FortiGate CLI Commands
FortiGate CLI Commands
FortiGate CLI Commands
CLI
FortiGate Basics:
Introduction:
Fortinet NGFWs meet the performance needs of highly scalable, hybrid IT architectures, enabling
organizations to reduce complexity and manage security risks.
Model used
• FortiGate 60E
• version 6.2.x
System related
Hardware related
Time related
execute time
# execute time
current time is: 15:02:56
last ntp sync:Sat Aug 8 14:49:25 2020
Copy
• Display the status of each interface such as up / down, speed, duplex, etc.
arp information
HA relationship
get system ha
• Show HA status
Link Monitor: 1, Status: alive, Server num(1), Create time: Sat Dec 28 08:52:08
2019
Source interface: VLAN50 (23)
Interval: 1
Peer: 192.168.179.1(192.168.179.1)
Source IP(10.1.50.1)
Route: 10.1.50.1->192.168.179.1/32, gwy(10.1.50.254)
protocol: ping, state: alive
Latency(Min/Max/Avg): 1.971/28.514/3.938 ms
Jitter(Min/Max/Avg): 0.002/23.504/2.436
Packet lost: 0.000%
Number of out-of-sequence packets: 2081298
Fail Times(0/1)
Packet sent: 3265569, received: 2146619, Sequence(sent/rcvd/exp):
54306/54306/65536
Copy
Routing relationship
OSFP related
OSPF process 0:
Codes: C - connected, D - Discard, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
BGP relationship
Other commands
NAT relationship
VPN related
gateway
name: 'hogeVPN'
type: route-based
local-gateway: 200.1.1.1:0 (static)
remote-gateway: 200.1.1.2:0 (static)
mode: ike-v1
interface: 'wan2' (6)
rx packets: 1 bytes: 112 errors: 0
tx packets: 6 bytes: 360 errors: 3
dpd: on-demand/negotiated idle: 20000ms retry: 3 count: 0
selectors
name: 'hogeVPN'
auto-negotiate: disable
mode: tunnel
src: 0:10.10.1.0/255.255.255.0:0
dst: 0:10.10.3.0/255.255.255.0:0
SA
lifetime/rekey: 3600/939
mtu: 1446
tx-esp-seq: 7
replay: enabled
inbound
spi: b6d3bcf0
enc: 3des a4593314d86840877574ce505f3cb5a1da5dad776bcdcabd
auth: sha1 a17f6c017664fa6a9f04306451f1012af1290eb6
outbound
spi: 930527e7
enc: 3des 2b0e04adf13362a39983efde93b753e2e7c2419e2ba45451
auth: sha1 0cbc298567e94e4e711582a2a1728c22dbb9f6cf
NPU acceleration: encryption(outbound) decryption(inbound)
Copy
Log related
• 1: memory
• 2: faz
• 4: fds
• 16: netscan
• 9: dlp
• 6: content
• 5: spam
• 4: ids
• 3: webfilter
• 2: virus
• 1: event
• 0: traffic
• View log
Happy Learning…
Rakesh