By Manny Fernandez

May 27, 2024

My FortiGate FortiOS CLI Bible’ish

My FortiGate FortiOS CLI Bible’ish

A working collection of the FortiOS CLI commands I actually reach for day to day: recon, interfaces, sniffer, sessions, VPN, HA, routing, logging, and more. No fluff. Just the commands that work.

General Recon

Gather helpful info: version, serial number, etc.

get system status

Debug WebUI Activity

diag debug cli 8
diag debug enable

Multi-Line Grep

Search multiple strings in a single grep pass:

show | grep '%something\|%something-else\|%even-more'

Example:

get router info bgp summary | grep '10.255.255.164\|152.162.33.49'

Interface and IP Information

dia ip address list

All IP addresses on the box (Cisco equivalent: show ip int br | e unass)

diagnose netlink interface list
diagnose netlink interface list port5
get system interface transceiver
diag ip arp delete <interface> <ip-address>
fnsysctl ifconfig port16

diag ip arp list shows the ARP table. Field reference:

Field Description
index Interface index of the corresponding FortiGate interface
ifname Name of the FortiGate interface
x.x.x.x IP address of the neighbor device connected to the corresponding interface
MAC address MAC address corresponding to the above IP address
state Hexadecimal value of the 8-bit field defining the current state of the ARP entry
use Time in seconds since the ARP entry was last used to add the MAC address to an egress packet
confirm Time in seconds since the ARP entry entered the state REACHABLE/NOARP/PERMANENT
update Time in seconds since the ARP entry was last updated with an ARP response
ref Number of times the ARP entry was used to forward an egress packet
Command Description
diagnose firewall iplist list Get information on ip-pool/VIP
diagnose sys vd list List virtual domains
diagnose sys cmdb info CMDB information (run 2 to 4 times)
diagnose hardware deviceinfo disk Display information on all disks (if the unit has one)
diagnose autoupdate versions Update object versions
diagnose sys session full-stat Displays the session stats (ESTABLISHED, SYN_SENT, etc.)
diagnose debug crashlog read Get the crash log info
diagnose user banned-ip list Display quarantined devices
diagnose user quarantine delete src4 x.x.x.x Delete a banned IP
show firewall acl Display the local ACLs on the FortiGate

Referenced Objects

Check references and dependencies for a given object:

diagnose sys cmdb refcnt show system.interface.name %object-name%
diag sys cmdb refcnt show system.interface.name <interface name>
diag sys cmdb refcnt show firewall.address:name <address name>
diag sys cmdb refcnt show firewall.profile: <profile name>
diag sys cmdb refcnt show firewall.service.group:name <servicegroup name>
diagnose sys cmdb info

The last line shows information about the latest configuration change performed by the daemon.

exec tac report

Generate a TAC report.

diag debug crashlog read
diag debug crashlog get

The first shows the crash log in a readable format; the second shows it in an encrypted format.

Command Line Shortcuts

Shortcut Action
Up arrow, CTRL-P Previous command
Down arrow, CTRL-N Next command
CTRL-A Beginning of line
CTRL-E End of line
CTRL-B Back one word
CTRL-F Forward one word
CTRL-D Delete current character
CTRL-C Abort command and exit branch (can disconnect you)
CTRL-L Clear screen
TAB key Completes the current word, or iterates through the following words
? Possible commands

Performance Commands

Command Description
get system status Displays firmware and FortiGuard engine versions plus other system information
get system performance status Run 5 times: CPU/memory states, average network usage, average sessions and session setup rate, viruses caught, IPS attacks blocked, and uptime
di sys top 2 50 Run for 30 sec, CTRL-C to stop: top processes running on the unit
di sys top-all Top threads information
diagnose sys mpstat CPU information
diagnose hardware sysinfo interrupts Display system interrupts information
diagnose hardware sysinfo memory Display system memory information
diag hardware sysinfo slab Display memory allocation information
diagnose sys top-mem Display processes with the most used memory (default 5 processes)
diagnose hardware sys conserve Aid in conserve mode issues
diagnose hardware deviceinfo nic %portx% Display stats on interfaces

Enabling / Disabling Features

Overlapping IP Addresses

config system settings
    set allow-subnet-overlap [enable/disable]
end

Enabling Async on FortiGate

conf sys setting
    set asymroute enable
end

Cisco Security Tag (SGT)

On the VWire, “wildcard VLAN” must be enabled:

set wildcard-vlan enable

On the policy, the SGT must be set:

config firewall policy
    edit 76
        set sgt-check enable
        set sgt 30
    next
end

Enabling LLDP on FortiGate

Globally:

config system global
    set lldp-reception enable
    set lldp-transmission enable
end

Per interface:

config system interface
    edit <port>
        set lldp-reception enable
        set lldp-transmission enable
    next
end

Showing LLDP neighbors:

diagnose lldprx neighbor {summary | details | clear}
diagnose lldprx port {details | summary | neighbor | filter}
diagnose lldprx port neighbor {summary | details}

Admin Connections

Showing Admin Connections

get system info admin status

Disconnect Admin Connection from CLI

execute disconnect-admin-session

Terminal Length on Console

Similar to term length 0 in Cisco:

config system console
    set output standard
end

Sniffer

I wrote a detailed blog post about the sniffer and TCP flags.

diag sniffer packet %int-name% 'host|net %ip|subnet% and|or %host|net% %ip|subnet% and proto|' 4 l 0

diagnose sniffer packet <interface> "<options>" <verbosity level> <count> <timestamp format>

Breaking that down:

Parameter Description
diagnose sniffer packet The base command
interface Choose the interface specifically, or use the keyword any
options Filter the capture by IP, protocol, etc.
verbosity level How much information you’re collecting (1 to 6, see below)
count Number of packets to capture (0 = unlimited)
timestamp Format of the timestamps on the capture

Verbosity levels:

Level Description
1 Print header of packets
2 Print header and data from IP of packets
3 Print header and data from ethernet of packets (if available)
4 Print header of packets with interface name
5 Print header and data from IP of packets with interface name
6 Print header and data from ethernet of packets (if available) with interface

Examples:

diag sniffer packet any "src 10.1.105.3 and icmp" 4 l 0
diag sniffer packet any "dst 8.8.8.8 and icmp" 4 l 0
dia sniff packet any "(src 10.1.105.3 or src 10.1.105.1) and icmp" 4 l 0
dia sniffer packet any 'host 10.1.105.3 and !port 22' 4 l 0
diag sniffer packet wan1 'host 10.109.16.137 and (icmp or tcp)' 1
diag sniffer packet wan1 'host 10.109.16.137 and host 172.26.48.21 and tcp port 80' 1 3

Filter keywords you can combine:

Address Protocol
host, src, dst, net, src net, dst net, and/or proto, port, !port, tcp, tcp port, udp, udp port

Use verbosity 3 or 6 when capturing traffic you plan to convert to a PCAP:

fgt2eth.pl -in ~/Desktop/diadebug.txt -out /Users/fernandezm/Desktop/remote4.pcap

You can create a per-interface PCAP file by adding a -demux argument while converting the text file to a PCAP. It creates two separate files, which is useful for troubleshooting pre/post-NAT issues.

Session

I have another post on sessions specifically.

diagnose sys session filter clear
diagnose sys session filter ?
diagnose sys session filter dst 8.8.8.8
diagnose sys session filter dport 53
diagnose sys session list

The last line shows the session table with the filter just set.

Filter Parameter Description
clear Clear session filter
dport Destination port
dst Destination IP address
negate Inverse filter
policy Policy ID
proto Protocol number
sport Source port
src Source IP address
vd Index of the virtual domain; -1 matches all

TCP session states:

State Value Expire Timer (default)
NONE 0 10 s
ESTABLISHED 1 3600 s
SYN_SENT 2 10 s
SYN & SYN/ACK 3 10 s
FIN_WAIT 4 120 s
TIME_WAIT 5 1 s
CLOSE 6 10 s
CLOSE_WAIT 7 120 s
LAST_ACK 8 30 s
LISTEN 9 120 s

Flow

Packet flow debug, the equivalent of FW Monitor in Check Point, used to evaluate whether a packet is accepted, forwarded, or denied:

diag debug flow show function enable
diag debug flow filter saddr X.X.X.X
diag debug flow filter saddr Y.Y.Y.Y
diag debug flow filter port N
diag debug flow trace start 100
diag debug enable
diag debug disable

IPerf

diag traffictest server-intf
diag traffictest client-intf
diag traffictest port [port]
diag traffictest run -c [public_iperf_server_ip]

VPN

VPN Debug Commands

diag vpn tunnel list
diag vpn ike log filter name
diag vpn ike log filter src-addr4 X.X.X.X
diag vpn ike log filter dst-addr4 Y.Y.Y.Y
diag debug application ike -1 (or 255)
diag debug enable
diag vpn tunnel flush
diag vpn tunnel reset
diag debug disable

Reset/Clear VPN Tunnels

diagnose vpn ike gateway list
diag vpn ike gateway clear name
diag vpn ike gateway flush name
diag vpn tunnel up|down <phase2-name>
diag vpn ike restart

gateway flush name tears down the specified phase 1. tunnel up|down brings the specified phase 2 up or down. ike restart restarts all tunnels.

Disable VPN offloading per phase 1:

config vpn ipsec phase-1-int
    set npu-offload disable
diagnose debug enable
diagnose debug application sslvpn -1
diagnose debug application sslvpn 0

The last line negates the debug.

config vpn ssl settings
    set idle-timeout 300
    set auth-timout 28000

idle-timeout only applies when idle. The auth timeout is a hard stop whether idle or not.

HA

Command Description
execute ha manage 0/1 Connect to the secondary box via CLI
get system ha status Show HA status
dia sys ha status More streamlined HA status view
get system checksum status Get the HA checksum
diagnose sys ha hadiff status Show HA difference (Global, Root, etc.)
diagnose sys ha checksum cluster Compare checksum with other cluster members
diagnose sys ha reset uptime Force fail-over
diag sys ha history read Check the history of the election process
diag sys ha mac Show HA MAC address assignment
diagnose sys ha reset-health-status Only use in response to the related error condition
execute ha failover set 1 Force fail-over from the active unit
diag debug appl hatalk -1 HA talk debug
diag debug appl hasync -1 HA sync debug

Disable the Shutting of Interfaces on Failover

config system ha
    set link-failed-signal enable
    set ha-mgmt-interface "mgmt"
end

Routing

dia ip rtcache list
dia firewall proute list
dia ip proute match <destination ip> <source ip> <incoming interface> <proto> <destination port number>
get router info
get router info protocol

ip rtcache list shows the route cache; firewall proute list shows matching PBR and SD-WAN rules; get router info protocol shows routing protocol information.

get router info routing-table subcommands:

Subcommand Shows
all Routing table information
protocols Routing protocols information
rip RIP information
ospf OSPF information
bgp Router BGP information
filter Filter for router information
multicast Routing multicast information
bfd BFD information
isis IS-IS information
kernel Kernel routing table
vrrp VRRP status
get router info routing-table detail 8.8.8.8
get router info routing-table all
execute router restart

The second line shows the current active routing table. The last line restarts the routing daemon.

BGP

get router info bgp summary
get router info routing-table bgp
get router info bgp neighbors 10.125.113.2 received-routes
get router info bgp neighbors 10.125.113.2 advertised-routes

The last two require graceful restart to be configured.

diagnose ip router bgp all enable
diagnose ip router bgp level info

TTL security for BGP (filed under BGP, though it lives under firewall):

config firewall ttl-policy
    edit 0
        set status enable
        set action deny
        set srcintf "any"
        set srcaddr "all"
        set service "BGP"
        set schedule "always"
        set ttl 1-252
    next
end

BGP best-path selection priority:

Priority Attribute
1 Weight
2 Local Preference
3 Originate
4 AS path length
5 Origin code
6 MED
7 eBGP path over iBGP path
8 Shortest IGP path to BGP next hop
9 Oldest path
10 Router ID
11 Neighbor IP address

Security Profile

diag test application ipsmonitor options:

Option Description
1 Display engine information
2 Enable/disable IPS engine
5 Toggle bypass status
99 Restart IPS engines/monitor
diag test application ipsengine 99

Restarts the IPS engine.

Contract and license check:

exec log fortiguard test-connectivity
get system fortiguard-service status

Verifying FortiGuard Labs:

diagnose autoupdate status
diagnose autoupdate versions

Log

exec log subcommands:

Subcommand Description
backup Backup
delete Delete local logs of one category
delete-all Delete all local logs and recreate the report database
detail Display UTM log entries for a particular traffic log
display Display filtered log entries
filter Filter
flush-cache Write disk log cache of the current category to disk in compressed format
flush-cache-all Write disk log cache of all categories to disk in compressed format
fortianalyzer / fortianalyzer-cloud / fortianalyzer2 / fortianalyzer3 FortiAnalyzer targets
fortiguard FortiGuard
list List current and rolled log file info
raw-backup Raw backup
roll Roll log files now

exec log filter % parameters:

Parameter Description
category Category
device Device to get log from
dump Dump current filter settings
field Filter by field
free-style Filter by free-style expression
ha-member HA member
local-search-mode Local log search mode
max-checklines Maximum number of lines to check
pre-fetch-pages Number of pages to check in advance under on-demand log search mode
reset Reset filter
start-line Start line to display
view-lines Lines per view

execute log filter category values:

Value Category
0 traffic
1 event
2 utm-virus
3 utm-webfilter
4 utm-ips
5 utm-emailfilter
7 utm-anomaly
8 utm-voip
9 utm-dlp
10 utm-app-ctrl
12 utm-waf
15 utm-dns
16 utm-ssh
17 utm-ssl
19 utm-file-filter
20 utm-icap
22 utm-sctp-filter
diag log test
execute log filter reset
execute log filter category event
execute log filter field
execute log filter field dstport 8001
execute log filter view-lines 1000
execute log filter start-line 1
execute log display

execute log filter field with no arguments prompts you with available field options.

To the FortiGate

See Established TCP/UDP Sessions to the FGT

diagnose sys tcpsock | grep %IP/PORT%
diagnose sys udpsock | grep %IP/PORT%

Firewall Interface Policy

Create a firewall address for the public IP:

config firewall address
    edit "ISP Internet"
        set associated-interface "port1X"
        set subnet X.X.X.X 255.255.255.255
    next
end

Create an IPS sensor to block offending IPs:

config ips sensor
    edit "Interface-Firewall-Sensor"
        set comment "Blocks all Critical/High/Medium and some Low severity vulnerabilities"
        set block-malicious-url enable
        set scan-botnet-connections block
        config entries
            edit 1
                set severity high critical
                set status enable
                set action block
                set quarantine attacker
                set quarantine-expiry 10d
            next
            edit 2
                set severity low medium
            next
        end
    next
end

Create the interface policy:

config firewall interface-policy
    edit 1
        set logtraffic all
        set interface "port16"
        set srcaddr "all"
        set dstaddr "ISP Internet"
        set service "ALL"
        set ips-sensor-status enable
        set ips-sensor "Interface-Firewall-Sensor"
    next
end

FortiSwitch

Command Description
diag switch-controller switch-info mac-table Managed FortiSwitch MAC address list
diag switch-controller switch-info port-stats Managed FortiSwitch port statistics
diag switch-controller switch-info trunk Trunk information
diag switch-controller switch-info mclag Dumps MCLAG-related information from the FortiSwitch
execute switch-controller get-conn-status Get FortiSwitch connection status
execute switch-controller diagnose-connection Get FortiSwitch connection diagnostics

Recent posts

  • If you've spent any time configuring user authentication on... Full Story

  • DNS is one of those technologies that quietly underpins... Full Story

  • BGP issues on FortiGate firewalls usually trace back to... Full Story

  • Every time your laptop talks to your router, a... Full Story

  • If you've spent any time configuring NAT on a... Full Story

  • If you have spent any time configuring firewall policies... Full Story

  • High availability on FortiGate is one of those features... Full Story

  • If you've configured SD-WAN on a FortiGate, you've almost... Full Story

  • FortiLink is the management protocol that turns a FortiSwitch... Full Story

  • FortiSwitches are pretty rock solid from Mean Time Between... Full Story

  • This is a quicky tip.  Have you ever gone... Full Story

  • DNS is one of those quiet pieces of internet... Full Story

  • This article is an updated version of the previous... Full Story

  • You will add ns2 as a secondary (slave) BIND9... Full Story

  • In the process of deploying my lab, I needed... Full Story

  • RFC 8805, used to be known as Self-Correcting IP... Full Story

  • Years back, I wrote an article about certificate pinning. ... Full Story

  • FortiGates have the ability to send alerts to Microsoft... Full Story

  • In this post, I am going to walk through... Full Story

  • Troubleshooting VoIP on a FortiGate can feel like trying... Full Story

  • Prior to FortiOS 7.0, there were three commands to... Full Story

  • In this post, I am going to go over... Full Story

  • What we are going to do:  We are going... Full Story

  • Choosing between FGCP (FortiGate Clustering Protocol) and FGSP (FortiGate... Full Story

  • Creating a VLAN on macOS (The "Pro" Move) A... Full Story

  • This blog post explores the logic behind how macOS... Full Story

  • Pretty Fly for a Wi-Fi Tell My Wi-Fi Love... Full Story

  • Part of my daily gig is creating BoMs (Bill-of-Materials)... Full Story

  • ICMP introduces several security risks, but careful filtering, rate... Full Story

  • The command diag debug application dhcps -1 enables full... Full Story

  • In the world of FortiOS, execute tac report is... Full Story

  • LLDP; What is it The Link Layer Discovery Protocol... Full Story

  • What it actually does When you run diagnose fdsm... Full Story

  • Monkey Bites are bite-sized, high-impact security insights designed for... Full Story

  • I have run macOS in macOS with Parallels but... Full Story

  • Don't be confused with my other FortiNAC posts where... Full Story

  • This is the third session in a multi-part article... Full Story

  • Today I was configuring key-based authentication on a FortiGate... Full Story

  • Netcat, often called the "Swiss Army knife" of networking,... Full Story

  • At its core, IEEE 802.1X is a network layer... Full Story

  • In case you did not see the previous FortiNAC... Full Story

  • This is our 5th session where we are going... Full Story

  • Now that we have Wireshark installed and somewhat configured,... Full Story

  • The Philosophy of Packet Analysis Troubleshooting isn't about looking... Full Story

  • In this guide Executive Summary Prerequisites: Which vi Do... Full Story

  • Objective: Strip blank and whitespace-only lines out of config... Full Story

  • In this guide Executive Summary Prerequisites and Architecture How... Full Story