diagnose sys tcpsock | grep %IP/PORT% diagnose sys udpsock | grep %IP/PORT%
Firewall Interface Policy
Create a firewall address for the public IP:
config firewall address
edit "ISP Internet"
set associated-interface "port1X"
set subnet X.X.X.X 255.255.255.255
next
end
Create an IPS sensor to block offending IPs:
config ips sensor
edit "Interface-Firewall-Sensor"
set comment "Blocks all Critical/High/Medium and some Low severity vulnerabilities"
set block-malicious-url enable
set scan-botnet-connections block
config entries
edit 1
set severity high critical
set status enable
set action block
set quarantine attacker
set quarantine-expiry 10d
next
edit 2
set severity low medium
next
end
next
end
Create the interface policy:
config firewall interface-policy
edit 1
set logtraffic all
set interface "port16"
set srcaddr "all"
set dstaddr "ISP Internet"
set service "ALL"
set ips-sensor-status enable
set ips-sensor "Interface-Firewall-Sensor"
next
end
FortiSwitch
| Command | Description |
|---|---|
| diag switch-controller switch-info mac-table | Managed FortiSwitch MAC address list |
| diag switch-controller switch-info port-stats | Managed FortiSwitch port statistics |
| diag switch-controller switch-info trunk | Trunk information |
| diag switch-controller switch-info mclag | Dumps MCLAG-related information from the FortiSwitch |
| execute switch-controller get-conn-status | Get FortiSwitch connection status |
| execute switch-controller diagnose-connection | Get FortiSwitch connection diagnostics |
Recent posts
-
-
DNS is one of those technologies that quietly underpins... Full Story
-
BGP issues on FortiGate firewalls usually trace back to... Full Story
-
Every time your laptop talks to your router, a... Full Story
-
If you've spent any time configuring NAT on a... Full Story
-
If you have spent any time configuring firewall policies... Full Story
-
High availability on FortiGate is one of those features... Full Story
-
If you've configured SD-WAN on a FortiGate, you've almost... Full Story
-
FortiLink is the management protocol that turns a FortiSwitch... Full Story
-
FortiSwitches are pretty rock solid from Mean Time Between... Full Story
-
This is a quicky tip. Have you ever gone... Full Story
-
DNS is one of those quiet pieces of internet... Full Story
-
This article is an updated version of the previous... Full Story
-
You will add ns2 as a secondary (slave) BIND9... Full Story
-
In the process of deploying my lab, I needed... Full Story
-
RFC 8805, used to be known as Self-Correcting IP... Full Story
-
Years back, I wrote an article about certificate pinning. ... Full Story
-
FortiGates have the ability to send alerts to Microsoft... Full Story
-
In this post, I am going to walk through... Full Story
-
Troubleshooting VoIP on a FortiGate can feel like trying... Full Story
-
Prior to FortiOS 7.0, there were three commands to... Full Story
-
In this post, I am going to go over... Full Story
-
What we are going to do: We are going... Full Story
-
Choosing between FGCP (FortiGate Clustering Protocol) and FGSP (FortiGate... Full Story
-
Creating a VLAN on macOS (The "Pro" Move) A... Full Story
-
This blog post explores the logic behind how macOS... Full Story
-
Pretty Fly for a Wi-Fi Tell My Wi-Fi Love... Full Story
-
Part of my daily gig is creating BoMs (Bill-of-Materials)... Full Story
-
ICMP introduces several security risks, but careful filtering, rate... Full Story
-
The command diag debug application dhcps -1 enables full... Full Story
-
In the world of FortiOS, execute tac report is... Full Story
-
LLDP; What is it The Link Layer Discovery Protocol... Full Story
-
What it actually does When you run diagnose fdsm... Full Story
-
Monkey Bites are bite-sized, high-impact security insights designed for... Full Story
-
I have run macOS in macOS with Parallels but... Full Story
-
Don't be confused with my other FortiNAC posts where... Full Story
-
This is the third session in a multi-part article... Full Story
-
Today I was configuring key-based authentication on a FortiGate... Full Story
-
Netcat, often called the "Swiss Army knife" of networking,... Full Story
-
At its core, IEEE 802.1X is a network layer... Full Story
-
In case you did not see the previous FortiNAC... Full Story
-
This is our 5th session where we are going... Full Story
-
Now that we have Wireshark installed and somewhat configured,... Full Story
-
The Philosophy of Packet Analysis Troubleshooting isn't about looking... Full Story
-
In this guide Executive Summary Prerequisites: Which vi Do... Full Story
-
Objective: Strip blank and whitespace-only lines out of config... Full Story
-
In this guide Executive Summary Prerequisites and Architecture How... Full Story