Fortinet white logo
Fortinet white logo

CLI Reference

diagnose firewall

diagnose firewall

Firewall

This topic includes the following commands:

diagnose firewall auth

Authenticated users.

diagnose firewall auth

diagnose firewall auth clear

Clear authenticated IPv4 users.

diagnose firewall auth clear

diagnose firewall auth filter

Filters used to list entries.

diagnose firewall auth filter

diagnose firewall auth filter clear

Clear all filters.

diagnose firewall auth filter clear

diagnose firewall auth filter group

Group name.

diagnose firewall auth filter group <name>

Parameter

Description

Type

Size

<name>

Group name.

string

diagnose firewall auth filter mac

MAC address.

diagnose firewall auth filter mac <xx:xx:xx:xx:xx:xx>

Parameter

Description

Type

Size

<xx:xx:xx:xx:xx:xx>

MAC address.

string

diagnose firewall auth filter method

method

diagnose firewall auth filter method <method>

Parameter

Description

Type

Size

<method>

Valid method name: fsso, rsso, ntlm, fw, wsso, disclaimer, fsso_citrix, sso_guest.

string

diagnose firewall auth filter policy

Policy ID.

diagnose firewall auth filter policy <xxx>

Parameter

Description

Type

Size

<xxx>

Policy ID.

string

diagnose firewall auth filter source

IPv4 source address.

diagnose firewall auth filter source <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

IPv4 source (range from).

string

diagnose firewall auth filter source6

IPv6 source address.

diagnose firewall auth filter source6 <xxxx::xxxx>

Parameter

Description

Type

Size

<xxxx::xxxx>

IPv6 source (range from).

string

diagnose firewall auth filter user

User name.

diagnose firewall auth filter user <name>

Parameter

Description

Type

Size

<name>

User name.

string

diagnose firewall auth ipv6

Authenticated IPv6 users.

diagnose firewall auth ipv6

diagnose firewall auth ipv6 clear

Clear authenticated IPv6 users.

diagnose firewall auth ipv6 clear

diagnose firewall auth ipv6 list

List authenticated IPv6 users.

diagnose firewall auth ipv6 list

diagnose firewall auth list

List authenticated IPv4 users.

diagnose firewall auth list

diagnose firewall auth mac

Authenticated MAC users.

diagnose firewall auth mac

diagnose firewall auth mac clear

Clear authenticated MAC users.

diagnose firewall auth mac clear

diagnose firewall auth mac list

List authenticated MAC users.

diagnose firewall auth mac list

diagnose firewall blocking

Blocking information.

diagnose firewall blocking

diagnose firewall blocking list

List information.

diagnose firewall blocking list <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

Source IP.

string

diagnose firewall dns-xlate

DNS translation.

diagnose firewall dns-xlate

diagnose firewall dns-xlate mapping

DNS translation mapping.

diagnose firewall dns-xlate mapping

diagnose firewall dns-xlate mapping list

List dynamic DNS mapping.

diagnose firewall dns-xlate mapping list

diagnose firewall dns-xlate pool

DNS translation pool.

diagnose firewall dns-xlate pool

diagnose firewall dns-xlate pool list

List DNS translation pool.

diagnose firewall dns-xlate pool list

diagnose firewall dynamic

Show dynamic addresses.

diagnose firewall dynamic

diagnose firewall dynamic address

Get summary of one or all dynamic addresses.

diagnose firewall dynamic address <name>

Parameter

Description

Type

Size

<name>

Dynamic address name. (Optional)

string

diagnose firewall dynamic list

Get list of one or all dynamic addresses.

diagnose firewall dynamic list <name>

Parameter

Description

Type

Size

<name>

Dynamic address name. (Optional)

string

diagnose firewall dynamic test-common-tag-update

Test update tags API for dynamic addresses.

diagnose firewall dynamic test-common-tag-update <TAG-INFO-JSON>

Parameter

Description

Type

Size

<TAG-INFO-JSON>

JSON string for commands.

string

diagnose firewall dynamic6

Show IPv6 dynamic addresses.

diagnose firewall dynamic6

diagnose firewall dynamic6 address

Get summary of IPv6 dynamic addresses.

diagnose firewall dynamic6 address <name>

Parameter

Description

Type

Size

<name>

Dynamic address name.

string

diagnose firewall dynamic6 list

List all IPv6 dynamic addresses.

diagnose firewall dynamic6 list <name>

Parameter

Description

Type

Size

<name>

Dynamic address name.

string

diagnose firewall fqdn

fqdn

diagnose firewall fqdn

diagnose firewall fqdn get-ip

Get and display one IP FQDN address.

diagnose firewall fqdn get-ip <name>

Parameter

Description

Type

Size

<name>

Address Name

string

diagnose firewall fqdn get-mac

Get and display one MAC FQDN address.

diagnose firewall fqdn get-mac <name>

Parameter

Description

Type

Size

<name>

Address Name

string

diagnose firewall fqdn getinfo-ip

Get info of IP FQDN address

diagnose firewall fqdn getinfo-ip <name>

Parameter

Description

Type

Size

<name>

name

string

diagnose firewall fqdn getinfo-mac

Get info of MAC FQDN address

diagnose firewall fqdn getinfo-mac <name>

Parameter

Description

Type

Size

<name>

name

string

diagnose firewall fqdn list-all

List FQDN.

diagnose firewall fqdn list-all

diagnose firewall fqdn list-ip

List IP FQDN.

diagnose firewall fqdn list-ip

diagnose firewall fqdn list-mac

List MAC FQDN.

diagnose firewall fqdn list-mac

diagnose firewall fqdn6

IPv6 FQDN.

diagnose firewall fqdn6

diagnose firewall fqdn6 list

List all IPv6 FQDN.

diagnose firewall fqdn6 list

diagnose firewall internet-service

Internet service in the kernel.

diagnose firewall internet-service

diagnose firewall internet-service list

List Internet Service.

diagnose firewall internet-service list <section>

Parameter

Description

Type

Size

<section>

Internet Service table section.(0: entry, 1: index, <integer>: singularity)

string

diagnose firewall internet-service-app-ctrl

Application control internet service in the kernel.

diagnose firewall internet-service-app-ctrl

diagnose firewall internet-service-app-ctrl list

List application control entries in the kernel.

diagnose firewall internet-service-app-ctrl list <ID>

Parameter

Description

Type

Size

<ID>

Application Control ID.

string

diagnose firewall internet-service-app-ctrl6

Application control internet service for IPv6 in the kernel.

diagnose firewall internet-service-app-ctrl6

diagnose firewall internet-service-app-ctrl6 list

List IPv6 application control entries in the kernel.

diagnose firewall internet-service-app-ctrl6 list <ID>

Parameter

Description

Type

Size

<ID>

Application Control ID.

string

diagnose firewall internet-service-cache

Internet Service database cache entries in the kernel.

diagnose firewall internet-service-cache

diagnose firewall internet-service-cache list

List Internet Service databse cache entries in the kernel.

diagnose firewall internet-service-cache list

diagnose firewall internet-service-custom

Custom Internet Service in the kernel.

diagnose firewall internet-service-custom

diagnose firewall internet-service-custom list

List Custom Internet Service.

diagnose firewall internet-service-custom list <name>

Parameter

Description

Type

Size

<name>

Custom Internet Service name.

string

diagnose firewall internet-service-disable

Internet Service disable entries in the kernel.

diagnose firewall internet-service-disable

diagnose firewall internet-service-disable list

List Internet Service disable entries.

diagnose firewall internet-service-disable list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service ID.

string

diagnose firewall internet-service-extension

Internet Service extension in the kernel.

diagnose firewall internet-service-extension

diagnose firewall internet-service-extension list

List Internet Service extension.

diagnose firewall internet-service-extension list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service ID.

string

diagnose firewall internet-service-prio-id

Internet service ID in firewall polcy, shaping policy, SD-WAN rule, static route, and router policy.

diagnose firewall internet-service-prio-id

diagnose firewall internet-service-prio-id list

List Internet Service Priority ID.

diagnose firewall internet-service-prio-id list

diagnose firewall internet-service6

Internet service6 in the kernel.

diagnose firewall internet-service6

diagnose firewall internet-service6 list

List Internet Service6.

diagnose firewall internet-service6 list <section>

Parameter

Description

Type

Size

<section>

Internet Service6 table section.(0: entry, 1: index, <integer>: singularity)

string

diagnose firewall internet-service6-cache

Internet Service database cache entries for IPv6 in the kernel.

diagnose firewall internet-service6-cache

diagnose firewall internet-service6-cache list

List Internet Service database cache entries for IPv6 in the kernel.

diagnose firewall internet-service6-cache list

diagnose firewall internet-service6-custom

Custom Internet Service6 in the kernel.

diagnose firewall internet-service6-custom

diagnose firewall internet-service6-custom list

List Custom Internet Service.

diagnose firewall internet-service6-custom list <name>

Parameter

Description

Type

Size

<name>

Custom Internet Service name.

string

diagnose firewall internet-service6-disable

Internet Service6 disable entries in the kernel.

diagnose firewall internet-service6-disable

diagnose firewall internet-service6-disable list

List Internet Service6 disable entries.

diagnose firewall internet-service6-disable list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service6 ID.

string

diagnose firewall internet-service6-extension

Internet Service6 extension in the kernel.

diagnose firewall internet-service6-extension

diagnose firewall internet-service6-extension list

List Internet Service6 extension.

diagnose firewall internet-service6-extension list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service6 ID.

string

diagnose firewall internet-service6-prio-id

Internet service ID in firewall polcy, SD-WAN rule, and router policy.

diagnose firewall internet-service6-prio-id

diagnose firewall internet-service6-prio-id list

List Internet Service6 Priority ID.

diagnose firewall internet-service6-prio-id list

diagnose firewall ip-translation

IP translation.

diagnose firewall ip-translation

diagnose firewall ip-translation list

List IP translation table.

diagnose firewall ip-translation list

diagnose firewall ipgeo

IP geolocation.

diagnose firewall ipgeo

diagnose firewall ipgeo copyright-notice

Copyright note.

diagnose firewall ipgeo copyright-notice

diagnose firewall ipgeo country-list

List all countries.

diagnose firewall ipgeo country-list

diagnose firewall ipgeo ip-list

List IP info of country.

diagnose firewall ipgeo ip-list <name>

Parameter

Description

Type

Size

<name>

Country ID.

string

diagnose firewall ipgeo ip2country

Get country info for the IP.

diagnose firewall ipgeo ip2country <ip>

Parameter

Description

Type

Size

<ip>

IPv4/IPv6 address.

string

diagnose firewall ipgeo ip6-list

List IPv6 info of country.

diagnose firewall ipgeo ip6-list <name>

Parameter

Description

Type

Size

<name>

Country ID.

string

diagnose firewall ipgeo override

Print out all user defined IP geolocation data.

diagnose firewall ipgeo override

diagnose firewall iplist

IP list.

diagnose firewall iplist

diagnose firewall iplist list

list

diagnose firewall iplist list

diagnose firewall iplist list optimized

List optimized iplist.

diagnose firewall iplist list optimized

diagnose firewall iplist6

IPv6 list.

diagnose firewall iplist6

diagnose firewall iplist6 list

list

diagnose firewall iplist6 list

diagnose firewall iplist6 list optimized

List optimized iplist6.

diagnose firewall iplist6 list optimized

diagnose firewall ipmac

ipmac

diagnose firewall ipmac

diagnose firewall ipmac add

add

diagnose firewall ipmac add <xxx.xxx.xxx.xxx> <xx:xx:xx:xx:xx:xx> <drop|accept>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

IP address.

string

<xx:xx:xx:xx:xx:xx>

MAC address.

string

<drop|accept>

action

string

diagnose firewall ipmac delete

delete

diagnose firewall ipmac delete <xxx.xxx.xxx.xxx> <xx:xx:xx:xx:xx:xx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

IP address.

string

<xx:xx:xx:xx:xx:xx>

MAC address.

string

diagnose firewall ipmac list

list

diagnose firewall ipmac list

diagnose firewall ipmac status

status

diagnose firewall ipmac status

diagnose firewall ippool

One-to-one/PBA IP pool.

diagnose firewall ippool

diagnose firewall ippool filter

Diag ippool list with filters.

diagnose firewall ippool filter

diagnose firewall ippool filter clear

Clear diag ippool filter.

diagnose firewall ippool filter clear

diagnose firewall ippool filter name

Ippool pool name.

diagnose firewall ippool filter name

diagnose firewall ippool list

list

diagnose firewall ippool list

diagnose firewall ippool list nat-ip

List allocated IP in ippool. Take ippool names as arguments.

diagnose firewall ippool list nat-ip

diagnose firewall ippool list pba

List PBA in ippool. Take ippool names as arguments.

diagnose firewall ippool list pba

diagnose firewall ippool list user

List users of ippool. Take ippool names as arguments.

diagnose firewall ippool list user

diagnose firewall ippool reset-log-stats

reset log statistics

diagnose firewall ippool reset-log-stats

diagnose firewall ippool stats

statistics

diagnose firewall ippool stats

diagnose firewall ippool-all

Any IP pool.

diagnose firewall ippool-all

diagnose firewall ippool-all list

list

diagnose firewall ippool-all list

diagnose firewall ippool-all stats

statistics

diagnose firewall ippool-all stats <name>

Parameter

Description

Type

Size

<name>

pool name

string

diagnose firewall ippool-fixed-range

Fixed range IP pool.

diagnose firewall ippool-fixed-range

diagnose firewall ippool-fixed-range list

list

diagnose firewall ippool-fixed-range list

diagnose firewall ippool-fixed-range list natip

NAT IP.

diagnose firewall ippool-fixed-range list natip <xxx.xxx.xxx.xxx>[-<xxx.xxx.xxx.xxx>] <Enter>|<port>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>[-<xxx.xxx.xxx.xxx>]

NAT IP/IP range | NAT IP/IP Range + port.

string

<Enter>|<port>

port

string

diagnose firewall ippool-nptv6

NPTv6 IP pool.

diagnose firewall ippool-nptv6

diagnose firewall ippool-nptv6 natip

NAT IPV6.

diagnose firewall ippool-nptv6 natip <xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx>

Parameter

Description

Type

Size

<xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx>

NAT IPV6.

string

diagnose firewall iprope

iprope

diagnose firewall iprope

diagnose firewall iprope appctrl

List application control lists.

diagnose firewall iprope appctrl

diagnose firewall iprope appctrl list

List application control lists.

diagnose firewall iprope appctrl list

diagnose firewall iprope appctrl shaper

application control app shapers.

diagnose firewall iprope appctrl shaper

diagnose firewall iprope appctrl shaper list

List application control app shapers.

diagnose firewall iprope appctrl shaper list

diagnose firewall iprope appctrl stats

Application control app statistics.

diagnose firewall iprope appctrl stats

diagnose firewall iprope appctrl stats clear

Clear application control app statistics.

diagnose firewall iprope appctrl stats clear

diagnose firewall iprope appctrl stats list

List application control app statistics.

diagnose firewall iprope appctrl stats list

diagnose firewall iprope appctrl status

Application control list status.

diagnose firewall iprope appctrl status

diagnose firewall iprope clear

Clear policy statistic.

diagnose firewall iprope clear

diagnose firewall iprope list

List.

diagnose firewall iprope list <No.>

Parameter

Description

Type

Size

<No.>

Number, hexadecimal.

string

diagnose firewall iprope lookup

Lookup firewall policy that matches provided criteria.

diagnose firewall iprope lookup <src_ip> <src_port> <dst_ip> <dst_port> <protocol> <device> <pol_type> [<auth type>] [<user/group>] [<server>] [<user-db>] [<group-attr-type>]

Parameter

Description

Type

Size

<src_ip>

Source IP address.

string

<src_port>

Source port.

string

<dst_ip>

Destination IP address.

string

<dst_port>

Destination port.

string

<protocol>

Protocol.

string

<device>

Source interface.

string

<pol_type>

Firewall policy type: policy, proxy.

string

[<auth type>]

Authentication type: ldap, saml, local, group.

string

[<user/group>]

Username or name of matching user/group on remote authentication server.

string

[<server>]

Name of auth server.

string

[<user-db>]

Name of user-database.

string

[<group-attr-type>]

Group attr type: name, id.

string

diagnose firewall iprope show

Show policy statistic.

diagnose firewall iprope show

diagnose firewall iprope state

state

diagnose firewall iprope state

diagnose firewall iprope top

Show top N policy statistics within a group.

diagnose firewall iprope top <No.> <String> <Integer>

Parameter

Description

Type

Size

<No.>

Policy group ID

string

<String>

Sort by pkts[-rate]/asic-pkts[-rate]/hit-count[-rate]/tcp-ses[-rate]/udp-ses[-rate]/sctp-ses[-rate]/all-ses[-rate].

string

<Integer>

Delay in seconds (default: 5).

string

diagnose firewall iprope6

iprope6

diagnose firewall iprope6

diagnose firewall iprope6 clear

Clear policy statistic.

diagnose firewall iprope6 clear

diagnose firewall iprope6 list

list

diagnose firewall iprope6 list <No.>

Parameter

Description

Type

Size

<No.>

Number, hexadecimal.

string

diagnose firewall iprope6 lookup

Lookup firewall policy that matches provided criteria.

diagnose firewall iprope6 lookup <src_ip> <src_port> <dst_ip> <dst_port> <protocol> <device> <pol_type> [<auth type>] [<user/group>] [<server>]

Parameter

Description

Type

Size

<src_ip>

Source IP address.

string

<src_port>

Source port.

string

<dst_ip>

Destination IP address.

string

<dst_port>

Destination port.

string

<protocol>

Protocol.

string

<device>

Source interface.

string

<pol_type>

Firewall policy type: policy, proxy.

string

[<auth type>]

Authentication type: user, group.

string

[<user/group>]

Username or name of matching user/group on remote authentication server.

string

[<server>]

Name of auth server.

string

diagnose firewall iprope6 show

Show policy statistic.

diagnose firewall iprope6 show

diagnose firewall iprope6 state

state

diagnose firewall iprope6 state

diagnose firewall iprope6 top

Show top N policy statistics within a group.

diagnose firewall iprope6 top <No.> <String> <Integer>

Parameter

Description

Type

Size

<No.>

Policy group ID

string

<String>

Sort by pkts[-rate]/asic-pkts[-rate]/hit-count[-rate]/tcp-ses[-rate]/udp-ses[-rate]/sctp-ses[-rate]/all-ses[-rate].

string

<Integer>

Delay in seconds (default: 5).

string

diagnose firewall ipv6-ehf

IPv6 extension header filter.

diagnose firewall ipv6-ehf

diagnose firewall ipv6-ehf list

List ipv6-eh-filter.

diagnose firewall ipv6-ehf list

diagnose firewall network-service-dynamic

Dynamic Network Service in the kernel.

diagnose firewall network-service-dynamic

diagnose firewall network-service-dynamic list

List Dynamic Network Service.

diagnose firewall network-service-dynamic list <name>

Parameter

Description

Type

Size

<name>

Dynamic Network Service name.

string

diagnose firewall ngfw-fix-application

Next Generation Firewall (NGFW) Applications handled by Kernel.

diagnose firewall ngfw-fix-application

diagnose firewall ngfw-fix-application list

List Kernel-handled NGFW applications.

diagnose firewall ngfw-fix-application list

diagnose firewall packet

Packet statistics.

diagnose firewall packet

diagnose firewall packet distribution

Show distribution statistics.

diagnose firewall packet distribution

diagnose firewall pcp-mapping

PCP mapping list.

diagnose firewall pcp-mapping

diagnose firewall pcp-mapping filter

List/flush mapping with filters.

diagnose firewall pcp-mapping filter

diagnose firewall pcp-mapping filter clear

Clear PCP mapping filter.

diagnose firewall pcp-mapping filter clear

diagnose firewall pcp-mapping filter client-ip

Client IP address.

diagnose firewall pcp-mapping filter client-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

client IP address (from).

string

diagnose firewall pcp-mapping filter ext-ip

External IP address.

diagnose firewall pcp-mapping filter ext-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

External IP address (from).

string

diagnose firewall pcp-mapping filter ext-port

Externel port.

diagnose firewall pcp-mapping filter ext-port <xxxx>

Parameter

Description

Type

Size

<xxxx>

<0-65535> (from).

string

diagnose firewall pcp-mapping filter intl-ip

Internal IP address.

diagnose firewall pcp-mapping filter intl-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

Internal IP address (from).

string

diagnose firewall pcp-mapping filter intl-port

Internal port.

diagnose firewall pcp-mapping filter intl-port <xxxx>

Parameter

Description

Type

Size

<xxxx>

<0-65535> (from).

string

diagnose firewall pcp-mapping filter pool

Pool ID.

diagnose firewall pcp-mapping filter pool <xx>

Parameter

Description

Type

Size

<xx>

Pool ID.

string

diagnose firewall pcp-mapping filter protocol

Protocol number.

diagnose firewall pcp-mapping filter protocol <xx>

Parameter

Description

Type

Size

<xx>

<0-255>.

string

diagnose firewall pcp-mapping filter remote-ip

Remote IP address.

diagnose firewall pcp-mapping filter remote-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

Remote IP address (from).

string

diagnose firewall pcp-mapping filter remote-port

Remote port.

diagnose firewall pcp-mapping filter remote-port <xxxx>

Parameter

Description

Type

Size

<xxxx>

<0-65535> (from).

string

diagnose firewall pcp-mapping flush

flush

diagnose firewall pcp-mapping flush

diagnose firewall pcp-mapping flush inbound

Flush PCP MAP mapping.

diagnose firewall pcp-mapping flush inbound

diagnose firewall pcp-mapping flush outbound

Flush PCP PEER mapping.

diagnose firewall pcp-mapping flush outbound

diagnose firewall pcp-mapping list

list

diagnose firewall pcp-mapping list

diagnose firewall pcp-mapping list inbound

List PCP MAP mapping.

diagnose firewall pcp-mapping list inbound

diagnose firewall pcp-mapping list outbound

List PCP PEER mapping.

diagnose firewall pcp-mapping list outbound

diagnose firewall proute

Policy route.

diagnose firewall proute

diagnose firewall proute clear

Clear policy routing stats.

diagnose firewall proute clear <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute list

List policy routing.

diagnose firewall proute list <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute show

Show policy routing stats.

diagnose firewall proute show <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute6

IPv6 policy route.

diagnose firewall proute6

diagnose firewall proute6 clear

Clear IPv6 policy routing stats.

diagnose firewall proute6 clear <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute6 list

List IPv6 policy routing.

diagnose firewall proute6 list

diagnose firewall proute6 show

Show IPv6 policy routing stats.

diagnose firewall proute6 show <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall route_tag

Route tag.

diagnose firewall route_tag

diagnose firewall route_tag list

List Route tag address.

diagnose firewall route_tag list <number>

Parameter

Description

Type

Size

<number>

Router tag ID.

string

diagnose firewall route_tag_v6

route_tag_v6.

diagnose firewall route_tag_v6

diagnose firewall route_tag_v6 list

List Route tag address v6.

diagnose firewall route_tag_v6 list <number>

Parameter

Description

Type

Size

<number>

Router tag ID.

string

diagnose firewall schedule

schedule

diagnose firewall schedule

diagnose firewall schedule debug

Set policy schedule debug level.

diagnose firewall schedule debug <level>

Parameter

Description

Type

Size

<level>

debug level (0-2)

string

diagnose firewall schedule list

List schedule.

diagnose firewall schedule list

diagnose firewall schedule reload

Reload schedule.

diagnose firewall schedule reload

diagnose firewall sf-addresses

Security Fabric device addresses.

diagnose firewall sf-addresses

diagnose firewall sf-addresses list

List IP addresses of Fortinet devices configured in the Security Fabric.

diagnose firewall sf-addresses list

diagnose firewall shaper

shapers

diagnose firewall shaper

diagnose firewall shaper dynamic-shaper

Dynamic shapers.

diagnose firewall shaper dynamic-shaper

diagnose firewall shaper dynamic-shaper flush

Flush all dynamic shapers.

diagnose firewall shaper dynamic-shaper flush

diagnose firewall shaper dynamic-shaper list

List Dynamic shapers.

diagnose firewall shaper dynamic-shaper list

diagnose firewall shaper dynamic-shaper list ip

IPv4 address.

diagnose firewall shaper dynamic-shaper list ip <IP addr>

Parameter

Description

Type

Size

<IP addr>

IPv4 Adress xxx.xxx.xxx.xxx.

string

diagnose firewall shaper dynamic-shaper list ipv6

IPv6 address.

diagnose firewall shaper dynamic-shaper list ipv6 <IPv6 addr>

Parameter

Description

Type

Size

<IPv6 addr>

IPv6 Adress xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx

string

diagnose firewall shaper dynamic-shaper list user

User name.

diagnose firewall shaper dynamic-shaper list user <string>

Parameter

Description

Type

Size

<string>

User name.

string

diagnose firewall shaper dynamic-shaper stats

Dynamic shapers statistic.

diagnose firewall shaper dynamic-shaper stats

diagnose firewall shaper per-ip-shaper

Traffic shapers.

diagnose firewall shaper per-ip-shaper

diagnose firewall shaper per-ip-shaper clear

Per-IP clear statistic data.

diagnose firewall shaper per-ip-shaper clear

diagnose firewall shaper per-ip-shaper list

List per-IP shapers.

diagnose firewall shaper per-ip-shaper list

diagnose firewall shaper per-ip-shaper state

Per-IP shapers state.

diagnose firewall shaper per-ip-shaper state

diagnose firewall shaper per-ip-shaper stats

Per-IP shapers statistic.

diagnose firewall shaper per-ip-shaper stats

diagnose firewall shaper traffic-shaper

Traffic shapers.

diagnose firewall shaper traffic-shaper

diagnose firewall shaper traffic-shaper list

List traffic shapers.

diagnose firewall shaper traffic-shaper list

diagnose firewall shaper traffic-shaper state

Global traffic shaper state.

diagnose firewall shaper traffic-shaper state

diagnose firewall shaper traffic-shaper stats

Traffic shaper statistics.

diagnose firewall shaper traffic-shaper stats

diagnose firewall shaper traffic-shaper stats clear

Clear traffic shaper statistics.

diagnose firewall shaper traffic-shaper stats clear <name>

Parameter

Description

Type

Size

<name>

Name of traffic shaper to clear.

string

diagnose firewall shaper traffic-shaper stats list

List traffic shaper statistics.

diagnose firewall shaper traffic-shaper stats list

diagnose firewall uuid

UUID list.

diagnose firewall uuid

diagnose firewall uuid list

list

diagnose firewall uuid list <type>

Parameter

Description

Type

Size

<type>

UUID category.

string

diagnose firewall vendor-mac

Vendor MAC in the kernel.

diagnose firewall vendor-mac

diagnose firewall vendor-mac list

List Vendor MAC Entries.

diagnose firewall vendor-mac list

diagnose firewall vip

VIP diagnostics.

diagnose firewall vip

diagnose firewall vip realserver

Load balance real servers.

diagnose firewall vip realserver

diagnose firewall vip realserver clear

Clear firewall VIP, VIP6 real server statistics.

diagnose firewall vip realserver clear

diagnose firewall vip realserver clear vip

Clear VIP real server statistics.

diagnose firewall vip realserver clear vip <name> <IPv4|IPv6|all>

Parameter

Description

Type

Size

<name>

firewall VIP name.

string

<IPv4|IPv6|all>

IPv4 address x.x.x.x or IPv6 address x:x:x:x:x:x:x:x of the real server, use "all" to clear statistics of all real servers of this VIP.

string

diagnose firewall vip realserver clear vip6

Clear VIP6 real server statistics.

diagnose firewall vip realserver clear vip6 <name> <IPv4|IPv6|all>

Parameter

Description

Type

Size

<name>

Firewall VIP6 name.

string

<IPv4|IPv6|all>

IPv4 address x.x.x.x or IPv6 address x:x:x:x:x:x:x:x of the real server, use "all" to clear statistics of all real servers of this VIP6.

string

diagnose firewall vip realserver down

Change address down.

diagnose firewall vip realserver down <name> <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<name>

IP address.

string

<xxx.xxx.xxx.xxx>

IP address.

string

diagnose firewall vip realserver healthcheck

Server health check.

diagnose firewall vip realserver healthcheck

diagnose firewall vip realserver healthcheck stats

Health check statistics.

diagnose firewall vip realserver healthcheck stats

diagnose firewall vip realserver healthcheck stats clear

Clear health check statistics.

diagnose firewall vip realserver healthcheck stats clear

diagnose firewall vip realserver healthcheck stats show

Show health check statistics.

diagnose firewall vip realserver healthcheck stats show

diagnose firewall vip realserver list

list

diagnose firewall vip realserver list

diagnose firewall vip realserver up

Change address up.

diagnose firewall vip realserver up <name> <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<name>

IP address.

string

<xxx.xxx.xxx.xxx>

IP address.

string

diagnose firewall vip virtual-server

Virtual-server diagnostics.

diagnose firewall vip virtual-server

diagnose firewall vip virtual-server filter

Filter for various virtual server diagnostics.

diagnose firewall vip virtual-server filter

diagnose firewall vip virtual-server filter clear

Erase the current filter.

diagnose firewall vip virtual-server filter clear

diagnose firewall vip virtual-server filter dst

Destination address range to filter by.

diagnose firewall vip virtual-server filter dst <ip-address>

Parameter

Description

Type

Size

<ip-address>

Destination IP address (from).

string

diagnose firewall vip virtual-server filter dst-port

Destination port range to filter by.

diagnose firewall vip virtual-server filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port (from).

string

diagnose firewall vip virtual-server filter list

Display the current filter.

diagnose firewall vip virtual-server filter list

diagnose firewall vip virtual-server filter name

VIP name to filter by.

diagnose firewall vip virtual-server filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose firewall vip virtual-server filter negate

Negate the specified filter parameter.

diagnose firewall vip virtual-server filter negate

diagnose firewall vip virtual-server filter negate dst-addr

Negate IPv4 destination address.

diagnose firewall vip virtual-server filter negate dst-addr

diagnose firewall vip virtual-server filter negate dst-port

Negate destination port.

diagnose firewall vip virtual-server filter negate dst-port

diagnose firewall vip virtual-server filter negate name

Negate name.

diagnose firewall vip virtual-server filter negate name

diagnose firewall vip virtual-server filter negate src-addr

Negate IPv4 source address.

diagnose firewall vip virtual-server filter negate src-addr

diagnose firewall vip virtual-server filter negate src-port

Negate source port.

diagnose firewall vip virtual-server filter negate src-port

diagnose firewall vip virtual-server filter negate vd

Negate virtual domain.

diagnose firewall vip virtual-server filter negate vd

diagnose firewall vip virtual-server filter negate worker

Negate worker index.

diagnose firewall vip virtual-server filter negate worker

diagnose firewall vip virtual-server filter src

Source address range to filter by.

diagnose firewall vip virtual-server filter src <ip-address>

Parameter

Description

Type

Size

<ip-address>

Source IP address (from).

string

diagnose firewall vip virtual-server filter src-port

Source port range to filter by.

diagnose firewall vip virtual-server filter src-port <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

diagnose firewall vip virtual-server filter vd

Index of virtual domain. -1 matches all.

diagnose firewall vip virtual-server filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose firewall vip virtual-server filter worker

Index of worker. -1 matches all.

diagnose firewall vip virtual-server filter worker <index>

Parameter

Description

Type

Size

<index>

Index of worker. -1 matches all.

string

diagnose firewall vip virtual-server real-server

Real-server diagnostics.

diagnose firewall vip virtual-server real-server

diagnose firewall vip virtual-server real-server list

List servers.

diagnose firewall vip virtual-server real-server list

diagnose firewall vip virtual-server stats

Statistics.

diagnose firewall vip virtual-server stats

diagnose firewall vip virtual-server stats clear

Clear all statistics.

diagnose firewall vip virtual-server stats clear

diagnose firewall vip virtual-server stats crypto-clear

Clear SSL crypto statistics.

diagnose firewall vip virtual-server stats crypto-clear

diagnose firewall vip virtual-server stats http

HTTP statistics.

diagnose firewall vip virtual-server stats http

diagnose firewall vip virtual-server stats http all

Per-process HTTP statistics.

diagnose firewall vip virtual-server stats http all

diagnose firewall vip virtual-server stats http clear

Clear HTTP statistics.

diagnose firewall vip virtual-server stats http clear

diagnose firewall vip virtual-server stats http list

List HTTP statistics.

diagnose firewall vip virtual-server stats http list

diagnose firewall vip virtual-server stats list

List all statistics.

diagnose firewall vip virtual-server stats list

diagnose firewall vip virtual-server stats operational

Operational info and statistics.

diagnose firewall vip virtual-server stats operational

diagnose firewall vip virtual-server stats operational all

Display per-process operational info and statistics.

diagnose firewall vip virtual-server stats operational all

diagnose firewall vip virtual-server stats operational list

Display operational info and statistics.

diagnose firewall vip virtual-server stats operational list

diagnose firewall vip virtual-server stats ssl

SSL statistics.

diagnose firewall vip virtual-server stats ssl

diagnose firewall vip virtual-server stats ssl all

Per-process SSL statistics.

diagnose firewall vip virtual-server stats ssl all

diagnose firewall vip virtual-server stats ssl clear

Clear SSL statistics.

diagnose firewall vip virtual-server stats ssl clear

diagnose firewall vip virtual-server stats ssl list

List SSL statistics.

diagnose firewall vip virtual-server stats ssl list

diagnose firewall vip virtual-server stats summary

Summary statistics.

diagnose firewall vip virtual-server stats summary

diagnose firewall vip virtual-server stats summary all

Per-process summary statistics.

diagnose firewall vip virtual-server stats summary all

diagnose firewall vip virtual-server stats summary clear

Clear summary statistics.

diagnose firewall vip virtual-server stats summary clear

diagnose firewall vip virtual-server stats summary list

List summary statistics.

diagnose firewall vip virtual-server stats summary list

diagnose firewall vip virtual-server test

Tests for internal use.

diagnose firewall vip virtual-server test

diagnose firewall vip virtual-server test benchmark

Crypto performance tests.

diagnose firewall vip virtual-server test benchmark

diagnose firewall vip virtual-server test benchmark dh-make-key

DH make-key.

diagnose firewall vip virtual-server test benchmark dh-make-key

diagnose firewall vip virtual-server test benchmark dh-make-secret

DH make-key & make-secret.

diagnose firewall vip virtual-server test benchmark dh-make-secret

diagnose firewall vip virtual-server test benchmark rand

RAND.

diagnose firewall vip virtual-server test benchmark rand

diagnose firewall vip virtual-server test benchmark rsa

RSA decryption.

diagnose firewall vip virtual-server test benchmark rsa

diagnose firewall vip virtual-server test benchmark rsa-mskb

RSA decrypt & MSKB.

diagnose firewall vip virtual-server test benchmark rsa-mskb

diagnose firewall vip virtual-server test key-exchange

Use synchronous/asynchronous key-exchange.

diagnose firewall vip virtual-server test key-exchange

diagnose firewall vip virtual-server test key-exchange async

Asynchronous key-exchange.

diagnose firewall vip virtual-server test key-exchange async

diagnose firewall vip virtual-server test key-exchange sync

Synchronous key-exchange (default).

diagnose firewall vip virtual-server test key-exchange sync

diagnose firewall vip virtual-server test next-proto

Enable/disable next-proto negotiation.

diagnose firewall vip virtual-server test next-proto

diagnose firewall vip virtual-server test next-proto disable

Disable next-proto negotiation.

diagnose firewall vip virtual-server test next-proto disable

diagnose firewall vip virtual-server test next-proto enable

Enable next-proto negotiation.

diagnose firewall vip virtual-server test next-proto enable

diagnose firewall vip virtual-server test rsa-blinding

Enable/disable RSA blinding.

diagnose firewall vip virtual-server test rsa-blinding

diagnose firewall vip virtual-server test rsa-blinding disable

Disable RSA blinding.

diagnose firewall vip virtual-server test rsa-blinding disable

diagnose firewall vip virtual-server test rsa-blinding enable

Enable RSA blinding (default).

diagnose firewall vip virtual-server test rsa-blinding enable

diagnose firewall vip virtual-server test ssl

SSL.

diagnose firewall vip virtual-server test ssl

diagnose firewall vip virtual-server test ssl async

Asynchronous SSL (default).

diagnose firewall vip virtual-server test ssl async

diagnose firewall vip virtual-server test ssl sync

Synchronous SSL.

diagnose firewall vip virtual-server test ssl sync

diagnose firewall

diagnose firewall

Firewall

This topic includes the following commands:

diagnose firewall auth

Authenticated users.

diagnose firewall auth

diagnose firewall auth clear

Clear authenticated IPv4 users.

diagnose firewall auth clear

diagnose firewall auth filter

Filters used to list entries.

diagnose firewall auth filter

diagnose firewall auth filter clear

Clear all filters.

diagnose firewall auth filter clear

diagnose firewall auth filter group

Group name.

diagnose firewall auth filter group <name>

Parameter

Description

Type

Size

<name>

Group name.

string

diagnose firewall auth filter mac

MAC address.

diagnose firewall auth filter mac <xx:xx:xx:xx:xx:xx>

Parameter

Description

Type

Size

<xx:xx:xx:xx:xx:xx>

MAC address.

string

diagnose firewall auth filter method

method

diagnose firewall auth filter method <method>

Parameter

Description

Type

Size

<method>

Valid method name: fsso, rsso, ntlm, fw, wsso, disclaimer, fsso_citrix, sso_guest.

string

diagnose firewall auth filter policy

Policy ID.

diagnose firewall auth filter policy <xxx>

Parameter

Description

Type

Size

<xxx>

Policy ID.

string

diagnose firewall auth filter source

IPv4 source address.

diagnose firewall auth filter source <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

IPv4 source (range from).

string

diagnose firewall auth filter source6

IPv6 source address.

diagnose firewall auth filter source6 <xxxx::xxxx>

Parameter

Description

Type

Size

<xxxx::xxxx>

IPv6 source (range from).

string

diagnose firewall auth filter user

User name.

diagnose firewall auth filter user <name>

Parameter

Description

Type

Size

<name>

User name.

string

diagnose firewall auth ipv6

Authenticated IPv6 users.

diagnose firewall auth ipv6

diagnose firewall auth ipv6 clear

Clear authenticated IPv6 users.

diagnose firewall auth ipv6 clear

diagnose firewall auth ipv6 list

List authenticated IPv6 users.

diagnose firewall auth ipv6 list

diagnose firewall auth list

List authenticated IPv4 users.

diagnose firewall auth list

diagnose firewall auth mac

Authenticated MAC users.

diagnose firewall auth mac

diagnose firewall auth mac clear

Clear authenticated MAC users.

diagnose firewall auth mac clear

diagnose firewall auth mac list

List authenticated MAC users.

diagnose firewall auth mac list

diagnose firewall blocking

Blocking information.

diagnose firewall blocking

diagnose firewall blocking list

List information.

diagnose firewall blocking list <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

Source IP.

string

diagnose firewall dns-xlate

DNS translation.

diagnose firewall dns-xlate

diagnose firewall dns-xlate mapping

DNS translation mapping.

diagnose firewall dns-xlate mapping

diagnose firewall dns-xlate mapping list

List dynamic DNS mapping.

diagnose firewall dns-xlate mapping list

diagnose firewall dns-xlate pool

DNS translation pool.

diagnose firewall dns-xlate pool

diagnose firewall dns-xlate pool list

List DNS translation pool.

diagnose firewall dns-xlate pool list

diagnose firewall dynamic

Show dynamic addresses.

diagnose firewall dynamic

diagnose firewall dynamic address

Get summary of one or all dynamic addresses.

diagnose firewall dynamic address <name>

Parameter

Description

Type

Size

<name>

Dynamic address name. (Optional)

string

diagnose firewall dynamic list

Get list of one or all dynamic addresses.

diagnose firewall dynamic list <name>

Parameter

Description

Type

Size

<name>

Dynamic address name. (Optional)

string

diagnose firewall dynamic test-common-tag-update

Test update tags API for dynamic addresses.

diagnose firewall dynamic test-common-tag-update <TAG-INFO-JSON>

Parameter

Description

Type

Size

<TAG-INFO-JSON>

JSON string for commands.

string

diagnose firewall dynamic6

Show IPv6 dynamic addresses.

diagnose firewall dynamic6

diagnose firewall dynamic6 address

Get summary of IPv6 dynamic addresses.

diagnose firewall dynamic6 address <name>

Parameter

Description

Type

Size

<name>

Dynamic address name.

string

diagnose firewall dynamic6 list

List all IPv6 dynamic addresses.

diagnose firewall dynamic6 list <name>

Parameter

Description

Type

Size

<name>

Dynamic address name.

string

diagnose firewall fqdn

fqdn

diagnose firewall fqdn

diagnose firewall fqdn get-ip

Get and display one IP FQDN address.

diagnose firewall fqdn get-ip <name>

Parameter

Description

Type

Size

<name>

Address Name

string

diagnose firewall fqdn get-mac

Get and display one MAC FQDN address.

diagnose firewall fqdn get-mac <name>

Parameter

Description

Type

Size

<name>

Address Name

string

diagnose firewall fqdn getinfo-ip

Get info of IP FQDN address

diagnose firewall fqdn getinfo-ip <name>

Parameter

Description

Type

Size

<name>

name

string

diagnose firewall fqdn getinfo-mac

Get info of MAC FQDN address

diagnose firewall fqdn getinfo-mac <name>

Parameter

Description

Type

Size

<name>

name

string

diagnose firewall fqdn list-all

List FQDN.

diagnose firewall fqdn list-all

diagnose firewall fqdn list-ip

List IP FQDN.

diagnose firewall fqdn list-ip

diagnose firewall fqdn list-mac

List MAC FQDN.

diagnose firewall fqdn list-mac

diagnose firewall fqdn6

IPv6 FQDN.

diagnose firewall fqdn6

diagnose firewall fqdn6 list

List all IPv6 FQDN.

diagnose firewall fqdn6 list

diagnose firewall internet-service

Internet service in the kernel.

diagnose firewall internet-service

diagnose firewall internet-service list

List Internet Service.

diagnose firewall internet-service list <section>

Parameter

Description

Type

Size

<section>

Internet Service table section.(0: entry, 1: index, <integer>: singularity)

string

diagnose firewall internet-service-app-ctrl

Application control internet service in the kernel.

diagnose firewall internet-service-app-ctrl

diagnose firewall internet-service-app-ctrl list

List application control entries in the kernel.

diagnose firewall internet-service-app-ctrl list <ID>

Parameter

Description

Type

Size

<ID>

Application Control ID.

string

diagnose firewall internet-service-app-ctrl6

Application control internet service for IPv6 in the kernel.

diagnose firewall internet-service-app-ctrl6

diagnose firewall internet-service-app-ctrl6 list

List IPv6 application control entries in the kernel.

diagnose firewall internet-service-app-ctrl6 list <ID>

Parameter

Description

Type

Size

<ID>

Application Control ID.

string

diagnose firewall internet-service-cache

Internet Service database cache entries in the kernel.

diagnose firewall internet-service-cache

diagnose firewall internet-service-cache list

List Internet Service databse cache entries in the kernel.

diagnose firewall internet-service-cache list

diagnose firewall internet-service-custom

Custom Internet Service in the kernel.

diagnose firewall internet-service-custom

diagnose firewall internet-service-custom list

List Custom Internet Service.

diagnose firewall internet-service-custom list <name>

Parameter

Description

Type

Size

<name>

Custom Internet Service name.

string

diagnose firewall internet-service-disable

Internet Service disable entries in the kernel.

diagnose firewall internet-service-disable

diagnose firewall internet-service-disable list

List Internet Service disable entries.

diagnose firewall internet-service-disable list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service ID.

string

diagnose firewall internet-service-extension

Internet Service extension in the kernel.

diagnose firewall internet-service-extension

diagnose firewall internet-service-extension list

List Internet Service extension.

diagnose firewall internet-service-extension list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service ID.

string

diagnose firewall internet-service-prio-id

Internet service ID in firewall polcy, shaping policy, SD-WAN rule, static route, and router policy.

diagnose firewall internet-service-prio-id

diagnose firewall internet-service-prio-id list

List Internet Service Priority ID.

diagnose firewall internet-service-prio-id list

diagnose firewall internet-service6

Internet service6 in the kernel.

diagnose firewall internet-service6

diagnose firewall internet-service6 list

List Internet Service6.

diagnose firewall internet-service6 list <section>

Parameter

Description

Type

Size

<section>

Internet Service6 table section.(0: entry, 1: index, <integer>: singularity)

string

diagnose firewall internet-service6-cache

Internet Service database cache entries for IPv6 in the kernel.

diagnose firewall internet-service6-cache

diagnose firewall internet-service6-cache list

List Internet Service database cache entries for IPv6 in the kernel.

diagnose firewall internet-service6-cache list

diagnose firewall internet-service6-custom

Custom Internet Service6 in the kernel.

diagnose firewall internet-service6-custom

diagnose firewall internet-service6-custom list

List Custom Internet Service.

diagnose firewall internet-service6-custom list <name>

Parameter

Description

Type

Size

<name>

Custom Internet Service name.

string

diagnose firewall internet-service6-disable

Internet Service6 disable entries in the kernel.

diagnose firewall internet-service6-disable

diagnose firewall internet-service6-disable list

List Internet Service6 disable entries.

diagnose firewall internet-service6-disable list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service6 ID.

string

diagnose firewall internet-service6-extension

Internet Service6 extension in the kernel.

diagnose firewall internet-service6-extension

diagnose firewall internet-service6-extension list

List Internet Service6 extension.

diagnose firewall internet-service6-extension list <ID>

Parameter

Description

Type

Size

<ID>

Internet Service6 ID.

string

diagnose firewall internet-service6-prio-id

Internet service ID in firewall polcy, SD-WAN rule, and router policy.

diagnose firewall internet-service6-prio-id

diagnose firewall internet-service6-prio-id list

List Internet Service6 Priority ID.

diagnose firewall internet-service6-prio-id list

diagnose firewall ip-translation

IP translation.

diagnose firewall ip-translation

diagnose firewall ip-translation list

List IP translation table.

diagnose firewall ip-translation list

diagnose firewall ipgeo

IP geolocation.

diagnose firewall ipgeo

diagnose firewall ipgeo copyright-notice

Copyright note.

diagnose firewall ipgeo copyright-notice

diagnose firewall ipgeo country-list

List all countries.

diagnose firewall ipgeo country-list

diagnose firewall ipgeo ip-list

List IP info of country.

diagnose firewall ipgeo ip-list <name>

Parameter

Description

Type

Size

<name>

Country ID.

string

diagnose firewall ipgeo ip2country

Get country info for the IP.

diagnose firewall ipgeo ip2country <ip>

Parameter

Description

Type

Size

<ip>

IPv4/IPv6 address.

string

diagnose firewall ipgeo ip6-list

List IPv6 info of country.

diagnose firewall ipgeo ip6-list <name>

Parameter

Description

Type

Size

<name>

Country ID.

string

diagnose firewall ipgeo override

Print out all user defined IP geolocation data.

diagnose firewall ipgeo override

diagnose firewall iplist

IP list.

diagnose firewall iplist

diagnose firewall iplist list

list

diagnose firewall iplist list

diagnose firewall iplist list optimized

List optimized iplist.

diagnose firewall iplist list optimized

diagnose firewall iplist6

IPv6 list.

diagnose firewall iplist6

diagnose firewall iplist6 list

list

diagnose firewall iplist6 list

diagnose firewall iplist6 list optimized

List optimized iplist6.

diagnose firewall iplist6 list optimized

diagnose firewall ipmac

ipmac

diagnose firewall ipmac

diagnose firewall ipmac add

add

diagnose firewall ipmac add <xxx.xxx.xxx.xxx> <xx:xx:xx:xx:xx:xx> <drop|accept>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

IP address.

string

<xx:xx:xx:xx:xx:xx>

MAC address.

string

<drop|accept>

action

string

diagnose firewall ipmac delete

delete

diagnose firewall ipmac delete <xxx.xxx.xxx.xxx> <xx:xx:xx:xx:xx:xx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

IP address.

string

<xx:xx:xx:xx:xx:xx>

MAC address.

string

diagnose firewall ipmac list

list

diagnose firewall ipmac list

diagnose firewall ipmac status

status

diagnose firewall ipmac status

diagnose firewall ippool

One-to-one/PBA IP pool.

diagnose firewall ippool

diagnose firewall ippool filter

Diag ippool list with filters.

diagnose firewall ippool filter

diagnose firewall ippool filter clear

Clear diag ippool filter.

diagnose firewall ippool filter clear

diagnose firewall ippool filter name

Ippool pool name.

diagnose firewall ippool filter name

diagnose firewall ippool list

list

diagnose firewall ippool list

diagnose firewall ippool list nat-ip

List allocated IP in ippool. Take ippool names as arguments.

diagnose firewall ippool list nat-ip

diagnose firewall ippool list pba

List PBA in ippool. Take ippool names as arguments.

diagnose firewall ippool list pba

diagnose firewall ippool list user

List users of ippool. Take ippool names as arguments.

diagnose firewall ippool list user

diagnose firewall ippool reset-log-stats

reset log statistics

diagnose firewall ippool reset-log-stats

diagnose firewall ippool stats

statistics

diagnose firewall ippool stats

diagnose firewall ippool-all

Any IP pool.

diagnose firewall ippool-all

diagnose firewall ippool-all list

list

diagnose firewall ippool-all list

diagnose firewall ippool-all stats

statistics

diagnose firewall ippool-all stats <name>

Parameter

Description

Type

Size

<name>

pool name

string

diagnose firewall ippool-fixed-range

Fixed range IP pool.

diagnose firewall ippool-fixed-range

diagnose firewall ippool-fixed-range list

list

diagnose firewall ippool-fixed-range list

diagnose firewall ippool-fixed-range list natip

NAT IP.

diagnose firewall ippool-fixed-range list natip <xxx.xxx.xxx.xxx>[-<xxx.xxx.xxx.xxx>] <Enter>|<port>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>[-<xxx.xxx.xxx.xxx>]

NAT IP/IP range | NAT IP/IP Range + port.

string

<Enter>|<port>

port

string

diagnose firewall ippool-nptv6

NPTv6 IP pool.

diagnose firewall ippool-nptv6

diagnose firewall ippool-nptv6 natip

NAT IPV6.

diagnose firewall ippool-nptv6 natip <xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx>

Parameter

Description

Type

Size

<xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx>

NAT IPV6.

string

diagnose firewall iprope

iprope

diagnose firewall iprope

diagnose firewall iprope appctrl

List application control lists.

diagnose firewall iprope appctrl

diagnose firewall iprope appctrl list

List application control lists.

diagnose firewall iprope appctrl list

diagnose firewall iprope appctrl shaper

application control app shapers.

diagnose firewall iprope appctrl shaper

diagnose firewall iprope appctrl shaper list

List application control app shapers.

diagnose firewall iprope appctrl shaper list

diagnose firewall iprope appctrl stats

Application control app statistics.

diagnose firewall iprope appctrl stats

diagnose firewall iprope appctrl stats clear

Clear application control app statistics.

diagnose firewall iprope appctrl stats clear

diagnose firewall iprope appctrl stats list

List application control app statistics.

diagnose firewall iprope appctrl stats list

diagnose firewall iprope appctrl status

Application control list status.

diagnose firewall iprope appctrl status

diagnose firewall iprope clear

Clear policy statistic.

diagnose firewall iprope clear

diagnose firewall iprope list

List.

diagnose firewall iprope list <No.>

Parameter

Description

Type

Size

<No.>

Number, hexadecimal.

string

diagnose firewall iprope lookup

Lookup firewall policy that matches provided criteria.

diagnose firewall iprope lookup <src_ip> <src_port> <dst_ip> <dst_port> <protocol> <device> <pol_type> [<auth type>] [<user/group>] [<server>] [<user-db>] [<group-attr-type>]

Parameter

Description

Type

Size

<src_ip>

Source IP address.

string

<src_port>

Source port.

string

<dst_ip>

Destination IP address.

string

<dst_port>

Destination port.

string

<protocol>

Protocol.

string

<device>

Source interface.

string

<pol_type>

Firewall policy type: policy, proxy.

string

[<auth type>]

Authentication type: ldap, saml, local, group.

string

[<user/group>]

Username or name of matching user/group on remote authentication server.

string

[<server>]

Name of auth server.

string

[<user-db>]

Name of user-database.

string

[<group-attr-type>]

Group attr type: name, id.

string

diagnose firewall iprope show

Show policy statistic.

diagnose firewall iprope show

diagnose firewall iprope state

state

diagnose firewall iprope state

diagnose firewall iprope top

Show top N policy statistics within a group.

diagnose firewall iprope top <No.> <String> <Integer>

Parameter

Description

Type

Size

<No.>

Policy group ID

string

<String>

Sort by pkts[-rate]/asic-pkts[-rate]/hit-count[-rate]/tcp-ses[-rate]/udp-ses[-rate]/sctp-ses[-rate]/all-ses[-rate].

string

<Integer>

Delay in seconds (default: 5).

string

diagnose firewall iprope6

iprope6

diagnose firewall iprope6

diagnose firewall iprope6 clear

Clear policy statistic.

diagnose firewall iprope6 clear

diagnose firewall iprope6 list

list

diagnose firewall iprope6 list <No.>

Parameter

Description

Type

Size

<No.>

Number, hexadecimal.

string

diagnose firewall iprope6 lookup

Lookup firewall policy that matches provided criteria.

diagnose firewall iprope6 lookup <src_ip> <src_port> <dst_ip> <dst_port> <protocol> <device> <pol_type> [<auth type>] [<user/group>] [<server>]

Parameter

Description

Type

Size

<src_ip>

Source IP address.

string

<src_port>

Source port.

string

<dst_ip>

Destination IP address.

string

<dst_port>

Destination port.

string

<protocol>

Protocol.

string

<device>

Source interface.

string

<pol_type>

Firewall policy type: policy, proxy.

string

[<auth type>]

Authentication type: user, group.

string

[<user/group>]

Username or name of matching user/group on remote authentication server.

string

[<server>]

Name of auth server.

string

diagnose firewall iprope6 show

Show policy statistic.

diagnose firewall iprope6 show

diagnose firewall iprope6 state

state

diagnose firewall iprope6 state

diagnose firewall iprope6 top

Show top N policy statistics within a group.

diagnose firewall iprope6 top <No.> <String> <Integer>

Parameter

Description

Type

Size

<No.>

Policy group ID

string

<String>

Sort by pkts[-rate]/asic-pkts[-rate]/hit-count[-rate]/tcp-ses[-rate]/udp-ses[-rate]/sctp-ses[-rate]/all-ses[-rate].

string

<Integer>

Delay in seconds (default: 5).

string

diagnose firewall ipv6-ehf

IPv6 extension header filter.

diagnose firewall ipv6-ehf

diagnose firewall ipv6-ehf list

List ipv6-eh-filter.

diagnose firewall ipv6-ehf list

diagnose firewall network-service-dynamic

Dynamic Network Service in the kernel.

diagnose firewall network-service-dynamic

diagnose firewall network-service-dynamic list

List Dynamic Network Service.

diagnose firewall network-service-dynamic list <name>

Parameter

Description

Type

Size

<name>

Dynamic Network Service name.

string

diagnose firewall ngfw-fix-application

Next Generation Firewall (NGFW) Applications handled by Kernel.

diagnose firewall ngfw-fix-application

diagnose firewall ngfw-fix-application list

List Kernel-handled NGFW applications.

diagnose firewall ngfw-fix-application list

diagnose firewall packet

Packet statistics.

diagnose firewall packet

diagnose firewall packet distribution

Show distribution statistics.

diagnose firewall packet distribution

diagnose firewall pcp-mapping

PCP mapping list.

diagnose firewall pcp-mapping

diagnose firewall pcp-mapping filter

List/flush mapping with filters.

diagnose firewall pcp-mapping filter

diagnose firewall pcp-mapping filter clear

Clear PCP mapping filter.

diagnose firewall pcp-mapping filter clear

diagnose firewall pcp-mapping filter client-ip

Client IP address.

diagnose firewall pcp-mapping filter client-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

client IP address (from).

string

diagnose firewall pcp-mapping filter ext-ip

External IP address.

diagnose firewall pcp-mapping filter ext-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

External IP address (from).

string

diagnose firewall pcp-mapping filter ext-port

Externel port.

diagnose firewall pcp-mapping filter ext-port <xxxx>

Parameter

Description

Type

Size

<xxxx>

<0-65535> (from).

string

diagnose firewall pcp-mapping filter intl-ip

Internal IP address.

diagnose firewall pcp-mapping filter intl-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

Internal IP address (from).

string

diagnose firewall pcp-mapping filter intl-port

Internal port.

diagnose firewall pcp-mapping filter intl-port <xxxx>

Parameter

Description

Type

Size

<xxxx>

<0-65535> (from).

string

diagnose firewall pcp-mapping filter pool

Pool ID.

diagnose firewall pcp-mapping filter pool <xx>

Parameter

Description

Type

Size

<xx>

Pool ID.

string

diagnose firewall pcp-mapping filter protocol

Protocol number.

diagnose firewall pcp-mapping filter protocol <xx>

Parameter

Description

Type

Size

<xx>

<0-255>.

string

diagnose firewall pcp-mapping filter remote-ip

Remote IP address.

diagnose firewall pcp-mapping filter remote-ip <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<xxx.xxx.xxx.xxx>

Remote IP address (from).

string

diagnose firewall pcp-mapping filter remote-port

Remote port.

diagnose firewall pcp-mapping filter remote-port <xxxx>

Parameter

Description

Type

Size

<xxxx>

<0-65535> (from).

string

diagnose firewall pcp-mapping flush

flush

diagnose firewall pcp-mapping flush

diagnose firewall pcp-mapping flush inbound

Flush PCP MAP mapping.

diagnose firewall pcp-mapping flush inbound

diagnose firewall pcp-mapping flush outbound

Flush PCP PEER mapping.

diagnose firewall pcp-mapping flush outbound

diagnose firewall pcp-mapping list

list

diagnose firewall pcp-mapping list

diagnose firewall pcp-mapping list inbound

List PCP MAP mapping.

diagnose firewall pcp-mapping list inbound

diagnose firewall pcp-mapping list outbound

List PCP PEER mapping.

diagnose firewall pcp-mapping list outbound

diagnose firewall proute

Policy route.

diagnose firewall proute

diagnose firewall proute clear

Clear policy routing stats.

diagnose firewall proute clear <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute list

List policy routing.

diagnose firewall proute list <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute show

Show policy routing stats.

diagnose firewall proute show <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute6

IPv6 policy route.

diagnose firewall proute6

diagnose firewall proute6 clear

Clear IPv6 policy routing stats.

diagnose firewall proute6 clear <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall proute6 list

List IPv6 policy routing.

diagnose firewall proute6 list

diagnose firewall proute6 show

Show IPv6 policy routing stats.

diagnose firewall proute6 show <number>

Parameter

Description

Type

Size

<number>

Policy route ID.

string

diagnose firewall route_tag

Route tag.

diagnose firewall route_tag

diagnose firewall route_tag list

List Route tag address.

diagnose firewall route_tag list <number>

Parameter

Description

Type

Size

<number>

Router tag ID.

string

diagnose firewall route_tag_v6

route_tag_v6.

diagnose firewall route_tag_v6

diagnose firewall route_tag_v6 list

List Route tag address v6.

diagnose firewall route_tag_v6 list <number>

Parameter

Description

Type

Size

<number>

Router tag ID.

string

diagnose firewall schedule

schedule

diagnose firewall schedule

diagnose firewall schedule debug

Set policy schedule debug level.

diagnose firewall schedule debug <level>

Parameter

Description

Type

Size

<level>

debug level (0-2)

string

diagnose firewall schedule list

List schedule.

diagnose firewall schedule list

diagnose firewall schedule reload

Reload schedule.

diagnose firewall schedule reload

diagnose firewall sf-addresses

Security Fabric device addresses.

diagnose firewall sf-addresses

diagnose firewall sf-addresses list

List IP addresses of Fortinet devices configured in the Security Fabric.

diagnose firewall sf-addresses list

diagnose firewall shaper

shapers

diagnose firewall shaper

diagnose firewall shaper dynamic-shaper

Dynamic shapers.

diagnose firewall shaper dynamic-shaper

diagnose firewall shaper dynamic-shaper flush

Flush all dynamic shapers.

diagnose firewall shaper dynamic-shaper flush

diagnose firewall shaper dynamic-shaper list

List Dynamic shapers.

diagnose firewall shaper dynamic-shaper list

diagnose firewall shaper dynamic-shaper list ip

IPv4 address.

diagnose firewall shaper dynamic-shaper list ip <IP addr>

Parameter

Description

Type

Size

<IP addr>

IPv4 Adress xxx.xxx.xxx.xxx.

string

diagnose firewall shaper dynamic-shaper list ipv6

IPv6 address.

diagnose firewall shaper dynamic-shaper list ipv6 <IPv6 addr>

Parameter

Description

Type

Size

<IPv6 addr>

IPv6 Adress xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx

string

diagnose firewall shaper dynamic-shaper list user

User name.

diagnose firewall shaper dynamic-shaper list user <string>

Parameter

Description

Type

Size

<string>

User name.

string

diagnose firewall shaper dynamic-shaper stats

Dynamic shapers statistic.

diagnose firewall shaper dynamic-shaper stats

diagnose firewall shaper per-ip-shaper

Traffic shapers.

diagnose firewall shaper per-ip-shaper

diagnose firewall shaper per-ip-shaper clear

Per-IP clear statistic data.

diagnose firewall shaper per-ip-shaper clear

diagnose firewall shaper per-ip-shaper list

List per-IP shapers.

diagnose firewall shaper per-ip-shaper list

diagnose firewall shaper per-ip-shaper state

Per-IP shapers state.

diagnose firewall shaper per-ip-shaper state

diagnose firewall shaper per-ip-shaper stats

Per-IP shapers statistic.

diagnose firewall shaper per-ip-shaper stats

diagnose firewall shaper traffic-shaper

Traffic shapers.

diagnose firewall shaper traffic-shaper

diagnose firewall shaper traffic-shaper list

List traffic shapers.

diagnose firewall shaper traffic-shaper list

diagnose firewall shaper traffic-shaper state

Global traffic shaper state.

diagnose firewall shaper traffic-shaper state

diagnose firewall shaper traffic-shaper stats

Traffic shaper statistics.

diagnose firewall shaper traffic-shaper stats

diagnose firewall shaper traffic-shaper stats clear

Clear traffic shaper statistics.

diagnose firewall shaper traffic-shaper stats clear <name>

Parameter

Description

Type

Size

<name>

Name of traffic shaper to clear.

string

diagnose firewall shaper traffic-shaper stats list

List traffic shaper statistics.

diagnose firewall shaper traffic-shaper stats list

diagnose firewall uuid

UUID list.

diagnose firewall uuid

diagnose firewall uuid list

list

diagnose firewall uuid list <type>

Parameter

Description

Type

Size

<type>

UUID category.

string

diagnose firewall vendor-mac

Vendor MAC in the kernel.

diagnose firewall vendor-mac

diagnose firewall vendor-mac list

List Vendor MAC Entries.

diagnose firewall vendor-mac list

diagnose firewall vip

VIP diagnostics.

diagnose firewall vip

diagnose firewall vip realserver

Load balance real servers.

diagnose firewall vip realserver

diagnose firewall vip realserver clear

Clear firewall VIP, VIP6 real server statistics.

diagnose firewall vip realserver clear

diagnose firewall vip realserver clear vip

Clear VIP real server statistics.

diagnose firewall vip realserver clear vip <name> <IPv4|IPv6|all>

Parameter

Description

Type

Size

<name>

firewall VIP name.

string

<IPv4|IPv6|all>

IPv4 address x.x.x.x or IPv6 address x:x:x:x:x:x:x:x of the real server, use "all" to clear statistics of all real servers of this VIP.

string

diagnose firewall vip realserver clear vip6

Clear VIP6 real server statistics.

diagnose firewall vip realserver clear vip6 <name> <IPv4|IPv6|all>

Parameter

Description

Type

Size

<name>

Firewall VIP6 name.

string

<IPv4|IPv6|all>

IPv4 address x.x.x.x or IPv6 address x:x:x:x:x:x:x:x of the real server, use "all" to clear statistics of all real servers of this VIP6.

string

diagnose firewall vip realserver down

Change address down.

diagnose firewall vip realserver down <name> <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<name>

IP address.

string

<xxx.xxx.xxx.xxx>

IP address.

string

diagnose firewall vip realserver healthcheck

Server health check.

diagnose firewall vip realserver healthcheck

diagnose firewall vip realserver healthcheck stats

Health check statistics.

diagnose firewall vip realserver healthcheck stats

diagnose firewall vip realserver healthcheck stats clear

Clear health check statistics.

diagnose firewall vip realserver healthcheck stats clear

diagnose firewall vip realserver healthcheck stats show

Show health check statistics.

diagnose firewall vip realserver healthcheck stats show

diagnose firewall vip realserver list

list

diagnose firewall vip realserver list

diagnose firewall vip realserver up

Change address up.

diagnose firewall vip realserver up <name> <xxx.xxx.xxx.xxx>

Parameter

Description

Type

Size

<name>

IP address.

string

<xxx.xxx.xxx.xxx>

IP address.

string

diagnose firewall vip virtual-server

Virtual-server diagnostics.

diagnose firewall vip virtual-server

diagnose firewall vip virtual-server filter

Filter for various virtual server diagnostics.

diagnose firewall vip virtual-server filter

diagnose firewall vip virtual-server filter clear

Erase the current filter.

diagnose firewall vip virtual-server filter clear

diagnose firewall vip virtual-server filter dst

Destination address range to filter by.

diagnose firewall vip virtual-server filter dst <ip-address>

Parameter

Description

Type

Size

<ip-address>

Destination IP address (from).

string

diagnose firewall vip virtual-server filter dst-port

Destination port range to filter by.

diagnose firewall vip virtual-server filter dst-port <port>

Parameter

Description

Type

Size

<port>

Destination port (from).

string

diagnose firewall vip virtual-server filter list

Display the current filter.

diagnose firewall vip virtual-server filter list

diagnose firewall vip virtual-server filter name

VIP name to filter by.

diagnose firewall vip virtual-server filter name <name>

Parameter

Description

Type

Size

<name>

Name to filter by.

string

diagnose firewall vip virtual-server filter negate

Negate the specified filter parameter.

diagnose firewall vip virtual-server filter negate

diagnose firewall vip virtual-server filter negate dst-addr

Negate IPv4 destination address.

diagnose firewall vip virtual-server filter negate dst-addr

diagnose firewall vip virtual-server filter negate dst-port

Negate destination port.

diagnose firewall vip virtual-server filter negate dst-port

diagnose firewall vip virtual-server filter negate name

Negate name.

diagnose firewall vip virtual-server filter negate name

diagnose firewall vip virtual-server filter negate src-addr

Negate IPv4 source address.

diagnose firewall vip virtual-server filter negate src-addr

diagnose firewall vip virtual-server filter negate src-port

Negate source port.

diagnose firewall vip virtual-server filter negate src-port

diagnose firewall vip virtual-server filter negate vd

Negate virtual domain.

diagnose firewall vip virtual-server filter negate vd

diagnose firewall vip virtual-server filter negate worker

Negate worker index.

diagnose firewall vip virtual-server filter negate worker

diagnose firewall vip virtual-server filter src

Source address range to filter by.

diagnose firewall vip virtual-server filter src <ip-address>

Parameter

Description

Type

Size

<ip-address>

Source IP address (from).

string

diagnose firewall vip virtual-server filter src-port

Source port range to filter by.

diagnose firewall vip virtual-server filter src-port <port>

Parameter

Description

Type

Size

<port>

Source port (from).

string

diagnose firewall vip virtual-server filter vd

Index of virtual domain. -1 matches all.

diagnose firewall vip virtual-server filter vd <index>

Parameter

Description

Type

Size

<index>

Index of virtual domain. -1 matches all.

string

diagnose firewall vip virtual-server filter worker

Index of worker. -1 matches all.

diagnose firewall vip virtual-server filter worker <index>

Parameter

Description

Type

Size

<index>

Index of worker. -1 matches all.

string

diagnose firewall vip virtual-server real-server

Real-server diagnostics.

diagnose firewall vip virtual-server real-server

diagnose firewall vip virtual-server real-server list

List servers.

diagnose firewall vip virtual-server real-server list

diagnose firewall vip virtual-server stats

Statistics.

diagnose firewall vip virtual-server stats

diagnose firewall vip virtual-server stats clear

Clear all statistics.

diagnose firewall vip virtual-server stats clear

diagnose firewall vip virtual-server stats crypto-clear

Clear SSL crypto statistics.

diagnose firewall vip virtual-server stats crypto-clear

diagnose firewall vip virtual-server stats http

HTTP statistics.

diagnose firewall vip virtual-server stats http

diagnose firewall vip virtual-server stats http all

Per-process HTTP statistics.

diagnose firewall vip virtual-server stats http all

diagnose firewall vip virtual-server stats http clear

Clear HTTP statistics.

diagnose firewall vip virtual-server stats http clear

diagnose firewall vip virtual-server stats http list

List HTTP statistics.

diagnose firewall vip virtual-server stats http list

diagnose firewall vip virtual-server stats list

List all statistics.

diagnose firewall vip virtual-server stats list

diagnose firewall vip virtual-server stats operational

Operational info and statistics.

diagnose firewall vip virtual-server stats operational

diagnose firewall vip virtual-server stats operational all

Display per-process operational info and statistics.

diagnose firewall vip virtual-server stats operational all

diagnose firewall vip virtual-server stats operational list

Display operational info and statistics.

diagnose firewall vip virtual-server stats operational list

diagnose firewall vip virtual-server stats ssl

SSL statistics.

diagnose firewall vip virtual-server stats ssl

diagnose firewall vip virtual-server stats ssl all

Per-process SSL statistics.

diagnose firewall vip virtual-server stats ssl all

diagnose firewall vip virtual-server stats ssl clear

Clear SSL statistics.

diagnose firewall vip virtual-server stats ssl clear

diagnose firewall vip virtual-server stats ssl list

List SSL statistics.

diagnose firewall vip virtual-server stats ssl list

diagnose firewall vip virtual-server stats summary

Summary statistics.

diagnose firewall vip virtual-server stats summary

diagnose firewall vip virtual-server stats summary all

Per-process summary statistics.

diagnose firewall vip virtual-server stats summary all

diagnose firewall vip virtual-server stats summary clear

Clear summary statistics.

diagnose firewall vip virtual-server stats summary clear

diagnose firewall vip virtual-server stats summary list

List summary statistics.

diagnose firewall vip virtual-server stats summary list

diagnose firewall vip virtual-server test

Tests for internal use.

diagnose firewall vip virtual-server test

diagnose firewall vip virtual-server test benchmark

Crypto performance tests.

diagnose firewall vip virtual-server test benchmark

diagnose firewall vip virtual-server test benchmark dh-make-key

DH make-key.

diagnose firewall vip virtual-server test benchmark dh-make-key

diagnose firewall vip virtual-server test benchmark dh-make-secret

DH make-key & make-secret.

diagnose firewall vip virtual-server test benchmark dh-make-secret

diagnose firewall vip virtual-server test benchmark rand

RAND.

diagnose firewall vip virtual-server test benchmark rand

diagnose firewall vip virtual-server test benchmark rsa

RSA decryption.

diagnose firewall vip virtual-server test benchmark rsa

diagnose firewall vip virtual-server test benchmark rsa-mskb

RSA decrypt & MSKB.

diagnose firewall vip virtual-server test benchmark rsa-mskb

diagnose firewall vip virtual-server test key-exchange

Use synchronous/asynchronous key-exchange.

diagnose firewall vip virtual-server test key-exchange

diagnose firewall vip virtual-server test key-exchange async

Asynchronous key-exchange.

diagnose firewall vip virtual-server test key-exchange async

diagnose firewall vip virtual-server test key-exchange sync

Synchronous key-exchange (default).

diagnose firewall vip virtual-server test key-exchange sync

diagnose firewall vip virtual-server test next-proto

Enable/disable next-proto negotiation.

diagnose firewall vip virtual-server test next-proto

diagnose firewall vip virtual-server test next-proto disable

Disable next-proto negotiation.

diagnose firewall vip virtual-server test next-proto disable

diagnose firewall vip virtual-server test next-proto enable

Enable next-proto negotiation.

diagnose firewall vip virtual-server test next-proto enable

diagnose firewall vip virtual-server test rsa-blinding

Enable/disable RSA blinding.

diagnose firewall vip virtual-server test rsa-blinding

diagnose firewall vip virtual-server test rsa-blinding disable

Disable RSA blinding.

diagnose firewall vip virtual-server test rsa-blinding disable

diagnose firewall vip virtual-server test rsa-blinding enable

Enable RSA blinding (default).

diagnose firewall vip virtual-server test rsa-blinding enable

diagnose firewall vip virtual-server test ssl

SSL.

diagnose firewall vip virtual-server test ssl

diagnose firewall vip virtual-server test ssl async

Asynchronous SSL (default).

diagnose firewall vip virtual-server test ssl async

diagnose firewall vip virtual-server test ssl sync

Synchronous SSL.

diagnose firewall vip virtual-server test ssl sync