Fortinet Document Library

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

CLI Reference

fmupdate

Use this command to diagnose update services.

Syntax

diagnose fmupdate dbcontract {fds | fgd} <serial>

diagnose fmupdate deldevice {fct | fds | fgd | fgc} <serial> <uid>

diagnose fmupdate del-log

diagnose fmupdate del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

diagnose fmupdate del-serverlist {fct | fds | fgd | fgc}

diagnose fmupdate fct-getobject

diagnose fmupdate fds-dump-breg

diagnose fmupdate fds-dump-srul

diagnose fmupdate fds-get-downstream-device <serial>

diagnose fmupdate fds-getobject

diagnose fmupdate fds-update-info

diagnose fmupdate fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

diagnose fmupdate fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

diagnose fmupdate fgd-dbver {wf | as | av-query}

diagnose fmupdate fgd-del-db {wf | as | av-query | file-query}

diagnose fmupdate fgd-get-downstream-device

diagnose fmupdate fgd-test-client <ip> <serial> <string> <integer>

diagnose fmupdate fgd-url-rating <ip> <serial> <version> <url>

diagnose fmupdate fgd-wfas-clear-log

diagnose fmupdate fgd-wfas-log {name | ip} <string>

diagnose fmupdate fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

diagnose fmupdate fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} {periods}

diagnose fmupdate fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgt-del-statistics

diagnose fmupdate fgt-del-um-db

diagnose fmupdate fmg-statistic-info

diagnose fmupdate fortitoken {seriallist | add | del} {add | del | required}

diagnose fmupdate getdevice {fct | fds | fgd | fgc} <serial>

diagnose fmupdate list-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

diagnose fmupdate service-restart {fds | fct | fgd | fgc}

diagnose fmupdate show-bandwidth {fct | fgt | fml | faz} <string>

diagnose fmupdate show-dev-obj <serial>

diagnose fmupdate updatenow {fds | fgd | fct} <string>

diagnose fmupdate update-status {fds | fct | fgd | fgc}

diagnose fmupdate view-configure {fds | fct | fgd | fgc}

diagnose fmupdate view-linkd-log {fct | fds | fgd | fgc}

diagnose fmupdate view-serverlist {fds | fct | fgd | fgc}

diagnose fmupdate view-service-info {fds | fgd}

diagnose fmupdate vm-license

Variable

Description

dbcontract {fds | fgd} <serial>

Dumb the subscriber contract.

deldevice {fct | fds | fgd | fgc} <serial> <uid>

Delete a device. The UID applies only to FortiClient devices.

del-log

Delete log for FDS and FortiGuard update events.

del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

Remove all objects from the specified service. Optionally, enter the object type and version or time.

del-serverlist {fct | fds | fgd | fgc}

Delete server list from the specified service.

fct-getobject

Get the version of all FortiClient objects.

fds-dump-breg

Dump the FDS beta serial numbers.

fds-dump-srul

Dump the FDS select filtering rules.

fds-get-downstream-device <serial>

Get information of all downstream FortiGate antivirus-IPS devices. Optionally, enter the device serial number.

fds-getobject

Get the version of all FortiGate objects.

fds-update-info

Display the FDS update information.

fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

Display antispam device statistics for single or all devices.

<integer>: Number of time periods to display (optional, default is 1).

fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display antispam server statistics.

fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

Display the download bandwidth.

fgd-dbver {wf | as | av-query}

Get the version of the database. Optionally, enter the database type.

fgd-del-db {wf | as | av-query | file-query}

Delete FortiGuard database. Optionally, enter the database type.

fgd-get-downstream-device

Get information on all downstream FortiGate web filter and spam devices.

fgd-test-client <ip> <serial> <string> <integer>

Execute FortiGuard test client. Optionally, enter the hostname or IPv4 address of the FGD server, the serial number of the device, and the query number per second or URL.

fgd-url-rating <ip> <serial> <version> <url>

Rate URLs within the FortiManager database using the FortiGate serial number. Optionally, enter the category version and URL.

fgd-wfas-clear-log

Clear the FortiGuard service log file.

fgd-wfas-log {name | ip} <string>

View the FortiGuard service log file. Optionally, enter the device filter type, and device name or IPv4 address.

fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

Get the web filter / antispam rating speed. Optionally, enter the server type.

fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} <serialnum>

Display web filter device statistics. Optionally, enter a specific device’s serial number.

fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display web filter server statistics for the top 10 sites or devices. Optionally, enter the time frame to cover.

fgt-del-statistics

Remove all statistics (antivirus / IPS and web filter / antispam). This command requires a reboot.

fgt-del-um-db

Remove UM and UM-GUI databases. This command requires a reboot.

Note: um.db is a sqlite3 database that update manager uses internally. It will store AV/IPS package information of downloaded packages. This command removed the database file information. The package is not removed. After the reboot, the database will be recreated. Use this command if you suspect the database file is corrupted.

fmg-statistic-info

Display statistic information for FortiManager and Java Client.

fortitoken {seriallist | add | del} {add | del | required}

FortiToken related operations.

getdevice {fct | fds | fgd | fgc} <serialnum>

Get device information. Optionally, enter a serial number.

list-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

List downloaded linkd service objects.

service-restart {fds | fct | fgd | fgc}

Restart linkd service.

show-bandwidth {fct | fgt | fml | faz} <string>

Display download bandwidth. Enter the device type and type a value for <string>. The following options are available:  

  • 1h: 1 hours
  • 6h: 6 hours
  • 12h: 12 hours
  • 24h: 24 hours
  • 7d: 7 days
  • 30d: 30 days

show-dev-obj <serialnum>

Display an objects version of a device. Optionally, enter a serial number.

updatenow {fds | fgd | fct} <string>

Update fds, fgd or fct immediately.

update-status {fds | fct | fgd | fgc}

Display the update status.

view-configure {fds | fct | fgd | fgc}

View running configurations. The string value includes the type fct|fds|fgd|fgc].

view-linkd-log {fct | fds | fgd | fgc}

View the linkd log file.

view-serverlist {fds | fct | fgd | fgc}

View the server list. The string value includes the type fct|fds|fgd|fgc].

view-service-info {fds | fgd}

Display the service information.

vm-license

Dump the FortiGate VM license.

fmupdate

Use this command to diagnose update services.

Syntax

diagnose fmupdate dbcontract {fds | fgd} <serial>

diagnose fmupdate deldevice {fct | fds | fgd | fgc} <serial> <uid>

diagnose fmupdate del-log

diagnose fmupdate del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

diagnose fmupdate del-serverlist {fct | fds | fgd | fgc}

diagnose fmupdate fct-getobject

diagnose fmupdate fds-dump-breg

diagnose fmupdate fds-dump-srul

diagnose fmupdate fds-get-downstream-device <serial>

diagnose fmupdate fds-getobject

diagnose fmupdate fds-update-info

diagnose fmupdate fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

diagnose fmupdate fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

diagnose fmupdate fgd-dbver {wf | as | av-query}

diagnose fmupdate fgd-del-db {wf | as | av-query | file-query}

diagnose fmupdate fgd-get-downstream-device

diagnose fmupdate fgd-test-client <ip> <serial> <string> <integer>

diagnose fmupdate fgd-url-rating <ip> <serial> <version> <url>

diagnose fmupdate fgd-wfas-clear-log

diagnose fmupdate fgd-wfas-log {name | ip} <string>

diagnose fmupdate fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

diagnose fmupdate fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} {periods}

diagnose fmupdate fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgt-del-statistics

diagnose fmupdate fgt-del-um-db

diagnose fmupdate fmg-statistic-info

diagnose fmupdate fortitoken {seriallist | add | del} {add | del | required}

diagnose fmupdate getdevice {fct | fds | fgd | fgc} <serial>

diagnose fmupdate list-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

diagnose fmupdate service-restart {fds | fct | fgd | fgc}

diagnose fmupdate show-bandwidth {fct | fgt | fml | faz} <string>

diagnose fmupdate show-dev-obj <serial>

diagnose fmupdate updatenow {fds | fgd | fct} <string>

diagnose fmupdate update-status {fds | fct | fgd | fgc}

diagnose fmupdate view-configure {fds | fct | fgd | fgc}

diagnose fmupdate view-linkd-log {fct | fds | fgd | fgc}

diagnose fmupdate view-serverlist {fds | fct | fgd | fgc}

diagnose fmupdate view-service-info {fds | fgd}

diagnose fmupdate vm-license

Variable

Description

dbcontract {fds | fgd} <serial>

Dumb the subscriber contract.

deldevice {fct | fds | fgd | fgc} <serial> <uid>

Delete a device. The UID applies only to FortiClient devices.

del-log

Delete log for FDS and FortiGuard update events.

del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

Remove all objects from the specified service. Optionally, enter the object type and version or time.

del-serverlist {fct | fds | fgd | fgc}

Delete server list from the specified service.

fct-getobject

Get the version of all FortiClient objects.

fds-dump-breg

Dump the FDS beta serial numbers.

fds-dump-srul

Dump the FDS select filtering rules.

fds-get-downstream-device <serial>

Get information of all downstream FortiGate antivirus-IPS devices. Optionally, enter the device serial number.

fds-getobject

Get the version of all FortiGate objects.

fds-update-info

Display the FDS update information.

fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

Display antispam device statistics for single or all devices.

<integer>: Number of time periods to display (optional, default is 1).

fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display antispam server statistics.

fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

Display the download bandwidth.

fgd-dbver {wf | as | av-query}

Get the version of the database. Optionally, enter the database type.

fgd-del-db {wf | as | av-query | file-query}

Delete FortiGuard database. Optionally, enter the database type.

fgd-get-downstream-device

Get information on all downstream FortiGate web filter and spam devices.

fgd-test-client <ip> <serial> <string> <integer>

Execute FortiGuard test client. Optionally, enter the hostname or IPv4 address of the FGD server, the serial number of the device, and the query number per second or URL.

fgd-url-rating <ip> <serial> <version> <url>

Rate URLs within the FortiManager database using the FortiGate serial number. Optionally, enter the category version and URL.

fgd-wfas-clear-log

Clear the FortiGuard service log file.

fgd-wfas-log {name | ip} <string>

View the FortiGuard service log file. Optionally, enter the device filter type, and device name or IPv4 address.

fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

Get the web filter / antispam rating speed. Optionally, enter the server type.

fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} <serialnum>

Display web filter device statistics. Optionally, enter a specific device’s serial number.

fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display web filter server statistics for the top 10 sites or devices. Optionally, enter the time frame to cover.

fgt-del-statistics

Remove all statistics (antivirus / IPS and web filter / antispam). This command requires a reboot.

fgt-del-um-db

Remove UM and UM-GUI databases. This command requires a reboot.

Note: um.db is a sqlite3 database that update manager uses internally. It will store AV/IPS package information of downloaded packages. This command removed the database file information. The package is not removed. After the reboot, the database will be recreated. Use this command if you suspect the database file is corrupted.

fmg-statistic-info

Display statistic information for FortiManager and Java Client.

fortitoken {seriallist | add | del} {add | del | required}

FortiToken related operations.

getdevice {fct | fds | fgd | fgc} <serialnum>

Get device information. Optionally, enter a serial number.

list-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

List downloaded linkd service objects.

service-restart {fds | fct | fgd | fgc}

Restart linkd service.

show-bandwidth {fct | fgt | fml | faz} <string>

Display download bandwidth. Enter the device type and type a value for <string>. The following options are available:  

  • 1h: 1 hours
  • 6h: 6 hours
  • 12h: 12 hours
  • 24h: 24 hours
  • 7d: 7 days
  • 30d: 30 days

show-dev-obj <serialnum>

Display an objects version of a device. Optionally, enter a serial number.

updatenow {fds | fgd | fct} <string>

Update fds, fgd or fct immediately.

update-status {fds | fct | fgd | fgc}

Display the update status.

view-configure {fds | fct | fgd | fgc}

View running configurations. The string value includes the type fct|fds|fgd|fgc].

view-linkd-log {fct | fds | fgd | fgc}

View the linkd log file.

view-serverlist {fds | fct | fgd | fgc}

View the server list. The string value includes the type fct|fds|fgd|fgc].

view-service-info {fds | fgd}

Display the service information.

vm-license

Dump the FortiGate VM license.