Advanced troubleshooting
More actions
Advanced troubleshooting commands and diagnostic procedures for Fortinet FortiGate devices.
Packet capture
Use the FortiGate packet sniffer to capture traffic directly from the CLI.
diag sniffer packet any '!port 22' 4 10 <tsformat>
Parameters
| Parameter | Description |
|---|---|
interfaces
|
any, or specify an interface name
|
filters
|
Example: udp and !port 22 and port 1812 and host 10.1.1.1. No filter can also be specified.
|
level
|
4 prints the interface name and packet header.
|
count
|
Number of packets to capture. Example: 10.
|
tsformat
|
If not specified, relative time is used. l displays local time.
|
Packet flow debugging
Packet flow debugging can be used to determine whether traffic is being accepted, forwarded or denied. This provides functionality similar to FW Monitor when troubleshooting Check Point environments.
diag debug flow show function enable diag debug flow show console enable diag debug flow filter addr 10.31.101.22 diag debug flow filter port 80 diag debug enable diag debug flow trace start 100 diag debug disable
VPN troubleshooting
VPN status and IKE debugging
diag vpn tunnel list get ipsec tunnel list get vpn ipsec tunnel summary diag vpn ike log filter name <phase1-name> diag vpn ike log filter src-addr4 <peer> diag debug application ike -1 diag debug enable diag vpn tunnel flush <phase1-name> diag vpn tunnel reset <phase1-name> diag debug disable
diag debug application ike -1 enables detailed IKE debugging. Some FortiOS versions and troubleshooting procedures may use 255 instead.Reset or clear VPN tunnels
diag vpn ike restart diag vpn ike gateway clear name <name_P1> diag vpn ike gateway flush name <name_P1>
IPS troubleshooting
IPS information and bypass mode
diag test application ipsmonitor <number>
Common values:
| Value | Function |
|---|---|
1
|
Display engine information |
2
|
Enable or disable the IPS engine |
5
|
Toggle bypass status |
99
|
Restart IPS engines/monitor |
Restart IPS engine
diag test application ipsengine 99
Web filtering
Restart WebFilter
diag test application urlfilter 99
Web cache database diagnostics
Display diagnostic information for the web cache database daemon (WACS).
diag wacs clear diag wacs recents diag wacs restart diag wacs stats
Authentication testing
LDAP
diag test auth ldap <server> <username> <password>
RADIUS
diag test auth radius <server> <chap|pap|mschap|mschap2> <username> <password>
WebUI debugging
diag debug cli 8 diag debug enable
Remember to disable debugging after completing the investigation.
diag debug disable
FortiGuard connectivity and licensing
exec log fortiguard test-connectivity get system fortiguard-service status
Log disk
exec formatlogdisk
FSSO troubleshooting
diagnose debug authd fsso filter ? diagnose debug authd fsso list diagnose debug authd fsso refresh-logons diagnose debug authd fsso refresh-groups get user adgrp
Factory reset
To clear the configuration while retaining network interface configuration:
execute factoryreset2
For FortiManager/FortiAnalyzer:
exec reset all-except-ip
Testing firmware without writing to flash
It is possible to load firmware for evaluation without immediately writing the image to flash.
Connect to the serial console and configure the TFTP server. Reboot the device and interrupt the boot process within the available boot-menu window. Retrieve the firmware image from the TFTP server and select the option to run the image rather than save it to flash.