Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Advanced troubleshooting

From Tech-Wiki


Advanced troubleshooting commands and diagnostic procedures for Fortinet FortiGate devices.

ⓘ
Command compatibility
Commands can vary between FortiOS versions. Verify command availability and syntax before using these examples on production devices.

Packet capture

Use the FortiGate packet sniffer to capture traffic directly from the CLI.

>_Packet capture (sniffer)
diag sniffer packet any '!port 22' 4 10 <tsformat>

Parameters

Parameter Description
interfaces any, or specify an interface name
filters Example: udp and !port 22 and port 1812 and host 10.1.1.1. No filter can also be specified.
level 4 prints the interface name and packet header.
count Number of packets to capture. Example: 10.
tsformat If not specified, relative time is used. l displays local time.
✓
Filter the capture
Use the narrowest practical packet filter when troubleshooting busy systems. This reduces unnecessary output and makes the resulting capture easier to analyse.

Packet flow debugging

Packet flow debugging can be used to determine whether traffic is being accepted, forwarded or denied. This provides functionality similar to FW Monitor when troubleshooting Check Point environments.

!
Production systems
Debug output can be verbose and may affect system performance. Apply appropriate filters and disable debugging when the investigation is complete.
>_Debug traffic for a specific address and port
diag debug flow show function enable
diag debug flow show console enable
diag debug flow filter addr 10.31.101.22
diag debug flow filter port 80
diag debug enable
diag debug flow trace start 100
diag debug disable

VPN troubleshooting

VPN status and IKE debugging

>_VPN diagnostic commands
diag vpn tunnel list
get ipsec tunnel list
get vpn ipsec tunnel summary

diag vpn ike log filter name <phase1-name>
diag vpn ike log filter src-addr4 <peer>
diag debug application ike -1
diag debug enable

diag vpn tunnel flush <phase1-name>
diag vpn tunnel reset <phase1-name>

diag debug disable
ⓘ
IKE debug level
diag debug application ike -1 enables detailed IKE debugging. Some FortiOS versions and troubleshooting procedures may use 255 instead.

Reset or clear VPN tunnels

>_Reset or clear VPN tunnels
diag vpn ike restart
diag vpn ike gateway clear name <name_P1>
diag vpn ike gateway flush name <name_P1>

IPS troubleshooting

IPS information and bypass mode

>_IPS monitor
diag test application ipsmonitor <number>

Common values:

Value Function
1 Display engine information
2 Enable or disable the IPS engine
5 Toggle bypass status
99 Restart IPS engines/monitor

Restart IPS engine

>_Restart IPS engine
diag test application ipsengine 99

Web filtering

Restart WebFilter

>_Restart WebFilter
diag test application urlfilter 99

Web cache database diagnostics

Display diagnostic information for the web cache database daemon (WACS).

>_WACS diagnostics
diag wacs clear
diag wacs recents
diag wacs restart
diag wacs stats

Authentication testing

LDAP

>_Test LDAP authentication
diag test auth ldap <server> <username> <password>

RADIUS

>_Test RADIUS authentication
diag test auth radius <server> <chap|pap|mschap|mschap2> <username> <password>
!
Credentials
Authentication test commands may require credentials to be entered directly at the CLI. Take appropriate precautions to prevent credentials being exposed through terminal logging, screen sharing or command history.

WebUI debugging

>_Debug WebUI activity
diag debug cli 8
diag debug enable

Remember to disable debugging after completing the investigation.

>_Disable debugging
diag debug disable

FortiGuard connectivity and licensing

>_Check FortiGuard connectivity and service status
exec log fortiguard test-connectivity
get system fortiguard-service status

Log disk

!
Destructive operation
Formatting the log disk removes data from the log disk. Confirm that this is appropriate before running the command.
>_Initialize the log disk
exec formatlogdisk

FSSO troubleshooting

>_FSSO diagnostic commands
diagnose debug authd fsso filter ?
diagnose debug authd fsso list
diagnose debug authd fsso refresh-logons
diagnose debug authd fsso refresh-groups
get user adgrp

Factory reset

!
Configuration loss
Factory reset operations can remove device configuration. Ensure that an appropriate configuration backup exists and confirm the behaviour of the command for the device and FortiOS version before proceeding.

To clear the configuration while retaining network interface configuration:

>_Factory reset while retaining interface configuration
execute factoryreset2

For FortiManager/FortiAnalyzer:

>_Reset while retaining IP configuration
exec reset all-except-ip

Testing firmware without writing to flash

It is possible to load firmware for evaluation without immediately writing the image to flash.

✓
Prerequisites
  • Serial console access
  • TFTP server
  • Appropriate firmware image
  • Current configuration backup

Connect to the serial console and configure the TFTP server. Reboot the device and interrupt the boot process within the available boot-menu window. Retrieve the firmware image from the TFTP server and select the option to run the image rather than save it to flash.

!
Firmware recovery procedure
Boot-loader options and firmware recovery procedures can vary between FortiGate models and firmware releases. Confirm the documented procedure for the specific device before proceeding.

See also