Fortinet white logo
Fortinet white logo

CLI Reference

diagnose vpn ssl

diagnose vpn ssl

SSL-VPN.

This topic includes the following commands:

diagnose vpn ssl app-session

List all app session in db.

diagnose vpn ssl app-session <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display all app session for all VDOMs or given VDOM name or VDOM ID. Without argument, app session for current VDOM is shown.

string

diagnose vpn ssl blocklist

SSL-VPN blocklist information

diagnose vpn ssl blocklist

diagnose vpn ssl blocklist count

Print counts of SSL-VPN blocklist

diagnose vpn ssl blocklist count <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN blocklist entries count for all VDOMs, given VDOM name or VDOM ID. Without argument, count for current VDOM is shown.

string

diagnose vpn ssl blocklist del

Del SSL-VPN blocklist

diagnose vpn ssl blocklist del <all|vfid|addr>

Parameter

Description

Type

Size

<all|vfid|addr>

Delete block list entries for all VDOMs, given VDOM ID or address.

string

diagnose vpn ssl blocklist list

List SSL-VPN blocklist

diagnose vpn ssl blocklist list <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN blocklist information for all VDOMs, given VDOM name or VDOM ID. Without argument, information for current VDOM is shown.

string

diagnose vpn ssl client

SSL-VPN Client diagnostics.

diagnose vpn ssl client

diagnose vpn ssl client config

SSL-VPN Client configuration.

diagnose vpn ssl client config

diagnose vpn ssl client config clear

Clear any cached configuration and re-load the configuration.

diagnose vpn ssl client config clear

diagnose vpn ssl client config list

Display SSL-VPN Client configuration.

diagnose vpn ssl client config list

diagnose vpn ssl client config load

Re-load the configuration.

diagnose vpn ssl client config load

diagnose vpn ssl client peer

SSL-VPN Client peer related commands.

diagnose vpn ssl client peer

diagnose vpn ssl client peer clear

Terminate SSL-VPN Clients.

diagnose vpn ssl client peer clear

diagnose vpn ssl client peer list

Display the status of SSL-VPN Clients.

diagnose vpn ssl client peer list

diagnose vpn ssl client restart

Restart the SSL-VPN Client manager process.

diagnose vpn ssl client restart

diagnose vpn ssl client stats

Display SSL-VPN Client statistics.

diagnose vpn ssl client stats

diagnose vpn ssl client time

Measure SSL-VPN Client times.

diagnose vpn ssl client time

diagnose vpn ssl client time disable

Disable measuring SSL-VPN Client times.

diagnose vpn ssl client time disable

diagnose vpn ssl client time enable

Enable measuring SSL-VPN Client times.

diagnose vpn ssl client time enable

diagnose vpn ssl client valgrind

Valgrind analysis.

diagnose vpn ssl client valgrind

diagnose vpn ssl client valgrind disable

Force daemon to restart.

diagnose vpn ssl client valgrind disable

diagnose vpn ssl client valgrind enable

Force daemon to restart.

diagnose vpn ssl client valgrind enable

diagnose vpn ssl client valgrind log

Valgrind logs.

diagnose vpn ssl client valgrind log

diagnose vpn ssl client valgrind log clear

Clear logs.

diagnose vpn ssl client valgrind log clear

diagnose vpn ssl client valgrind log show

Show logs.

diagnose vpn ssl client valgrind log show

diagnose vpn ssl client valgrind memcheck

Force daemon to restart.

diagnose vpn ssl client valgrind memcheck

diagnose vpn ssl client valgrind memcheck_less

Force daemon to restart.

diagnose vpn ssl client valgrind memcheck_less

diagnose vpn ssl client valgrind status

Show valgrind status.

diagnose vpn ssl client valgrind status

diagnose vpn ssl debug-filter

SSL-VPN debug message filter.

diagnose vpn ssl debug-filter

diagnose vpn ssl debug-filter clear

Erase the current filter.

diagnose vpn ssl debug-filter clear

diagnose vpn ssl debug-filter list

Display the current filter.

diagnose vpn ssl debug-filter list

diagnose vpn ssl debug-filter negate

Negate the specified filter parameter.

diagnose vpn ssl debug-filter negate

diagnose vpn ssl debug-filter negate src-addr4

IPv4 source address.

diagnose vpn ssl debug-filter negate src-addr4

diagnose vpn ssl debug-filter negate src-addr6

IPv6 source address.

diagnose vpn ssl debug-filter negate src-addr6

diagnose vpn ssl debug-filter negate vd

Virtual domain.

diagnose vpn ssl debug-filter negate vd

diagnose vpn ssl debug-filter src-addr4

IPv4 source address range.

diagnose vpn ssl debug-filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

source IPv4 address (from)

string

<ipv4-address>

source IPv4 address (to)

string

diagnose vpn ssl debug-filter src-addr6

IPv6 source address range.

diagnose vpn ssl debug-filter src-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

source IPv6 address (from)

string

<ipv6-address>

source IPv6 address (to)

string

diagnose vpn ssl debug-filter vd

Name of virtual domain.

diagnose vpn ssl debug-filter vd <vdom name>

Parameter

Description

Type

Size

<vdom name>

Name of virtual domain.

string

diagnose vpn ssl info

SSL-VPN information

diagnose vpn ssl info <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN information for all VDOMs, given VDOM name or VDOM ID. Without argument, information for current VDOM is shown.

string

diagnose vpn ssl list

List current connections.

diagnose vpn ssl list

diagnose vpn ssl mux

Show mux information.

diagnose vpn ssl mux

diagnose vpn ssl mux-stat

Show mux statistics.

diagnose vpn ssl mux-stat <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN interface statistics for all VDOMs or given VDOM name or VDOM ID. Without argument, statistics for current VDOM is shown.

string

diagnose vpn ssl saml-metadata

Display SSL-VPN SAML SP metadata for given SAML name.

diagnose vpn ssl saml-metadata <SAML name>

Parameter

Description

Type

Size

<SAML name>

Name of SAML user.

string

diagnose vpn ssl statistics

SSL-VPN statistics

diagnose vpn ssl statistics <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN statistics for all VDOMs or given VDOM name or VDOM ID. Without argument, statistics for current VDOM is shown.

string

diagnose vpn ssl tunnel-test

Enable/disable SSL-VPN old tunnel mode IP allocation method.

diagnose vpn ssl tunnel-test <enable>

Parameter

Description

Type

Size

<enable>

Enable SSL-VPN old tunnel mode IP allocation method. disable Disable SSL-VPN old tunnel mode IP allocation method.

string

diagnose vpn ssl user-session

List all user session in db.

diagnose vpn ssl user-session <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display all user session for all VDOMs or given VDOM name or VDOM ID. Without argument, user session for current VDOM is shown.

string

diagnose vpn ssl web-mode-test

Enable/disable random session ID in proxy URL for testing.

diagnose vpn ssl web-mode-test <enable>

Parameter

Description

Type

Size

<enable>

Enable random session ID in proxy URL for testing. disable Disable random session ID in proxy URL for testing.

string

diagnose vpn ssl

diagnose vpn ssl

SSL-VPN.

This topic includes the following commands:

diagnose vpn ssl app-session

List all app session in db.

diagnose vpn ssl app-session <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display all app session for all VDOMs or given VDOM name or VDOM ID. Without argument, app session for current VDOM is shown.

string

diagnose vpn ssl blocklist

SSL-VPN blocklist information

diagnose vpn ssl blocklist

diagnose vpn ssl blocklist count

Print counts of SSL-VPN blocklist

diagnose vpn ssl blocklist count <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN blocklist entries count for all VDOMs, given VDOM name or VDOM ID. Without argument, count for current VDOM is shown.

string

diagnose vpn ssl blocklist del

Del SSL-VPN blocklist

diagnose vpn ssl blocklist del <all|vfid|addr>

Parameter

Description

Type

Size

<all|vfid|addr>

Delete block list entries for all VDOMs, given VDOM ID or address.

string

diagnose vpn ssl blocklist list

List SSL-VPN blocklist

diagnose vpn ssl blocklist list <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN blocklist information for all VDOMs, given VDOM name or VDOM ID. Without argument, information for current VDOM is shown.

string

diagnose vpn ssl client

SSL-VPN Client diagnostics.

diagnose vpn ssl client

diagnose vpn ssl client config

SSL-VPN Client configuration.

diagnose vpn ssl client config

diagnose vpn ssl client config clear

Clear any cached configuration and re-load the configuration.

diagnose vpn ssl client config clear

diagnose vpn ssl client config list

Display SSL-VPN Client configuration.

diagnose vpn ssl client config list

diagnose vpn ssl client config load

Re-load the configuration.

diagnose vpn ssl client config load

diagnose vpn ssl client peer

SSL-VPN Client peer related commands.

diagnose vpn ssl client peer

diagnose vpn ssl client peer clear

Terminate SSL-VPN Clients.

diagnose vpn ssl client peer clear

diagnose vpn ssl client peer list

Display the status of SSL-VPN Clients.

diagnose vpn ssl client peer list

diagnose vpn ssl client restart

Restart the SSL-VPN Client manager process.

diagnose vpn ssl client restart

diagnose vpn ssl client stats

Display SSL-VPN Client statistics.

diagnose vpn ssl client stats

diagnose vpn ssl client time

Measure SSL-VPN Client times.

diagnose vpn ssl client time

diagnose vpn ssl client time disable

Disable measuring SSL-VPN Client times.

diagnose vpn ssl client time disable

diagnose vpn ssl client time enable

Enable measuring SSL-VPN Client times.

diagnose vpn ssl client time enable

diagnose vpn ssl client valgrind

Valgrind analysis.

diagnose vpn ssl client valgrind

diagnose vpn ssl client valgrind disable

Force daemon to restart.

diagnose vpn ssl client valgrind disable

diagnose vpn ssl client valgrind enable

Force daemon to restart.

diagnose vpn ssl client valgrind enable

diagnose vpn ssl client valgrind log

Valgrind logs.

diagnose vpn ssl client valgrind log

diagnose vpn ssl client valgrind log clear

Clear logs.

diagnose vpn ssl client valgrind log clear

diagnose vpn ssl client valgrind log show

Show logs.

diagnose vpn ssl client valgrind log show

diagnose vpn ssl client valgrind memcheck

Force daemon to restart.

diagnose vpn ssl client valgrind memcheck

diagnose vpn ssl client valgrind memcheck_less

Force daemon to restart.

diagnose vpn ssl client valgrind memcheck_less

diagnose vpn ssl client valgrind status

Show valgrind status.

diagnose vpn ssl client valgrind status

diagnose vpn ssl debug-filter

SSL-VPN debug message filter.

diagnose vpn ssl debug-filter

diagnose vpn ssl debug-filter clear

Erase the current filter.

diagnose vpn ssl debug-filter clear

diagnose vpn ssl debug-filter list

Display the current filter.

diagnose vpn ssl debug-filter list

diagnose vpn ssl debug-filter negate

Negate the specified filter parameter.

diagnose vpn ssl debug-filter negate

diagnose vpn ssl debug-filter negate src-addr4

IPv4 source address.

diagnose vpn ssl debug-filter negate src-addr4

diagnose vpn ssl debug-filter negate src-addr6

IPv6 source address.

diagnose vpn ssl debug-filter negate src-addr6

diagnose vpn ssl debug-filter negate vd

Virtual domain.

diagnose vpn ssl debug-filter negate vd

diagnose vpn ssl debug-filter src-addr4

IPv4 source address range.

diagnose vpn ssl debug-filter src-addr4 <ipv4-address> <ipv4-address>

Parameter

Description

Type

Size

<ipv4-address>

source IPv4 address (from)

string

<ipv4-address>

source IPv4 address (to)

string

diagnose vpn ssl debug-filter src-addr6

IPv6 source address range.

diagnose vpn ssl debug-filter src-addr6 <ipv6-address> <ipv6-address>

Parameter

Description

Type

Size

<ipv6-address>

source IPv6 address (from)

string

<ipv6-address>

source IPv6 address (to)

string

diagnose vpn ssl debug-filter vd

Name of virtual domain.

diagnose vpn ssl debug-filter vd <vdom name>

Parameter

Description

Type

Size

<vdom name>

Name of virtual domain.

string

diagnose vpn ssl info

SSL-VPN information

diagnose vpn ssl info <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN information for all VDOMs, given VDOM name or VDOM ID. Without argument, information for current VDOM is shown.

string

diagnose vpn ssl list

List current connections.

diagnose vpn ssl list

diagnose vpn ssl mux

Show mux information.

diagnose vpn ssl mux

diagnose vpn ssl mux-stat

Show mux statistics.

diagnose vpn ssl mux-stat <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN interface statistics for all VDOMs or given VDOM name or VDOM ID. Without argument, statistics for current VDOM is shown.

string

diagnose vpn ssl saml-metadata

Display SSL-VPN SAML SP metadata for given SAML name.

diagnose vpn ssl saml-metadata <SAML name>

Parameter

Description

Type

Size

<SAML name>

Name of SAML user.

string

diagnose vpn ssl statistics

SSL-VPN statistics

diagnose vpn ssl statistics <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display SSL-VPN statistics for all VDOMs or given VDOM name or VDOM ID. Without argument, statistics for current VDOM is shown.

string

diagnose vpn ssl tunnel-test

Enable/disable SSL-VPN old tunnel mode IP allocation method.

diagnose vpn ssl tunnel-test <enable>

Parameter

Description

Type

Size

<enable>

Enable SSL-VPN old tunnel mode IP allocation method. disable Disable SSL-VPN old tunnel mode IP allocation method.

string

diagnose vpn ssl user-session

List all user session in db.

diagnose vpn ssl user-session <all|vdom-name|vfid>

Parameter

Description

Type

Size

<all|vdom-name|vfid>

Display all user session for all VDOMs or given VDOM name or VDOM ID. Without argument, user session for current VDOM is shown.

string

diagnose vpn ssl web-mode-test

Enable/disable random session ID in proxy URL for testing.

diagnose vpn ssl web-mode-test <enable>

Parameter

Description

Type

Size

<enable>

Enable random session ID in proxy URL for testing. disable Disable random session ID in proxy URL for testing.

string