Fortinet white logo
Fortinet white logo

CLI Reference

fmupdate

fmupdate

Use this command to diagnose update services.

Syntax

diagnose fmupdate dbcontract {fds | fgd} <serial>

diagnose fmupdate del-device {fct | fds | fgd | fgc} <serial> <uid>

diagnose fmupdate del-log

diagnose fmupdate del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

diagnose fmupdate del-serverlist {fct | fds | fgd | fgc}

diagnose fmupdate fct-getobject

diagnose fmupdate fds-dump {breg | downstream-fct | fct | fgt | fmgi | srul}

diagnose fmupdate fds-get-downstream-device <serial>

diagnose fmupdate fds-getobject

diagnose fmupdate fds-update-info

diagnose fmupdate fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

diagnose fmupdate fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

diagnose fmupdate fgd-dbver {wf | as | av-query}

diagnose fmupdate fgd-del-db {wf | as | av-query | file-query}

diagnose fmupdate fgd-get-downstream-device

diagnose fmupdate fgd-test-client <ip> <serial> <string> <integer>

diagnose fmupdate fgd-url-rating <ip> <serial> <version> <url>

diagnose fmupdate fgd-wfas-clear-log

diagnose fmupdate fgd-wfas-log {name | ip} <string>

diagnose fmupdate fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

diagnose fmupdate fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} {periods}

diagnose fmupdate fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgt-del-statistics

diagnose fmupdate fgt-del-um-db

diagnose fmupdate fmg-statistic-info

diagnose fmupdate fortitoken {seriallist | add | del} {add | del | required}

diagnose fmupdate get-device {fct | fds | fgd | fgc} <serial>

diagnose fmupdate list-object {fds | fct | fgd | fgc | fgd-fgfq} [type] [version]

diagnose fmupdate service-restart {fds | fct | fgd | fgc}

diagnose fmupdate show-bandwidth {fct | fgt | fml | faz} {1h | 6h | 12h | 24h | 7d | 30d}

diagnose fmupdate show-dev-obj [serial_num]

diagnose fmupdate updatenow {fds | fgd | fct}

diagnose fmupdate update-status {fds | fct | fgd | fgc}

diagnose fmupdate view-configure {fds | fct | fgd | fgc}

diagnose fmupdate view-linkd-log {fct | fds | fgd | fgc}

diagnose fmupdate view-serverlist {fds | fct | fgd | fgc}

diagnose fmupdate view-service-info {fds | fgd}

diagnose fmupdate vm-license

Variable

Description

dbcontract {fds | fgd} <serial>

Dumb the subscriber contract.

del-device {fct | fds | fgd | fgc} <serial> <uid>

Delete a device. UID is required for FortiClient (fct) only.

del-log

Delete all the logs for FDS and FortiGuard update events.

del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

Remove all objects from the specified service. Optionally, enter the object type and version or time.

del-serverlist {fct | fds | fgd | fgc}

Delete the server list file (fdni.dat) from the specified service.

fct-getobject

Get the versions of all FortiClient objects.

fds-dump {breg | downstream-fct | fct | fgt | fmgi | srul}

Dumb FDS files:

  • breg: Dump the FDS beta serial numbers.
  • downstream-fct: Dump the downstream FortiClient file.
  • fct: Dump the FortiClient file.
  • fgt: Dump the FortiGate file.
  • fmgi: Dump FMGI (Object description details) file.
  • srul: Dump the FDS select filtering rules.

fds-get-downstream-device <serial>

Get information of all downstream FortiGate antivirus-IPS devices. Optionally, enter the device serial number.

fds-getobject

Get the versions of all FortiGate objects.

fds-update-info

Display scheduled update information.

fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

Display antispam device statistics for single or all devices.

  • <integer>: Number of time periods to display (optional, default = 1).

fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display antispam server statistics.

fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

Display the download bandwidth.

fgd-dbver {wf | as | av-query}

Get the version of the database. Optionally, enter the database type.

fgd-del-db {wf | as | av-query | file-query}

Delete FortiGuard database. Optionally, enter the database type.

fgd-get-downstream-device

Get information on all downstream FortiGate web filter and spam devices.

fgd-test-client <ip> <serial> <string> <integer>

Execute FortiGuard test client. Optionally, enter the hostname or IPv4 address of the FGD server, the serial number of the device, and the query number per second or URL.

fgd-url-rating <ip> <serial> <version> <url>

Rate URLs within the FortiManager database using the FortiGate serial number. Optionally, enter the category version and URL.

fgd-wfas-clear-log

Clear the FortiGuard service log file.

fgd-wfas-log {name | ip} <string>

View the FortiGuard service log file. Optionally, enter the device filter type, and device name or IPv4 address.

fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

Get the web filter / antispam rating speed. Optionally, enter the server type.

fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} <serialnum>

Display web filter device statistics. Optionally, enter a specific device’s serial number.

fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display web filter server statistics for the top 10 sites or devices. Optionally, enter the time frame to cover.

fgt-del-statistics

Remove all statistics (antivirus / IPS and web filter / antispam). This command requires a reboot.

fgt-del-um-db

Remove UM and UM-GUI databases. This command requires a reboot.

Note: um.db is a sqlite3 database that update manager uses internally. It will store AV/IPS package information of downloaded packages. This command removes the database file information. The package is not removed. After the reboot, the database will be recreated. Use this command if you suspect the database file is corrupted.

fmg-statistic-info

Display statistic information for FortiManager and Java Client.

fortitoken {seriallist | add | del} {add | del | required}

FortiToken related operations.

get-device {fct | fds | fgd | fgc} <serialnum>

Get device information. Optionally, enter a serial number.

list-object {fds | fct | fgd | fgc | fgd-fgfq} [type] [version]

List downloaded objects of linkd service. Optional enter the object type and version or time.

service-restart {fds | fct | fgd | fgc}

Restart the linkd service.

show-bandwidth {fct | fgt | fml | faz} {1h | 6h | 12h | 24h | 7d | 30d}

Display the download bandwidth for a device type over a specified time period.

show-dev-obj [serial_num]

Display an objects version of a device. Optionally, enter a serial number.

updatenow {fds | fgd | fct}

Update immediately.

update-status {fds | fct | fgd | fgc}

Display the update status.

view-configure {fds | fct | fgd | fgc}

Dump the running configuration.

view-linkd-log {fct | fds | fgd | fgc}

View the linkd log file.

view-serverlist {fds | fct | fgd | fgc}

Dump the server list.

view-service-info {fds | fgd}

Display the service information.

vm-license

Dump the FortiGate VM license.

fmupdate

fmupdate

Use this command to diagnose update services.

Syntax

diagnose fmupdate dbcontract {fds | fgd} <serial>

diagnose fmupdate del-device {fct | fds | fgd | fgc} <serial> <uid>

diagnose fmupdate del-log

diagnose fmupdate del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

diagnose fmupdate del-serverlist {fct | fds | fgd | fgc}

diagnose fmupdate fct-getobject

diagnose fmupdate fds-dump {breg | downstream-fct | fct | fgt | fmgi | srul}

diagnose fmupdate fds-get-downstream-device <serial>

diagnose fmupdate fds-getobject

diagnose fmupdate fds-update-info

diagnose fmupdate fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

diagnose fmupdate fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

diagnose fmupdate fgd-dbver {wf | as | av-query}

diagnose fmupdate fgd-del-db {wf | as | av-query | file-query}

diagnose fmupdate fgd-get-downstream-device

diagnose fmupdate fgd-test-client <ip> <serial> <string> <integer>

diagnose fmupdate fgd-url-rating <ip> <serial> <version> <url>

diagnose fmupdate fgd-wfas-clear-log

diagnose fmupdate fgd-wfas-log {name | ip} <string>

diagnose fmupdate fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

diagnose fmupdate fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} {periods}

diagnose fmupdate fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

diagnose fmupdate fgt-del-statistics

diagnose fmupdate fgt-del-um-db

diagnose fmupdate fmg-statistic-info

diagnose fmupdate fortitoken {seriallist | add | del} {add | del | required}

diagnose fmupdate get-device {fct | fds | fgd | fgc} <serial>

diagnose fmupdate list-object {fds | fct | fgd | fgc | fgd-fgfq} [type] [version]

diagnose fmupdate service-restart {fds | fct | fgd | fgc}

diagnose fmupdate show-bandwidth {fct | fgt | fml | faz} {1h | 6h | 12h | 24h | 7d | 30d}

diagnose fmupdate show-dev-obj [serial_num]

diagnose fmupdate updatenow {fds | fgd | fct}

diagnose fmupdate update-status {fds | fct | fgd | fgc}

diagnose fmupdate view-configure {fds | fct | fgd | fgc}

diagnose fmupdate view-linkd-log {fct | fds | fgd | fgc}

diagnose fmupdate view-serverlist {fds | fct | fgd | fgc}

diagnose fmupdate view-service-info {fds | fgd}

diagnose fmupdate vm-license

Variable

Description

dbcontract {fds | fgd} <serial>

Dumb the subscriber contract.

del-device {fct | fds | fgd | fgc} <serial> <uid>

Delete a device. UID is required for FortiClient (fct) only.

del-log

Delete all the logs for FDS and FortiGuard update events.

del-object {fds | fct | fgd | fgc | fgd-fgfq} <type> <version>

Remove all objects from the specified service. Optionally, enter the object type and version or time.

del-serverlist {fct | fds | fgd | fgc}

Delete the server list file (fdni.dat) from the specified service.

fct-getobject

Get the versions of all FortiClient objects.

fds-dump {breg | downstream-fct | fct | fgt | fmgi | srul}

Dumb FDS files:

  • breg: Dump the FDS beta serial numbers.
  • downstream-fct: Dump the downstream FortiClient file.
  • fct: Dump the FortiClient file.
  • fgt: Dump the FortiGate file.
  • fmgi: Dump FMGI (Object description details) file.
  • srul: Dump the FDS select filtering rules.

fds-get-downstream-device <serial>

Get information of all downstream FortiGate antivirus-IPS devices. Optionally, enter the device serial number.

fds-getobject

Get the versions of all FortiGate objects.

fds-update-info

Display scheduled update information.

fgd-asdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} {all | <serial>} <integer>

Display antispam device statistics for single or all devices.

  • <integer>: Number of time periods to display (optional, default = 1).

fgd-asserver-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display antispam server statistics.

fgd-bandwidth {1h | 6h | 12h | 24h | 7d | 30d}

Display the download bandwidth.

fgd-dbver {wf | as | av-query}

Get the version of the database. Optionally, enter the database type.

fgd-del-db {wf | as | av-query | file-query}

Delete FortiGuard database. Optionally, enter the database type.

fgd-get-downstream-device

Get information on all downstream FortiGate web filter and spam devices.

fgd-test-client <ip> <serial> <string> <integer>

Execute FortiGuard test client. Optionally, enter the hostname or IPv4 address of the FGD server, the serial number of the device, and the query number per second or URL.

fgd-url-rating <ip> <serial> <version> <url>

Rate URLs within the FortiManager database using the FortiGate serial number. Optionally, enter the category version and URL.

fgd-wfas-clear-log

Clear the FortiGuard service log file.

fgd-wfas-log {name | ip} <string>

View the FortiGuard service log file. Optionally, enter the device filter type, and device name or IPv4 address.

fgd-wfas-rate {wf | av | as_ip | as_url | as_hash}

Get the web filter / antispam rating speed. Optionally, enter the server type.

fgd-wfdevice-stat {10m | 30m | 1h | 6h | 12h | 24h | 7d} <serialnum>

Display web filter device statistics. Optionally, enter a specific device’s serial number.

fgd-wfserver-stat {top10sites | top10devices} {10m | 30m | 1h | 6h | 12h | 24h | 7d}

Display web filter server statistics for the top 10 sites or devices. Optionally, enter the time frame to cover.

fgt-del-statistics

Remove all statistics (antivirus / IPS and web filter / antispam). This command requires a reboot.

fgt-del-um-db

Remove UM and UM-GUI databases. This command requires a reboot.

Note: um.db is a sqlite3 database that update manager uses internally. It will store AV/IPS package information of downloaded packages. This command removes the database file information. The package is not removed. After the reboot, the database will be recreated. Use this command if you suspect the database file is corrupted.

fmg-statistic-info

Display statistic information for FortiManager and Java Client.

fortitoken {seriallist | add | del} {add | del | required}

FortiToken related operations.

get-device {fct | fds | fgd | fgc} <serialnum>

Get device information. Optionally, enter a serial number.

list-object {fds | fct | fgd | fgc | fgd-fgfq} [type] [version]

List downloaded objects of linkd service. Optional enter the object type and version or time.

service-restart {fds | fct | fgd | fgc}

Restart the linkd service.

show-bandwidth {fct | fgt | fml | faz} {1h | 6h | 12h | 24h | 7d | 30d}

Display the download bandwidth for a device type over a specified time period.

show-dev-obj [serial_num]

Display an objects version of a device. Optionally, enter a serial number.

updatenow {fds | fgd | fct}

Update immediately.

update-status {fds | fct | fgd | fgc}

Display the update status.

view-configure {fds | fct | fgd | fgc}

Dump the running configuration.

view-linkd-log {fct | fds | fgd | fgc}

View the linkd log file.

view-serverlist {fds | fct | fgd | fgc}

Dump the server list.

view-service-info {fds | fgd}

Display the service information.

vm-license

Dump the FortiGate VM license.