Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

FortiManager & FortiAnalyzer

From Tech-Wiki


Operational FortiManager and FortiAnalyzer command reference covering device replacement, backups, task repair, logging, database rebuilds and alerting.

FortiManager device operations

Replace a failed device

The original procedure notes that the unregistered device should be deleted first.

>_Replace a device
execute device replace sn <device_name> <serial>
execute fgfm reclaim-dev-tunnel

Restore FortiManager configuration

>_Restore all settings
execute migrate all-settings <ftp | scp | sftp> <server> <filepath> <user> <password> [cryptpasswd]

Enable scheduled scripts

config system admin setting
  set show_schedule_script enable
end

Clear hit counters

>_Reset hit count
execute reset hitcount

Repair stuck tasks

>_Repair DVM tasks
diag dvm task repair

Debug policy push

>_Security Console debug
diag debug app securityconsole 255
diag debug enable
!
Disable verbose debug after collection
Verbose diagnostic output can be high-volume. Enable it only for the troubleshooting window and return the appliance to its normal diagnostic state afterwards.

FortiManager backup

config system backup all-settings
  set status enable
  set server "10.1.10.2"
  set user "backup"
  set directory "/home/backup/"
  set week_days sunday
  set time "23:00:00"
  set passwd 1234
  set crptpasswd 1234
end
!
Use protected credentials
The values above are examples retained from the original article. Do not copy example passwords into a production backup configuration.

FortiGuard update status

>_Review update state and versions
diag autoupdate status
diag autoupdate versions

FortiAnalyzer database operations

Rebuild the database index from log data:

>_Rebuild the local SQL database
exec sql-local rebuild-db
diag sql status rebuild-db

FortiAnalyzer log rate

>_Display log/event rates
diag fortilogd lograte
diag fortilogd msgrate-type

Archive logs

>_Back up all logs
execute backup logs all ftp|sftp|scp <server> <username> <password>

After archiving, the original procedure enables the configured log-retention/deletion setting under System Settings → File Management.

FortiGate syslog forwarding

config log syslogd setting
  set status enable
  set server 192.168.1.50
  set reliable disable
  set port 514
  set csv disable
  set facility alert
  set source-ip 192.168.1.254
end

Log-based email alerting

config system alert-event
  edit warning
    config alert-destination
      edit 1
        set type mail
        set from [email protected]
        set to [email protected]
        set smtp-name mail.example.com
      next
    end
    set enable-severity-filter enable
    set severity-level-log error
    set severity-level-comp =
    set severity-filter medium
    set event-time-period 1
    set num-events 5
    set enable-generic-text enable
    set generic-text <string>
  next
end

Relevant values from the original reference:

  • severity-level-log: no-check, information, notify, warning, error, critical, alert, emergency.
  • severity-level-comp: >=, =, <=.
  • event-time-period: 0.5, 1, 3, 6, 12, 24, 72, 168.
  • num-events: 1, 5, 10, 50, 100.
  • generic-text supplies the string used for matching in generic-text/Grep mode.

See also